Why agents changed the question
Okta's 2026 research on agents at work puts numbers on the gap. 91 per cent of organisations say they already use AI agents, 10 per cent have a mature strategy for non-human identity, and 88 per cent report a suspected or confirmed agent security incident. A vendor commissioned that survey, which is worth knowing, and the shape of it matches what shows up in architecture reviews. Agents went into production first. The identity and control work is arriving second.
What changed in 2026
Four dated facts, because this page is only useful if its facts carry dates.
- 9 December 2025: OWASP published its Top 10 for Agentic Applications, giving the market its first agent-specific risk vocabulary, ASI01 to ASI10, built from documented 2025 incidents including EchoLeak, tracked as CVE-2025-32711.
- Q1 2026: IBM added Agent Monitoring and Insights to watsonx.governance, tracking agent decisions and behaviour in production with threshold alerts. IBM's page would not load for us on 2 September 2026, so this comes from search results.
- By 2 September 2026: Credo AI's product page describes a dedicated Agent Governance module and a runtime governance module built on trace ingestion, with enforcement integration listed as planned.
- 27 July 2026: the Digital Omnibus entered into force and deferred the EU AI Act's high-risk obligations for Annex III systems to 2 December 2027. Transparency duties under Article 50 still apply from 2 August 2026.
AI inventory and registry tools
These catalogue what exists: discovery, ownership, risk classification and a record of what was assessed when. Credo AI is the name that comes up most, and its product page describes an AI registry with discovery, risk intelligence, a compliance and policy engine carrying framework packs, and a governance assistant called GAIA. Buy this group when nobody can currently say how many AI systems the organisation runs, or who owns them. It answers what exists, and does not decide what runs.
GRC and policy suites
These assess AI systems, document the controls and produce attestations. IBM watsonx.governance sits here, with model inventory, monitoring for bias and explainability, and coverage across IBM technologies and third-party platforms. Holistic AI reaches the same job from a different direction, through more than 100 automated tests for bias, hallucinations, red teaming and adversarial probes, plus continuous monitoring for drift and discovery of shadow AI. Buy this group when the obligation is to demonstrate a control environment to somebody external.
Runtime enforcement platforms
These govern what agents do while they run. The product holds the credential away from the agent, evaluates a proposed action against a policy, refuses or escalates it, and records what happened. Difinity sits in this group. Buy it when an agent is going to act in a system that matters and somebody has to be able to say, afterwards, exactly what it was allowed to do and why.
Where each one fits
Four short decision rules, which between them decide most shortlists.
- If nobody can list the AI systems in use, start with AI inventory and registry tools. Nothing else works without that list.
- If the pressure is an external obligation, an audit or a certification programme, then GRC and policy suites are the group that produces what the assessor asks for.
- If an agent is about to act in a production system, only a runtime enforcement platform changes what happens next. The other two document it.
- If two of these are already in your shortlist from the same group, one of them is redundant.
The mistake to avoid in 2026
Buying two products that describe, and none that decides. This was easier to spot two years ago, when only one group claimed agent coverage. Credo AI ships an Agent Governance module now. IBM ships agent monitoring with alerts. Both are genuine coverage of agent behaviour, and both describe the run rather than deciding it. Sort the shortlist by the verb before you sort it by the feature list.
The scaling test
Ask what the hundredth agent inherits. If governance is configured per deployment, the tenth agent is affordable and the hundredth is not, and the failure mode is quiet: teams start shipping agents around the governed path because the paperwork is slower than the build. Put it to the vendor directly. What does a team have to do by hand before a new agent is governed? If the answer is a list of steps, multiply that list by your agent roadmap and see whether the number still looks reasonable.
Where Difinity fits
The decision happens at the tool gateway, which holds the credential and decides before an action runs. It is not reachable from the internet, so no customer calls it and neither does an agent. Least privilege is structural rather than a per-feature setting: an agent's authority is the intersection of what its version binds, what the caller is entitled to, and what the use case permits, and an agent version can bind at most 32 tools.
What that means at scale
Evidence is append-only and cannot be edited. The run trail records each guardrail verdict, each proposed action, the gateway's decision, approvals asked for and answered, and the outcome, and a repeated write is rejected rather than stored twice. On the scaling test: chat runs and agent runs share one enforcement pipeline, so a new agent inherits it rather than having its governance rebuilt per deployment. Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification.
How to run the evaluation itself
This page maps the market. The criteria, the tests for each one, and a 90-minute script you can run against your own workflow are in the companion guide to evaluating an agent governance platform, linked below. Give every shortlisted vendor the same workflow and the same evidence request, and compare what the target system looks like afterwards rather than what the demo looked like.
What would change this answer
Three things. The EU AI Act's high-risk dates moved in July 2026 and could move again. OWASP's agentic categories will be revised as the incident pattern changes. And several products that only read traces today have enforcement on their roadmaps, which would blur the sorting above. One limit worth stating: capability statements about other vendors here come from what those vendors publish, and in IBM's case from search results, because its own page would not load. Nothing here rests on a console we logged into.
Frequently asked questions
What is an AI agent governance platform?
A platform that gives each agent an identity and an owner, binds it to the authority its job needs, decides whether a proposed action may run, keeps credentials out of the agent's reach, and preserves a record of what was attempted and what resulted.
Which vendors are in this market in 2026?
Credo AI anchors the AI inventory and registry tools. IBM watsonx.governance and Holistic AI sit among the GRC and policy suites. Difinity is a runtime enforcement platform. Identity vendors cover the agent identity slice alongside these, rather than replacing any of them.
Do all agent governance platforms enforce policy at runtime?
No. Several describe runtime governance as reading traces and evaluating them continuously, which happens after the action. Ask specifically whether the product can refuse an action before the target system changes, and ask to see a record of a refusal.
When do the EU AI Act obligations apply to agents?
Transparency duties under Article 50 apply from 2 August 2026. High-risk obligations for Annex III systems were deferred to 2 December 2027 by the Digital Omnibus, which entered into force on 27 July 2026. Which duties apply to your agent depends on the classification of the system it is part of.
Does a governance platform make an organisation compliant?
No. It can contribute operational controls and evidence to a wider programme of legal review, risk management and audit. The obligations, the classification and the assurance work stay with the organisation.
Sources and further reading
- OWASP Top 10 for Agentic Applications, published 9 December 2025 (opens in a new tab)
- Okta, AI Agents at Work 2026, commissioned research (opens in a new tab)
- Credo AI product page, fetched 2 September 2026 (opens in a new tab)
- Holistic AI platform overview, fetched 2 September 2026 (opens in a new tab)
- IBM watsonx.governance product page, direct fetch blocked 2 September 2026 (opens in a new tab)
- European Commission, AI Act implementation timeline, fetched 2 September 2026 (opens in a new tab)
- NIST AI Risk Management Framework 1.0, January 2023, and the Generative AI Profile, NIST AI 600-1, July 2024 (opens in a new tab)
- ISO/IEC 42001:2023, AI management systems (opens in a new tab)