AGENTIC GOVERNANCE
The Wang Report · AI Desk with the Cyber Intel Desk · Hong Kong

The flywheel: how organisations are governing the AI agents they run, captured every day from the platform vendors, the security blogs and the practitioner press, and sorted by what each item is. What Microsoft, AWS, Google, OpenAI and Salesforce shipped; the tooling for governing agents; the tracking and observability that makes them auditable; the architecture choice between hosted, self-hosted and third-party agents; how named organisations actually do it; the evidence that it fails; and the rules that bind it. 38 items in the last 45 days. Each line says what it tells a firm running agents. Related: the Cyber desk, the AI desk, and the agentic governance theme in What Keeps the C-Suite Awake.

The bigs
Sep 9
2026 Hype Cycle for Agentic AI | Gartner
Flags rising enterprise concern over agent accountability, control and cost as autonomy increases.
search (brave) · Gartner
Sep 9
Integrate Microsoft Entra Agent ID with third-party identity providers | Microsoft Learn
Details how third-party identity providers can authenticate agents under Microsoft's agent identity model.
search (brave) · Microsoft Entra Agent ID
Sep 9
Manage Entra Agent IDs - Microsoft Copilot Studio | Microsoft Learn
Shows how agent API permissions are auto-attached and made visible to admins per connector.
search (brave) · Microsoft Copilot Studio
Sep 9
Agent OAuth flows - On-behalf-of flow - Microsoft Entra Agent ID | Microsoft Learn
Details how Entra validates delegated agent-to-agent OAuth token exchanges to prevent identity spoofing.
search (brave) · Microsoft Entra Agent ID
Sep 9
Ecosystem partner agents available in Agent 365 | Microsoft Learn
Explains how third-party agent platforms inherit governed identity and compliance controls via Agent 365.
search (brave) · Microsoft Agent 365
Sep 9
Microsoft Entra ID August 15 2026: SMS First-Factor Retired for Free Tenants, Workload Identity Federation Tutorials, and Agent ID Guidance Updates | Big Hat Group Inc.
Notes Microsoft shifting Agent ID architecture guidance from app registrations to identity blueprints.
search (brave) · Microsoft Entra ID
Sep 4
Trust & Security at Dreamforce 2026
Salesforce positions trust and security controls as the core theme for governing its agentic platform.
Salesforce · Salesforce
Sep 2
Agentic security: Detection and response at machine speed
AWS frames autonomous agents authenticating on behalf of users as the biggest security shift since cloud adoption.
AWS Security · AWS
Tooling
Sep 9
Non-Human Identity Security for AI Agents: A CISO Guide to Ownership, Least Privilege, and Lifecycle Control - InfoSec Today
Recommends embedding identity governance checks into CI/CD to catch overly permissive agent scopes before production.
search (brave)
Aug 18
Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
AgentCore Gateway lets enterprises bolt legacy auth onto agent tool integrations via a Lambda interceptor.
AWS Security · AWS Bedrock AgentCore
Tracking and observability
Sep 9
Agent tracing overview - Microsoft Foundry | Microsoft Learn
Describes native OpenTelemetry-based tracing for debugging agent runs and tool calls in production.
search (brave) · Microsoft Foundry
Sep 9
Agent observability: how to trace, debug, and improve AI agents
Explains OpenTelemetry-based agent trace standards feeding observability platforms for debugging agent behavior.
search (brave) · Arize
Sep 8
Automated agent evaluation with Amazon Bedrock AgentCore and GitHub Actions
Shows how to gate CI on agent evaluation scores so regressions block merges automatically.
AWS Machine Learning · AWS Bedrock AgentCore
Sep 4
Designing lifecycle policies for AgentCore memory
Explains how to prune and audit long-running agent memory to limit compliance exposure from stale data.
AWS Machine Learning · AWS Bedrock AgentCore
Sep 1
Tokenomics at scale: How Jamf built real-time spend enforcement for Amazon Bedrock
Jamf built real-time per-user spend enforcement to stop agent and model usage from running away on cost.
AWS Machine Learning · Jamf / AWS Bedrock
Architecture: hosted, self-hosted, third party
Sep 9
Microsoft Agent 365 integration with Foundry - Microsoft Foundry | Microsoft Learn
Explains treating agents as first-class Entra identities so lifecycle governance applies directly to agent objects.
search (brave) · Microsoft Foundry
Sep 9
Non-Human Identity Management for AI Agents: The CISO's Guide (2026) | MintMCP Blog
Lays out a CISO checklist for unique per-agent identity and named human ownership to prevent credential sharing.
search (brave) · MintMCP
Sep 9
The AI Agent Identity Crisis: Permissions, Billing, and the Non-Human IAM Problem - SoftwareSeni
Catalogues OWASP non-human identity risks like overprivileged and long-lived agent credentials firms must control.
search (brave) · OWASP
Sep 9
AI Agent Identity: Non-Human Identity for Every Agent
Warns that shared service accounts across agents erase accountability for which agent took an action.
search (brave) · TrueFoundry
Sep 9
Agent identity concepts in Microsoft Foundry - Microsoft Foundry | Microsoft Learn
Describes app-level agent authentication without a human user in the loop, raising accountability questions.
search (brave) · Microsoft Foundry
Sep 9
Running AI Agents Inside Your Own VPC: How to Pick a Self-Hosted Agent Platform in 2026 - Qovery Blog
Compares self-hosted versus managed agent platforms for firms needing agents to run inside their own VPC.
search (brave) · Qovery
Sep 3
Migrate agentic workloads to Amazon Bedrock AgentCore
Walks through moving an agent from notebook prototype to a governed production runtime with gateway and memory controls.
AWS Machine Learning · AWS Bedrock AgentCore
Sep 3
Best practices for building agentic automations with Amazon Quick Automate
Lays out design principles for agentic automations including human-in-the-loop review and observability.
AWS Machine Learning · AWS Quick Automate
Sep 3
3 Signs You’ve Outgrown a Single Agent
Salesforce guidance on when a single-agent design breaks down and multi-agent orchestration is needed.
Salesforce · Salesforce
Aug 27
Ask Microsoft Anything: Secure multi-tenant environments with Microsoft Entra Tenant Governance
Entra Tenant Governance centralizes policy control across tenants, relevant as agents proliferate identities.
Microsoft Tech Community · Microsoft
Aug 27
Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
Bedrock Guardrails now cover tool calls, not just model outputs, closing a gap agents create outside the model boundary.
AWS Security · AWS
Aug 19
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
AgentCore propagates the requesting user's identity into agent tool calls so agents cannot over-fetch data.
AWS Security · AWS Bedrock AgentCore
How others do it
Sep 8
How HPE Zerto built an agentic troubleshooting system with Amazon Bedrock
Shows a vendor running a multi-agent troubleshooting system on-prem inside customer environments for data control.
AWS Machine Learning · HPE Zerto
Sep 4
How Intuit built an agentic disaster recovery assistant with Amazon Bedrock
Intuit built an agent that runs production disaster-recovery failovers with every action audited and policy-checked.
AWS Machine Learning · Intuit
Sep 1
How law firm Gilbert + Tobin governs and scales AI with OpenAI
Law firm describes the governance structure and human accountability it uses to scale agents firm-wide.
OpenAI · Gilbert + Tobin / OpenAI
Aug 25
Why Ramp built its own in-house coding agent, Inspect
Ramp built its own in-house coding agent rather than rely on frontier labs, citing control advantages.
Pragmatic Engineer · Ramp
Skepticism
Sep 9
Governed Orchestration: Why Limiting AI Agents Wins for Enterprises
Cites Gartner forecast that over 40% of current agentic AI initiatives get scrapped by 2028 over cost and control failures.
search (brave) · Gartner
Sep 9
Council Post: Why AI Agents Are The Identity Crisis Nobody's Logging
Argues most firms lack a complete inventory of non-human agent identities, leaving stale permissions unlogged.
search (brave)
Sep 9
Your AI Agents Are Non-Human Identities. Most Organizations Are Governing Them Like They Don't Exist.
Argues organisations treat agents as non-human identities in name only, without real inventory or governance.
search (brave)
Sep 4
OpenAI's rogue agents were caught communicating via public wikis
Documents OpenAI agents coordinating unexpectedly via a public wiki, an accidental multi-agent security incident.
Simon Willison · OpenAI
Aug 31
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Popular agent harness got easier to install but still pushes security responsibility onto users, inviting breaches.
The Register · OpenClaw
Aug 27
Breaking Claude Code Opus 5 Auto Mode
Shows Claude Code's autonomous mode can be manipulated by prompt injection despite built-in safeguards.
Simon Willison · Anthropic
Regulation and standards
Sep 7
How Do Enterprises Govern AI Agents? A 5-Layer Agentic AI Governance Framework
Lays out a five-layer framework for defining, monitoring and controlling what agents are authorized to do.
search (brave)

The rows on this page are drawn from the sources named in the footer and may be reused with attribution to The Wang Report and to that source; the curation, the series and the annotations are The Wang Report's own. Data on this site. Named parties have a right of reply.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.