# OpenAI (API Platform + ChatGPT Enterprise + Codex) — 4+1 Layer AI Infrastructure Assessment

> Mapped to the 4+1 Layer AI Infrastructure Model  
> Version: v1.1 - Reader-Legible Summary Lead · Date: July 22, 2026  
> Source: OpenAI product documentation (Responses API, file search and vector stores, Agents SDK, fine-tuning), OpenAI Help Center (Compliance Platform, company knowledge, gpt-oss open-weight models, Workspace Agents), AgentKit introduction (Oct 6, 2025) and Agent Builder/Evals wind-down notice (June 3, 2026; retired Nov 30, 2026), Assistants API deprecation (shutdown Aug 26, 2026), Microsoft/OpenAI restructured agreement (April 27, 2026), GPT-5.5/5.4/Codex GA on AWS Bedrock (June 1, 2026), GPT-5.6 family GA (July 9, 2026), OpenAI Frontier launch (Feb 5, 2026, limited availability), Workspace Agents research preview (April 22, 2026), OpenAI-Broadcom Jalapeño announcement (June 24, 2026), Stargate/AWS/Oracle capacity coverage, Daybreak (May-June 2026), Microsoft Purview documentation for ChatGPT Enterprise, Layer2C Labs 001/002/006, published 4+1 model. Rulings ratified on this row: substrate-surface rule (Layer 0 credit requires the substrate itself to be the purchasable thing; administered abstractions score at runtime layers); wrapper-vs-primitive discipline (cells anchor to the durable primitive; convenience wrappers concentrate lock-in and deprecation risk — Lab 001 extended); completions-interface ruling (the OpenAI-compatible completions API is a genuine multi-vendor standard, 'the S3 of inference' — model access behind it is Delegated, with capture graduated by how far past the standard interface the buyer builds); limited availability is a disqualifying status under the GA-gate (Frontier watch-listed row-wide). v1.1 (July 22, 2026): summary lead paragraph rewritten for reader legibility, matching the Anthropic row treatment; findings, grades, and DAPM unchanged.  
> Published by: The CTO Advisor LLC · thectoadvisor.com  
> Author: Keith Townsend

[Full interactive assessment](https://layer2c.com/assessment/openai) · [Methodology](https://layer2c.com/methodology) · [What Is Layer 2C?](https://layer2c.com/what-is-layer-2c)

## Executive Summary

OpenAI is the inversion of the traditional infrastructure vendor. The company conducting the largest AI infrastructure buildout in history sells none of it: Stargate, the serving fleet spread across OpenAI-operated, Azure, AWS, and Oracle capacity, and the Jalapeño inference chip are OpenAI's supply chain, not the customer's menu. What a customer can actually deploy is the top of the stack: frontier model serving, an agent runtime, and the most widely used AI application on earth. Everything below that, compute, data foundation, pipelines, orchestration, stays the enterprise's responsibility, by design.

The capture is two-tier, and the tiers point in opposite directions. The model is the commodity; the platform is the capture. The OpenAI-compatible completions interface has become the S3 of inference — a genuine multi-vendor standard implemented across the industry, hot-swappable in production when the application's logic lives in deterministic code rather than in the model — and gpt-oss is a real Apache 2.0 open-weight exit. That openness is genuine, and it is the reassuring layer. The captivity accumulates beyond it: the Responses platform surface, fine-tunes whose weights never export, the Codex harness, and above all the accumulated context estate. Consumer sentiment is the clean evidence: users don't complain about rival models' capability — they rate the alternatives as capable enough — they stay because memory and context don't move. The more judgment you borrow, the harder it is to leave as capabilities grow.

That is the same capture mechanism as the deepest coupled lock-in in enterprise software, running at conversational speed. Salesforce accumulates org config and sharing logic over decades of admin decisions; OpenAI accumulates memory, groundings, and working context per user per day, which makes it faster-compounding and harder to audit. Enterprise architects should read ChatGPT's consumer memory lock-in as the preview of what company knowledge and workspace-scale context become at enterprise scale.

The governance hole is the row's sharpest asymmetry. The vendor whose models power more production agents than anyone else's ships no generally available plane to govern them. Today, OpenAI-powered agent estates are governed by other vendors' reasoning planes — Microsoft Agent 365 registers them, MuleSoft Agent Fabric brokers and meters them, Entra Agent ID gives them identities. OpenAI is the object of everyone else's Layer 2C and the operator of none. Frontier is the reclaim attempt — agent registry, per-agent permissions, onboarding lifecycle, model-agnostic governance — and it is limited availability, watch-listed until a customer can buy it per the docs.

Platform mutability is the finding a capability grade can't carry, so the row carries it in prose: the primitives hold and the wrappers die on schedule. Custom GPTs gave way to Workspace Agents, the Assistants API shuts down August 26, 2026, Agent Builder and Evals retire November 30, 2026 — while the models, the Responses API, and the vector stores persist underneath. Lab 001's guidance, extended: build against the primitive, not the wrapper. The wrapper adds captivity and subtracts visibility while it lives, and the vendor's own history says the wrapper is the layer that dies.

The buyer's trade: frontier intelligence, the largest application estate in the market, zero infrastructure burden, and zero transmitted NVIDIA exposure. In exchange, the buyer's Layer 0 through 2A position is not just unowned but unknowable — the same token contract can be served from four different owners' silicon — and the judgment estate compounds toward captivity by default. The exits are real: the standard interface, the open weights, the multi-cloud channels. But every exit is an architectural decision the buyer must make on day one, because none of them is the default, and the default path borrows more judgment every day it runs.

## Layer Status

| Layer | Status | Classification |
|---|---|---|
| Layer 0 · Compute | ○ Not a Customer Surface (By Design) | Compute & Network Fabric |
| Layer 1A · Storage | ○ Trust Apparatus, Not a Data Foundation | Data Storage & Governance |
| Layer 1B · Retrieval | ◑ Hosted RAG Primitive | Context Management & Retrieval |
| Layer 1C · Pipelines | ○ Intake, Not Movement | Data Movement & Pipelines |
| Layer 2A · Orchestration | ○ Metered Consumption, No Customer Plane | Infrastructure Orchestration |
| Layer 2B · Runtime | ● Frontier Serving + Agent Runtime | Application Runtime & Execution |
| Layer 2C · Reasoning | ○ Enterprise Responsibility (Frontier Pre-GA) | Agentic Infrastructure — The Reasoning Plane |
| Layer 3 (+1) · Applications | ● First-Party Value Plane, Assistant Altitude | AI Application Layer — The Value Plane |

## DAPM Profile

| Classification | Count | Meaning |
|---|---|---|
| Retained | 2 | Enterprise owns and controls this capability |
| Delegated | 2 | Provided by substitutable partner; enterprise retains swap authority |
| Ceded | 9 | Vendor controls this; enterprise has no governance authority |
| Absent | 0 | No capability at this layer |

## Strongest Layers

- **Layer 2B** (Application Runtime & Execution) — Frontier Serving + Agent Runtime
- **Layer 3 (+1)** (AI Application Layer — The Value Plane) — First-Party Value Plane, Assistant Altitude

## Gap Areas

- **Layer 0** (Compute & Network Fabric) — Not a Customer Surface (By Design)
- **Layer 1A** (Data Storage & Governance) — Trust Apparatus, Not a Data Foundation
- **Layer 1C** (Data Movement & Pipelines) — Intake, Not Movement
- **Layer 2A** (Infrastructure Orchestration) — Metered Consumption, No Customer Plane
- **Layer 2C** (Agentic Infrastructure — The Reasoning Plane) — Enterprise Responsibility (Frontier Pre-GA)

## Layer-by-Layer Detail

### ○ Layer 0 · Compute: Compute & Network Fabric

*Raw compute, networking, and acceleration fabric*  
**Status:** Not a Customer Surface (By Design)

**Gap Analysis:** The buyer never thinks about silicon, and that is the pitch. Behind the API sits arguably the largest single-purpose compute buildout in history: Stargate (the Oracle/SoftBank joint venture), a $38B AWS compute commitment, roughly $250B in committed Azure consumption, and the Broadcom partnership deploying 10 GW of OpenAI-designed accelerators. None of it is an option on the architect's menu. An architect building a production system today cannot buy, rent, or administer any OpenAI compute; provisioned API capacity is a throughput commitment denominated in tokens, not compute.

The exposure test governs (ratified CoreWeave 1C vs. Supermicro 1C; applied to Salesforce's first-party data centers): an underlay capability the vendor does not surface as a purchasable, customer-administered product is not that vendor's capability. The substrate-surface rule, ratified on this row, makes the boundary decidable: Layer 0 credit requires the substrate itself to be the purchasable thing — silicon choice, instance types, fabric, placement. Compute administered through an abstraction that hides the substrate is a runtime product and scores at the runtime layers; OpenAI's container and sandbox execution surfaces are scored at 2B on exactly that basis.

The OpenAI-specific sharpening: the enterprise's Layer 0 position under the OpenAI API is not just unowned, it is unknowable. Post-restructuring, the same API contract can be served from OpenAI-operated Stargate capacity, Azure, AWS, or Oracle infrastructure, and OpenAI can move inference between them without notice. A Salesforce adoption decision resolves no Layer 0 authority question; an OpenAI adoption decision actively obscures it. The counterweight is real: gpt-oss and the Bedrock/Azure channels let an enterprise resolve the Layer 0 question deliberately by choosing the hosting channel — at which point the authority lands in that channel's row, not this one.

**Borrowed Judgment:** Total at Layer 0, and structurally invisible. The enterprise inherits the silicon, fabric, and placement judgment of whichever owner's cloud serves the request, and cannot audit which one that was. The vendor spending the most on Layer 0 on the entire instrument transmits no Layer 0 authority to its customers at all.

### ○ Layer 1A · Storage: Data Storage & Governance

*Durable, governed data foundation — the Governance Catalog that Layer 2C queries*  
**Status:** Trust Apparatus, Not a Data Foundation

**Gap Analysis:** The enterprise's data comes to OpenAI, not the reverse, and OpenAI has built real trust machinery around that fact: data residency in 10 regions (some with in-region inference), customer-managed encryption keys, SCIM, the Global Admin Console as a tenant-level control plane across ChatGPT workspaces and API organizations, retention controls, and a Compliance API exposing logs and metadata for eDiscovery and DLP workflows. For the buyer this answers the question they actually ask: can I let my people use this without losing control of our data.

None of it is a data foundation. The layer's purpose is the governed data foundation — the governance catalog a Layer 2C would query — and OpenAI ships no storage product, no catalog, no classification engine, no lineage, and no authorization authority beyond its own workspace walls. The doc-confirmed findings are decisive. Classification is inherited, not provided: when a file carries a sensitivity label, ChatGPT captures the label into the audit log; it does not author or enforce one, and the actual classification and DLP enforcement belong to third-party integrations — Microsoft publishes its own Purview guide for governing ChatGPT Enterprise, which is the tell that the governance authority for ChatGPT data is a different vendor's product. Permissions are inherited too: company knowledge respects existing permissions in connected apps, so OpenAI is a permission consumer, honoring the source system's catalog rather than being one. Honoring someone else's catalog is well-designed behavior, and it is the opposite of 1A capability.

The deciding line from the Salesforce/Qlik boundary is authorization authority versus curation, and OpenAI does not reach the curation rung: there is no catalog to curate. The uploaded files and vector stores in the API are real shipped bits, but they are derived, rebuildable copies — captive input caches for the retrieval tool — so the real-dependence guardrail does not trigger. Their weight is scored at 1B, per the precedent that splits retrieval from movement and storage.

**Borrowed Judgment:** None to borrow at this layer — the enterprise's data foundation stays wherever it already lives (SharePoint, Drive, Salesforce, the lakehouse), governed by those vendors' catalogs and the enterprise's own DLP stack. An OpenAI adoption decision transfers no data-governance authority; it adds a consumer that honors the existing authorities.

### ◑ Layer 1B · Retrieval: Context Management & Retrieval

*Low-latency retrieval for RAG — vector/hybrid search, context windows*  
**Status:** Hosted RAG Primitive

**File Search + Vector Stores (Responses API)** [DAPM: Ceded]  
GA. Managed parse/chunk/embed pipeline with hybrid semantic-plus-keyword retrieval, metadata filtering, reranking, and a standalone vector-store search endpoint any application can call — retrieval as consumable infrastructure, not an OpenAI-app-only feature. Single-vendor API with no independent implementations; the embeddings are OpenAI's models, so leaving means re-embedding and rebuilding every store and retriever binding elsewhere. The retrieval capability is scored here; its integration as a hosted tool inside the agent runtime is scored at 2B, not double-counted.

**Embeddings API** [DAPM: Ceded]  
GA. The endpoint shape is OpenAI-compatible and widely imitated, but the accumulated opinions are the vectors themselves, and vectors are useless without the same model at query time. No second vendor can serve the same embedding space, and OpenAI does not release these weights — so unlike the completions interface (Delegated at 2B, where integration code and prompts lift and recalibrate), the embedding artifacts have no exit: lift-to-leave is a full re-embed of every corpus. The standard-looking interface is the decoy; the embedding space is the capture.

**Company Knowledge + Connectors (ChatGPT)** [DAPM: Ceded]  
GA for Business/Enterprise/Edu. Cross-SaaS retrieval with citations across Slack, SharePoint, Google Drive, GitHub, Salesforce and more, honoring source-system permissions per user. The index and retrieval layer are OpenAI's; connector configuration and enabled-app decisions live in OpenAI's admin plane. The source data staying put is the decoupled-capture decoy: the bytes remain in the source systems while the grounding layer accumulates in OpenAI.

**Gap Analysis:** Two real surfaces, one infrastructure and one product. The infrastructure surface: file search on vector stores in the API. Upload files and OpenAI handles parsing, chunking, embedding, and hybrid semantic-plus-keyword retrieval with metadata filtering and reranking, composable with the Responses API and Structured Outputs. Critically, a standalone vector-store search endpoint exists, so a non-OpenAI application can consume the retrieval directly — the external-consumption gate that separated Salesforce (strong) from Qlik (moderate), and OpenAI clears it. The product surface: company knowledge in ChatGPT — retrieval across the connected SaaS estate (Slack, SharePoint, Drive, GitHub, Salesforce) with citations and source-permission inheritance. That is the Azure M365-grounding play made cross-vendor: OpenAI retrieves from everyone's corpus, a grounding reach even Microsoft cannot claim outside its own estate.

What holds the cell at moderate is rule 4 and rule 6 together. The pipeline shape is fixed: upload, OpenAI parses, OpenAI chunks, OpenAI embeds, hybrid search. No bring-your-own embeddings, no insertable stages, no structured-data retrieval, no index architecture beyond the exposed knobs. That is the NetApp AIDE precedent almost exactly — fixed stages terminating in the vendor's own retrieval surface scored moderate — versus the VAST DataEngine's arbitrary-functions strong. Frontier check (rule 6): the 1B frontier is integrated enterprise retrieval platforms (Azure AI Search's full search-engine architecture, Vertex AI Search, Salesforce's permission-aware VDMO stack, Databricks). File search is a hosted RAG primitive for agent knowledge bases — real, GA, deployable, externally consumable, and a slice of the layer's function rather than the general enterprise retrieval platform. Moderate is that trade stated honestly: above Dell's Delegated-to-Elastic moderate (OpenAI's is first-party IP), below the platform frontier.

**Borrowed Judgment:** The retrieval intelligence is entirely OpenAI's and entirely opaque: chunking defaults, the embedding model, ranking behavior, and the agentic query planning inside deep research are opinions the enterprise inherits and cannot inspect. The capture is the decoupled kind: the documents stay in Slack and SharePoint, feeling portable, while the retriever configurations, vector stores, and agent grounding accumulate in OpenAI's namespace. Wrapper-vs-primitive guidance applies (Lab 001, 'Borrow the vendor's plumbing, not its judgment', June 27, 2026), extended by this row's own history: the wrapper adds captivity and subtracts visibility while it lives, and the vendor's deprecation record says the wrapper is the layer that dies. Build against the primitive.

### ○ Layer 1C · Pipelines: Data Movement & Pipelines

*Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering*  
**Status:** Intake, Not Movement

**Gap Analysis:** Thin by design. What exists: batch ingestion into vector stores (the upload-parse-chunk-embed path scored at 1B), the Batch API for asynchronous bulk inference at half price, and connector-based sync where company knowledge pulls from SaaS sources on OpenAI's schedule. The buyer never builds an ETL pipeline to use OpenAI, and that is the offer: bring nothing, connect and go.

There is no data movement platform here. No ETL/ELT authoring, no lineage, no CDC, no cost-aware movement, and no administrable KV-cache tiering surface — OpenAI runs prompt caching internally, but it is a billing discount, not a tier the architect manages. Movement between the enterprise's systems remains entirely the enterprise's problem, solved with someone else's tools (MuleSoft, Informatica, Glue, Airflow). The connector sync is fixed-function ingestion feeding OpenAI's own retrieval surface — the narrowest possible slice of this layer.

Calibration: Salesforce holds strong here on two owned movement platforms; Qlik's strong ran on CDC plus Talend; Dell's moderate carries an owned orchestration engine. OpenAI has no movement product at all, and the shipped bits are features of the retrieval and inference products. The real-dependence guardrail does not trigger: connector configs are trivially rebuildable and the Batch API holds no accumulated opinions. Where Salesforce moves and governs records between systems that were never designed to talk, OpenAI moves nothing between anyone's systems but its own intake.

**Borrowed Judgment:** None to borrow — the movement function stays with the enterprise and its existing integration stack. The sync cadence of company-knowledge connectors is OpenAI's judgment, inherited invisibly, and it is scheduling texture rather than a pipeline authority.

### ○ Layer 2A · Orchestration: Infrastructure Orchestration

*GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization*  
**Status:** Metered Consumption, No Customer Plane

**Gap Analysis:** There is nothing to operate, and as with Salesforce, that is the offer. OpenAI provisions, schedules, and scales the entire inference fleet invisibly. What the customer touches is the commercial metering edge: rate limits and usage tiers, Scale Tier and provisioned-throughput commitments for guaranteed API capacity, priority and flex service tiers trading latency for price per request, the Batch API queue, and per-project quota and budget administration through the admin console.

No GPU plane is exposed. No scheduler, no quotas on compute (quotas are on tokens), no fair-share configuration, no utilization visibility. The Salesforce precedent decides the grade: Salesforce earned moderate at 2A on Runtime Fabric — a real orchestration product the customer deploys on their own Kubernetes — while its governor limits and consumption metering were ruled to weigh on the authority reading rather than lift the capability grade. OpenAI has no deployable orchestration artifact of any kind; everything the customer configures is denominated in tokens and dollars, never in compute, scheduling, or placement. A procurement surface is not an orchestration surface. The layer's function stays with whoever hosts the workload: the enterprise's own cluster for gpt-oss, the cloud's 2A for the Bedrock and Azure channels.

The authority sharpening from Layer 0 recurs at this layer's altitude: the enterprise cannot see which silicon, which region, or even which owner's cloud served a request. Substrate-level decision provenance — which model instance, at what cost or compliance tier — is structurally unanswerable for the customer. You cannot audit what you cannot configure.

**Borrowed Judgment:** Total for the serving substrate, and unauditable. The enterprise inherits an unconfigurable orchestration plane spread across a multi-owner fleet, with the metering edge as the only visible surface of that authority.

### ● Layer 2B · Runtime: Application Runtime & Execution

*Model serving, agent execution, inference APIs, distributed inference*  
**Status:** Frontier Serving + Agent Runtime

**Model Serving via the OpenAI-Compatible Completions Interface** [DAPM: Delegated]  
GA. Frontier models consumed through the interface the industry standardized on: independent vendors (vLLM, the inference clouds, competing model providers) implement the same API, so integration opinions lift and providers hot-swap without rebuilding — the S3 of inference. The remaining switching cost is behavioral recalibration (prompts and evals re-validated against a different model), the managed-Kubernetes kind of cost that kept managed K8s Delegated across the cloud rows. Depth of prompt-calibration to one model's dispositions is a graduated capture narrated in borrowedJudgment, not a component chip.

**Responses API Platform Surface (Stateful Runtime + Hosted Tools)** [DAPM: Ceded]  
GA. The proprietary surface layered beyond the standard interface: stateful sessions, hosted tool execution (code-interpreter containers, computer use, web search, file search integration), structured outputs orchestration. Opinions built against it run nowhere else. This is the industry-standard-then-proprietary-surface pattern the litmus names at S3 (a captive engine layered past the open interface), executed by OpenAI on its own product line. The container/sandbox execution inside it is the landing spot for the Layer 0 ruling: execution-as-a-service on an invisible, unchoosable substrate.

**Fine-Tuning + Reinforcement Fine-Tuning** [DAPM: Ceded]  
GA. Managed customization whose accumulated opinions live in weights the customer can never take — fine-tunes on OpenAI's platform do not export. Lab 002 ('Own the weights, or the platform owns you', July 1, 2026): the managed path takes the weights, and against an owned-weights alternative the token price becomes a rented floor.

**Codex (Cloud Agent + CLI + Sandboxes)** [DAPM: Ceded]  
GA, including on AWS Bedrock (June 1, 2026). Hosted autonomous coding agent with cloud sandboxes and terminal/IDE surfaces. The harness, sandbox environments, and execution opinions are OpenAI-hosted; AGENTS.md conventions are portable texture, the harness is not. The runtime is scored here; the developer-application altitude is scored at Layer 3, not double-counted.

**Agents SDK (Open-Source)** [DAPM: Retained]  
GA. Open-source agent framework — handoffs, guardrails, sessions, tracing — self-hostable and runnable against any compatible endpoint. Matches the Microsoft Agent Framework and Google ADK Retained calls: agent code built on the open SDK lifts out; the substrate is the enterprise's.

**gpt-oss Open-Weight Models (Apache 2.0)** [DAPM: Retained]  
GA (self-managed; OpenAI provides no support for self-hosted deployments). gpt-oss-120b (o4-mini-class reasoning, datacenter GPUs) and gpt-oss-20b (high-end consumer hardware). The one place on the row where the enterprise can own OpenAI-lineage intelligence outright: weights lift anywhere, no vendor required. No other closed frontier lab on the instrument ships an escape valve at this capability class.

**Gap Analysis:** The deepest inference and agent-execution surface on the instrument. Model serving at the industry's largest scale through the Responses API: the GPT-5.6 family (Sol/Terra/Luna, GA July 9, 2026), GPT-5.5/5.4, Codex models, all multimodal. Around the serving core, a real agent runtime estate: the open-source Agents SDK (handoffs, guardrails, sessions, tracing), Codex as a hosted autonomous coding agent with cloud sandboxes, hosted tool execution (code-interpreter containers, computer use, web search, file search), ChatKit for embedding, and managed fine-tuning including reinforcement fine-tuning. And the escape valve no other closed frontier lab ships: gpt-oss-120b and gpt-oss-20b, Apache 2.0 open-weight models an enterprise can run on its own hardware with no OpenAI relationship at all.

Frontier-pegged strong by rule 6 and genuinely at the frontier: the serving scale, the model family, and the agent-execution estate stand with Azure Foundry and the Gemini Enterprise Agent Platform, and above them on raw serving. The capable-but-captive ruling applies cleanly: platform binding is an authority finding on the DAPM axis, not a capability deduction.

The authority map is graduated, and that is this cell's distinctive finding. The completions interface has become the S3 of inference: a genuine multi-vendor standard implemented by independent vendors across the industry, with an entire routing ecosystem existing precisely because swaps work. Plain completions consumption is therefore the most portable position in the OpenAI relationship (Delegated). Every step past the standard interface — Responses-native state and hosted tools, fine-tunes, the Codex harness — moves authority toward Ceded. Capture is not a property of the vendor relationship; it is a function of how far past the standard interface the buyer builds.

**Borrowed Judgment:** The most concentrated model-judgment inheritance on the instrument: alignment, refusal behavior, safety tuning, and — distinctly — lifecycle judgment. OpenAI retires and swaps models on its own cadence, and behavior drifts under the enterprise's feet unless versions are pinned; the wrapper-churn finding at 1B has a model-layer sibling here. The mitigations are real: version pinning, the four-month first-mover lag before models reach other clouds, and the gpt-oss exit. The switching cost itself is architectural, not fixed: production swaps across model vendors — Gemini-class to GPT-5.6-class with no rebuild — are documented where the application's logic lives in deterministic code and the model does bounded work behind the standard interface (Lab 006, 'Put the judgment in the constraints, not the weights'). DCITL-style builds make the model a commodity; prompt-deep builds re-create Ceded one prompt at a time. The vendor does not decide which position the buyer is in. The buyer's architecture does.

### ○ Layer 2C · Reasoning: Agentic Infrastructure — The Reasoning Plane

*Policy-driven placement and resource coordination — the Autonomy Layer*  
**Status:** Enterprise Responsibility (Frontier Pre-GA)

**Gap Analysis:** What ships today: workspace and tenant administration with RBAC over which connectors, apps, and tools users and agents may touch; the Compliance API streaming full interaction logs into eDiscovery/DLP/SIEM tooling; guardrails as an open-source library inside the Agents SDK; sandbox-level controls on Codex cloud environments (network egress policy, secrets handling); and user-confirmation gates on consequential agent-mode actions. An enterprise can constrain what OpenAI's surfaces are allowed to reach, and audit what happened after the fact.

None of that is a reasoning plane, and the sharper finding is that OpenAI's actual 2C story is entirely pre-GA. Frontier — the agent registry, per-agent permissions, onboarding lifecycle, feedback loops, model-agnostic governance, the 'treat agents like employees' claim — is the productized 2C, and it is limited availability, watch-listed under the GA-gate. What is GA is platform administration, not agent governance: no agent identity system, no registry, no cross-agent gateway or broker, no policy engine evaluating anything at request time beyond connector allow-lists.

Calibration is the crisp part. The moderate cohort at 2C (Salesforce, AWS, Databricks, IBM) earned it on a productized governance plane — gateway plus registry plus governed agent identity, GA, enforcing statically authored policy. The gap cohort is defined as inherited permissions and at most a thin gateway rather than a productized governance plane. OpenAI's GA surface — inherited source-system permissions, workspace RBAC, log export, a client-side guardrails library — matches the gap cohort's description almost word for word. The real-dependence guardrail does not rescue it: admin RBAC is dependence on platform administration, the same trust apparatus ruled sub-threshold at 1A.

The headline finding: the vendor whose models power more production agents than anyone else's ships no GA plane to govern them. Today, OpenAI agents are governed by other vendors' 2C products — Microsoft Agent 365 registers them, MuleSoft Agent Fabric brokers and meters them, Entra Agent ID gives them identities. OpenAI is the object of everyone else's reasoning plane and the operator of none, pending Frontier — which is honestly framed as OpenAI's attempt to reclaim the governance layer currently being built on top of it.

The universal findings are logged as universal, not charged to this vendor: no live infrastructure placement (the customer cannot even express a placement policy — consistent with the 2A finding that the fleet is multi-owner and invisible), and no deterministic outcome validation (SDK guardrails are prompt-shaped or code the developer writes; the platform validates legality of tool access, never rightness of outcome — you can't prompt your way to deterministic output). Routing-is-not-reasoning, vendor-specific note: ChatGPT's automatic model routing across the 5.6 family is opaque vendor-side model selection, the same sub-threshold signal as Salesforce Default's managed mix.

**Borrowed Judgment:** There is no judgment to borrow — the enterprise retains full responsibility for this function, and in practice discharges it with a different vendor's product. An OpenAI-centric agent estate today has someone else's reasoning plane or none. That is the most consequential architecture decision an OpenAI buyer makes, and it is made outside the OpenAI relationship entirely.

### ● Layer 3 (+1) · Applications: AI Application Layer — The Value Plane

*AI-powered business capabilities — business logic, workflow automation*  
**Status:** First-Party Value Plane, Assistant Altitude

**ChatGPT Enterprise (Knowledge-Work Application Estate)** [DAPM: Ceded]  
GA. The horizontal knowledge-work surface: projects, company knowledge, deep research, agent mode, memory. The accumulated workspace estate — habits, instructions, groundings, working context — is the fastest-compounding captive artifact set on the instrument, and it survives model interchangeability entirely: swap the model underneath and none of it moves, which is precisely what makes it the moat. Proprietary platform, no open exit.

**Codex (Developer Application)** [DAPM: Ceded]  
GA across cloud, CLI, and IDE surfaces. The application-altitude relationship: issue-to-PR delegation, code review, autonomous task execution against the enterprise's repos. AGENTS.md conventions are portable texture; the application relationship and its accumulated delegation patterns are not. Runtime scored at 2B, not double-counted.

**Sora (Video / Creative Generation)** [DAPM: Ceded]  
GA as application and API (doc-confirmed via standard customer dashboard availability, July 2026). Creative-generation surface; prompts, styles, and workflow integrations are captive to the platform. Proprietary, no open exit.

**Apps in ChatGPT + Apps SDK (MCP)** [DAPM: Delegated]  
GA (connectors renamed to apps December 17, 2025). Menu-altitude Delegated, matching AppExchange and Dell's Ecosystem Program: the pre-purchase choice among third-party apps is real, and each deployed app captures per its own terms. The interface split from 2B replays in miniature: an app's MCP-server core is built on a genuine multi-vendor standard and lifts to other MCP hosts; the OpenAI-specific UI components and the directory/monetization surface sit beyond the standard. The distribution judgment — which app ChatGPT invokes for a user's intent — is OpenAI's, and opaque.

**Gap Analysis:** The largest-installed-base AI application on earth, and the row's center of gravity for the business buyer. ChatGPT Enterprise/Business is the horizontal knowledge-work surface: projects, company knowledge, deep research, agent mode. Codex is the developer application (runtime scored at 2B; the application altitude scores here, per the Azure precedent that put Foundry at 2B and GitHub Copilot at 3). Sora covers video and creative generation, as an application and through the API. Apps in ChatGPT (connectors renamed December 17, 2025) plus the Apps SDK turn ChatGPT itself into a distribution surface where third-party software meets users inside the conversation. Daybreak (May-June 2026) extends into a defensive-cybersecurity vertical.

Strong, frontier-pegged, with the caveat named the way peers got theirs. This is a first-party value plane peer to Salesforce's on installed base, breadth, and product maturity. The caveat: OpenAI's GA Layer 3 is assistant-altitude — knowledge work, coding, creative. The business-execution altitude (agents executing workflows in systems of record under commit-boundary governance, which is what Salesforce's strong does all day) is exactly the part of OpenAI's story that is pre-GA: Frontier is limited availability, Workspace Agents is research preview. The strong stands on what ships; the caveat keeps it honest about domain.

A distribution-authority finding new to the instrument: when ChatGPT decides which third-party app to invoke for a user's intent, OpenAI holds app-store-grade distribution judgment inside the conversation itself, opaque to both the enterprise and the ISV.

**Borrowed Judgment:** The capture here is coupled and visible, Salesforce-style, but broader and faster-compounding: the workforce's daily habits, projects, custom instructions, memory, and grounded workflows accumulate in OpenAI's namespace and lift nowhere — and they accumulate per user per day rather than per admin per release cycle. Practitioner-conversation sentiment supplies the clean evidence, because it holds capability constant: users of the consumer product do not complain about rival models' capability — they rate Gemini and Claude as capable enough for their needs — they stay because the memory and context do not move. The moat was never the model. The model is the commodity (proven by production swaps at 2B); the platform surfaces and the accumulated context estate are the capture, which is why the platform owners are racing up-stack while the models commoditize underneath them. The more judgment you borrow, the harder it is to leave as capabilities grow. The blast-radius point from the Azure row applies at maximum width: this is every employee's daily tool, not a department's.

---
*Layer2C · AI Infrastructure Decision Intelligence · The CTO Advisor LLC · thectoadvisor.com*
