Agent Governance Becomes the New Enterprise Battleground — and a New Displacement Vector
A Fortune report (September 16, 2026) — "AI agents are going rogue. CIOs are racing to put guardrails around them" — documents how agent governance is turning into a product category, a procurement gate, and a fresh way for incumbents to be locked out of accounts.
The starkest data point is Cisco, which is banning third-party AI agents outright. When Cisco debuted its internal agent platform MyAgent in August, it centralized all authorized LLMs, agents, and enterprise data into one platform built on its own infrastructure. EVP of Operations Thimaya Subaiya: "We are going to cannibalize and kill every other AI assistant within the company" — and he "won't authorize any AI agents sold by third-party vendors." Around 90,000 employees have access, with 50% daily adoption within two weeks and ~700 internally built agents approved. That is a 90,000-seat enterprise where every third-party SaaS AI agent is structurally locked out — a migration pattern (to internal builds) that no legacy vendor's AI add-on can win.
Incumbents are racing to sell the control plane:
- Workday has built an "agent system of record" to manage "all non-human identities of the digital workforce" — used internally and sold to customers. CTO Gabe Monroy: "It's got to be delegated down to the team who's driving these agents... and making sure that agent adheres to what we deem responsible behavior" (Workday Q2 FY2027: AI ARR Reaches $600M, Driving 25% of New ACV, as Sana Enterprise and Organic Agents Scale).
- ServiceNow's AI Control Tower is "probably one of the fastest-growing products ServiceNow has ever built" because it "gives a lot of peace of mind for all C-level execs and the board" — president/COO Amit Zavery (ServiceNow: AI Disruption Fears Met by "AI Control Tower" Governance Pivot, Strong Q2 2026 Backlog, and $1B AI ACV). ServiceNow has backed this with the acquisitions of Veza and Armis.
- Salesforce launched its AI Control Plane as part of the Dreamforce "Trusted Enterprise AI Harness" — the governance layer is now table stakes across the big incumbents.
Why buyers are scared: Zscaler CISO Sam Curry: "AI is non-deterministic, it can take initiative, and it is effectively a new form of insider." PwC global chief AI officer Joe Atkinson: "'The agent made me do it' is not going to be a defense from a moral or legal perspective." A Collibra/Harris Poll survey published the same week found 72% of tech decision-makers root-cause AI pilot failures in "an unaligned or poor data foundation," over half report spending significant staff hours manually reviewing agent outputs before launch, and 87% need to re-verify an agent's context — a still-manual, expensive process. Cisco, ServiceNow, and Workday are all members of the Nvidia-led Open Secure AI Alliance, which is developing open-source agent safeguards.
For anyone evaluating the landscape: agent-governance capability is becoming a shortlist criterion, data-foundation quality is the binding constraint on AI ROI, and "agent sprawl" is pushing some CIOs toward centralized internal platforms — a displacement vector that bypasses SaaS vendors entirely and strengthens data-platform and security incumbents (Incumbent Data Moats and the "Build vs. Buy" AI Realignment in the Enterprise Software Landscape).