Every counterparty in a trade will happily mark its own book. That is precisely why you never let a counterparty be the arbiter of the position.
Why the Neutral-Arbiter Gap Matters Now
The model vendors are doing the responsible thing. Anthropic is shipping organization preferences and enterprise controls for Claude. Microsoft is building governance into Agent 365 and Copilot. Google is wiring policy into its Gemini and Vertex agents. OpenAI is adding admin controls around Operator and its enterprise agents. Each of these is rational, useful, and — this is the part that matters — structurally partial. A vendor governs the agents it ships, on the surfaces it controls, according to the telemetry it can see.
The problem is that no real enterprise runs a single-vendor agent estate. The median large organization is running Copilot in finance, Claude in engineering, Gemini in the Google-shop marketing team, and a fistful of custom Python agents on Bedrock in ops — plus whatever a citizen developer stood up last Tuesday. Each vendor marks its own book honestly. Nobody marks the portfolio. That un-netted exposure is where the incidents actually live.
This is not a coverage bug that a roadmap closes. It is a permanent property of walled gardens: a model vendor cannot be the neutral arbiter of a competitor’s agent, and none of them reach down to the endpoint where the agent actually touches a file. The gap is architectural, and it is widening as fast as adoption.
| Signal | Figure | Source |
|---|---|---|
| CIOs who have deployed AI agents / plan to within a year | 17% now, 42% within 12 mo. | Gartner CIO Survey |
| Agent incidents from internal violations (through 2028) | ≥80% | Gartner |
| Enterprises operating ungoverned agents in their estate | 88% | Ospiri research |
| Avg. cost delta of an ungoverned agent incident | +$670K | Ospiri research |
Four Honest Vendors, One Blind Portfolio
Take each vendor’s governance at its best and the gap is still there. The failure is not in any single control — it is in the space between them, the seams no participant is incentivized or architecturally able to see.
| Vendor governs | What it sees well | What it structurally cannot see |
|---|---|---|
| Microsoft (Copilot / Agent 365) | M365 agents, Graph API calls, tenant policy | Claude reading the same SharePoint file from a local disk |
| Anthropic (Claude enterprise) | Claude conversations, connector scopes | A Copilot agent exfiltrating to a personal OneDrive |
| Google (Gemini / Vertex) | Workspace + Vertex-hosted agents | A custom Bedrock agent spawning a local process |
| OpenAI (Operator / enterprise) | OpenAI-hosted sessions and tool calls | An MCP server wiring any of the above into your source tree |
| Custom (Bedrock / Python / OSS) | Whatever you instrument yourself | Everything you forgot to instrument |
Read the right-hand column top to bottom. Every line is a data-touching action on an endpoint that the responsible vendor is, by design, blind to — because it belongs to a competitor’s agent or to a local process below the SaaS API. The estate does not respect the SKU boundary. The risk pools in exactly the place no vendor owns.
The Anatomy of a Seam Incident
The dangerous incidents rarely happen inside one garden. They happen in the handoff. A recognizable pattern from the field:
- A Copilot-authored agent is published enterprise-wide and inherits the user’s full M365 OAuth scope.
- A developer, in a different tool entirely, points a local Claude or Cursor session at the same repository the agent’s output landed in.
- A citizen-built Python agent on Bedrock picks up that repo on a nightly schedule and writes a derived dataset to a shared drive.
- Nobody’s dashboard shows the chain — Microsoft saw step 1, Anthropic saw step 2, AWS saw step 3, and no one correlated the three into a single NPI-touching path.
Each vendor’s log is individually clean. The portfolio view — the only view that would have flagged the exposure — does not exist inside any garden. This is the multi-vendor equivalent of booking three offsetting trades in three systems and never computing net delta. Each desk looks flat. The firm is not.
Scoring the Exposure You Can’t See
You can put a number on this. The seam risk of a multi-vendor estate is not additive — it compounds with every un-correlated boundary, the way tail risk compounds with every uncorrelated position you can’t net.
Seam Exposure = (Number of Vendor Gardens × Cross-Garden Data Paths) + (Unmonitored Endpoints × Reversibility of Action)
| Factor | Low | High |
|---|---|---|
| Vendor gardens in estate | 1 platform | 4+ platforms, no shared control plane |
| Cross-garden data paths | Isolated workloads | Shared repos, drives, and datasets |
| Unmonitored endpoints | Managed, instrumented fleet | Contractor laptops, local MCP servers |
| Reversibility of action | Read-only, sandboxed | Irreversible writes to labeled data |
The point of the formula is not precision to the dollar — it is to move the conversation from “each vendor says they’ve got it covered” to “here are the four boundaries where no one does, ranked.” That is a position you can hedge. A pile of vendor assurances is not.
The Correlation Layer Is the Only Neutral Ground
If no participant can arbitrate the mix, the arbiter has to sit outside all of them — at the one layer every agent shares regardless of which garden it came from. That layer is the endpoint, and the control is one identity graph resolved down to the device and the action.
| What the neutral layer provides | Why a model vendor can’t |
|---|---|
| One identity graph across every vendor’s agents | Each vendor only authenticates its own |
| Kernel ground truth: process, file, label, action | SaaS APIs never see the local filesystem |
| Cross-garden correlation of a single data path | No vendor can subpoena a competitor’s telemetry |
| Enforcement that is in-line, not after-the-fact | Dashboards observe; they do not intervene |
This is not an argument against the model vendors’ controls — keep every one of them. It is an argument that the correlation and enforcement layer must be independent, because independence is the whole value. You would not accept a trade confirmation signed only by the counterparty. The same logic governs agents: the agent firewall is the neutral book that reconciles what every garden reports against what actually happened on disk. That is what makes multi-vendor agent governance provable rather than assumed.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Enumerate every model vendor with agents in the estate | Garden inventory | 1 day |
| 2 | Map cross-garden data paths (shared repos, drives, datasets) | Seam map | 1 week |
| 3 | Deploy endpoint correlation + enforcement across all gardens | Neutral control plane | 2–4 weeks |
| 4 | Reconcile each vendor’s log against kernel ground truth | Drift report for the board | Ongoing |
The Bottom Line
Every model vendor will govern its own agents, and none of them will ever govern the mix — that is not a gap that closes, it is the permanent shape of a walled garden. Real enterprises run the combination, and the incidents pool in the seams where each vendor is honestly, structurally blind. Treating four vendor assurances as one governance program is booking offsetting trades in four systems and calling the firm flat. The only durable arbiter is the layer every agent shares: the endpoint, with one identity graph resolved to the device, the file, and the action. Independence is not a nice-to-have here — it is the entire point of an arbiter.
If your team is sizing multi-vendor agent governance for the enterprise this fiscal year, request a working session. We will walk through your actual vendor mix, map the cross-garden data paths no single console can see, and scope a neutral enforcement deployment — 90 minutes to a seam map you can take to the board.