AI Platforms: Count the Control Planes, Not the Tools

For most companies the honest answer to "which AI platform should we standardise on" is: you will end up running more than one AI platform whether you plan to o

For most companies the honest answer to "which AI platform should we standardise on" is: you will end up running more than one AI platform whether you plan to or not, so the decision that matters is not which one wins, it is how many separate control planes you are willing to operate. Pick platforms by the identity, credential, record and spend surfaces they force you to run, not by their feature grids.

Our position is narrower than the usual roundup advice. The industry line is that tool sprawl is cured by consolidation — fewer vendors, one all-in-one AI platform, done. The data says consolidation is already happening at the vendor level and the ungoverned surface is still expanding, because a vendor count and a control-plane count are different numbers. On Hacker News in March 2025, a commenter who says he talks to corporate users a lot described the trap precisely: Copilot is valuable as an internal super-search, but "no company is so completely on the Microsoft train" that it covers everything — if the CRM is Salesforce, Copilot cannot see into it (kjellsbells, HN item 43316801). That single limitation is why the second platform arrives, and the second platform is where the second set of logins, tokens, logs and invoices arrives with it.

The short answer: Count control planes, not tools — a company that runs four AI platforms on one shared identity, credential, audit and budget layer is in better shape than one that runs two platforms with two of everything.

Last updated: July 30, 2026.

We have not run a controlled bake-off of these platforms ourselves, and this article contains no first-hand test results. Every product fact below is taken from the vendor's own current documentation, quoted and linked, with the date we fetched it.

Diagram comparing four AI platforms each running separate identity, credential, record and spend planes against one shared control layer

Every AI platform you add brings its own identity, credential, record and spend plane unless something underneath collapses them.

What an AI platform actually means in 2026

An AI platform is a product that holds three things at once: access to one or more models, a place for your people to work with them, and connections into your existing systems. That third element is what separates a platform from a tool. A tool answers a prompt; a platform reaches into your mail, your files, your CRM or your ticket queue and acts there, which is why an AI platform decision is an access decision before it is a capability decision.

The category has widened fast enough that the word now covers products with almost nothing in common. A chat assistant with enterprise admin controls, a productivity suite with generative features welded into the apps, a workflow automation engine that happens to call a model, and a cloud ML stack for building your own systems are all sold as AI platforms. They compete for the same budget line and answer to the same security review, but they fail in completely different ways. Anything sold as an enterprise AI platform should therefore be read as a claim about administration and control, not about model quality.

What an AI platform is not: it is not a model. GPT, Claude and Gemini are models; the platform is the wrapper that decides who may call them, with what data, under whose credentials, and who gets the bill. Buyers who conflate the two end up comparing benchmark scores when the thing that will actually cause them pain is whether the connector to their document store is scoped per user or per workspace.

Adoption is now broad enough that this is a live question in most organisations rather than a forward-looking one. Stanford's 2026 AI Index puts organisational AI adoption at 88 percent, and reports documented AI incidents rising to 362 from 233 the year before. Capability spread faster than the governance around it, which is the gap this article is about.

One sourcing note before the specifics. The two sources a buyer would most expect here — analyst rankings behind Gartner's paywall, and practitioner threads on Reddit — were not independently reachable for this piece, so nothing is attributed to either. Everything below comes from vendor documentation we fetched directly, from Netskope's telemetry-based threat report, and from public research.

Re-cutting the AI platform categories by control surface

Most platform roundups sort the market the way vendors sort themselves: content generation, coding assistance, voice, analytics, automation. Those categories describe what the product does, which is useful for exactly one meeting: the first one. They are useless for the meeting where someone asks what happens when it is wrong, because two products in the same marketing category can differ completely in what they are allowed to touch.

Sorting the same market by control surface produces four categories that behave differently under a security review, and the sort is worth doing on your own shortlist before anything else.

Control-surface categoryWhat it can do without a humanTypical examplesThe plane that decides it
AssistiveProduces text, code or analysis a person then usesChat assistants, coding copilots, meeting summarisersRecord — you need to know what data went in
EmbeddedReads across your existing corpus under your existing permissionsSuite assistants grounded in mail, files and chatCredentials — it inherits your sharing mistakes
ActuatingWrites into another system, sometimes unattendedWorkflow automation, agent platforms, ticket handlersCredentials plus Record — reach and evidence
FoundationalHosts models and data you build onCloud ML stacks, model APIs, vector storesSpend plus Identity — service accounts and meters

The categories are ordered by escalating blast radius, and the escalation is the point. An assistive platform that hallucinates costs you a rewrite. An actuating platform that hallucinates costs you a refund issued, an email sent, or a record changed. We argued the general form of this in our analysis of AI workflow tools: choose for what happens when the model is wrong, not for what happens in the demo.

Two practical uses. First, when a team asks to buy something, the category tells you which review it needs — an assistive tool does not need the same scrutiny as one holding a write-capable credential, and treating them identically is how security review becomes the bottleneck everyone routes around. Second, the categories are additive rather than substitutable: buying an actuating platform does not remove the need for an assistive one, which is another reason the platform count in a real company settles above one.

The four control planes every AI platform brings with it

A control plane is the place where you answer one governance question for one platform. Every one of them ships with four of these planes, and if you do not deliberately collapse them, each new platform hands you four more. We call the resulting inventory the Plane Count, and it is the number we would put on the first slide of any AI platform business case.

PlaneThe question it answersWhat it looks like when it is missing
IdentityWho is allowed to use this, and does access end when employment ends?Ex-employees keep working accounts; nobody can produce a user list
CredentialsUnder whose authority does the platform reach into other systems?A shared token in a workflow with rights nobody remembers granting
RecordWhat did it do, and can you show someone?An incident with no answer to "which prompt sent that data out"
SpendWho is consuming what, and what is the ceiling?A surprise invoice attributed to "engineering"

Identity is the plane that looks solved and usually is not. SAML single sign-on is table stakes at the enterprise tier, but SSO controls the front door only. It says nothing about the agent that runs on a schedule at three in the morning under a service account, which is the identity most likely to still be alive a year after the person who created it has left. Our earlier work on non-human identity for AI agents makes the case that every agent needs an owner, a scope and an expiry the same way every employee account does.

Credentials is the plane buyers underweight most consistently, and the platforms differ here more than anywhere else. When ChatGPT connects to an internal system, OpenAI states that "each end user is required to authenticate with a connected application before use" (enterprise privacy page, updated January 8, 2026, fetched July 30, 2026) — the reach of the AI platform is bounded by the individual's own permissions. Microsoft describes the same principle for Copilot: it "only surfaces organizational data to which individual users have at least view permissions" (Microsoft Learn, updated July 9, 2026). An automation platform typically works the other way: a stored connection belongs to the workspace and runs at whatever privilege it was created with, for anyone who can trigger the workflow. Neither model is wrong. Buying both without noticing the difference is what produces the eventual surprise.

Record is where audit questions get answered, and it is the plane most often locked behind the top price tier. OpenAI puts conversation and GPT audit logs behind the Enterprise Compliance API. Anthropic's Claude publishes audit logs as an Enterprise-only line item, absent from Team (Claude pricing, fetched July 30, 2026). Google places audit logs at Business Plus and above (Workspace pricing, fetched July 30, 2026). n8n gates audit logging and log streaming to its Enterprise plan (n8n pricing, fetched July 30, 2026). The pattern is consistent enough to be a planning assumption: the record plane is a paid upgrade, priced per platform.

Spend is the plane that decides whether AI stays a line item or becomes a budget event. Per-seat pricing makes spend look predictable until usage-based components appear underneath it, which they increasingly do. Anthropic lists Enterprise as a seat price "plus usage costs that scale with model and task". A company running four AI platforms with four billing models has no single answer to "what did the finance team's AI cost last quarter", which is the question that eventually arrives from someone senior.

Four planes, multiplied by however many platforms you run. That multiplication is the real cost of a platform portfolio, and no feature comparison table shows it to you.

Why consolidating vendors does not reduce your plane count

Vendor consolidation is the standard prescription for AI sprawl and it is not wrong, it is just aimed at the wrong count. Cutting from twelve platforms to four is a genuine saving in procurement, security review and training. It leaves sixteen control planes standing. And the evidence says the floor is higher than most consolidation plans assume, because the platforms overlap in the market rather than replacing each other.

Netskope's Cloud and Threat Report 2026, published January 2026 from telemetry across its customer base, measured adoption of individual genAI applications inside organisations. These are not market shares that add to 100; they are the share of organisations where each application is in use.

genAI applicationShare of organisations using it (Netskope, 2026 report)
ChatGPT77%
Google Gemini69% (up from 46%)
Microsoft 365 Copilot52%
Perplexity35% (up from 23%)
Grok28%

Add those up and the average organisation is not choosing between ChatGPT and Gemini and Copilot. It is running them concurrently. Netskope names the mechanism directly, describing "a growing trend of organisations using multiple SaaS genAI services with overlapping functionality". Overlapping functionality is exactly what a consolidation plan is supposed to eliminate, and it is what the telemetry keeps finding.

The rest of the same report explains why the plane count matters more each year rather than less. Users of SaaS genAI apps tripled in a year in the average organisation, and prompt volume grew sixfold, from 3,000 to 18,000 prompts per month, with the top quartile above 70,000. Sensitive-data policy violations involving genAI doubled, to an average of 223 incidents per month per organisation. The share of AI users working through personal accounts fell from 78 percent to 47 percent, which is real progress. But the share of users switching back and forth between personal and corporate accounts more than doubled, from 4 percent to 9 percent. People do not abandon the platform that works for them; they add the sanctioned one alongside it.

The strongest counterargument deserves stating in its own words: every additional platform is also an additional vendor relationship, an additional breach surface and an additional renewal, and a company that runs four platforms on a shared control layer has still quadrupled the number of third parties holding its prompts. That is true, and it is why the argument here is for a deliberate, small portfolio rather than an open one. Sharing the planes lowers the cost of each platform you keep; it does not make platforms free, and it is not a licence to say yes to everything. The discipline the shared layer enables is the ability to say "yes, through the layer" instead of either "no" — which produces personal accounts — or an unconditional "yes" — which produces the fifteen-plane inventory below.

There is also a second-order effect worth naming. When the record and credential planes are shared, removing a platform gets cheaper too, because the evidence of what it did does not leave with it. Portfolios that cannot be pruned are usually portfolios where each platform holds the only copy of its own history.

That is the case against treating the AI platform decision as a single-winner tournament. The realistic goal is not one platform. It is a small, deliberate portfolio in which the four planes are shared rather than duplicated: one directory that governs access to all of them, one place credentials are brokered, one record that survives a vendor change, one budget that reconciles.

Here is the fifty-one-minute conversation we would point a sceptical executive to before their own platform decision, because it is a bank deploying across 70,000 employees rather than a vendor demo:

Play video

The Plane Count: a one-sitting inventory

The diagnostic takes an afternoon and needs no vendor involvement. List every platform in use, including the ones bought on a corporate card by a team, which is where a meaningful share of them live. For each one, answer four questions with yes or no. No scoring subtleties, no weighting. A "no" means that plane is separate and you are running it by hand.

  1. Identity: does this platform's access list come from our directory, and does deprovisioning there remove access here?
  2. Credentials: when this platform reaches into another system, does it do so as the individual user, with that user's existing permissions?
  3. Record: can we export, today, a log of who did what in this platform, into the place we keep our other logs?
  4. Spend: can we attribute this platform's cost to a team without asking the vendor?

Your Plane Count is the number of "no" answers. There is no universal target number, and anyone who gives you one is selling something; the useful threshold is simpler — any plane with no named owner against it is not being run at all, and that is the line worth acting on first. Every "no" is a manual process someone owns, or a question you cannot currently answer. Run it before the shortlist, not after: it changes which platforms make the shortlist.

The illustrative sheet below shows the shape of the output. It is built from the published vendor facts in this article applied to a mid-sized company that has bought the mainstream tiers rather than the top ones — a common pattern, not a client engagement, and not a measurement of any real deployment.

Platform in useIdentityCredentialsRecordSpendPlanes not shared
ChatGPT EnterpriseYes (SAML SSO)Yes (per-user app auth)Yes (Compliance API)No (seat cost only)1
Microsoft 365 CopilotYes (Entra)Yes (user permissions)Yes (Purview)No1
Claude TeamYes (SSO, SCIM)Yes (admin connector controls)No (Enterprise only)No2
n8n Cloud, Pro planNo (SSO from Business)No (workspace credentials)No (Enterprise only)No4
Two team-bought niche toolsNoNoNoNo8

Sixteen unshared planes across six products, and the two cheapest line items produce three quarters of them. That is the characteristic result: the governance debt does not sit with the expensive platform that went through security review, it sits with the small ones that did not.

Three refinements make the inventory more useful. First, count agents and workflows separately from human seats. A platform with 40 users and 200 scheduled automations has a non-human identity problem the seat count hides. Second, mark each "no" with the name of the person who currently compensates for it manually; a plane with no name against it is not being run at all. Third, re-run the sheet quarterly, because AI platforms move faster than procurement cycles and the answers change under you.

Five AI platforms scored on control surface

These are not rankings. Each block reports the same four planes from the vendor's own current documentation, fetched July 30, 2026, with a verdict about the shape of company it suits. Two caveats bind everything that follows. These are vendor commitments published by the vendor, not behaviour we observed, so anything load-bearing belongs in your contract rather than in a marketing page. And prices and terms on this list change frequently; re-check any figure before it goes in a business case.

OpenAI ChatGPT (Business and Enterprise)

Best for: broad workforce assistance where the strongest general-purpose chat experience matters and the connected systems are diverse.

  • Identity: SAML SSO; SCIM and role-based access at the Enterprise tier.
  • Credentials: apps connect to internal sources, admins control which apps are enabled, and "each end user is required to authenticate with a connected application before use" — reach is bounded by the individual.
  • Record: workspace admins access "an audit log of conversations and GPTs through the Enterprise Compliance API". On Business, admins can view, access, export and delete workspace conversations, which is oversight rather than an audit trail.
  • Spend: per-seat plans; OpenAI states it offers "monthly plans for Go, Plus and Business and annual plans for Business and Enterprise" (pricing page, fetched July 30, 2026). Enterprise pricing is not published.
  • Data handling: "We do not train our models on your data by default"; deleted conversations removed within 30 days; admin-controlled retention; SOC 2 Type 2; data residency options listed for a range of regions.
  • Verdict: the cleanest per-user credential model of the five, and a real audit surface. But that surface is an Enterprise-tier API, so a company on Business has bought the assistant without the record plane.

Microsoft 365 Copilot

Best for: organisations already standardised on Microsoft 365, where the assistant can inherit an identity and compliance stack that already exists.

  • Identity: Entra ID, so the directory you already deprovision from governs it.
  • Credentials: grounded in Microsoft Graph and constrained by existing permissions. Copilot "only surfaces organizational data to which individual users have at least view permissions". This is a genuine strength and a genuine hazard: it inherits whatever over-sharing already exists in SharePoint.
  • Record: prompts and responses are stored as user activity history, and admins "can use Content search or Microsoft Purview" to view and manage it, including retention policies. Admins have "full control to select which agents are allowed".
  • Spend: published add-on pricing of $18.00 per user per month paid yearly under a promotion running July 1 to September 30, 2026 (list $21.00), or $25.20 per user per month on a monthly commitment (Microsoft 365 Copilot pricing, fetched July 30, 2026).
  • Data handling: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs." EU traffic stays within the EU Data Boundary — with a caveat worth reading twice. "Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary."
  • Verdict: the lowest marginal plane count of any option for a Microsoft-native company, because all four planes are ones you already run. The subprocessor exclusion is the sort of detail that turns a signed data residency assumption into a finding, and it is documented rather than hidden.

Google Gemini for Workspace

Best for: Workspace-native organisations wanting assistance inside the apps people already use, with admin control from the same console.

  • Identity: Workspace admin console; per-service enablement across Gmail, Drive, Docs, Meet and Chat.
  • Credentials: access follows Workspace permissions; admins "manage which Workspace services Gemini accesses".
  • Record: Google states it provides admins with "a robust set of audit logs to track user activity and interactions with Gemini", and admins "have control over conversation history" including retention periods (Workspace privacy hub, fetched July 30, 2026). Audit logs and Vault sit at Business Plus and above.
  • Spend: Business Starter $7, Standard $14, Plus $22 per user per month, with AI features included in Standard and above; data regions at Enterprise (fetched July 30, 2026).
  • Data handling: "Workspace does not use customer data for training models without customer's prior permission or instruction." Note the documented limit: "Your organization's file sharing and data region settings do not apply to data in Gemini Notebook."
  • Verdict: strong plane consolidation for a Workspace company, with the same inheritance risk as Copilot, and the tier at which the record plane switches on is a real budget decision rather than a footnote.

Anthropic Claude for Work

Best for: teams whose main use is heavy reasoning and long-document work, often alongside a broader assistant rather than instead of one.

  • Identity: SSO and SCIM on both Team and Enterprise.
  • Credentials: admin controls for remote and local connectors on both tiers.
  • Record: audit logs are Enterprise-only; Team does not have them. Retention changes are themselves logged: "All retention-related actions and changes are automatically tracked in audit logs" (Anthropic privacy documentation, fetched July 30, 2026).
  • Spend: Team at $20 per seat per month annually or $25 monthly; Enterprise at $20 per seat plus usage that scales with model and task.
  • Data handling: the retention default deserves attention. Anthropic documents that "by default, data is retained indefinitely unless a custom retention period is set", with a minimum configurable period of 30 days, set by a Primary Owner or Owner under Organization settings.
  • Verdict: buy Team for capability and you have bought a platform without a record plane and with indefinite retention until someone changes it. That is a defensible product decision by the vendor and a governance gap by default for the buyer.

n8n (as the representative workflow automation platform)

Best for: engineering-adjacent teams building event-triggered automation where a model is one step among many.

  • Identity: SSO, SAML and LDAP from the Business tier.
  • Credentials: workspace-level stored credentials with an external secret store integration available only at Enterprise, which is the structural difference from the assistant platforms above.
  • Record: audit logging and log streaming to external services are Enterprise features, absent on Starter and Pro; insights retention runs 7 to 30 days on lower plans against 365 days on Enterprise.
  • Spend: priced by monthly execution volume with unlimited users on all plans; Enterprise is quote-only.
  • Data handling: self-hosted or cloud-hosted, which is the one option here that lets you keep everything inside your own boundary.
  • Verdict: the highest plane count per dollar on lower tiers and the lowest on Enterprise, which makes it the clearest illustration of the general rule. The automation platform is where governance is most often deferred, because it starts as one person's useful workflow. Our earlier analysis of choosing AI automation platforms goes into what to check before an automation runs unattended.

At a glance

AI platformIdentity planeCredential modelRecord planeCheapest tier with audit logs
ChatGPT Business/EnterpriseSAML SSO, SCIM (Ent.)Per end user, per appCompliance APIEnterprise
Microsoft 365 CopilotEntra IDInherits user permissionsPurviewPurview, subject to your compliance licensing
Gemini for WorkspaceWorkspace adminInherits Workspace permissionsWorkspace audit logsBusiness Plus
Claude for WorkSSO, SCIM (both tiers)Admin-controlled connectorsEnterprise onlyEnterprise
n8nSSO from BusinessWorkspace credentialsEnterprise onlyEnterprise

Read that final column as the real price of governance. On four of five platforms, the audit trail is a tier upgrade. You pay it once per platform.

What the control surface actually costs

Comparing AI platform pricing by headline seat price produces a wrong answer, because the tier that includes the record plane is rarely the tier in the comparison. The honest comparison prices the tier you would actually be allowed to deploy after a security review.

PlatformEntry per-user price (fetched July 30, 2026)What the entry price omits
Microsoft 365 Copilot$18.00/user/month annual promo; $21.00 list; $25.20 monthlyRequires an underlying Microsoft 365 subscription
Google Workspace Standard$14.00/user/monthAudit logs and Vault start at Plus ($22); data regions at Enterprise
Claude Team$20/seat/month annual, $25 monthlyAudit logs; Enterprise adds usage-based cost
ChatGPT BusinessPer-seat, monthly or annual; Enterprise annual onlyCompliance API audit logs are Enterprise
n8nBy execution volume; unlimited usersAudit logging, log streaming and external secrets are Enterprise

The pattern holds across every enterprise AI platform we checked: capability is priced per seat, control is priced per tier. Three practical consequences follow. First, a four-platform portfolio bought at governed tiers costs materially more per person than the same portfolio quoted at entry tiers, and the difference is invisible in most business cases. Second, because each platform charges separately for its record plane, the marginal cost of the fifth platform is higher than the fourth. Plane duplication compounds. Third, promotional pricing has an expiry: the Copilot discount above is documented as applying to the first year only, which is a renewal conversation with a date on it.

The alternative that does not appear in vendor pricing tables is to stop buying the same plane repeatedly. If identity, credential brokering, logging and budget attribution live one layer beneath the platforms, a new AI platform costs a seat price rather than a seat price plus a fifth governance stack. That is a build-or-buy decision in its own right, and it is the one this whole article has been walking toward. It is not free either: a shared layer carries its own licence or engineering cost, and the fair comparison is that cost against the sum of the per-platform governance tiers you would otherwise buy, plus the staff time currently spent answering access and spend questions by hand. In our judgment the comparison turns mainly on how many platforms the plan contains, since the duplicated cost scales with that count rather than with usage — but we have not published a model behind that, and you should build the arithmetic with your own numbers rather than ours.

Choose this AI platform if

  • Choose Microsoft 365 Copilot if your identity, records management and compliance tooling are already Microsoft, and your SharePoint permissions are in good order. It adds the fewest new planes. Verify the subprocessor and data-boundary details against your own residency commitments first.
  • Choose Gemini for Workspace if you are a Workspace company and the assistance you want is inside Docs, Gmail and Meet. Budget for Business Plus if anyone will ever ask for an audit log.
  • Choose ChatGPT Enterprise if the strongest general assistant matters more than suite integration, and you want per-user authentication into connected systems as the default reach limit. Do not buy Business and assume you have the Enterprise audit surface.
  • Choose Claude for Work if the workload is deep reasoning over long documents, and go straight to Enterprise if any regulated data will touch it. Team's missing audit logs and indefinite default retention are the deciding factors, not model quality.
  • Choose a workflow automation platform such as n8n if the value is in unattended, event-triggered chains rather than conversation. Price the Enterprise tier from the start; the lower tiers are where credential and audit debt accumulates.
  • Choose more than one, deliberately, if no single platform covers your systems, which the adoption data suggests is most companies. Then make the plane count, not the vendor count, the thing you actively manage.

When one all-in-one AI platform really is the right answer

There is a real case for the all-in-one platform and it deserves better than a strawman. If you are under about fifty people, if your systems are already inside one suite, and if nobody has yet asked for an audit trail, then one platform on one directory is not a compromise, it is the correct engineering decision. Four planes total. Every argument in this article about duplication assumes the duplication is already happening; if it is not, do not go looking for it.

The consolidation case also wins when the alternative is genuine chaos rather than a deliberate portfolio. Twelve tools bought by nine teams with no shared login is worse on every axis than one suite that covers 80 percent of the need adequately. The 80 percent solution with one control plane beats the 100 percent solution with five, and it is not close.

Where consolidation stops paying is at the boundary the Hacker News comment identified — the moment the suite cannot see into the system that matters most to the business. At that point the choice is not "one platform or several", it is "several platforms with a shared control layer, or several platforms without one". The incumbent suite keeps the work it can do; the shared layer is what stops the additions from each bringing a full governance stack with them.

Where this framework runs out of road

The Plane Count is a planning heuristic, not a measurement, and we would rather say where it is weak than oversell it.

It does not weight the planes. In practice a missing credential plane on a platform with write access to your finance system is worth several missing spend planes on a summarisation tool. A serious version of this inventory would weight each "no" by what the platform can reach and change, which is the argument our analysis of AI agent platforms makes in more depth. Use the raw count to find the problem, then judge severity by blast radius.

It says nothing about output quality. A platform can score four out of four on control and still be the wrong choice because its answers are not good enough for the work. Control is a constraint on the shortlist, not a substitute for evaluating capability.

The vendor facts have a short shelf life. Every figure here was fetched on July 30, 2026, and platform tiers, prices and data-handling terms change on a scale of weeks. Anything in this article that would change a decision should be re-verified on the vendor's page before you rely on it — including the parts that flatter our argument.

Two things we deliberately did not do: we ran no head-to-head test of these platforms, and we make no claim about which produces better output. Independent, reproducible testing of AI platforms on an identical task, with the transcript published, is the thing this genre is missing most, and roundups that claim it rarely show the artifacts. We would rather log that gap than fill it with an unrepeatable anecdote.

Finally, the regulatory floor is moving underneath all of this. The EU AI Act entered into force on August 1, 2024 and phases in through 2028, with governance rules and general-purpose model obligations applicable from August 2, 2025 and further obligations following; the European Commission summarises deployer duties as ensuring "human oversight and monitoring" and reporting serious incidents (European Commission, regulatory framework for AI, fetched July 30, 2026). Human oversight and incident reporting are, in operational terms, the record plane. A company that cannot answer "what did this platform do" cannot demonstrate either.

Where LeapForce fits

LeapForce builds the layer this article keeps pointing at: one controlled place where identity, policy, cost and audit apply to every AI tool, connector, model and agent, so that adding an AI platform does not mean adding a governance stack. Our AI gateway sits in the request path — identify, check, protect, route, execute, record — and the rollout model we publish is deliberately unglamorous: observe first, enforce second, optimize third. Point one team's traffic at the gateway in observe mode, find out what is actually in use and what it costs, and only then write rules. Our earlier analysis of what an AI gateway is covers the mechanics.

The honest boundary: LeapForce is not an alternative to ChatGPT, Copilot, Gemini or Claude, and nothing here replaces choosing good platforms — we are the layer underneath them, and per-capability build status is disclosed on our site because not every capability ships today.

 FAQ

Frequently asked questions

An AI platform is a product that combines model access, a working surface for your people, and connections into your existing systems, under some form of administrative control. The third part is what separates a platform from a tool: a tool answers prompts, a platform reaches into your mail, files, CRM or ticket queue and acts there. That reach is why platform selection is an access decision before it is a capability decision.

There is no single best AI platform for business, and the adoption data suggests most companies run several. Netskope's 2026 telemetry found ChatGPT in use at 77 percent of organisations, Gemini at 69 percent and Microsoft 365 Copilot at 52 percent. Concurrently, not as alternatives. The better question for anyone choosing an AI platform for business use is which combination covers your systems while sharing one identity, credential, audit and budget layer between them.

Free tiers exist on every major vendor, but none of them include the enterprise control surface: no admin console, and no integrations governed by anything but the individual user. Admin consoles, SSO, audit logs, retention controls and data residency all sit on paid tiers, and on four of the five platforms reviewed here the audit log specifically requires the top tier. A free tier used for company work is, structurally, shadow AI with a corporate logo on it.

The major enterprise platforms say they do not by default. OpenAI states "we do not train our models on your data by default", Microsoft states that Copilot prompts, responses and Graph data "aren't used to train foundation LLMs", and Google states that Workspace "does not use customer data for training models without customer's prior permission or instruction". Those commitments attach to business tiers, not to consumer accounts, which is precisely why personal-account usage is the exposure that matters.

Most no longer do for basic use. Assistant platforms need no code at all, and workflow automation platforms are built around visual editors where a model is one node among many. Coding re-enters for custom connectors, for anything running against your own APIs, and for self-hosted deployments. The no-code claim is about building; the work that survives a security review is usually scoping, not building.

A tool does one job with what you give it. A platform holds credentials, connects to systems, supports multiple users under administrative control, and keeps state between sessions. The practical test is whether it can act inside another system on your behalf. If it can, it is a platform, it belongs in your access review, and it brings the four control planes with it regardless of how it is marketed.

Price the tier you would actually be permitted to deploy, not the headline seat price. Audit logs sit at Enterprise for Claude, ChatGPT and n8n, and at Business Plus for Google Workspace, so an entry-tier comparison compares products you could not put into production. Then add the usage-based component where one exists. Anthropic prices Enterprise as a seat cost plus usage that scales with model and task — and multiply the governance cost by the number of platforms, because each vendor charges for it separately.

ChatGPT Enterprise exposes conversation and GPT audit logs through its Compliance API. Microsoft 365 Copilot interactions are searchable and retainable through Purview. Google Workspace provides Gemini audit logs from Business Plus. Claude has audit logs on Enterprise only. n8n gates audit logging and log streaming to Enterprise. Check the export path too: a log you cannot get into your own SIEM is oversight, not evidence.

Sometimes, with caveats worth reading in full. Microsoft applies the EU Data Boundary to Copilot but documents that Anthropic models supplied as a subprocessor "are currently excluded" from it. Google offers data regions at the Enterprise tier while noting that region settings "do not apply to data in Gemini Notebook". OpenAI lists data residency across a range of regions on its enterprise plans. Residency commitments in AI platforms tend to have named exceptions, and the exceptions are where compliance findings come from.

On most AI platforms, nothing automatic. Removing the user's SSO access closes their front door but does not necessarily stop a scheduled automation running under a stored workspace credential, and the prompts that encoded how the work was done leave with them. This is the non-human identity problem: every agent needs a named owner, a scope and an expiry, and ownership has to survive the person. Our analysis of turning personal prompts into owned assets covers the handover in detail.

The Plane Count inventory takes an afternoon and should happen before the shortlist. Vendor evaluation then runs on whatever cycle your security review demands — but the sequence matters more than the duration: inventory first, shortlist second, pilot third. Teams that pilot first end up justifying a platform they have already deployed, which is how a fifth control plane arrives without anyone deciding to add one.

Ready to Govern Your AI?

Talk to LeapForce — one controlled layer for every AI tool, connector, model, and agent.

Thirty minutes · No pitch deck

Ready to turn AI experiments into measurable ROI?

Bring one outcome you'd like AI to move. We'll help you scope a pilot you can actually measure — and tell you honestly if it's not worth doing yet.

Comments