Two signals today point in opposite directions, and the gap between them is where the risk lives.
On one side, VentureBeat's research finds that enterprises burned by AI agent failures are accelerating human removal from deployment decisions. Trust in automated evaluation jumped from 5% to 13% in a single month, and the organizations doing this are the same ones naming poor test-to-reality alignment as their top concern. Read that again. The firms most aware their tests do not predict production behavior are the ones fastest to remove the humans who catch what the tests miss. Production pressure is setting the review threshold that policy should have set first.
On the other side, the tooling to govern agents as first-class objects is arriving in purchasable form. Netwrix now inventories AI agent identities inside Microsoft Entra ID. xpander is selling a neutral control layer for agent sprawl. The Identity Control Surface has a supply side now.
The argument for principals this morning is that these two movements are not sequenced correctly inside most organizations. The decision surface is being automated before the identity control surface is activated. Agents carry service account-level access without the audit history human accounts accumulate, and enterprises are removing the human gate before the logging, scoping, and inventory that would make removal safe are in place.
The index reflects the same misalignment. Organization sits at 68 and climbing, Product at 62. Brand holds flat at 41. That Brand number is the tell: it measures the distance between what firms say about responsible deployment and what their incident response actually produces. When 85% of burned companies race toward more automation, the Brand score stops being a soft metric. It is the institutional gap made visible.
Deloitte names the underlying condition: most firms layer agents onto existing processes for quick wins without redesigning the human-AI interaction. Removing the human checkpoint from a process that was never redesigned around agents is not maturity. It is agent debt with the safety catch pulled.
The move today is to define, in writing, where human review is mandatory before your next incident forces the answer. Own the decision surface before the agent that fails inside it forces you to explain who authorized what.
Watch this: whether established IAM vendors, CyberArk, Saviynt, One Identity, respond to NCC Group and SailPoint's AI Agent Security line with equivalent agent-specific offerings inside 60 days. If they do, non-human identity governance has become a standard procurement category, and the tooling excuse disappears.
¶
Google Cloud Deploys Context-Creating AI Agents to Automate Forward-Deployed Engineer Tasks
Google Cloud is deploying context-creating AI agents within its tools to automate tasks handled by forward-deployed engineers while simultaneously hiring hundreds of FDEs. OpenAI, Anthropic, Microsoft, and Amazon are following a parallel playbook: investing in human forward-deployment capacity while automating its core functions.
Why it matters
This is the Compiled Corporation dynamic operating at the vendor layer. The FDE role, which exists to translate enterprise context into working AI deployments, is being automated by the same vendors who sell the AI. For enterprise buyers, this creates a compressing window: the consulting layer that bridges model capability and production deployment is being absorbed into the product. Clients who have not yet built internal AI architecture capacity are increasingly dependent on vendors whose agents will soon perform the advisory and implementation work. The AAI Organization score delta (+2) captures organizational momentum, but this signal marks where that momentum concentrates: in vendor-controlled decision surfaces, not enterprise-owned ones.
WatchNCC Group and SailPoint's AI Agent Security service line formalizes a commercial market for non-human identity governance at enterprise scale. Monitor whether established IAM vendors (CyberArk, Saviynt, One Identity) respond with equivalent agent-specific offerings in the next 60 days, which would signal that AI agent identity has become a standard procurement category rather than a specialty add-on.