Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

Governance Stopped Being a Document This Week

For three years, enterprise AI governance lived in PDFs—policy frameworks, ethics charters, board attestations. This week it moved into the execution layer, and that relocation is the only story that matters.

Microsoft Agent 365 reached general availability (Microsoft Security Blog), embedding identity verification, scoped permissions, and audit trails directly into the agent runtime. This is the Identity Control Surface made product: non-human identity treated as a first-class operational concern, not bolted onto legacy IAM. Days later, KPMG committed to deploying it across 276,000 staff (Enterprise DNA) under its Trusted AI framing—a textbook Janus Brands move, aligning agent deployment with the firm's legacy authority as a governance and audit house. That is what production autonomy at population scale looks like, and it is why the AAI Organization dimension sits at 63 and rising.

The gap that holds the Brand dimension at 39—with AI-Native Messaging at 42—is precisely this: most enterprises can say that their agents are governed but cannot describe how. They have no auditable artifact. Agent 365, ServiceNow and Accenture's 300+ pre-built agent skills bundled with AI Control Tower, and Mastercard's Verifiable Intent (agenticplug.ai) each supply that missing artifact at a different layer. Verifiable Intent is the sharpest of the three: it pushes authorization records below the policy layer into tamper-resistant cryptography. The Governance & Ethics dimension leads our index at 73, but that score reflects policy adoption, not cryptographic enforcement. Those are not the same thing, and the distance between them is where your audit exposure now accumulates.

Here is the argument: the strategic question has decisively shifted from build or buy at the model layer to configure or customize at the agent workflow layer. If your team is still assembling a homegrown RAG stack while KPMG encodes firm-level decision workflows into managed agent infrastructure, you are spending engineering cycles on a problem the market just commoditized. Map your roadmap against those 300+ skills before you commit another sprint. And map your authorization model against Verifiable Intent before procurement, expense, or B2B payment agents go live—because the Compiled Corporation thesis is no longer theoretical. Decision-making is being encoded into runtime, with or without your governance keeping pace.

One caution: the EU's DMA designation of Azure and AWS means what is conveniently bundled in 2026 may be unbundled by 2027. Build with that optionality in mind.

Watch this: The first major ERP vendor to announce native Stripe Machine Payments Protocol support. That announcement—not any agent demo—is the production inflection signal for autonomous transactions, and it makes Verifiable Intent's authorization questions urgent for every firm with a procurement workflow.

Index Reference · Applied AI Index 2026-W25
Overall
52.7
Organization
63
▲ +1
Brand
39
▲ +1
Product
56
▲ +1
Movers · Governance & Ethics (+1) · AI-Native Messaging (+1) · Agent-Ready Infrastructure (+1)
Signals

Microsoft Agent 365 GA: Enterprise AI agents now carry identity and governance controls

Microsoft Agent 365 reached general availability on May 1, 2026, embedding identity verification, access controls, audit trails, and real-time monitoring directly into the agent runtime. Organizations assign roles, permissions, and compliance metadata to AI entities as digital employees—moving agent governance from policy documents to execution layer enforcement. This is the first major platform GA that treats non-human identity as a first-class operational concern rather than an afterthought bolted onto existing IAM frameworks.

Why it matters

This is the Identity Control Surface made product. The AAI Brand dimension scores only 39 overall, with AI-Native Messaging at 42—partly because most enterprises cannot yet describe how their agents are governed, only that they are. Agent 365 GA gives organizations a concrete governance artifact: auditable agent identity records, scoped permissions, and compliance metadata. Enterprises that deploy this close a specific gap between governance intent and execution reality. Those that don't now have a named benchmark to explain away to auditors and boards.

KPMG deploys Agent 365 across 276,000 staff; signals shift from AI pilots to production autonomy

KPMG announced June 9, 2026 that it will roll out Microsoft Agent 365 across its entire global workforce of 276,000+ professionals alongside Microsoft 365 Copilot. The deployment is explicitly framed around KPMG's Trusted AI framework—governance-first sequencing, not capability-first autopilot. This is the market's first documented enterprise-scale agent deployment at professional services firm size, moving agentic AI from isolated proof-of-concept to operational production headcount.

Why it matters

The Compiled Corporation lens applies directly: KPMG is encoding firm-level decision workflows into agent infrastructure at full population scale. The "Trusted AI" framing is also a Janus Brands signal—KPMG is explicitly aligning its AI deployment narrative with its legacy brand position as a governance and audit authority. Competitors in professional services now face a specific reference point. The AAI Organization dimension sits at 63 and rising; deployments at this scale are what moves that number. Enterprises in adjacent sectors should benchmark their own pilot-to-production conversion timelines against this deployment.

ServiceNow + Accenture FDE program: 300+ pre-built agent skills enter enterprise standardization

ServiceNow and Accenture launched a forward-deployed engineering program (announced at Knowledge 2026, May 6, 2026) offering enterprises access to 300+ pre-built AI agent skills and workflows on the ServiceNow AI Platform. The offering bundles standardized agent patterns with Accenture's industry consulting depth and ServiceNow's AI Control Tower—a governance layer designed to manage agents at operational scale. Packaged skill libraries, not custom builds, are the delivery vehicle.

Why it matters

This is Compiled Corporation infrastructure delivered as a managed service: the firm outsources decision-making to pre-configured agent templates rather than building bespoke. The bundling of AI Control Tower governance with commercial agent skills is a direct answer to the identity and oversight gap that holds the AAI Brand dimension at 39. For enterprise buyers, the strategic question is no longer "build or buy" at the model layer—it is "configure or customize" at the agent workflow layer. Organizations still assembling homegrown RAG stacks should map these 300+ skills against their own roadmaps before committing additional engineering cycles.

Mastercard Verifiable Intent: Cryptographic framework for tamper-resistant agent transaction authorization

Mastercard and Google (March 2026) introduced Verifiable Intent—an open, standards-based cryptographic framework that creates tamper-resistant authorization records for AI agent transactions using Selective Disclosure. Designed to interoperate with AP2 and ACP protocols. The framework establishes non-repudiation and audit trails at the cryptographic layer for agent-initiated commerce, not at the application layer where they can be bypassed or spoofed.

Why it matters

Verifiable Intent is the Identity Control Surface extended into commerce: it answers who authorized this transaction and under what conditions for any agent acting on a user's behalf. The AAI Governance & Ethics dimension leads at 73, but that score reflects policy adoption—not cryptographic enforcement. Mastercard's framework moves authorization records below the policy layer into tamper-resistant infrastructure. Any enterprise building agent-mediated purchasing, procurement, or financial workflows needs to map its authorization model against what Verifiable Intent establishes as the emerging standard. Compliance exposure accumulates for those who don't.

Google UCP expands to cart, catalog, identity linking; retail consortia coalesces around open standard

Google's Universal Commerce Protocol (UCP), launched January 2026 and expanded May 2026, now covers cart, catalog, and identity linking, with lodging and food verticals in active expansion. The protocol has accumulated 3,107 GitHub Stars and is co-developed by Shopify, Etsy, Wayfair, Target, and Walmart. UCP is the dominant retail-side protocol for agent commerce; Stripe's ACP governs the payment side. Two complementary open standards are consolidating the agentic commerce stack.

Why it matters

The Decision Surface is migrating: for consumer-facing commerce, the human/agent interface now sits inside the AI assistant—not on the brand's own web property. UCP is the infrastructure that determines whether an enterprise's products are discoverable and transactable from that interface. Brand-controlled product pages remain relevant for SEO and loyalty; they become insufficient for agentic discovery. The AAI Brand score sits at 39 with Agent-Ready Infrastructure at 47—both reflect the reality that most enterprise product catalogs are not yet structured for agent-native retrieval. UCP adoption is the concrete action that closes that gap for retail and consumer goods verticals.

Azure, AWS face DMA oversight; EU targets cloud duopoly for stricter gatekeeping rules

The EU designated Microsoft Azure and Amazon AWS as the largest and second-largest cloud services in the European Union and announced preliminary findings to subject both to Digital Markets Act (DMA) gatekeeping obligations. The designation opens both platforms to interoperability mandates, data portability requirements, and restrictions on bundling practices. Regulatory proceedings are preliminary; enforcement timelines remain uncertain.

Why it matters

The Decision Surface and Identity Control Surface implications are significant: if DMA obligations force interoperability on agent platforms, governance runtimes, and identity systems—currently tightly bundled inside Azure and AWS—enterprises may gain optionality they do not currently have. For organizations building agent infrastructure on either platform today, DMA proceedings create architectural risk: what is bundled and convenient in 2026 may be unbundled under regulatory mandate by 2027–2028. The AAI Governance & Ethics dimension at 73 reflects strong policy intent; regulatory fragmentation of cloud infrastructure tests whether that intent survives platform dependencies. Enterprises with significant EU operations should begin mapping DMA exposure in their agent deployment architecture now.

Watch

Stripe Machine Payments Protocol (MPP) + Visa Acceptance Platform integration: The convergence of MPP, Coinbase x402, and Visa's card-based extension is assembling a complete autonomous transaction stack—agent-to-merchant payments without human intervention at any step. No single signal this week fully captures the compounding effect of these three infrastructure layers closing simultaneously. When MPP achieves broad merchant adoption (the current gap), the Identity Control Surface and authorization questions raised by Mastercard Verifiable Intent become urgent for every enterprise with procurement, expense, or B2B payment workflows. Watch for the first major ERP vendor to announce native MPP support—that will be the production inflection signal.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 50 · tavily: 15 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com