A hyperscaler is now claiming this ground and its cross-cloud registry is still a preview that wants delete permissions on a firm’s other clouds’ agents. Whatever a firm buys, a registry that maps to no enforcement point is a compliance artifact, not a control.

What this category solves (and what you did before it)

The promise is one place for inventory, risk assessment, policy workflow and framework mapping: ISO/IEC 42001, NIST AI RMF, the EU AI Act. Before it: spreadsheets and screenshots, which is also what several of these products still are underneath (frameworks).

Who is claiming this ground

The platform-native option is real and shipping. Microsoft Agent 365 reached general availability on 1 May 2026, and its breadth claim holds up at the register-and-observe tier: auto-instrumentation for OpenAI, LangChain and Agent Framework, manual instrumentation for anything else, and a path to send telemetry over raw OTLP/HTTP with no SDK dependency at all.

The marketing sentence hides three limits. Deeper capabilities are not SDK-agnostic: agents registered as Entra applications must first create an agent identity blueprint, and the Purview, Defender and Entra governance benefits flow only to blueprint-based agents. The SDK covers Python, Node.js and .NET, with Java documented as not yet supported. And the top tier, an agent with its own identity, mailbox, Teams presence and org-chart entry, is restricted to preview participants rather than generally available.

Cross-cloud registry sync is the interesting part and the least mature. Microsoft’s own documentation says agents built on Google Vertex AI or Amazon Bedrock can be pulled into the registry with no SDK integration, no blueprint and no code changes. That is accurate and it is a genuine claim on the cross-platform governance plane. It is also labelled preview, not for production, covers exactly four external platforms (Bedrock, Vertex AI, Salesforce Agentforce, Databricks Genie), and was manual, button-triggered sync with scheduled sync listed as future work.

The part a reviewing CTO should be told before anyone clicks connect: “no code changes” is not “no setup.” It requires an admin-created IAM user or service account in the firm’s other clouds, holding list, get, invoke and delete permissions on agents, with long-lived access keys or client secrets held by Microsoft. That hands one vendor’s governance plane the ability to delete agents in the firm’s other clouds, secured by a static credential, and the trade may still be the right one, but it is not a formality.

The HR platforms want it too. At least one HCM vendor markets an agent system of record: register through retirement, identity permissioning, observability, cost and ROI, a gateway control point for third-party agents, with explicit anti-sprawl framing. Its pitch is “just like you’d manage your people,” a framing that a randomized experiment found measurably reduces human accountability; see citizen developer roles.

The standalone cross-platform layer is, so far, a thesis. Its most-quoted advocate is a venture partner explaining why startups can compete with hyperscaler-native tooling, and his firm is invested in the standalone vendor the article is about. That makes it a view to attribute rather than adopt.

What actually differentiates products

Two questions, and neither appears on a feature matrix.

Does the inventory discover agents, or wait to be told about them? A registry populated by self-declaration governs the population that already cooperates. See shadow agents.

Does the policy connect to an enforcement point? A tier assignment that no gate consumes and no runtime control reads is a record of an intention. This is the whole argument of the page: the case for buying governance tooling is the evidence trail, and the enforcement comes from the control plane.

The skepticism this category has earned elsewhere

Attestation businesses have a documented failure mode, and the precedent is regulator-established rather than commentary. The FTC found that the leading online privacy-seal certifier had failed to conduct the annual recertifications it sold for nearly a thousand sealed companies between 1997 and 2013, and had continued describing itself as a nonprofit for years after converting to for-profit; the proposed order carried a $200,000 disgorgement and a decade of compliance reporting.

Worse than the non-performance is the selection effect. Independent research found sites carrying that certifier’s seal were more than twice as likely to be untrustworthy as uncertified sites, a difference that held when restricted to complex commercial sites; a seal nobody audits is empirically worse than no seal.

That is 2006-era research about web privacy seals, and nobody has measured adverse selection in AI attestation. It is a precedent and an argument by analogy. It survives as one question for a vendor: who checks that you did the check?

Tier

Day 2, and situational. The registry-and-tiering practice is Day 1 and lives in tooling most firms already own. Buying a platform is justified when the evidence burden (an examiner, a client diligence questionnaire, an ISO 42001 audit) exceeds what a spreadsheet can defend, not when the agent count grows.

The enterprise bar

SOC 2 Type II, ISO 27001, deployment mode, SSO and SCIM, RBAC, environment separation, exportable audit logs, zero retention, no-training terms, audit rights, viability and exit path. Three category-specific additions: what credentials does this product hold in the buyer’s other systems and with what permissions; can the inventory be exported in full, including history, on exit; and name the enforcement point each policy maps to, or accept that it maps to none.

M&A state and category maturity

Regulatory demand is pulling products to market faster than agent-discovery capability is maturing. That is the standard recipe for a category that consolidates into GRC suites. The more immediate structural risk is different: the hyperscalers are giving away at platform level what the independents sell, and the independents’ answer, a genuinely cross-platform layer, is the thing Microsoft is now previewing.

Buyer sentiment supports the caution without supporting a dramatic reading. In a survey of 496 executives with direct AI-governance responsibility, 36% named gaps in responsible-AI tooling and control as an obstacle to scaling agentic AI and 28% named an immature vendor or ecosystem landscape. Those figures come from a choose-all-that-apply item, and vendor immaturity ranked seventh of nine, below security and risk concerns (62%), regulatory uncertainty and technical limitations (38% each), budget (34%) and unclear business value (32%); vendor-landscape immaturity is a real second-tier complaint, not a verdict.

Where the category is immature

Discovery, enforcement linkage, and audit of the auditor. Until a product can find an agent nobody declared and make a tier assignment change what that agent can do, this category produces excellent evidence of governance and very little governance.

See also