Boomi’s Agent Control Plane Targets the Governance Gap Stalling Enterprise AI

Conceptual illustration of Boomi’s Agent Control Plane, managing secure enterprise AI operations with data flow visualization.

Key Takeaways

Boomi's Agent Control Plane provides AI-native infrastructure for governing agent access to core business systems and managing token spend.

The platform addresses governance gaps and execution risks, supporting deployment across public cloud, VPC, or on-premises environments.

Enterprises must rethink API layers for agents, integrate FinOps from the start, and implement a single control point for agent actions.

Boomi has launched its Agent Control Plane, positioning it as AI-native infrastructure that connects agents to core business systems, governs what they do once connected, and reins in runaway token spend. The platform runs across public cloud, a customer’s own VPC, or on-premises, a deployment choice Boomi ties directly to data and digital sovereignty.

The September 2 announcement completes an arc ERP Today has tracked all year. Boomi’s March pivot to data activation introduced Meta Hub and a European platform instance. Boomi World in May added Boomi Connect, Orchestrate, and a letter of intent for AI gateway specialist Lunar.dev. That deal closed on July 27, and the Lunar-based Boomi AI Gateway now serves as the enforcement layer beneath the control plane, combining MCP gateway and LLM gateway functions in one control point.

From Model Risk to Execution Risk

The release frames the problem as a governance gap that widens as adoption accelerates. Enterprises are moving agents into production faster than they can see what those agents do, what they cost, or what happens when one touches the wrong system. Many respond by restricting connectivity, which keeps the enterprise safe on paper but starves agents of the systems that make them useful.

Third-party data supports the framing. A Forrester Consulting study commissioned by Boomi found 86% of leaders had moved beyond pilots. Yet, only 34% trust the actions their agents take, and organizations that deployed prematurely reported an average of $2.1 million in added cost. The FinOps Foundation’s 2026 survey found 98% of practitioners now manage AI spend, up from 31% two years earlier.

Omdia chief analyst Michael Barnes summarized the change in the release. “Enterprises are no longer primarily worried about what an agent says,” he noted. “They are worried about what it does to a general ledger or a customer record, and whether anyone can reconstruct the decision six months later in an audit.”

Why Pilots Died

Chris Hallenbeck, Boomi’s SVP and GM of AI and Platform, offered a blunter diagnosis. He said that projects failed when CISOs refused to sign off on systems that could not protect personal data or verify the identity behind an agent’s request, when connectivity to systems of record was too hard to build, and when data quality was too poor to give agents usable context.

The deeper failure: agent ownership. Without ownership, integration and data teams disclaim AI, while centers of excellence lack authority. Hallenbeck said that the companies that reached production made integration teams responsible for agent-ready APIs, embedded the CISO at design time, and paired AI teams with FinOps.

What Changes for ERP

The Agent Control Plane sits between any agent, whether built on Boomi, third-party frameworks, or open source, and transactional systems including SAP, Oracle, Salesforce, and Workday. It inspects live traffic, applies identity and rate limits, and holds high-risk transactional actions for human approval. Boomi Connect exposes those systems as governed MCP tools, more than 1,000 of them, so that employees can use Claude, ChatGPT, or Gemini against enterprise data with access provisioned through existing identity providers.

The runtime story matters as much for regulated industries. Bring-your-own-model support spans commercial LLMs, open-weight models, and private instances, with fine-tuned small language models coming soon. Running models on infrastructure the enterprise controls converts variable per-token cost into predictable compute cost. That answers a concern Steve Lucas raised with ERP Today as far back as 2024, when he asked who was watching the agents and argued that agent governance would be championed out of Europe.

The thesis Lucas laid out in 2024- that integration is innovation, and AI is impossible without a data house in order- has hardened into a product category. Whether enterprises buy it from Boomi or assemble it themselves, the control layer between agents and the ERP is no longer optional.

What This Means for ERP Insiders

Put enforcement in the path, not alongside it. Cloud and model vendors each govern their own estate, leaving partial audit trails. CIOs should demand a single control point that logs, meters, and can halt every agent action against a system of record.

Audit APIs before exposing them to agents. Enterprise architects should assume legacy transactional APIs are unsafe for autonomous access and budget for a fine-grained, business-level API layer with throttling and delegated authorization.

Bring FinOps into agent design from day one. Token cost variability is now a board-level risk. Model routing between frontier models, cloud models, and on-premise SLMs should be a governed policy, not a developer’s choice.