Ninety-six percent of enterprises already run AI agents in production. Only 12% say they can actually govern them, according to a 2026 OutSystems survey of 1,900 IT leaders. That gap is now the competitive contest in enterprise AI, and three months after Google launched Gemini Enterprise Agent Platform at Cloud Next ‘26 in April, the strategies are diverging sharply.
Google is placing governance controls below the application layer entirely. OpenAI closed its free preview window for Workspace Agents on July 6, moving to credit-based billing. Anthropic’s Claude Cowork expanded from desktop to web and mobile on July 7. Each vendor is making a different bet on what enterprise buyers will prioritize: identity architecture, cost transparency, or accessibility.
Cryptographic Identity at the Infrastructure Layer
The clearest signal of Google’s strategy is where it places its controls. Where Anthropic and OpenAI have largely positioned governance at the application tier through role-based access controls and admin dashboards, Gemini Enterprise places two foundational primitives below the application entirely, according to Tech Times analysis.
Agent Identity assigns every deployed agent a unique cryptographic identifier. Every API call, every data access request, every file operation is signed, logged, and traceable to that identity. Agent Gateway sits alongside it as the central policy enforcement point: a connectivity layer that governs all agent interactions with tools and data sources, manages authentication across agent-to-tool calls, and applies security guardrails via integration with Google’s Model Armor content protection system.
A third primitive, Agent Registry, provides a centralized catalog for discovering, tracking, and managing all agents, tools, and MCP servers across an organization. Google Cloud VP of Product Management Michael Gerstenhaber framed the architectural choice in the platform launch announcement: the original Vertex AI was designed for the complexity of the early generative AI era, but “today, we’re managing a different level of complexity with agents interacting across multiple systems.”
The platform made Vertex AI’s retirement explicit. All future Vertex AI roadmap evolutions will ship under the Gemini Enterprise Agent Platform brand.
The Governance Gap in Numbers
The OutSystems survey quantifies the problem Google is targeting. Of 1,900 IT leaders surveyed, 97% of organizations are already exploring agentic AI strategies and 49% describe their own capabilities as advanced or expert. Yet only 36% have a centralized approach to governance. Gartner’s 2026 Hype Cycle for Agentic AI places agentic AI at the Peak of Inflated Expectations, with governance capabilities maturing well behind deployment intent.
OWASP’s Top 10 for Agentic Applications 2026 identifies goal hijacking, tool misuse, and identity privilege abuse as core threats. Each is an identity-layer failure. Google’s bet on cryptographic identity targets exactly this attack surface.
OpenAI’s Billing Shift
OpenAI’s move is financial rather than architectural. Workspace Agents shifted to credit-based billing on July 6, ending the free preview that had allowed enterprise teams to experiment without cost visibility. The shift to end-of-month billing mirrors the ChatGPT Work pricing model and signals that OpenAI is prioritizing monetization clarity over governance infrastructure.
The timing matters. Forrester Research predicted that 25% of planned enterprise AI spending in 2026 would be deferred to 2027 as CFOs demanded ROI evidence and security teams flagged governance gaps. Moving agents to explicit billing gives enterprise finance teams the cost transparency they need to justify continued spending, but it does not solve the identity and access control problems that Gemini Enterprise is targeting.
Compliance as Competitive Moat
Google’s compliance layer is substantial. The platform holds ISO 42001 certification, the international standard for AI Management Systems, meaning Google’s governance claims have been independently audited rather than self-reported. Native integration with Google Cloud IAM provides granular least-privilege access controls. Built-in Data Loss Prevention logging creates continuous visibility into model inputs and outputs. Regional data residency controls at the Enterprise tier address GDPR, HIPAA, NIS2, and EU AI Act Article 10 requirements.
In a market where every vendor claims enterprise-grade security, independent audit-based certification is the one claim a competitor cannot match by updating marketing copy.
Three Governance Strategies, One Market
The enterprise agent market now has three distinct governance philosophies competing for the same buyer. Google is betting that identity architecture at the infrastructure layer will win security-conscious enterprises. OpenAI is betting that cost transparency and billing discipline will satisfy CFOs. Anthropic is betting that expanding Claude Cowork’s accessibility across desktop, web, and mobile will drive adoption before governance becomes the gating factor.
The OutSystems data suggests the market has not decided yet. With 96% running agents and only 12% governing them, the vendor that closes that gap fastest has the strongest lock-in position.