The context layer for AI is a land grab. The half that matters is yours to own.
The market is converging on one context layer for AI under a dozen names, and the one part that actually governs agents is yours to own. Here is the map.
Call it a context layer, a semantic layer, an ontology, or an agent governance plane. Serious vendors are building the same thing. The part that actually governs is the one you have to own.
The previous pieces argued that a context layer for AI has two halves, and that the enforced half is the one that matters. That is a claim about what should exist. This piece is about what does exist: who is building toward this layer, under how many names, and the specific part almost none of them has finished. If you are choosing partners and platforms, the map matters more than the manifesto, because it tells you what to buy, what to build, and what nobody can sell you yet.
Start with the vocabulary, because it gives the game away. Count the labels in circulation: context layer, enterprise data graph, ontology, semantic layer, knowledge graph, agent governance plane, AI gateway, AI command centre, system of context, agent registry, MCP-enabled tool layer. Eleven names, one underlying idea: agents cannot safely operate on raw data, unmanaged documents, and ungoverned tools. They need business meaning, access control, lineage, quality signals, policy, and evidence at the moment they run. When an industry invents eleven names for one thing in a couple of years, it is telling you the thing is real and the shape of it is still being argued out. Atlan, one of the most prominent, has been the most literal about it, positioning its entire platform as 'the context layer for AI' outright.
The convergence goes well past naming, though. It is shipping.
The data platforms already moved
Through 2025 and into 2026, the major data platforms put governed semantic objects into their products specifically to ground agents. Snowflake shipped Semantic Views and Cortex Analyst. Databricks added metrics, business semantics, and a glossary to Unity Catalog. Looker has carried LookML for years, and the headless players (Cube, AtScale, dbt's MetricFlow) filled the gaps, with MetricFlow open-sourced. There is even a cross-vendor standard forming on top, so semantic definitions can move between tools rather than being re-modelled in each.
There is a concrete engineering reason all of them landed here. Point an agent at raw tables and it re-derives the joins, the grain, and the metric maths on every prompt, producing answers that are inconsistent and ungoverned. A governed semantic layer makes the computation deterministic and enforces access at query-compile time, so the agent literally cannot query what the user may not see. The failure mode even changes in a way a regulated business should care about: a semantic-layer failure tends to be an auditable refusal, while raw text-to-SQL tends to fail as a confident, wrong number. One of those you can defend in a review. The other you find out about from a customer.
So the 'what is known' half of the context layer for AI has serious people and serious money behind it. Good. That is not the half I worry about.
The half of the context layer for AI still being fought over
The agent protocols, MCP and A2A, are the other big movement of the last two years, and they are genuinely useful. They standardise how an agent discovers a tool, calls it, and moves context around. What they deliberately do not do is govern. That is not a criticism; a transport standard should not encode a bank's entitlement model. But it means the governance has to live somewhere above the protocol, and that space is still contested.
You do not have to take my word for it; it is in the protocol's own design. MCP has no native mapping from a human identity to a session, treats authentication as optional rather than required, and offers only partial audit. Standard zero-trust practice says the opposite: least privilege, a cryptographically anchored agent identity, and a session you assume is untrusted until proven otherwise. Whichever way you come at it, the missing governance is a layer above the standards, not a feature within them.
The encouraging part, and the honest update, is that this is now widely recognised and actively worked on. An 'agent control plane' has begun to form as a category of its own, and the context-layer leaders now fold policy, lineage, and audit into the same pitch as governed meaning. The discouraging part is that these efforts are early and uneven, and most live inside a single vendor's ecosystem: almost none is neutral or enterprise-owned across the systems a bank actually runs. The need is acknowledged. A dependable, portable answer is not yet delivered.
Connectivity got standardised. Governance did not. That space above the protocols is not a missing feature; it is a whole layer, still up for grabs.
What the contested half costs, concretely
Take a composite from a tier-1 UK lender. The data team does everything right on the semantic side: it standardises metric definitions across two platforms, so every agent computes exposure and arrears the same way. Impressive, and genuinely useful. Then the financial-crime group wants an investigation agent, and the second line asks the question the semantic layer cannot answer: when this agent reads a customer file, is it applying this investigator's entitlements, for this case, and can we prove afterwards what it saw? Two governed semantic layers, and the answer was no. The meaning was solved twice over. The authority and the evidence, the enforced half, had no owner, because no product the bank had bought owned that seam. The agent waited another two quarters, not for a better model, but for a layer no single vendor could sell them.
Multiply that across an agent programme and the cost stops being one delayed pilot and becomes a portfolio stuck at a single gate. The bank in the composite had four agent use cases queued behind the same unanswered question, each duplicating the same semantic work and each failing the same second-line review for the same reason. The semantic investment was genuine and reusable. The unowned enforced half was the one dependency none of the four could clear on its own, and no additional semantic-layer maturity would move it. That is why this gap is strategic rather than tactical: it is not a feature missing from one project, it is a shared bottleneck sitting under every regulated agent the enterprise wants to ship. A CIO who reads the delay as 'the agents are not good enough yet' will keep buying model upgrades and keep hitting the same wall, because the wall is not made of model quality. It is made of an ownership gap, nobody accountable for enforcement and evidence across systems bought from different vendors, and ownership gaps do not close by waiting.
The objection: won't a standard just close the gap?
The strongest counter is that this is a temporary vacuum. The protocols are open, the need is obvious, and a governance extension or a category winner will emerge and make the whole discussion moot in a year or two. There is real force in this. Standards do converge, and some of what is bespoke today will be absorbed into platforms and protocols tomorrow.
But two things resist that tidy outcome. The first is that enforcement has to span systems bought from different vendors (a warehouse from one, case management from another, a fraud platform from a third), and no single vendor's standard governs a seam it does not own. The second is that the enterprises thinking hardest about this do not want their entitlement model, their policies, and their audit trail sealed inside whichever vendor wins. A standard for moving context is welcome and likely. A single owner of your cross-vendor enforcement and evidence is neither likely nor something a regulated business should want. That is precisely why this half stays open, and why owning it is the point.
What to do differently on Monday
If you are setting context-layer strategy, separate the two halves in your buying and your building. Buy the semantic layer where your data platform does it well; there is no prize for rebuilding governed metrics you can get off the shelf. But do not expect that purchase to govern your agents, and do not let a semantic-layer roadmap slide sold as 'agent governance' convince you the enforced half is handled.
Then ask one question of your own architecture, not a vendor's: who owns cross-vendor enforcement and the evidence trail at the moment an agent acts? If the answer is 'the data platform', you have probably confused the two halves. If the answer is 'nobody yet', you have found the work. Unlike the semantic half, it is work you will want to own rather than rent.
Where this leaves us
The land everyone can see being grabbed is the semantic layer, and the incumbents are winning it. The ground still open is the control layer above the protocols: recognised as the need, being prototyped in a dozen places, not yet delivered in a neutral, enterprise-owned form. That is the more valuable half precisely because it is harder and less settled.
Which turns on the distinction the whole series keeps circling: the difference between writing a policy down and making an agent physically unable to break it. That is where most 'governance' quietly falls apart, and it deserves its own piece.
Next: why writing the rule down is the easy part, and enforcing it is the job.
The Engineering Notebook
Once a month, a long read on what we're learning building governed AI for regulated enterprises. No hot takes, no roundups.
Ankur Chrungoo
Principal Engineer and Architect
Principal Engineer and architect at Bugni Labs, writing about production AI systems, agent governance, model controls, and regulated decisioning.
Related case studies
- Automating evidence extraction for regulatory narrativesReducing manual effort in regulatory narratives while improving traceability and consistency.
- Authorised payment fraud: designing for speed, signals and supervisionExperimenting with multi-agent fraud detection under tight sprint constraints.
- Building a cloud-native payment and data foundation for a new digital bankFrom concept to reference architecture, ISO20022 payments, data services and open banking adapters.
You might also enjoy
Agentic AI Is Not a Chatbot With Extra Steps
Unpack why agentic AI enterprise surpasses chatbots. Explore definitions, mechanisms, financial services examples, benefits like 3-5x velocity, and misconceptions for CIOs building governed AI systems.
PerspectiveBuild vs Buy for Enterprise AI
Compare building in-house AI solutions versus buying from vendors for enterprises. Review costs, timelines, pros, cons, stats, and top platforms to decide.
PerspectiveAI Vendor Lock-In Is a CIO Problem, Not Procurement's
AI vendor lock-in is usually fought as a pricing negotiation. In regulated institutions it is an architecture and concentration-risk decision the CIO owns.