For three years, enterprise AI governance lived in PDFs—policy frameworks, ethics charters, board attestations. This week it moved into the execution layer, and that relocation is the only story that matters.
Microsoft Agent 365 reached general availability (Microsoft Security Blog), embedding identity verification, scoped permissions, and audit trails directly into the agent runtime. This is the Identity Control Surface made product: non-human identity treated as a first-class operational concern, not bolted onto legacy IAM. Days later, KPMG committed to deploying it across 276,000 staff (Enterprise DNA) under its Trusted AI framing—a textbook Janus Brands move, aligning agent deployment with the firm's legacy authority as a governance and audit house. That is what production autonomy at population scale looks like, and it is why the AAI Organization dimension sits at 63 and rising.
The gap that holds the Brand dimension at 39—with AI-Native Messaging at 42—is precisely this: most enterprises can say that their agents are governed but cannot describe how. They have no auditable artifact. Agent 365, ServiceNow and Accenture's 300+ pre-built agent skills bundled with AI Control Tower, and Mastercard's Verifiable Intent (agenticplug.ai) each supply that missing artifact at a different layer. Verifiable Intent is the sharpest of the three: it pushes authorization records below the policy layer into tamper-resistant cryptography. The Governance & Ethics dimension leads our index at 73, but that score reflects policy adoption, not cryptographic enforcement. Those are not the same thing, and the distance between them is where your audit exposure now accumulates.
Here is the argument: the strategic question has decisively shifted from build or buy at the model layer to configure or customize at the agent workflow layer. If your team is still assembling a homegrown RAG stack while KPMG encodes firm-level decision workflows into managed agent infrastructure, you are spending engineering cycles on a problem the market just commoditized. Map your roadmap against those 300+ skills before you commit another sprint. And map your authorization model against Verifiable Intent before procurement, expense, or B2B payment agents go live—because the Compiled Corporation thesis is no longer theoretical. Decision-making is being encoded into runtime, with or without your governance keeping pace.
One caution: the EU's DMA designation of Azure and AWS means what is conveniently bundled in 2026 may be unbundled by 2027. Build with that optionality in mind.
Watch this: The first major ERP vendor to announce native Stripe Machine Payments Protocol support. That announcement—not any agent demo—is the production inflection signal for autonomous transactions, and it makes Verifiable Intent's authorization questions urgent for every firm with a procurement workflow.
¶
Microsoft Agent 365 GA: Enterprise AI agents now carry identity and governance controls
Microsoft Agent 365 reached general availability on May 1, 2026, embedding identity verification, access controls, audit trails, and real-time monitoring directly into the agent runtime. Organizations assign roles, permissions, and compliance metadata to AI entities as digital employees—moving agent governance from policy documents to execution layer enforcement. This is the first major platform GA that treats non-human identity as a first-class operational concern rather than an afterthought bolted onto existing IAM frameworks.
Why it matters
This is the Identity Control Surface made product. The AAI Brand dimension scores only 39 overall, with AI-Native Messaging at 42—partly because most enterprises cannot yet describe how their agents are governed, only that they are. Agent 365 GA gives organizations a concrete governance artifact: auditable agent identity records, scoped permissions, and compliance metadata. Enterprises that deploy this close a specific gap between governance intent and execution reality. Those that don't now have a named benchmark to explain away to auditors and boards.
¶
Google UCP expands to cart, catalog, identity linking; retail consortia coalesces around open standard
Google's Universal Commerce Protocol (UCP), launched January 2026 and expanded May 2026, now covers cart, catalog, and identity linking, with lodging and food verticals in active expansion. The protocol has accumulated 3,107 GitHub Stars and is co-developed by Shopify, Etsy, Wayfair, Target, and Walmart. UCP is the dominant retail-side protocol for agent commerce; Stripe's ACP governs the payment side. Two complementary open standards are consolidating the agentic commerce stack.
Why it matters
The Decision Surface is migrating: for consumer-facing commerce, the human/agent interface now sits inside the AI assistant—not on the brand's own web property. UCP is the infrastructure that determines whether an enterprise's products are discoverable and transactable from that interface. Brand-controlled product pages remain relevant for SEO and loyalty; they become insufficient for agentic discovery. The AAI Brand score sits at 39 with Agent-Ready Infrastructure at 47—both reflect the reality that most enterprise product catalogs are not yet structured for agent-native retrieval. UCP adoption is the concrete action that closes that gap for retail and consumer goods verticals.
WatchStripe Machine Payments Protocol (MPP) + Visa Acceptance Platform integration: The convergence of MPP, Coinbase x402, and Visa's card-based extension is assembling a complete autonomous transaction stack—agent-to-merchant payments without human intervention at any step. No single signal this week fully captures the compounding effect of these three infrastructure layers closing simultaneously. When MPP achieves broad merchant adoption (the current gap), the Identity Control Surface and authorization questions raised by Mastercard Verifiable Intent become urgent for every enterprise with procurement, expense, or B2B payment workflows. Watch for the first major ERP vendor to announce native MPP support—that will be the production inflection signal.