
Summary: Seventy-four percent of organisations plan to adopt agentic AI within two years. Only 21% have a mature model for governing it. Gartner's own research now confirms why that gap is dangerous: applying uniform, binary governance across every AI agent, rather than calibrating control to what each agent is actually authorised to do, is the leading cause of enterprise AI agent failure. This paper proposes the AI Control Stack, an 18-map, six-tier enterprise AI governance framework built on a single governing principle: design the control plane before granting autonomy.
In brief: Most AI programmes are still built the way conventional software was, starting with model selection, prompt engineering, and orchestration tooling, and treating governance as a deployment checklist. Autonomous AI breaks that assumption. An agent doesn't just execute code, it interprets intent, retrieves enterprise knowledge, invokes tools, spends compute, and increasingly acts without waiting for a human. The AI Control Stack reorganises enterprise AI around six architectural tiers, Intent, Authority, Knowledge, Connected Architecture, Operational Excellence, and a Control Plane that runs through all of them, so that autonomy is earned through governance rather than assumed through technology.
In This Article:
- The architecture gap enterprise AI has quietly created
- Why intelligence architecture is a different discipline from software architecture
- The six tiers of the AI Control Stack, one by one
- What Gartner, the EU AI Act, and Singapore's new framework all confirm about this approach
- A new definition of AI maturity
- Where to start
The architecture gap enterprise AI has quietly created
Enterprise conversations about AI have become sophisticated fast. Multi-agent systems, retrieval-augmented generation, reasoning models, and cognitive automation now come up in board meetings with real confidence behind them. One observation keeps surfacing underneath that confidence, though, across industries and company sizes alike: the technology is advancing considerably faster than the AI agent governance responsible for it.
Most AI programmes still start with the software-engineering playbook: selecting a model, evaluating cloud platforms, building prompts, integrating a vector database, experimenting with an orchestration framework. Each of those steps matters. None of them answer the questions that actually determine whether an AI capability can be trusted in production:
- Who authorised the agent to make this particular decision?
- Which policy governs its behaviour?
- Can every response be traced to its original source?
- What happens if the underlying model changes overnight?
- Who is accountable when an autonomous agent causes financial or operational harm?
Traditional enterprise architecture gives only partial answers, because it was built for deterministic systems. Conventional software executes predefined logic. Autonomous AI continuously evaluates context, generates new outcomes, adapts its own behaviour, and interacts dynamically with its environment. That's not a technology evolution. It's an architectural one.
The evidence backs up how unresolved this still is. By April 2026, 65% of enterprises with deployed AI agents had experienced a confirmed security incident. A Cloud Security Alliance and Token Security study found that 63% of organisations cannot enforce purpose limitations on their AI agents at all, and 60% cannot terminate a misbehaving agent once it's running. Regulators have noticed too: under the EU AI Act, penalties for prohibited AI practices reach up to €35 million or 7% of global annual turnover, whichever is higher, and most multi-step autonomous agents now fall under its "high-risk" classification.

From software architecture to intelligence architecture
Enterprise architecture has always existed to give structure to complexity, organising technology into applications, services, infrastructure, security, integration, and data. Those disciplines remain necessary. They no longer capture the full operational reality of an autonomous system.
An AI capability introduces genuinely new architectural responsibilities. It has to understand business intent before it acts. It needs access to trusted knowledge while respecting privacy and regulatory constraints. It invokes tools on a user's behalf, collaborates with other agents, reasons through ambiguity, and continuously absorbs changing organisational context. Unlike conventional software, an autonomous system generates operational risk through the decisions it makes, not just through the code that runs it.
That's the shift the AI Control Stack is built around: enterprise architecture has to evolve from managing applications to governing intelligence itself, treating decision authority, explainability, lifecycle governance, economic accountability, operational resilience, and trust as first-class architectural concerns, not implementation details filled in after the fact.
The six tiers of the AI Control Stack
The AI Control Stack isn't built to replace existing enterprise architecture frameworks. It extends them, adding the specific architectural capabilities that governed autonomy actually requires: six interconnected tiers, spanning 18 architectural maps, with a Control Plane running vertically through every one of them, continuously enforcing policy, protection, assurance, and accountability.
Tier 1: Architecture begins with intent, not technology
The first tier deliberately avoids technology altogether. AI programmes fail disproportionately often because organisations mistake activity for purpose, and a convincing demo can create the illusion of business value that isn't actually there.
Every AI capability needs a clear articulation of the business problem it exists to solve. Leadership needs to define the measurable outcomes, revenue growth, efficiency, customer experience, compliance, risk reduction, that justify continued investment, before implementation starts, not after.
Tier 2: Autonomy demands explicit authority
The defining trait of autonomous AI is that it can act without waiting for a human instruction. That capability introduces an entirely new architectural question: authority.
Some decisions should stay exclusively human. Others need approval under specific circumstances. Routine operational actions may eventually earn full autonomy. What matters is that these boundaries are never allowed to emerge accidentally through prompt engineering or scattered application code. They need to be designed intentionally and documented as enterprise architecture, because without explicit constraints, autonomy reliably expands beyond whatever it was originally scoped for.
Tier 3: Intelligence depends on trusted knowledge
A large language model has no organisational memory of its own. It depends entirely on the quality of what it's given, which makes enterprise knowledge architecture one of the most consequential parts of the whole framework.
Every AI response should be explainable through sources whose lineage, freshness, ownership, and access permissions are fully understood. Organisations need repeatable architectural blueprints standardising prompt orchestration, model routing, retrieval strategy, evaluation, and deployment. Unlike traditional software, AI capability keeps evolving after deployment, so versioning, regression testing, drift monitoring, rollback, and retirement planning become continuous architectural responsibilities, not operational afterthoughts.
Tier 4: Connected intelligence requires connected architecture
No enterprise AI system runs in isolation. Modern agents pull from knowledge repositories, call APIs, update transactional systems, talk to external services, and increasingly coordinate across multiple specialised models.
Every integration adds capability while also adding operational complexity. Foundation models, embedding providers, third-party plugins, SaaS platforms, vector databases, and orchestration frameworks together form an AI supply chain whose resilience directly shapes organisational stability. Understanding those dependencies matters as much now as understanding application dependencies did in the previous generation of enterprise architecture.
Tier 5: Operational excellence defines whether it lasts
Plenty of organisations celebrate a successful AI deployment. Far fewer invest equally in operating it responsibly for the months and years afterwards.
Observability has to extend beyond infrastructure metrics to cover prompts, reasoning paths, tool invocations, cost, latency, policy violations, and decision history. Financial governance becomes AI FinOps, where every inference carries a measurable economic cost. Human interaction architecture has to guarantee explainability and intervention pathways, and resilience architecture has to allow graceful degradation, because failures are not a possibility to plan around. They're a certainty.
Tier 6: The Control Plane, where governance becomes engineering
The most significant part of the AI Control Stack is how it treats governance. Rather than bolting governance on as a final deployment checklist, the framework embeds it directly into the architecture through a dedicated Control Plane that continuously evaluates policy, compliance, security, assurance, approvals, operational controls, and accountability across every one of the other five tiers.
The shift this creates is simple to state and hard to achieve:
- Policies become executable instead of documented.
- Security becomes contextual instead of static.
- Trust becomes measurable instead of assumed.
- Accountability becomes explicit instead of implied.
Governance stops being documentation and becomes engineering.
What Gartner, the EU AI Act, and Singapore's new framework all confirm
This is where independent research now backs the framework's central design choice directly, and not from just one source.
Gartner's May 2026 research on enterprise AI agent governance found that applying a uniform governance strategy across every agent is itself the leading cause of enterprise AI agent failure, and predicts that by 2027, 40% of companies will decommission agents specifically because their technical teams never distinguished between what an agent is able to do and what it's actually authorised to do. Gartner's own recommendation, tiered controls calibrated to an agent's autonomy level and trust boundary rather than a binary locked-down-or-fully-trusted approach, is functionally the same argument the Authority tier makes here.
Two other independent bodies reached the same conclusion in parallel. Singapore's IMDA published the world's first Model AI Governance Framework specifically designed for agentic AI at Davos in January 2026, structured around risk-proportional oversight calibrated to what each agent is actually authorised to do, not a one-size-fits-all policy. The World Economic Forum's own agent governance framework makes the identical point: governance levels must be dynamically calibrated to agent autonomy and authority in real time, rather than applied as static checkboxes.
Three separate bodies, a research analyst, a national regulator, and a global policy forum, arriving at the same architectural conclusion independently is not a coincidence worth glossing over. It's confirmation that treating governance as binary, rather than tiered to autonomy and trust boundary, is precisely the failure mode a Control Plane is built to prevent.
A new measure of AI maturity
Organisations have historically measured AI maturity by model sophistication: biggest context window, newest architecture, most capable reasoning. A more meaningful measure is governance maturity.
The most advanced organisations are not necessarily the ones deploying the largest models. They're the ones capable of operating autonomous intelligence within clearly defined architectural boundaries, backed by measurable value, enforceable controls, transparent operations, and named accountability. In this model, maturity reflects organisational discipline, not technological novelty, and the returns on that discipline are already visible in the data. Organisations with fully integrated AI governance are roughly ten times more likely to pass an independent governance audit, and nearly four times more likely to report revenue growth from their AI investment. Separately, companies with dedicated governance tooling are already pushing production deployments at roughly 12 times the rate of those without it, in a governance tooling market itself projected to reach $3.4 billion in 2026.
Conclusion: design the control plane before granting autonomy
Enterprise AI is one of the most significant architectural transitions since the emergence of cloud computing, and its defining challenge was never intelligence. It's control.
The organisations that succeed over the next decade won't simply build more capable AI systems. They'll build systems whose autonomy is earned through governance rather than assumed through technology, because the technology alone will keep getting more capable regardless of what any single enterprise does. The governance around it will not improve on its own.
The AI Control Stack is one blueprint for closing that gap. Its purpose isn't to constrain innovation. It's to make innovation sustainable, because in enterprise AI, architecture is no longer just about building systems. It's about governing intelligence, and that begins with a simple principle every enterprise architect, CTO, and AI leader should hold onto: design the control plane before granting autonomy.
If your organisation is scaling agentic AI and the governance model hasn't kept pace, talk to Tarento's Generative & Agentic AI team about what a Control Plane looks like for your specific architecture.

