PTV Fund II
Investment landscape / August 2026

Enterprise AI infrastructure

Where durable demand and open-source investment opportunity will concentrate as enterprises move from AI pilots to governed agentic operations.

Enterprise-first Infrastructure software Open-source lens 0-5 year horizon L1 deep dive: the life of a prompt →
01 / The shift

From user-driven software to machine-driven operations

AI does not remove the enterprise stack. It creates a new, high-frequency consumer of every system and adds new requirements for trust, control, and accountability.

Classical enterprise

01
EmployeeInitiates work
ApplicationFixed workflow
APIKnown action
SystemBusiness record

Human-paced, largely deterministic, and controlled through application boundaries.

Agentic enterprise

02
GoalHuman intent
Agent fleetDynamic plan
Controlled actionsMany systems
OutcomeEvidence required

Machine-speed, probabilistic, and dependent on identity, context, policy, and continuous assurance.

02 / Landscape

The enterprise AI stack

The most attractive layers sit between agents and the existing enterprise estate. They govern every action and accumulate durable policy, context, and operating history.

Business workflows, assistants, and vertical agents.

Context only

Approval, escalation, accountability, and measurable value.

Selective

Quality, monitoring, recovery, cost, and production evidence.

High conviction

Durable workflows, isolated execution, and controlled autonomy.

High conviction

Governed access, routing, discovery, and agent connectivity.

High conviction

Who is acting, what is allowed, and how authority is proven.

Highest conviction

Current, permitted, and business-correct data for every decision.

Highest conviction

Safe transaction paths into enterprise and legacy systems.

Strong / selective

The installed enterprise estate and underlying model infrastructure.

Demand driver
03 / Layer guide

What each layer does for the business

A buyer-facing guide to the stack. Each layer is explained in plain business terms, with its technology role and representative products.

Layer 08

Agentic applications

Context only

Technology role

The visible software employees and customers use. It turns a goal into a sequence of AI-assisted tasks across one or more business systems.

Business problems solved

  • Reduces time spent on repetitive knowledge and service work.
  • Coordinates work that normally crosses several applications.
  • Makes specialist capabilities available to more employees.

Representative products

Microsoft Copilot Studio Salesforce Agentforce ServiceNow AI Agents Google Gemini Enterprise UiPath
Layer 07

Human control and outcomes

Selective

Technology role

Approval, escalation, and evidence workflows that decide when an agent may continue alone and when a responsible person must step in.

Business problems solved

  • Delegates routine work without losing management accountability.
  • Prevents high-impact actions from happening without review.
  • Connects AI activity to savings, revenue, risk, and service KPIs.

Representative products

HumanLayer Camunda ServiceNow Microsoft Copilot Studio Salesforce Agentforce
Layer 06

Reliability and evaluation

High conviction

Technology role

Tests agent quality before launch, monitors decisions in production, traces failures, and provides the evidence needed to improve or stop a system.

Business problems solved

  • Reduces costly wrong answers and uncontrolled actions.
  • Shortens incident investigation and recovery time.
  • Gives leaders measurable proof that an AI workflow is improving.

Representative products

Langfuse Arize Phoenix Braintrust LangSmith Datadog LLM Observability
Layer 05

Runtime and safe execution

High conviction

Technology role

Runs long or multi-step agent jobs, preserves progress, handles retries, and isolates generated code or browser actions from core company systems.

Business problems solved

  • Allows agents to finish complex work reliably over time.
  • Contains the damage if generated code behaves unexpectedly.
  • Improves continuity when a model, tool, or network service fails.

Representative products

Temporal E2B Kubernetes Agent Sandbox Modal Blaxel
Layer 04

Model and tool gateways

High conviction

Technology role

A controlled front door through which agents reach AI models, internal tools, and approved external services. It centralizes discovery, routing, limits, and audit.

Business problems solved

  • Reduces dependence on any single model or platform vendor.
  • Controls usage cost and prevents unapproved tool access.
  • Creates one governed catalog of capabilities for the company.

Representative products

LiteLLM Envoy AI Gateway Kong AI Gateway Cloudflare AI Gateway TrueFoundry
Layer 03

Identity, policy, and security

Highest conviction

Technology role

Gives every agent a traceable identity and enforces what it may do, for whom, with which data, and for how long. Credentials remain limited and revocable.

Business problems solved

  • Prevents an agent from exceeding an employee's authority.
  • Reduces data leakage, fraud, and uncontrolled system access.
  • Creates accountability for audits, incidents, and regulators.

Representative products

Microsoft Entra Okta CyberArk Cerbos OpenFGA Aembit
Layer 02

Trusted enterprise context

Highest conviction

Technology role

Organizes business definitions, data quality, ownership, access rights, and freshness so agents receive the right information with its source and limitations.

Business problems solved

  • Reduces confident but wrong answers based on stale or ambiguous data.
  • Unlocks information spread across departments and systems.
  • Preserves privacy and consistent business definitions at scale.

Representative products

DataHub OpenMetadata Databricks Unity Catalog Microsoft Purview Collibra Atlan
Layer 01

APIs and integration

Strong / selective

Technology role

Connectors, APIs, and workflow adapters that let agents read from and safely write to ERP, CRM, IT, finance, data, and legacy systems.

Business problems solved

  • Turns isolated AI pilots into workflows that complete real work.
  • Reduces custom integration time across old and new systems.
  • Makes transactions repeatable, controlled, and recoverable.

Representative products

MuleSoft Boomi Workato Composio Sideko Apache Camel
Foundation

Cloud, data, and systems

Demand driver

Technology role

The compute, storage, data platforms, models, and existing business systems on which every AI workload ultimately runs.

Business problems solved

  • Provides reliable capacity, scale, resilience, and data residency.
  • Supports hybrid and regulated deployment requirements.
  • Creates the installed base that drives demand for every layer above.

Representative products

AWS Microsoft Azure Google Cloud Kubernetes Databricks Snowflake
Cross-cutting

Enterprise agent control plane

Emerging end-state

Technology role

A common management layer that inventories agents and tools, applies policy, tracks cost and evidence, and governs the full lifecycle across otherwise separate platforms.

Business problems solved

  • Gives management one view of what agents exist and who owns them.
  • Stops every department from rebuilding governance independently.
  • Enables faster adoption through approved, reusable deployment paths.

Representative emerging products

AWS Bedrock AgentCore Google Gemini Enterprise Agent Platform Microsoft Agent 365 / Entra Agent Registry ServiceNow AI Control Tower Workday Agent System of Record

Product names are representative category examples, not a ranking, endorsement, or exhaustive market list. Open-source status and ownership should be re-verified before investment use.

04 / Demand

Production gates reveal the budget

Enterprise spending will concentrate around the constraints that stop promising pilots from becoming reliable operations.

The constraint is no longer model access.

Model capability is abundant and increasingly multi-vendor. Scarcity lies in connecting agents to the business safely, with trusted context and proof that actions were correct.

The value pool shifts from creation to control.
Security and complianceProduction barrier
52%
Monitoring at scaleProduction barrier
51%
Existing-system integrationAdoption barrier
46%
Implementation costAdoption barrier
43%
Data access and qualityAdoption barrier
42%

Directional evidence from 2026 enterprise surveys by Dynatrace/Qualtrics and Anthropic/Material. Vendor-sponsored findings are used as demand signals, not neutral market sizing.

05 / Priorities

Where to invest

Prefer infrastructure that controls a production action, scales with agent activity, and becomes harder to replace as policy, context, and evidence accumulate.

Enterprise urgency versus durability of control point High-conviction categories cluster in the upper right. Crowded and bundling-prone categories sit in the lower left. Enterprise urgency → Durable control point → BUILDING MARKET HIGHEST CONVICTION UNDERWEIGHT SELECTIVE Agent identity + policy Trusted context Runtime assurance Tool gateway + registry Sandbox AI supply chain API modernization Agent FinOps Durable execution Sovereign Agent frameworks Generic memory Thin tool wrappers Governance dashboard
Tier 1: high conviction Tier 2: selective Underweight
06 / Themes

Six high-conviction themes

Each theme has immediate production relevance, usage-linked growth, and the potential to become a deeply embedded enterprise control point.

01 / Highest

Agent identity and delegated authorization

Every agent action needs a provable identity, bounded authority, and a link to the accountable human or service.

Must prove: inline enforcement, not inventory alone. Risk: IAM incumbents.
02 / Highest

Trusted enterprise context

Agents need current, permitted, business-correct information, not simply more retrieved text.

Must prove: runtime trust and intervention. Risk: data-platform bundling.
03 / High

Governed tool gateway and registry

A neutral control point for discovering, approving, securing, and auditing agent capabilities.

Must prove: federation and policy depth. Risk: hyperscaler bundling.
04 / High

Runtime assurance and evaluation

Connect technical behavior to business outcomes, then trigger approval, rollback, or shutdown.

Must prove: closed-loop control. Risk: becoming an APM feature.
05 / High

Secure agent execution

Isolated environments for generated code, browser actions, and long-running machine work.

Must prove: security, density, and low latency. Risk: undifferentiated hosting.
06 / High

AI asset supply chain

Provenance, signing, scanning, admission, and continuous verification for agents, tools, and skills.

Must prove: inline prevention. Risk: point-scanner commoditization.
07 / Horizon

Demand develops in three waves

The infrastructure buildout begins with production controls, expands into fleet management, and matures into cross-enterprise trust.

Now / 0-18 months

Productionize

  • Connect existing systems
  • Establish trusted context
  • Control access and cost
  • Evaluate and observe outcomes
  • Keep humans on high-risk actions
Next / 18-36 months

Govern fleets

  • Central agent and tool registries
  • Delegated agent identity
  • Runtime policy enforcement
  • Durable execution and recovery
  • AI asset supply-chain controls
Later / 3-5 years

Transact across boundaries

  • Federated agent identity
  • Cross-company policy and trust
  • Machine-scale metering
  • Portable evidence and liability
  • Bounded autonomous remediation
08 / Filter

What PTV should buy

The key distinction is not "AI" versus "non-AI." It is durable infrastructure control versus replaceable application logic.

Prioritize

Inline products that can allow, block, route, isolate, revoke, or recover.
Usage-linked economics that grow with agents, actions, context queries, or evidence.
Open, neutral infrastructure across models, clouds, frameworks, and enterprise systems.
Products accumulating policy, lineage, identity graphs, outcomes, or operating history.
Self-hosted and hybrid deployment for regulated enterprise buyers.

Underweight

×Generic agent frameworks and horizontal copilots in crowded markets.
×Thin protocol wrappers or public directories without enterprise control.
×Generic memory, undifferentiated retrieval, or prompt-management features.
×Governance dashboards that observe but cannot enforce production policy.
×Capital-intensive inference without durable software differentiation.
PTV Fund II conclusion

Invest where autonomous systems meet enterprise constraints.

Identity, trusted context, controlled actions, secure execution, runtime assurance, and evidence are the enterprise buildings of the agentic era. Models and agents are tenants. The strongest opportunities make every tenant safer and more useful, regardless of which model or application wins.