The numbers in today's Economist Enterprise research settle an argument that enterprise AI leaders have been having with themselves for two years: 98% of large organizations have experienced agent-related incidents, and 90% are deploying agents faster than security can govern them. This is not a forecast. It is a live operational condition. The readiness gap was never about whether agents could do the work — it was about whether anyone could prove what they did, revoke their access, or attribute their actions. That gap is now an incident backlog.
What sharpens the picture is that the rest of today's signals are not warnings about this problem — they are the market pricing it in. KPMG embedded its Trusted AI framework directly into the Agent 365 runtime rather than bolting governance on as a parallel layer. Google reframed the Gemini Enterprise Agent Platform as a governance-at-the-platform-layer claim, naming ungoverned multi-system agents as the failure state it resolves. The platform race and the governance race are now the same race. Vendors have read the same data principals are reading this morning, and they are competing on control surface coverage, not capability.
This is where our index context matters. Organization sits at 63 and Governance & Ethics ticked up to 74 — the maturity signal is real but uneven, and it is dragging a Brand pillar stuck at 39. That spread is the danger zone. MIT Technology Review's rejection of the 'coworker' framing is not a semantics quibble; it is a Janus Brands alert with timing. Organizations that built adoption narratives around 'digital teammates' while their governance posture sits in the 98%-incident cohort are carrying a brand-reality mismatch that regulators and employees can now see named in print. The aspirational story and the operational truth have to be the same story.
The deeper move is structural. Microsoft's Memora solves stateful agent memory, which means agents are about to graduate from single-session tasks to multi-day, multi-step workflows. The moment agents become stateful, your Decision Surface shifts — humans stop reviewing interactions and start reviewing outcomes of extended autonomous chains. If you have not relocated your oversight checkpoints before you deploy stateful agents, you are governing the wrong layer.
The action is not to slow deployment — the data shows nobody will. It is to make your Identity Control Surface a procurement criterion, not a remediation project. Ask every agent vendor where attribution, revocation, and audit live, and refuse the ones who answer at the application layer.
Watch: Track the FIDO Alliance's progression of Agent Payments Protocol (AP2) v0.2 toward ratification. If its Human-Not-Present framework gains payment-network adoption alongside Mastercard's Verifiable Intent, the identity control surface for agentic commerce will be defined by cryptographic delegation standards — and anyone building procurement or fulfillment agents needs a declared position on AP2 before the standard hardens.
¶
Agentic commerce protocols consolidate into four competing open standards — UCP, AP2, MPP, Verifiable Intent
Four protocol stacks are now established for autonomous agent-mediated commerce: Universal Commerce Protocol (UCP) (3,107 GitHub stars, multimerchant cart and checkout, integrated across Google Search, Gemini, YouTube, and Gmail); Agent Payments Protocol (AP2) (donated to FIDO Alliance, v0.2 with Human-Not-Present transaction support); Machine Payments Protocol (MPP) (Stripe and Tempo, direct settlement at request time); Verifiable Intent (Mastercard and Google, cryptographic authorization via Selective Disclosure). Gap Inc. has deployed native Gemini checkout against UCP.
Why it matters
The Identity Control Surface question for agentic commerce is now a protocol selection decision. AP2's Human-Not-Present framework and Mastercard's Verifiable Intent both address the same problem from different angles: how do you establish cryptographic proof that an authorized identity — human or agent — initiated a transaction? The protocol layer that wins here will define where non-human identity governance sits in commercial workflows for the next decade. Organizations building agent-mediated purchasing, procurement, or fulfillment workflows cannot defer this decision — Gap's live deployment against UCP signals that early movers are already locking in protocol dependencies. The Compiled Corporation model requires a settled answer to the question of which identity claims an agent can make on behalf of a human principal.
WatchTrack the FIDO Alliance's progression of Agent Payments Protocol (AP2) v0.2 toward ratification. The Human-Not-Present transaction framework is the first serious attempt to establish a standards-body-backed identity claim architecture for non-human principals in commercial workflows. If AP2 gains enterprise payment network adoption alongside Mastercard's Verifiable Intent, the Identity Control Surface for agentic commerce will be defined by cryptographic delegation standards — not platform-level controls. Organizations building procurement, fulfillment, or financial agent workflows need a declared position on AP2 before the standard hardens.