ISG Software Research Analyst Perspectives

The Fourth Enterprise Control Plane Is Emerging Around AI

Written by Jeff Orr | Aug 11, 2026, 10:00:00 AM

Enterprise architecture has traditionally been organized around three primary control planes: infrastructure, identity and applications. Each evolved to solve a specific challenge. Infrastructure established where workloads execute. Identity determined who could access enterprise resources. Applications standardized business processes and information flows.

Artificial intelligence introduces a different problem. Autonomous software can now make decisions, invoke tools, modify data and initiate workflows with limited human involvement. Existing control planes were never designed to govern autonomous actions that span multiple systems simultaneously.

This gap is driving the emergence of a fourth enterprise control plane.

The market signals have become difficult to ignore. Identity providers are extending governance to non-human identities. Observability platforms are evolving into operational execution platforms capable of validating and initiating automated responses. Application development platforms now emphasize agent permissions, policy enforcement and audit trails alongside developer productivity. Workflow platforms increasingly position themselves as systems of action that coordinate autonomous work across enterprise processes.

These announcements appear to represent different product strategies. Collectively, they address the same architectural problem. The enterprise does not need another place to run AI. It needs a consistent way to govern AI regardless of where it runs.

The fourth enterprise control plane spans infrastructure, applications and identities without replacing any of them. Its responsibility is to establish enterprise-wide policies governing autonomous execution. That includes runtime authorization, delegated permissions, observability, rollback, evidence collection and operational accountability.

ISG Research asserts that by 2028, two-thirds of large enterprises will establish a cross-platform control plane for autonomous systems, reducing policy conflicts and improving accountability across AI-enabled operations. This architectural shift extends well beyond AI. Future autonomous systems will include intelligent automation, software-defined infrastructure, adaptive cybersecurity and business process orchestration. Each introduces additional autonomous actors requiring consistent governance across organizational boundaries.

Enterprise IT leaders should resist solving this challenge through isolated platform investments. Individual software providers will continue expanding governance capabilities, but organizations that allow every platform to define its own control model will create fragmented operational policies and inconsistent accountability.

Instead, CIOs should begin defining an enterprise control architecture that answers several foundational questions. Which systems authorize autonomous actions? Where are enterprise policies enforced? How is evidence collected across platforms? Who owns operational accountability when autonomous systems interact?

Organizations that answer these questions first will scale autonomous technologies with greater confidence and lower operational risk. Those that delay will discover that managing autonomous work is fundamentally different from deploying another application.

Regards,

Jeff Orr