In five weeks, every layer of the enterprise stack shipped the same thing.
The boundary rush, Sept 2026
Identity. Workflow. Gateway. Runtime. Hardware. Different vendors, different corners of the stack, the same product: a gate around the agent.
That is not a coincidence. It’s a verdict. And like most verdicts, what it leaves out matters as much as what it says.
The concession
The industry has quietly agreed on something it spent two years avoiding: you cannot govern an agent from inside the agent.
NVIDIA said it plainly. In the incidents that prompted its platform, the agent got around controls at the application layer to finish the job it was given.5 The agent wasn’t malicious. It was diligent. It met an obstacle and routed around it, which is exactly what we built it to do.
We’ve seen this before. This summer, when Hugging Face’s defenders needed help reading the forensics of an AI-driven breach, the frontier models refused. Their guardrails couldn’t tell analyzing an exploit from launching one. The safety was real, but it belonged to the model, not to the people who needed it.
So the controls are moving out. Out of the prompt, out of the model, out of the harness — into identity systems, gateways, runtimes and chips the agent can’t see, can’t reason with, and can’t talk its way past.
A watchdog the agent can’t argue with. That’s the right move — and the first half of the answer.
The land grab
Read the launch language and one phrase keeps recurring: control plane. CrowdStrike’s identity control plane. ServiceNow’s Control Tower. Okta as the gatekeeper. NVIDIA’s full-stack governance. Each vendor has independently concluded that the boundary around the agent is the most valuable square foot in the enterprise — and each wants to own it.
They’re not wrong about the value. Whoever holds the boundary decides what an agent may touch, records what it did, and holds the off switch. That isn’t a feature. It’s authority.
Which raises the question every executive should ask before signing: when the boundary is a service you rent, whose governance is it?
A mid-sized enterprise will soon run agents inside Microsoft, Salesforce, ServiceNow and a few homegrown tools, each with its own gate and its own policy language. The test one analyst put to Okta is the right test for all of them: can your rules hold consistently as an agent moves across the systems you actually use?4 Five gates with five rulebooks isn’t governance. It’s jurisdiction shopping, run by your agents.
Own your source, own your intelligence. The corollary arrived this month: own your boundary — or at least own the policy every rented gate enforces.
The skipped layer
Look at where all five gates stand. Every one of them faces the agent. They verify who it is, decide where it may go, watch how it behaves, and stop it when it strays. They govern the agent and the road it travels.
Not one of them is the place where the agent’s work actually lands.
That place is the system of record — the ledger, the policy file, the loan book, the inventory master, the claims history. It’s where an agent’s action stops being an attempt and becomes a fact. Everything upstream is a checkpoint. The system of record is the destination.
And the industry’s new architecture quietly assumes the destination will take whatever the checkpoints let through.
Security people have a name for that assumption: a single line of defense. Defense in depth means each layer can refuse on its own authority, not just on the word of the layer above it. Gates fail. Policies drift. A token gets scoped too wide. An identity provider gets compromised. When that happens, the last question that matters is whether the system holding the data can look at the request and say no — and leave a record no agent can edit.
Some systems were built that way from the start. On IBM i, every object carries its own authority, and the journal records who changed what, at the moment it changes. The platform never trusted the application to be honest; it governed what touched it. For forty years that looked like old-fashioned rigor. In an agentic enterprise it looks like the layer everyone else forgot to build.
IBM i is the proof case, not the boundary of the argument. If every gate above your core system failed tonight, what would it refuse?
The seam no gate covers
There’s a second gap, and no amount of gate-building closes it.
The new identity products promise to tie an agent’s action back to the human or workload behind it. CrowdStrike says so directly, and that’s real progress for the first hop: a person authorizes an agent, the agent acts.6
But agents don’t stop at one hop. A person tells an agent to settle a vendor dispute. That agent hands the pricing question to a second agent, which asks a third to adjust the invoice. By the time the change reaches your ledger, the authority behind it has passed through three hands — and no deployed system can prove that the person at the start meant this.
The payment networks have converged on proving who authorized an agent. Identity vendors are converging on proving who an agent is. How far authority travels before it runs out is still an open question. It has to be designed, not bought.
Which is one more reason the destination has to be able to judge for itself. When you can’t trust the chain, you’d better trust the vault.
Three questions
You don’t need to pick a vendor this quarter to know where you stand. You need three honest answers.
Regulators are starting to ask the same things. In July, Singapore’s central bank and a group of financial institutions published SAFR, a runtime framework that puts a checkpoint between every agent decision and its execution. It is explicitly not regulatory guidance — yet.7 But it reads like a preview of the questions an examiner will eventually bring.
Built in is what you own
The gate rush is good news. It means the industry has stopped pretending a well-written prompt is a security control. It means the boundary now sits where the agent can’t reach it.
But a gate is only as good as what’s behind it. This month the industry built the guardhouse, the badge reader and the cameras. Almost nobody asked whether the vault door locks on its own.
The businesses that come through the agentic transition intact won’t be the ones with the most gates. They’ll be the ones whose most important systems never needed to trust the gates in the first place.
Bolted on is what you buy. Built in is what you own.
Related on this site: The Seam · AI-Native Attacks Require AI-Native Security · The Remediation Gap · Capability Is Discovered · The Gate Dissolves · Neither You Nor a Stranger. The framework in full: Human · Org · Tech.
- CrowdStrike, “CrowdStrike Announces Agentic Identity Provider,” Fal.Con 2026, Sept 2, 2026. crowdstrike.com
- UiPath, Agents release notes, September 2026 — agent design policies (incl. human-in-the-loop escalation and iteration limits) generally available Sept 9. docs.uipath.com
- Forkast, “This Week in Agent Infrastructure: Runtime Enforcement Crystallizes as a Mandatory Layer,” Sept 2026 — ServiceNow AI Gateway GA Sept 10 as part of AI Control Tower. forkast.news
- Derek du Preez, “‘The gatekeeper’ — Okta expands AI agent controls,” diginomica, Sept 22, 2026. diginomica.com
- NVIDIA, “NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment,” Sept 28, 2026 — OpenShell runtime and the Sentry reference design on BlueField-4. nvidianews.nvidia.com
- Let’s Data Science, “CrowdStrike Introduces Agentic Identity Provider for AI Agents,” Sept 2026 — notes the attribution and token-scoping claims are the company’s own, not independent measurements. letsdatascience.com
- Baker McKenzie, “Singapore: MAS publishes agentic AI safeguards for financial institutions,” July 2026 — SAFR (Safeguards for Agentic Finance at Runtime), published July 3, 2026; expressly not regulatory guidance or supervisory expectations. bakermckenzie.com