企業 AI エージェント管理難題、xpander が制御層と文脈層の自社所有を提案
本文の状態
日本語全文を表示中
詳細モードで約25分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
Gartner の予測によると企業は AI エージェントの管理に遅れをとっており、xpander.ai はモデルやベンダーに依存しない制御層を提供するプラットフォームを一般公開し、資金調達も発表した。
AI深層分析を開く2026年8月18日 00:34
AI深層分析
キーポイント
AI エージェントガバナンスのギャップ拡大
Gartner の調査では、2028 年には平均的な Fortune 500 企業で 15 万個以上の AI エージェントが稼働すると予測される一方、適切なガバナンス体制を持つ組織はわずか 13% に留まっている。
ベンダー中立な制御層の提供
xpander.ai は、複数のモデルやフレームワークにまたがるエージェントの構築・実行・管理を担うベンダー中立の制御 plane を一般公開し、特定の AI プロバイダーへのロックインを防ぐことを目指す。
新たな依存関係と移行リスク
xpander の独自ハーネスは機能を提供するが、その設定や運用状態の他プラットフォームへの移行性が公開ドキュメントで明確にされていないため、制御層自体への新しいロックインが発生する可能性が指摘されている。
シードラウンドの発表
同社は Pico Venture Partners の主導により 750 万ドルの資金調達を行い、Samsung Next や Emerge Ventures などの投資家から支援を受けたことを発表した。
フレームワークに依存しない制御層の必要性
競合他社も柔軟なデプロイを提供する中、xpander の差別化はモデルやエージェントフレームワークが混在する環境で動作するフレームワーク非依存の制御層にある。
重要な引用
The third issue is the most critical part: it's being locked into one vendor.
Everything that you do is actually owned by the company that you chose to work with — their tools, their roadmap, their political view of how agents should react to everything that you do.
"Multi-cloud, multi-vendor is a must-have strategy."
"Our strategy was to bring the great thing called cloud computing and then try to create solutions that are serverless and, by definition, create vendor lock-in," Twizer told VentureBeat.
編集コメントを表示
編集コメント
xpander.ai が掲げるベンダー中立の制御層は、AI エージェントの普及に伴うガバナンス課題への有効な解決策となり得るが、その移行性の不明確さが新たな依存リスクを生むという皮肉な指摘も含まれている。業界全体として、単なるモデルの置き換えではなく、管理基盤自体の標準化とポータビリティが次の重要な争点となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
エンタープライズAIには新たなインフラ課題が浮上しています。企業は、それを統制するシステムを開発する速度よりも速いペースでAIエージェントを蓄積しているのです。
ガートナーの試算によると、世界のフォーチュン500社の平均的な企業が保有するAIエージェント数は2028年までに15万個を超えると予測されています。これは2025年の15個未満から劇的に増加した数値です。しかし同調査会社によれば、現在適切なガバナンス体制が整っていると回答している組織はわずか13%に過ぎません。
この格差の拡大が、個別のモデルやエージェントの上に位置するインフラ市場を生み出しています。この層では、実行、権限管理、可観測性、メモリ、エンタープライズシステムへのアクセス、ライフサイクル管理といった機能を担いますが、開発者が新しいエージェントごとにこれらのサービスを再構築する必要はありません。
元AWSのシニアエンジニア3名が設立したスタートアップ「xpander.ai」は、この層を支配しようとする最新企業の1つです。
同社は本日、エンタープライズAIエージェントプラットフォームの一般提供を開始しました。これは、異なるモデルやエージェントフレームワーク、インフラ環境にまたがってエージェントを構築・実行・管理するためのベンダー中立なコントロールプレーンとして位置づけられています。
VentureBeatとの独占インタビューで、xpander.aiのCEO兼共同創業者であるDavid Twizer氏は、企業が抱える3つの主要な課題について語りました。それは、中央集権的なガバナンスなしでローカルで動作するエージェント、個々のユーザーに孤立したままのエージェントワークフロー、そして単一のAIプロバイダーにインフラが縛られてしまう状況です。
「3 つ目の課題が最も重要です。特定のベンダーにロックインされてしまう点です」と Twizer 氏は VentureBeat に語りました。「あなたが行うすべてのことが、あなたが選んだ企業の所有物になってしまいます。その企業が持つツールやロードマップ、そしてエージェントがあなたの行動に対してどう反応すべきかという政治的な見解まで、すべてが企業によって支配されるのです。」
ただし注意すべきは、xpander のベンダー中立性が依存関係を完全に排除するわけではない点です。依存関係の所在が、スタックの上層へと移転しているだけです。xpander の下では、エンタープライズはモデルやフレームワーク、インフラを自由に切り替えることができます。しかし、その実行・ガバナンス・アイデンティティ管理・メモリ・監査可能性を調整する役割を担うのは、xpander 独自のユニバーサルハーネスとコントロールプレーンです。
もしこれらの設定や運用状態が別のコントロールプレーンへ移行しにくいものとなれば、新たな形のロックインが生じる可能性があります。xpander の公開ドキュメントにはまだ、顧客がエンタープライズライセンスを解約した場合にこの層がどの程度ポータブルであるかについての説明がありません。
同社はまた、Pico Venture Partners が主導し、Emerge Ventures、Samsung Next、SeedIL が参加する 750 万ドルのシードラウンドを発表しました。
しかし、xpander が参入するのは、単なる独占的なハイパースケーラープラットフォームと中立な代替案との単純な二項対立を超えて進化を遂げた市場です。
戦いの場はモデルの上層へと移っている
エージェントインフラにおけるモデルのポータビリティ(移植性)は、ますます一般的になりつつあります。
LangChain の LangSmith は、生産環境で動作するエージェントのデプロイとガバナンスのためのインフラストラクチャを提供します。企業は、エアギャップされた環境やデータ所在地に敏感なケースを含め、制御プレーンとエージェントサーバーを自社の Kubernetes インフラ上で完全に運用できます。また、顧客がエージェントサーバーを運営し、LangChain が制御プレーンを管理するハイブリッドデプロイも提供しています。
CrewAI も同様の方向へ進んでいます。そのエンタープライズ版には、集中型ガバナンス、SSO(シングルサインオン)、ロールベースのアクセス制御、ワークロードアイデンティティとポリシーが含まれており、CrewAI のクラウド上、顧客の VPC、あるいは顧客が所有するインフラでのデプロイをサポートしています。同社は、自社のプラットフォームが複数のモデルやクラウドにまたって機能し、顧客が生成されたコードを保持・修正できる点を強調しています。
Temporal は別のアプローチでこの問題に取り組んでいます。エンドツーエンドのエージェント管理環境を提供するのではなく、クラッシュからの回復、リトライ、人間の承認、障害を越えて状態を維持する機能など、長時間実行される AI ワークフローのための永続的な実行環境を提供します。その AI プラットフォームは、異なるモデル、ツール、システムにまたるワークフローのオーケストレーションも可能です。
一方、モデルやクラウドベンダー自身も、このインフラ層へと事業領域を拡大しています。OpenAI の Frontier プラットフォームは、共有された企業コンテキスト、権限管理、エージェントの実行と管理を提供します。また Google の Gemini Enterprise Agent Platform は、マネージドなランタイム基盤に、エージェント間やツールとの相互作用に関するアイデンティティ、中央集権的なガバナンス、メモリ機能、トレーシング、ポリシー適用を組み合わせています。
つまり、xpander の差別化要因は単に「企業が 1 つのモデルプロバイダーのクラウド外でエージェントを実行できる」という点だけでは不十分です。その柔軟性を提供するバージョンを持つ競合他社はすでに複数存在します。
xpander が賭けているのは、企業が多様なモデル、エージェントフレームワーク、従業員向け AI インターフェースが混在する環境において、特定のフレームワークに依存しない制御プレーン(コントロールプレーン)を上位層に望むという点です。
Twizer 氏の主張は、彼が AWS で過ごした 7 年間の経験にも一部基づいています。その間、企業は過去のインフラロックインと格闘する姿を目の当たりにしました。
「私たちの戦略は、クラウドコンピューティングという素晴らしいものを持ち込み、サーバーレスなソリューションを構築し、定義上、ベンダーロックインを生み出すことでした」と Twizer 氏は VentureBeat に語りました。しかし、最終的に企業側が求めたのは、ワークロードをプロバイダー間で移動させる能力だと彼は付け加えました。
「AI も同じです。マルチクラウド、マルチベンダーは必須の戦略です」
モデルの入れ替わりにも耐えるランタイム
xpander プラットフォームの中心にあるのが、同社が「ユニバーサル・ハーネス」と呼ぶ実行環境です。これはモデルやフレームワーク、クラウドベンダーに依存しないランタイムであり、エージェントをポータブルなエンタープライズ・ワークロードとして実行することを可能にします。
企業は xpander のホスト型環境を利用することもできますし、エンタープライズ向けプランでは Kubernetes やオンプレミスインフラストラクチャ上で自己デプロイも可能です。同社は AWS、Google Cloud、Microsoft Azure、プライベート VPC、そして完全にエアギャップされたオンプレミス環境など、サポート対象のデプロイ先を明確にリストしています。
フレームワークに関する主張も同様にはっきりしています。xpander によれば、顧客は LangChain、Strands、Agno などを用いて構築したエージェントや、既存のプロンプト、ルール、スキルを持ち込むことができます。また、独自モデル、オープンウェイトモデル、顧客が微調整を施したモデルにも対応しています。
開発者向けには、主に 3 つの統合ルートを提供します。制御プレーン操作用の言語非依存 REST API、エージェントやワークフロー構築のための Python SDK、そして Claude Desktop や Cursor などの MCP クライアントにエージェントとツールを公開する Model Context Protocol (MCP) サポートです。REST インターフェースにはエージェント、タスク、ナレッジベースの管理・呼び出しオペレーションが含まれ、SDK ではイベント処理やエージェントライフサイクルの抽象化が追加されています。
「これは、自社の敷地内、プライベートクラウド、あるいは xpander クラウド内で稼働する Kubernetes 環境のように考えてください」と Twizer は VentureBeat に語りました。「このハーネスはベンダーを問わないため、あらゆるベンダーのエージェントを実行できます。」
Twizer 氏は、最終的な目標はモデル選択をアプリケーション下の計算リソースを選ぶことと同様に扱い、組織が特定のソフトウェアエコシステムに縛り付けることを避けることだと語りました。
「Claude から ChatGPT、Kimi、そして自社でファインチューニングしたモデルへも移行できます」と彼は説明します。「これらはすべて CPU を使用するのと同じように利用されます。誰が製造しているかはあまり気にせず、アプリケーションが正常に動作すればそれでよいのです。」
このアーキテクチャは、基盤となるワークロードを変更しつつ、オーケストレーションと運用層を比較的安定した状態に保つことを意図しています。
企業が複数の AI ベンダーを利用するようになれば、この区別はより重要になるでしょう。OpenAI 自身も、エンタープライズ AI は支援からエージェントが代行する業務へと移行していると述べています。最新の企業データでは、法務、営業、採用、マーケティングなど各機能において、エージェントによる利用が急速に増加していることが示されています。
同時に、Google も大規模なベンダーとして、エージェントとツールの相互作用をスケールして管理するために、集中的なエージェントガバナンス、ID 管理、ゲートウェイ制御の追加を進めています。こうした大手ベンダーからの投資は、xpander の基本的な前提を裏付けるものです。つまり、エージェントを実運用に投入する際、モデル管理だけが課題なのではなく、その一部に過ぎないということです。
実務における「ガバナンス」の意味
Twizer 氏は、ローカルで動作するエージェントが、この運用上の問題を特に深刻化させると指摘しています。
「社員のノートパソコンに Claude や ChatGPT、Codex、あるいは他の AI システムをインストールすると、それはブラックボックス化します」と彼は VentureBeat に語った。「何のガバナンスも機能せず、監査もされず、制御も効かないのです。」
彼の懸念は、単にエージェントがローカルリソースにアクセスできる点だけではありません。AI プロダクトがテキスト生成からアクション実行へと急速に進化する一方で、企業側にはそれを支える同等のガバナンス基盤が整っていないという問題です。
「一夜にして、『メール作成を支援するチャットボット』から『マシンを制御し API 呼び出しを実行できる AI エージェント』へとシフトしました」と Twizer は述べています。
xpander のドキュメントでは、この活動をガバナンスされた環境へ移行させる際に同社が何を意味するのか、より具体的な定義が示されています。
コントロールプレーンでは、誰がエージェントを起動できるか、エージェントがアクセス可能なリソースは何か、そしてどのアクションに人間の承認が必要かを定義できます。xpander によれば、エージェントには名前付きのアイデンティティが付与され、実行されたアクションはそれを呼び出した人間まで遡って追跡可能です。ツール呼び出し、実行履歴、トレーシング、承認、失敗のすべてがログ記録され、コストはタスクレベルで明確に把握できます。
セキュリティチームにとって特に重要なアーキテクチャ上の詳細として、認証情報の扱いがあります。xpander によると、ツール呼び出しの実行時に Vault から認証情報が注入されるため、モデルに対して直接公開されることはありません。
同社は SOC 2 Type II の認証を取得し、GDPR にも準拠しています。エンタープライズ版には SSO や OIDC、プライベートなモデルゲートウェイに加え、チームごとの利用状況を追跡できるサブ組織機能も含まれています。
xpander が LangSmith や CrewAI と差別化を図っている点は、独自の開発環境として自社のフレームワークを押し付けるのではなく、基盤となるエージェント・フレームワーク自体を交換可能なコンポーネントの一つと捉えている点にあります。
同社によると、そのランタイムでは xpander ネイティブのエージェントだけでなく、他のフレームワークで構築されたカスタムエージェントも同時に動作可能です。この広範なフレームワーク中立性は企業の主張に過ぎず、実際の運用環境での実証が求められます。すでにこれらのプラットフォーム間には相当な重複が見られるからです。
エージェント層を自社で構築するコスト
ベンダーのインフラを導入せず、中央集権的な管理を実現したい企業にとって、選択肢はこれらのコンポーネントを自前で組み立てることに移りつつあります。
Twizer 氏は、ここで生産環境におけるエージェントの隠れたコストが顕在化すると指摘します。基盤モデルへのアクセス自体は比較的容易ですが、高度なマネージド型エージェントを取り巻く運用インフラを再現するのはそう簡単ではありません。
「Anthropic の Claude Code のような素晴らしいものを、ガバナンスとセキュリティを確保した形で実現したいなら、ハッチ全体を構築する必要があります」と Twizer 氏は VentureBeat に語りました。「サンドボックスや認証、人間が関与するループ、ストレージ、セッション管理、そしてメモリ層まで、すべてを自前で実装しなければなりません。」
「セキュアな方法でエージェントを実行するために、インフラストラクチャに 2 年分の投資をするようなものです」と彼は付け加えました。
同社のドキュメントによると、このハーン(harness)は長期かつ多ツールを要するタスクの処理、サンドボックス化されたコード実行、永続的なメモリ管理、そしてタスクが失敗したり逸脱した際の回復機能に対応しています。これは Twizer 氏の主張を理解する上で重要な文脈です。xpander は単にモデル API を別のものへ置き換えるゲートウェイを提供しているわけではありません。企業がこれらの API と並行して運用せざるを得ない多くのランタイムサービスを、パッケージ化して提供しようとしているのです。
Twizer 氏は、生産環境で自社の技術を利用する政府機関や金融機関から、このインフラの負担がエージェントを統制された形で展開することを阻んでいるという声を聞いていると語りました。
同社のウェブサイトでは、「Used by teams at(以下チームで使用)」というラベルの下に、Lenovo、Intel、Workday、Siemens、Nvidia、Intuit、SAP、PagerDuty、Mozilla、Salesforce などのロゴが並んでいます。
同社が提案するのは、Anthropic や OpenAI など他の AI プロバイダーの製品を放棄することではありません。Twizer 氏はむしろ、これらのモデル自体は維持しつつ、権限管理、監視、実行機能を企業が制御するインフラストラクチャ層へ移行すべきだと主張しています。
「Claude を使うな」という話ではありません」と彼は言います。「Claude を使うことは問題ありません。ただし、それを監視し、セキュリティを確保し、モニタリングできる形で利用することです。許可されたスキルや、特定のリソースへのアクセス権限に対するコントロールも必要になります」
エージェントを個人のものから組織的な資産へ転換する
xpander はさらに、マルチプレイヤー AI と呼ぶコラボレーション機能のレイヤーを追加しています。
この仕組みの前提は、エンタープライズ向けのエージェントが単一のユーザーによるチャットセッションを超えて存続する必要性が高まっているという点です。例えば、あるエージェントがデータを収集し、別のシステムがアクションを実行し、従業員が承認し、数時間や数日後に異なるチームがプロセスを再開するというワークフローが存在します。
Twizer 氏は、ローカルで展開されたアシスタントにはもう一つの欠点があると指摘しています。それは、従業員がエージェントを通じて蓄積した専門知識——プロンプト、スキル、ワークフロー、コンテキストなど——が個人に留まってしまう傾向があるという点です。
「AI エージェントはより良くなりますが、会社自体は良くならないのです」と Twizer 氏は VentureBeat に語りました。「このエコシステムに投資しているすべてのデータ、すべてのプロンプト、すべてのワークフロー、すべてのスキルがベンダーの内部にロックされ、他の同僚と共有するのが非常に困難になっています。」
さらに複雑なエンタープライズ業務は、単一のチャットセッションにきれいに収まることはめったにありません。
「仕事は一人プレイではありません。マルチプレイヤーなのです」と Twizer 氏は述べています。「数日、場合によっては数週間にわたって行われるものです。企業にとって重要なワークフローは、チャットボットのようなものではありません。」
xpander の共有会話機能は、これらの対話を永続的で権限スコープに限定されたスレッドとして維持するように設計されています。エージェントは一度公開されれば組織全体で利用可能になり、従業員は Slack、Teams、ChatGPT、Claude、および xpander 独自のインターフェースを通じてエージェントと対話することができます。
同社のドキュメントによると、下流のアクションは OIDC を用いたエンドツーエンド認証を通じて、エージェントを呼び出した人間として識別可能になります。これは、作業がエージェント間を移動する際にもユーザーレベルのアイデンティティと権限を維持する必要がある組織にとって、重要な区別となります。
継続的な実行が必要という要件は xpander 固有のものではありません。Temporal は長期間稼働し障害に強いワークフローを AI プラットフォームの中核として掲げており、LangSmith もエージェントの永続的デプロイと本番環境での観測機能をサポートしています。
xpander が目指しているのは、こうしたランタイム基盤を、エンタープライズ向けのコラボレーションやガバナンス機能と統合し、単一のポータブルで柔軟なベンダー中立型のコントロールプレーンにまとめることです。
Omni でハッチの仮説を検証
同社はまた、事前構築済みのエージェント「Omni」の一般提供を開始しました。
Omni を単なる汎用エージェントと表現するのは、xpander が現在販売しているものの本質を過小評価することになります。ドキュメントでは Omni は「AI による先遣エンジニア」として位置づけられ、要求されたビジネス成果を同社が「エージェント型アプリケーション」と呼ぶものへと変換すると説明されています。これはバックエンドのエージェントとチャットやインタラクティブな UI コンポーネント、レポート、ダッシュボード、可視化機能を備えたフロントエンド体験を組み合わせたものです。
ユーザーは望む成果を記述するだけで、Omni がアプリケーションの構築、モデル・スキル・ツール・データの接続、追跡可能なタスクとしての業務実行、そしてファイルや再利用可能なコンテキストの管理を Agent Workspace 上で支援します。こうして完成したアプリケーションは、チームメンバーと共有可能です。
例えば、xpander のドキュメントには、ユーザーが Omni に「Redshift Analyzer」の構築を依頼する事例が記載されています。Omni は要件の収集からインターフェース設計、バックエンドエージェントの構築、適切なコネクタやツールの接続、そして最初のライブアプリケーション画面の生成までを一貫して担います。
ドキュメントでは Slack、WhatsApp、Telegram、メールを Omni のチャネルとして挙げていますが、xpander のプラットフォーム全体に関する資料には、Teams、Claude、ChatGPT、API、Webhook、CLI、MCP などもエージェントへの入力経路として含まれています。Omni とプラットフォーム全体で扱われるチャネルセットが若干異なるため、各企業は自社の特定のインターフェースやデプロイ構成に対応しているか確認する必要があります。
Omni は既存のデスクトップ向け AI プロダクトを置き換えるのではなく、併用することも可能です。Twizer 氏によれば、従業員は引き続き好みのデスクトップエージェントを利用でき、Omni は企業が承認したデータとコネクタのみを公開するスキル層として機能します。また、バックグラウンドでの実行が必要な場合は、Omni が中央管理されたエージェントを作成して業務を実行します。
xpander は、Omni が GAIA ベンチマークで 90.9% のスコアを記録したと発表しています。これは最も困難なタスクでも高い性能を示した結果です。この数値は企業側が報告したものであり、プラットフォームの独自検証というよりは、xpander のより広範な主張を裏付ける根拠として捉えるべきものです。
Twizer 氏は、同社が単一の独自システムに最適化するのではなく、さまざまなモデルを組み合わせてハネス(実行基盤)でテストしたと説明しました。
「Opus、Sonnet、Kimi、GPT を使い分け、ベンチマークで 90.9% のスコアを達成しました」と VentureBeat に語っています。
Twizer 氏にとって、この結果はエージェントの性能が基盤モデルそのものよりも、それを支えるインフラストラクチャに依存するようになっているという主張を裏付けるものです。
「価値があるのはモデル層ではなく、ハネス層にあることが証明されました。重要なのは、長時間実行されるタスクをどう処理するか、ツール呼び出しをどう管理するか、サンドボックス化をどう行うか、そしてエージェントがタスクに集中できる状態をどう維持するかです」と彼は述べています。
ベンチマークの結果は公開されており、他社も同社の手法を検証できますが、より広い結論については xpander による独自の解釈にとどまります。
この考え方は業界全体で共有されつつありますが、焦点となっているのは「その層を誰が制御すべきか」という点です。
OpenAI と Google は、これを広範な AI プラットフォームの一部として位置づけようとしています。LangChain や CrewAI は開発エコシステムを企業向けランタイムへと拡張しています。一方、Temporal は実行の問題をインフラストラクチャの観点から解決しようとしています。
xpander は、企業が求めるコントロールプレーンが、モデル・クラウド・エージェントフレームワークのいずれにも依存しない独立したものであるべきだと考えています。
同社はすでに混雑しつつあるエンタープライズ AI スタックに、もう一つのプラットフォームを追加する価値があることを示す必要があります。そのためには、この追加された抽象化層が十分に価値あるものでなければならないのです。
価格と利用状況
xpander のプラットフォームと Omni は現在、一般提供されています。チーム向けには xpander が提供するホストサービスを利用するモデルを、企業向けには自社のインフラ上でプラットフォームを稼働させるモデルを提供しており、両者で商業モデルは大きく異なります。
セルフサービスの Team オファリングでは、ユーザー数に応じた料金(シートチャージ)はなく、エージェントの活動量に基づいてクレジット課金されます。xpander によると、1 クレジットは 1 セントに相当し、$100 で 10,000 クレジットを購入できます。エージェントを起動する各イベントやメッセージには、ターン(処理サイクル)がどの程度長くても、そのターン全体で 1 クレジットがかかります。また、ツール呼び出しや API 呼び出しを行うたびに、さらに 1 クレジットが発生します。モデルのトークン使用量は、選択したモデルに応じて設定されたレートでクレジット単位で別途請求されます。
この料金体系は、Twizer が「エージェントからの出力」に対して課金すると説明しているものよりも、より細かく設計されています。公開されている価格情報によると、実行時間が長いこと自体が時間ベースの課金要素となることはありません。ただし、ワークフロー内での繰り返し呼び出し、ツール呼び出し、モデルトークンの消費が積み重なることで、コストは増加します。
新規アカウントには、期間限定の無料トライアルではなく、1,000 クレジットが無料で付与されます。クレジットカードでの登録も可能です。xpander によると、チーム版ではエージェント、ワークフロー、ユーザー席数に制限はありません。
モデルの利用料は総コストの大きな割合を占めることがあり、同社は費用の見積もりを可能にするための事例を公開しています。料金ページには個別のモデルごとの入力・出力トークン単価が記載されており、これらのモデル利用料はクレジットシステムに含まれるため、ホスト型顧客には別々のプロバイダー請求書が発生しない仕組みです。実際の支出額は、選択したモデルの種類、トークンの総量、およびツール呼び出し回数に大きく依存します。
自社でホストする企業向けには異なる契約形態が用意されています。xpander のエンタープライズプランは年間ライセンス制で、50 エージェント以上からの導入に対応し、c へのデプロイをサポートしています。
原文を表示
Enterprise AI has a new infrastructure problem: companies are accumulating agents faster than they are developing systems to govern them.
Gartner estimates that the average global Fortune 500 company will have more than 150,000 AI agents in use by 2028, up from fewer than 15 in 2025. Yet only 13% of organizations believe they currently have the right AI agent governance in place, according to the research firm.
That widening gap is creating a market for infrastructure that sits above individual models and agents — handling execution, permissions, observability, memory, access to enterprise systems and lifecycle management without forcing developers to reconstruct those services for every new agent.
xpander.ai, a startup founded by three former AWS principal engineers, is the latest company trying to own that layer.
The company is making its enterprise AI agent platform generally available today, positioning it as a vendor-neutral control plane for building, running and governing agents across different models, agent frameworks and infrastructure environments.
In an exclusive interview with VentureBeat, xpander.ai CEO and co-founder David Twizer said the company increasingly hears three problems from enterprise customers: agents running locally without centralized governance, agent workflows remaining isolated to individual users, and infrastructure becoming tied to a single AI provider.
“The third issue is the most critical part: it’s being locked into one vendor,” Twizer told VentureBeat. “Everything that you do is actually owned by the company that you chose to work with — their tools, their roadmap, their political view of how agents should react to everything that you do.”
The caveat is that xpander’s vendor neutrality does not eliminate dependency; it moves the dependency up the stack. Enterprises can swap models, frameworks and infrastructure underneath xpander, but xpander’s proprietary Universal Harness and control plane become the layer coordinating execution, governance, identity, memory and auditability.
That could create a new form of lock-in if those configurations and operational state are difficult to migrate to another control plane. xpander’s public documentation does not yet explain how portable that layer is if a customer terminates its enterprise license.
The company is also announcing a $7.5 million seed round led by Pico Venture Partners, with participation from Emerge Ventures, Samsung Next and SeedIL.
But xpander is entering a market that has evolved considerably beyond a simple divide between proprietary hyperscaler platforms and neutral alternatives.
The battle is shifting above the model
Model portability is becoming increasingly common in agent infrastructure.
LangChain's LangSmith Deployment, for example, provides infrastructure for deploying and governing production agents. Enterprises can run its control plane and agent servers entirely inside their own Kubernetes infrastructure, including for air-gapped and data-residency-sensitive environments. LangChain also offers hybrid deployments in which the customer operates agent servers while LangChain manages the control plane.
CrewAI is moving in much the same direction. Its enterprise offering includes centralized governance, SSO, role-based access controls, workload identity and policies, while supporting deployment in CrewAI's cloud, a customer's VPC or customer-owned infrastructure. CrewAI says its platform can work across models and clouds and lets customers retain and modify the code generated for their agents.
Temporal approaches the problem from another direction. Rather than offering an end-to-end agent management environment, it provides durable execution for long-running AI workflows, including crash recovery, retries, human approvals and state that can persist through failures. Its AI platform can orchestrate workflows across different models, tools and systems.
Meanwhile, the model and cloud vendors themselves are expanding upward into this infrastructure layer. OpenAI's Frontier platform provides shared enterprise context, permissions, agent execution and management, while Google's Gemini Enterprise Agent Platform combines managed runtime infrastructure with agent identity, centralized governance, memory, tracing and policy enforcement around agent-to-agent and agent-to-tool interactions.
In other words, xpander's differentiator cannot simply be that enterprises can run agents outside one model provider's cloud. Several competitors already offer versions of that flexibility.
Its bigger bet is that enterprises will want a framework-independent control plane sitting above an increasingly heterogeneous collection of models, agent frameworks and employee-facing AI interfaces.
Twizer's argument draws partly on his seven years at AWS, where he watched enterprises wrestle with a previous generation of infrastructure lock-in.
“Our strategy was to bring the great thing called cloud computing and then try to create solutions that are serverless and, by definition, create vendor lock-in,” Twizer told VentureBeat. But, he said, enterprises ultimately demanded the ability to move workloads among providers.
“I think AI is no different,” he said. “Multi-cloud, multi-vendor is a must-have strategy.”
A runtime intended to survive model churn
At the center of xpander's platform is what it calls a Universal Harness — a model-, framework- and cloud-agnostic runtime for executing agents as portable enterprise workloads.
Companies can use xpander's hosted environment or, under its enterprise offering, self-deploy on Kubernetes or on-premises infrastructure. The company also explicitly lists AWS, Google Cloud, Microsoft Azure, private VPCs and fully air-gapped on-premises environments as supported deployment targets.
The framework claim is similarly broad: xpander says customers can bring agents built with frameworks including LangChain, Strands and Agno, as well as their existing prompts, rules and skills. It supports proprietary, open-weight and customer fine-tuned models.
For developers, xpander exposes three main integration routes: a language-agnostic REST API for control-plane operations, a Python SDK for building agents and workflows, and Model Context Protocol support that exposes agents and tools to MCP clients such as Claude Desktop and Cursor. The REST interface includes operations for managing and invoking agents, tasks and knowledge bases, while the SDK adds event handling and agent lifecycle abstractions.
“Think like a Kubernetes environment that runs inside your own premises, your private cloud or our xpander cloud,” Twizer told VentureBeat. “The harness that is agnostic can run any agent of any vendor.”
Twizer said the goal is eventually to make model selection more analogous to choosing compute underneath an application than committing an organization to an entire software ecosystem.
“You can go from Claude to ChatGPT to Kimi and to your own fine-tuned models,” he said. “All of them will be used in the same way that you use CPUs. You don’t really care who makes them. You just want your application running.”
That architecture is intended to let the underlying workloads change while the orchestration and operational layer remains relatively stable.
The distinction could become more important as enterprises use more than one AI supplier. OpenAI itself says enterprise AI is shifting from assistance toward delegated work performed by agents, with its latest enterprise data showing rapidly growing agentic usage across functions including legal, sales, recruiting and marketing.
At the same time, Google is adding centralized agent governance, identity and gateway controls specifically to manage interactions between agents and tools at scale. Those investments from much larger vendors reinforce xpander's basic premise: managing the model is increasingly only one part of putting agents into production.
What 'governance' means in practice
Twizer argues that locally running agents make that operational problem particularly acute.
“You install Claude or ChatGPT or Codex or any other AI system that runs on the employee laptop, and you get a black box,” he told VentureBeat. “Nothing is governed, nothing is audited, and nothing is controlled.”
His concern is not simply that an agent can access local resources, but that AI products have rapidly moved from generating text to taking actions without enterprises necessarily building equivalent governance infrastructure around them.
“It happened overnight that the shift from, ‘Here is the chatbot that helps me write an email,’ became, ‘It is an AI agent that can control my machine and perform API calls,’” Twizer said.
xpander's documentation provides a more concrete definition of what the company means by moving that activity into a governed environment.
The control plane can define who is allowed to run an agent, which resources the agent can reach and which actions require human approval. xpander says agents receive named identities and actions can be traced back to the human who invoked them. Tool calls, runs, traces, approvals and failures are logged, with spending attributable at the task level.
One particularly relevant architectural detail for security teams is credential handling. xpander says credentials are injected from a vault when a tool call executes, rather than being exposed directly to the model.
The company says it is SOC 2 Type II certified and GDPR compliant. Its enterprise tier also includes SSO and OIDC, a private model gateway and sub-organizations with per-team usage attribution.
Where xpander is trying to separate itself from products such as LangSmith and CrewAI is in treating the underlying agent framework itself as another replaceable component rather than making its own framework the primary development environment.
The company says its runtime can operate xpander-native agents alongside custom agents built with other frameworks. That broader framework neutrality is a company claim and will need to prove itself in production; the overlap among these platforms is already substantial.
The cost of building the agent layer yourself
For enterprises that want centralized control without adopting another vendor's infrastructure, the alternative is increasingly to assemble many of these components themselves.
Twizer argues that this is where the hidden cost of production agents emerges. Accessing a foundation model is comparatively straightforward; recreating the operational infrastructure surrounding a sophisticated managed agent is not.
“If you want to do something like the amazing [Anthropic] Claude Code in a way that is governed and secure, you need to build the entire harness,” Twizer told VentureBeat. “You need to build the sandbox and the authentication and the human in the loop and the storage and the session management and the memory layer.”
“It’s like investing two years of infrastructure just to run that agent in a secure way,” he added.
The company's documentation says its harness handles long-horizon and multi-tool tasks, sandboxed code execution, persistent memory and recovery when tasks fail or drift. That is important context for Twizer's argument: xpander isn't merely offering a gateway that swaps one model API for another; it is attempting to package many of the runtime services enterprises otherwise have to operate alongside those APIs.
Twizer said xpander has heard from government organizations and financial institutions using its technology in production that this infrastructure burden was preventing them from deploying agents in a controlled way.
The company's website separately displays logos for organizations including Lenovo, Intel, Workday, Siemens, Nvidia, Intuit, SAP, PagerDuty, Mozilla and Salesforce under the label “Used by teams at.”
The company's answer is not that enterprises should abandon products from Anthropic, OpenAI or other AI providers. Twizer instead argues that companies should retain those models while moving permissions, monitoring and execution into an infrastructure layer they control.
“It’s not, ‘Don’t use Claude,’” he said. “It’s actually, ‘Use Claude, but in a way that you watch it, that you secure it, that you monitor it,’” with controls over authorized skills and who can access particular resources.
Making agents organizational rather than personal
xpander is also adding a collaboration layer it calls Multiplayer AI.
The premise is that enterprise agents increasingly need to outlive a single user's chat session. A workflow might involve an agent collecting data, another system taking an action, an employee approving it and a different team resuming the process hours or days later.
Twizer argues that locally deployed assistants have another disadvantage: the expertise employees accumulate through their agents — prompts, skills, workflows and context — tends to stay with those individuals.
“You’re making the AI agents better, and you’re not making the company better,” he told VentureBeat. “All the data, all the prompts, all the workflows, all the skills that you are now investing in that ecosystem are being locked inside that vendor, and it’s very hard to share it with other colleagues.”
More complex enterprise work also rarely maps neatly onto a single chat session.
“Work is not single player. It’s multiplayer,” Twizer said. “It’s happening over the period of multiple days, even weeks. Workflows that are significant to enterprises are not chatbots.”
xpander's shared conversations are designed to keep those interactions in persistent, permission-scoped threads. An agent can be published once for use across an organization, while employees can interact with agents through Slack, Teams, ChatGPT, Claude and xpander's own interface.
The company's documentation says downstream actions can identify as the human who invoked the agent through end-to-end authentication using OIDC — a potentially important distinction for organizations that need to preserve user-level identity and authorization as work moves through an agent.
The requirement for persistent execution is not unique to xpander. Temporal has made long-running, failure-resistant workflows the core of its AI pitch, while LangSmith supports persistent agent deployment and production observability.
What xpander is attempting to combine is that runtime infrastructure with enterprise collaboration and governance into a single, portable, flexible, vendor-neutral control plane.
Omni tests the harness thesis
The company is also making Omni, its prebuilt agent, generally available.
Calling Omni simply a general-purpose agent understates what xpander is now selling. Its documentation describes Omni as an AI forward-deployed engineer that turns a requested business outcome into what the company calls an “Agentic Application”: a backend agent coupled with a frontend experience that can include chat, interactive UI components, reports, dashboards and visualizations.
A user can describe the desired outcome, after which Omni is designed to help construct the application, connect its model, skills, tools and data, execute work as tracked tasks, and maintain files and reusable context in an Agent Workspace. The resulting application can then be shared with teammates.
For example, xpander's documentation shows a user asking Omni to build a Redshift Analyzer. Omni is intended to gather the requirements, design the interface, construct the backend agent, attach appropriate connectors and tools, and generate the first live application surface.
The documentation also lists Slack, WhatsApp, Telegram and email as Omni channels, while xpander's broader platform materials list Teams, Claude, ChatGPT, API, webhook, CLI and MCP among the ways work can reach agents. Because the company's materials describe slightly different channel sets for Omni and the broader platform, enterprises should verify support for their particular interface and deployment configuration.
Omni can also function alongside desktop AI products rather than replacing them. Twizer said employees can continue using their preferred desktop agents while Omni acts as a skill exposing only enterprise-approved data and connectors. When background execution is needed, Omni can create a centrally controlled agent to perform the work.
xpander says Omni scored 90.9% on the GAIA benchmark, including strong performance on its most difficult tasks. The result is company-reported and should be viewed as evidence for xpander's broader thesis rather than independent validation of the platform.
Twizer said the company deliberately tested the harness with a mixture of models rather than optimizing around a single proprietary system.
“We took Opus, we took Sonnet, we took Kimi, we took GPT, and on that benchmark we got a 90.9% score,” he told VentureBeat.
For Twizer, the result supports an argument that agent performance increasingly depends on the infrastructure surrounding the foundation model.
“It just proves that the value is in the harness layer and not in the model layer,” he said. “The value is in: How do you handle long-running tasks? How do you handle tool calling? How do you do sandboxing? How do you focus? How do you make the agents focused on the task?”
The benchmark results are publicly available, allowing others to examine the company's methodology, but the broader conclusion remains xpander's interpretation of its own results.
That thesis is increasingly shared across the industry. The disagreement is over who should control that layer.
OpenAI and Google are turning it into part of broader AI platforms. LangChain and CrewAI are extending their development ecosystems into enterprise runtimes. Temporal is attacking the execution problem as infrastructure.
xpander is betting enterprises will instead want that control plane to remain independent of all three choices: model, cloud and agent framework.
The company now has to demonstrate that the extra abstraction is valuable enough to justify another platform in an enterprise AI stack that is already becoming crowded.
Pricing and Availability
xpander's platform and Omni are generally available now, with two substantially different commercial models for teams using xpander's hosted service and enterprises running the platform on their own infrastructure.
The self-service Team offering has no seat charge and is priced in credits based on agent activity. xpander defines one credit as one cent, meaning $100 buys 10,000 credits. Each event or message that wakes an agent costs one credit for the entire turn, regardless of how long the turn runs, and each tool or API call costs another credit. Model tokens are billed separately in credits at configured rates for the selected model.
That makes the cost structure more granular than Twizer's description of paying for agent “output” might suggest. Long-running execution itself does not appear to create a duration-based charge under the published pricing, but a workflow can accumulate costs through repeated invocations, tool calls and model-token consumption.
New accounts receive 1,000 free credits rather than a time-limited free trial, and customers can sign up with a credit card. The Team tier permits unlimited agents, workflows and seats, according to xpander.
Model usage can represent a significant portion of total cost, and the company publishes examples intended to make that expense calculable. Its pricing page lists different input and output token rates for individual models and says those model charges are incorporated into the credit system, eliminating a separate model-provider bill for hosted customers. Actual spending therefore depends heavily on the models selected, token volumes and number of tool calls.
Enterprises that self-host get a different arrangement. xpander's Enterprise plan is an annual license starting at 50 agents and supports deployment on a c
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み