
Most companies now run AI in several places at once. The hard part is not connecting to each one. It is working out that the same person is behind all four accounts, and that gets more expensive the longer you leave it.
Governing one AI is a solved problem. Governing several at once is not, and the reason has very little to do with any of them individually.
One number sets the shape of that work, and it is the one that decides what we build and in what order.
Menlo Ventures asked 495 enterprise AI decision makers in November 2025 which providers they use. No single provider has more than 40%.1
That chart is the whole engineering problem in one picture. There is no provider you can connect to and call the job done, because the largest one still leaves 60% of enterprise use somewhere else. Whichever AI you govern today, you are governing a minority of your own estate.
So the work is never one integration. It is the same job, done again, for every provider, forever.
That sounds like a scale problem. It is not. It is a shape problem, and it took building the second one to see it.
What this looks like from the engineering side
When we started building for a second provider, the connector was not the hard part. Connectors are work, not difficulty.
The hard part is that every provider is its own governance system. Its own admin console. Its own audit log. Its own way of naming things, its own list of events, and its own idea of who or what counts as doing something. When we counted on one provider, it came to 46 settings at the organisation level, 464 different types of event, and six kinds of actor, meaning the different things that can perform an action: people, service accounts, agents and so on. Very little of that lines up with the next provider. All of it moves when the provider changes its API.
A team can build that once. The cost is the second year, and the year after that, for every provider, forever.
Underneath it sits the thing that actually breaks governance. The same employee is a separate account in every system.
Here is what that looks like in practice. Someone joins the finance team and gets a Microsoft 365 account. Over the next year they turn up as a user in a second AI tool through a departmental pilot, as the owner of two projects in a third, and as a member of a workspace someone else set up in a fourth. Four systems now hold part of that person. Each one names them differently. Each records what they do in its own format, under its own ID, with its own view of what is worth recording. None of this is unusual, and none of it is joined up.
Four accounts, four IDs, four audit trails, and nothing connecting them. Ask what one person can reach across all the AI your company runs and no system can answer, because no system holds the whole person.
That is the gap we set out to close. Not seeing into AI. Seeing the estate the AI sits in.
The part that gets more expensive every month
The fair response at this point is that this is a next-year problem. Three reasons it is not, and all three are practical rather than commercial.
The mess grows, and nobody clears it up for you. We have watched this happen once already. Between 2015 and 2020, Microsoft 365 collaboration grew faster than anyone’s governance could keep up with. The companies that started governing after the sprawl spent years cleaning up what the companies who started before never had to. AI has the same shape. It just moves faster. Every month without governance means more accounts, more projects, more shared files and more permissions to sort out by hand later.
Audit logs are not archives. This one is specific to AI and it is the one most people miss. Retention is finite, and how long you get varies by provider and often by plan, so it is worth checking what yours actually keep. Whatever the window turns out to be, the principle holds. Turn governance on in eighteen months and you can see your estate as it stands that day. You cannot see how it got that way.
Every question a security team asks after an incident is about the past. The past you did not record is gone.
Agents change what governance is for. Until recently, AI answered questions. Now it acts. An agent has its own identity, holds its own permissions, and runs without anyone watching. Gartner expects 40% of business applications to have task-specific agents built in by the end of 2026, up from under 5% in 2025.2 Once AI acts instead of answering, controlling what it can reach stops being housekeeping. It becomes the thing that decides what an unsupervised system is allowed to do.
Why this cannot be fixed inside the tools
Every provider governs itself, and most do it well. Each one gives you an admin console, an audit log, a permissions model and a sensible set of controls for the thing it covers.
None of them governs across. That is not a criticism, and it is not a gap any of them will close. No provider can see inside another provider. None of them has a reason to build the view that would let you compare its own risk against a competitor’s. The information does not sit in one place, and nothing in the market is going to put it there.
So the question of what one person can reach across all your AI has no owner. The answer is not hard to find. No system is responsible for holding it.
That leaves one place for the answer to live. A layer above the tools, reading from all of them and owned by none of them.
The next question is what that layer is built around, and it decides whether it still works in three years.
Coverage is the obvious answer. Connect to as many providers as you can and show a list for each one. It demos well. It solves very little, because four lists still leave someone joining them up by hand, and the fifth provider adds a fifth list.
We are building around the person instead. Every AI account gets matched back to the same person in Entra ID, the directory the organisation already runs. AI users, projects, sessions, settings and spend then sit in the same inventory our customers already govern Microsoft 365 from. Same policies, same automation, same access reviews.
Identity is the right thing to build on for a simple reason. It is the only part that does not change. Providers come and go. Pilots end, departments switch tools, software gets replaced. The person stays, their job stays, and what they are allowed to reach is what the security team asks about. Governance built around the provider has to be rebuilt every time the provider list changes. Governance built around the person does not.
It also means nobody has to log into a fifth console to fix having four. AI becomes another set of things in a governance model the company already runs.
That approach costs us speed. It is slower to ship than a connector, and it only works where there is a directory to match against. It pays back on the second provider, and on every one after that, because the model does not change when the provider does.
What we are not going to do
We are not going to claim we can govern every AI. There is a sequence, it follows where enterprise usage actually sits rather than where we would prefer to start, and we will set it out in full on 1 October.
I would rather say that than something more impressive. A roadmap you can check is worth more than a claim that falls apart under the first technical question, and this audience asks it early.
What I can tell you now is the shape. Three providers account for roughly 80% of enterprise use,1 so most of the problem is reachable without boiling the ocean. And the long tail after that does not need a rebuild each time, because governance built around people does not have to be reinvented for every vendor.
What we look at, and what we do not
One more thing, because it is the first question in every security review we go through.
Rencore governs what AI can reach. We work from ownership, permissions, sharing and labels: who owns something, who can get to it, where it has been shared outside the company, and how it is classified. We do not read the contents of conversations, files or prompts to do that.
That is a design decision, not a limitation we are working around. Access is where the risk sits. An agent is only as safe as the data it can reach, and you do not need to read the content to control the access.
The Multi-AI Era: the vision and the roadmap
Webinar, 1 October 2026, 16:00 CET. Matt Einig covers where Rencore is going and why. I cover what governs more than one AI from a single place today, what is being built next, and in what order.
Sources
- Menlo Ventures, “The State of Generative AI in the Enterprise”. Published November 2025. 495 US enterprise AI decision makers, surveyed 7 to 25 November 2025. Used here for: which AI providers enterprises use. Anthropic 40%, OpenAI 27%, Google 21%, all others 12%.
- Gartner press release, 26 August 2025. “Gartner Predicts 40% of Enterprise Applications Will Feature Task-Specific AI Agents by End of 2026.” Used here for: 40% of business applications having task-specific AI agents built in by the end of 2026, up from under 5% in 2025.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organisation and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Last updated 25 September 2026


