Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

The Gap Was Never the Model. It Was the Authority Layer.

Six signals this cycle. One argument runs through all of them: enterprises are spending on agent capability while starving the layer that governs what that capability is allowed to do.

Start with the failure data. 88% of enterprise coding agent pilots never reach production (Northflank), and one in four deployed agents runs at negative ROI (ITSM.tools). Neither number is a model problem. Both are governance problems wearing an infrastructure costume — pilots stall at the handoff to production because sandbox isolation, RBAC, audit logging, and code sovereignty were never built, and deployed agents bleed value through unauthorized access, decision opacity, and unintended autonomous actions. The technology works in isolation. It fails at the boundary where authority is supposed to live.

That boundary now has a name. Nuggets Labs shipped a framework structured as a trust stack — Identity → Authority → Intent → Action (Biometric Update) — that formalizes what our Identity Control Surface framework has treated as foundational: traditional IAM verifies who can log in, but says nothing about whether a non-human actor has the authority to execute a specific action. The agentic commerce signal makes the stakes concrete. Delegated authority has replaced per-transaction authentication, and PCI DSS, NACHA, and card network rules contain no definition of autonomous software at all (FinTech Weekly). The blast radius is no longer one charge — it is an entire purchasing stream.

This is why our Governance & Ethics sub-score sitting at 75 is misleading comfort. It moved only +1 this cycle. Awareness is high; execution is inconsistent. Meanwhile Agent-Ready Infrastructure holds at 49 — the lowest tracked dimension — because you cannot buy your way out of it with better models. You close it by building the Authority and Intent layers before first deployment, not after the first incident.

The NVIDIA move sharpens the decision. OpenShell embedded across SAP Joule, ServiceNow, and Red Hat (NVIDIA) means the policy-enforcement layer and the runtime layer now ship from the same vendor. Accept that stack and your Identity Control Surface defaults to NVIDIA's governance assumptions — a Compiled Corporation decision made by procurement, not architecture. The discipline this week: for every agent your firm is piloting, name where Identity, Authority, Intent, and Action are enforced today. If any layer is absent or inherited from a vendor default, that is where your next ROI failure originates.

Watch: Microsoft Research Memora. Persistent agent memory is a research prototype today, but when it lands as a default in Azure AI or Copilot runtimes, agents gain institutional memory — and the authority frameworks you build now must already account for decision-makers that remember.

Index Reference · Applied AI Index 2026-W27
Overall
53.7
Organization
64
▲ +1
Brand
40
▲ +1
Product
57
— 0
Movers · Scaling Maturity (+1) · Governance & Ethics (+1) · Agent-Ready Infrastructure (+1)
Signals

Enterprise AI Coding Agent Deployment Infrastructure Gap

88% of enterprise AI coding agent pilots never reach production—the blocker is not the agent itself but the infrastructure surrounding it. Northflank identifies the mandatory stack: MicroVM sandbox isolation, BYOC across AWS/GCP/Azure/on-premises, RBAC, audit logging, SSO, and GPU workload support. Before any agent touches a production system, enterprises must establish data residency controls and code sovereignty. The pattern is consistent: pilots succeed in isolation, then stall at the handoff to production engineering.

Why it matters

This is a Decision Surfaces signal in its most concrete form. The human/agent interface is failing not at the model layer but at the infrastructure boundary. With the AAI Agent-Ready Infrastructure sub-score sitting at 49 — the lowest-scoring tracked dimension — this data point is a direct structural explanation. Enterprises cannot improve that score by purchasing better models. They close the gap by building the governance and isolation layers Northflank describes. Applied Identities clients should audit whether their pilot-to-production pipeline has explicit controls for each of these six requirements before committing further agent spend.

Source: Northflank

AI Agent ROI Failure: 25% of Enterprise Deployments Unprofitable

One in four enterprise AI agent deployments is not generating positive ROI, per KTSL/BMC Helix research. The failure mode is not technology — it is governance: unauthorized access, decision opacity, compliance violations, and unintended autonomous actions dominate the incident log. The counterweight: 71% of UK enterprises report ROI from learning agents — those that adapt behavior over time — suggesting the value is real but conditional on organizational readiness. Enterprises deploying agents without early-stage access controls, behavior audit trails, and governance frameworks are accumulating long-tail compliance exposure that does not show up in initial deployment metrics.

Why it matters

The AAI Governance & Ethics sub-score leads the index at 75 but only moved +1 this cycle — meaning enterprise awareness of governance is high while execution remains inconsistent. This signal explains the gap. The 25% failure rate maps directly to organizations that treat governance as a post-deployment compliance task rather than a pre-deployment design requirement. Under the Identity Control Surface framework, agents initiating autonomous actions must have defined operating boundaries before first deployment. Learning agents that adapt behavior over time introduce additional surface area: their authority scope must be versioned and audited as behavior changes.

Source: ITSM.tools

Nuggets Enterprise AI Governance Framework: Action Governance as New Control Layer

Nuggets Labs released a vendor-neutral Enterprise AI Governance Framework targeting the gap between traditional IAM and autonomous agent operations. The framework introduces Action Governance — a control layer positioned between access and execution — structured as a trust stack: Identity → Authority → Intent → Action. Traditional IAM verifies who can log in; this framework verifies whether an AI actor has the authority to execute a specific action, whether that action matches declared intent, and whether a tamper-resistant audit record exists. Targeted at CISOs, CIOs, and Chief Risk Officers. Framework is risk-classified across governance domains.

Why it matters

This is the most directly applicable Identity Control Surface artifact to emerge this cycle. Standard IAM systems were designed for human actors authenticating to systems — they have no native concept of an AI agent delegating authority across a transaction stream or modifying infrastructure autonomously. The Nuggets trust stack operationalizes a concept Applied Identities has treated as foundational: non-human identity governance requires its own control plane. Enterprises evaluating this framework should map it against their current IAM architecture and identify where the Authority and Intent layers are absent. The absence of those layers is where the ROI failures documented in the KTSL/BMC research originate.

Agentic Commerce Risk Model Shift: Delegated Authority Replaces Per-Transaction Authentication

Agentic commerce has inverted the fraud assumption. Traditional payment security assumes a human at checkout with credentials to steal. Agentic transactions operate on continuous delegated authority — no per-transaction authentication, no human in the loop. The attack surface shifts from credential theft to orchestration layer compromise, which can corrupt entire purchasing streams rather than individual transactions. Existing payment infrastructure — PCI DSS, card network rules, NACHA — defines roles for merchants, issuers, and acquirers but contains no definition of how autonomous software should be identified, authorized, or controlled. Standards-based protocols (AP2, Mastercard Verifiable Intent) are filling this gap with tamper-resistant, cryptographically signed authorization records.

Why it matters

This is a Decision Surfaces problem operating at commercial infrastructure scale. The decision boundary for a purchasing agent is not a single transaction — it is a mandate with scope, duration, and spending limits. When that mandate is compromised, the blast radius is a stream of transactions, not a single charge. The Identity Control Surface implication is immediate: enterprises deploying procurement or expense agents must define the authorization record format before deployment, not after the first incident. The convergence of AP2, UCP, and MCP signals that protocol consolidation is underway — enterprises that delay governance architecture until standards stabilize will find themselves deploying agents into a framework they did not help shape.

NVIDIA Enterprise Agent Stack: SAP, ServiceNow, Red Hat, Foxconn Deploy OpenShell

NVIDIA announced coordinated enterprise agent deployments across SAP, ServiceNow, Red Hat, and Foxconn. SAP embeds OpenShell into Joule Studio as the enterprise agent runtime. ServiceNow deploys Project Arc with OpenShell policy-based management. Red Hat integrates OpenShell into its AI platform at the infrastructure oversight layer. Foxconn pilots NemoClaw for clinical reasoning agents (Nurabot, CoDoctor) handling documentation and care coordination, and MoMClaw for factory operations with live sensor data integration.

Why it matters

This is a Compiled Corporation signal at enterprise stack depth. NVIDIA is not selling chips into these deployments — it is positioning OpenShell as the policy-based management layer for agent runtime across four distinct verticals. When the runtime layer and the policy enforcement layer come from the same vendor, the Identity Control Surface defaults to that vendor's governance model. Enterprises accepting this stack inherit NVIDIA's assumptions about how agent identity, authority, and action are controlled. That is a consequential architectural decision. Applied Identities clients evaluating SAP Joule, ServiceNow, or Red Hat AI should explicitly audit whether OpenShell's policy model maps to their internal governance requirements — or whether it substitutes for governance design they have not yet done.

AI Identity Governance as Primary Security Perimeter

Identity-centric security is becoming the primary enterprise security perimeter as network boundaries dissolve. AI identity governance now functions as the control plane integrating DLP, CASB, endpoint security, and browser security into a unified policy layer. Organizations that treat identity governance as a standalone compliance function — rather than the architectural center of their security posture — are exposed to identity-based attacks, which now represent the majority of enterprise breach vectors. Unified access policies must be driven by identity context, not network location.

Why it matters

This signal connects directly to the AAI Agent-Ready Infrastructure sub-score gap (+1 delta, score 49) and the broader Identity Control Surface framework. The shift from network-perimeter to identity-perimeter security is well-documented; what is new is the assertion that AI identity governance — governing non-human actors alongside human ones — is now the integration point for the entire security stack. Enterprises that have invested in IAM for human workforce access but have not extended that architecture to AI agents have a structural gap that grows with every agent deployment. This is not a future risk — the Nuggets framework, the agentic commerce authorization gap, and the coding agent production failure rate all point to the same root cause.

Watch

Microsoft Research Memora — harmonic memory architecture enabling persistent state for long-running agents — is not production infrastructure today, but it defines the capability boundary that separates current stateless agent deployments from continuous autonomous decision-makers. When agents can maintain coherent state across extended task horizons without full context reload, the Compiled Corporation model becomes technically viable at scale. Track Memora's progression from research publication toward integration with Azure AI and GitHub Copilot runtimes. The inflection point will be when persistent agent memory becomes a default infrastructure feature rather than a research prototype — at that moment, the governance frameworks being built today must already account for agents with institutional memory.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 50 · tavily: 15 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com