The gateway is the architecture
Agents were deployed as features and are being retrofitted as principals. Identity, scope and audit are arriving about two years late, and the vendors selling them are describing exactly what went wrong.
Two vendors shipped the same abstraction in the same week: discovery, registries, agent identity, and calls that never hand an agent a raw credential.
Read the product, learn the failure
Security products are confessions. When a vendor ships "AI Discovery — surfaces every agent, provider and MCP server already running by mining your existing security logs", it is telling you that nobody knows what is running. You do not build a discovery tool for an inventory somebody maintained.
The numbers support it. Roughly 97 million SDK downloads a month, about 41% of technical leaders reporting production use, and a majority of public MCP servers carrying exploitable risk with only a small fraction defaulting to OAuth.
The credential-free call is the real primitive
Letting an agent invoke approved APIs without ever holding the key changes the blast radius of a compromise from "everything that credential could reach" to "the specific calls the registry permits". That is the difference between an incident and a disclosure obligation.
None of this is exotic. It is IAM arriving for a new kind of principal.
The part that will get argued about
Binding a persona — a job description tied to a specific model, tool set and guardrails — makes scope explicit and therefore auditable. It also makes it somebody's job to own that document. Which is progress, and is why evaluating agents where actions have consequences is becoming its own research problem.
The organisations getting value did the boring order: gateway, identity, audit trail, then scale. The ones writing incident reports did it backwards.
Snowflake — Enterprise AI Security: Agentic Controls and MCP Governance → · ITECS — MCP Tool Poisoning: Enterprise AI Agent Security in 2026 → · The Agentics — The Enterprise MCP Guide 2026 →