SAP is the largest first-party value plane on the instrument with a governed data plane underneath it and a serving-and-agents runtime between, and the row reads that way: strong at the data foundation (Layer 1A), retrieval (1B), the runtime (2B), and the applications (Layer 3), moderate at the substrate SAP now operates itself (Layer 0), at orchestration (2A), at pipelines (1C), and at the reasoning plane (2C). Authority is the SaaS shape with more seams than most: nearly everything is SAP intellectual property (IP) and Ceded, with Delegated readings where the consumed interface is a multi-vendor standard (Delta Sharing at 1A and 1C, the Kubernetes API and Cloud Foundry at 2A) or where SAP brokers models the enterprise can swap or hosts models the enterprise owns (the generative AI hub and AI Core at 2B), and one Retained decision-authority reading at 1C, where SAP's engines execute flows the enterprise wrote without judgment of their own.
The capture is coupled and visible, and it runs through the business semantics rather than the bytes. BDC Connect leaves the data in place and shares it live over an open protocol, which is true and reassuring, while the data products, the master data rules, the HANA schema, the knowledge graph, the Joule agents, and the skills and automations built in SAP Build accumulate in SAP; the Salesforce decoupled pattern, at larger scale. Decision authority follows the code where there is code: the enterprise's flows decide at 1C; the model decides inside the agent loop at 2B with a documented per-tool confirmation toggle as the enterprise's gate; SAP's engines decide placement and ranking on policy the enterprise writes at 1A, 1B, and 2A; SAP alone decides at Layer 0 and Layer 3; and at 2C the enterprise's own policy is the last word over a plane whose identity, agent-level observability, and bidirectional agent gateway are dated for the second half of 2026.
The buyer gets a governed multi-model database with an in-database vector and graph engine, mastering and lineage on the vendor's own paper, any-model serving plus custom-model hosting on graphics processing unit (GPU) instance types, a generally available agent builder with deterministic execution, and the application suite the enterprise already runs. In exchange: a data-engineering surface that's deepest for SAP sources, a governance plane designed complete and shipped partial, and a platform whose artifacts run nowhere else. What moves this row: generally available (GA) product documentation for Agent Hub identity and access control and the agent-to-tool enforcement point (2C to strong); a general CDC and transformation surface with external targets in one step (1C to strong); public production documentation for GPU worker pools on Kyma (2A's GPU plane).
Layer-by-layer status: Layer 0 (SAP-Operated IaaS in SAP Data Centers; Sovereign Cloud On-Site; Hyperscalers for the Rest), Layer 1A (Governed Business Data Cloud: HANA, Data Products, Mastering, Zero-Copy), Layer 1B (In-Database Vector + Knowledge Graph + Grounding Service; Embedding Choice), Layer 1C (iPaaS + Datasphere Replication with SAP-Source CDC + Zero-Copy Sharing; Transformation Stays Local), Layer 2A (Managed Kubernetes (Kyma) + AI Core GPU Instance Types + Cloud Foundry; No Fair-Share), Layer 2B (Generative AI Hub Serving + AI Core Custom Models + Joule Studio Agents; Any-Model), Layer 2C (Registry GA + MCP Gateway GA + Joule Orchestration; Identity, Agent Observability, and A2A Dated H2 2026), Layer 3 (+1) (First-Party Business Applications with Joule Across the Suite; Autonomous Suite Arriving).
Assessment framework: 4+1 Layer AI Infrastructure Model. Scoring model: Decision Authority Placement Model (DAPM) — Retained, Delegated, or Ceded. Published by The CTO Advisor LLC (DBA The Advisor Bench). Author: Keith Townsend. Date assessed: September 5, 2026. Version: v1.0 - 4+1 v2: Authority Split.
Raw compute, networking, and acceleration fabric
An open-source-based, API-first IaaS platform with self-service provisioning, automation, and consistent resource management, operated in SAP-owned data centers and co-locations worldwide, running SAP's services and customer-specific workloads. Commodity hardware under SAP's stack and catalog; the provisioning opinions are SAP's unless the API is a multi-vendor standard (flagged). Ceded.
Globally available since September 2025: SAP provides and manages the full technology stack from hardware to SAP Cloud Infrastructure and the Sovereign Cloud portfolio in a customer-designated facility. An integrated system SAP procures and operates; physical control on site, authority with SAP. Ceded under the integrated-system rule.
SAP AI Core's flexible instance types reach NVIDIA L4, L40S, and H100 on hyperscaler capacity; the Joule Studio runtime and NVIDIA partnership features announced at Sapphire 2026 have GA planned for Q3 2026. SAP sells no silicon; the dependency is inherited through the clouds and instance types SAP exposes.
SAP has a Layer 0 of its own, which most software rows don't. SAP Cloud Infrastructure is an SAP-developed, SAP-operated infrastructure-as-a-service (IaaS) platform in SAP-owned data centers and co-locations: open-source-based, API-first, with self-service provisioning and automation, running SAP's cloud services and customer-specific workloads on one infrastructure; its German data centers achieved ISO/IEC 27001 on the basis of IT-Grundschutz in April 2026. SAP Sovereign Cloud is generally available for RISE with SAP across regions, and SAP Sovereign Cloud On-Site (globally available since September 2025) has SAP provide and manage the full stack, from hardware to SAP Cloud Infrastructure, inside a customer-designated data center. The rest of the estate runs on hyperscalers: SAP Business Technology Platform (BTP) has regions on Amazon Web Services (AWS), Microsoft Azure, Google Cloud, Alibaba Cloud, and SAP Cloud Infrastructure, while SAP Business Data Cloud, Joule, and SAP AI Core follow a controlled regional rollout on AWS, Azure, and Google Cloud. The buyer gets sovereignty as a product line, from hyperscaler regions to SAP's own floor to SAP's rack in their building. The exposure test decides the grade. On the hyperscaler paths the substrate is invisible behind a software-as-a-service (SaaS) interface, the Salesforce and ServiceNow reading. SAP Cloud Infrastructure is different: it's purchasable, it's customer-administered through self-service provisioning, and it runs the customer's own workloads, so it's a scored capability, and shipped bits the enterprise depends on make the layer moderate rather than gap. What keeps it from strong is what the clouds have and SAP doesn't: owned silicon, an AI fabric, or GPU capacity of its own. On-Site is SAP-procured, SAP-operated hardware under the integrated-system rule. Calibration: AWS, GCP, and Azure read strong on owned data centers and custom silicon; HPE strong on hardware it builds and operates; Salesforce, ServiceNow, and Snowflake gap with the substrate absorbed beneath the service; VMware moderate on an abstraction layer over other people's hardware. SAP is a real operator of commodity infrastructure without silicon or fabric of its own: moderate.
The substrate judgment is SAP's on SAP Cloud Infrastructure and On-Site (data centers, hardware procurement, the open-source stack) and the hyperscaler's elsewhere. On SAP's own paths the enterprise provisions inside SAP's catalog and sees it, but the placement, hardware, and stack decisions are SAP's with no runtime override: vendor decides, visible, not overridable, Ceded. The hyperscaler paths inherit the Ceded-invisible reading.
Ruled moderate (Keith, September 5, 2026): SAP Cloud Infrastructure is a self-service IaaS running customer workloads, which passes the exposure test; a no-peer shape on the map, now its own precedent. Inference flagged: whether SAP Cloud Infrastructure's API is OpenStack-compatible or a multi-vendor standard (which would read Delegated) or SAP's own. Watch-list, notes only: European Union (EU) AI Cloud (November 2025) and the twenty-billion-euro sovereign investment; Joule Studio runtime and NVIDIA partnership features (GA planned Q3 2026).
Durable, governed data foundation — the Governance Catalog that Layer 2C queries
The in-memory multi-model database, generally available natively in Business Data Cloud with shared capacity pooling. Proprietary engine and schema; the accumulated models don't lift.
SAP-managed data products with business semantics, Datasphere modeling, lineage, and access control within the SAP perimeter, Business Warehouse and Analytics Cloud under the same experience. SAP objects with no second implementer.
The mastering leg: master data governance as a core BDC component, generally available. Rules and workflows are SAP's model.
A trimmed Databricks with Unity Catalog, Mosaic AI, and SQL warehouse embedded in BDC on a controlled regional rollout (AWS, Azure, Google Cloud, with some regions still excluded), with SAP semantic metadata and governance tags synced into the catalog. Databricks' governance under SAP's paper: Ceded to its owner through SAP, the channel-substitution rule.
Bidirectional, live sharing of governed data products with the customer's Databricks, Snowflake, or BigQuery over the Delta Sharing protocol; data stays in place at the source and is queried there (BigQuery caches blocks locally and lacks fine-grained access control on the shared tables). A multi-vendor interface with a substitutable consumer: Delegated, the Databricks Marketplace-via-Delta-Sharing and Salesforce zero-copy readings.
The data foundation is SAP HANA Cloud and Business Data Cloud; nothing here depends on NVIDIA.
This is the layer SAP rebuilt the company around in 2025 and 2026. SAP Business Data Cloud (BDC) brings Datasphere, Business Warehouse, and Analytics Cloud under one experience, ships SAP-managed data products with business semantics, and embeds SAP Databricks (a trimmed Databricks with Unity Catalog, Mosaic AI, and a Structured Query Language (SQL) warehouse) inside the SAP perimeter on a controlled regional rollout across AWS, Azure, and Google Cloud. SAP HANA Cloud runs natively in BDC with shared capacity pooling (generally available), and it's a multi-model database: relational, in-database vector, and a knowledge graph engine in one system. Governance is an authorization authority: SAP Master Data Governance is generally available as a BDC component, Datasphere carries lineage and access control inside the SAP perimeter, and semantic metadata and governance tags (including personal-data tags) sync into Unity Catalog for attribute-based access control. Reach beyond the perimeter is zero copy and bidirectional: BDC Connect shares governed data products live over Delta Sharing with Databricks (October 2025), Snowflake (early 2026), and Google BigQuery (2026), with Microsoft Fabric targeted for the third quarter and Amazon Athena for the first half of 2027. The Dremio acquisition (announced May 4, completed July 6, 2026) points at Apache Iceberg and a format-agnostic BDC. The deciding line is the one that separated Salesforce (strong) from Qlik (moderate): authorization authority enforced at runtime, and a general data plane with mastering, quality, and lineage. SAP has both on its own paper. Master Data Governance is the mastering leg Salesforce had to buy Informatica for; Datasphere and the data products carry lineage and semantics; HANA Cloud is a general database. Rule 4 holds: the plane serves any data, not only SAP's. The architect's concern is the decoupled split every lakehouse row carries, with the governance edge named: the shared data stays at its source and is queried in place, and the data-product semantics, the governance tags, the HANA schema, and the mastering rules accumulate in SAP; in BigQuery the shared tables don't support fine-grained access control, so the authority that travels with the share is coarser than Unity Catalog's. Calibration: Snowflake and Databricks read strong on a governed lakehouse plus a catalog; Salesforce strong on authorization authority plus Informatica; ServiceNow moderate on a workflow system of record plus a catalog without mastering. SAP stands with the first three. Strong.
Low for the governance logic, which is SAP IP and Ceded: HANA Cloud, the data products, Master Data Governance, and Datasphere's semantics and lineage. SAP Databricks inside BDC is Databricks' catalog under SAP's paper, Ceded to its owner. BDC Connect is Delegated on the consumed interface: Delta Sharing is a multi-vendor protocol, the data stays at its source and is queried in place, and the consuming warehouse is substitutable. The runtime tradeoff is SAP's engine placing and serving data on policy the enterprise writes: vendor decides, visible, overridable per object, Delegated, the Snowflake and Databricks reading.
Watch-list, notes only: SAP Domain Models (early adopter; GA planned Q3 2026); BDC Connect for Microsoft Fabric (Q3 2026) and Amazon Athena (first half 2027); Autonomous Data Governance (observability, quality, privacy; second half 2026); Apache Iceberg support following the Dremio acquisition (completed July 6, 2026); BDC Agentic AI (private preview). BigQuery limitation named in the cell: SAP Delta Sharing tables don't support fine-grained access control there, and cross-cloud queries cache data blocks in the Google Cloud region. Public evidence that moves the cell: nothing upward from strong.
Low-latency retrieval for RAG — vector/hybrid search, context windows
Native vector type with cosine and Euclidean similarity in SQL and full-text search for hybrid retrieval; a LangChain integration ships. The store is SAP's database: Ceded, low blast radius (vectors export as arrays).
SAP's own embedding model generating vectors inside HANA Cloud (768 dimensions; German, English, Spanish, French, Portuguese). Embedding carve-out: Ceded.
OpenAI, Google Gemini, and other embedding models reached through the hub's harmonized API and stored in HANA. Ceded to the model owner through SAP's paper; open-weights models the enterprise serves itself are the Delegated exception.
Graph storage and SPARQL over RDF in the same database as the vectors, so semantic similarity and fact-based traversal compose. SAP engine.
The orchestration service's grounding stage with Document Grounding and the HANA vector store behind it. SAP service with no second implementer.
Embeddings run in HANA Cloud or at the provider chosen through the generative AI hub; the GPUs behind third-party models are the providers'.
Retrieval infrastructure the enterprise builds on, inside the database it already runs. SAP HANA Cloud's vector engine stores embeddings in a native REAL_VECTOR type with cosine and Euclidean similarity in SQL, generates embeddings in-database with the VECTOR_EMBEDDING function on SAP's own model (SAP_NEB, 768 dimensions, five languages), and combines with full-text search for hybrid retrieval; the knowledge graph engine adds SPARQL (the RDF query language) over Resource Description Framework (RDF) in the same system, so vector similarity and fact-based traversal compose in one query. Above the database, the generative AI hub's orchestration service has a grounding module with Document Grounding and a HANA vector store behind it, and any embedding model on the hub (OpenAI, Gemini, and others) can populate the store. A LangChain integration ships; other frameworks work through the hub's SDKs and custom code. The buyer gets a vector store with a SQL application programming interface (API), embedding choice, a graph engine, and a managed grounding pipeline without a second system. The architect's concern is the usual one at this layer. The vectors are only as portable as the model that made them (SAP_NEB is SAP's; third-party embeddings are their owners'), and the grounding pipeline and the HANA schema are SAP's. Rule 4 holds: the store and the engine serve any retrieval workload, not only SAP experiences, which is what separates this cell from ServiceNow's. Calibration: Snowflake reads strong on a VECTOR type plus Cortex Search and semantic views; Databricks strong on Mosaic AI Vector Search; Elastic strong as the retrieval engine itself; Salesforce strong on a governed retrieval surface; ServiceNow moderate on a platform-scoped feature with no surface. SAP matches Snowflake's legs and adds an in-database knowledge graph engine that no lakehouse row scores. Strong.
Low for the mechanism and split at the model. The vector engine, the knowledge graph engine, and the grounding module are SAP IP and Ceded; SAP_NEB embeddings are Ceded under the embedding carve-out; third-party embeddings through the generative AI hub are Ceded to their owners under the channel-substitution rule, with any open-weights model the enterprise serves itself reading Delegated. The runtime tradeoff is HANA executing the similarity and graph queries the enterprise writes per request: vendor decides, visible, overridable, Delegated under the override rule.
Watch-list, notes only: SAP Knowledge Graph and SAP Domain Models as Joule grounding assets (Domain Models early adopter, GA planned Q3 2026; the knowledge graph engine in HANA Cloud is the scored product, SAP Knowledge Graph as a Joule asset is context). Instrument follow-up: Snowflake and Databricks 1B read vendor / Ceded on managed retrieval services; SAP's SQL-composed retrieval reads Delegated on per-request override, the Elastic reading. Public evidence that moves the cell: nothing upward from strong.
Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering
The iPaaS: integration flows with mapping and scripting, API management, and eventing across SAP and non-SAP systems. Flows and policies are SAP artifacts that rebuild elsewhere.
Configuration-first replication with trigger-based change data capture from S/4HANA and ECC CDS views, and outbound replication to Google BigQuery, Amazon S3, Google Cloud Storage, Azure Data Lake Storage Gen2, and Apache Kafka under the paid Premium Outbound Integration; Snowflake isn't a supported target. Datasphere objects with no second implementer.
Arbitrary transformation into Datasphere local tables, from which replication flows carry results outbound. Two steps for an external destination. SAP artifacts.
The movement-avoidance half, scored at 1A and referenced here: live governed sharing rather than replication. Delegated on the multi-vendor protocol.
Nothing in the integration and pipeline estate depends on NVIDIA.
Two platforms sit here on SAP paper. SAP Integration Suite is the integration platform as a service (iPaaS): Cloud Integration flows with arbitrary mapping and scripting, API Management, and Event Mesh across SAP and non-SAP systems. SAP Datasphere is the data-engineering half: replication flows with change data capture (CDC) from S/4HANA and enterprise resource planning (ERP) Central Component (ECC) through Core Data Services (CDS) views (trigger-based deltas after an initial load), data flows and transformation flows for transformation, and, with the paid Premium Outbound Integration, replication from Datasphere into Google BigQuery, Amazon Amazon S3 (Simple Storage Service), Google Cloud Storage, Azure Data Lake Storage Gen2, and Apache Kafka. BDC Connect adds the movement-avoidance path, sharing governed data products live over Delta Sharing rather than copying them, and the Dremio acquisition (completed July 6, 2026) points at Iceberg. Datasphere carries lineage. Rule 4's decidable test is where the grade lands. Integration Suite passes it for application integration. Datasphere's documentation separates its flows: data flows and transformation flows write only to Datasphere local tables, and replication flows reach external targets with projection and mapping rather than arbitrary transformation. An arbitrary transformation bound for an external destination therefore takes two steps inside Datasphere (transform to a local table, then replicate outbound), and the outbound target list is object stores, BigQuery, and Kafka: Snowflake isn't a supported replication target and Databricks is reached through Delta Sharing, not replication. CDC is deepest for SAP sources. That's a real, general-in-kind pipeline platform with two documented scope gates (rule 5): transformation stays local, and CDC is SAP-centric. Calibration: Salesforce reads strong on MuleSoft plus Informatica, and Qlik strong on any-to-any CDC plus Talend, both general on source and destination in one step. Snowflake and Databricks read strong on general pipeline engines. ServiceNow reads moderate on an integration fabric with no CDC or extract, load, transform (ELT); Elastic moderate on a telemetry pipeline. SAP sits between: more than ServiceNow (real CDC, real outbound replication, real transformation), less than Qlik (SAP-source CDC, two-step transformation to external targets). Moderate, with the strong case named and escalated.
Low. Integration Suite, Datasphere's flows, and the lineage are SAP IP and Ceded; BDC Connect is Delegated on the Delta Sharing protocol. The runtime is SAP's engines executing flows the enterprise authored deterministically, with load type and delta frequency set by the enterprise and no vendor judgment about what moves where: code decides, visible, overridable, Retained, the Elastic, VAST, and ServiceNow reading under the override rule.
Ruled moderate (Keith, September 5, 2026) on two documented scope gates: transformation flows write only to local tables, and CDC is SAP-source-centric; a two-step transform-then-replicate path doesn't clear the Qlik and Informatica single-step bar. Watch-list, notes only: Apache Iceberg support following the Dremio acquisition; BDC Connect for Microsoft Fabric (Q3 2026) and Amazon Athena (first half 2027). The Model Context Protocol (MCP) Gateway is scored at 2C, not here: agent tool exposure isn't movement, the ServiceNow reading. Inference flagged: the current non-SAP source list for replication flows.
GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization
SAP-provisioned Kubernetes on AWS, Azure, or Google Cloud with worker pools sized from the documented machine types; the enterprise writes the manifests. The consumed interface is the Kubernetes API: manifests lift. Delegated on the managed-Kubernetes convention. GPU worker pools watch-listed.
Published resource plans (T4, V100) plus flexible instance types reaching L4, L40S, and H100; tenant deployment and replica quotas, resource-group quotas, and model rate limits; KServe-based deployments and training executions the enterprise creates. SAP's abstraction and API over hyperscaler capacity: Ceded.
The application runtime for non-Kubernetes workloads on an open-source, multi-vendor platform. Delegated.
AI Core's flexible instance types reach NVIDIA L4, L40S, and H100 on hyperscaler capacity; the legacy resource plans are T4 and V100. The kyma-project GPU module (NVIDIA GPU Operator on Kyma clusters) is an open-source project and watch-listed until public production documentation exposes GPU worker pools.
SAP has a real, customer-administered orchestration surface, which most of the SaaS rows don't. SAP BTP, Kyma runtime is managed Kubernetes provisioned through Gardener (SAP's open-source cluster manager) on AWS, Azure, or Google Cloud, with worker pools the enterprise sizes from the documented machine types and manifests it writes itself. SAP AI Core adds a serving and training plane on top: resource plans (T4 and V100 in the published table) and flexible instance types that reach L4, L40S, and H100, tenant-level deployment and replica quotas, resource-group quotas, model rate-limit quotas, and KServe-based deployments the enterprise creates and scales. Cloud Foundry runtime remains the application runtime for non-Kubernetes workloads. The buyer gets Kubernetes it doesn't operate and GPU serving it doesn't provision. What's missing is the top of the layer: no fair-share scheduling, no utilization optimizer, no fleet-level GPU plane, and no publicly documented GPU worker pools on Kyma itself (the GPU module exists as an open-source project; the production provisioning parameters list CPU families). AI Core's instance types are SAP's abstraction over hyperscaler instances rather than a scheduler the enterprise tunes. Rule 6: the frontier at 2A is a general orchestrator with a real GPU plane (IBM on OpenShift, Azure on AKS with Arc, CoreWeave); SAP's is platform-scoped and hyperscaler-backed. Calibration: OCI reads moderate on managed Kubernetes plus GPU superclusters; Snowflake moderate on managed compute plus GA GPU pools; Salesforce moderate on CloudHub and Runtime Fabric; ServiceNow gap with no surface at all. SAP sits with OCI and Snowflake: managed Kubernetes plus a GPU serving plane with quotas, no fair-share. Moderate.
Moderate. Kyma is Delegated: the consumed interface is the Kubernetes API and manifests lift to any cluster, the managed-Kubernetes convention. AI Core's plans, instance types, and deployment API are SAP's abstraction, Ceded, though the models deployed on them are the enterprise's (scored at 2B). Cloud Foundry is a multi-vendor open-source runtime, Delegated. The runtime tradeoff is SAP's provisioning and scaling inside policy the enterprise sets per cluster and per deployment, with Kubernetes-level overrides the enterprise controls: vendor decides, visible, overridable, Delegated, the Azure reading.
Watch-list, notes only: GPU worker pools on Kyma (the kyma-project GPU module manages the NVIDIA GPU Operator and names AWS g4dn and g6, GCP g2, and Azure NC machine types, but the public provisioning parameters don't yet list them); Joule Studio runtime and NVIDIA partnership features (GA planned Q3 2026). Public evidence that moves the cell: a fleet-level GPU scheduler or utilization optimizer on SAP paper; production documentation for GPU worker pools on Kyma.
Model serving, agent execution, inference APIs, distributed inference
One API over frontier and open models, each reachable through its provider's own interface behind the hub, that the enterprise can swap without rewriting prompts. A managed broker of named third-party models: Delegated on the Elastic and ServiceNow Managed-LLM precedent, not because the harmonized API is itself a standard.
The orchestration service's pipeline (grounding, templating, translation, masking, filtering, model configuration), the batch API, and the inference observability service recording prompts, responses, labels, and feedback. SAP surfaces beyond the model interface: Ceded, the Salesforce large language model (LLM) Gateway and Trust Layer reading.
The enterprise deploys and trains its own models on SAP-managed GPU instance types. The model is the enterprise's; the serving surface is SAP's. Delegated on the customer-containers precedent.
Agents built from instructions, skills, APIs, and other agents, orchestrated by Joule with SAP's own agents; Joule Studio's managed runtime and 2.0 landing in Q3 2026. SAP objects that run nowhere else.
The skills, workflows, and automations the enterprise writes, and the per-tool require-confirmation setting that asks the user Yes or No before the tool runs. The customer authors the logic; it runs only on BTP. Ceded: the logic runs only on the vendor's platform (ruled September 5, 2026).
The generally available agents named in the Q2 2026 highlights (Expense Automation, Process Consulting, Enterprise Content Research, and the AI-assisted capabilities in Digital Manufacturing, Ariba, Fieldglass, and Revenue Growth Management), orchestrated by Joule; the Autonomous Suite rollout is watch-listed. SAP IP.
Mistral on the Business AI Platform as a European sovereign option, generally available; Cohere North planned. Proprietary models through SAP's paper: Ceded to their owners, with open-weight Mistral models the enterprise serves itself reading Delegated.
Custom models serve on NVIDIA L4, L40S, and H100 instance types; the Joule Studio runtime and NVIDIA partnership features announced at Sapphire 2026 have GA planned for Q3 2026.
Both halves of the layer are generally available on SAP paper. Serving: the generative AI hub in SAP AI Core gives one harmonized API to OpenAI (GPT-5 family), Anthropic Claude through Amazon Bedrock (through Opus 4.7), Google Gemini, Mistral, Amazon Nova, and open-source Llama-family models, with the orchestration service's pipeline (grounding, templating, translation, data masking, input and output filtering, model configuration), a batch API, and an inference observability service (Q2 2026); Mistral is generally available on the Business AI Platform as a European sovereign option and Cohere North is planned. AI Core serves and trains the enterprise's own models on GPU instance types through KServe. Agents: the agent builder in Joule Studio has been generally available since January 2026, building agents from instructions, skills (through SAP Build Process Automation, generally available since 2025), APIs, and other agents, with a per-tool setting that requires the user's confirmation, shown as Yes or No, before the tool runs; the managed Joule Studio runtime, an embedded n8n workflow environment, and Joule Studio 2.0 arrive with Q3 general availability. Joule orchestrates SAP's own agents, and the Autonomous Suite plans more than fifty assistants orchestrating more than two hundred agents in the coming months, with close to fifty assistants by the end of the third quarter and more than four hundred agents by year end. Claude is integrated into Joule. The buyer gets any-model serving, custom-model hosting, and a constructible agent runtime grounded in the business data. The architect's concern: the agents, skills, and automations are SAP artifacts that run only on BTP, the runtime is Joule-bound, the orchestration pipeline and observability are SAP surfaces beyond the model interface, and the studio half is in motion, with the managed runtime and 2.0 still landing in Q3. Rule 5 names that maturity on the studio half; the serving half is years old. Calibration: Snowflake and Databricks read strong with serving, agents, and fine-tuning; Salesforce and Palantir strong on a constructible any-model runtime without serving; ServiceNow strong on a multi-model runtime. SAP has both halves: serving and custom models on AI Core plus a GA agent builder with deterministic execution and a documented confirmation gate. Strong.
Low for the runtime, split at the model. Joule, Joule Studio, the agents, and the hub's orchestration, batch, and observability surfaces are SAP IP and Ceded. Model access through the hub's harmonized API is Delegated: named third-party models the enterprise can swap, the Elastic and ServiceNow Managed-LLM reading. Custom models on AI Core are the enterprise's artifacts on SAP's serving surface, Delegated on the Snowflake customer-containers precedent. The skills and automations the enterprise writes are written Ceded pending the customer-tools ruling. The model decides which skill to call; the documented per-tool confirmation before a tool runs is a gate on the specific effect, the kind the override rule needs: model decides, visible, overridable, Delegated.
Customer-tools chip ruled Ceded (Keith, September 5, 2026): skills and automations the enterprise builds in SAP Build Process Automation run only on BTP; customer-authored tool logic reads Retained only where it runs outside the vendor. The Snowflake and Elastic customer-tools chips are logged for re-reading under this ruling. Watch-list, notes only: Joule Studio managed runtime, n8n orchestration, and Joule Studio 2.0 (Q3 2026); Joule Work web and desktop (second half 2026); Cohere North on the platform (planned); NVIDIA secure agent runtime (Q3 2026); SAP-RPT-1.5 retrieval-augmented prediction (Q3 2026); the Autonomous Suite rollout (more than fifty assistants and two hundred agents in the coming months; four hundred agents by year end). The confirmation gate is a per-tool setting rather than a platform default; the authority reading rests on the documented setting.
Policy-driven placement and resource coordination — the Autonomy Layer
System of record for agents, large language models (LLMs), and MCP servers across SAP and non-SAP environments, with automated discovery across Microsoft, Google, AWS, ServiceNow, and SAP AI Core; registry generally available, four further capabilities Q3 2026. SAP IP.
Request-time enforcement on MCP tool calls: OIDC-based authentication and authorization, rate limiting, payload protection, traffic management, monitoring, and traceability across SAP and non-SAP APIs, integration flows, data sources, and external MCP servers exposed as tools. The catalog and policies are SAP's: Ceded on the vendor-hosted MCP precedent.
Joule as the orchestrator of SAP's agents and Joule Studio agents. A2A to third-party agents through the Agent Gateway is watch-listed until GA. SAP IP.
The governance plane is platform software; the planned NVIDIA secure agent runtime is a 2B fact.
SAP's reasoning plane is designed complete and shipped in thirds. Registry: SAP AI Agent Hub (from LeanIX, opened to Joule Studio customers at Sapphire 2026) is a vendor-agnostic system of record for agents, large language models, and MCP servers, with automated discovery across Microsoft, Google, AWS, ServiceNow, and SAP AI Core; the registry is generally available today. Gateway: the MCP Gateway in Integration Suite (generally available July 2026, Premium and Enhanced editions) enforces authentication, authorization, rate limiting, and payload protection on every tool call it fronts, for SAP and non-SAP APIs alike. Orchestration: Joule orchestrates SAP's agents and Joule Studio agents. Those three legs are GA. The other two are documented and dated: the Agent Gateway that would expose Joule agents over agent-to-agent (A2A) with App2App named-user tokens isn't yet generally available and doesn't yet support bidirectional exchange with third-party agents (enhanced A2A is Q4 2026); agent identity is designed in SAP Cloud Identity Services (agents in a user's context with agent-specific constraints, or autonomous agents with a dedicated technical identity, tokens, and audit trail) with the Agent Hub's identity and access control scheduled for Q3 2026 and the policy enforcement point between an agent and its tools in the second half; agent-level observability (session health, tool-call correctness, root cause) is Q3 2026, and what's GA today is the inference observability service, a model-call surface scored at 2B. The reference architecture says so itself: some components aren't yet generally available. Applying the strong criterion: registry, gateway, and orchestration are GA; identity and agent observability aren't. No reasoning mechanism; live placement and the deterministic outcome validator are absent as everywhere. Calibration: GCP reads strong on a complete plane; Databricks moderate on governance, gateway, and supervisor; Salesforce moderate on MuleSoft Agent Fabric with the identity leg thin; ServiceNow moderate with identity and gateway contested; Snowflake moderate with identity, registry, and observability and no gateway. SAP has the clearest identity design on the map and the least of it shipped. Moderate at the Databricks standard, with the H2 2026 legs named.
Low upstream borrowed judgment, and the term means dependence on third parties: the Agent Hub, the MCP Gateway, and Joule are SAP IP and Ceded. Which agent may act on what is decided by policy the enterprise writes, gateway policies, confirmation settings, registry governance, evaluated deterministically at the gateway and in the studio: code decides, visible, overridable, Retained, the Salesforce and ServiceNow reading.
Watch-list, notes only: AI Agent Hub observability, identity and access control through SAP Cloud Identity Services, agent mining with Signavio, and org chart and skills mapping with SuccessFactors (Q3 2026); the Agent Gateway (A2A exposure of Joule agents; not yet GA; bidirectional third-party exchange not yet supported; enhanced A2A Q4 2026); the agent-to-tool policy enforcement point (second half 2026); inference observability for governance tracing (Q4 2026). Public evidence that moves the cell: GA product documentation for the Agent Hub identity and access control and agent observability, and for the Agent Gateway; with those, the plane completes and the cell reads strong.
AI-powered business capabilities — business logic, workflow automation
The first-party applications with Joule embedded across them. SAP IP.
Generally available across finance, spend, supply chain, and customer experience (CX): Expense Automation Agent, Ariba contract creation, Fieldglass statement of work (SOW) role recommendations, Ariba Invoicing multi-model extraction, Digital Manufacturing production engineering and description enhancement, Revenue Growth Management trade promotion creation and deal sheet generation, Process Consulting Agent, Enterprise Content Research Agent. The rest of the Autonomous Suite is on the published schedule. SAP IP.
The agentic work surface on mobile, generally available; web and desktop are early adopter with general availability in the second half of 2026 and watch-listed. SAP IP.
Certified partner applications and extensions beside the first-party suite. Substitutable independent software vendor (ISV) ecosystem at menu altitude: Delegated on the AppExchange precedent.
The applications are SAP software; the models behind them are brokered at 2B.
This is SAP's native layer and the reason the rest exists. SAP Cloud ERP (S/4HANA Cloud), SuccessFactors, Ariba, Concur, Fieldglass, Customer Experience, Integrated Business Planning, Digital Manufacturing, and the industry solutions ship with Joule embedded and, per the second-quarter 2026 release highlights, with generally available AI-assisted capabilities and agents across finance, spend, supply chain, and customer experience. The Autonomous Suite is arriving on a published schedule: finance, spend, human capital management (HCM), and supply-chain assistants with general availability spread across the second, third, and fourth quarters of 2026 and into November, close to fifty assistants by the end of the third quarter and more than four hundred agents by year end, Joule Work generally available on mobile with web and desktop in the second half, and SAP Enterprise Planning in the third quarter. AI and Business Data Cloud were in more than 90% of SAP's fifty largest deals in the second quarter. The SAP Store and the partner ecosystem sit beside the first-party suite. Everything SAP-built is SAP's: the applications, the agents, the workflows, and the data model they act on rebuild nowhere, the deepest coupled capture on the map. The AI-driven pieces put a model in the process with a confirmation gate at the consequential steps, and the application's opinions about what to surface, route, and automate are SAP's, invisible to the buyer. Calibration: Salesforce reads strong on first-party business applications; ServiceNow on workflow applications with an autonomous workforce arriving; Qlik on the analytics value plane. SAP is the largest first-party value plane on the instrument. Strong, with the scored component limited to what the release highlights mark GA.
Low. The applications and the agents are SAP IP and Ceded; the partner ecosystem on the SAP Store is Delegated on the AppExchange and ServiceNow Store precedent. Vendor decides, not visible, not overridable, Ceded, the first-party value-plane reading.
Watch-list, notes only: the Sapphire 2026 availability schedule (assistants across Q2 through Q4 2026 and November 2026 for workforce planning and upskilling; Joule Work web and desktop second half 2026; Joule Work and A2A capabilities Q4 2026; SAP Enterprise Planning Q3 2026; sustainability agents Q4 2026). The scored components name only what the Q2 2026 release highlights mark GA. Public evidence that moves the cell: nothing upward from strong.
SAP is the largest first-party value plane on the instrument with a governed data plane underneath it and a serving-and-agents runtime between, and the row reads that way: strong at the data foundation (Layer 1A), retrieval (1B), the runtime (2B), and the applications (Layer 3), moderate at the substrate SAP now operates itself (Layer 0), at orchestration (2A), at pipelines (1C), and at the reasoning plane (2C). Authority is the SaaS shape with more seams than most: nearly everything is SAP intellectual property (IP) and Ceded, with Delegated readings where the consumed interface is a multi-vendor standard (Delta Sharing at 1A and 1C, the Kubernetes API and Cloud Foundry at 2A) or where SAP brokers models the enterprise can swap or hosts models the enterprise owns (the generative AI hub and AI Core at 2B), and one Retained decision-authority reading at 1C, where SAP's engines execute flows the enterprise wrote without judgment of their own.
The capture is coupled and visible, and it runs through the business semantics rather than the bytes. BDC Connect leaves the data in place and shares it live over an open protocol, which is true and reassuring, while the data products, the master data rules, the HANA schema, the knowledge graph, the Joule agents, and the skills and automations built in SAP Build accumulate in SAP; the Salesforce decoupled pattern, at larger scale. Decision authority follows the code where there is code: the enterprise's flows decide at 1C; the model decides inside the agent loop at 2B with a documented per-tool confirmation toggle as the enterprise's gate; SAP's engines decide placement and ranking on policy the enterprise writes at 1A, 1B, and 2A; SAP alone decides at Layer 0 and Layer 3; and at 2C the enterprise's own policy is the last word over a plane whose identity, agent-level observability, and bidirectional agent gateway are dated for the second half of 2026.
The buyer gets a governed multi-model database with an in-database vector and graph engine, mastering and lineage on the vendor's own paper, any-model serving plus custom-model hosting on graphics processing unit (GPU) instance types, a generally available agent builder with deterministic execution, and the application suite the enterprise already runs. In exchange: a data-engineering surface that's deepest for SAP sources, a governance plane designed complete and shipped partial, and a platform whose artifacts run nowhere else. What moves this row: generally available (GA) product documentation for Agent Hub identity and access control and the agent-to-tool enforcement point (2C to strong); a general CDC and transformation surface with external targets in one step (1C to strong); public production documentation for GPU worker pools on Kyma (2A's GPU plane).