ANALYSIS The agentic AI stack is splitting into three distinct layers, and the seam that matters most right now is the one nobody ships as a finished product: the control plane that decides whether an agent's proposed action is actually permitted. Across hyperscaler launches, framework releases, and protocol milestones, the industry is converging on a shared anatomy for autonomous agents while leaving the authority layer underbuilt.
Why it matters
Enterprises face an 80-point gap between experimentation and production: Cisco RSA 2026 data shows 85% of customers experimenting with agentic AI but only 5% in production2. ◆ That gap is not primarily a model problem or a tooling problem; it is an architectural problem rooted in the absence of a unified layer governing routing, state, permissions, and recovery across heterogeneous agent deployments.
The big picture
The industry has reached consensus on what an agent needs to run: shell access, file manipulation, web tools, and long-term memory3. AWS, DigitalOcean, and Aiven shipped agent harnesses in the same week that LangChain Interrupt 2026 in New York City confirmed the same pattern at the framework layer. The harness, as defined by OpenAI's Codex platform post of August 19, 2026, manages conversation state, streams execution, uses tools, enforces sandbox and approval policies, and carries work across turns5. Anthropic's Claude Agent SDK exposes "the same tools, agent loop, and context management that power Claude Code"6. Microsoft Agent Framework reached 1.0 GA in April 2026. DeepSeek released DeepSeek Harness v0.1 on August 13, 2026, under the MIT license.
Below the harness sits the protocol layer. Model Context Protocol, which began at Anthropic in late 2024, now records 500 million monthly downloads of its tier-1 SDKs and more than 1 billion MCP tool calls through the Claude platform alone, according to co-creator David Soria Parra, who told a keynote audience in Amsterdam, "I think MCP today is in a pretty reasonable spot"4. The protocol was donated to the Linux Foundation's Agentic AI Foundation in December, and less than a quarter of its more than 40 maintainers work at Anthropic.
ANALYSIS What sits above both layers is less settled. The control plane, the system that answers whether a given action is authorized for a given principal in a given context, remains fragmented.
Between the lines
The distinction between capability and authority is the crux. As one technical analysis put it: "An LLM has a capability when it can select a tool and produce arguments. It has authority only when a separately enforced policy permits a bounded action for an identified principal in the current context"7. Schema validation confirms well-formed input; authentication confirms who presented a request; a tool definition tells the model what it can ask for. "None of these things establish that the current principal may cancel that specific subscription that the user meant, that account, or that the cancellation actually took effect".
AWS Bedrock AgentCore, which reached general availability in June 2026, offers a managed agent loop with configuration-driven definitions and isolated microVMs per session. ANALYSIS Yet it remains, as industry analysis notes, a vendor-walled ecosystem prioritizing internal consistency over the heterogeneous interoperability enterprises demand. The meta-orchestration layer that must unify MCP, Agent-to-Agent communication, identity frameworks, sandbox lifecycles, and execution governance "simply does not exist as a cohesive product or standard".
LangChain is attacking the problem from the framework side. LangSmith Engine monitors production data, clusters failures into named issues, and diagnoses root causes against the developer's codebase. LangSmith Sandboxes use hardware-virtualized microVMs with a p50 spin-up time under 0.98 seconds and are now generally available. LangChain is also partnering with Elastic, MongoDB, Pinecone, and Redis to push for an open memory standard. ◆ These moves pull control-plane responsibilities (observability, sandboxing, memory governance) into the framework layer, blurring the boundary that the three-layer taxonomy attempts to draw.
Practitioners are building their own answers. One developer's open-source control plane for coding agents separates task and risk routing from retrieval routing, context assembly, structural analysis, execution, and verification, emitting a "bounded orchestration contract" that caps agent-slot limits, graph depth, review passes, and verification passes8. Retrieval ends in one of three states: sufficient, requires_exploration, or abstain, and weak evidence can prevent an agent from editing prematurely. ◆ This bottom-up pattern mirrors the top-down vendor efforts but enforces authority through deterministic contracts rather than platform-managed policies.
What's next
MCP's governance trajectory under the Agentic AI Foundation will shape whether the protocol layer absorbs identity and authorization or leaves that to the control plane above it. AAIF head Mazin Gilbert stated that "you cannot deploy agentic applications at scale without MCP" and that the protocol needs to become "a central part of every deployment". ◆ If MCP expands to cover identity and execution governance, it compresses the space available for standalone control-plane products; if it stays narrow, the control plane becomes the most contested layer in the stack. MCP co-creator Soria Parra cited 500 million monthly SDK downloads and more than 1 billion tool calls, numbers that give the foundation leverage to set terms for whatever the protocol becomes next.