New Lyzr launches Control Plane for AI Agents Access now (opens in a new tab)
Customers Pricing
All white papers

The enterprise agent estate is the next infrastructure decision

When the model layer can shift, governing what you've built matters more than what you built it on.

L
Lyzr Team
Jul 23, 2026
17 min read

Your model choice is now a supply-chain decision

Most agent stacks are not built like they know that. The strongest reason a technical leader needs a control layer in 2026 is not that agent sprawl is messy. It is that the ground under every model is moving, and the layer that survives the movement is the one this paper is about.

Ask a harder question
Not “which model is best,” but “how fast could I replace it?”

Ask this: if the foundation model your agents run on were pulled offline tomorrow by a government you do not answer to, how long would it take you to swap it out? For most teams, the honest answer is measured in re-architecture, not in minutes. That answer is now a live operational risk, not a thought experiment, and it is the argument for everything that follows.

The model landscape became a geopolitical variable

For most of the last decade, choosing a model was a technical decision: benchmark it, price it, ship it. That era is closing. In mid-2026 the model layer has become an object of statecraft, and the events are no longer hypothetical.

In June 2026, Anthropic suspended access to two of its frontier models , Fable 5 and Mythos 5 , to comply with United States Department of Commerce export controls. Access was restored roughly three weeks later, once those controls were lifted, not because the models changed.1 Read that sequence plainly: a globally deployed frontier model went dark on government order, and came back on government order. The scenario most architecture reviews had filed under “theoretical” happened, was resolved by policy rather than engineering, and left every team that depended on those models with an outage they could not fix themselves.

What happened next is the part that should worry a technical leader more than the outage itself. US enterprise usage of Chinese models surged in the wake of those restrictions: unsurprising, given some of those systems offer 60% to 90% cost savings over domestic alternatives.2 The US government is now evaluating restrictions on corporate use of Chinese models on security grounds, and Congress is investigating the trend.3 At the same time, Beijing is reportedly weighing curbs on overseas access to its own most advanced models. Authorities have held meetings with Alibaba, ByteDance and Z.ai about a tiered framework: basic open-source tools subject to registration or filing, advanced technologies requiring rigorous security review, and frontier models barred from public global release or restricted to domestic use entirely.4

Read those two developments together and the shape is a vise, not a list. An export control pushed teams toward a cheaper alternative; that alternative is now under scrutiny on one side and may be walled off from the other. A team that reacted to June by migrating to a Chinese model did not remove a sovereign dependency; it may have acquired a second one. And note the detail that closes the last escape hatch: open-weight releases sit inside the proposed scope. “We will just self-host an open model” stops being a governance strategy the moment the release itself becomes a policy variable.

None of this is new, and that is the point. Regulators were acting on Chinese models eighteen months before the June suspension. Italy’s Garante imposed a definitive limitation on DeepSeek processing Italian users’ personal data in early 2025 , after the company argued that EU law did not apply to it , and the app came off both major app stores. Germany’s data protection commissioner asked Apple and Google to remove it over unlawful data transfers to China. South Korea’s PIPC suspended new downloads until the service was brought into line with Korean law. Australia, Taiwan and the Netherlands barred it from government devices outright.5

Read the scope of those actions carefully, because the detail is instructive rather than alarming. They targeted a consumer app, its data transfers, and its presence on public-sector devices: not an enterprise’s right to run open weights inside its own environment. What they establish is precedent: regulators will act on a model’s provenance, and they will act quickly. Set that alongside 2026, where states are now acting on a model’s availability, and two independent mechanisms are converging on the same dependency from opposite directions. Data-protection enforcement governs where your data may go. Export control governs whether the model exists for you at all. Neither is a problem you solve by choosing a better model.

The direction of travel is unambiguous even where individual details keep shifting, and they will keep shifting, in both capitals, faster than any procurement cycle. The model you standardize on is now exposed to export law, sanction, and sovereign policy in ways it was not eighteen months ago. The lesson is not “pick the right model.” It is that picking is no longer a durable strategy.

Screenshot 2026 07 23 at 7.19.16 PM

One metric operationalizes the whole argument


Geopolitics is abstract until you can measure your exposure to it. The single number that makes it concrete is Model Dependency Exposure: the share of your production agent workloads riding on any one foundation model. A control plane is what lets you see that number and cap it, so that no ban, price shock, or policy change against a single model can take a disproportionate slice of your production estate offline at once.

Screenshot 2026 07 23 at 7.21.19 PM

Everything downstream of this point , how agents are built, added, governed, and deployed , depends on first having a layer that can hold the model at arm’s length. A control plane earns the model-portability argument on its own. In the next section we separate that job from the three it is constantly confused with, so the rest of the paper has a spine to hang on.

AGENT TO PRODUCTION

Four jobs the market keeps conflating

“Agent to production” sounds like one problem. It is four, each needing a different tool. Naming them cleanly is the difference between buying a control plane and buying something that only looks like one.

Build, add, govern, deploy. These are distinct jobs, and most of the market sells one while implying all four.

  • Build is authoring the agent: the logic, the prompts, the orchestration graph.
  • Add is dropping an agent into an existing stack, the additive motion of extending what you already run.
  • Deploy is getting an agent to production and keeping it live: uptime, SLA, rollback.
  • And Govern , visibility, audit, model control, evaluation gates, identity, escalation tracking , is the job a control plane exists to do. A control plane sits squarely in Govern.

But it is the layer that makes Build and Deploy safe, and makes Add auditable; it touches all four without being reducible to any of the other three.

Screenshot 2026 07 23 at 7.23.58 PM

The production gap, quantified

The reason Govern becomes non-optional is a matter of arithmetic, not ideology. Two forces collide: most agents die before production, and the ones that live multiply until no human can watch them by eye.

On the first, the industry’s own number is stark: 42% of companies now abandon most of their AI initiatives before they reach production, up from 17% a year earlier.6 The gap is rarely the model; it is the transition from pilot to production, where fragmented data, thin integrations, and operational constraints unravel what looked finished in a sandbox. Against that baseline, a control-plane-native motion changes the odds: roughly 85% of customers who start a sandbox go on to a paid production deployment, with evaluation gating a core reason why.

On the second, depth compounds. Adoption does not stop at one agent per team; it multiplies into the dozens, and at the leading edge a single enterprise runs hundreds of interconnected agents in one function. You cannot watch a fleet that size by eye. The moment an organization crosses from a handful of copilots to a fleet, governance stops being a nicety and becomes the only way to keep the fleet trustworthy.

Screenshot 2026 07 23 at 7.25.52 PM

INSIDE THE CONTROL PLANE

The numbers a control plane can produce

Most agentic-AI tools cannot emit clean operational telemetry: because they observe agents built inside frameworks they do not own, and can watch a trace without being able to gate, cap, or promote it. Producing these numbers is itself the maturity signal.

Why the numbers are the differentiator

An observability tool bolted onto a framework can tell you what happened. It cannot stop the thing that is about to happen. The difference between watching and governing is the difference between a dashboard and a control surface, and it shows up precisely in which numbers a system can produce cleanly and act on. The following families are what a real control plane watches, gates, or caps. Read them as a feature tour told through metrics rather than screenshots.

Screenshot 2026 07 23 at 7.27.43 PM

Agent task success rate , end-to-end completion without a human having to take over, sits around 95% on measured workloads. Availability runs at 99.9% of scheduled minutes, weighted by customer, against a contractual SLA target of 99.5%. We report it without ceremony: uptime in this range is table stakes for anything calling itself production infrastructure, and a technical reader trusts the plain framing more than the boast. Eval pass rate before promotion runs near 95%: the share of agents that clear the evaluation gate before they are allowed anywhere near a user. On workload shape, 100% of production workflow invocations involve more than one step or more than one agent, up from 90% a quarter earlier, against an internal bar of 50%. Read that as a statement about population rather than prowess: it says the estate is doing genuinely multi-step work rather than single-prompt call-and-response, which is the thing that makes governance necessary in the first place.

Two governance-specific numbers matter most for this paper. Model Dependency Exposure, from Section 1, is the control rather than the slide: inference calls per model over total inference calls in the period, read off the model gateway, with a standing policy that no single model exceeds 60% of production workloads. It is a cap you enforce per estate, not a trophy number to quote. And inference cost per agent action is the margin-and-defensibility metric, the one that decides whether a fleet is economically sustainable at scale.

Screenshot 2026 07 23 at 7.28.08 PM

How it actually plugs in


A technical reader will not accept “framework-agnostic, drop-in governance” as an assertion. It needs a mechanism. The Lyzr Control Plane sits above the model and across the framework.

Exhibit 1: Agent Control Plane dashboard providing a centralized view of AI agent deployments across frameworks and cloud providers, with deployment status, branch management, and one-click deployment actions.

image 13

Agents built in LangChain, CrewAI, Agentforce, a hyperscaler’s builder, or a custom stack connect to one plane without migration or rewrite. Because the plane sits above the LLM choice, swapping one model for another, GPT-class for Claude, Gemini for Llama , does not touch agent logic; the swap propagates from the control layer, which is exactly what makes the Section 1 model-portability promise real rather than rhetorical.

Screenshot 2026 07 23 at 7.28.37 PM

Underneath, the observable surface is generated by the plane’s orchestration, evaluation, and memory capabilities. Long-running, multi-agent flows execute as persisted, retried, exactly-once steps; the orchestration layer of Lyzr Studio, which the control plane governs like any other.

Group 1321324829

A simulation and evaluation stage runs many thousands of simulations per agent as a proving ground, so failures surface before a user ever sees them, and a shared knowledge graph and memory give agents grounded context. Each capability contributes a slice of the surface the plane watches; the metrics in Figure 3 are what they make visible.

“I ALREADY HAVE ORCHESTRATION”

Workflow automation is not a control plane

The real question is fair: “I already run workflow tooling: why do I need this?” The honest answer is that they solve different problems, and confusing them is how governance debt accumulates.

Frame the tool fairly
Capable orchestration is a real category: just a different layer

Workflow-automation platforms are genuinely capable: visual builders, hundreds of integrations, human-in-the-loop gates, execution logs, model routing, queue-based scaling, self-hosting. None of that is in dispute, and a control plane does not replace it. What it does is govern a different surface. A workflow tool governs the tool: authentication and role-based access on its own platform. A control plane governs agent behaviour across every agent, regardless of where that agent was built.

Draw the line where workflow automation stops and governance begins. Model-concentration caps, evaluation-gated promotion, and audit trails are first-class primitives in a control plane: not things you wire up node by node and hope stay consistent. Governance in a workflow tool is scoped to the workflows built inside that tool; governance in a control plane is scoped to the whole estate: an agent built in LangChain, a CrewAI service, an Agentforce flow, a Claude-backed assistant, all held to the same policy from one place.

Exhibit 3: Expanded deployment view showing branch-level environments, deployment history, runtime status, and redeployment controls, enabling complete lifecycle visibility and management for enterprise AI agents.

image 3 1

The positioning statement is not adversarial. Workflow automation is where you build some flows. A control plane is where all your agents , however built , get governed. Lyzr Studio has its own orchestration for building flows, and those flows inherit the control plane’s governance by default rather than bolting it on node by node. The useful mental model, borrowed from the broader market’s “agent gateway” framing, is that these are different layers of the same stack; and the reader who already runs orchestration is exactly the reader who most needs a governing layer above it, because they are already producing agents faster than they can watch them.

Screenshot 2026 07 23 at 7.31.36 PM

COMPETITIVE LANDSCAPE

Observability tells you what already happened

The control-plane field is real and crowded. The credible move is to name it, then differentiate on the axis a CTO actually cares about.

The category is legitimately contested. Enterprise monitoring platforms unify ML and GenAI observability for regulated, safety-critical settings. Framework-native tools offer the deepest integration with the framework they belong to, at the cost of being locked to it. Telemetry-native platforms bring open-standards tracing and drift detection from an ML-monitoring heritage. Open-source self-hosting leaders let teams run the stack themselves. Eval-first and issue-lifecycle challengers compete on evaluation depth. And the hyperscalers ship their own agent gateways and model-safety layers. This is a serious field, and any paper that waves it away loses the reader in a sentence.

The differentiation axis that matters is not feature count; it is observe versus govern. Most of the field observes: it tells you what happened, cleanly and often beautifully. The claim here is narrower and harder: govern, build, and deploy in one plane, framework-agnostic, with the model-concentration and sovereignty controls that pure observability does not carry. Tie it back to Section 1: an observability tool does not help you when a model gets banned. A control plane with model governance does. That is the axis, and it is the one a technical leader is actually buying on.

Group 1321324864

Two honest refinements keep this credible. First, the sharpest competitor is not an observability tool at all but an enterprise platform that already calls itself a control plane; against it, the differentiation is not “they only watch” but the verb , it monitors ML and GenAI, whereas the Lyzr Control Plane builds, gates, and deploys agents across frameworks and clouds. Second, the hyperscaler is the real objection, because adopting the cloud you already pay for is the path of least resistance , and here the geopolitical thread cuts our way: a hyperscaler’s governance is scoped to agents built in its ecosystem and running in its cloud, while a neutral plane is cross-cloud, cross-framework, and portable off the hyperscaler entirely. For a reader worried about concentration, adding a vendor they can leave is a very different proposition from deepening one they cannot.

The same estate, ungoverned versus governed


Stated as a before-and-after, the difference stops being abstract.

Screenshot 2026 07 23 at 7.33.09 PM
Screenshot 2026 07 23 at 7.33.22 PM

PACKAGING & FORM FACTOR

Lyzr Studio, block, or the plane you adopt

No pricing here; this is a technical paper, and dollar tiers belong in the sales conversation. The question this section answers is structural: how does the control plane arrive, and can it govern agents you built somewhere else?

The Lyzr Control Plane is part of Lyzr Studio, and it is also available as a separate block. The stronger technical story is the second: framework-agnostic, drop-in governance over agents built anywhere. That is what ties it directly to the build-versus-govern distinction in Section 2. You do not need to have built inside Lyzr Studio to bring an agent under governance, the plane connects to what you already run.

Open source is the on-ramp, not a footnote

For a developer-credible audience, the way in is not a sales call; it is running the thing yourself. An open-source control plane is how a technical team adopts and builds confidence before any commercial engagement, and it is also the honest answer to the lock-in question this whole paper has to face. There is a tension a careful reader will notice: Section 1 warns against single points of dependency, and the paper’s ask is to adopt one governing layer. The resolution is that a framework- and model-agnostic control plane is the thing that prevents lock-in rather than creating it; but that only holds if the exit is real. It is: everything runs on open protocols in your own environment, the runtime keeps running wherever you take it, and there is no proprietary format or migration penalty on the way out. An adoption motion you can reverse is a fundamentally different commitment from one you cannot.

Deployment form factors

The genuinely technical packaging question is where it runs. The plane deploys to cloud, self-hosted, or on-premises and private environments, running inside the customer’s own boundary so data never leaves it, which is what the geopolitical thread of Section 1 demands for regulated and on-prem readers.

Screenshot 2026 07 23 at 7.34.55 PM

PROOF IN THE FIELD

Governance at scale, proven first

The proof that validates a control-plane thesis is not “we built agents for a big logo.” It is “the governance works, at scale, across frameworks.” The roster below leads with the deployments that prove that.

Enterprise logos answer “can Lyzr build?” The control-plane thesis needs the answer to “does the governance hold?”; so this section is sorted by what each deployment actually proves, not by brand recognition. The first tier is on-thesis: multi-agent control, auditability, framework-agnostic governance, production at scale.

Tier 1; Governance, proven

Screenshot 2026 07 23 at 7.36.07 PM
Screenshot 2026 07 23 at 7.36.25 PM
Screenshot 2026 07 23 at 7.36.45 PM

Tier 2: Production and metric proof

Screenshot 2026 07 23 at 7.37.20 PM

First-party and aggregate proof

The most on-thesis evidence is that Lyzr runs its own agents in production under its own control plane , CFO’s office, KYC pre-validation, dispute management, universal banking support , the “we run on the thing we sell” proof. And at aggregate, hundreds of tracked use cases span multiple frameworks, industries, and channels, demonstrating governance across a genuinely heterogeneous estate rather than a single showcase build.

Screenshot 2026 07 23 at 7.37.50 PM

THE LAYER THAT OUTLIVES THE MODEL

The models will keep moving. Ship anyway.

The argument of this paper is a single line: the model landscape will keep shifting , by export law, by sanction, by sovereign policy , and the control plane is the layer that lets you keep shipping agents to production regardless of which model is available, banned, or repriced this quarter.

Everything else followed from that. Build, add, and deploy are real jobs, but they are only safe when something governs them. The numbers a control plane can produce are the signal of maturity, because observing an agent and governing it are different acts. And the whole case rests on neutrality , framework-agnostic, model-agnostic, cloud-portable , because neutrality is exactly the property that survives a model going dark. A control plane that locks you in would fail its own thesis; one you can leave is the only kind worth adopting.

And for the reader who simply wants to see it work: run the open-source control plane yourself, today.

Move beyond demos.
Govern the fleet.

See how agents go from any framework to production through a single governed pipeline: with model control, evaluation, and identity built in. Or run the open-source control plane yourself and bring your own agents under governance.

Run the OSS Control Plane →
Book a technical walkthrough →

SOURCES

References

  1. Anthropic suspension of Fable 5 and Mythos 5 (Section 1). Anthropic, “Redeploying Fable 5.” anthropic.com/news/redeploying-fable-5↩
  2. Chinese-model cost savings of 60–90% (Section 1). CNBC, “Chinese AI models undercut U.S. rivals on cost,” 7 July 2026. cnbc.com↩
  3. US government evaluating restrictions; Congress investigating (Section 1). The Economic Times, citing Axios, “Trump administration may ban Chinese AI models.” economictimes.indiatimes.com↩
  4. Beijing’s tiered framework for overseas model access (Section 1). AI Weekly, “Beijing weighs curbing overseas access to top Chinese AI models.” aiweekly.co↩
  5. DeepSeek regulatory actions across jurisdictions (Section 1). The Hacker News, “South Korea suspends DeepSeek AI downloads.” thehackernews.com↩
  6. 42% of companies abandon most AI initiatives before production (Section 2). S&P Global Market Intelligence, Voice of the Enterprise: AI & Machine Learning 2025. spglobal.com↩
Build with Lyzr

Try it in
Agent Studio
today.

From framework-agnostic design to production-grade agents, deployed in under 24 hours.

The Future of Enterprise Infrastructure
By continuing, you agree to Lyzr's Terms of Service and Privacy Policy.