Two of today's signals should be read together, because between them they close the argument enterprises have been using to defer agentic deployment. Berkeley BAIR documents a 50x annual inference cost decline, with both frontier and open-source models reaching sub-$0.10 per million tokens. OpenAI's Ultrafast tier delivers 750 tokens per second through a Cerebras partnership, removing latency as the ceiling on synchronous decision surfaces. Cost was one objection. Latency was the other. Both are now gone for most enterprise use cases.
What remains is governance, and the index confirms where the weakness sits. The AAI Brand dimension holds at 41, the lowest score in the index, while Organization leads at 66. That gap is the story. Firms have built the org readiness to deploy agents. They have not built the trust surface that governs what those agents do in the firm's name.
The market has now named this gap and priced it. Dark Reading's survey puts agentic AI as the number one attack vector for 2026, cited by 48 percent of security professionals, outranking deepfakes. CrowdStrike launched continuous identity for AI agents, which turns the Identity Control Surface from an architectural concern into a procurement line item. Imprivata's Fran Rosch states the structural problem plainly: each agent is a non-human identity, and identity systems built for human principals at human scale cannot audit machine-scale deployments.
Here is the practical implication for anyone running an AI readiness assessment. When inference cost approaches zero, the constraint on deployment is governance maturity, and the firms that build governed agent infrastructure now set the integration baseline later entrants must match. Microsoft's framework already embeds an approval_mode checkpoint on every function tool, which means enterprises building on that stack inherit a human-in-the-loop control by default. That raises the floor across the installed base, and it also decides who owns the identity control surface.
That ownership question is where the board conversation moves next. When identity governance becomes a named product category, the decision surface shifts from CISO to CFO, because someone has to answer whether existing IAM contracts cover non-human principals. Most do not.
The move this week: audit your agent inventory against a single question. For every deployed or planned agent, can you name its identity, its credential lifetime, and the human who approves its high-consequence actions? If any of those three is blank, you are accumulating unaudited attack surface at machine scale.
Watch: Microsoft Agent Framework v1.0, which consolidates Semantic Kernel and AutoGen into one orchestration platform, with AutoGen now in maintenance mode. Confirm whether your current framework selection is supported through 2027 or absorbed, because that answer decides who owns your identity control surface.
WatchMicrosoft Agent Framework v1.0 consolidates Semantic Kernel and AutoGen into a single production orchestration platform with graph workflows, A2A protocol, MCP support, and human-in-the-loop checkpoints. The consolidation is accelerating: AutoGen (54,600+ GitHub stars) is now in maintenance mode. Enterprises evaluating orchestration infrastructure should assess whether their current framework selection will be supported through 2027 or absorbed into a larger vendor platform, as the pattern of consolidation around Microsoft's stack has direct implications for vendor lock-in and identity control surface ownership.