Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

The credential surface is growing faster than anyone is governing it

Two numbers from today's signals belong in the same sentence. Enterprises now carry 45 non-human identities per human employee, and 78% of organizations have no policy governing them (iEnable). Agentic transaction volume grew 1,300% in the first eight months of 2026 (Nevermined). One number describes a governance gap. The other describes the speed at which that gap is filling with live, authorized activity.

This is the Identity Control Surface problem, and it is no longer theoretical. Every agent an enterprise deploys spawns at least one non-human identity: a service account, an API key, an automation token. Most firms are adding to a pile they already cannot see. The market is now building infrastructure that assumes those identities are governed, when the data says they are not. Google's Agent Payments Protocol, backed by Mastercard, PayPal, American Express, Adobe, and Alibaba (Charle), answers exactly the question 78% of enterprises cannot answer for themselves: which agent, on whose authority, committed this transaction. The protocol is ready. The credential governance underneath it is not.

That inversion is the argument this week. The index reflects it directly. Organization sits at 66 and Governance & Ethics ticked to 78, the strongest dimension in the book. Brand sits at 41 and did not move. The gap between them is the gap between what enterprises say about readiness and what their credential estate actually supports. A high governance-policy score means nothing if the policies stop at human identities while 45 non-human ones per employee operate outside them.

So the near-term move is narrow and unglamorous. Before the next agent rollout, inventory the non-human identities you already carry and assign each one an owner and an authority scope. This is the precondition for engaging any agent payment standard on your own terms. AP2 and its peers give you the audit trail; they do not give you the governance model that decides which agent should have held the credential in the first place. OpenAI's Daybreak arriving inside Bedrock (OpenAI) makes the same point from the security side: the tooling lands inside your IAM, and the policy for what triggers automated response versus human escalation has to exist before deployment.

Enterprises that treat identity governance as a follow-on to agent deployment will retrofit controls into live transaction flows, which is the most expensive place to install them.

Watch this: Universal Commerce Protocol adoption cadence. Shopify's UCP integration and Visa's Intelligent Commerce Connect are converging toward a de facto standard layer. If a major ERP or procurement platform adopts UCP or AP2 in the next 60 days, the standard-setting window closes, and firms without a protocol position will integrate to a fait accompli rather than shape their own terms.

Index Reference · Applied AI Index 2026-W32
Overall
56
Organization
66
— 0
Brand
41
— 0
Product
61
▲ +1
Movers · Workforce AI Access (+1) · Governance & Ethics (+1) · Talent & Upskilling (+1)
Signals

Enterprise AI governance gap: 45 non-human identities per human employee, 78% unmanaged

Research from iEnable found that enterprises carry 45 non-human identities, service accounts, API keys, automation tokens, and AI agents, for every human identity. 78% of organizations have no identity policies governing those non-human identities, leaving the majority of an enterprise's active credential surface ungoverned.

Why it matters

This is the Identity Control Surface problem stated in numbers. As agent deployment accelerates, each new agent spawns at least one non-human identity, and most enterprises are adding to a pile they already cannot see. The governance gap is structural: the tooling conversation has outpaced the credential management conversation by years. For Applied Identities clients, this data point anchors the business case for NHI governance before agent rollouts scale further. The 78% figure is the opening of every board-level conversation on AI readiness.

Source: iEnable

Google Agent Payments Protocol (AP2) cryptographically secures agentic transactions

Google's Agent Payments Protocol uses cryptographically signed intent mandates linking intent, cart, and payment across users, merchants, and payment networks. Mastercard, PayPal, American Express, Adobe, and Alibaba back AP2 as a secure open standard for agent transactions with full audit trails.

Why it matters

AP2 moves agentic commerce from a trust-on-honor model to a cryptographically verifiable one. The signed mandate chain, intent to cart to payment, creates an audit trail that answers the core Identity Control Surface question: which agent, acting on whose authority, committed this transaction? For enterprises evaluating agent-mediated procurement or commerce, AP2's coalition of payment networks signals that this standard will reach critical mass. Organizations that wait to engage with agent payment protocols will find themselves retrofitting governance into live transaction flows.

Source: Charle

OpenAI Daybreak cybersecurity models now available on AWS

OpenAI and AWS made Daybreak cybersecurity AI capabilities available through Amazon Bedrock, extending AI-assisted security workflows across cloud infrastructure for enterprise security teams.

Why it matters

Security tooling delivered through Bedrock means enterprise buyers get Daybreak inside their existing IAM and VPC controls, which is the right distribution channel for a security product. The Decision Surface implication is meaningful: Daybreak puts AI judgment inside threat detection and response workflows, shifting where human review enters the loop. Enterprises need a clear policy on which Daybreak-generated findings trigger automated response versus human escalation before they deploy, not after.

Source: OpenAI News

NVIDIA Nemotron 3.5 Lightning optimizes agentic AI efficiency

NVIDIA released Nemotron 3.5 Lightning, described as the highest-efficiency open model for long-running agentic workloads, alongside NeMo Switchyard for faster agent deployment across edge and data center environments.

Why it matters

Long-running agentic workloads are the operational reality of the Compiled Corporation: agents that execute multi-step processes over extended sessions, not single-turn queries. Efficiency at that workload profile directly affects the economics of agent deployment. Nemotron 3.5 Lightning being open also matters for enterprises that cannot route sensitive workflows through third-party API endpoints. The NeMo Switchyard routing layer adds a Decision Surface management dimension worth evaluating in any agentic architecture review.

Source: NVIDIA Blog

OpenAI begins testing advertisements in ChatGPT

OpenAI started testing ads in ChatGPT with clear labeling, answer-independence guarantees, privacy protections, and user control mechanisms, framed as support infrastructure for the free tier.

Why it matters

The Janus Brand tension here is acute. OpenAI built its enterprise positioning on trust and answer integrity. Introducing a commercial layer inside the answer surface, even with independence guarantees, creates a verification problem: enterprise buyers cannot audit whether the independence guarantee holds at inference time. For organizations that have embedded ChatGPT in customer-facing or employee-facing workflows, the ad model shifts the underlying incentive structure of the platform they depend on. This warrants explicit review of ChatGPT's role in any workflow where answer integrity is load-bearing.

Source: OpenAI News

Agentic transaction volume grew 1,300% in first eight months of 2026

Agentic commerce traffic grew over 1,300% in the first eight months of 2026, reflecting accelerating adoption of agent-mediated commerce across platforms and protocols.

Why it matters

1,300% growth in eight months is a governance timeline problem. Every transaction in that volume represents an agent acting on a user's behalf, and the identity and authorization infrastructure for those agents is, per the iEnable data above, largely absent. Enterprises in retail, procurement, or any commerce-adjacent vertical are already operating inside this growth curve whether they have a formal agentic commerce strategy or not. The question is whether their non-human identity controls were built before or after the volume arrived.

Source: Nevermined
Watch

Universal Commerce Protocol adoption cadence. Shopify's UCP integration via Agentic Storefronts and Visa's Intelligent Commerce Connect supporting four agent protocols including ACP are converging toward a de facto standard layer for agent-mediated transactions. If a major ERP or procurement platform adopts UCP or AP2 in the next 60 days, the standard-setting window closes and enterprises without a protocol position will be integrating to a fait accompli rather than shaping their own terms.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 70 · tavily: 15 · tavily_queries: agentic commerce checkout agent transaction launch 2026,AI agent payments settlement protocol enterprise 2026,non-human identity AI agent governance enterprise 2026 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com