150,000 Agents. 13% Governance. Something Has to Give.
Enterprises are accumulating AI agents faster than the systems to govern them. The infrastructure gap is widening — and it matters.
There is a quiet infrastructure crisis building inside large enterprises. AI agents are proliferating — across departments, desktops, cloud environments and vendor ecosystems — faster than the governance frameworks meant to manage them. Gartner projects that the average global Fortune 500 company will operate more than 150,000 AI agents by 2028, up from fewer than 15 in 2025. Yet only 13% of organizations believe they currently have adequate AI agent governance in place. That gap is not a procurement problem. It is an architectural one.
From Assistance to Action — Without the Guardrails
The shift happened quickly. Tools that once drafted emails or summarised documents now execute multi-step workflows, call external APIs, access enterprise data stores and take actions on behalf of users — often with no centralised audit trail and no clear chain of accountability. When an agent runs locally on an employee's laptop, it operates as what one infrastructure founder recently described as a black box: nothing governed, nothing audited, nothing controlled.
The governance problem is compounded by fragmentation. Many enterprises have agents tied to a single AI provider's tooling, frameworks and roadmap. Others have agent workflows siloed to individual users, with the prompts, skills and institutional context those employees have built staying locked inside a vendor's ecosystem rather than becoming organisational assets. A third pattern — arguably the most operationally risky — is agents running entirely without a centralised permission model, with no defined scope for what resources they can reach or what actions require human approval.
The agent isn't the problem. The missing infrastructure around the agent is.
The Emerging Control Plane Market
A new category of infrastructure is forming in response: control planes that sit above individual models and agent frameworks, handling execution, permissions, identity, memory, observability and lifecycle management without requiring developers to rebuild those services for every new agent deployment. The premise is that accessing a foundation model is comparatively straightforward; recreating the operational infrastructure surrounding a governed, production-grade agent is not.
xpander.ai, founded by former AWS principal engineers, is the latest entrant positioning itself as a vendor-neutral control plane for enterprises that want to retain flexibility across models, frameworks and cloud environments. Its architecture treats the underlying agent framework as a replaceable component, allowing enterprises to bring agents built with different tools into a single governed runtime. The company's broader argument — that model selection should eventually resemble choosing compute rather than committing to an entire software ecosystem — reflects a thesis gaining traction across the industry.
That thesis is not unique to xpander. LangChain's LangSmith, CrewAI's enterprise offering, Temporal's durable workflow infrastructure and AWS's AgentCore all address overlapping portions of the same problem. The differences lie in how much of the agent stack each platform attempts to own, and whether they provide a development framework, a neutral runtime, durable execution infrastructure or a managed cloud service. Enterprises evaluating this space should map those distinctions carefully against their own deployment requirements — particularly around data residency, model portability and the portability of the control plane itself if a vendor relationship ends.
One governance detail worth noting regardless of platform choice: how credentials are handled at tool-call time. Injecting credentials from a vault at execution rather than exposing them to the model is an architectural pattern security teams should look for explicitly when evaluating any agent runtime.
What This Means for Operators in AI-Intensive Industries
The agent sprawl problem is not confined to large technology companies. Healthcare providers, legal practices, real estate firms and hospitality operators are all beginning to deploy autonomous agents for intake, scheduling, follow-up and communication — often without a clear governance framework in place for the agents running those workflows.
The infrastructure question that enterprise technology teams are wrestling with today — who can invoke an agent, what resources it can reach, which actions require human approval, and how actions are traced back to the individual who authorised them — applies equally to a clinic deploying an AI agent for patient intake and to a law firm using an agent for client follow-up. The operational stakes are different in each context, but the underlying governance requirement is the same: agents that take actions on behalf of an organisation need defined permission boundaries, auditable trails and human oversight at appropriate decision points.
The emergence of vendor-neutral control plane infrastructure is a signal that the industry is moving past the question of whether to deploy agents and toward the harder question of how to deploy them responsibly. Many early agent pilots stall not because the underlying model fails, but because the surrounding governance, integration and oversight infrastructure was never built. Organisations that invest in that layer now — whether through a third-party control plane or carefully assembled internal tooling — are likely to find their agent deployments more durable, more auditable and more capable of scaling beyond individual users into genuinely organisational workflows.
Further Reading: venturebeat.com
Ready to Put Agentic AI to Work?
See how autonomous AI agents can handle booking, intake, and follow-up for your business.