A recent VentureBeat survey of 40 enterprise companies reveals that 72% claim to operate two or more primary AI platforms, exposing significant gaps in AI governance and security. The proliferation of AI platforms—from leaders like Microsoft Azure, Google, OpenAI, Anthropic, and other major software vendors—has led to operational sprawl without a unified strategy. This creates contradictions in control and security, as seen in examples like Mass General Brigham hospital system, which built custom solutions around large providers’ AI tools to address data privacy concerns.
The survey data highlights a governance paradox: although 56% of enterprises express confidence in detecting AI misbehavior, many lack systematic mechanisms and clear ownership of governance responsibilities. Vendor opacity and the absence of a single accountable team are among the biggest obstacles. Industry voices like Red Hat warn of “day-two” challenges, where initial ease of adoption masks the complexity and risk of vendor lock-in or unmanaged shadow AI projects.
Some enterprises adopt a flexible “dynamic defensive” approach, avoiding long-term commitments due to rapidly evolving vendor landscapes. Meanwhile, platform providers increasingly offer “managed agents” that consolidate more AI operations but risk deepening dependency and reducing oversight.
Security risk escalates as many enterprises rely on the very providers that generate AI risks to also secure their systems, creating a “security irony.” In response, experts call for a centralized “control plane” or a “Dynatrace for AI”—a unified observability platform that enables end-to-end visibility and control, including a hard-stop “big red button” for emergency intervention. Enterprises need to formalize governance with independent oversight rather than depend solely on vendors, ensuring sustainable AI scaling amid evolving risks.