The Agentic Index Brief
August 2 to August 8, 2026 · Published August 9, 2026
The week in one line
Four enterprise incumbents shipped agent governance control planes inside the same seven days the EU AI Act's general enforcement date arrived. The old worry was agents with no governor. The new worry is agents with four.
Theme 1: The control plane got crowded
The EU AI Act's general enforcement stage took effect on August 2, the first day of this issue's window. Nobody builds a control plane in a week, but you can certainly schedule one for it, and this week's calendar reads less like coincidence than a coordinated landing.
ServiceNow launched Autonomous Security, six solutions unified inside its AI Control Tower, with AI Specialists that consolidate vulnerability findings, orchestrate triage, and execute low risk patches autonomously. SAP detailed its AI Agent Hub, a vendor agnostic command center to discover, manage, and govern AI agents, LLMs, and MCP servers wherever they sit in a business process. Microsoft expanded Zero Trust for AI with tooling and guidance for verifying agent behavior before agents reach production. And NICE introduced Witness, which keeps an impartial, cross vendor record of AI activity and personnel actions from first call through final review.
Note what the four have in common: each already runs a system of record, and each is now claiming the layer that governs everyone else's agents. In last week's issue, ServiceNow shipped both halves of MCP because nobody wants to be a tool in someone else's palette. This week it is selling security for the palette.
The specialists answered with sharper blades. Straiker launched the Agentic Kill Switch, which takes a rogue or compromised agent offline in seconds once it crosses a defined boundary. Five weeks ago, in the July 4 issue, a kill switch was a feature Sprinklr added. It is now a product with a name.
Tuskira shipped an Agentic Control Plane for exposure management that follows an AI discovered vulnerability from first scan to verified closure, checking reachability against production context across 150 integrations. Tray.ai introduced Helix, a governed runtime whose centralized credential broker means raw secrets never touch application code or AI prompts, the same architecture Daytona applied to sandboxes in issue one, now wrapped around entire applications. Writer put Supervise into beta, an observability command center where administrators enforce policies and trace agent execution paths. And Airia announced conformance with the AARM specification for autonomous action runtime management, which says something bigger than one roadmap: the category now has paperwork to conform to.
The finance wing arrived in the same window. Rippling launched an AI Spend Console giving CFOs and CTOs permissioned dashboards that track token costs by individual and team, tie usage to business outcomes, and govern which LLMs are approved at all. GitHub retired its Copilot Billing Preview app into native billing with budget caps and raw usage exports. Spend control is folding into the same plane as everything else, which is where it belongs. The invoice was always the first observability tool. Finance has been doing telemetry for centuries; it just calls the alerts "budgets."
Our read: the control plane above agents is being claimed simultaneously by every vendor that already owns a control plane for something else: ITSM, ERP, cloud, communications, HR. Each has a legitimate claim and none will yield. The realistic outcome for a midsize enterprise next year is not zero governance. It is four partial governors with overlapping jurisdiction and no supremacy clause.
Buyer question this week: count the control planes that can currently see, stop, or bill each production agent you run. If the answer is more than one, decide which is authoritative for which class of action, and write it down before an incident writes it for you.
Theme 2: The application layer is growing its own models
In last week's issue, depthfirst trained a proprietary security model inside its own agent harness and we called it the first entry of its kind in our log. It took one week to stop being alone.
Thomson Reuters introduced Thomson, a proprietary large language model built for legal, tax, and compliance work, wired into CoCounsel to power features like Tabular Analysis and, per the vendor's own benchmarks, competitive with frontier models including Claude Opus 4.8. Days later it took the next generation of CoCounsel Legal to general availability, with agentic workflows that plan, choose tools, and retrieve authoritative content from Westlaw and Practical Law on their own. Writer released Palmyra X6, a general purpose model tuned for agentic and long running work, alongside Agent Memory and an admin switch that governs browser automation. And Scaled Cognition launched APT, an Agentic Pretrained Transformer: a model and system trained from the start to execute real world actions rather than to predict text describing them.
The open side moved in parallel. Prime Intellect open sourced Prime Agent under MIT, a self improving coding and research harness in which prompts, sub agents, skills, and memory are state variables the agent can modify mid run. Emergence AI released VCG, a verified coding agent specialized in Python that writes, verifies, and executes autonomously. Jina AI shipped jina-reranker-v3.5, a 0.6 billion parameter listwise reranker that runs 1.56x faster than its predecessor. The component layer keeps compounding while the application layer votes on where models come from. "Bring your own model" and "our model only" are now competing architectural philosophies.
Our read: owning the model changes three things at once. The economics, because there is no pass through meter, and restraint can even be trained into the weights, as depthfirst showed last week. The evaluation, because the benchmark is now the vendor's own homework, and a vendor grading its model against a frontier lab deserves the scrutiny of any self graded exam. And the dependency, because model choice quietly becomes our model only. None of these is bad. All of them belong in the diligence file.
Buyer question this week: for any platform running a proprietary model, ask what exactly it was trained on and how much of it, who outside the company has reproduced the benchmark, and what the fallback is if the model falls behind the frontier between now and your renewal.
Theme 3: The connectors got a security detail
The connector wave we have tracked since July kept landing. Deel shipped a native Claude connector over MCP that answers questions and takes actions on payroll and compliance data across 150 countries, scoped strictly to the requesting user's permissions, which is the clause that makes the rest of the sentence tolerable.
HubSpot expanded its Claude connector with partner read access and verified domain restrictions for Claude Enterprise accounts. Sendbird launched Delight Agent MCP, exposing more than 35 operational tools to Claude, ChatGPT, Cursor, and Codex. Synthflow added Claude and Five9 integrations. Chatbase made its entire agent lifecycle programmable through an API, down to creating an agent by crawling a website. And Cursor sent traffic the other way, with plugins that let its coding agents read, write, and act across Gmail, Drive, and Calendar from inside the IDE.
Then the security vendors followed the traffic, as they tend to do once the traffic becomes interesting enough to subpoena. Zenity extended its governance platform to Claude Enterprise, including Claude Code and Cowork, and separately wired its findings into AWS Security Hub. Noma Security built a unified control plane for enterprise AI on Claude's Compliance API. Stacklok integrated with Anthropic's MCP Tunnels to serve as the MCP management layer for connections into systems behind corporate firewalls. Add CrowdStrike's Falcon AIDR coverage of Copilot Studio and Claude Code agents from last issue, and the count reaches four security vendors in two weeks converging on assistant ecosystems as a governance surface.
Our read: an ecosystem crosses into enterprise infrastructure at the moment third parties can build governance on top of it, and a compliance API consumed by outside security vendors is exactly that tell. The connector pattern is now mature enough to have its own defense industry. A connector without a governance story, meanwhile, is shadow IT with a nicer OAuth screen.
Buyer question this week: when a system of record connects to an assistant, establish whose control plane records the traffic, the vendor's, the assistant's, or yours, and whether the connector inherits the requesting user's permissions or carries standing permissions of its own. "We'll figure that out later" remains a surprisingly popular authorization model.
Market notes
The acquisition run that spent three consecutive issues eating coding tools has moved on. Galileo completed its transition into Splunk Agent Observability, with the standalone platform now serving legacy customers only. Rox acquired Persana AI and folded its signal detection into revenue agents that act on buying signals as they fire. Legora bought Wexler, a UK litigation intelligence startup and its fifth acquisition this year. And Deel acquired Clarity, a deepfake fraud defense company, to verify that the person being hired exists. Observability, GTM signal, legal research, and the concept of identity: the consolidation menu is broadening.
Compliance certificates continued their run as market access documents. Salesforce's Agentforce 360 reached Department of Defense Impact Level 5 authorization and is now embedded in Missionforce for controlled unclassified workloads. WISEnut's agent development platform took Grade 1 GS certification from the Korea Testing Laboratory. Different flags, same function: paper that opens doors.
Agents moved deeper into regulated paperwork itself. Unit21 introduced SAR Agents that draft FinCEN ready suspicious activity narratives directly into filings, with the analyst as reviewer of record. An agent now writes the first draft of a document read by financial regulators, which means the reviewer's signature has never carried more weight per keystroke. Healthcare deepened along the same line: Abridge unveiled a clinician intelligence platform that coordinates clinical, financial, and evidence based decisions around the patient, and DeepScribe wired its ambient documentation into Flatiron Health's OncoEMR, reaching roughly 4,200 oncology providers.
The runtime tier thickened. LangSmith opened Managed Deep Agents in public beta, a managed runtime with durable execution, memory, sandboxes, and evaluations included. Mastra made workflows persistable as declarative JSON graphs with full API and database support. Kestra announced 2.0, billed as the largest release in its history. And memory kept arriving with an audit surface attached: Oracle gave agent memory hybrid search, Kognitos shipped a finance context graph that encodes approval hierarchies for deterministic execution, and Base44 gave its Superagent persistent memory with a reviewable log the user can edit or delete. Memory with a log is governance shaped, which is presumably the point. Once software remembers things, enterprises immediately want to know precisely what, when, why, and whether Legal can delete it.
At the interface, Decagon gave its support agents Browser Actions to complete tasks inside any web based system, and Bland AI taught its voice agents to measure a caller's pace and pauses and adjust their own timing in response, retiring the manual setting. Adaptive patience, now a shipped feature.
The action item: a patch list with no deadline, because every deadline already passed
Three entries this week are do it now rather than calendar it, the familiar point in the security lifecycle where the roadmap becomes a fire extinguisher.
First, CISA flagged the Langflow remote code execution vulnerabilities as actively exploited in automated exploit chains. The July 26 issue covered this exploit when researchers found it. It has since been industrialized. If your Langflow instances have not been upgraded since July, treat them as internet facing liabilities and patch or isolate today.
Second, Claude Code 2.1.223 patches a Bash permission bypass, alongside new marketplace controls that let administrators allow or block every repository under a GitHub organization with a single wildcard. There are bugs that can wait until Tuesday. "The autonomous coding tool may ignore permission boundaries" is not among them.
Third, Kilo Code disclosed a breach of customer data through its business intelligence provider, Metabase. Two notes. The breach entered through a vendor's vendor, which is where agent era supply chains keep getting caught. The modern software stack is increasingly a row of dominoes with API keys. And Kilo Code was acquired by Anaconda two issues ago, a reminder that disclosure obligations ride along in the data room. If your team uses Kilo Code, watch the notification channel and rotate anything that touched it.
The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 984 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.