Read the week as one argument: the agentic adoption curve has detached from the agentic governance curve, and the market has finally noticed what's holding in the gap.
The numbers tell it cleanly. 96% of enterprises are running AI agents (OutSystems) — and 94% flag agent sprawl as a concern. 88% of coding-agent pilots never reach production (Northflank), and the blocker is not model capability. It is isolation, audit, and authorization. Translated into Applied Identities terms: the pilot-to-production gap is an Identity Control Surface failure, not an intelligence failure. Enterprises automated tactically before they governed structurally — exactly what the Compiled Corporation framework predicts — and the bill is now due in deployment.
What changed this week is that the missing layer became purchasable. Google shipped the Gemini Enterprise Agent Platform with Agent Identity, Agent Registry, and Agent Gateway (Google Cloud) — the Identity Control Surface as first-class infrastructure, not a slide. Microsoft Research published Vega (Microsoft), zero-knowledge proofs that let an agent prove authorization without exposing credentials — the cryptographic floor under runtime least-privilege. Mastercard joined the multi-protocol commerce effort where verifiable agent identity is a stated requirement (Mastercard). Three of the largest infrastructure vendors on earth converged on the same primitive in a single week. That is not coincidence; that is a category forming.
The adversaries have already arrived. The FBI-Google takedown of Outsider Enterprise (BleepingComputer) confirms that AI-scaled identity compromise is operational. The Identity Control Surface is now a security perimeter, not a governance nicety. Enterprises without a non-human identity posture are not merely behind — they are targeted.
The index frames the stakes. Brand sits at 38, Product at 55, Organization at 62 — and all three moved zero this week. The infrastructure shipped; readiness did not respond. That gap is the opportunity and the warning. The vendors have answered who authorizes the agent and how it's tracked at scale. The question for principals is whether your architecture can consume that answer, or whether you're still counting agents you can't name.
The move this week is not to evaluate models. It is to inventory agents — count, owner, scope, audit trail — and benchmark that inventory against the reference architecture Google just published. If you can't produce the inventory, you don't have a pilot problem. You have an identity problem.
Watch: BBVA's 100,000-employee ChatGPT Enterprise rollout — the largest confirmed regulated-sector deployment on record. Any operational disclosure over the next 60 days (latency, governance failure, compliance incident, workflow redesign) is the first real stress test of whether agentic identity governance holds under production load in financial services. Treat any post-mortem as primary source.
WatchBBVA's 100,000-employee ChatGPT Enterprise rollout is the largest confirmed regulated-sector agentic deployment on record. Watch for operational disclosures — latency, governance failures, compliance incidents, or workflow redesign announcements — over the next 60 days. At that scale in financial services, BBVA becomes the stress test for whether enterprise agentic identity governance holds under real production load. Any public post-mortem from that deployment will be a primary data source for what Identity Architecture at scale actually requires.