Skip to content
NagentNagent
Log inSign upHire your AI team
STATE OF AGENT GOVERNANCE The control plane is a category before it is a product.
STATE OF AGENT GOVERNANCE

The control plane is a category before it is a product.

Forrester opened the market in December 2025. Microsoft put a price on it in May 2026. Almost every claim to own the category is still confined to a single vendor's own agents, the standards that would make governance portable do not yet exist, and the analyst with the sharpest thesis argues that the way most platforms are building it is the reason enterprises will switch their agents off.

17 %
of organisations have deployed AI agents, against more than 60 % expecting to within two years
GARTNER, 15 APR 2026
16 %
of enterprise deployments qualify as true agents rather than fixed-sequence workflows
MENLO VENTURES, 9 DEC 2025
53 %
have had agents exceed intended permissions; 47 % had an agent-involving security incident in a year
CSA AND ZENITY, 16 APR 2026
$15
per user per month, the first published price for a cross-vendor agent control plane
MICROSOFT AGENT 365, 1 MAY 2026
01

An agent control plane is the answer to a question that only appears at the second agent

A single agent needs a prompt, a model and a tool. A fleet of agents needs an answer to who authorised this, what it is allowed to touch, what it did last night, what it cost, and who is accountable when it is wrong. The control plane is the system that holds those answers.

The term borrows from networking, and the borrowed meaning is the useful one

In network infrastructure the data plane moves packets and the control plane decides how packets should be moved. Applied to agents, the data path is the agent doing its work: reasoning, calling tools, writing to systems of record. The control plane is everything that decides what that agent may do, records what it actually did, and changes the rules without changing the agent.

Forrester's definition, published on 4 December 2025, is the closest thing the market has to a formal one: an enterprise control plane that inventories, governs, orchestrates and assures heterogeneous AI agents across vendors and domains. IBM defines it as the system that deploys, operates, monitors and governs agents across an organisation. The two differ on scope, which matters commercially and is covered in section 03.

Six questions define the job

Inventory. Which agents exist, who owns each one, which version is running, and which were never registered at all.
Identity and authority. What each agent is, distinct from the person who deployed it, and what authority it holds when it reaches another system.
Policy. Which actions are permitted, which require approval, which are refused outright, and how those rules are enforced at the moment of execution rather than in documentation.
Evidence. A record of what was proposed, what was approved, by whom, what was executed and what changed as a result.
Cost. What each agent, team and run consumed, with caps that hold.
Lifecycle. How an agent is promoted, demoted, paused and retired, and what happens to its credentials when it is.
nagent.ai/notes/agent-control-planeLive
BUILD PLANE, WHERE AGENTS ARE CREATED
frameworksagent buildersskills and promptsevaluations
ORCHESTRATION PLANE, WHERE AGENTS COORDINATE
workflowsroutinghandoffsagent teams
CONTROL PLANE, WHERE AUTHORITY IS DECIDED AND RECORDED
registryagent identityautonomy and approvalguardrailsbudgetsaudit traillifecycle
ENTERPRISE SYSTEMS THE AGENT REACHES
recordstools and APIsMCP serverscustomers

The reason it is being bought now is that agents write, not read

Assistants that summarise and draft carry review risk. Agents that send, purchase, refund, escalate and update records carry action risk, and action risk is what security teams, auditors and regulators price. The Cloud Security Alliance and Zenity found that 53 % of organisations have already seen agents exceed intended permissions, while only 31 % had formally adopted policies for agents at all. That distance between capability and control is the market.

02

Adoption is real, narrow, and measured three different waysPublished agent-adoption figures range from 16 % to 91 % of enterprises. The spread is definitional rather than empirical, and reconciling it is the first thing any governance argument has to do.

The defensible band for agents doing real multi-step work in production is 16 % to 20 %

Four independent sources converge once the word agent is defined tightly. Menlo Ventures placed 16 % of enterprise deployments in the true-agent category, where a model plans, executes, observes and adapts, against 27 % for startups, and described the remainder as fixed-sequence or routing workflows wrapped around a single model call. Gartner reported 17 % deployed. McKinsey put roughly 20 % of organisations at the scaling stage for agents, against 47 % for conversational assistants.

Figures above 50 % are counting assistants and copilots. Okta's Businesses at Work 2026 found 91 % of organisations already using AI agents on a sample screened for AI use, and in the same study only 10 % reported a well-developed strategy for managing them.

Growth is in scaling, not in attributed profit

McKinsey's 2026 survey of 1,719 respondents across 97 countries found 40 % of large organisations scaling AI agents, up from 27 % the year before. In the same survey the share attributing any EBIT impact to AI held flat at 37 %, and the share qualifying as high performers held flat at about 6 %. Adoption moved and measured profit did not, which is the strongest evidence behind unclear business value as a cancellation driver.

The agent platform market is small, and the governance layer inside it is smaller

Menlo measured $37 billion of enterprise generative AI spend in 2025, 3.2 times the prior year. Agent platforms took roughly $750 million of the $8.4 billion horizontal category, about 10 %, against 86 % for copilots. Forecasts placing agentic AI at $1.3 trillion by 2029, published by IDC, count total IT spending influenced by agentic AI rather than agent software licences, and the two figures should never appear in the same argument.

"Most deployments remain narrowly scoped, and fully autonomous agents are not ready for the majority of enterprise use cases."

GARTNER, HYPE CYCLE FOR AGENTIC AI, 15 APRIL 2026
03

Five analysts have defined the category and no two definitions agreeThe phrase agent control plane is under a year old as a market term and is already attached to four different kinds of product.

Forrester opened the market and drew the boundary tightly

Leslie Joseph announced Forrester's evaluation of the Agent Control Plane market on 4 December 2025, with five in-scope areas: agent inventory and identity, policies and guardrails, monitoring and insight, control and coordination, and risk, compliance and auditing. Development environments and orchestration fabrics sit explicitly outside it. Forrester expects 12 to 24 months before the market resolves into comparable offerings, so no Wave and no vendor ranking exists today.

The definitional fault lines are commercially material

Scope. Forrester excludes build and orchestration. IBM's definition folds in execution management, request routing and state. Activant Capital defines the control plane as a build studio plus an agent marketplace, close to the opposite of Forrester's position.
Uniform against tiered policy. Nearly every shipping product markets one common policy layer. Gartner's 26 May 2026 release names exactly that as the failure mode.
Security product or operations product. Okta, CyberArk, Palo Alto, Zenity and Zscaler frame the category as identity and security. ServiceNow, IBM and Microsoft frame it as operations, cost and compliance.
Gateway against plane. The gateway camp argues that the only mandatory chokepoint is the governed hop between agent and tool, so the gateway is the control plane. Forrester treats data-path mediation as one input among five.
Naming. Gartner says agent management platforms. Forrester says agent control plane. ServiceNow says AI Control Tower, Microsoft says Agent 365, Google says Agent Gateway and Agent Registry.

Gartner's tiered-autonomy thesis is the most useful analytic asset in the category

Gartner predicts that by 2027, 40 % of enterprises will demote or decommission autonomous AI agents "due to governance gaps identified only after production incidents occur", and attributes the cause to binary treatment of governance. Its remedy is four autonomy tiers, each carrying its own control set: Observe, with read-only access to defined sources; Advise, producing recommendations under human review; Act with Approval, executing only after explicit human sign-off; and Act Autonomously, executing independently inside guardrails.

"Enterprises are treating AI agent governance as binary, either locked down or fully trusted, and that is the root cause of failure."

SHIVA VARMA, SENIOR DIRECTOR ANALYST, GARTNER, 26 MAY 2026

The category is forming faster than the standards beneath it

In a February 2026 poll of vendors, Forrester found 92 % had assigned a named product manager or team to agent governance or control plane functionality, 79 % recognised the category, and 40 % reported active requests for proposal. The same analysis lists three blocking gaps: OpenTelemetry has not published a stable version of the generative AI semantic conventions, no portable agent identity and policy-propagation standard exists at enterprise maturity, and there are no cross-plane governance schemas. Vendor-neutral governance is therefore a claim no product can currently substantiate in full.

04

Fourteen layers, four settled, six contested, and one that is entirely unsolvedReference models from Futurum, BCG, IBM, Salesforce and the hyperscalers cover broadly the same ground under different names. The table reconciles them and marks where the market has actually converged.

LAYERNAMES IN USESTATUS
Registry and inventoryAgent Registry and Agent Card (AWS), Agent 365 Registry and identity blueprint (Microsoft), Agent Registry (Google), agent catalogue (IBM)CONCEPT SETTLED, SCHEMA CONTESTED
Agent identity and credentialsEntra Agent ID, Agent Identity, AgentCore Identity, workload identityCONVERGING
Authorisation and delegationPolicy and Cedar (AWS), on-behalf-of execution (Databricks), user-proxy against autonomous agents (Salesforce), token exchange and actor claims (IETF)UNSOLVED BEYOND ONE HOP
Policy engine and guardrailsGuardrails, Model Armor, deny / steer / warn / log / allow, judge-model guardrails, behaviour guardrailsCONTESTED
Tool and MCP gatewayagentgateway, AgentCore Gateway, Agent Gateway, Unity AI Gateway, Omni GatewayCOMMODITISED
Orchestration and runtimeRuntime and Harness, Agent Runtime and Agent Sandbox, Agent Server, execution environmentCOMMODITISED
Memory and context governanceAgentCore Memory, Agent Memory Bank and Memory Profiles, knowledge authority, semantic layerLEAST CONVERGED
Evaluation and testingEvaluations, Agent Simulation, continuous evaluation on production traffic, red-teaming agentSHAPE AGREED, METRICS NOT
Observability, tracing, auditOpenTelemetry generative AI conventions against OpenInference span kinds; unified audit logTRANSPORT SETTLED, SEMANTICS NOT
Cost and token budgetFinOps on dollar cost, run-scoped budgets with steer and halt, spend caps and failoverEMERGING
Human approval and interventionInterrupt and resume, pause / escalate / narrow / modify / defer / rollback, approval per action against per planNO CONTROL-PLANE STANDARD
Lifecycle and kill switchDraft to pending approval to published, agent lifecycle management, quarantine of unsanctioned agentsCONTESTED
Drift and quality scoringAgent Anomaly Detection, Optimisation, alerts, semantic anomaliesNEWEST, NO AGREED METRIC
Inter-agent accountabilityA2A signed agent cards, coordination layer, typed provenance, signed action receiptsPROTOCOL EXISTS, ACCOUNTABILITY DOES NOT

Delegation across more than one hop is the genuine hole in the stack

The Model Context Protocol authorisation specification makes an MCP server an OAuth 2.1 resource server, requires resource indicators, and bans token pass-through, which closes the confused-deputy problem for a single hop. Nothing standardises what happens next: cross-organisational, multi-hop delegation in which authority narrows at every step, each hop is cryptographically bound to the last, and a downstream service can verify the chain without calling a central authority. IETF work on identity assertion authorisation grants reached an adopted OAuth working group draft in May 2026 with an explicit AI-agent use case, but the nested-actor claim is informational and unenforced. Workload identity proves which process holds a credential, not what authority it holds.

Autonomy is described four incompatible ways

As levels. The Cloud Security Alliance published a six-rung model in January 2026, graded by approval granularity: no autonomy, assisted with approval per action, supervised with approval per plan or batch, conditional inside boundaries, high autonomy with monitoring and a kill switch, and full self-directed autonomy. Its author states plainly that the highest rung is not appropriate for enterprise deployment today.
As a user role. The Knight Institute taxonomy names five levels by what the human is: operator, collaborator, consultant, approver, observer, and insists that autonomy is a design choice independent of capability.
As two scores. Anthropic measures deployments on separate risk and autonomy scores rather than tiers, and reports that full auto-approve rises from about 20 % of interactions among light users to more than 40 % among users with 750 or more sessions. That is the closest published evidence that trust is earned through exposure.
As a per-action decision. Galileo's control server returns deny, steer, warn, log or allow at each governed function call. AWS goes further and evaluates against what the agent has already done in the session.

No source defines human-on-the-loop normatively. The vocabulary remains open.

05

Every incumbent is bundling governance into a platform it already sellsThe competitive shape matters more than the feature lists. Governance is arriving as an attached module on platforms enterprises already own, and the data-path layer is being given away.

PLATFORM INCUMBENTS

Microsoft sets the price and the reference implementation

Agent 365 reached general availability on 1 May 2026 at $15 per user per month, or inside Microsoft 365 E7. It ships registry sync with AWS Bedrock and Google Cloud in public preview, the only shipped cross-hyperscaler agent inventory. Entra Agent ID supplies identity blueprints, parent and child agent relationships and conditional access. Purview logs agent to human, human to agent, agent to tool and agent to agent interactions.

PLATFORM INCUMBENTS

Google and AWS compete on runtime primitives

Google's Gemini Enterprise Agent Platform, announced 22 April 2026, is organised as build, scale, govern and optimise, with cryptographic agent identity, a registry, a gateway, anomaly detection using a judge model, and pre-deployment simulation.

AWS released Dogwood on 6 August 2026: an Apache 2.0 governance language, a superset of Cedar, that evaluates policies over sequences of agent actions rather than single calls, with policy support inside AgentCore.

PLATFORM INCUMBENTS

ServiceNow and IBM sell governance over other vendors' agents

ServiceNow's AI Control Tower positions to discover, secure, govern, observe and measure any AI across the enterprise, auto-discovering agents, models, assistants, MCP servers and datasets, and absorbed Traceloop's observability team in March 2026. IBM announced an agentic control plane in watsonx Orchestrate on 2 July 2026, with policy management, credential health, an agent catalogue and versioning, arguing that the value lies in not standardising the build stack.

GATEWAYS

The chokepoint layer is now open source

Solo.io contributed agentgateway to the Linux Foundation in August 2025, covering LLM, MCP and agent-to-agent traffic with authorisation, rate limits, budgets and tamper-evident audit trails. Kong added agent-to-agent traffic to its AI Gateway in April 2026. Galileo released Agent Control under Apache 2.0 on 11 March 2026, and Cisco announced its acquisition of Galileo on 9 April 2026. Policy enforcement and MCP mediation are being commoditised towards zero.

IDENTITY AND SECURITY

Identity vendors hold the strongest cross-vendor claim

Okta expanded AI agent security on 14 May 2026 across Amazon Bedrock AgentCore, Salesforce Agentforce and the ServiceNow AI Platform, with unsanctioned-agent discovery by monitoring new OAuth consent grants in managed browsers, and brought Okta for AI Agents Core into regulated environments on 25 June 2026. SailPoint shipped agent-discovery connectors across eight platforms in March 2026. CyberArk, Zenity, Palo Alto Networks and Zscaler are all pushing from the security side.

COMPLIANCE

The compliance pure-plays are being outflanked on enforcement

Drata announced AI agent governance on 10 June 2026 with inline sensors, real-time policy evaluation and tamper-evident logging, moving to limited availability in August. Vanta, Credo AI and Holistic AI remain framework and evidence tools rather than runtime enforcement. The distinction buyers are starting to draw is between evidencing a control and enforcing one.

Consolidation is being driven by security buyers, not operations buyers

DATEDEALREPORTED VALUE
25 Aug 2025Solo.io contributes agentgateway to the Linux FoundationDonation
9 Dec 2025Anthropic donates the Model Context Protocol to the Linux Foundation's Agentic AI FoundationDonation
Mar 2026ServiceNow acquires Traceloop, folded into AI Control TowerUndisclosed
9 Apr 2026Cisco announces acquisition of GalileoUndisclosed
Apr to Jun 2026Palo Alto Networks acquires Portkey, folded into Prisma AIRSUndisclosed
4 May 2026Cisco acquires Astrix SecurityUndisclosed
28 Jul 2026Cyera agrees to acquire Oasis SecurityAround $1bn per press reports, undisclosed by both parties
30 Jul 2026Okta agrees to acquire Permiso Security, closed 26 Aug 2026Undisclosed
Aug 2026Zenity Series C led by Norwest$125m

The acquirers are identity and security platforms. The targets are gateways, non-human identity, observability and guardrails. No acquirer has yet bought a horizontal registry-and-policy company, which is the open slot in the consolidation map.

06

Buyers are blocked on data, trust and cost, in that orderThe blockers that appear in the top three of independent surveys are consistent, and the incidents that reset procurement requirements are traceable to specific dates.

Confidence is running ahead of control

Okta's Businesses at Work 2026 found 91 % of organisations already using AI agents, fewer than a third at 32 % securing agents with the same rigour applied to human employees, 58 % naming AI governance and oversight as their top security concern, and only 10 % with a well-developed strategy for managing agents. The Cloud Security Alliance and Zenity study of 445 organisations found 53 % had seen agents exceed intended permissions, 47 % had an agent-involving security incident in the past year, only 31 % had formally adopted agent policies, and only 15 % had defined ownership for most of their agents.

Cost has become a first-order governance requirement

KPMG's second-quarter 2026 pulse of 204 US C-suite leaders at firms above $1 billion in revenue reported only 26 % with real-time visibility into AI operating costs and 36 % with token or usage controls deployed, against average planned AI investment of $202 million over the following twelve months. Gartner named escalating cost as the first of three cancellation drivers and added FinOps for agentic AI to the 2026 Hype Cycle. Run-scoped budgets, per-action cost prediction, loop-depth caps and circuit breakers are moving from engineering hygiene into the control set buyers ask about by name.

Four incidents set the current procurement questionnaire

Replit, July 2025. A coding agent executed destructive commands during a stated code freeze and dropped a production database. This is the origin of the kill switch, blast radius and environment separation line items in agent requests for proposal.
EchoLeak, CVE-2025-32711, patched June 2025. The first documented zero-click prompt-injection exfiltration in a production assistant, establishing injection as a production risk rather than a laboratory result.
Salesloft Drift, 8 to 18 August 2025. OAuth tokens for an integration were stolen and replayed against customer tenants, affecting more than 700 organisations. FINRA instructed member firms to disconnect all Salesloft integrations, rotate exposed credentials, review logs forensically for the window and report to FINRA, the SEC and the FBI. Token scope, lifetime and revocation entered financial-services questionnaires as a direct result.
ShareLeak, CVE-2026-21520, disclosed 16 April 2026. Untrusted form input concatenated into system instructions inside an agent-building platform, leading to data exfiltration by email. The follow-on lesson buyers drew was that a patched injection path can be re-exploited through a different channel.

Two structural headwinds face every independent governance vendor

First, incumbency: a16z's January 2026 survey of 100 verified senior buyers at Global 2000 firms found 65 % prefer incumbent solutions where available, citing integration and procurement simplicity. Second, provider-native defaults: buyers rely heavily on the agent security shipped by their model and platform providers rather than a third-party control layer. Independent positioning has to be earned on something a platform incumbent cannot do, which in practice means heterogeneity, exportable evidence and regulated-industry depth.

07

The compliance cliff moved, and the liability cliff did notThe most common error in current market positioning is urgency built on an EU deadline that no longer exists. The obligations that actually bite this year are transparency, general-purpose model enforcement and product liability.

There is no agent-specific law in the EU, and the Commission says none is needed

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred standalone high-risk obligations under Annex III to 2 December 2027 and embedded high-risk obligations under Annex I to 2 August 2028. Article 12 logging, Article 14 human oversight, Article 26 deployer duties and Article 73 incident reporting travel with those dates. The Commission's position is that the existing definitions of an AI system and a general-purpose model already cover AI agents.

What did apply on 2 August 2026 is Article 50 transparency, which catches any user-facing agent regardless of risk tier: disclosure that a person is dealing with an AI system, and machine-readable marking of synthetic output, with a four-month transitional period for systems already on the market. Enforcement powers over general-purpose models went live on the same date. No harmonised standard has yet been cited in the Official Journal, so no presumption of conformity is available to anyone, which is a large part of why the high-risk date moved.

Product liability is the near-term exposure, and it lands in December

The EU withdrew the AI Liability Directive in October 2025. Directive (EU) 2024/2853 fills the gap and applies to products placed on the market after 9 December 2026. It expressly treats software as a product, names AI system providers as manufacturers, adds liability for failure to supply security updates, extends recoverable damage to destruction of data, and creates rebuttable presumptions of defect and causation where technical complexity makes proof excessively difficult or the defendant fails to disclose evidence. The disclosure-triggered presumption is the sharp edge for an agent vendor: a platform that cannot produce decision traces stands in a worse position than one that can.

The United States is moving the other way, and courts are allocating agent liability directly

Executive Order 14365 of December 2025 established a Justice Department task force to challenge state AI laws, and Colorado repealed its AI Act, replacing it in May 2026 with a disclosure-and-fault regime effective January 2027. California SB 53 is in force, with transparency reports, a published frontier framework, 15-day critical-incident reporting and penalties to $1 million per violation. On 4 August 2026 the Ninth Circuit held in Amazon against Perplexity that under the Computer Fraud and Abuse Act it is the user who accesses a site with the help of an assistant, and that the assistant "is a tool, not a person for statutory purposes". The holding turns on architecture: browser-mediated agents are protected in a way server-to-server designs are not, and tort, contract and copyright theories were left open.

Financial regulators have split, and the Indian bar is currently the higher one

US interagency guidance SR 26-2 of 17 April 2026 superseded SR 11-7 and SR 21-8, applies to banks above $30 billion in assets, states that it sets no enforceable standards, and excludes generative and agentic AI from scope as novel and rapidly evolving. The Reserve Bank of India moved in the opposite direction, issuing draft Guidance on Regulatory Principles for Model Risk Management on 24 June 2026, covering all models used by regulated entities including third-party and machine-learning models across the lifecycle. Law-firm analyses of the draft report board-approved frameworks, independent validation of third-party models by the regulated entity before and after deployment, kill-switch and override arrangements, long retention of decommissioned model records, and contractual audit rights.

The most operationally specific government guidance on agents is Singapore's

Singapore's IMDA published a Model AI Governance Framework for Agentic AI on 22 January 2026: bound the agent through use-case selection and constrained autonomy, tool access and data permissions; define human accountability with checkpoints requiring approval and mitigation of automation bias; apply baseline testing, access control and lifecycle management; and provide end-user transparency and training. Paired with the NSA's 2026 information sheet on MCP security, which names absent access control, optional authorisation, weak re-approval on capability change and inadequate logging as systemic, these are the two most citable control checklists in existence, and both are free.

IN FORCE AS AT 1 SEPTEMBER 2026
2 Aug 2025

EU general-purpose model obligations and penalties apply; code of practice in effect

1 Jan 2026

California SB 53, AB 2013 and SB 243; Texas TRAIGA; Illinois HB 3773; California removes the autonomous-AI defence

22 Jan 2026

Singapore IMDA agentic AI governance framework; Korea AI Basic Act with a one-year enforcement grace

5 Feb 2026

UK Data (Use and Access) Act automated decision-making safeguards

15 Jul 2026

China's interim measures on anthropomorphic interaction services, the first binding regime aimed at human-like agents

27 Jul 2026

Regulation (EU) 2026/1744 in force, deferring the high-risk regime

2 Aug 2026

EU Article 50 transparency applies; AI Office enforcement powers over general-purpose models go live

4 Aug 2026

Ninth Circuit rules on agent access under the Computer Fraud and Abuse Act

COMING
2 Dec 2026

EU synthetic-content marking grace ends for systems already on the market

9 Dec 2026

EU product liability applies to products placed on the market, software and AI included

1 Jan 2027

Colorado's replacement AI law takes effect

28 Feb 2027

EU standardisation request expires; harmonised standards must land or the 2027 date is at risk

May 2027

India DPDP Rules reach full applicability (phased from the November 2025 notification)

2 Aug 2027

EU legacy general-purpose models must comply; regulatory sandboxes operational

2 Dec 2027

EU Annex III high-risk obligations: logging, human oversight, deployer duties, incident reporting

2 Aug 2028

EU Annex I embedded high-risk obligations

08

India regulates agents through sectoral regulators, and that changes what a platform must ship

MeitY's India AI Governance Guidelines of 5 November 2025 explicitly favour amending existing law over new AI legislation, and hand enforcement to sectoral regulators, with an AI Governance Group, a technology and policy expert committee and an AI Safety Institute as the institutional machinery.

The practical consequence is that for financial services the binding authority is the Reserve Bank of India rather than MeitY. The RBI's FREE-AI committee report of August 2025 set two commercially decisive principles: final decision-making vests with humans rather than models, and the regulated entity remains accountable regardless of the level of autonomy. The June 2026 draft on model risk management extends this to third-party and machine-learning models across the lifecycle.

For personal data, the DPDP Rules notified in November 2025 phase in over eighteen months to roughly May 2027, require breach notification to the Data Protection Board and to affected individuals with no materiality threshold, and require consent managers to be companies incorporated in India. An agent that touches personal data and acts without a human in the path is a notification liability under that regime.

The design consequence: an Indian buyer in banking or insurance cannot accept a model card as evidence, because the regulated entity is required to validate independently. A platform built to that bar, with model and agent inventory export, per-agent documentation, drift monitoring, an auditable override and complete action-chain logs held for long periods, is already over-compliant for a US bank operating under SR 26-2, which excludes agents from scope entirely. Building to the harder regime first turns compliance depth into an export asset.

Demand-side signal: EY's 2025 GCC pulse reported 58 % of India global capability centres investing in agentic AI and 29 % planning to scale within the year, while only 7 % had a fully embedded cybersecurity centre of excellence and 60 % now monitor third-party data access, up from 44 % a year earlier. Buying intent is running well ahead of governance maturity, and third-party scrutiny is tightening quickly.

09

Six problems the market has named and not yet solvedThese are the places where the analyst literature says control should exist and the shipped product landscape says it does not.

PROBLEM 01

Autonomy tiers as the organising unit of policy

Gartner names uniform governance as the root cause of agent failure and prescribes four tiers with distinct control sets. Most shipping products market one policy layer with autonomy as an attribute of an agent rather than as the structure that determines which controls apply.

PROBLEM 02

Governed paved roads, not enforcement alone

BCG's model is the only one treating pre-governed deployment templates, with identity, registration, monitoring and policy embedded by default, as a first-class control-plane component, and reports order-of-magnitude reductions in time to deploy. Enforcement stops unsafe agents. Paved roads are what make safe agents cheap.

PROBLEM 03

Inventory that genuinely crosses vendors

Forrester's definition requires heterogeneity, and Forrester's own assessment is that offerings remain platform-specific. Only Microsoft's registry sync and SailPoint's connector set currently reach beyond their own estate. Cross-vendor inventory is the capability the category is named after and the one least often delivered.

PROBLEM 04

Memory governance

Memory poisoning has a live attack literature and its own entry in the OWASP agentic top ten, yet no major vendor memory product publishes a write-admission policy, a provenance tag or an expiry model for learned experience. This is the layer where product maturity lags published attack research by the widest margin.

PROBLEM 05

Evidence a regulated buyer can export

Standard contracts confer no right to logs, decision traces or explainability. The product answer is an export: agent inventory, approval-gate evidence with approver identity, full action chains, evaluation records and model-change history, in a form an auditor or a regulated customer can lift without vendor assistance.

PROBLEM 06

Multi-hop accountability

Agent-to-agent protocols exist and are governed by the Linux Foundation. Accountability semantics across a delegation chain do not. Any platform running agent teams with reporting lines is already generating the artefact the standards bodies are still specifying.

10

How Nagent approaches the control plane

Nagent is a vendor in the market described above, and the disclosure belongs at the top rather than the bottom. What follows is an account of the design choices, set against the six problems in section 09, so that they can be judged rather than taken on trust.

Autonomy is the organising unit, not an attribute

Every agent on the platform carries an autonomy level alongside a risk level, on a five-rung ladder. The level determines which controls apply, which actions can fire without a human, and what the approval queue looks like. This is the tiered structure Gartner prescribes, implemented as the primary construct of the system rather than as a setting inside a uniform policy layer.

L0Locked

A human acts on every output. Nothing executes.

L1Suggest only

Drafts are visible and never sent. Read-only actions may fire; anything with a side effect queues.

L2Execute with approval

The agent runs automatically once a human has signed off on the action.

L3Audit only

The agent runs autonomously and every action is logged for review after the fact.

L4Fully autonomous

Unrestricted within the agent's guardrails, policies and budget.

Trust is earned and can be lost without anyone intervening

Each agent carries a trust score from 0 to 100 that moves with observed behaviour. Governance is scored twice: per agent in the workbench, where autonomy, risk, guardrails, policies and budget are configured, and across the fleet on a governance surface that ranks agents by a composite score, bands them, and names the weakest dimension for each. Drift beyond a threshold raises a warning, and an agent can be downgraded automatically rather than waiting for a human to notice. The same surface scores operator decisions alongside agent behaviour, on the view that approval quality is part of the control system rather than outside it.

Guardrails, policies and budgets are separate objects with separate enforcement

Guardrails are per agent, drawn from a template library, and carry a severity that is advisory or blocking, a category such as content restriction, cost cap, time window, audience restriction, tool restriction or approval required, and an enforcement action of warn, queue for approval, or block. Advisory means the agent is alerted and the action still runs, which is stated rather than hidden.
Approval policies name the actions that must route through the approval engine instead of executing, the approvers who receive them, and the service-level window for a decision. Approval authority is expressed as who may override the agent's verdict, with named final approvers.
Execution policies are hard runtime gates: maximum runs per hour, daily cost cap, per-action cap.
Budgets are per agent, with daily and monthly caps and a spend trend, and on breach the agent queues its actions for approval rather than stopping, which keeps the work visible instead of silently dropping it.

Tool authority is scoped, and blast radius is shown before anything ships

Whitelisting an action makes it available to an agent as a runtime tool, and the autonomy level then decides whether it fires or queues: read-only actions execute from L1 upwards, actions with side effects queue for approval below L3. Every action carries a scope, and narrowing an action to named agents prevents any other agent in the tenant from reaching it regardless of its own tool list. In the workflow builder, a blast radius panel flags conditions such as calling a third party at design time rather than at run time.

Memory is governed in two layers and every turn is replayable

Agent memory separates a creator layer, holding operator-authored hard rules and brand voice, from a user layer holding the agent's own observed tendencies, recent successes and recent failures. Every agent turn persists the context that was assembled for it, so a decision can be inspected and replayed rather than reconstructed. Against problem 04, this is a write-admission boundary and a provenance record at the point where most platforms hold an undifferentiated store.

Agent teams carry reporting lines, and the record is the deliverable

Agents have a reports-to relationship and a tier, and handoff targets are derived from the reporting line rather than configured separately, routing to parent, children, root or sideways to a specialist. Teams mix people and agents under a lead, and team membership is the access boundary for the team's thread, documents and decisions. The workspace is a shared thread where humans and agents post together, feedback is captured on each agent turn, and a decision can be recorded as such. Each team keeps a repository holding its charter, roster, memory, tasks, pending decisions, decision log and run records, which is the exportable evidence described in problem 05.

The deployment path is governed by default

Agents are created from a one-line description through a three-step flow that assembles skills, tools, triggers and guardrails together, so a new agent arrives registered, scoped and constrained rather than being retrofitted afterwards. Workflows are versioned with draft and published states, and the builder states plainly that nothing goes live without an explicit accept. This is the paved road in problem 02, implemented as the default route rather than an optional template.

One honest limit, stated plainly

Under Forrester's strict definition, a control plane governs agents it did not build. Nagent spans build, orchestration and control in a single platform, which means governance is enforced as a property of the runtime rather than inferred from outside it. The gain is that policy, memory, autonomy and evidence share one model, so an approval is bound to the exact context that produced the proposal. The trade-off is that agents built elsewhere are governed through integration rather than natively, and no vendor in this market, including those claiming vendor-neutrality, currently delivers full cross-vendor governance in the way the category definition implies.

The argument in one line

Agents fail in production not because models are weak but because authority is undefined, and authority is a product decision rather than a policy document. A control plane earns its place when the level of autonomy an agent holds is visible, evidenced, reversible and earned.

11

How to read the numbers in this marketEvery figure in this brief was checked against a primary source. These are widely repeated claims that did not survive that check, with the defensible substitute in each case.

NOT SOURCED

"Only 21 % of organisations have a mature agentic governance model."

Circulated with an attribution to a large April 2026 consultancy study. No such publication could be located on the named firm's own properties. The defensible substitutes are the Cloud Security Alliance ownership and policy figures, and Okta's 10 % with a well-developed agent management strategy.

MISATTRIBUTED

"Okta, AI Agents at Work 2026: 92 % widespread use, 34 % same controls, 58 % had an incident."

No report of that name or date exists. The correct source is Businesses at Work 2026, published 30 April 2026: 91 % using agents, 32 % securing agents with the same rigour as employees, and 58 % naming governance and oversight as their top security concern, which is a concern figure rather than an incident rate.

QUALIFY

"92 % of enterprises have named an owner for agent governance."

Forrester's 92 % is a poll of vendors, not enterprises. Cited as an enterprise statistic it inverts the meaning: it is evidence of supply-side crowding rather than buyer maturity.

QUALIFY

"AWS AgentCore shipped Dogwood."

Dogwood is a standalone Apache 2.0 governance language for agents and tools, released on 6 August 2026, with policy support additionally available inside AgentCore. Describing it as a product feature understates the strategic move, which is an open language other platforms can adopt.

UNDISCLOSED

Reported prices for the Cyera and Oasis, and Okta and Permiso, transactions.

Both deals are confirmed and neither price is disclosed by the parties. One figure comes from press reporting and the other has no primary support. The deals are citable; the numbers are not.

SUPERSEDED

"EU AI Act high-risk obligations apply from 2 August 2026."

Deferred to 2 December 2027 and 2 August 2028 by Regulation (EU) 2026/1744. Urgency framing built on the old date is now wrong, and buyers who have read the omnibus will notice. Article 50 transparency is the live obligation.

QUALIFY

"95 % of AI projects fail" and "ISO 42001 is a procurement requirement".

The first measures attributable profit from generative AI pilots on a small, non-probability sample and says nothing about agents. For the second, no primary survey quantifies buyer demand; the frameworks buyers actually name are HIPAA, the NIST AI Risk Management Framework, and SOC 2 or ISO 27001.

CONTESTED

"Machine identities outnumber humans 45 to 1."

Publishers report 45, 80 and 109 to one for different populations counted in different ways. Cite one publisher with its date, or drop the ratio.