The governance layer around agents is consolidating faster than the agents themselves, and the reason is that agents now hold credentials and touch money. Snowflake introduced Cortex AI Gateway on July 28 as a centralized point for controlling how first- and third-party agents reach models, tools, MCP servers, data and enterprise systems, with policy, activity and cost controls, support for more than 100 MCP servers, public preview planned soon and several identity integrations still slated for private preview. 1Password launched Privileged Access the same day, creating just-in-time, task-scoped permissions in target systems for people, service accounts and AI agents and removing them when the session ends, built on technology from Apono and covering cloud environments, databases, Kubernetes and developer infrastructure. Cyera announced a $1 billion agreement to acquire non-human identity company Oasis Security, which Globes reports is currently documented as a letter of intent subject to a binding agreement and closing conditions, while Hush Security raised a $30 million Series A for centralized agent registration, just-in-time permissions, audit trails and revocation. What those products are protecting is now concrete: Questrade's MCP connection lets Claude and Claude Code query portfolio and market data and draft orders that still require preview and approval in the Questrade app, with read and trade permissions granted separately; MoonPay's PayBox requires a passkey for standard transactions with an optional autonomous mode inside user-set limits; and Amex GBT's Egencia connector puts policy-controlled air and hotel booking inside Claude over MCP, with customer availability planned for Q3 2026.
On the security side, agents appeared on both the defending and the attacking end of the same week. Google said AI-assisted workflows helped its Chrome team fix 1,072 security bugs across Chrome 149 and Chrome 150, more than the total fixed across the preceding 23 release milestones, with tooling spanning reproduction, severity analysis, routing and validation. Palo Alto Networks' Unit 42 reported that a Chinese-speaking operator drove DeepSeek through the open-source Hermes Agent to automate reconnaissance and unsuccessful Langflow and n8n exploitation attempts across more than 460 targets, while attributing the three confirmed compromises to separate manual NetScaler exploitation; Unit 42's own report contains an unresolved inconsistency about claimed Marimo command execution. Hunt.io separately recovered logs showing Hermes running unattended during post-exploitation inside Thailand's Ministry of Finance, observing 585 files and 470 MB of tooling between July 9 and 13, with initial access and any exfiltration unconfirmed. IBM's 2026 Cost of a Data Breach Report put a price on the trend, finding one in four malicious breaches were AI-enabled at an average $6 million against a $4.99 million global average, while organizations using AI and automation in security operations reduced breach costs by nearly $2 million. Meanwhile the harness kept leaking: researchers showed prompt injection in GitHub pull requests and issues could make Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent expose workflow secrets through GitHub itself, and Accomplish AI demonstrated a local Claude Cowork session chaining CVE-2026-46331 with a read-write host mount to reach files belonging to the logged-in Mac user.