Four major infrastructure vendors have now shipped standalone agent governance products at general availability. The vendor rush itself has become the signal.
Okta’s July 2026 product innovations pushed the furthest into new territory. The company shipped Agent-to-Agent Connections at general availability, enabling secure multi-agent workflows by issuing temporary runtime tokens that enforce which agents may invoke which others. The Agent Gateway — available as a research release — lets Okta sit between agents and the systems they access without requiring code changes, validating identity and brokering short-lived credentials at runtime. “Enterprises are deploying AI agents in higher-value, but more complex workflows that require deeper access to sensitive resources and collaboration with other agents,” said Ely Kahn, Okta’s Chief Product Officer.
IBM’s Think 2026 announcement positioned next-generation watsonx Orchestrate as an agentic control plane, introduced in June on AWS and IBM Cloud. The platform provides a unified way to manage and govern an organization’s entire agent estate regardless of where those agents were built, with runtime policy management, credential health monitoring, and an Agent Access overview showing which agents can access which integrations and data.
Broadcom’s approach embeds governance directly into the compute fabric. AgentMinder, unveiled at VMware Explore on August 31 and shipping at general availability bundled into the VMware Private AI Cloud, treats agents as enterprise-grade identities — binding their authority to a declared mission, permitted intents, approved tools, and authorized resources. Runtime enforcement runs through a cloud-native AI gateway that secures every tool call and directs traffic only to authorized backends.
Dataiku makes a different architectural bet entirely. Rather than embedding governance into a specific compute environment, Dataiku Agent Management scans agents across nine platforms — Microsoft Copilot Studio, Salesforce Agentforce, AWS Bedrock, Google Vertex, and five others — providing a cross-platform control tower for discovery, certification, and audit-readiness. The bet is that enterprises will need visibility across heterogeneous environments, not just control within one.
Four vendors. Four different infrastructure layers. One structural conclusion: agent governance is decoupling from individual platforms to become a category of its own.
The urgency behind this rush tracks to two numbers. Menlo Ventures found that 76 percent of AI applications are purchased rather than built internally, which means enterprises cannot rely on a single vendor’s native controls to govern their entire agent estate. And the Cloud Security Alliance reported in February that 84 percent of organizations doubt they could pass a compliance audit focused on agent behavior or access controls. The gap between deployment speed and governance readiness is the market these vendors are racing to fill.
These products map directly onto the three-layer governance stack we have been tracking across the beat. Governance specifications from standards bodies like OWASP, NIST, and AAIF (Post 129814) define what policies should exist. Runtime authority mechanisms like Akeyless (Post 130077) define how credentials and permissions are brokered. Runtime enforcement tools like the Akamai and MuleSoft integration (Post 129957) define how policies are applied at the moment an agent acts. The new wave of products acts as the connective tissue — the control plane that wires these layers together into something enterprises can actually operate.
One tension is already visible: platform-native governance versus cross-platform control towers. Broadcom and IBM embed governance into their compute and cloud fabrics, offering deep integration with lower friction for organizations already running on their infrastructure. Dataiku and Okta sit above the execution path, providing visibility across heterogeneous environments. Neither approach is obviously wrong — they answer different questions. Platform-native tools ask how to govern agents within a controlled environment. Cross-platform tools ask how to govern agents you did not build, running on infrastructure you do not own.
For enterprise architects, the practical implication is that agent governance is no longer optional and no longer a bolt-on. It is becoming the foundational layer required to scale AI safely — and the vendor rush confirms that the market agrees.