---
title: "Whose Agents Run Your Operations? The Managed Agent War"
slug: "managed-agent-platform-war-whose-agents-run-your-operations"
author: "Jaione Amigot"
date: "2026-09-24 15:00:00"
category: "Premium"
topics: "managed agent platforms, enterprise AI agents, vendor lock-in, self-hosted AI, per-seat pricing, AI sovereignty, agent orchestration"
summary: "Five vendors now sell managed enterprise agent platforms, from AWS Bedrock AgentCore in October 2025 to Google's Gemini Enterprise Agent Platform in April 2026. All of them operate the agents for you, and that is the whole buying decision."
banner: ""
thumbnail: ""
linkedin: |
  Google announced its Gemini Enterprise Agent Platform on 22 April 2026, the fifth major managed agent platform.

  The full sequence: AWS Bedrock AgentCore reached general availability 13 October 2025. Microsoft announced Agent 365 at Ignite on 18 November 2025. OpenAI launched Frontier on 5 February 2026. Anthropic shipped Claude Managed Agents on 8 April 2026. Google followed in April.

  Then in May 2026 both frontier labs went further and bought their way into the implementation layer: Anthropic into a joint venture valued at roughly $1.5B with Blackstone, Hellman & Friedman and Goldman Sachs, and OpenAI reported the same day to be raising $4B from 19 investors at a $10B pre-money valuation for a separate venture, launched 11 May as the OpenAI Deployment Company.

  These platforms are genuinely good. Identity for agents, audit trails, sandboxed execution, evaluation harnesses — real engineering that most teams should not rebuild.

  But the decision has quietly changed shape. It is no longer "which agent is most capable". It is:

  → Who operates the agents that execute your processes
  → Whose perimeter your operational data is reasoned over inside
  → What you keep if you leave — and on every managed platform, the orchestration layer is not it
  → Whether your model choice survives a change of vendor, or is the same decision

  Anthropic's self-hosted sandboxes make the point precisely: execution can run inside your perimeter, and on our reading the orchestration layer still runs on Anthropic's.

  With ibl.ai you own all the code and the data — self-hosted inside your own perimeter, model-agnostic across any LLM, usage-based with no per-seat pricing, deployable anywhere from your own cloud to a fully air-gapped network.

  #iblai #AgenticAI #EnterpriseAI #VendorLockIn #AIGovernance #SelfHosted
---

## The Short Answer

**Every major vendor now sells a managed agent platform: AWS Bedrock AgentCore reached GA on 13 October 2025, Microsoft announced Agent 365 on 18 November 2025, OpenAI launched Frontier on 5 February 2026, Anthropic shipped Claude Managed Agents on 8 April 2026, and Google announced its Gemini Enterprise Agent Platform on 22 April 2026. Each operates the agents for you. With ibl.ai you own all the code and the data, so the agents running your operations stay yours.**

When five vendors sell the same category, capability stops being the differentiator. Operating custody starts being it.

## Which enterprise agent platforms do OpenAI, Anthropic, Microsoft, Google and AWS actually sell today?

All five ship a named product, and the products are more alike than their marketing suggests.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Vendor</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Product</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Announced</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Who operates the agents</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>AWS</strong></td>
      <td style="padding:0.75rem;"><a href="https://aws.amazon.com/about-aws/whats-new/2025/10/amazon-bedrock-agentcore-available">Bedrock AgentCore</a></td>
      <td style="padding:0.75rem;">13 Oct 2025 (GA)</td>
      <td style="padding:0.75rem;">AWS</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>Microsoft</strong></td>
      <td style="padding:0.75rem;"><a href="https://www.microsoft.com/en-us/copilot/blog/2025/11/18/microsoft-agent-365-the-control-plane-for-ai-agents/">Agent 365</a></td>
      <td style="padding:0.75rem;">18 Nov 2025</td>
      <td style="padding:0.75rem;">Microsoft</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>OpenAI</strong></td>
      <td style="padding:0.75rem;"><a href="https://techcrunch.com/2026/02/05/openai-launches-a-way-for-enterprises-to-build-and-manage-ai-agents/">Frontier</a></td>
      <td style="padding:0.75rem;">5 Feb 2026</td>
      <td style="padding:0.75rem;">OpenAI</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>Anthropic</strong></td>
      <td style="padding:0.75rem;"><a href="https://claude.com/blog/claude-managed-agents">Claude Managed Agents</a></td>
      <td style="padding:0.75rem;">8 Apr 2026</td>
      <td style="padding:0.75rem;">Anthropic</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>Google</strong></td>
      <td style="padding:0.75rem;"><a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform">Gemini Enterprise Agent Platform</a></td>
      <td style="padding:0.75rem;">22 Apr 2026</td>
      <td style="padding:0.75rem;">Google</td>
    </tr>
  </tbody>
</table>

The feature lists converge almost line for line. [AgentCore](https://aws.amazon.com/about-aws/whats-new/2025/10/amazon-bedrock-agentcore-available) ships Runtime, Gateway, Memory, Browser, Code Interpreter, Identity and Observability.

Google's platform ships Agent Studio, Agent Runtime, Agent Sandbox, Agent Memory Bank, Agent Identity, Agent Registry and Agent Gateway, with access to [more than 200 models](https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform) through Model Garden.

[Microsoft's Agent 365](https://www.microsoft.com/en-us/copilot/blog/2025/11/18/microsoft-agent-365-the-control-plane-for-ai-agents/) calls itself a control plane, with an agent registry, risk-based access controls and hooks into Entra, Purview and Defender.

Same primitives, five control planes, none of them yours.

## Did the managed agent war start this month, or has it been building since late 2025?

It has been building for roughly a year, and the timeline matters because it changes what the announcements mean.

The first of these platforms reached general availability on **13 October 2025**. The most recent of the five landed on **22 April 2026**. Anything framed this week as the opening shot is describing a market that is already consolidating.

What is new is the layer above the platform. Both frontier labs moved into the implementation layer in May 2026.

On **4 May 2026** Anthropic joined Blackstone, Hellman & Friedman and Goldman Sachs in an [AI-native enterprise services company](https://www.cnbc.com/2026/05/04/anthropic-goldman-blackstone-ai-venture.html) valued at roughly **$1.5 billion**, including a $300 million commitment each from Anthropic, Blackstone and Hellman & Friedman.

Goldman is a founding partner with no disclosed commitment.

And OpenAI was reported [the same day](https://techcrunch.com/2026/05/04/anthropic-and-openai-are-both-launching-joint-ventures-for-enterprise-ai-services/) to be raising **$4 billion from 19 investors at a $10 billion pre-money valuation** for a separate venture, launched 11 May as the OpenAI Deployment Company, with TPG, Brookfield, Advent and Bain Capital.

The services layer is filling in around them, and two examples in the brief that prompted this post need correcting.

**CrowdStrike did not build AI security with HCLTech.** On [14 September 2026](https://www.crowdstrike.com/en-us/press-releases/hcltech-crowdstrike-expand-strategic-partnership-advancing-ai-security-resilience/) the two expanded an existing partnership so that HCLTech delivers CrowdStrike Falcon Guardian inside its own advisory and managed services, using HCLTech's TRiBe framework and VERITY Frontier AI Resilience, a cybersecurity operating model. CrowdStrike supplies the product; HCLTech operates it. That extends a [CTEM partnership announced 31 March 2026](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-hcltech-expand-partnership-with-ai-powered-ctem-services/).

**Codos is real, but its numbers are not independently sourced.** The company [describes a "Virtual CAIO"](https://codos.ai) with on-premise deployment and a16z Speedrun backing. The impact figures circulating with its launch come from the founder's own posts, not from a newsroom or an audited filing, so they are not cited here.

## What do managed agent platforms genuinely do well?

A great deal, and pretending otherwise would misread the decision.

They solve agent identity. Giving every agent a cryptographic identity, scoping its permissions and revoking them centrally is unglamorous infrastructure that most organizations should not rebuild.

They solve sandboxed execution. Running model-generated code safely, with resource limits and network isolation, is a security problem with a long tail of failure modes.

They solve observability and evaluation. Tracing a multi-step agent run, clustering failures and scoring changes before they reach production is engineering that takes a dedicated team quarters to get right.

And they solve deployment mechanics. AgentCore added VPC and PrivateLink support at GA, and [reached AWS GovCloud (US-West) in May 2026](https://aws.amazon.com/about-aws/whats-new/2026/05/bedrock-agentcore-launch-aws-govcloud-us/).

None of that is marketing. It is the reason the category exists, and a team evaluating one of these platforms should weigh it honestly.

## What can you not get from any managed agent platform?

Three things, and they are structural rather than a matter of vendor goodwill.

**The source code.** Every platform above is consumed as a service. You configure it, you extend it through supported interfaces, and you cannot read or modify the orchestration layer that decides how your agents behave.

**Your data inside your own perimeter, end to end.** The closest any of them comes is instructive. Anthropic's Managed Agents now let agents [operate inside your own perimeter with self-hosted sandboxes and MCP tunnels](https://claude.com/blog/claude-managed-agents), phrasing that comes from a later "What's new" note rather than the 8 April launch announcement.

That is a real improvement. Our reading of the arrangement is that execution runs in your environment while orchestration stays on Anthropic's, which is a precise illustration of the boundary; Anthropic does not describe it in those terms.

**Model freedom that survives a change of vendor.** Google's platform reaches 200-plus models and AgentCore works with any model in or outside Bedrock, so model choice is genuinely broad. But the platform is not portable: switching the control plane means rebuilding the agents, the evaluations and the integrations on someone else's primitives.

Put together, these decide what you retain if you leave. On a managed platform, you keep your data exports and your prompts. The operating layer stays with the vendor, which is the part that actually runs your processes.

## Why is per-seat pricing the wrong shape for agents that run operations?

Because headcount stopped being a proxy for consumption the moment agents started doing the work.

Microsoft publishes Microsoft 365 Copilot at [**$30.00 per user per month, paid yearly**](https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise), on top of a qualifying Microsoft 365 license. At 5,000 employees that is **$1.8 million a year** before a single agent runs, and the bill is identical whether 5,000 people use it daily or 400 do.

The agent platforms themselves have already moved. Anthropic prices Managed Agents at [**$0.08 per session-hour**](https://claude.com/blog/claude-managed-agents) of active runtime plus standard token rates — a meter, not a seat count.

That split is the tell. Per-seat licensing survives where the product is a person's assistant. Where the product is an agent executing a process, every vendor including the per-seat incumbents bills by what runs, because seats describe nothing about the workload.

An agent that reconciles invoices overnight has no seat. Charging for one is a pricing artifact inherited from software humans opened, and above a few hundred users it detaches from cost entirely.

## How does ibl.ai let you own the agents that run your operations?

By making the operating layer itself part of what you buy.

With ibl.ai you own all the code and the data.

The full source code transfers under a perpetual license and runs on your infrastructure, so the orchestration layer that decides how your agents behave is one you can read, audit and modify.

The platform is model-agnostic across any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switching providers does not mean rewriting the platform.

Billing is usage-based with **no per-seat pricing**, against a budget cap you set. And you can deploy anywhere: your own cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

The practical difference shows up in the exit question. Leaving a managed platform means rebuilding your agents on another vendor's primitives.

Leaving ibl.ai is not an event, because the stack is already yours; the [Agentic OS](/product/agentic-os) keeps running on your hardware whether or not the relationship continues.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY.

*Related reading: [how enterprise organizations are deploying autonomous AI agents in 2026](/blog/enterprise-ai-agents-2026) — the governance architecture these platforms are competing to supply, and [enterprise AI consolidation](/blog/enterprise-ai-consolidation-2026) on what happens as the vendor field narrows.*

*Sources: AgentCore general availability from [AWS](https://aws.amazon.com/about-aws/whats-new/2025/10/amazon-bedrock-agentcore-available) and its GovCloud launch from [AWS](https://aws.amazon.com/about-aws/whats-new/2026/05/bedrock-agentcore-launch-aws-govcloud-us/); Agent 365 from the [Microsoft 365 blog](https://www.microsoft.com/en-us/copilot/blog/2025/11/18/microsoft-agent-365-the-control-plane-for-ai-agents/); Frontier from [TechCrunch](https://techcrunch.com/2026/02/05/openai-launches-a-way-for-enterprises-to-build-and-manage-ai-agents/); Managed Agents, session-hour pricing and self-hosted sandboxes from [Anthropic](https://claude.com/blog/claude-managed-agents); the Gemini Enterprise Agent Platform from [Google Cloud](https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform); the joint ventures from [CNBC](https://www.cnbc.com/2026/05/04/anthropic-goldman-blackstone-ai-venture.html) and [TechCrunch](https://techcrunch.com/2026/05/04/anthropic-and-openai-are-both-launching-joint-ventures-for-enterprise-ai-services/); the HCLTech partnership from [CrowdStrike](https://www.crowdstrike.com/en-us/press-releases/hcltech-crowdstrike-expand-strategic-partnership-advancing-ai-security-resilience/); Copilot pricing from [Microsoft](https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise).*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
