Every counterparty in a trade will happily mark its own book. That is precisely why you never let a counterparty be the arbiter of the position.

Why the Neutral-Arbiter Gap Matters Now

The model vendors are doing the responsible thing. Anthropic is shipping organization preferences and enterprise controls for Claude. Microsoft is building governance into Agent 365 and Copilot. Google is wiring policy into its Gemini and Vertex agents. OpenAI is adding admin controls around Operator and its enterprise agents. Each of these is rational, useful, and — this is the part that matters — structurally partial. A vendor governs the agents it ships, on the surfaces it controls, according to the telemetry it can see.

The problem is that no real enterprise runs a single-vendor agent estate. The median large organization is running Copilot in finance, Claude in engineering, Gemini in the Google-shop marketing team, and a fistful of custom Python agents on Bedrock in ops — plus whatever a citizen developer stood up last Tuesday. Each vendor marks its own book honestly. Nobody marks the portfolio. That un-netted exposure is where the incidents actually live.

This is not a coverage bug that a roadmap closes. It is a permanent property of walled gardens: a model vendor cannot be the neutral arbiter of a competitor’s agent, and none of them reach down to the endpoint where the agent actually touches a file. The gap is architectural, and it is widening as fast as adoption.

Signal Figure Source
CIOs who have deployed AI agents / plan to within a year 17% now, 42% within 12 mo. Gartner CIO Survey
Agent incidents from internal violations (through 2028) ≥80% Gartner
Enterprises operating ungoverned agents in their estate 88% Ospiri research
Avg. cost delta of an ungoverned agent incident +$670K Ospiri research

Four Honest Vendors, One Blind Portfolio

Take each vendor’s governance at its best and the gap is still there. The failure is not in any single control — it is in the space between them, the seams no participant is incentivized or architecturally able to see.

Vendor governs What it sees well What it structurally cannot see
Microsoft (Copilot / Agent 365) M365 agents, Graph API calls, tenant policy Claude reading the same SharePoint file from a local disk
Anthropic (Claude enterprise) Claude conversations, connector scopes A Copilot agent exfiltrating to a personal OneDrive
Google (Gemini / Vertex) Workspace + Vertex-hosted agents A custom Bedrock agent spawning a local process
OpenAI (Operator / enterprise) OpenAI-hosted sessions and tool calls An MCP server wiring any of the above into your source tree
Custom (Bedrock / Python / OSS) Whatever you instrument yourself Everything you forgot to instrument

Read the right-hand column top to bottom. Every line is a data-touching action on an endpoint that the responsible vendor is, by design, blind to — because it belongs to a competitor’s agent or to a local process below the SaaS API. The estate does not respect the SKU boundary. The risk pools in exactly the place no vendor owns.

The Anatomy of a Seam Incident

The dangerous incidents rarely happen inside one garden. They happen in the handoff. A recognizable pattern from the field:

  1. A Copilot-authored agent is published enterprise-wide and inherits the user’s full M365 OAuth scope.
  2. A developer, in a different tool entirely, points a local Claude or Cursor session at the same repository the agent’s output landed in.
  3. A citizen-built Python agent on Bedrock picks up that repo on a nightly schedule and writes a derived dataset to a shared drive.
  4. Nobody’s dashboard shows the chain — Microsoft saw step 1, Anthropic saw step 2, AWS saw step 3, and no one correlated the three into a single NPI-touching path.

Each vendor’s log is individually clean. The portfolio view — the only view that would have flagged the exposure — does not exist inside any garden. This is the multi-vendor equivalent of booking three offsetting trades in three systems and never computing net delta. Each desk looks flat. The firm is not.

Scoring the Exposure You Can’t See

You can put a number on this. The seam risk of a multi-vendor estate is not additive — it compounds with every un-correlated boundary, the way tail risk compounds with every uncorrelated position you can’t net.

Seam Exposure = (Number of Vendor Gardens × Cross-Garden Data Paths) + (Unmonitored Endpoints × Reversibility of Action)

Factor Low High
Vendor gardens in estate 1 platform 4+ platforms, no shared control plane
Cross-garden data paths Isolated workloads Shared repos, drives, and datasets
Unmonitored endpoints Managed, instrumented fleet Contractor laptops, local MCP servers
Reversibility of action Read-only, sandboxed Irreversible writes to labeled data

The point of the formula is not precision to the dollar — it is to move the conversation from “each vendor says they’ve got it covered” to “here are the four boundaries where no one does, ranked.” That is a position you can hedge. A pile of vendor assurances is not.

The Correlation Layer Is the Only Neutral Ground

If no participant can arbitrate the mix, the arbiter has to sit outside all of them — at the one layer every agent shares regardless of which garden it came from. That layer is the endpoint, and the control is one identity graph resolved down to the device and the action.

What the neutral layer provides Why a model vendor can’t
One identity graph across every vendor’s agents Each vendor only authenticates its own
Kernel ground truth: process, file, label, action SaaS APIs never see the local filesystem
Cross-garden correlation of a single data path No vendor can subpoena a competitor’s telemetry
Enforcement that is in-line, not after-the-fact Dashboards observe; they do not intervene

This is not an argument against the model vendors’ controls — keep every one of them. It is an argument that the correlation and enforcement layer must be independent, because independence is the whole value. You would not accept a trade confirmation signed only by the counterparty. The same logic governs agents: the agent firewall is the neutral book that reconciles what every garden reports against what actually happened on disk. That is what makes multi-vendor agent governance provable rather than assumed.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Enumerate every model vendor with agents in the estate Garden inventory 1 day
2 Map cross-garden data paths (shared repos, drives, datasets) Seam map 1 week
3 Deploy endpoint correlation + enforcement across all gardens Neutral control plane 2–4 weeks
4 Reconcile each vendor’s log against kernel ground truth Drift report for the board Ongoing

The Bottom Line

Every model vendor will govern its own agents, and none of them will ever govern the mix — that is not a gap that closes, it is the permanent shape of a walled garden. Real enterprises run the combination, and the incidents pool in the seams where each vendor is honestly, structurally blind. Treating four vendor assurances as one governance program is booking offsetting trades in four systems and calling the firm flat. The only durable arbiter is the layer every agent shares: the endpoint, with one identity graph resolved to the device, the file, and the action. Independence is not a nice-to-have here — it is the entire point of an arbiter.

If your team is sizing multi-vendor agent governance for the enterprise this fiscal year, request a working session. We will walk through your actual vendor mix, map the cross-garden data paths no single console can see, and scope a neutral enforcement deployment — 90 minutes to a seam map you can take to the board.