Read today's signals in sequence and one story emerges: the agentic production stack is now complete, and the identity governance layer underneath it is not.
Google shipped remote MCP support and background tasks into the Gemini API (Google Blog), then opened an Agent Gallery letting Adobe, Salesforce, ServiceNow, and Workday agents compose into shared workflows (IT Pro). Oracle brought OCI Enterprise AI to GA with OpenAI API compatibility (Oracle Blogs). NVIDIA positioned open-weight Nemotron models as the sovereign-control default (NVIDIA Blog). Four vendors, four routes to production agents in a single week.
Here is the seam. Every one of these launches lands on the Decision Surface — the handoff from human oversight to autonomous execution — and every one of them defers the same question: which agent, running under whose credential, with what scope, auditable by whom? Google's Agent Gallery simplifies deployment but does not federate identity across four vendors' credential models. That gap doesn't disappear. It lands on your architects as governance debt.
The index says the same thing more quietly. Governance & Ethics sits at 76 and Workforce AI Access at 65, both nudging up a point — but overall readiness holds at 54, and brand stays flat at 40. Translation: organizations are getting more comfortable granting AI access faster than they are building the identity control surface to govern it. The capability curve is outrunning the credential curve.
OpenAI clarified the stakes on both ends. GPT-Red hardens models against prompt injection — the primary vector for hijacking agent identity (OpenAI) — but model-layer safety is not a substitute for your own scoped credentials and audit trails. And its 'reverse federalism' policy stance (OpenAI) confirms no unified federal standard is coming. Assume multi-jurisdictional compliance as a permanent condition for any agent that crosses state lines.
What to do before you enable any of this week's capabilities: treat non-human identity governance as a prerequisite, not a follow-up. Establish an agent registry, scoped credentials, and cross-vendor federation before the first third-party agent enters your orchestration layer. The vendors have made deployment trivial. They have not made it safe. That work is yours, and it is a control surface, not a checkbox.
Watch item: NVIDIA's Jetson Thor launch pushes foundation-model inference onto commodity edge hardware — moving the identity control surface out of the network-governed data center and into physical environments with no enforced credential layer. Watch for the first enterprise incident involving a compromised edge-agent credential. It will convert hardware-rooted identity from a research topic into a procurement line item overnight.
WatchNVIDIA's Jetson Thor T3000/T2000 launch targets mass-market robotics and edge AI with foundation models running on-device. As edge inference becomes commodity hardware, the Identity Control Surface for physical agents — robots, autonomous edge systems — moves out of the data center and into environments with no network-enforced identity governance. Watch for the first enterprise incident involving a compromised edge agent credential; it will accelerate demand for hardware-rooted identity frameworks purpose-built for non-cloud deployment contexts.