Foraging: Game of Planes
Foraging: Game of Planes

Three conferences opened in the first week of June. Microsoft Build in San Francisco. Snowflake Summit, also in San Francisco. Salesforce Connections in Chicago. Three stages, three keynotes, three sets of slides. And all three companies, without any public coordination, announced the same product category using the same two words: control plane.

Snowflake CEO Sridhar Ramaswamy opened his keynote by positioning Snowflake as "the agentic control plane." Salesforce had already used the phrase in April when it announced Agent Fabric as a "trusted agent control plane for the multi-vendor AI landscape." Microsoft Build showcased Agent 365 as a "unified control plane for managing, securing, and governing AI agents." Box, Ramp, and ServiceNow made structurally identical moves the same week.

Six vendors, one phrase, zero coordination.

Something shifted in the first week of June. And it tells us more about where enterprise AI is heading than any model benchmark.

The Middle Layer

The model layer is commoditizing. That is no longer a controversial claim. GPT-5.5 went generally available in Microsoft Foundry the same week a Chinese open-source model beat it on Humanity's Last Exam. When the frontier moves that fast, betting on model superiority is betting on a lead that shrinks by the quarter.

What these six vendors are really betting on is the layer above the models: the governance, orchestration, routing, and context infrastructure that determines which agent does what, with whose data, under whose rules. The control plane.

Each vendor arrived at the same architectural conclusion from a different starting point. And the starting point is what makes this interesting.

Salesforce staked its claim on CRM data and MuleSoft's API fabric. Their Agent Fabric scans and governs agents across Amazon Bedrock, Microsoft Foundry, and any MCP-compatible server. The target is the rules layer: governance and orchestration above the model and the agent runtime. Marc Benioff put it directly at TDX: "Our API is the UI." The entire Salesforce platform, now exposed as APIs, MCP, and CLI, becomes the substrate that agents operate on.

Microsoft anchored its play in identity and the productivity graph. Agent 365 inherits everything from Entra ID, Microsoft Graph, Teams, and Fabric. If your company already runs on Microsoft, your agents inherit those permissions, those org charts, those data flows. Windows itself is becoming, in Saanya Ojha's framing, the "DirectX for AI": a runtime that shapes what agents can see, touch, and modify.

Snowflake built its version on the enterprise data warehouse. Their new Cortex Sense feature automatically builds shared context from the data, business definitions, and operational knowledge that agents need to be useful. CoCo, their autonomous coding agent, now runs on desktop, mobile, Slack, and as a Claude Code plugin. The acquisition of Natoma, an agent governance startup, signals the intent: the data platform itself becomes the trust boundary.

Ramp went vertical with financial data. They just raised $750 million at a $44 billion valuation, tripling in a year, with token spend management as one of the growth drivers. Ramp Stack, launched the day before the raise, is an AI operating system for accounting firms. Geoff Charles, Ramp's CPO, put it simply: "Firms aren't asking for another AI tool to prompt. They need something that actually does the work."

Box chose content and permissions as its moat. Aaron Levie called this "the first year where agents in the enterprise become practical." Box AI Studio lets admins build custom agents (Legal Reviewer, Brand Steward) per workflow, choosing their own foundation model. Box Automate orchestrates content-centric workflows. When your unstructured data carries permissions, the permission layer becomes the control plane.

And ServiceNow built the kill switch. Their AI Control Tower is an "observe, govern, secure" layer for enterprise agents. Fortune's headline framed the product pitch as a problem: "Your company's AI could delete everything in 9 seconds."

The Data Plane

Here is the pattern worth naming. Every vendor's control plane maps to the data asset they already own.

Salesforce owns the customer record. Microsoft owns the identity graph. Snowflake owns the analytical data. Ramp owns the spend ledger. Box owns the content corpus. ServiceNow owns the IT workflow. Each of them is making the same argument: the data gravity well you already orbit is where the agents should live.

This is a classic platform dynamics play, and the June conferences weren't even the first move. Google Cloud made a structurally identical bet at Next in April, launching the Gemini Enterprise Agent Platform with Agent Identity, Agent Gateway, and Agent Registry as core governance infrastructure. Bain published an analysis of that event titled "The Agentic Enterprise Control Plane Comes into View." Their thesis: the company that owns the control plane owns the customer relationship for the next decade. Futurum called it "one of the industry's most aggressive attempts to establish a universal enterprise AI control plane."

The numbers beneath the pitch are sobering. Salesforce's 2026 Connectivity Report found organizations now average 12 agents, and half of them operate in silos. Gartner projects 40% of agentic AI projects will fail by 2027 because governance hasn't kept pace.

I build content infrastructure at Typeface, where the interaction between AI agents and enterprise data is the whole product surface. What I see from the inside tracks what these announcements reveal from the outside: the constraint on enterprise AI is organizational trust infrastructure. Who can see what, who approved what, and who's accountable when the agent does something wrong.

I wrote earlier this year about permission lock-in: the idea that AI vendor lock-in lives in the accumulated decisions, permissions, and organizational knowledge embedded in how you use the platform. Every control plane announcement this week validates that thesis. The lock-in is the governance layer you can't migrate.

The Talent Plane

If you're a product or marketing leader reading this, the control plane war is also a talent war. Every vendor can ship the governance layer. The people who can wire it into an actual organization are scarce.

The control plane thesis has a gap. It assumes the organizational plumbing is ready. Most of it isn't. As one practitioner put it this week, the operating model is the bottleneck, and missing from the agentic literature are the power dynamics and trust workstreams that actually live on leaders' calendars. You can build the control plane. If the org chart doesn't match the agent topology, the control plane governs nothing.

Andrew Ng sees the same gap from the hiring side. The Forward Deployed Engineer role, pioneered by Palantir and now resurgent at OpenAI and Anthropic, exists because someone needs to bridge the gap between the platform and the organization. Ng predicts the role will fragment into LLMOps, Evals, and Harness Engineers. The people who understand both the technology layer and the organizational layer, who can translate agent topology into org design, are about to become the most valuable hires in enterprise software.

Salesforce's own engineering philosophy reflects this tension. They call it "guided determinism": fixed handoff rules between agents with LLM reasoning operating within those guardrails. The deterministic layer sits on the outside. The probabilistic intelligence operates within. It's an explicit admission that fully autonomous multi-agent orchestration isn't enterprise-ready. The humans set the rails. The agents ride them.

The multiplayer problem I wrote about last month is the same problem in different clothes. Individual AI productivity is real. Organizational compounding requires shared infrastructure. And shared infrastructure requires something no vendor can ship: agreement about who's in charge, what matters, and which agents get to act without asking. That's an org design problem wearing a technology costume.

The Odd Find

A Numerator study on consumer AI adoption found something that breaks every model we have for technology diffusion. A 25-year-old and a 65-year-old are equally likely to sit anywhere on the AI adoption spectrum. PCs, social media, and smartphones all skewed young. AI is the first major technology in decades where age doesn't predict adoption tier. The early-adopter playbook that governed technology marketing since the 1990s may not apply to the thing everyone assumed would follow it most closely.

Six vendors in one week, each claiming the control plane, each building it on top of the data they already own. The convergence is real. The question it raises is whether any single vendor can govern a landscape where the agents span all six data gravity wells at once.

The answer, most likely, is that they can't. And the organizations in the middle, the ones running 12 agents across 4 vendors, will spend the next two years building the governance layer themselves. Not because the platforms failed. Because the platforms all succeeded, in six different directions at once.