Architecture · September 25, 2026 · 6 min read

Salesforce, SAP, UiPath and AWS all shipped the same layer this quarter. Nobody agrees on its name.

In September 2026, four unrelated companies landed a governed control layer between AI models and business systems — and a fifth dataset suggests that layer is where the ROI lives. The industry is converging on the missing middle of enterprise AI. Here's the map, without the vendor gloss.

Four announcements, one architecture

SAP (Q3, building on May's Sapphire launch): the AI Agent Hub — described at the Transformation Excellence Summit on September 22 as the foundation for enterprise-grade AI governance: "inventorying agents, large language models, and MCP servers across the enterprise, mapping them to capabilities and owners," with a new AI Governance Assistant embedding EU AI Act and NIST compliance intelligence and automating risk classification. Cloud ALM "tracks every agent action" in production. Governance as a system of record, for SAP estates.

Salesforce, September 10: the "Trusted Enterprise AI Harness" — the vendor that previously called this the "Open Customer 360" — six capabilities spanning context, agency, action, governance, security and models, plus an AI Control Plane: one place to register agents, set identity and policy, observe behavior and control cost, including for third-party models and agents. Notably headless: reachable via MCP and APIs into Claude, Slack, Teams — not only Salesforce surfaces.

UiPath, September 24 (FUSION 2026): Cartographer — mapping the process knowledge (rules, exceptions, judgment calls) that agents need — plus a control-plane batch: Model Hub (which models are in use), a Runtime Checker that validates agent behavior continuously while running, not just at build time, an LLM-as-Judge guardrail, and a Decision Ledger recording every human correction to agent output in live execution.

AWS, September 23–24 (HumanX): Swami Sivasubramanian, VP of agentic AI, described a feature in the open-source Strands framework that "puts an agent in a box" — a deterministic layer outside the agent that governs which tool calls it can make, and widens as the agent proves itself. Consolidation onto Bedrock + AgentCore was sold internally as "a single path approved by security."

Salesforce calls it a harness. UiPath calls it a control plane. AWS calls it a box. They are describing the same architectural fact: the model is a component, and the enterprise layer around it is the product.

The survey that explains why this is happening now

KPMG's Q3 Global AI Pulse (2,131 leaders, 20 countries, published September 24) gives the convergence a number: 55% of organizations now operate a formal "AI harness layer" — and among those reporting established AI ROI, it is 86%. At the experimentation stage, 31%. The correlation is not proof of causation, but it is the strongest evidence yet that the layer between models and business is where the pilot economy stalls or compounds. Same dataset: 72% now formally consider model sovereignty — where models, data and IP are hosted and governed — and 86% are reworking cybersecurity operating models for AI-accelerated threats.

Three ways this lands for a firm of 20–200 people

1. You do not need to pick a mega-suite to get the layer. The four announcements all aim at large installed bases (Salesforce customers with Data 360, UiPath shops with Maestro, SAP estates). A smaller firm buying governed access to frontier models is buying a subset — masked inputs, logged decisions, policy on model access, spend metering — and that subset can live in front of whatever models you use. If a vendor tries to sell the harness as a replatforming project, that's a tell.

2. Audit is becoming table stakes, not a premium module. UiPath's Runtime Checker, its Decision Ledger, AWS's deterministic box, Salesforce's control plane — every one of the four ships with "what happened, replayably" at the center. When regulators (or your biggest client's questionnaire) asks what your AI saw and said, the answer must come from the layer, not from someone's memory of the prompt.

3. The sovereignty conversation is now procurement's job. KPMG's 72%, and Denmark's DCAI/Corti launching a sovereign AI control layer on the Gefion supercomputer (August 20) with "recent disruptions in access to frontier models" as the stated motivation — model access is becoming a dependency to manage, like a data center region. Firms in the Gulf that treat "which jurisdiction does my inference cross" as a compliance checkbox will be ahead of the ones treating it as a sales question.

The unglamorous version

Strip the keynotes and the four announcements say: stop wiring frontier models directly to people and systems. Put something between them that checks identity, masks sensitive data, constrains actions, records outcomes and meters cost — and let the "harness" earn more freedom over time (AWS's widening box is the honest metaphor for that). Nobody in the room called it "the enterprise AI gateway," but that is what the shape on the whiteboard has always been.

The harness, without the replatforming.

Start free — $5 credits, no card