Why Enterprise Software Is Building Walls Around AI
Enterprise software's walls around AI trap business outcomes, forcing workers to navigate fragmented systems while vendors profit from architectural failures.
No one in the room is careless. That is what makes the pattern durable. The people are competent, the tools are legitimate, and the caution is real. Each system is doing what it was designed to do inside its boundary. The failure is not inside any single application. It is in the distance between them. The visible debate is about APIs, vendor policy, and artificial intelligence. The real debate is about where control moves when work no longer fits inside the walls that software companies built to contain it. Incumbent vendors are tightening access because they see what is coming. If AI becomes the new interface to work, the old application interface loses power. If reasoning can coordinate across systems, the system of record remains necessary but stops being the place where the customer experiences control. What would have to be true for this outcome to keep repeating. It would have to be true that the application remains the place where work begins. It would have to be true that the worker continues to adapt to the software faster than the software adapts to the work. It would have to be true that the customer keeps paying for outcome failure while being told the architecture needed to prevent it must remain inside the vendor’s approved corridors. Those conditions have held for a long time. Second-generation AI is beginning to make them unstable.
The wall does not merely protect data. It protects the old route to work
The Wall Goes Up When the Interface Feels Threatened
For most of the modern enterprise software era, the bargain was clear. A company bought a major application because the application contained a domain of work. ERP held the transaction spine. PLM held the product definition. MES held the production record. QMS held the deviation and corrective action trail. CRM held the customer record. EAM held the maintenance history. The application did not just store data. It organized behavior. That bargain produced enormous value. It gave companies common processes, audit trails, standard data structures, permission models, and operating memory. It also produced dependence. Once the workflow lived inside the application, the vendor owned not only the record but also much of the route by which human beings reached the record. Control over the screen became control over the work. AI changes the route. The question a user wants answered is not always an application question. It is an outcome question. What is causing this deviation? Which customers are exposed? What inventory is at risk? Which supplier lot is implicated? What decision rights exist? What can be contained now? What must be escalated? What action can the system take without exceeding authority? That question crosses the boundaries the enterprise spent decades hardening. The old application asks the user to come to the system. The new intelligence must go to the work. That is why the walls are going up. The incumbents understand that the threat is not a better chatbot. The threat is a better control point. SAP’s latest API policy makes the control point visible. The policy allows Published APIs for Documented Use such as integration, extensions, synchronization, data exchange, and event triggering. It prohibits access to non-published APIs, restricts uses that create performance, stability, or security risk, and prohibits, outside SAP-endorsed pathways, API use involving semi-autonomous or generative AI systems that plan, select, or execute sequences of API calls. It also prohibits scraping, harvesting, systematic extraction, large-scale replication, and circumvention through proxies, gateways, intermediary services, or custom code. Enforcement can include throttling, suspension, or termination. That is not an accidental document. It is a boundary document. It tells customers and partners where intelligence may touch the system, what kinds of agency are allowed, and which forms of access will be treated as a threat. The language is framed in safety, health, fairness, and misuse prevention. Those are real concerns. The document also protects the platform from becoming the substrate for somebody else’s agentic control layer. SAP’s own public AI posture confirms the distinction. SAP is not rejecting agentic AI. It describes Joule Studio as a way to build, deploy, and manage AI agents and Joule skills, including conversational and autonomous agents, skills for data retrieval and structured task execution, and orchestration of multiple AI agents for business problems. SAP’s Q1 2026 Business AI release said it had more than 30 specialized agents and more than 2,500 Joule Skills, and described an agent-to-agent protocol for SAP and non-SAP systems along with an AI Agent Hub for governance and discovery.
That is not anti-AI. It is AI inside the house. The incumbent claim is not that intelligence should not act. The claim is that intelligence should act through the incumbent’s platform, under the incumbent’s rules, with the incumbent’s agents carrying the approved form of authority. That is a rational position for a company protecting decades of investment. It is also a signal to customers that the next fight is not over whether AI exists in the enterprise. The fight is over who governs the moment when AI moves from answer to action. Dassault Systèmes shows the same pressure from a different angle. In February 2026, Dassault announced AI-powered Virtual Companions that understand user intent, reason, simulate consequences, and orchestrate actions across the life cycle of products and services. The company also described the 3DEXPERIENCE agentic platform as capable of managing the asynchronous choreography of thousands of Virtual Companions and humans while meeting sovereignty requirements. This is the market’s tell. The walls are not going up because incumbents doubt AI. The walls are going up because incumbents understand that agency changes the control surface. If a third-party reasoning layer can coordinate across systems, generate capability near the point of work, and carry the user away from the old application route, the incumbent does not merely lose a feature contest. It risks losing the route to the decision.
Safety Is the Strongest Case for the Wall, and the Reason It Will Not Be Enough
The fair counterargument has to be taken seriously because it is partly right. Mission-critical systems cannot become open hunting grounds for autonomous agents. A poorly governed agent can read the wrong field, infer the wrong state, trigger the wrong sequence, or write into a system that other systems trust. In a regulated industry, a wrong write is not a typo. In a plant, a wrong action can become downtime. In engineering, it can corrupt configuration. In finance, it can move a control failure from inconvenience to disclosure. No serious customer should want uncontrolled access. This is where simplistic openness arguments fail. They treat vendor restriction as pure selfprotection, when some portion of restriction is basic duty of care. Enterprise systems carry production, safety, financial, customer, employee, supplier, and intellectual property risk. An AI agent that plans and executes across those systems is not a user with a faster keyboard. It is a new kind of actor inside the operating model. The wall is defensible when it prevents reckless agency. The problem is what happens when the same wall prevents governed agency. That is the line customers will begin to feel in their operating results. The company does not merely need safer systems. It needs safer speed. It needs
the ability to connect evidence, authority, and action without forcing people to reassemble the business by hand every time the work crosses a system boundary. The old model made sense when software recorded work and humans performed the integration. It becomes expensive when software can reason but is only allowed to reason locally. A PLM companion can understand product context and still miss supplier exposure. An ERP assistant can understand transaction status and still miss engineering consequence. A QMS assistant can process corrective action and still miss process drift. An MES assistant can read production behavior and still miss customer consequence. The plant still waits. The customer still waits. The margin still waits for no one. This is the trade that will be tested in the market. If vendor-native agents can reduce end-to-end decision time across functions without changing the architecture of permission, then the wall strategy may hold longer than critics expect. If they cannot, customers will keep the systems of record but look above them for the place where the work is actually governed. That is the falsifiable claim. By the end of 2027, the companies relying only on applicationnative agents will show visible productivity gains inside domains, but little improvement in decision latency across workflows that require ERP, PLM, MES, QMS, supplier, and customer data to meet before action. If that proves wrong, the evidence will be cycle-time data, not conference demos.
A customer may own the data and still lack practical control over the outcome.
Customers Are Not Asking for Open Chaos The end user does not want to fight a vendor’s API policy. The end user wants the work to stop punishing the people who have to carry context across systems. A planner wants to know whether a constraint matters before the schedule is frozen. A quality leader wants containment options before a deviation becomes a customer conversation. A controller wants variance drivers before the close becomes theater. A plant manager wants the next permissible action, not one more dashboard proving that the condition exists. The desired outcome is not more access for its own sake. It is burden reduction with accountability intact. That distinction matters because the incumbent defense often frames the alternative as risk. The implied argument is that third-party agentic systems will scrape, extract, bypass, or act without permission. Some will. Those companies should lose. The more important category is different. It is the platform that respects documented pathways, honors rate limits, keeps systems of record intact, separates read from write, and makes permission executable at the moment of action. That platform does not weaken control. It relocates control to the place where decisions actually cross the enterprise. The customer does not need a rebel integration layer. The customer needs a governed reasoning layer. That is where the next architecture begins to take shape. It does not pretend ERP, PLM, MES, QMS, EAM, CRM, and supplier systems will vanish. They will not. They have earned their place because records matter. What changes is the burden placed on humans to translate, reconcile, and carry those records into decisions. A system of record tells the organization what has been made official. An agentic control layer must help the organization decide what should be made true next. Those are different jobs.
The winning architecture will not break the wall. It will make the wall less central
A practical version of that architecture would begin with a customer-owned context layer. It would hold operating intent, policy constraints, roles, decision rights, standing exceptions, evidence definitions, and current states. It would connect through authorized means. It would not treat extraction as cleverness. It would not confuse access with legitimacy. It would maintain a journal of what evidence was used, what was inferred, what action was recommended, what authority existed, and who approved or rejected the step. That is the kind of system a board can ask about without being sold a magic trick. It would also make visible the real question hidden behind most AI demos. What is the system allowed to do when the answer is good enough to act on? If the answer is nothing, the enterprise has not bought agency. It has bought narration. The new worker skill makes this point harder for incumbents to avoid. Claude Code is described by Anthropic as an agentic coding tool that can read a codebase, edit files, run commands, and connect to development tools. Anthropic’s documentation also describes Claude Skills as organized folders of instructions, scripts, and resources that Claude can load to perform specialized tasks. That is not another spreadsheet. It is the early form of generated capability. The old digital worker learned the application. The new worker learns how to direct intelligence that can build the tool the moment requires. An engineer does not only open Excel and build a static workbook. The engineer can increasingly ask an AI system to create a temporary analysis tool, build a small interface, test logic, call permitted resources, and retire the tool when the
context changes. The enterprise application does not vanish, but it no longer owns the full shape of work. That is why rigid ERP and MES architectures are exposed to erosion. The word is erosion, not replacement. The transaction record still matters. The batch record still matters. The work instruction still matters. The audit trail still matters. But when skills and disposable applications can be generated at the edge, the application loses its monopoly on how work is shaped.
The Go Player Does Not Assault the Castle
The chess player studies the board as a set of pieces to capture. The castle, the queen, the rook, the center. The movement is explicit and bounded. The fight is visible. Much of incumbent software strategy still looks this way. Protect the module. Protect the workflow. Protect the account. Protect the interface. Protect the data model. Protect the approved routes in and out. That logic is not childish. It is how large software companies have defended position for years. In a stable environment, chess thinking works because the rules are clear and the pieces are known. The agentic market looks more like Go. The best Go player does not need every point on the board. He shapes influence. He builds positions that make later movement cheaper. He surrounds without announcing every attack. He understands that territory is not only what is occupied but what becomes hard for the other player to use. The equivalent in enterprise AI is not owning every application. It is owning the flow from signal to action. A challenger that understands this does not attack SAP where SAP is strong. It does not attack Dassault where Dassault is strong. It does not tell customers to abandon the systems they still need. It goes after the cost those systems create when work crosses them. That is a different campaign. It asks where evidence stalls. It asks where permission is unclear. It asks where the same issue is argued again because no system carries the full context. It asks where a meeting exists only because software cannot yet carry authority safely. It asks where an approval is called governance when it is really compensation for missing architecture. The wall builder defends territory. The Go player changes the meaning of territory. This is why the value will make the Go strategy inevitable. Customers will not move because they dislike incumbents. They will move because the economic burden of delay, reconciliation, missed options, and outcome failure becomes too large to tolerate. Once second-generation AI proves it can remove real burden at the edge, generate capability in context, and improve decisions without violating legitimate controls, the market will not ask whether the incumbent prefers the old boundary. The market will ask why the old boundary is still allowed to tax the outcome. Value will surround the wall before anyone has to attack it.
The language matters because serious customers will not buy recklessness. They will buy relief. They will buy faster decisions if the speed is auditable. They will buy cross-system reasoning if the system can explain not only what it recommends, but what it is allowed to do and why. They will buy agency if accountability does not disappear when the agent acts.
If it cannot shape an outcome, it is not an agent
That sentence should be treated as a standard, not a slogan. A tool that summarizes is useful. A tool that drafts is useful. A tool that answers questions is useful. But an agent must be able to shape an outcome within authority, or the word becomes marketing cover for automation that still leaves the human carrying the burden. The customer will learn this quickly because the burden will remain visible. If the AI produces a better answer and the human still has to open five systems, seek three approvals, reconcile two records, and explain the same context in the next meeting, the enterprise has not changed the work. It has accelerated one fragment of it.
The Losers Will Confuse Restriction With Strategy
Every incumbent will say it is protecting customers. Some of that will be true. The question is whether protection becomes a doctrine that prevents the customer from reaching the outcome. That is the danger. A policy that begins as a security boundary can become a commercial boundary. A commercial boundary can become a product strategy. A product strategy can become a belief that the customer’s future must remain inside the vendor’s architecture.
That belief will not survive the customer’s operating reality. A manufacturer does not experience the business through one system. A life sciences company does not experience risk through one system. A supply chain leader does not experience constraint through one system. The board does not care which application produced the delay. The board cares that the delay was expensive. There is a simple board-usable test. When a material operating exception occurs, can the organization see the relevant evidence, decision rights, available actions, and required escalations in one governed place? If not, then the enterprise is still relying on human beings as the integration layer. A second test is more painful. If every vendor agent became twice as capable tomorrow inside its own application, which cross-functional decisions would actually close faster? If the answer is unclear, the company is not constrained by local intelligence. It is constrained by cross-system authority. These questions cut through much of the current AI noise. They do not ask whether the demo works. They ask whether the work changes. The difference will matter more as AI becomes common. When every vendor has a companion, assistant, copilot, agent, or virtual teammate, the market will stop rewarding the existence of AI and start repricing the effect of AI. The earningsrelevant question will be whether the business became faster, safer, and less dependent on human intermediation. That is where many application-native AI strategies will be exposed. They will improve the room but not the route. Regulation will add pressure, but it will not design the answer. The EU Data Act became applicable on September 12, 2025, and the European Commission frames it as part of a fair and innovative data economy, with measures concerning access to and use of data and data processing services. Reuters reported on April 28, 2026, that EU regulators are turning attention toward cloud and AI services under the Digital Markets Act, including whether cloud providers and certain AI services should face gatekeeper-style review. That matters because the pressure against hard lock-in is not only commercial. It is also regulatory. Regulation will not tell a manufacturer how to connect evidence, permission, and action across systems. It will not build the operating architecture. But it can alter the assumptions around portability, switching, contestability, and the cost of defending walls that function more as market control than customer protection. There is a boundary here that matters. Vendor rights are real. Security risks are real. Intellectual property is real. So are customer rights to their operating data, their decision speed, and their ability to assemble the systems needed to run the business. The fight will not be settled by saying one side is right. It will be settled by architectures that can prove both safety and movement.
The Bill for Delay Never Says Architecture
Decision latency sounds abstract until the bill arrives. It arrives as inventory held longer than necessary because the exception was not trusted soon enough. It arrives as premium freight because the supply constraint was visible before the decision was. It arrives as scrap because the process signal was detected but not converted into action. It arrives as customer concessions because the organization could describe the problem before it could contain it. It arrives as meetings where competent people translate system language into business action one more time. The ledger rarely names this as latency. That is why the cost persists. A CFO can see expedited freight. A COO can see schedule disruption. A quality leader can see recurring deviations. A CIO can see integration cost. A commercial leader can see customer pain. Each one sees a legitimate piece of the expense. The harder work is to see the common cause, which is that the enterprise does not have a governed way to move from evidence to authorized action across systems. This is where the old application era produced a hidden tax. It taught companies to measure the inside of domains while under-measuring the cost between them. Response time inside a system improved. Report freshness improved. Workflow status improved. The business still waited because the decision required more than status. The next generation of enterprise AI will be judged here. Not by how well it talks, but by how much burden it removes from the people who keep the business moving when the systems stop at their boundaries. That is the outcome value that will force the Go strategy. Not because Go is elegant, but because the bill has become too visible to ignore.
The bill for delay does not say architecture. It says freight, rework, inventory, and apology
The winners will not sell openness as a virtue detached from control. They will sell governed movement. They will treat permission as architecture, not administration. They will know the difference between seeing, recommending, simulating, approving, and acting. They will preserve the system of record while building a higher-order memory of intent, constraints, evidence, authority, and consequence. They will build causal journals because the enterprise cannot rely on explanation after the fact. A system that recommends action should leave behind the path by which it reached the recommendation. What was observed. What was inferred. What was projected. What evidence mattered. What was missing. What authority existed. What was escalated. What changed after the action. That distinction between observation, inference, and projection will become central. Observed fact belongs to the record. Inference belongs to reasoning. Projection belongs to risk. A serious architecture cannot blur them and then ask the customer for trust. The winners will also understand that not every process needs the same level of agency. Some work belongs inside a vendor-native agent. Contained workflows with clear authority and low cross-system dependence can be handled locally. A configuration validation inside a PLM boundary may not require a broad enterprise control layer. A transaction check inside ERP may be better handled inside ERP. The mistake would be to make the contained case the general case. Margin, risk, service, safety, and resilience usually do not stay contained. They move across the business. That is where the larger architecture earns its place. The loser will overclaim. The winner will know where not to act. That restraint will become a mark of trust. Customers will not reward platforms that try to act everywhere. They will reward platforms that know when action is legitimate, when recommendation is sufficient, and when escalation is the only responsible move.
The Strongest Incumbents Will Stop Treating the Wall as the Strategy
The incumbents still have options. They can treat the wall as a temporary control while building real interoperability for governed agency. They can expose richer permission models, event structures, context services, audit hooks, and customer-controlled pathways. They can accept that some intelligence will sit above their applications and decide to be indispensable to that architecture. Or they can treat the wall as the strategy. The second path feels safer. It keeps the customer inside familiar boundaries. It protects near-term economics. It gives product teams time to add
agents and assistants. It allows sales teams to say the platform already has AI and that external orchestration creates risk. It may work for a while. But if the customer’s end-to-end burden remains, the wall will begin to look less like safety and more like tax. The moment customers begin to measure decision latency across systems, many vendor claims will become easier to test and harder to defend. The strongest incumbents will not be the ones that block everything above them. They will be the ones whose systems can participate safely in a customer-owned operating architecture. That is a hard turn for companies trained to own the workflow. The alternative is worse. If the application insists on being the whole operating model, it will become less valuable as the customer learns to govern work at a higher level. The end state is not the disappearance of enterprise systems. That is fantasy. The end state is a different distribution of control. Systems of record will continue to matter because records matter. Vendor domain logic will continue to matter because expertise matters. Applicationnative agents will matter because local work matters. But the highest value layer will move toward the place where intent, evidence, authority, and action meet. That layer will not be owned automatically by the largest incumbent. It will be earned by the architecture that makes the enterprise faster without making it reckless. It will be earned by the system that can prove what it saw, what it inferred, what it was allowed to do, and what happened after it acted. The companies that win will be able to answer a hard question without flinching. Did the system reduce the human burden required to shape the outcome, or did it merely make the old burden easier to describe? That is where this goes. The walls will rise because fear is rational when the old control point is threatened. Some walls will be necessary. Some will be dressed up as safety when they are really share defense. Customers will learn to tell the difference by following the work, not the language. The future will not belong to the platform with the tallest wall. It will belong to the one that can be trusted when the wall is no longer where the work happens. The wall is not the moat.
References
This article draws on SAP’s API Policy v.4.2026a, which defines Published API use, restricts non-published API access, limits autonomous and generative AI interactions that plan or execute API sequences outside endorsed pathways, and prohibits scraping, large-scale extraction, and circumvention through intermediaries or custom code. It also draws on the user-supplied article draft, “The Companies Building Walls Are Telling You Where the Future Is Going,” including the 7:42 operating-review scene, the language of evidence, permission, timing, and authority not
being in the same place, the Go strategy framing, and the distinction between breaking the wall and making the wall less central. The public-source ballast includes SAP’s Joule Studio and Q1 2026 Business AI materials, Dassault Systèmes’ February 2026 announcement of AI-powered Virtual Companions and its 3DEXPERIENCE agentic platform, the European Commission’s Data Act materials, Reuters reporting from April 28, 2026 on EU scrutiny of cloud and AI services under the Digital Markets Act, Anthropic’s public materials on Claude Code and Claude Skills, W. Edwards Deming’s Out of the Crisis, Herbert Simon’s bounded rationality work, Daniel Kahneman’s work on judgment under uncertainty, Judea Pearl’s work on causal reasoning and intervention, Jay Forrester’s systems thinking, real-options logic on timing and option value, and Michael Carroll’s foundational work on 1° architecture, second-generation AI, automated reasoning, permission architecture, causal systems, decision latency, burden transfer, outcome value, and the standard that an agent must be able to shape an outcome or it is not an agent.
agentic-authority, permission-in-advance, outcome-ownershipOpen in the Radiant ↗All dispatches