Every mature technology ends up with a control plane. Networks got one when traffic outgrew the ability of any one device to police it. Cloud got one when workloads outgrew any one machine. Kubernetes is, at its heart, a control plane with a fan club. The pattern repeats because the problem repeats: when something powerful proliferates faster than the rules around it, you stop trying to govern each instance and you build the layer that governs all of them.
Enterprise AI has reached that point, and it got there faster than anything before it.
Consider what's actually running inside a mid-sized regulated company today. Employees on two or three chat interfaces. Developers on coding agents that read repositories and call internal APIs. A dozen custom agents wired into the ERP, the CRM, the document store — each built by a different team, each with its own credentials, each one prompt away from touching three systems in a single operation. Multiple model providers, because no sensible architect bets the company on one. And a security organisation asked to govern all of it with tools designed for a world where software did what it was configured to do, not what it was asked to do.
The instinctive response has been to buy point tools — one for prompt safety, one for agent monitoring, one for shadow-AI discovery, one for spend tracking. The market is happy to oblige; there's a vendor for every slice. But fifteen narrow tools don't add up to control, they add up to fifteen dashboards, fifteen integration projects and fifteen renewal conversations. The security leaders we talk to — especially in financial services, healthcare and insurance — are saying the same thing with increasing impatience: one framework, not fifteen. A reference architecture, not a collection of features.
That's what a control plane is. One gateway that every AI call passes through, doing four jobs that today are scattered across departments and tools, or not done at all:
- Access. Role-based control at the tool level, enforced before execution. The agent cannot invoke a tool its operator's role doesn't permit — across the ERP, the document store and the systems of record, not just inside the AI tool. Identity inherits from the directory you already run, so there's no cold start.
- Audit. A complete record of every action — who asked, in what role, which model, which tool with which arguments, allowed or denied — captured at your gateway, in your environment. Evidence you own and can put in front of an auditor, a regulator or a committee without asking a model provider for a favour.
- Cost. Token-level metering on the same layer: live spend by department, user, model and workflow, with budget caps and alerts ahead of the surprise. This is the piece the security market almost universally lacks, and it's the piece that turns governance from a cost centre into the function that can finally answer what AI is returning.
- Independence. Model-agnostic routing, so Claude, GPT, Gemini and self-hosted models are swappable per request under one policy. Deployment in your own cloud or on-prem, so sovereignty is structural rather than promised. No lock-in to a provider's roadmap — including ours, which is why source-code delivery exists for customers who require it.
Notice what's not on that list: the control plane doesn't replace your security stack, it completes it. Your EDR keeps watching endpoints. Your SIEM keeps doing analytics — fed, now, with deterministic and complete logs instead of fragments. Runtime guardrail tools, if you run them, sit on top of the plane the way intrusion detection sits on top of a firewall. The plane is the layer underneath: the one that decides, meters and records.
There's a reason this layer won't come from the model providers, and it's not a conspiracy — it's just incentives. No provider profits from making itself substitutable, from surfacing complete cross-provider spend, or from handing you an audit trail that works against its competitors as well as itself. The control plane has to be neutral to be useful. It has to sit with the customer, in the customer's environment, agnostic to everything above it.
The control plane has to be neutral to be useful — it sits with the customer, agnostic to everything above it.
Adoption usually follows the same sequence. First, the invisible layer: existing tools repointed through the gateway, so governance arrives without anyone changing how they work — most people never need to know the plane exists. Then policy tightens from observed reality rather than theory. Then, where it's wanted, a governed portal for the use cases that have no natural home. Weeks, not quarters, because the plane wraps around what's already running instead of asking anyone to rebuild.
AI will keep proliferating; that part is no longer a decision anyone gets to make. The decision that remains is whether it proliferates on top of a layer that can answer who, what, whether it was allowed, and what it cost — or on top of nothing.
Every mature technology ends up with a control plane. AI's is overdue.
MisaLabs builds the enterprise AI control plane. Govern AI usage. Prove the ROI. In your environment.
Talk to us →