Four of today's six signals point at the same structural gap, from different angles. Read together, they say something the index already hints at: organization readiness sits at 68, Agent-Ready Infrastructure at 55, and the space between those numbers is where the next class of breaches lives.
Start with sequencing. Enterprise deployments now confirm that AI agent identity must precede access control, not follow it (VentureBeat). Teams building gateways on top of unattributed agents are hardening a perimeter around a foundation that was never secured. And authentication, once achieved, settles nothing. The LiteLLM exploit put a gateway bypass and host-level command execution into the wild, on agents that passed the access gate cleanly. Authentication is a point-in-time check on a system that runs continuously. The Decision Surface between human oversight and autonomous action cannot be reduced to a login.
Then the attack surface moves upstream. Researchers ran a full autonomous compromise chain against Fortune 500 targets with no phishing and no user interaction: the agent read an llms.txt file, found an install command, and pulled an attacker-controlled package. This is a Compiled Corporation failure mode. As firms push decision-making into agents, the attack surface migrates into the documentation and context those agents consume, a place conventional application security never looks.
Now scale it. Workday's Sana Enterprise let 12,000 employees build 22,000 custom agents in three weeks (StockStory). Each one is a non-human identity holding permissions inside enterprise systems. Natural-language agent creation compresses the time from conception to deployment to near zero, and it leaves permission auditing and behavioral monitoring to catch up. The Identity Control Surface problem scales linearly with agent count, and the count is now growing faster than any governance function was designed to handle.
The move for principals this week is not another gateway procurement. It is to establish agent identity, attribution, and runtime attestation as prerequisites before agent creation is opened to the workforce. If your platform lets employees spin up agents faster than security can inventory them, you have the Workday problem whether or not you run Workday. Audit your llms.txt and agent-readable vendor docs now, because that supply chain is already being probed. And treat authentication as the start of governance, not the end.
The brand score holds at 42 for a reason: public AI positioning keeps outrunning the internal controls that would make it credible.
Watch this week: whether OpenAI's termination of the Cursor contract after SpaceX's acquisition hardens into documented model-licensing policy. If ownership-based API restrictions become the rule, every enterprise embedding OpenAI models across acquired or acquiring entities inherits contract risk overnight.