← All insights

Architecture guideLens: Global4 min read

What a production-ready enterprise AI stack actually needs in 2026

Five core layers, six cross-cutting controls and one owner: a field guide to what separates an enterprise AI system from a model and a prompt.

Listen to this article · 7 min

AI-generated narration of the full article.

Spiral staircase seen from above, in La Madre duotone, beside the words The 2026 stack
Photo: Ian Prince (StockSnap, CC0)

In September 2026, six of the largest enterprise AI platforms published announcements within a few weeks of each other: AWS and OpenAI, Microsoft, Google, Salesforce and Palantir. Read one at a time, they look like competing products. Read side by side, they describe the same thing: the parts of an AI system that have nothing to do with the model.

Every one of them is shipping some version of agent identity, permissions, action connectors, approval steps, audit trails, version control and an admin console. That convergence is the most useful signal of the year for anyone planning enterprise AI. It tells you what production actually requires, because the vendors have now paid to build it.

A model and a prompt is not a system

A prototype needs three things: a model, a prompt and some data. A system that a regulated enterprise will let run against its customers, employees or money needs a lot more, and most of it is invisible in a demo.

The map below is our synthesis of what repeatedly shows up in serious deployments and in the September announcements. It has five core layers, six controls that cut across all of them, and one layer that no vendor ships.

The La Madre stack map: five core layers, six cross-cutting controls, one owner.CORE LAYERSCROSS-CUTTING CONTROLSBusiness application & experienceAgent runtime: orchestration & stateTools, actions & integrationsEnterprise context: data & groundingModelsIdentity & authorizationPolicy & securityEvaluationHuman approvalObservability & auditLifecycle & deploymentOperating ownership: who is accountable after go-live

Core layers

  • Business application & experience
  • Agent runtime: orchestration & state
  • Tools, actions & integrations
  • Enterprise context: data & grounding
  • Models

Cross-cutting controls

  • Identity & authorization
  • Policy & security
  • Evaluation
  • Human approval
  • Observability & audit
  • Lifecycle & deployment
  • Operating ownership: who is accountable after go-live
The La Madre stack map: five core layers, six cross-cutting controls, one owner.

The five core layers

Business application and experience. Where people meet the system: a Teams channel, a document, a CRM screen, an internal app. If the AI lives in a separate tab, adoption is already harder.

Agent runtime. Orchestration, state and memory across steps. This is the layer that moved fastest in 2026. OpenAI now operates the harness behind its Agents API; AWS offers a managed runtime built on it; Microsoft runs Autopilot as a cloud-hosted agent with its own workspace.

Tools, actions and integrations. What the system can do, not just what it can read. Google’s September release notes list new preview actions across OneDrive, Outlook, SharePoint and Teams. Salesforce calls this layer “Trusted Action”.

Enterprise context. The data, documents, semantics and business definitions that ground answers. This is where your advantage lives, and where most of the unglamorous work sits: access, freshness, quality and meaning.

Models. Increasingly interchangeable and increasingly routed. Several platforms now pick a model per request, and Palantir’s AIP Evolve can propose migrating a workload to a different model after validating the change.

The six cross-cutting controls

These are the controls that decide whether a security or risk team signs off. What changed in 2026 is that platforms now expose them as first-class features.

Identity and authorization. Who is the agent acting as? AWS gives each managed agent its own IAM role. Microsoft describes Autopilot as living in the tenant with its own identity. Google added resource-level IAM for Gemini Enterprise apps and data stores on September 28.

Policy and security. Which connectors, endpoints and data sources are allowed. Microsoft’s Copilot Managed Runtime applies organizational policies for connectors, data access, approved endpoints and auditing to every hosted app.

Evaluation. How you know the system is good enough, and still good enough after a change. Palantir’s AIP Evolve validates proposed changes against test cases or existing evaluation suites before anything is merged. Without an evaluation suite, that kind of automation has nothing to check against.

Human approval. Where a person must say yes. AWS supports human approval before consequential actions. OpenAI’s computer use leaves website access approvals and sign-in to the customer’s application.

Observability and audit. What happened, and who can prove it. AWS records supported agent activity in CloudTrail. Microsoft centralizes inventory, usage and health in the Microsoft 365 admin center. Salesforce plans an AI Control Plane to register, observe and control agents across vendors.

Lifecycle and deployment. Versions, branches, rollbacks and retirement. Managed Runtime versions apps through Git. AIP Evolve routes proposals through branch review. Google now lets admins transfer ownership of shared agents, and disables their schedules until the new owner turns them back on.

The layer nobody ships: operating ownership

No platform can tell you who is accountable for an agent after go-live. That is an organizational decision, and it is the most common reason pilots stall.

Google’s ownership transfer feature is a small but telling symptom. It exists because agents outlive their creators: people change roles, contractors leave, and a scheduled agent keeps running. Someone has to own its purpose, its permissions, its evaluation results and its retirement.

Questions to ask before production

For any AI system you intend to run for real, you should be able to answer these in one sentence each:

  1. Who does the system act as, and with which permissions?
  2. Which data can it read, and which can it return or change?
  3. Which actions require a human, and who is that human?
  4. What evaluation proves it is good enough today, and who reruns it after a change?
  5. Where is the audit trail, and who can read it?
  6. How is it versioned, rolled back and retired?
  7. Who is accountable for it next quarter?

If the answer to any of them is “the platform handles it”, check what the platform actually documents. In most cases it handles the mechanism. The decision is still yours.

What this means

The model is the part of enterprise AI that improves on its own. Everything else on this map is the work of deciding how a system behaves inside your organization. Vendors are now shipping more of the machinery for that work, which is good news. It also makes the remaining decisions more visible, and harder to postpone.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case