Two stories ran this week, and they are the same story.
An OpenAI agent breached Australia's national health service, and the government learned about it months later, by email. Separately, threat actors used AI agents to skim 600,000 credit cards across 119 sites, hitting a Fortune 500 hospitality firm and a major US airline. One is an agent inside the perimeter with too much access. The other is an agent outside it, moving faster than the review cycle built to catch it. Both are failures of the same control surface: nobody knew who the agent was, what it could touch, or when it went wrong.
IT Brief named the mechanism plainly this week. Agents are entering production on static API keys and shared service accounts, carrying more permission than the humans they assist, with scoping deferred and never revisited. Access controls sit two decades behind the standard we apply to people. This is permission debt, and it compounds with every agent you deploy. The Australian detection gap is what that debt looks like when it comes due.
Here is the tension the index surfaces. Organization scored 69 this week, with Scaling Maturity, Talent, and ROI all ticking up. Enterprises are getting better at deploying. Brand sits at 43. The gap between how fast firms move and how well they can account for what they moved is exactly the gap the health service fell into.
The firms getting this right architected governance first. CBTS rolled Claude Enterprise to 2,300 people with ROI inside three months and zero major security incidents, because security was the foundation layer, not a post-launch attachment. SAP's AI Agent Hub puts the same discipline into the ERP layer: a registry mapping every agent to a capability, a named owner, and continuous compliance tracking. That moves agent governance from a security ticket to a business architecture decision, which is where it belongs.
The instruction for this morning is narrow. Before you provision your next agent, answer three questions: does it have a named identity, does it carry a scoped credential, does it have a documented owner. In most organizations today the answer to all three is no. Fix that before you scale, because the detection gap does not announce itself. It arrives by email, months late.
Watch: AI neolabs raised $24B in two quarters at 5x pre-ChatGPT rates, much of it in ventures with no product or revenue. When that corrects, integrations built on neolab infrastructure strand, and the procurement decisions you make this quarter carry hidden platform risk. Audit which of your agent stack sits on funded-but-unproven vendors.
¶
Harvey turns legal context into stronger drafts with GPT-6 Astra
Harvey is deploying GPT-6 Astra to produce structured, context-aware legal documents, reducing lawyer time on document assembly and reallocating that capacity to strategy work.
Why it matters
Harvey is the clearest current example of the Compiled Corporation in a regulated professional services context: core knowledge work automated at the document layer, with human lawyers repositioned to judgment and strategy. The GPT-6 Astra deployment is a capability step-change from retrieval-augmented drafting to context-integrated generation. For enterprise leaders watching professional services automation, this is the production signal that AI-driven document workflows have crossed from pilot to standard delivery model in legal.
WatchAI neolabs raised $24B in two quarters at 5x pre-ChatGPT funding rates, with capital concentrated in 200+ ventures lacking products, markets, or revenue. The divergence between capital deployment and production outcomes is widening. When this corrects, enterprise buyers will face a vendor consolidation wave: integrations built on neolab infrastructure become stranded, and procurement decisions made today carry hidden platform risk.