Agent Inventory and Spend Governance: 7 Signals, Week of September 1 2026 · Enterprise Agentic AI Insights
Agent 365 prices per user while risk scales per agent. Four registries, one fleet, and the model risk letter that stopped covering agentic AI. Weekly roundup.
Microsoft will sell you a control plane for your AI agents this quarter. It prices per user. Your risk prices per agent. Those two curves do not meet, and the gap between them is where the next renewal review, board question and examiner conversation is going to land. That is the through-line for the week of September 1, 2026. Seven signals below, in the order a CIO, CDO or Chief Risk Officer will actually meet them, followed by a comparison of the four control planes now competing for the same job and a three-minute self-check you can run before Monday. Jump to: The 7 signals · How to choose your agent control plane · Score your own fleet · Sources The 7 signals 1. Agent 365 prices the fleet before you can count it Microsoft Agent 365 is generally available as a unified control plane to observe, govern and secure agents across Microsoft and partner ecosystems. It costs $15 per user per month standalone, or arrives inside Microsoft 365 E7 at $99. The licence attaches to the person, not the agent, and agents do not carry licences of their own. CITED C01, C02 The practical consequence for a CIO: finance can model the cost of agent governance today, from the headcount file, without knowing how many agents exist. The invoice is knowable before the inventory is. Every conversation that follows starts from a number the platform team did not produce. 2. Four vendors shipped four registries for one fleet Within a single quarter: - Microsoft shipped Agent 365 as the control plane over Microsoft and partner agents. CITED C01 - ServiceNow and Google Cloud joined the AI Control Tower to the Gemini Enterprise Agent Platform, producing a single registry of every agent and MCP server with a live view of what they access and how they behave. CITED C04 - Google Cloud made the Gemini Enterprise Agent Registry generally available as a central catalog for agents and MCP servers. CITED C05 - Snowflake launched the Cortex AI Gateway at Black Hat 2026, adding MCP governance, agent identity controls and data exfiltration prevention, built on its May 2026 acquisition of Natoma. CITED C06 Four registries. One fleet. No single roster. The integration work nobody budgeted for is the reconciliation between them. 3. Agent identity became a product category, not a design pattern Microsoft Entra Agent ID is available to all Entra customers and creates agent identities and identity blueprints inside the directory that already holds your employees. Snowflake AI Agent Identity is generally available with cryptographic identity per agent, per-agent RBAC and a full audit trail. CITED C03, C07 The test for a CDO is not whether identities exist. It is whether you can revoke one agent's access in under an hour without taking a person offline with it, and whether anyone has run that drill. 4. The federal model risk letter stopped covering the models On April 17, 2026 the Federal Reserve, OCC and FDIC issued revised model risk management guidance as SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026, replacing SR 11-7 after fifteen years. The revised guidance states that generative AI and agentic AI models "are not within the scope of this guidance." VERIFIED C10 Read that again, because most commentary this quarter has it backwards. This was not new AI rules for banks. It was the removal of the systems banks are actually deploying from the framework that used to govern them. Traditional quantitative models stay in scope. Existing third-party risk guidance still applies where AI touches it: the June 2023 interagency guidance, SR 23-4, OCC Bulletin 2023-17, FDIC Part 364 and the SEC Regulation S-P amendments. CITED C12 The agencies have signalled a request for information covering bank use of generative and agentic AI. No date. CITED C11 For a Chief Risk Officer that produces a specific, uncomfortable position: the supervisory letter you would have pointed at is gone, the examiner still asks, and the burden of writing the control standard has moved onto the institution. 5. Article 50 is live, and December 2 is the date with runway left EU AI Act Article 50 transparency obligations have applied since August 2, 2026, with Commission guidelines adopted July 20, 2026. Systems that interact directly with people, including chatbots, voice assistants and agents, must disclose that the user is dealing with AI unless it is already obvious. Penalties reach EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities. VERIFIED C13 CITED C15 The deadline still ahead: generative systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) marking requirements. VERIFIED C14 That is 88 days from today. It is the only Article 50 date left with room to plan against. 6. January 1, 2027 is the US state cliff Three separate regimes land on the same morning: - California SB 53. From January 1, 2027 the California Office of Emergency Services publishes an annual aggregated report of critical safety incidents reported by frontier developers and the public. CITED C16 - Colorado AI Act. Effective January 1, 2027 after two delays, with SB 189 having removed the deployer risk-management and impact-assessment duties. CITED C17 - Colorado HB 1263 and HB 1139. Chatbot safety and AI in health insurance coverage decisions, both effective January 1, 2027. CITED C17 If you operate in healthcare or insurance, HB 1139 is the one that reaches a live claims workflow rather than a policy document. 7. The production gap did not close Deloitte's 2026 Tech Trends puts the agent pilot failure rate at 89 percent; independent studies land in an 86 to 89 percent band. Roughly 31 percent of enterprises have at least one agent in production, with banking and insurance leading at 47 percent, healthcare at 18 percent and government at 14 percent. Only 21 percent of organisations report a mature governance model for autonomous agents, against roughly three-quarters expecting to use agentic AI within two years. CITED C18, C19, C20 The gap between 31 percent in production and 21 percent with mature governance is the honest description of the current market. More organisations are running agents than can account for them. How to choose your agent control plane Four vendors, one job. The right answer depends on where your evidence problem actually sits, not on which platform your largest contract is with. | Control plane | Strongest at | Pricing shape | Choose it when | |---|---|---|---| | Microsoft Agent 365 + Entra Agent ID | Identity-first governance inside an existing directory; broadest partner-agent coverage | Per user, $15/user/month standalone or M365 E7 at $99 | Your workforce already lives in Entra and your first problem is who owns this agent | | ServiceNow AI Control Tower + Google Gemini Enterprise Agent Registry | Cross-platform observability; live behavioural view of agents and MCP servers | Platform-bundled | Your agents span several clouds and your first problem is what is running where | | Snowflake Cortex AI Gateway + AI Agent Identity | Data-plane control; per-agent RBAC, tool-call policy, exfiltration prevention | Consumption | Your exposure is the data an agent can reach and your first problem is blast radius | | Salesforce Agentforce 360 | Service-org agent operations and in-workflow observability of reasoning, accuracy and compliance | Platform-bundled | Your agent population is concentrated in the service org and your first problem is deflection quality | Three decision rules that hold regardless of vendor: 1. Buy the registry that matches your worst blind spot, not your biggest contract. The renewal argument is easier when the tool solves the problem you can name. 2. Make registration a precondition of credentials. A roster that has to be reconciled quarterly is stale by construction. A roster that gates access maintains itself. 3. Separate the cost owner from the risk owner. Agent 365 scales cost with head