Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

The Rails Arrived Before the Governance

Read today's signals in sequence and a single argument emerges: the infrastructure for agent-mediated transactions is being standardized at network scale while the enterprises that will run on it have no governance layer to plug into.

Start with the empirical gap. OutSystems puts 96% of enterprises deploying AI agents and only 3% scaling (OutSystems) — a figure IDC/AWS independently confirms. That 3% ceiling is not a capability problem. It is the Compiled Corporation gap made measurable: distributed experiments that cannot be compiled into coordinated operational capability because the orchestration, ownership, and identity scaffolding doesn't exist.

Now watch how fast the rails are hardening underneath that gap. Google's AP2 is live with 60+ partners using signed Mandates (Currency Research). Stripe and OpenAI have Etsy merchants transacting through ChatGPT today (Fintech Blueprint). Microsoft Vega operationalizes credential proofs that travel with the agent (Microsoft Research). Google's Gemini Enterprise Agent Platform packages production governance as a line item you can buy (Google Cloud). The Decision Surface for commerce has already moved from a checkout page to a conversational turn.

This is the asymmetry that should set this morning's agenda. The index reads brand at 38 against organization at 62 — your house is more ready to deploy than to position. But the deeper risk is sequencing. When the payment networks, the identity layer, and the platform vendors all standardize the agent transaction before your firm has an Identity Control Surface — ownership registries, audit trails, provisioning controls for non-human actors — you don't get to architect against the standard. You re-architect after it hardens. Microsoft's Project Ire finding sharpens the stakes: agents acquiring system-level permissions are already drawing the class of evasion malware standard EDR misses (Microsoft Research). You are expanding attack surface faster than posture.

The move for principals: treat agent governance as a deployment prerequisite, not a retrospective audit. Before the next agent pilot ships, demand the ownership registry and identity attribution that lets you compile it into the firm — not an experiment that quietly becomes ungoverned decision infrastructure. And note the Janus Brand trap in the Google posture: the vendor selling you capability is the same one selling you governance. Scrutinize that.

Watch this: whether OpenAI, Microsoft, and Google roadmaps converge on agent cost attribution tied to identity. OpenAI's ChatGPT Enterprise spend controls are the first indicator. When cost visibility arrives before ownership accountability, procurement — not security or architecture — will define your agent governance standard by default. Track that convergence; it sets the terms.

Index Reference · Applied AI Index 2026-W24
Overall
51.7
Organization
62
— 0
Brand
38
— 0
Product
55
— 0
Movers · Workforce AI Access (+1) · Governance & Ethics (+1) · Talent & Upskilling (+1)
Signals

Microsoft Vega brings zero-knowledge proofs to AI-age digital identity

Microsoft Research's Vega system condenses full credential sets into single zero-knowledge proofs, exposing only the attributes required for a given transaction. The architecture is explicitly designed for agent-mediated interactions — where an autonomous agent must prove user authorization without surfacing the underlying credentials to counterparty systems.

Why it matters

This is a direct answer to the Identity Control Surface problem Applied Identities has been tracking: when agents transact autonomously, the credential governance layer must travel with the agent, not sit behind a human login event. Vega operationalizes that principle. Enterprises deploying agentic workflows without a non-human identity governance layer are accumulating provenance debt — Vega signals that the tooling to close that gap is arriving. Watch for this pattern to become a procurement requirement in regulated industries within 12 months.

Google AP2 and Mastercard establish structural rails for agent-initiated payments

Google's Agent Payments Protocol (AP2), live with 60+ partners including Mastercard, PayPal, and American Express, uses W3C Verifiable Credentials-based signed Mandates (Intent, Cart, Payment) to prove user authorization and agent identity at the transaction layer. Mastercard simultaneously launched its own Agent Pay framework and joined AP2 — signaling that payment networks are treating agent-initiated transactions as a structural category requiring new rails, not a feature addition to existing checkout flows.

Why it matters

This directly instantiates the Agentic Commerce credential problem at financial-network scale. The signed Mandate pattern — where the agent carries cryptographically verifiable proof of user intent scoped to a specific transaction — is the payment-layer equivalent of Vega's identity proof. Enterprises building procurement, expense, or supply-chain agents now have a live protocol stack to architect against. Firms that delay agent payment governance until post-pilot will face retroactive re-architecture against an already-hardened standard.

Stripe and OpenAI deploy Agentic Commerce Protocol with Shared Payment Tokens in ChatGPT

Stripe and OpenAI's Instant Checkout in ChatGPT executes full purchase flows — discovery through payment — inside a conversation thread using Shared Payment Tokens scoped to specific merchants and amounts. Live with Etsy merchants; Shopify partnership announced. The protocol prevents credential exposure while enabling ChatGPT to act as a purchase-initiating agent on behalf of the user.

Why it matters

The Decision Surface just moved. The human/agent interface for commerce is no longer a checkout page — it is a conversational turn. Enterprises selling through digital channels must now evaluate whether their product discovery, pricing, and fulfillment logic is accessible to agent-mediated purchase flows or invisible to them. This is not a future-state scenario: Etsy merchants are live on this rail today. B2C and B2B sellers need a position on agent channel strategy before their distribution is structurally disadvantaged.

OutSystems: 96% of enterprises using AI agents, only 3% scaling — sprawl is the stated threat

OutSystems' 2026 State of AI Development report surveyed enterprise organizations and found 96% already deploying AI agents, 94% expressing concern about uncontrolled proliferation, and only 3% successfully scaling across departments. The IDC/AWS parallel finding — 62% experimenting, 3% at multi-department scale — confirms the pattern is not sample-specific. Gartner projects 40% of enterprise applications will embed task-specific agents by end of 2026.

Why it matters

This is the Compiled Corporation gap made empirical: organizations are running distributed agent experiments without the orchestration, governance, or identity infrastructure to compile them into coordinated operational capability. The 94% sprawl concern is not a perception problem — it is a structural one. Agents deployed without ownership registries, audit surfaces, and provisioning controls are accumulating as ungoverned decision infrastructure. The 3% scaling rate will remain the ceiling until Identity Control Surface governance becomes a prerequisite for agent deployment, not a retrospective audit.

Google Gemini Enterprise Agent Platform closes the production gap explicitly

Google's Gemini Enterprise Agent Platform provides integrated infrastructure for building, scaling, governing, and optimizing agents in production — including DevOps tooling, orchestration, integration connectors, and security guardrails. Google's framing is explicit: pilot-to-production failure is an infrastructure problem, not a capability problem.

Why it matters

Google is packaging the Compiled Corporation transition as a platform sale. The operational gap between agent pilots and governed production deployment is now a named product category, not an internal engineering problem. This accelerates the timeline for enterprise procurement decisions: organizations can no longer defer production agent governance as a future-state concern when hyperscalers are actively selling the governance layer. The Janus Brand dimension applies here — Google is simultaneously the AI capability vendor and the AI governance vendor, a posture that will require scrutiny in enterprise procurement.

Microsoft Project Ire detects LOTUSLITE malware that standard EDR tools missed

Microsoft Research's Project Ire identified LOTUSLITE malware specimens using reverse engineering techniques that major endpoint detection and response (EDR) tools did not flag. The malware uses evasion patterns specifically targeting system-level access pathways.

Why it matters

The Identity Control Surface is under active adversarial pressure. As agents acquire system-level permissions — file access, API credentials, browser sessions — they become high-value targets for exactly the class of evasion malware Project Ire identified. Standard EDR tooling built for human-operated endpoints does not have coverage parity for agent-mediated access patterns. Enterprises extending permissions to agents without agent-specific detection and audit tooling are expanding their attack surface faster than their security posture is adapting.

Watch

OpenAI's spend controls and usage analytics release for ChatGPT Enterprise is the earliest indicator of a coming shift: AI vendors will begin publishing agent unit economics tooling before enterprises have governance frameworks to act on it. When cost visibility arrives before ownership accountability, procurement will drive agent governance decisions instead of security or architecture teams. Track whether OpenAI, Microsoft, and Google roadmaps converge on agent cost attribution tied to identity — that convergence will define the governance standard.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 50 · tavily: 15 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com