Six signals this cycle. One argument runs through all of them: the binding constraint on enterprise agent deployment has shifted from model capability to identity governance—and the infrastructure to solve it shipped this week.
Start with the convergence. Microsoft's Vega delivers production-grade zero-knowledge proofs for authorizing non-human actors without exposing the full credential surface. Google's AP2, now backed by Mastercard and 60+ partners, settles agentic commerce onto W3C Verifiable Credentials and signed mandates. Gemini Enterprise makes the governance layer the product, not the model. And OpenAI's Ona acquisition hands agents the persistent runtime that turns short-horizon tasks into multi-day workflows—which means session-scoped credentials, state integrity, and revocation under drift become live problems, not roadmap items.
Read together, these are not four product launches. They are the Identity Control Surface crystallizing into a vendor-owned stack. The question every principal must answer before the architecture hardens: which agent identities are authorized to act, under what credential scope, with what audit trail? Treat this as a future problem and you will be retrofitting governance into live payment flows. The index agrees with the urgency—Governance & Ethics sits at 72, the highest indicator this cycle, while Brand languishes at 38. Organizations are building the policy layer faster than they can articulate it publicly. That gap is the risk.
Which is exactly what makes BBVA the week's most instructive move. A Tier-1 regulated bank put ChatGPT Enterprise in front of 100,000 employees. The Janus Brand question it had to resolve—is OpenAI's compliance promise consistent with our own risk identity?—is the one most enterprises are still avoiding. BBVA answered it. The 'pilot forever' posture is no longer a defensible strategy; it is a competitive liability.
But do not mistake infrastructure maturity for solved governance. The MIT Media Lab study names the hardest problem in the cycle: human-in-the-loop oversight assumes the human retains judgment to audit and intervene. That capacity decays under sustained delegation. Every governance design that leans on human checkpoints is leaning on a depreciating asset—and almost no one is modeling the half-life of their oversight capacity. The infrastructure to authorize agents is arriving faster than the architecture to supervise them.
The move this week: inventory your non-human identities and define their credential scope before you adopt a platform's governance defaults. Adopting Google's or OpenAI's defaults without customization is outsourcing a core governance decision.
Watch: SpaceX's pending $60B acquisition of Anysphere (Cursor), expected to close Q3 2026. Enterprise Cursor adoption policies will become the clearest proxy for how seriously your peers are pricing AI vendor concentration risk inside the security perimeter.
¶
Google AP2 + Mastercard: Verifiable Credentials as the Identity Control Surface for Agentic Commerce
Google's Agent Payments Protocol (AP2), live since September 2025 with 60+ partners including Mastercard, PayPal, Coinbase, Amex, and Salesforce, uses W3C Verifiable Credentials to carry signed Intent, Cart, and Payment Mandates. Stablecoins are first-class rails. Mastercard's formal entry into the protocol stack, alongside alignment with OpenAI's Agentic Commerce Protocol and Google's Agent2Agent Protocol, signals convergence on a shared interoperability standard for agent-merchant transactions.
Why it matters
The Decision Surface for agentic commerce is no longer theoretical—it is settling into a specific technical stack: W3C VCs + signed mandates + tokenized payment credentials. Stripe and OpenAI's parallel work on Shared Payment Tokens confirms the direction. Enterprises need to answer a concrete question now: which agent identities are authorized to initiate financial transactions, under what credential scope, and with what audit trail? Organizations that treat this as a future problem will find themselves building identity governance retroactively into live agentic payment flows. The convergence of Google, Mastercard, Stripe, and OpenAI on interoperable standards compresses the decision timeline.
WatchSpaceX's $60B acquisition of Anysphere (Cursor) is pending close in Q3 2026. If it closes at that valuation, it will establish agentic software development as critical infrastructure in the same asset class as launch systems and satellite networks. The Janus Brand collision between Musk's infrastructure empire and a developer productivity tool used inside enterprise security perimeters will force procurement and security teams to make an explicit vendor trust decision they have not yet had to make. Watch for enterprise Cursor adoption policies to become a proxy for how organizations are thinking about AI vendor concentration risk.