The signals this week converge on one uncomfortable fact: agent deployment has outrun agent governance, and the gap is now measurable.
Start with the number. Salesforce reports the average organization now runs 13 deployed agents, nearly triple early-2025 levels, with seven in ten customer-service sessions handled autonomously in participating firms. At five agents, a spreadsheet and a careful team lead can track who has access to what. At thirteen, informal oversight fails silently. Each agent is a non-human identity with tool access, data permissions, and decision authority, and the count is compounding.
The vendors know this, which is why the same week produced two governance blueprints. AWS published a reference architecture for identity-aware authorization at the tool-invocation layer, the exact point where an agent reaches into a production system. OpenAI made workspace identity controls native to ChatGPT Work rather than a configuration afterthought. Both moves relocate the Identity Control Surface from optional to assumed. The question for buyers shifts to whether existing controls are correctly scoped and audited.
Then the reason this matters is made vivid by LoveHolidays, where non-engineering teams now ship product through Codex. When a travel company's marketers are building software, the blast radius of a misconfigured permission stops being an engineering concern and becomes a business one. Those teams need the same audit trails engineering has: what the agent built, on whose authority, with access to what.
And here is the trap. Most governance programs still read risk off vulnerability scanners. Prompt injection has held OWASP's number-one LLM risk for three years running, yet ranks twelfth in actual incident records, because it operates where scanners cannot see. If your LLM risk posture comes from scanner output, you are measuring the wrong surface. Detection lives in behavioral monitoring at the agent interface, a capability most organizations have not built.
The through-line: the organization index sits at 68, ahead of most enterprises' actual readiness, precisely because vendor-published control planes are running faster than internal adoption. The homework this week is unglamorous. Inventory your agents. Map each one to an identity, a permission scope, and an audit trail. Validate that inventory against the AWS pattern. The firms that do this before agent count fourteen will govern; the rest will discover their control plane the hard way.
Watch this: whether local agentic inference reaches production-grade reliability. Perplexity's Portable Computer model on NVIDIA DGX Spark carries zero token costs, and if it holds up in early enterprise deployments over the next 60 days, the cloud-hosted agent economics behind most current vendor contracts move under board-level scrutiny.
WatchPerplexity Portable Computer's local agentic inference model, running on NVIDIA DGX Spark with zero token costs, warrants tracking as enterprise cost structures for high-volume agent workloads come under board-level scrutiny. If local inference reaches production-grade reliability, the cloud-hosted agent economics that underpin most current vendor contracts shift materially. Monitor adoption signals from early enterprise deployments over the next 60 days.