Six signals this morning, and they resolve into one argument: agent identity governance has moved from a security afterthought to the load-bearing wall of enterprise AI. Read the week from the top and the sequence is deliberate.
Start with the threat. Microsoft disrupted EvilTokens, an AI-assisted platform that automated the full credential-attack chain and compromised 12,000 accounts. That is the operational reality every agentic buildout now inherits. Every service account, API key, and agent credential issued during a rollout is a target, and human-workforce authentication controls are structurally insufficient once agents hold delegated authority over production systems.
Now read the vendor response in that light. IBM positioned watsonx Orchestrate as a control plane where governance sits above individual agents, turning policy enforcement into a platform function through identity-aware pipelines. Quest extended its identity platform to cover the in-flight compromise scenario, isolate-and-replay for agents already under attack. These announcements read as precautionary until you put EvilTokens next to them. Then they read as load-bearing.
The economics arrived on the same day. OpenAI's Sol and Luna and Anthropic's cost-optimized line have pushed the frontier race into a cost-tiering phase. Cheaper capable models lower the marginal cost of every deployed agent, which means agent fleets scale faster than the governance to contain them. Falling model prices are precisely what makes the identity control surface urgent.
And the outcome case is already public. Trane hit 60x on building analysis, and the durable win was the reuse standard across business units, not the model. AT&T is automating its legacy core under Wall Street pressure, compressing labor and infrastructure overhead at once. The Compiled Corporation is operating at scale in regulated, capital-intensive businesses.
The index frames the tension. Organization sits at 69 with Scaling Maturity, Talent, and ROI Impact all nudging up. Brand lags at 43. Enterprises are getting better at deploying and measuring, and the governance vendors are meeting them. The gap is whether identity architecture keeps pace with agent proliferation. That is a design decision made now, not a control retrofitted after the first agent-mediated breach.
The move for principals: before approving the next agent deployment, ask where the identity context lives and whether it travels through every execution hop. If the answer is per-agent, you have agent sprawl waiting to happen. If it is platform-level, you have something auditable.
Watch this week: OpenAI's third-party assessment principles. If they harden into contractual deployment requirements, the question becomes which assessors can certify agent-level safety, not just model-level. That is your next procurement filter.