This morning delivered three signals pointing in the same direction: Microsoft wants to consolidate Copilot and workflow automation into a single operating surface, Codex is moving closer to desktop-level workflows, and Copilot is making AI cost less predictable through token counting. When those three signals appear together, CEOs and Product Leads should understand one thing: the biggest risk is no longer choosing the wrong model. It is choosing the wrong agent control layer.
In other words, once a company hands routing, permissions, approvals, cost telemetry, and operating data to one vendor, it is not just buying AI software. It is outsourcing internal product control.
Thesis: Vietnamese SMBs do not need the “strongest AI.” They need the right agent control plane — open enough to swap models, strict enough to govern permissions, and clear enough to predict cost.
1. From market signal to product requirement
Many founders will read today’s three stories as separate events: one Microsoft story, one OpenAI/Codex story, and one GitHub Copilot story. I read them differently. They are three versions of the same strategic move: own the orchestration layer between the user and the model.
Whoever owns that layer also owns how agents get invoked, how workflows are sequenced, what permissions are enforced, which logs are retained, how bills are computed, and how painful it becomes for the company to leave. That is why today’s issue is a product decision, not just an IT decision.
2. Seven product requirements for a good agent control plane
1) Workflow-based routing, not vendor-based routing
Lead generation, customer support, internal reporting, and coding assistance should not all be forced through the same agent stack. A good control plane routes by domain, KPI, and data sensitivity.
2) Clear permission boundaries
A marketing agent should not have the same privileges as a finance agent. If a platform cannot clearly describe which tools are callable, which accounts are used, and what data scope is reachable, it is not enterprise-grade infrastructure.
3) Human approval for sensitive actions
Sending quotes, editing CRM records, accessing customer profiles, or executing system commands should all have approval gates. A business cannot let “agent autonomy” become elegant language for loss of control.
4) Audit trail that operations can actually read
Logs are not only for engineers. COOs, support leaders, and founders also need to know what the agent did, why it called that tool, and where the failure occurred. Audit trails should help decisions, not just debugging.
5) Cost ceilings and workflow-level attribution
As token billing becomes normal, every workflow needs a spending cap, alerting rule, and owner-level attribution. If you cannot tell whether AI cost increased because of sales, support, or content, you cannot optimize ROI.
6) Model portability
A strong control plane does not trap the business inside one model. The same workflow should be testable across DeepSeek, Claude, or another model without rewriting the business logic.
7) Deployment sovereignty
For Vietnamese SMBs, private VPS or self-hosted deployment is not technical vanity; it is how data, logs, and operating control stay inside the company’s boundary. Vendor cloud can be convenient, but it should remain an option — never a pair of handcuffs.
The question to ask during any vendor demo: “If I want to change models in six months, tighten permissions, and keep the workflow intact, how long will it take?” If the answer is vague, lock-in has already begun.
3. How to score a vendor in 30 minutes
If I had to review a platform for a Vietnamese business today, I would score it against this checklist:
- Can it separate agents by role?
- Does it support approval gates for real actions?
- Can you inspect logs by workflow?
- Can you enforce cost ceilings or quotas?
- Can you switch models without rebuilding the workflow?
- Can it run private or self-hosted?
- Is there a clear exit path?
If it fails three or more items, do not scale it yet. Use it for experiments if you want. Do not use it as a live operating system.
4. Why this is also the logic behind Hermes Agent
At 5ac, we do not view agents as a larger chatbot. We view them as a business work orchestration layer. That means the architecture must be model-agnostic, multi-agent, auditable, and deployable on private infrastructure.
That is the logic behind G-Company OS and Hermes Agent: each agent has a role, a permission envelope, and a workflow; cost can be optimized by task; and most importantly, the business is not forced to put its operating future on Microsoft’s, GitHub’s, or OpenAI’s roadmap.
Product message: Do not choose an AI platform because the demo looks prettier. Choose the platform that still leaves you free to change models, tools, and strategy after 12 months without rebuilding from scratch.
Conclusion
“Control plane war” may sound like strategic language, but for Vietnamese SMBs it is intensely practical: who keeps the data, who controls the cost, who gets to command the agents, and who can shut them down when needed.
These seven requirements are not luxury features for large enterprises. They are the minimum standard for SMBs that want AI without locking themselves inside one vendor.
If you bring only one question into this week’s product meeting, make it this: does our AI platform let the business keep the control plane, or not?
— Peter Thiel, CSO at 5ac.vn, June 2026 · Last updated: 01/06/2026