← Back to list

We wouldn’t run a refinery without a control plane.

What two decades building fault-tolerant systems — from oil refineries to global supply chains — taught me about the missing layer in…

Gopikrishna Kannan · 2026-05-13 21:03 · 0 claps · 4.6 min read
#ai-governance #delivery-control #operational-ai #ai-control-plane #enterprise-ai
Open on Medium ↗
Wiki topics: MAC · Macroeconomics 🚆 · Urban & Transport

We wouldn’t run a refinery without a control plane. So why are we running enterprise AI without one?

What two decades building fault-tolerant systems — from oil refineries to global supply chains — taught me about the missing layer in enterprise AI adoption. And why the answer isn’t more tooling.

In 1997, I joined Invensys Process Systems as a trainee engineer. My first years were spent deep inside refineries and petrochemical plants — not the clean, air-conditioned kind you’d visit on a corporate tour, but the kind where things failing meant things burning. I wrote code in C, Assembly and Ladder Logic. I implemented TCP/IP and DNP3 protocols so intelligent field devices could communicate with supervisory systems. I worked on emergency shutdown architectures for plants operated by ARAMCO, Shell and Reliance Industries.

It was demanding, sometimes tedious, always consequential work. But it gave me an instinct that has quietly shaped everything I’ve built since — and that I now believe is the most important insight missing from the enterprise AI conversation.

In industrial automation, you don’t debate this. The control plane is what maintains state awareness across the entire facility. It governs how changes propagate. It validates decisions before they become actions. It logs everything — not because someone asked for an audit trail, but because when something goes wrong in a refinery, you need to reconstruct exactly what happened and why, right down to the microsecond.

Nobody runs a petrochemical plant on ad-hoc experiments and ungoverned instrumentation. The consequences are too physical, too immediate and too irreversible.

The same pattern, twenty-five years later

After Invensys, I spent eight years at Dell — running global programmes across Dell.com, factory planning, order management and supply chain. I commissioned Dell factories in Ireland, Brazil, India, Malaysia and Poland. I built the integration layer between Dell’s supply chain systems and its manufacturing operations. Hundreds of interdependencies. Real-time data flowing between systems that were never designed to talk to each other.

What made it tractable, every time, was the control plane. Not any single brilliant piece of software — but the architecture that maintained consistency, enforced policy and governed how changes propagated across a deeply interconnected system.

Later, I led product at a modern data platform startup during the early cloud and big-data wave, before joining Publicis Sapient as Senior Director, where I conceived and built Sustain, a licensable autonomous IT operations platform. We took it to pilot across Retail, Financial Market Infrastructure and Telecommunications. The product worked. But the harder problem — the one I kept running into — was getting enterprises to adopt it without creating new governance risks in the process.

That’s when I understood something clearly: the pattern I’d seen in refineries wasn’t specific to industrial systems. It was universal. Any system that becomes complex enough, fast enough, without a control plane, eventually fails in unpredictable ways.

Now I watch enterprises deploy AI the way nobody would ever run a refinery. Ungoverned experiments spreading across teams. AI tools adopted department by department, without shared context, without a unified state model, without policy enforcement. Pilots that succeed brilliantly in isolation and then fail to scale because there’s no architecture to receive them.

The CIO question I hear most often isn’t “which AI tool should we use?” It’s “how do we scale AI safely across the enterprise?” Those are completely different questions. The industry has been busy answering the first while the second goes largely unanswered.

What a control plane for AI actually means

When I work with enterprise clients now, I use AI to compress the time it takes to map their landscape — systems, actors, dependencies, where the real decisions get made versus where people think they get made. What used to take days takes hours. But that’s not the interesting part.

The interesting part is what happens after the mapping. Most organisations see a clear picture of their AI situation for the first time and realise they don’t have an AI-building problem. They have an AI-diffusion problem. Experiments everywhere. No shared intelligence. No governed propagation. No state awareness.

An enterprise AI control plane needs to do what the industrial control systems of my early career did — translated into a new domain. It needs to understand enterprise context: the systems, actors and workflows that make up the organisation. It needs to synthesise that understanding into executable plans, not just recommendations. It needs to govern how AI propagates across workflows through a controlled diffusion framework, not ad-hoc adoption. And it needs to maintain full governance throughout: policy enforcement, audit trails, decision validation, compliance.

Critically, it needs to work across the full enterprise lifecycle — from Day 0 greenfield builds through to Day 1000+ legacy modernisation. Because the enterprise doesn’t live in a clean-slate world. It lives in a world of inherited technical debt, legacy systems and workflows that can’t simply be switched off.

The lesson I keep coming back to

When I was commissioning the Dell factory in Poland, integrating factory automation systems with supply chain software that ran across five continents, there were moments of genuine complexity. Systems that were never meant to communicate. Data that needed to move in real time between processes with zero tolerance for error.

We solved it not by finding smarter software, but by building a coherent control architecture. One that knew the state of the whole system at any given moment. One that governed how a change in one place propagated through everything else. One that had clear, enforced rules about what could happen and what couldn’t.

That’s what I’m building with Purple Cortex at PurpleAI Labs. Not because the world needs another AI tool — it doesn’t. But because it needs the layer that makes AI adoption at enterprise scale both possible and safe. The closed-loop system that understands enterprise context, synthesises execution plans, governs the full lifecycle and controls how AI spreads across workflows, teams and environments.

I’ve been building control planes for complex systems for twenty-seven years. The domain has changed. The discipline hasn’t.

From fault-tolerant systems for refineries to cognitive governance for enterprise AI — the instinct is the same. The stakes are just different.


메타데이터
post_id
8f4aab7b0508
slug
we-wouldnt-run-a-refinery-without-a-control-plane-8f4aab7b0508
url
https://medium.com/@gkrishnak/we-wouldnt-run-a-refinery-without-a-control-plane-8f4aab7b0508
canonical_url
https://medium.com/@gkrishnak/we-wouldnt-run-a-refinery-without-a-control-plane-8f4aab7b0508
author_url
https://medium.com/@gkrishnak
status
ok
fetched_at
2026-06-23 06:34:20