In the span of two weeks this spring, five of the largest enterprise software platforms shipped โ almost in unison โ a governance layer for autonomous AI agents. Google folded a Managed Agent Harness into its cloud. Microsoft and ServiceNow pushed MCP governance deeper into their stacks. WSO2 released an Agent Manager. And a quieter name, TrueFoundry, took a category-leadership designation from Frost & Sullivan for an "AI control plane" it says routes a trillion tokens a day.
The coincidence is the story. When competitors converge on the same launch window, they are not copying each other โ they are responding to a shift in the substrate beneath them. I have watched this pattern twice before. In the summer of 2020, every lending protocol published near-identical yield curves. In 2022, every algorithmic stablecoin insisted its peg was structurally unique. Both times, the uniformity was a warning, not a confirmation. What looks like noise is often pattern.
To understand what is being contested, you have to start with a protocol most readers have never configured. In November 2024, Anthropic open-sourced the Model Context Protocol, a spec for how AI agents call tools, models, and each other. Its significance is architectural: MCP moves governance from the platform layer to the protocol layer. Once a model can reach any tool through a shared grammar, the question stops being which platform hosts the agent and becomes who governs the agent's access.
That question created a new layer in the stack. The industry now calls it the AI control plane โ a vendor-neutral overlay sitting between the model and the application. TrueFoundry's version is a split-plane architecture with four components: an MCP Gateway for protocol-level control, an Agent Gateway for lifecycle management, a Model Gateway for inference routing, and a Skills Registry that catalogs agent capabilities. A single pane governs all four.

Sound familiar? It should. A model gateway is an API gateway with an LLM router bolted on โ Portkey and LiteLLM already sell that. A skills registry is a service registry wearing new clothes; Consul and etcd solved cataloging a decade ago. The genuine innovation is not any single layer; it is the bet that enterprises will buy one integrated pane instead of five specialized tools. That is a purchasing hypothesis, not a technical breakthrough, and it deserves the skepticism I applied to permissionless yield in 2020.
The scale claim is the headline: 1 trillion tokens per day, roughly 11.6 million tokens per second if evenly distributed. For a governance layer that mostly forwards and audits rather than generates, that is a plausible production load. But the metric is doing more rhetorical work than technical work. Tokens processed is not revenue. The designation came from an independent analyst firm marking a category barely a year old, and the announcement carried no pricing, no ARR, no retention, no customer count. In my years auditing yield mechanisms, I learned that when a dashboard shows only the inputs that flatter it, the missing fields are the analysis.
None of this is an argument that the category is fake. It is an argument that the category and the company are being certified at the same time, and only one of them has earned it. The five-vendor convergence is real evidence that a governance layer is forming. It is also evidence that the layer is being colonized before it matures, which is precisely how categories get absorbed before they can defend themselves.
So let me supply what the company did not. Three structural facts matter, and none of them appear in the announcement. Every control plane imposes a tax. Routing all agent traffic through a single governance overlay adds a hop. I modeled this in 2024 when I helped allocate $15 million into spot bitcoin ETFs and spent weeks correlating equity flows with crypto liquidity โ a 0.85 correlation during high-rate regimes. The lesson was that latency and liquidity are the same conversation wearing different clothes. The control plane's entire value proposition, visibility into every action, is purchased with latency on every action. The source material never quantifies the delay, the throughput ceiling, or the failure-recovery profile. A gate that cannot be measured cannot be trusted with a ledger.
The competitive terrain is a rerun of a war infrastructure investors already know the ending to. Vendor-neutral overlays versus platform bundling is the oldest contest in software. Kubernetes distributions mostly lost to managed cloud Kubernetes. Istio was absorbed into the platforms it once floated above. Observability vendors survived only by moving into a budget category the clouds were slow to claim. The pattern is consistent: a neutral layer survives only when the platform's cost of replicating it stays higher than the platform's willingness to bundle it. TrueFoundry's compliance bundle โ SOC 2, HIPAA, ITAR โ is the flimsiest kind of moat, because it is a certificate, and certificates expire or get matched. The company's own material concedes the biggest threat is hyperscaler zero-marginal-cost bundling. When a founder names your executioner, believe them.
And the same fight is already underway on-chain, where it is more honest because the state is public. In the first half of 2026, I mapped roughly $500 million in decentralized exchange volume moved by autonomous agents reacting to macro prints faster than any human could click. These agents do not ask permission; they route around governance the way water routes around a stone. The enterprise control plane is building a dam upstream of that behavior. The crypto-native equivalent โ a governance layer whose every decision is verifiable on a public ledger โ has a structural property the enterprise version can never copy: it does not have to be trusted, because it can be checked.

This is why the LayerZero comparison is unavoidable. I have written before that LayerZero's verification rests on an oracle and a relayer, meaning its trust assumptions are social, not cryptographic โ decentralized in name, custodial in architecture. An enterprise AI control plane repeats that error at larger scale. It promises neutrality while concentrating the ability to see every agent, every tool call, and every payload into one operator, one audit trail, one attack surface. The bridge stands only when foundations are sound, and a foundation of a single pane of glass shatters as one.
The assumption underneath all of it is that enterprises will remain multi-cloud and multi-model. That is the load-bearing wall, and it is cracking. In my 2026 research on AI agents and liquidity, I found the opposite tendency accelerating: agents concentrate onto the venues with the deepest books, because routing to a thin venue costs more in slippage than it saves in optionality. If corporate AI follows the same gravity โ toward one dominant cloud, one dominant model provider โ the neutral layer loses its reason to exist. The value of neutrality is proportional to the cost of switching, and the cost of switching is falling every quarter as the major platforms standardize their agent interfaces.
There is a governance-token parallel here that crypto spent five years failing to price. A DAO governance token is non-dividend stock: the holder's only exit is a later buyer taking the bag. An enterprise control plane's neutrality is non-dividend infrastructure: its only defense is that no incumbent chooses to bundle. Both rest on a promise that a structural advantage persists. Liquidity is a narrative, not a metric. So is neutrality.
There is also a compliance story folded inside the architecture. ITAR certification is not a badge; it is a legal arrangement with the United States government, and it cuts both ways. It grants access to defense buyers no cloud-native competitor can easily court, and it permanently caps the market at the boundary of American export control. This is the dynamic I watched with stablecoins in 2025, when I declined to structure a $30 million token launch around cross-border gray areas. Regulatory arbitrage is a bridge built over a river that moves. The honest version of that strategy โ the PayPal version, where you become a regulatory partner before you are regulated โ is expensive, slow, and unglamorous. It is also the one that tends to survive the next cycle.
The deepest omission is structural. The source material presents compliance as pure advantage. It never asks what happens when the control plane itself is breached. A system with visibility into every agent across every model on every cloud is, by construction, the single most valuable target in the enterprise โ one breach yields lateral control over all of it. Multi-tenant governance means a shared audit plane holding defense and healthcare metadata side by side. The illusion of liquidity dissolves in silence โ and the silence here is the missing paragraph on blast radius.
For readers who trade crypto and wonder why an enterprise AI control plane belongs in a macro letter: because the same capital is being allocated against both. The fund that buys into an agent-infrastructure story is the fund that repriced DeFi infrastructure two years ago. Governance layers are where the next liquidity premium is being priced, and price is discovered long before it is understood.
Everyone is framing this as neutral overlay versus hyperscaler bundling. That is the framing the incumbents want, because it makes the fight about distribution, where they win. The subtler reading is that the control plane is not a product at all. It is a moment โ the interval between a new protocol becoming standard and the platform absorbing it. The category was certified; the company behind it was not. Frost & Sullivan does not so much certify markets as confirm that competition exists within one, and awards of this kind are frequently transactional.

The contrarian claim is this: the durable agent-governance layer will not be built by a vendor, because the one thing a vendor cannot credibly sell is the guarantee that it will not act in its own interest. It will be built where the state is public and the audit is cryptographic โ on-chain, or in a hybrid the enterprise market is not yet ready to name. Crypto is ignoring this because the money is in the enterprise narrative. The winner in agent governance will be the party that can prove, not promise, correct behavior under adversarial conditions. Today that party is nobody. But the architecture of proof already exists, and it is not a SaaS dashboard.
The market is sideways, and sideways markets are where positioning happens, not where narratives settle. The real question is not whether TrueFoundry wins. It is whether any neutral governance layer can survive being sandwiched between a protocol it does not control and platforms that can give it away. Watch three signals: whether Google prices its agent harness at zero, whether MCP governance consolidates under a multi-party standard, and whether any control plane publishes a verifiable audit rather than an audited certificate. Bridge the gap between capital and conviction โ but only where the foundation can be inspected.