// news · tools2026-08-22source: Enterprise deployment guidance, 2026

The minimum enterprise checklist has stopped being about the model

SOC 2 Type II, GDPR, HIPAA where applicable, SSO/SAML, data residency, sandbox isolation, audit logging, RBAC, BYOC. Not one item on the list concerns model quality — which is what it looks like when a category finishes becoming enterprise software.

The requirements now stated as the minimum for enterprise agent deployment: SOC 2 Type II, GDPR and HIPAA alignment where applicable, SSO/SAML, data residency options, sandbox isolation, audit logging, RBAC and bring-your-own-cloud.

Nothing on that list is about capability

Every item is a procurement control, and every one of them predates AI by a decade or more. This is the checklist for buying software that touches production systems, applied unchanged to agents — which is both entirely correct and quietly significant.

It means the buying decision has moved out of the hands of the people evaluating models and into the hands of the people who run vendor review. Benchmarks do not appear on this list. Nor does model choice.

Sandbox isolation is the AI-specific one

The rest are standard. Sandbox isolation is on the list because an agent generates and executes code paths nobody wrote or reviewed — the one genuinely new requirement, and the one most likely to be waived in a pilot because it slows things down.

What it means for vendors

A better model does not close a SOC 2 gap. A startup with the strongest agent on the market and no audit report loses to an incumbent with a worse product and a complete compliance file, and it loses in procurement rather than in evaluation. That is the ordinary fate of every enterprise software category, arriving on schedule.

Northflank — Enterprise AI coding agent deployment in 2026 → · Airtable — Best Enterprise AI Agent Platforms for 2026 → · Lyzr — Understanding Enterprise AI Agents: The 2026 Guide → · ITNET — Securing enterprise AI agents: agentic workflows 2026 →