Explainer

What is an AI control plane?

An AI control plane is the layer between the people using AI and the models doing the work. It keeps an inventory of approved AI use, checks policy before a request runs, routes each request to the right model or environment, and records what happened.

The defining characteristic is timing. A control plane enforces policy at the moment of action, rather than documenting rules that get reviewed later.

Written by Christopher Bale, Founder of Kubrius · Updated July 2026

Four jobs, running on every request.

Vendors describe the category slightly differently, but the working parts are consistent.

1. Inventory

Know which AI tools, models and workflows are actually in use, and which are approved. You cannot govern what you cannot see, and in most businesses the real answer differs from the official one.

2. Policy evaluation

Before a request reaches a model, decide what should happen to it: allow, warn, block, or send it somewhere private. The decision is based on the task, the user's role and the sensitivity of the data involved.

3. Routing

Send each request to the appropriate destination. Ordinary drafting can use an approved commercial model. Confidential material may need to run on infrastructure the business controls, or not run at all.

4. Evidence

Record every request, including the ones that were refused: who asked, what was decided, which rule applied, where it ran, and which sources an answer came from. Records that depend on people choosing to create them do not exist.

What it is not.

Three adjacent terms get used interchangeably. They describe different things.

Not an AI gateway

A gateway routes model traffic: keys, failover, rate limits, cost tracking. Useful plumbing, and most control planes use one underneath. On its own it has no notion of company policy and cannot tell an approved request from a prohibited one.

Not an AI management system

An AI management system, in the sense of ISO/IEC 42001, is organisational: policies, roles, risk assessments, records. It describes what a business must have. A control plane is the machinery that carries those decisions out. More on that distinction here.

Not a compliance register

Plenty of governance tools document and assess AI risk without ever touching a live request. They produce useful paperwork. They cannot stop an employee pasting a client contract into a personal chatbot account.

Every control plane is built for someone else's company.

The category formed around large organisations. Products in this space are generally designed for platform engineering teams governing fleets of AI agents, and priced for businesses already spending tens of thousands a month on AI.

What the enterprise version assumes

  • A platform or IT team to run it
  • Existing identity and DLP infrastructure to plug into
  • Agent sprawl as the primary problem to solve
  • Procurement, a pilot, and a rollout programme
  • Pricing that starts in the hundreds per month before usage

What a 20 to 200 person business actually has

  • No dedicated platform team, often no IT team
  • Staff already using AI on real client work
  • Shadow usage rather than agent sprawl
  • A client, insurer or auditor starting to ask questions
  • No appetite for a six-month governance programme
The functions are identical. The scale, the price and the assumptions are not.
Question Enterprise control plane What an SME needs
Primary problem Governing many autonomous agents and MCP servers at scale Staff using public AI tools on confidential client work
Who operates it Platform engineering or security team Whoever runs operations, alongside their day job
Where staff experience it Invisible infrastructure behind other tools A workspace they open and use directly
Private execution Usually routes to third-party APIs; on-prem means rack-scale hardware One quiet appliance that fits in an office
Evidence Feeds an existing SIEM and GRC stack A readable report to send a client or insurer
Commercial model Custom quotes, seat minimums, annual commitments Published price, no minimum, cancel if it does not work

Kubrius is a control plane sized for the businesses everyone else skipped.

Same four functions. Different assumptions about who is running it and what they can spend.

The control layer

The Kubrius Portal gives staff one approved workspace built around business tasks rather than model choices. Policy checks run before each request. Sensitive work is routed automatically, and every request is logged whether it ran or not.

The private execution path

Kubrius Core is the part most control planes do not have: local models and private retrieval running on a small appliance inside your own network, for the work that should never reach a third-party API.

Already paying for Microsoft 365? That is a fair question to ask first. We wrote an honest comparison covering where Microsoft Agent 365 and Copilot are the better choice, and where they leave gaps.

Frequently asked questions.

What is an AI control plane?

An AI control plane is the layer that sits between the people using AI and the models doing the work. It keeps an inventory of approved AI use, evaluates policy before a request runs, routes each request to the appropriate model or environment, and records what happened. Its defining characteristic is that policy is enforced at the moment of action rather than reviewed afterwards.

What is the difference between an AI control plane and an AI gateway?

A gateway routes model traffic: it handles API keys, failover, rate limits and cost tracking. A control plane sits above that and decides whether a request should run at all, which environment it belongs in, and what evidence to record. Most control planes use a gateway underneath; the gateway alone has no notion of company policy.

What is the difference between an AI control plane and an AI management system?

An AI management system, as defined by ISO/IEC 42001, is organisational: policies, roles, risk assessments and records. It describes what a business must have. A control plane is the technical layer that enforces those decisions in practice and produces the records automatically. One is the framework, the other is the machinery underneath it.

Do small and medium businesses need an AI control plane?

The need appears as soon as staff use AI on real company data, which for most businesses has already happened. What smaller businesses do not need is the enterprise version of the product. Most control planes are built for platform teams governing fleets of agents at organisations spending tens of thousands a month on AI. An SME needs the same three functions at a far smaller scale: visibility of what is being used, checks before sensitive work runs, and a record it can show a client or insurer.

Does an AI control plane replace ChatGPT or Copilot?

No. It sits in front of whichever models a business uses and decides how each request is handled. Everyday work can continue to run on approved commercial models, while sensitive work is routed to private infrastructure or blocked according to policy.

Can an AI control plane run on our own infrastructure?

Some can. This matters when a business handles material that should not reach a third-party API at all, such as client contracts or proprietary code. In that case the control plane needs a private execution path, meaning local models running on hardware the business controls, rather than only routing between external providers.

Start with what you can see.

The AI Control Scorecard maps where AI is already being used in your business, what data is exposed, and which controls are worth putting in first. No platform team required.