Editorial illustration of GPU server racks and a data center with glowing compute nodes

Enterprise AI agents can now read the policy, draft the refund, and fill in the form. What most of them still cannot do is press submit – because no one in the building can safely say who the agent is, what it is allowed to touch, and what it did after it acted.

Stuck between capable and cleared

The scale of the push is not in doubt. Gartner projects that 33% of enterprise software applications will embed agentic AI by 2028, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously by then, from a standing start of zero.

Vendors are shipping into that demand: Cisco is rolling a personal agent to roughly 90,000 employees by the end of July 2026, SAP has folded its stack into a data-context, build, and governance layering, and Google has consolidated its enterprise agent tools into a single Gemini Enterprise platform built on open agent protocols.

The conversion rate tells the other half of the story. One industry analysis puts the share of agent pilots that never reach production at roughly 88%, with agents completing about half of complex tasks reliably in live environments; the figure circulates widely but without a single originating study, so read it as a direction rather than a market-wide conversion rate – reliability, not raw capability, is the gate.

When organizations are asked what blocks them, they do not point at the model – around 46% name system integration as the top barrier, and a mid-July 2026 industry report reframed the whole problem as making enterprise content and data usable and trustworthy for the agents that depend on it. Gartner's blunter number: it expects more than 40% of agentic AI projects to be canceled by the end of 2027, citing cost, unclear value, and weak risk controls, and estimates that only about 130 of the thousands of self-described "agentic AI" vendors are building anything real.

The security picture underneath is thinner than the ambition. In Okta's 2026 survey of enterprise leaders, 58% said their organization had already hit an AI-related security incident or close call in the prior twelve months, yet only 34% apply the same controls to AI agents that they apply to human employees; 52% of knowledge workers admitted using AI tools nobody approved. The capability arrived before the permission model did.

Bar chart — Enterprise apps with embedded agentic AI (Gartner): 2024 (<1%) 1, 2028 (est.) 33.

The bottleneck moved to who the agent is

Most coverage reads this as a governance-lag story: policy and oversight will catch up, and then agents ship. That framing is half a step short. Descend one layer. An agent that is genuinely useful does not answer questions – it acts, which means it calls tools and writes into a system of record: the ERP, the CRM, the ticketing queue, the payments API.

The moment software can write to those systems on its own initiative, the enterprise needs to answer the same three questions it asks of any employee with keys: who is this, what can it reach, and what did it do. A year ago, few off-the-shelf products combined those answers specifically for a non-human actor that picks its own next step at runtime.

Here is how the mechanism actually works, because the plumbing is the story. A human gets into enterprise systems through single sign-on and role-based access – an identity a directory already knows, scoped by a role. An agent has neither by default. So the industry is retrofitting one.

Two protocols anchor the current interoperability push, according to industry reporting: Anthropic's Model Context Protocol (MCP), the agent-to-tool standard reported at around 97 million downloads and adopted across Anthropic, OpenAI, Google, and Microsoft, and Google's Agent-to-Agent (A2A) protocol, now under the Linux Foundation with 150-plus supporting organizations, which lets agents delegate work to one another through signed "Agent Cards". On top of the protocols sits the harder layer: identity.

Microsoft's Entra Agent ID reached general availability in April 2026, treating each agent as a first-class identity with its own OAuth 2.0 credentials, MCP and A2A support, and Zero-Trust scoping; Okta launched a parallel product that registers agents in a directory, assigns them an owner and a lifecycle, and extended it to Amazon Bedrock in May 2026. An emerging implementation pattern: per-agent machine-to-machine tokens, short-lived and rotated, scoped to specific endpoints, with every action logged.

The reason this is hard, not just new, is that an agent is not robotic process automation with a chatbot bolted on. RPA follows a fixed script, so its permissions can be nailed down in advance. An agent chooses its actions as it goes, which means least-privilege access has to hold against behavior nobody enumerated – and the audit trail has to reconstruct a decision the software made on its own. That runtime autonomy is exactly what makes the identity layer both necessary and unfinished.

It also opens a new attack surface: Trustwave researchers showed that a rogue agent can advertise an inflated Agent Card whose description manipulates an orchestrator's model into routing tasks to it – prompt injection moved down into the infrastructure.

Follow that to money and the winners are specific – and they are mostly not the model labs. For mature, widely replicated capabilities the model becomes an interchangeable component, the way a database driver is; pricing power stays with the newest frontier capability until competitors catch up.

The durable value accrues one layer out: to whoever issues the agent's credentials (the identity vendors – Okta, Microsoft Entra, the IAM incumbents) and to whoever owns the system of record the agent has to write into (SAP, ServiceNow, Salesforce, Microsoft), because they can grant governed, auditable write access that a standalone lab cannot.

Gartner has put as much as $234 billion of enterprise application-software spend "at risk" from agentic AI between now and 2030 – a share Gartner projects will reach about 20% of enterprise SaaS spending by then – but at-risk cuts both ways, and the incumbents controlling the write surface are positioned to recapture much of it. The same logic we traced when the reasoning economy turned token efficiency into a cost line rather than a moat applies here from the access side: the model is necessary and no longer sufficient.

The ripple reaches past software. Cybersecurity and identity vendors get a new product category outright – "non-human identity" governance is becoming a line item, and the same directory that manages employees may need to manage a much larger and faster-changing population of short-lived agent identities. Audit, compliance, and cyber-insurance feel it next: an autonomous action that moves money or changes a record creates a liability and an evidence requirement that did not exist when a human clicked the button – and no loss history yet exists to price that exposure against.

And enterprise operations broadly inherit a workforce-management problem in a new form – provisioning, ownership, and offboarding for agents that are spun up and killed by the thousand, a scale of identity churn no HR-shaped process was built for. This is not confined to tech; the same access questions we flagged for the perception layer robots need before they can act in the physical world show up here for software acting in systems of record.

The numbers that decide who's right

Watch these as an operator would, not a headline reader:

1. Production conversion. The tell is whether documented pilot-to-production conversion improves through 2026-2027 as identity tooling matures. If Entra Agent ID and Okta-style registries are the missing piece, conversion should climb where they are deployed; if it doesn't, the wall was never authorization. Watch it against Gartner's "more than 40% canceled by end-2027" line – that projection is the falsification test. 2. Identity-control parity. Okta's 34% figure – the share of firms applying human-grade controls to agents – is the cleanest single gauge.

If it is not moving toward a majority within a year, agents are being deployed faster than they are being governed, and the incident rate will follow. 3. Protocol lock-in. Whether MCP and A2A stay open and multi-vendor or fragment into walled dialects decides who captures the layer. A single vendor quietly making its MCP or identity flavor the default inside a dominant platform would be the signal that the toll booth is being built.

The layer worth owning

The enterprise-agent race has quietly stopped being about which lab has the smartest model and become about who can safely hand that model a badge. The reframe that matters for anyone buying, building, or investing: an agent's value is capped by the permission you can defend to an auditor, so the durable margin is pooling around the credential issuers and the systems of record, not the reasoning engine.

The one number to keep on the desk is Okta's control-parity figure – if the share of firms governing agents like employees is not clearly rising a year from now, the production wall is going to hold, and most of the projects Gartner expects to cancel will cancel on schedule.

Sources

  • gartner.com — Gartner projections: >40% of agentic AI projects canceled by end-2027; 33% of enterprise apps agentic by 2028 (from <1% in 2024); 15% of decisions autonomous by 2028; "agent washing" (~130 real vendors). (2025-06-25)
  • okta.com — Okta "AI Agents at Work 2026" survey: 58% had an AI security incident/close call in 12 months; 34% apply human-grade controls to agents; 52% use unapproved AI; where/connect/do framework. (2026-05-27)
  • digitalapplied.com — MCP ~97M downloads, adopted by Anthropic/OpenAI/Google/Microsoft; A2A 150+ orgs under Linux Foundation, production-grade by April 2026; signed Agent Cards. (2026-05-01)
  • digitalapplied.com — ~88% of agent pilots never reach production; ~50% task success in production; blockers are integration/reliability/latency/security, not model quality. (2026-04-01)
View all sources
  • virtualizationreview.com — Enterprise content/data access reframed as the agentic AI bottleneck; ~46% cite system integration as the top barrier. (2026-07-14)
  • bighatgroup.com — Microsoft Entra Agent ID GA April 2026: agents as first-class identities, OAuth 2.0, MCP/A2A, Zero-Trust scoping for non-human identities. (2026-04-15)
  • ruh.ai — Per-agent OAuth 2.0 M2M tokens, short expiry/rotation, scoped endpoints, signed Agent Cards; Trustwave rogue Agent Card prompt-injection attack class. (2026-06-01)
  • hectorpincheira.com — Technology Radar July 2026: Cisco ~90k-employee agent rollout by end-July; SAP/Google platform consolidation; Gartner ~$234B enterprise app spend at risk by 2030. (2026-07-10)
  • team8.vc — The capability-vs-reliability gap decides whether agents ship; reliability, not raw capability, is the production gate. (2026-06-01)
  • siliconangle.com — Okta for AI Agents: agent registry, ownership, lifecycle, human-like policy; extended to Amazon Bedrock, opened to rival identity providers. (2026-05-14)
  • ciodive.com — Gartner press release 2026-07-01, quoted directly: "Agentic AI is slated to continue to disrupt the enterprise application software market with up to $234 billion in spending between now and 2030"; ~20% of enterprise SaaS spend by 2030. (Gartner's own newsroom page returns 403 to automated fetch; this trade-press report quotes the release verbatim.) (2026-07-06)

This article is for informational and educational purposes only and does not constitute investment, financial, or legal advice.