Six signals landed on the same day, and they point in one direction: the industry has decided that agent governance is an infrastructure layer, and it is shipping the parts.
Start with the two that define the pattern. Broadcom's AgentMinder treats agents as identities that must declare a mission before they touch a system, with runtime authorization enforced through existing AuthZEN stacks. NVIDIA and CrowdStrike's SafeMind hands core security decision-making, detection through response, to an agent stack. One product governs agent access. The other makes autonomous response production-grade. Read together, they set a timeline: if agents can act with system-write authority in security operations, every enterprise deploying agents with write access now owns that governance question, whether or not it has answered it.
The Azure case study is the one to pin above the desk. An agent passed every evaluation and still served files the requesting user could not open. The fix was identity-aware filtering at the retrieval layer. The lesson is blunt: evaluation suites do not catch permission-boundary failures, and access controls assumed from upstream do not hold at the agent's point of retrieval. If your RAG deployment inherits permissions rather than enforcing them, you have this bug and you do not know it yet.
The index frames why this matters now. Agent-Ready Infrastructure sits at 55 and is rising. Governance and Ethics sits at 80. The gap between those two numbers is the whole story. Organizations know how to govern in principle and are still building the surfaces to govern agents in fact. AgentMinder names the architectural pattern, Azure names the failure mode, and Gilbert + Tobin names the operating model: CEO-level accountability wrapped around firm-wide tool access, so the professional identity the firm sells survives contact with scaled AI.
One procurement item hides in the noise. Anthropic's move to 30-day retention trades a zero-retention posture for cross-session misuse detection. That is Anthropic automating its own trust and safety decisions, and it changes the data-handling terms on every enterprise deployment. Check whether your agreement accounts for it before your security team finds out from the release notes.
The move for principals this week: audit the retrieval layer. Do not ask whether your agents pass evaluations. Ask whether identity-aware filtering is enforced where the agent reads data, and whether every agent has a declared mission and a scoped authorization gate. That is the Broadcom pattern applied to what you already run.
Watch item: the FBI investigation of Nexus, a dark web service claiming scans of 153 million-plus North American driver licenses. If any fraction of that corpus surfaces in fabricated or compromised non-human identities, the Identity Control Surface exposure is direct. Track for law enforcement disclosures and vendor advisories linking the dataset to enterprise credential abuse. Source.
WatchFBI investigation of Nexus, a dark web service claiming digital scans of 153 million-plus North American driver licenses, has not yet produced public findings on how that credential corpus intersects with enterprise identity systems. If even a fraction of those records are used to fabricate or compromise non-human identities in enterprise environments, the Identity Control Surface exposure is significant. Track for law enforcement disclosures and any vendor advisories linking the dataset to enterprise credential abuse. Source.