# SAP Business AI Platform (Joule + Business Data Cloud + BTP) — 4+1 Layer AI Infrastructure Assessment

> Mapped to the 4+1 Layer AI Infrastructure Model  
> Version: v1.0 - 4+1 v2: Authority Split · Date: September 5, 2026  
> Source: SAP Sapphire 2026 Innovation News Guide (May 2026) with per-item availability; SAP Business AI Q2 2026 release highlights (July 2026); Joule Studio announcement (May 2026), the agent builder GA post (January 2026), and Joule Studio tool documentation; SAP Architecture Center reference architectures (A2A and MCP interoperability; Agent Identity; Copilot Studio integration); SAP AI Core documentation and SAP posts (resource plans, flexible instance types, quotas, orchestration service, models); SAP HANA Cloud vector engine and knowledge graph engine documentation; SAP Business Data Cloud Connect GA posts (Databricks October 2025, Snowflake early 2026, Google BigQuery 2026) and Google Cloud's SAP BDC lakehouse documentation; SAP Datasphere replication, data, and transformation flow documentation; SAP API Management What's New (MCP Gateway); SAP AI Agent Hub coverage (Sapphire 2026); SAP Cloud Identity Services agentic AI material (July 2026); Kyma runtime documentation and the kyma-project GPU module; SAP Cloud Infrastructure (April 2026) and SAP Sovereign Cloud On-Site (September 2025); Dremio acquisition (announced May 4, completed July 6, 2026); Q2 2026 results and call (July 23, 2026). Peer-reviewed cell by cell through the labs claims ledger (sap-<layer>-chatgpt, ChatGPT gpt-5.5, 27 claims) and as a whole row by Antigravity (sap-row-agy); totals and escalated items in labs/reviews/sap-judgment.md.  
> Published by: The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com  
> Author: Keith Townsend

[Full interactive assessment](https://layer2c.com/assessment/sap) · [Methodology](https://layer2c.com/methodology) · [What Is Layer 2C?](https://layer2c.com/what-is-layer-2c)

## Executive Summary

SAP is the largest first-party value plane on the instrument with a governed data plane underneath it and a serving-and-agents runtime between, and the row reads that way: strong at the data foundation (Layer 1A), retrieval (1B), the runtime (2B), and the applications (Layer 3), moderate at the substrate SAP now operates itself (Layer 0), at orchestration (2A), at pipelines (1C), and at the reasoning plane (2C). Authority is the SaaS shape with more seams than most: nearly everything is SAP intellectual property (IP) and Ceded, with Delegated readings where the consumed interface is a multi-vendor standard (Delta Sharing at 1A and 1C, the Kubernetes API and Cloud Foundry at 2A) or where SAP brokers models the enterprise can swap or hosts models the enterprise owns (the generative AI hub and AI Core at 2B), and one Retained decision-authority reading at 1C, where SAP's engines execute flows the enterprise wrote without judgment of their own.

The capture is coupled and visible, and it runs through the business semantics rather than the bytes. BDC Connect leaves the data in place and shares it live over an open protocol, which is true and reassuring, while the data products, the master data rules, the HANA schema, the knowledge graph, the Joule agents, and the skills and automations built in SAP Build accumulate in SAP; the Salesforce decoupled pattern, at larger scale. Decision authority follows the code where there is code: the enterprise's flows decide at 1C; the model decides inside the agent loop at 2B with a documented per-tool confirmation toggle as the enterprise's gate; SAP's engines decide placement and ranking on policy the enterprise writes at 1A, 1B, and 2A; SAP alone decides at Layer 0 and Layer 3; and at 2C the enterprise's own policy is the last word over a plane whose identity, agent-level observability, and bidirectional agent gateway are dated for the second half of 2026.

The buyer gets a governed multi-model database with an in-database vector and graph engine, mastering and lineage on the vendor's own paper, any-model serving plus custom-model hosting on graphics processing unit (GPU) instance types, a generally available agent builder with deterministic execution, and the application suite the enterprise already runs. In exchange: a data-engineering surface that's deepest for SAP sources, a governance plane designed complete and shipped partial, and a platform whose artifacts run nowhere else. What moves this row: generally available (GA) product documentation for Agent Hub identity and access control and the agent-to-tool enforcement point (2C to strong); a general CDC and transformation surface with external targets in one step (1C to strong); public production documentation for GPU worker pools on Kyma (2A's GPU plane).

## Layer Status

| Layer | Status | Classification |
|---|---|---|
| Layer 0 · Compute | ◑ SAP-Operated IaaS in SAP Data Centers; Sovereign Cloud On-Site; Hyperscalers for the Rest | Compute & Network Fabric |
| Layer 1A · Storage | ● Governed Business Data Cloud: HANA, Data Products, Mastering, Zero-Copy | Data Storage & Governance |
| Layer 1B · Retrieval | ● In-Database Vector + Knowledge Graph + Grounding Service; Embedding Choice | Context Management & Retrieval |
| Layer 1C · Pipelines | ◑ iPaaS + Datasphere Replication with SAP-Source CDC + Zero-Copy Sharing; Transformation Stays Local | Data Movement & Pipelines |
| Layer 2A · Orchestration | ◑ Managed Kubernetes (Kyma) + AI Core GPU Instance Types + Cloud Foundry; No Fair-Share | Infrastructure Orchestration |
| Layer 2B · Runtime | ● Generative AI Hub Serving + AI Core Custom Models + Joule Studio Agents; Any-Model | Application Runtime & Execution |
| Layer 2C · Reasoning | ◑ Registry GA + MCP Gateway GA + Joule Orchestration; Identity, Agent Observability, and A2A Dated H2 2026 | Agentic Infrastructure — The Reasoning Plane |
| Layer 3 (+1) · Applications | ● First-Party Business Applications with Joule Across the Suite; Autonomous Suite Arriving | AI Application Layer — The Value Plane |

## DAPM Portability Profile (components)

| Classification | Count | Meaning |
|---|---|---|
| Retained | 0 | I possess the capability and can operate it independently of this provider |
| Delegated | 7 | Someone else provides the capability, but I can substitute that provider without reconstructing my accumulated opinions |
| Ceded | 26 | Changing providers requires reconstructing those opinions |

**Decision authority (per layer, gaps included)**

| Reading | Layers | Meaning |
|---|---|---|
| Retained | 2 | The enterprise, or code it writes or controls, decides |
| Delegated | 4 | Vendor or model decides; the enterprise can see and override |
| Ceded | 2 | Vendor or model decides; no override, often invisible |
| Absent | 0 | Nothing offered, nothing inherited |

## Strongest Layers

- **Layer 1A** (Data Storage & Governance) — Governed Business Data Cloud: HANA, Data Products, Mastering, Zero-Copy
- **Layer 1B** (Context Management & Retrieval) — In-Database Vector + Knowledge Graph + Grounding Service; Embedding Choice
- **Layer 2B** (Application Runtime & Execution) — Generative AI Hub Serving + AI Core Custom Models + Joule Studio Agents; Any-Model
- **Layer 3 (+1)** (AI Application Layer — The Value Plane) — First-Party Business Applications with Joule Across the Suite; Autonomous Suite Arriving

## Layer-by-Layer Detail

### ◑ Layer 0 · Compute: Compute & Network Fabric

*Raw compute, networking, and acceleration fabric*  
**Status:** SAP-Operated IaaS in SAP Data Centers; Sovereign Cloud On-Site; Hyperscalers for the Rest

**Decision authority:** Ceded (decides: vendor; visible: true; overridable: false; boundary: vendor)

**SAP Cloud Infrastructure (SAP-Operated IaaS in SAP-Owned Data Centers)** [DAPM: Ceded]  
An open-source-based, API-first IaaS platform with self-service provisioning, automation, and consistent resource management, operated in SAP-owned data centers and co-locations worldwide, running SAP's services and customer-specific workloads. Commodity hardware under SAP's stack and catalog; the provisioning opinions are SAP's unless the API is a multi-vendor standard (flagged). Ceded.

**SAP Sovereign Cloud On-Site (SAP-Provided, SAP-Managed Stack in the Customer's Data Center)** [DAPM: Ceded]  
Globally available since September 2025: SAP provides and manages the full technology stack from hardware to SAP Cloud Infrastructure and the Sovereign Cloud portfolio in a customer-designated facility. An integrated system SAP procures and operates; physical control on site, authority with SAP. Ceded under the integrated-system rule.

**Gap Analysis:** SAP has a Layer 0 of its own, which most software rows don't. SAP Cloud Infrastructure is an SAP-developed, SAP-operated infrastructure-as-a-service (IaaS) platform in SAP-owned data centers and co-locations: open-source-based, API-first, with self-service provisioning and automation, running SAP's cloud services and customer-specific workloads on one infrastructure; its German data centers achieved ISO/IEC 27001 on the basis of IT-Grundschutz in April 2026. SAP Sovereign Cloud is generally available for RISE with SAP across regions, and SAP Sovereign Cloud On-Site (globally available since September 2025) has SAP provide and manage the full stack, from hardware to SAP Cloud Infrastructure, inside a customer-designated data center. The rest of the estate runs on hyperscalers: SAP Business Technology Platform (BTP) has regions on Amazon Web Services (AWS), Microsoft Azure, Google Cloud, Alibaba Cloud, and SAP Cloud Infrastructure, while SAP Business Data Cloud, Joule, and SAP AI Core follow a controlled regional rollout on AWS, Azure, and Google Cloud. The buyer gets sovereignty as a product line, from hyperscaler regions to SAP's own floor to SAP's rack in their building.

The exposure test decides the grade. On the hyperscaler paths the substrate is invisible behind a software-as-a-service (SaaS) interface, the Salesforce and ServiceNow reading. SAP Cloud Infrastructure is different: it's purchasable, it's customer-administered through self-service provisioning, and it runs the customer's own workloads, so it's a scored capability, and shipped bits the enterprise depends on make the layer moderate rather than gap. What keeps it from strong is what the clouds have and SAP doesn't: owned silicon, an AI fabric, or GPU capacity of its own. On-Site is SAP-procured, SAP-operated hardware under the integrated-system rule.

Calibration: AWS, GCP, and Azure read strong on owned data centers and custom silicon; HPE strong on hardware it builds and operates; Salesforce, ServiceNow, and Snowflake gap with the substrate absorbed beneath the service; VMware moderate on an abstraction layer over other people's hardware. SAP is a real operator of commodity infrastructure without silicon or fabric of its own: moderate.

**Borrowed Judgment:** The substrate judgment is SAP's on SAP Cloud Infrastructure and On-Site (data centers, hardware procurement, the open-source stack) and the hyperscaler's elsewhere. On SAP's own paths the enterprise provisions inside SAP's catalog and sees it, but the placement, hardware, and stack decisions are SAP's with no runtime override: vendor decides, visible, not overridable, Ceded. The hyperscaler paths inherit the Ceded-invisible reading.

### ● Layer 1A · Storage: Data Storage & Governance

*Durable, governed data foundation — the Governance Catalog that Layer 2C queries*  
**Status:** Governed Business Data Cloud: HANA, Data Products, Mastering, Zero-Copy

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**SAP HANA Cloud (Relational + Vector + Knowledge Graph Engines, Native in BDC)** [DAPM: Ceded]  
The in-memory multi-model database, generally available natively in Business Data Cloud with shared capacity pooling. Proprietary engine and schema; the accumulated models don't lift.

**SAP Business Data Cloud Data Products + Datasphere (Semantics, Lineage, Access)** [DAPM: Ceded]  
SAP-managed data products with business semantics, Datasphere modeling, lineage, and access control within the SAP perimeter, Business Warehouse and Analytics Cloud under the same experience. SAP objects with no second implementer.

**SAP Master Data Governance (Mastering, GA in BDC)** [DAPM: Ceded]  
The mastering leg: master data governance as a core BDC component, generally available. Rules and workflows are SAP's model.

**SAP Databricks in BDC (Unity Catalog Inside the SAP Perimeter)** [DAPM: Ceded]  
A trimmed Databricks with Unity Catalog, Mosaic AI, and SQL warehouse embedded in BDC on a controlled regional rollout (AWS, Azure, Google Cloud, with some regions still excluded), with SAP semantic metadata and governance tags synced into the catalog. Databricks' governance under SAP's paper: Ceded to its owner through SAP, the channel-substitution rule.

**BDC Connect Zero-Copy Sharing (Databricks, Snowflake, BigQuery via Delta Sharing)** [DAPM: Delegated]  
Bidirectional, live sharing of governed data products with the customer's Databricks, Snowflake, or BigQuery over the Delta Sharing protocol; data stays in place at the source and is queried there (BigQuery caches blocks locally and lacks fine-grained access control on the shared tables). A multi-vendor interface with a substitutable consumer: Delegated, the Databricks Marketplace-via-Delta-Sharing and Salesforce zero-copy readings.

**Gap Analysis:** This is the layer SAP rebuilt the company around in 2025 and 2026. SAP Business Data Cloud (BDC) brings Datasphere, Business Warehouse, and Analytics Cloud under one experience, ships SAP-managed data products with business semantics, and embeds SAP Databricks (a trimmed Databricks with Unity Catalog, Mosaic AI, and a Structured Query Language (SQL) warehouse) inside the SAP perimeter on a controlled regional rollout across AWS, Azure, and Google Cloud. SAP HANA Cloud runs natively in BDC with shared capacity pooling (generally available), and it's a multi-model database: relational, in-database vector, and a knowledge graph engine in one system. Governance is an authorization authority: SAP Master Data Governance is generally available as a BDC component, Datasphere carries lineage and access control inside the SAP perimeter, and semantic metadata and governance tags (including personal-data tags) sync into Unity Catalog for attribute-based access control. Reach beyond the perimeter is zero copy and bidirectional: BDC Connect shares governed data products live over Delta Sharing with Databricks (October 2025), Snowflake (early 2026), and Google BigQuery (2026), with Microsoft Fabric targeted for the third quarter and Amazon Athena for the first half of 2027. The Dremio acquisition (announced May 4, completed July 6, 2026) points at Apache Iceberg and a format-agnostic BDC.

The deciding line is the one that separated Salesforce (strong) from Qlik (moderate): authorization authority enforced at runtime, and a general data plane with mastering, quality, and lineage. SAP has both on its own paper. Master Data Governance is the mastering leg Salesforce had to buy Informatica for; Datasphere and the data products carry lineage and semantics; HANA Cloud is a general database. Rule 4 holds: the plane serves any data, not only SAP's. The architect's concern is the decoupled split every lakehouse row carries, with the governance edge named: the shared data stays at its source and is queried in place, and the data-product semantics, the governance tags, the HANA schema, and the mastering rules accumulate in SAP; in BigQuery the shared tables don't support fine-grained access control, so the authority that travels with the share is coarser than Unity Catalog's.

Calibration: Snowflake and Databricks read strong on a governed lakehouse plus a catalog; Salesforce strong on authorization authority plus Informatica; ServiceNow moderate on a workflow system of record plus a catalog without mastering. SAP stands with the first three. Strong.

**Borrowed Judgment:** Low for the governance logic, which is SAP IP and Ceded: HANA Cloud, the data products, Master Data Governance, and Datasphere's semantics and lineage. SAP Databricks inside BDC is Databricks' catalog under SAP's paper, Ceded to its owner. BDC Connect is Delegated on the consumed interface: Delta Sharing is a multi-vendor protocol, the data stays at its source and is queried in place, and the consuming warehouse is substitutable. The runtime tradeoff is SAP's engine placing and serving data on policy the enterprise writes: vendor decides, visible, overridable per object, Delegated, the Snowflake and Databricks reading.

### ● Layer 1B · Retrieval: Context Management & Retrieval

*Low-latency retrieval for RAG — vector/hybrid search, context windows*  
**Status:** In-Database Vector + Knowledge Graph + Grounding Service; Embedding Choice

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**SAP HANA Cloud Vector Engine (REAL_VECTOR, Similarity Search, Hybrid with Full-Text)** [DAPM: Ceded]  
Native vector type with cosine and Euclidean similarity in SQL and full-text search for hybrid retrieval; a LangChain integration ships. The store is SAP's database: Ceded, low blast radius (vectors export as arrays).

**SAP_NEB In-Database Embeddings (VECTOR_EMBEDDING)** [DAPM: Ceded]  
SAP's own embedding model generating vectors inside HANA Cloud (768 dimensions; German, English, Spanish, French, Portuguese). Embedding carve-out: Ceded.

**Third-Party Embeddings via the Generative AI Hub** [DAPM: Ceded]  
OpenAI, Google Gemini, and other embedding models reached through the hub's harmonized API and stored in HANA. Ceded to the model owner through SAP's paper; open-weights models the enterprise serves itself are the Delegated exception.

**SAP HANA Cloud Knowledge Graph Engine (RDF, SPARQL)** [DAPM: Ceded]  
Graph storage and SPARQL over RDF in the same database as the vectors, so semantic similarity and fact-based traversal compose. SAP engine.

**Generative AI Hub Grounding Module (Document Grounding + HANA Vector Store)** [DAPM: Ceded]  
The orchestration service's grounding stage with Document Grounding and the HANA vector store behind it. SAP service with no second implementer.

**Gap Analysis:** Retrieval infrastructure the enterprise builds on, inside the database it already runs. SAP HANA Cloud's vector engine stores embeddings in a native REAL_VECTOR type with cosine and Euclidean similarity in SQL, generates embeddings in-database with the VECTOR_EMBEDDING function on SAP's own model (SAP_NEB, 768 dimensions, five languages), and combines with full-text search for hybrid retrieval; the knowledge graph engine adds SPARQL (the RDF query language) over Resource Description Framework (RDF) in the same system, so vector similarity and fact-based traversal compose in one query. Above the database, the generative AI hub's orchestration service has a grounding module with Document Grounding and a HANA vector store behind it, and any embedding model on the hub (OpenAI, Gemini, and others) can populate the store. A LangChain integration ships; other frameworks work through the hub's SDKs and custom code. The buyer gets a vector store with a SQL application programming interface (API), embedding choice, a graph engine, and a managed grounding pipeline without a second system.

The architect's concern is the usual one at this layer. The vectors are only as portable as the model that made them (SAP_NEB is SAP's; third-party embeddings are their owners'), and the grounding pipeline and the HANA schema are SAP's. Rule 4 holds: the store and the engine serve any retrieval workload, not only SAP experiences, which is what separates this cell from ServiceNow's.

Calibration: Snowflake reads strong on a VECTOR type plus Cortex Search and semantic views; Databricks strong on Mosaic AI Vector Search; Elastic strong as the retrieval engine itself; Salesforce strong on a governed retrieval surface; ServiceNow moderate on a platform-scoped feature with no surface. SAP matches Snowflake's legs and adds an in-database knowledge graph engine that no lakehouse row scores. Strong.

**Borrowed Judgment:** Low for the mechanism and split at the model. The vector engine, the knowledge graph engine, and the grounding module are SAP IP and Ceded; SAP_NEB embeddings are Ceded under the embedding carve-out; third-party embeddings through the generative AI hub are Ceded to their owners under the channel-substitution rule, with any open-weights model the enterprise serves itself reading Delegated. The runtime tradeoff is HANA executing the similarity and graph queries the enterprise writes per request: vendor decides, visible, overridable, Delegated under the override rule.

### ◑ Layer 1C · Pipelines: Data Movement & Pipelines

*Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering*  
**Status:** iPaaS + Datasphere Replication with SAP-Source CDC + Zero-Copy Sharing; Transformation Stays Local

**Decision authority:** Retained (decides: code; visible: true; overridable: true; boundary: vendor)

**SAP Integration Suite (Cloud Integration, API Management, Event Mesh)** [DAPM: Ceded]  
The iPaaS: integration flows with mapping and scripting, API management, and eventing across SAP and non-SAP systems. Flows and policies are SAP artifacts that rebuild elsewhere.

**SAP Datasphere Replication Flows (CDC from SAP Sources; Premium Outbound to BigQuery, S3, GCS, ADLS, Kafka)** [DAPM: Ceded]  
Configuration-first replication with trigger-based change data capture from S/4HANA and ECC CDS views, and outbound replication to Google BigQuery, Amazon S3, Google Cloud Storage, Azure Data Lake Storage Gen2, and Apache Kafka under the paid Premium Outbound Integration; Snowflake isn't a supported target. Datasphere objects with no second implementer.

**SAP Datasphere Data Flows and Transformation Flows (Local Tables)** [DAPM: Ceded]  
Arbitrary transformation into Datasphere local tables, from which replication flows carry results outbound. Two steps for an external destination. SAP artifacts.

**BDC Connect Zero-Copy Sharing (Delta Sharing)** [DAPM: Delegated]  
The movement-avoidance half, scored at 1A and referenced here: live governed sharing rather than replication. Delegated on the multi-vendor protocol.

**Gap Analysis:** Two platforms sit here on SAP paper. SAP Integration Suite is the integration platform as a service (iPaaS): Cloud Integration flows with arbitrary mapping and scripting, API Management, and Event Mesh across SAP and non-SAP systems. SAP Datasphere is the data-engineering half: replication flows with change data capture (CDC) from S/4HANA and enterprise resource planning (ERP) Central Component (ECC) through Core Data Services (CDS) views (trigger-based deltas after an initial load), data flows and transformation flows for transformation, and, with the paid Premium Outbound Integration, replication from Datasphere into Google BigQuery, Amazon Amazon S3 (Simple Storage Service), Google Cloud Storage, Azure Data Lake Storage Gen2, and Apache Kafka. BDC Connect adds the movement-avoidance path, sharing governed data products live over Delta Sharing rather than copying them, and the Dremio acquisition (completed July 6, 2026) points at Iceberg. Datasphere carries lineage.

Rule 4's decidable test is where the grade lands. Integration Suite passes it for application integration. Datasphere's documentation separates its flows: data flows and transformation flows write only to Datasphere local tables, and replication flows reach external targets with projection and mapping rather than arbitrary transformation. An arbitrary transformation bound for an external destination therefore takes two steps inside Datasphere (transform to a local table, then replicate outbound), and the outbound target list is object stores, BigQuery, and Kafka: Snowflake isn't a supported replication target and Databricks is reached through Delta Sharing, not replication. CDC is deepest for SAP sources. That's a real, general-in-kind pipeline platform with two documented scope gates (rule 5): transformation stays local, and CDC is SAP-centric.

Calibration: Salesforce reads strong on MuleSoft plus Informatica, and Qlik strong on any-to-any CDC plus Talend, both general on source and destination in one step. Snowflake and Databricks read strong on general pipeline engines. ServiceNow reads moderate on an integration fabric with no CDC or extract, load, transform (ELT); Elastic moderate on a telemetry pipeline. SAP sits between: more than ServiceNow (real CDC, real outbound replication, real transformation), less than Qlik (SAP-source CDC, two-step transformation to external targets). Moderate, with the strong case named and escalated.

**Borrowed Judgment:** Low. Integration Suite, Datasphere's flows, and the lineage are SAP IP and Ceded; BDC Connect is Delegated on the Delta Sharing protocol. The runtime is SAP's engines executing flows the enterprise authored deterministically, with load type and delta frequency set by the enterprise and no vendor judgment about what moves where: code decides, visible, overridable, Retained, the Elastic, VAST, and ServiceNow reading under the override rule.

### ◑ Layer 2A · Orchestration: Infrastructure Orchestration

*GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization*  
**Status:** Managed Kubernetes (Kyma) + AI Core GPU Instance Types + Cloud Foundry; No Fair-Share

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**SAP BTP, Kyma Runtime (Managed Kubernetes via Gardener)** [DAPM: Delegated]  
SAP-provisioned Kubernetes on AWS, Azure, or Google Cloud with worker pools sized from the documented machine types; the enterprise writes the manifests. The consumed interface is the Kubernetes API: manifests lift. Delegated on the managed-Kubernetes convention. GPU worker pools watch-listed.

**SAP AI Core Resource Plans, Flexible Instance Types, and Deployments (KServe; L4, L40S, H100)** [DAPM: Ceded]  
Published resource plans (T4, V100) plus flexible instance types reaching L4, L40S, and H100; tenant deployment and replica quotas, resource-group quotas, and model rate limits; KServe-based deployments and training executions the enterprise creates. SAP's abstraction and API over hyperscaler capacity: Ceded.

**SAP BTP, Cloud Foundry Runtime** [DAPM: Delegated]  
The application runtime for non-Kubernetes workloads on an open-source, multi-vendor platform. Delegated.

**Gap Analysis:** SAP has a real, customer-administered orchestration surface, which most of the SaaS rows don't. SAP BTP, Kyma runtime is managed Kubernetes provisioned through Gardener (SAP's open-source cluster manager) on AWS, Azure, or Google Cloud, with worker pools the enterprise sizes from the documented machine types and manifests it writes itself. SAP AI Core adds a serving and training plane on top: resource plans (T4 and V100 in the published table) and flexible instance types that reach L4, L40S, and H100, tenant-level deployment and replica quotas, resource-group quotas, model rate-limit quotas, and KServe-based deployments the enterprise creates and scales. Cloud Foundry runtime remains the application runtime for non-Kubernetes workloads. The buyer gets Kubernetes it doesn't operate and GPU serving it doesn't provision.

What's missing is the top of the layer: no fair-share scheduling, no utilization optimizer, no fleet-level GPU plane, and no publicly documented GPU worker pools on Kyma itself (the GPU module exists as an open-source project; the production provisioning parameters list CPU families). AI Core's instance types are SAP's abstraction over hyperscaler instances rather than a scheduler the enterprise tunes. Rule 6: the frontier at 2A is a general orchestrator with a real GPU plane (IBM on OpenShift, Azure on AKS with Arc, CoreWeave); SAP's is platform-scoped and hyperscaler-backed.

Calibration: OCI reads moderate on managed Kubernetes plus GPU superclusters; Snowflake moderate on managed compute plus GA GPU pools; Salesforce moderate on CloudHub and Runtime Fabric; ServiceNow gap with no surface at all. SAP sits with OCI and Snowflake: managed Kubernetes plus a GPU serving plane with quotas, no fair-share. Moderate.

**Borrowed Judgment:** Moderate. Kyma is Delegated: the consumed interface is the Kubernetes API and manifests lift to any cluster, the managed-Kubernetes convention. AI Core's plans, instance types, and deployment API are SAP's abstraction, Ceded, though the models deployed on them are the enterprise's (scored at 2B). Cloud Foundry is a multi-vendor open-source runtime, Delegated. The runtime tradeoff is SAP's provisioning and scaling inside policy the enterprise sets per cluster and per deployment, with Kubernetes-level overrides the enterprise controls: vendor decides, visible, overridable, Delegated, the Azure reading.

### ● Layer 2B · Runtime: Application Runtime & Execution

*Model serving, agent execution, inference APIs, distributed inference*  
**Status:** Generative AI Hub Serving + AI Core Custom Models + Joule Studio Agents; Any-Model

**Decision authority:** Delegated (decides: model; visible: true; overridable: true; boundary: model)

**Generative AI Hub Model Access (Harmonized API to OpenAI, Claude, Gemini, Mistral, Nova, Open Source)** [DAPM: Delegated]  
One API over frontier and open models, each reachable through its provider's own interface behind the hub, that the enterprise can swap without rewriting prompts. A managed broker of named third-party models: Delegated on the Elastic and ServiceNow Managed-LLM precedent, not because the harmonized API is itself a standard.

**Generative AI Hub Orchestration, Batch, and Inference Observability** [DAPM: Ceded]  
The orchestration service's pipeline (grounding, templating, translation, masking, filtering, model configuration), the batch API, and the inference observability service recording prompts, responses, labels, and feedback. SAP surfaces beyond the model interface: Ceded, the Salesforce large language model (LLM) Gateway and Trust Layer reading.

**SAP AI Core Custom Model Serving and Training (KServe on GPU Instance Types)** [DAPM: Delegated]  
The enterprise deploys and trains its own models on SAP-managed GPU instance types. The model is the enterprise's; the serving surface is SAP's. Delegated on the customer-containers precedent.

**Joule + Joule Studio Agent Builder (GA January 2026)** [DAPM: Ceded]  
Agents built from instructions, skills, APIs, and other agents, orchestrated by Joule with SAP's own agents; Joule Studio's managed runtime and 2.0 landing in Q3 2026. SAP objects that run nowhere else.

**Customer-Authored Skills and Automations (SAP Build Process Automation) + Per-Tool Confirmation Gate** [DAPM: Ceded]  
The skills, workflows, and automations the enterprise writes, and the per-tool require-confirmation setting that asks the user Yes or No before the tool runs. The customer authors the logic; it runs only on BTP. Ceded: the logic runs only on the vendor's platform (ruled September 5, 2026).

**SAP's Joule Agents and Assistants (GA per the Q2 2026 Release Highlights)** [DAPM: Ceded]  
The generally available agents named in the Q2 2026 highlights (Expense Automation, Process Consulting, Enterprise Content Research, and the AI-assisted capabilities in Digital Manufacturing, Ariba, Fieldglass, and Revenue Growth Management), orchestrated by Joule; the Autonomous Suite rollout is watch-listed. SAP IP.

**Sovereign Model Options (Mistral GA; Cohere North Planned)** [DAPM: Ceded]  
Mistral on the Business AI Platform as a European sovereign option, generally available; Cohere North planned. Proprietary models through SAP's paper: Ceded to their owners, with open-weight Mistral models the enterprise serves itself reading Delegated.

**Gap Analysis:** Both halves of the layer are generally available on SAP paper. Serving: the generative AI hub in SAP AI Core gives one harmonized API to OpenAI (GPT-5 family), Anthropic Claude through Amazon Bedrock (through Opus 4.7), Google Gemini, Mistral, Amazon Nova, and open-source Llama-family models, with the orchestration service's pipeline (grounding, templating, translation, data masking, input and output filtering, model configuration), a batch API, and an inference observability service (Q2 2026); Mistral is generally available on the Business AI Platform as a European sovereign option and Cohere North is planned. AI Core serves and trains the enterprise's own models on GPU instance types through KServe. Agents: the agent builder in Joule Studio has been generally available since January 2026, building agents from instructions, skills (through SAP Build Process Automation, generally available since 2025), APIs, and other agents, with a per-tool setting that requires the user's confirmation, shown as Yes or No, before the tool runs; the managed Joule Studio runtime, an embedded n8n workflow environment, and Joule Studio 2.0 arrive with Q3 general availability. Joule orchestrates SAP's own agents, and the Autonomous Suite plans more than fifty assistants orchestrating more than two hundred agents in the coming months, with close to fifty assistants by the end of the third quarter and more than four hundred agents by year end. Claude is integrated into Joule. The buyer gets any-model serving, custom-model hosting, and a constructible agent runtime grounded in the business data.

The architect's concern: the agents, skills, and automations are SAP artifacts that run only on BTP, the runtime is Joule-bound, the orchestration pipeline and observability are SAP surfaces beyond the model interface, and the studio half is in motion, with the managed runtime and 2.0 still landing in Q3. Rule 5 names that maturity on the studio half; the serving half is years old.

Calibration: Snowflake and Databricks read strong with serving, agents, and fine-tuning; Salesforce and Palantir strong on a constructible any-model runtime without serving; ServiceNow strong on a multi-model runtime. SAP has both halves: serving and custom models on AI Core plus a GA agent builder with deterministic execution and a documented confirmation gate. Strong.

**Borrowed Judgment:** Low for the runtime, split at the model. Joule, Joule Studio, the agents, and the hub's orchestration, batch, and observability surfaces are SAP IP and Ceded. Model access through the hub's harmonized API is Delegated: named third-party models the enterprise can swap, the Elastic and ServiceNow Managed-LLM reading. Custom models on AI Core are the enterprise's artifacts on SAP's serving surface, Delegated on the Snowflake customer-containers precedent. The skills and automations the enterprise writes are written Ceded pending the customer-tools ruling. The model decides which skill to call; the documented per-tool confirmation before a tool runs is a gate on the specific effect, the kind the override rule needs: model decides, visible, overridable, Delegated.

### ◑ Layer 2C · Reasoning: Agentic Infrastructure — The Reasoning Plane

*Policy-driven placement and resource coordination — the Autonomy Layer*  
**Status:** Registry GA + MCP Gateway GA + Joule Orchestration; Identity, Agent Observability, and A2A Dated H2 2026

**Decision authority:** Retained (decides: code; visible: true; overridable: true; boundary: vendor)

**SAP AI Agent Hub Registry (LeanIX; Vendor-Agnostic Discovery)** [DAPM: Ceded]  
System of record for agents, large language models (LLMs), and MCP servers across SAP and non-SAP environments, with automated discovery across Microsoft, Google, AWS, ServiceNow, and SAP AI Core; registry generally available, four further capabilities Q3 2026. SAP IP.

**MCP Gateway in SAP Integration Suite (GA July 2026)** [DAPM: Ceded]  
Request-time enforcement on MCP tool calls: OIDC-based authentication and authorization, rate limiting, payload protection, traffic management, monitoring, and traceability across SAP and non-SAP APIs, integration flows, data sources, and external MCP servers exposed as tools. The catalog and policies are SAP's: Ceded on the vendor-hosted MCP precedent.

**Joule Orchestration Across Agents** [DAPM: Ceded]  
Joule as the orchestrator of SAP's agents and Joule Studio agents. A2A to third-party agents through the Agent Gateway is watch-listed until GA. SAP IP.

**Gap Analysis:** SAP's reasoning plane is designed complete and shipped in thirds. Registry: SAP AI Agent Hub (from LeanIX, opened to Joule Studio customers at Sapphire 2026) is a vendor-agnostic system of record for agents, large language models, and MCP servers, with automated discovery across Microsoft, Google, AWS, ServiceNow, and SAP AI Core; the registry is generally available today. Gateway: the MCP Gateway in Integration Suite (generally available July 2026, Premium and Enhanced editions) enforces authentication, authorization, rate limiting, and payload protection on every tool call it fronts, for SAP and non-SAP APIs alike. Orchestration: Joule orchestrates SAP's agents and Joule Studio agents. Those three legs are GA. The other two are documented and dated: the Agent Gateway that would expose Joule agents over agent-to-agent (A2A) with App2App named-user tokens isn't yet generally available and doesn't yet support bidirectional exchange with third-party agents (enhanced A2A is Q4 2026); agent identity is designed in SAP Cloud Identity Services (agents in a user's context with agent-specific constraints, or autonomous agents with a dedicated technical identity, tokens, and audit trail) with the Agent Hub's identity and access control scheduled for Q3 2026 and the policy enforcement point between an agent and its tools in the second half; agent-level observability (session health, tool-call correctness, root cause) is Q3 2026, and what's GA today is the inference observability service, a model-call surface scored at 2B. The reference architecture says so itself: some components aren't yet generally available.

Applying the strong criterion: registry, gateway, and orchestration are GA; identity and agent observability aren't. No reasoning mechanism; live placement and the deterministic outcome validator are absent as everywhere.

Calibration: GCP reads strong on a complete plane; Databricks moderate on governance, gateway, and supervisor; Salesforce moderate on MuleSoft Agent Fabric with the identity leg thin; ServiceNow moderate with identity and gateway contested; Snowflake moderate with identity, registry, and observability and no gateway. SAP has the clearest identity design on the map and the least of it shipped. Moderate at the Databricks standard, with the H2 2026 legs named.

**Borrowed Judgment:** Low upstream borrowed judgment, and the term means dependence on third parties: the Agent Hub, the MCP Gateway, and Joule are SAP IP and Ceded. Which agent may act on what is decided by policy the enterprise writes, gateway policies, confirmation settings, registry governance, evaluated deterministically at the gateway and in the studio: code decides, visible, overridable, Retained, the Salesforce and ServiceNow reading.

### ● Layer 3 (+1) · Applications: AI Application Layer — The Value Plane

*AI-powered business capabilities — business logic, workflow automation*  
**Status:** First-Party Business Applications with Joule Across the Suite; Autonomous Suite Arriving

**Decision authority:** Ceded (decides: vendor; visible: false; overridable: false; boundary: vendor)

**SAP Cloud ERP and the Application Suite with Joule (S/4HANA Cloud, SuccessFactors, Ariba, Concur, Fieldglass, CX, IBP)** [DAPM: Ceded]  
The first-party applications with Joule embedded across them. SAP IP.

**Joule Agents and AI-Assisted Capabilities (GA per the Q2 2026 Release Highlights)** [DAPM: Ceded]  
Generally available across finance, spend, supply chain, and customer experience (CX): Expense Automation Agent, Ariba contract creation, Fieldglass statement of work (SOW) role recommendations, Ariba Invoicing multi-model extraction, Digital Manufacturing production engineering and description enhancement, Revenue Growth Management trade promotion creation and deal sheet generation, Process Consulting Agent, Enterprise Content Research Agent. The rest of the Autonomous Suite is on the published schedule. SAP IP.

**Joule Work Mobile App (GA)** [DAPM: Ceded]  
The agentic work surface on mobile, generally available; web and desktop are early adopter with general availability in the second half of 2026 and watch-listed. SAP IP.

**SAP Store and Partner Ecosystem** [DAPM: Delegated]  
Certified partner applications and extensions beside the first-party suite. Substitutable independent software vendor (ISV) ecosystem at menu altitude: Delegated on the AppExchange precedent.

**Gap Analysis:** This is SAP's native layer and the reason the rest exists. SAP Cloud ERP (S/4HANA Cloud), SuccessFactors, Ariba, Concur, Fieldglass, Customer Experience, Integrated Business Planning, Digital Manufacturing, and the industry solutions ship with Joule embedded and, per the second-quarter 2026 release highlights, with generally available AI-assisted capabilities and agents across finance, spend, supply chain, and customer experience. The Autonomous Suite is arriving on a published schedule: finance, spend, human capital management (HCM), and supply-chain assistants with general availability spread across the second, third, and fourth quarters of 2026 and into November, close to fifty assistants by the end of the third quarter and more than four hundred agents by year end, Joule Work generally available on mobile with web and desktop in the second half, and SAP Enterprise Planning in the third quarter. AI and Business Data Cloud were in more than 90% of SAP's fifty largest deals in the second quarter. The SAP Store and the partner ecosystem sit beside the first-party suite.

Everything SAP-built is SAP's: the applications, the agents, the workflows, and the data model they act on rebuild nowhere, the deepest coupled capture on the map. The AI-driven pieces put a model in the process with a confirmation gate at the consequential steps, and the application's opinions about what to surface, route, and automate are SAP's, invisible to the buyer.

Calibration: Salesforce reads strong on first-party business applications; ServiceNow on workflow applications with an autonomous workforce arriving; Qlik on the analytics value plane. SAP is the largest first-party value plane on the instrument. Strong, with the scored component limited to what the release highlights mark GA.

**Borrowed Judgment:** Low. The applications and the agents are SAP IP and Ceded; the partner ecosystem on the SAP Store is Delegated on the AppExchange and ServiceNow Store precedent. Vendor decides, not visible, not overridable, Ceded, the first-party value-plane reading.

---
*Layer2C · AI Infrastructure Decision Intelligence · The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com*
