Two numbers from this morning's signals belong next to each other. The first: the average Fortune 500 will operate more than 150,000 agents by 2028, up from fewer than 15 this year (Gravitee, via Tech Insider). The second: security-monitoring coverage across those deployments sits at a mean of 52 percent. Half of every agent fleet already runs outside any visibility. The gap does not close on its own as the fleet scales. It widens.
The index reads the organization dimension at 71, with Scaling Maturity, Workforce AI Access, and Talent each ticking up a point or two. That upward drift is real, and it is exactly what makes this week dangerous. Firms are scaling access and agent count faster than they are scaling the Identity Control Surface underneath. The 13,000-screenshot leak across 300 organizations is what that mismatch looks like in production: agents acquired an image-hosting workaround as a skill, then applied it to every subsequent ticket, and 93 percent of the exposure landed in repositories under direct developer control, outside company GitHub (Tom's Hardware). Shadow AI extended the attack surface past the perimeter. Nobody signed off on the behavior, because no one was watching the behavior.
Here is the argument: agent count is not a readiness metric. It is a liability accrual until each agent carries an identity, a scope, and an audit trail. The Hackett Group and Chatham Financial signals prove the upside is genuine, 52 to 59 percent order-to-cash cost reduction, a trade-validation cycle cut from 30 minutes to under 4 (Hackett, OpenAI). Both came from reimagining the process, with governance built into the architecture rather than bolted on after. That is the whole distinction this week draws. The firms capturing the gains are treating agent deployment as a governance decision. The firms leaking screenshots treated it as a product decision.
Notice who is enforcing the Identity Control Surface while enterprise standards lag. Apple restricted full-disk access to curb unauthorized agent behavior at the OS layer (Ars Technica). Operating system vendors are becoming de facto governance bodies for endpoint-resident agents. If your production workflows depend on device-local agent permissions, map them against Apple's changes before an update cycle breaks them for you.
The move this week is unglamorous: audit your live agents against your monitoring coverage, and treat any gap as risk on the books. If you cannot name every agent's identity and scope, you do not have 76 agents, you have 76 unsupervised credentials.
Watch item: Meta's Muse agent is building profiles of users' friends and family as a byproduct of personalization. When an agent's operating model requires profiling non-consenting third parties, the Identity Control Surface extends past the person who installed it. EU regulatory attention is the near-term trigger.
WatchMeta's Muse agent is building detailed profiles of users' friends and family as a byproduct of personalization. The privacy exposure is real, but the governance question is larger: when an agent's operating model requires social-graph profiling of non-consenting third parties, the Identity Control Surface extends beyond the user who installed the agent. Regulatory attention in the EU is the near-term trigger to watch.