Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

The Identity Control Surface Just Shipped as Product

Read the week as one argument: the agentic adoption curve has detached from the agentic governance curve, and the market has finally noticed what's holding in the gap.

The numbers tell it cleanly. 96% of enterprises are running AI agents (OutSystems) — and 94% flag agent sprawl as a concern. 88% of coding-agent pilots never reach production (Northflank), and the blocker is not model capability. It is isolation, audit, and authorization. Translated into Applied Identities terms: the pilot-to-production gap is an Identity Control Surface failure, not an intelligence failure. Enterprises automated tactically before they governed structurally — exactly what the Compiled Corporation framework predicts — and the bill is now due in deployment.

What changed this week is that the missing layer became purchasable. Google shipped the Gemini Enterprise Agent Platform with Agent Identity, Agent Registry, and Agent Gateway (Google Cloud) — the Identity Control Surface as first-class infrastructure, not a slide. Microsoft Research published Vega (Microsoft), zero-knowledge proofs that let an agent prove authorization without exposing credentials — the cryptographic floor under runtime least-privilege. Mastercard joined the multi-protocol commerce effort where verifiable agent identity is a stated requirement (Mastercard). Three of the largest infrastructure vendors on earth converged on the same primitive in a single week. That is not coincidence; that is a category forming.

The adversaries have already arrived. The FBI-Google takedown of Outsider Enterprise (BleepingComputer) confirms that AI-scaled identity compromise is operational. The Identity Control Surface is now a security perimeter, not a governance nicety. Enterprises without a non-human identity posture are not merely behind — they are targeted.

The index frames the stakes. Brand sits at 38, Product at 55, Organization at 62 — and all three moved zero this week. The infrastructure shipped; readiness did not respond. That gap is the opportunity and the warning. The vendors have answered who authorizes the agent and how it's tracked at scale. The question for principals is whether your architecture can consume that answer, or whether you're still counting agents you can't name.

The move this week is not to evaluate models. It is to inventory agents — count, owner, scope, audit trail — and benchmark that inventory against the reference architecture Google just published. If you can't produce the inventory, you don't have a pilot problem. You have an identity problem.

Watch: BBVA's 100,000-employee ChatGPT Enterprise rollout — the largest confirmed regulated-sector deployment on record. Any operational disclosure over the next 60 days (latency, governance failure, compliance incident, workflow redesign) is the first real stress test of whether agentic identity governance holds under production load in financial services. Treat any post-mortem as primary source.

Index Reference · Applied AI Index 2026-W24
Overall
51.7
Organization
62
— 0
Brand
38
— 0
Product
55
— 0
Movers · Workforce AI Access (+1) · Governance & Ethics (+1) · Talent & Upskilling (+1)
Signals

Google launches Gemini Enterprise Agent Platform with Agent Identity and Registry

Google released the Gemini Enterprise Agent Platform, purpose-built infrastructure for moving agentic AI from pilot to production. The platform includes Agent Identity, Agent Registry, and Agent Gateway — centralized control primitives that govern how agents authenticate, register, and route in enterprise environments. This is not a tooling announcement; it is an identity control surface shipped as product.

Why it matters

This is the most structurally significant signal of the week. Google has formalized the Identity Control Surface as a first-class infrastructure layer — Agent Identity and Agent Registry are direct responses to the non-human identity governance gap that has blocked enterprise agentic adoption. For Applied Identities clients, this is the reference architecture they've been waiting for: a vendor-endorsed answer to who authorizes the agent, and how is that tracked at scale. The Decision Surface implication is equally sharp — Agent Gateway centralizes the human/agent interface, making policy enforcement tractable. Clients building agent programs now have a concrete infrastructure target to evaluate against.

Enterprise agentic AI adoption reaches 96%, but 94% flag agent sprawl

OutSystems' 2026 State of AI Development report surveyed enterprises globally: 96% are running AI agents, 97% are exploring system-wide agentic strategies. The counterweight: 94% cite agent sprawl as a concern — uncontrolled proliferation of agents without coordinated governance, ownership, or lifecycle management. The gap between experimentation and governed production is widening, not closing.

Why it matters

The 96% adoption figure is a vanity metric. The 94% sprawl concern is the operative signal. This data confirms what the Compiled Corporation framework predicts: enterprises automate tactically before they govern structurally, creating compounding risk as agents multiply across business units. Identity Control Surface is directly implicated — sprawl is, by definition, a failure of non-human identity governance. Clients who cannot answer how many agents are running, who owns them, and what they are authorized to do are already in deficit. This report gives consulting engagements a hard data anchor.

88% of enterprise AI coding agent pilots fail to reach production

Northflank analyzed enterprise AI coding agent deployments and found 88% of pilots never reach production. The blocker is not model capability — it is deployment infrastructure: isolation, governance, compliance controls, and data residency requirements. Agents that work in sandbox conditions fail when the production environment demands accountability.

Why it matters

This is the clearest current evidence that the pilot-to-production gap is an identity and governance problem, not a capability problem. The Decision Surface breaks down at the production boundary because enterprises lack the controls to authorize, audit, and isolate agent behavior at the required fidelity. The Identity Control Surface is the missing layer — agents need governed identities, scoped permissions, and auditable action logs before regulated environments will accept them. For Applied Identities, this signal is a direct brief for why Identity Architecture precedes agent deployment, not follows it.

Source: Northflank

Mastercard joins multi-protocol agentic commerce standards effort

Mastercard joined Google's Universal Commerce Protocol and is collaborating across Agent Payments Protocol, Agent2Agent Protocol, and OpenAI's Agentic Commerce Protocol. The protocols define standards for clear user intent, secure credentials, and verifiable agent identity in commerce transactions — establishing the accountability chain for agent-mediated payments.

Why it matters

Mastercard's multi-protocol participation signals that verifiable agent identity in financial transactions is moving from research to standard. The Identity Control Surface dimension is explicit in the protocols themselves: verifiable agent identity is listed as a core requirement. The Janus Brand implication for Mastercard is notable — a brand built on trusted transaction infrastructure is betting that its identity in agentic commerce depends on owning the protocol layer, not just the rails. Enterprises building agentic procurement or payments workflows need to track which protocols their vendors are adopting, because interoperability will determine which agent stacks are viable in regulated commerce contexts.

Source: Mastercard

Microsoft Vega: zero-knowledge proofs for AI-era digital identity

Microsoft Research published Vega, a zero-knowledge proof system designed for digital identity in AI environments. Vega converts full credential sets into single compact proofs, sharing only the minimum necessary data while delivering real-application performance. The system is explicitly designed for the non-human identity context — agents proving authorization without exposing underlying credential data.

Why it matters

Vega is the most technically precise signal on the Identity Control Surface this cycle. Zero-knowledge proofs solve a specific problem that matters enormously in agentic deployments: an agent must prove it is authorized to act without revealing credentials that could be exfiltrated or replayed. This is the cryptographic foundation that makes least-privilege agent identity enforceable at runtime, not just at policy time. For clients designing agent identity architecture, Vega represents the direction of travel for credential infrastructure — and Microsoft shipping it from Research signals it will surface in Azure identity products within 12–18 months. Watch this.

FBI dismantles AI-powered Chinese phishing operation Outsider Enterprise

FBI, Google, and Black Lotus Labs jointly dismantled Outsider Enterprise, an AI-powered phishing operation attributed to Chinese threat actors. The operation used AI to generate and scale identity compromise attacks. $100K in Tether was seized. The joint takedown involved coordination across federal law enforcement and two major technology firms.

Why it matters

Adversarial agentic AI is operational, not theoretical. Outsider Enterprise demonstrates that the same infrastructure driving enterprise agent adoption — scalable, autonomous, capable of impersonating identity at volume — is being weaponized against enterprise identity surfaces. The Identity Control Surface is now a security perimeter, not just a governance framework. Enterprises that have not defined their non-human identity governance posture are not only operationally exposed; they are a target. The FBI-Google-Black Lotus coordination model also signals that identity threat response is becoming a multi-party infrastructure problem, mirroring the multi-party agentic commerce protocol efforts on the legitimate side.

Watch

BBVA's 100,000-employee ChatGPT Enterprise rollout is the largest confirmed regulated-sector agentic deployment on record. Watch for operational disclosures — latency, governance failures, compliance incidents, or workflow redesign announcements — over the next 60 days. At that scale in financial services, BBVA becomes the stress test for whether enterprise agentic identity governance holds under real production load. Any public post-mortem from that deployment will be a primary data source for what Identity Architecture at scale actually requires.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 50 · tavily: 15 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com