A single week of industry reporting, read closely, described one thing the enterprise does not yet have. This is that argument, and where the answer already exists.
Beneath the Act. Above the Machine. Impossible to Bypass.
A single week of industry reporting, read closely, converges on one thesis: enterprises are moving from experimenting with AI to institutionalizing it, and the layer that decides who wins is not the model. It is the control plane that governs what agents may do.
The clearest proof is not a lab. It is BNY, the oldest bank in the United States, whose chief executive now describes an in-house AI platform that reads his calendar, his mail, and his documents, and coaches his day. The firm reports moving from roughly one hundred digital employees to well over one hundred and thirty, put thousands of staff through an internal AI bootcamp, and spent on the order of 3.8 billion dollars on technology in a single year, close to a fifth of revenue.
What makes BNY credible where most enterprise AI stories are noise is that it paired deployment with operating-model change: a platform integrated with internal data and compliance systems, explicit human supervisors for agents, employee numbers and roles for the agents themselves, and task-specific performance review. This is not a copilot. It is a workforce.
A copilot answers questions. An agent executes bounded workflow steps. A digital employee is a governed production identity with a defined role, permissions, an owner, a performance envelope, an audit trail, and a kill switch. Most firms giving agents names and avatars have not built that last definition. Naming an agent does not make it accountable. Its owners, its policy, and its evidence do.
The same executive's instinct, that AI can finally see across every thread in the firm at once, is exactly right and exactly the risk. Cross-domain insight requires cross-domain access. The moment a platform can read calendars, mail, documents, staff feedback, and operating data, it becomes the single highest-value target for both mistakes and misuse in the enterprise. Capability is no longer the hard part. Authority is.
Traditional identity and access management asks one question: which person may access this system. Agent governance has to answer a far richer chain, and most organizations cannot answer even the first link of it:
The critical error is to conflate an agent's role with its authority. Calling an agent a research analyst or a finance operations specialist says nothing about what it may read, decide, or execute. The high-risk cases are predictable: broad data access joined to production write permission, third-party tool connections, and standing credentials that outlive the person who granted them. An agent that only reads a curated internal library is manageable. An agent that reads untrusted email, reaches customer records, sends messages, and touches financial or identity systems is a different class of system, even when both wear the same digital-employee badge.
Security vendors are circling the same conclusion from the other side. One argues, correctly, that you cannot inventory every agent because they spin up faster than any list can track, so you should control what an agent can reach the moment it acts. That is right but incomplete. You do need a continuously generated inventory, just not a hand-maintained spreadsheet. The honest pattern is three moves at once: discover dynamically, authorize continuously, and prove every consequential action afterward.
Strip away the vocabulary and the market is describing one piece of infrastructure that does not yet exist inside most enterprises: an agent governance control plane. Read from independent sources, its shape is consistent. It has six control layers.
| Control layer | What must be controlled |
|---|---|
| Identity | Every agent, sub-agent, tool, workload, and delegated session carries a unique non-human identity. |
| Authority | Least privilege, time-bound credentials, scoped tokens, and explicit delegation chains rather than standing access. |
| Action | Policy enforced at each tool or API call: allowed target, data class, amount, operating window, approval, rate limit. |
| Data | Retrieval permissions, purpose limits, residency, classification, retention, and egress control. |
| Evidence | An immutable trail: context reference, model and version, tool call, authority decision, output, reviewer, outcome. |
| Lifecycle | Registration, owner assignment, testing, production approval, monitoring, revocation, decommissioning. |
The framing is not inventory or access control. It is a verifiable chain of consequence: who or what acted, under whose authority, against which data, using what model and tools, within which policy, to what end. For an enterprise product, that chain is the wedge. Everything else is a chat interface.
The uncomfortable fact is that the six-layer architecture the market is describing in blog posts is, for ICA, already engineered and running. The table below maps the market's own control layers onto what ICA does today. The right column is not a roadmap. It is the product.
| Control layer | What ICA does | Status |
|---|---|---|
| Identity | Every agent and sub-agent is a registered identity with a decentralized identifier. No agent operates without one. | Live |
| Authority | A deterministic authority check, evaluated from the principal, the tool, the data, and the policy, not from model output. Scoped execution tokens and purpose binding gate every governed call. | Live |
| Action | A preflight gate at the tool boundary. Denied or halted calls never run. A live kill switch quarantines an agent on demand. | Live |
| Data | Purpose-bound access and caller intersection, so an agent's reach is confined to the purpose it was authorized for, with tenant isolation enforced at the data layer. | Live |
| Evidence | Every consequential action seals a signed receipt into an append-only ledger, hash-chained, anchored, and provable after the fact with a Merkle inclusion proof. Verification fails closed. | Live |
| Lifecycle | Agents are governed before production, monitored continuously, and can be retired or revoked. Standing is sourced from the real credential, never asserted. | Live |
The research thread that prompted this paper pushed past evidence logging into the hard problems: tamper-evident chains, immutable-ledger anchoring, efficient inclusion proofs, and privacy-preserving attestation. Those are not future features. ICA already answers a question the market has not yet thought to ask: was the agent's authority valid at the exact moment it acted, not merely valid now. The ALEETH as-of-execution verifier reconstructs authority at the time of the action and returns a signed verdict anyone can check. That is the difference between a log and proof.
Everyone will soon be counting agents. It is the wrong number, and BNY's own framing hints at why. The metric that will separate the safe institutions from the exposed ones is not how many agents a firm runs. It is what share of agent actions are governed, attributable to an accountable human, evaluated against policy, and reconstructable end to end.
That single sentence is the right diagnostic. It reframes a firm's self-assessment from a comfortable count of pilots into an honest question about proof, and ICA is the answer that already carries the receipts. The scoring of agent risk is equally simple, and worth running on your own estate:
Agent risk ≈ Data sensitivity × Action impact × Autonomy × Reachability
Read against that formula, a research agent on a curated library scores low. An agent that reads untrusted mail, reaches customer data, sends messages, and updates financial systems scores at the top. Any firm that runs that math on its own estate arrives at the need for a governed control plane on its own.
If the shift is real, and the reporting says it is, the questions a board should be asking change. Not how many agents are we running, but a harder set:
This is the layer ALEETH built, and its sharpest claim is the one the market has not yet thought to ask for: proof that an agent's authority was valid at the exact moment it acted, not merely valid now. That is the difference between a log and proof, and the difference between watching agents and governing them.