Agent governance stopped being an argument and became a product line, with a single week producing a control plane, a permissions model, an acquisition and a funding round aimed at the same problem. Snowflake introduced Cortex AI Gateway on July 28 as a centralized layer for controlling how first- and third-party agents reach models, tools, MCP servers, data and enterprise systems, with policy, activity and cost controls and support for more than 100 MCP servers; it is planned for public preview soon and several identity integrations remain planned for private preview, so production enforcement is not yet demonstrated. The same day, 1Password launched Privileged Access, applying just-in-time, task-scoped permissions to people, service accounts and AI agents by creating permissions in the target system on request and removing them when the session ends; Cyera announced a $1 billion agreement to acquire non-human identity company Oasis Security, currently documented as a letter of intent still subject to a binding agreement; and Hush Security raised a $30 million Series A for centralized agent registration, just-in-time permissions and revocation. MinIO's AIStor Memory, announced July 29, addresses the adjacent gap by separating durable organizational knowledge, active workspace state and credential custody into distinct services, though the announcement carries no pricing, retrieval benchmarks or independent production results. Microsoft's contribution is narrower and slower: a Purview DLP rule in preview that excludes externally received email from Microsoft 365 Copilot grounding by checking sender-domain metadata, with general availability listed for January 2027. Read together, these are answers to the same question, which is what an agent is allowed to touch and who can prove it afterwards, and the honest status on nearly all of them is preview rather than production.
The economics moved in the opposite direction from the governance spend, which is the tension worth planning around. OpenAI said its models reach more than 1 billion active users and more than 2 million businesses, company-reported figures with no stated measurement window, and cut GPT-5.6 Luna to $0.20 per million input tokens and $1.20 output; Amazon Bedrock made the same Sol, Terra and Luna family generally available through the OpenAI Responses API with a 272K-token context window and prompt caching whose reported 90% cached-input discount matters most for exactly the long-context agent traces this hub cares about. Moonshot AI published the weights of its 2.8-trillion-parameter Kimi K3 on July 27, and ABC documented individual Australian companies routing simpler work to cheaper models. But provenance now has a procurement cost: on July 31 US House committee chairmen requested documents from DoorDash about its evaluation and deployment of Chinese AI systems, following disclosures that it used Moonshot's Kimi K2.6 for lower-level work, a request that alleges no wrongdoing but extends congressional scrutiny from model developers to the enterprises that adopt them. Cheaper tokens are also not translating into controlled spend, with Harness estimating 26% of enterprise AI spending wasted and 52% of its 700 respondents lacking a clear AI-cost owner. The consolidation around all this continued, with Nscale signing a definitive agreement for Anyscale expected to close in the second half of 2026 on undisclosed terms, Bloomberg agreeing to acquire Canoe Intelligence, and Sierra acquiring Takeoff to build a long-horizon agent platform called Horizon. The starkest signal was monday.com's July 22 decision to cut about 20% of its workforce, roughly 620 people, while reorganizing around its AI Work Platform and raising its non-GAAP operating-margin outlook to about 15%, taking $45 million to $55 million in net restructuring charges for a bet whose product and customer effects are still unproven.