Six signals this cycle. One argument runs through all of them: enterprises are spending on agent capability while starving the layer that governs what that capability is allowed to do.
Start with the failure data. 88% of enterprise coding agent pilots never reach production (Northflank), and one in four deployed agents runs at negative ROI (ITSM.tools). Neither number is a model problem. Both are governance problems wearing an infrastructure costume — pilots stall at the handoff to production because sandbox isolation, RBAC, audit logging, and code sovereignty were never built, and deployed agents bleed value through unauthorized access, decision opacity, and unintended autonomous actions. The technology works in isolation. It fails at the boundary where authority is supposed to live.
That boundary now has a name. Nuggets Labs shipped a framework structured as a trust stack — Identity → Authority → Intent → Action (Biometric Update) — that formalizes what our Identity Control Surface framework has treated as foundational: traditional IAM verifies who can log in, but says nothing about whether a non-human actor has the authority to execute a specific action. The agentic commerce signal makes the stakes concrete. Delegated authority has replaced per-transaction authentication, and PCI DSS, NACHA, and card network rules contain no definition of autonomous software at all (FinTech Weekly). The blast radius is no longer one charge — it is an entire purchasing stream.
This is why our Governance & Ethics sub-score sitting at 75 is misleading comfort. It moved only +1 this cycle. Awareness is high; execution is inconsistent. Meanwhile Agent-Ready Infrastructure holds at 49 — the lowest tracked dimension — because you cannot buy your way out of it with better models. You close it by building the Authority and Intent layers before first deployment, not after the first incident.
The NVIDIA move sharpens the decision. OpenShell embedded across SAP Joule, ServiceNow, and Red Hat (NVIDIA) means the policy-enforcement layer and the runtime layer now ship from the same vendor. Accept that stack and your Identity Control Surface defaults to NVIDIA's governance assumptions — a Compiled Corporation decision made by procurement, not architecture. The discipline this week: for every agent your firm is piloting, name where Identity, Authority, Intent, and Action are enforced today. If any layer is absent or inherited from a vendor default, that is where your next ROI failure originates.
Watch: Microsoft Research Memora. Persistent agent memory is a research prototype today, but when it lands as a default in Azure AI or Copilot runtimes, agents gain institutional memory — and the authority frameworks you build now must already account for decision-makers that remember.
¶
Agentic Commerce Risk Model Shift: Delegated Authority Replaces Per-Transaction Authentication
Agentic commerce has inverted the fraud assumption. Traditional payment security assumes a human at checkout with credentials to steal. Agentic transactions operate on continuous delegated authority — no per-transaction authentication, no human in the loop. The attack surface shifts from credential theft to orchestration layer compromise, which can corrupt entire purchasing streams rather than individual transactions. Existing payment infrastructure — PCI DSS, card network rules, NACHA — defines roles for merchants, issuers, and acquirers but contains no definition of how autonomous software should be identified, authorized, or controlled. Standards-based protocols (AP2, Mastercard Verifiable Intent) are filling this gap with tamper-resistant, cryptographically signed authorization records.
Why it matters
This is a Decision Surfaces problem operating at commercial infrastructure scale. The decision boundary for a purchasing agent is not a single transaction — it is a mandate with scope, duration, and spending limits. When that mandate is compromised, the blast radius is a stream of transactions, not a single charge. The Identity Control Surface implication is immediate: enterprises deploying procurement or expense agents must define the authorization record format before deployment, not after the first incident. The convergence of AP2, UCP, and MCP signals that protocol consolidation is underway — enterprises that delay governance architecture until standards stabilize will find themselves deploying agents into a framework they did not help shape.
WatchMicrosoft Research Memora — harmonic memory architecture enabling persistent state for long-running agents — is not production infrastructure today, but it defines the capability boundary that separates current stateless agent deployments from continuous autonomous decision-makers. When agents can maintain coherent state across extended task horizons without full context reload, the Compiled Corporation model becomes technically viable at scale. Track Memora's progression from research publication toward integration with Azure AI and GitHub Copilot runtimes. The inflection point will be when persistent agent memory becomes a default infrastructure feature rather than a research prototype — at that moment, the governance frameworks being built today must already account for agents with institutional memory.