OguzhanTekin
The AI Stack Is Being Rebundled Around Control and Outcomes
FinOps & Cloud StrategyAugust 30, 2026

The AI Stack Is Being Rebundled Around Control and Outcomes

By Oguzhan TekinBack to Blog

An AI agent can complete every technical step and still produce the wrong result.

The model responds. The tool executes. The workflow closes. The infrastructure reports success.

But the agent may have used outdated information, exceeded its authority, violated policy, or created work that a person must correct later.

This silent gap between technical completion and an acceptable business outcome explains why the AI stack is changing.

A useful AI system depends on much more than a model. It needs compute, data, retrieval, tools, permissions, evaluation, monitoring, security, and an application that produces a real result.

These capabilities are not disappearing into one giant platform. They are being rebundled around the places where organizations make important decisions: what to deploy, which provider to use, what an agent may do, whether it can be trusted, and whether the result justifies the full cost.

Across the stack sits the control plane: the capabilities used to evaluate, govern, secure, monitor, and approve AI systems.

The question isn't which layer wins. It's who controls the evidence used to decide what runs.

Four Planes, One Agent, and an Outcome

The stack can be understood through four operating planes, plus the application that runs on them and the outcome it produces.

The capacity plane includes power, data centers, chips, networking, storage, and cloud infrastructure.

The intelligence plane includes foundation models, specialized models, embeddings, inference services, and model routing.

The context-and-action plane connects models to enterprise data, retrieval systems, APIs, databases, and tools.

The control plane cuts across the stack. It includes evaluation, observability, identity, permissions, security, cost attribution, versioning, release controls, and audit records. It governs the application and judges whether its result is correct, authorized, policy-compliant, and worth the full cost.

The application — or agent — is the actor. It runs on the capacity, intelligence, and context-and-action planes to perform the workflow.

The outcome is the result: a support case resolved, a claim processed, a fault detected, or a refund correctly approved.

The three enabling planes make the application possible. The application produces the outcome. The control plane wraps around both, determining whether the agent and its result can be trusted.

Diagram of the four-plane AI stack: capacity, intelligence, and context-and-action enable the application or agent, which produces an outcome; the control plane wraps around the agent and outcome, judging whether the result is correct, authorized, in policy, and worth the cost.
The three enabling planes make AI possible. The application runs on them to produce an outcome — and the control plane wraps around the agent and its result, judging whether it is correct, in policy, and worth its full cost.

Agents Make Control Part of the Product

A conventional application usually fails in a visible way. An endpoint is unavailable. A query fails. A transaction times out.

An agent can fail while every component appears to be working.

Production AI therefore needs more than operational telemetry. Teams need to know whether the system ran, whether it performed the task correctly, whether it remained within its authorized and policy-compliant boundaries, and whether the result was worth the full cost.

That requires four kinds of evidence: operational, quality, security and governance, and economic.

A trace can show what happened. It cannot decide whether the result was acceptable.

That decision requires business criteria, security policy, evaluation data, and someone accountable for the outcome. This lifecycle approach also aligns with NIST's guidance on AI monitoring, documentation, risk management, and human oversight.

Open Standards Help, but They Do Not Create Trust

MCP standardizes an important part of how AI applications connect to tools and external data. OpenTelemetry provides common conventions for recording application and AI-system activity.

These standards reduce integration friction, but they do not create automatic portability or trust.

MCP is not a universal identity, authorization, governance, or model-portability standard. OpenTelemetry's generative-AI conventions are still evolving, so organizations should version their telemetry mappings.

Two models can support the same API and still differ in quality, latency, safety behavior, contractual terms, regional availability, and tool-use reliability.

MCP improves connections. OpenTelemetry improves visibility. Neither decides whether an agent should access a customer record, whether an action requires approval, or whether a cheaper configuration preserves quality.

Follow the Acquisitions — Carefully

Acquisition activity reveals what large buyers consider strategically useful.

CoreWeave completed its acquisition of Weights & Biases in May 2025. Multiple reports valued the transaction at approximately $1.7 billion, although CoreWeave did not publicly disclose the purchase price.

ClickHouse acquired Langfuse in January 2026, adding AI observability and evaluation to its data platform. Cisco completed its acquisition of Galileo in May 2026, adding similar capabilities to its broader portfolio.

Dynatrace later agreed to acquire Arize for $915 million, subject to closing conditions. Stripe agreed to acquire OpenRouter, extending its business into model-gateway capabilities, token routing, and usage optimization.

These transactions can be understood as product expansion. They also show where buyers seek influence over AI deployment decisions, workload routing, operational evidence, and economic flows.

A platform that measures performance, governs releases, or routes demand can strengthen the buyer's existing cloud, database, security, or payments business.

This does not prove that every specialist will be acquired. It shows that the systems surrounding AI deployment decisions are becoming strategically important.

Integration Creates Convenience and Incentives

Integrated platforms can reduce implementation time and bring cost, quality, security, and operational data together.

But integration also changes incentives.

A cloud provider benefits when workloads remain on its infrastructure. A model provider benefits from more model calls. A gateway benefits from routed traffic. An observability company benefits from retained telemetry.

These incentives do not make their tools untrustworthy. They mean customers should preserve the ability to test important claims independently.

The practical goal is controlled replaceability: the ability to test and replace components that materially affect quality, cost, risk, or strategic dependence without designing the entire system around constant switching.

The AI Bill Is Not the Cost of the Outcome

Tokens explain one component of an AI bill. They do not show whether the system created value, followed policy, remained within its authority, or transferred hidden costs to employees, customers, or security teams.

A lower-priced model may require more retries, invoke expensive tools unnecessarily, or create more work for human reviewers. An agent may complete a task at a low visible cost while exposing sensitive data or creating an incident.

That is not a low-cost outcome. It is an incomplete cost calculation.

I previously explored this problem in Why AI Security Is Becoming a New FinOps Cost Layer, where I argued that the recurring controls required to operate an agent safely belong in its operating cost.

For lower-risk systems, a useful measure is:

Cost per successful outcome = total attributable workflow cost ÷ verified successful outcomes

For agents that access sensitive data, execute consequential actions, or operate in regulated environments, the stronger measure is:

Cost per verified, policy-compliant outcome =
(AI service costs + allocated control costs + remediation costs) ÷ qualifying outcomes

Consider an illustrative refund agent handling 1,000 requests.

Its visible model and tool charges are only $420 — or $0.42 per request. That appears inexpensive.

But retries and human review add $480. The agent's allocated share of access management, approval controls, logging, and monitoring adds $600. One authorization error requires investigation, correction, and customer support costing another $1,200.

The fully loaded cost is now $2,700.

Suppose 850 refunds met the predefined quality threshold, remained within the agent's authority, followed policy, and finished within the required service level.

The cost is not $0.42 per request.

It is $3.18 per verified, policy-compliant outcome.

The example is illustrative, but the principle is practical. The cheapest model or lowest token rate does not necessarily produce the lowest-cost acceptable outcome.

The word allocated also matters. A shared security platform or governance team should not be charged entirely to one agent. Control costs should be distributed using a reasonable driver such as usage, privileged actions, protected records, business value, or risk tier.

A public FAQ assistant and a refund-authorizing agent should not carry the same control burden. The refund agent has greater authority and therefore needs stronger authorization, logging, approval thresholds, and post-action review.

More authority may create more business value. It also increases the cost of operating the agent safely.

Where Bargaining Power May Move

Infrastructure retains leverage where power, compute, and capital are scarce. Applications retain leverage where they own a workflow, customer relationship, proprietary data, or measurable business outcome.

The control plane is emerging as an important source of bargaining power. It influences what gets deployed, what an agent may do, what the complete workflow costs, and whether an outcome can be trusted.

That does not mean every control-plane vendor will capture the most value. Cloud providers, model providers, databases, security platforms, and application vendors can all bundle these capabilities into broader offerings.

Independent platforms can remain valuable where organizations need portability, cross-platform evidence, or a neutral view of quality, risk, and cost.

The durable advantage will not come from owning every layer.

The question isn't which layer wins. It's who controls the evidence used to decide what runs.

References

Standards and frameworks

Company announcements

Author research

  • Mapping the Emerging AI Stack — internal research report, August 2026
  • AI Stack Layers, Playbooks, and Best-Fit Wedge — internal research report, August 2026