---
title: "Enterprise Agent Security: What Actually Shipped in 2026"
slug: "enterprise-agent-security-what-shipped-2026"
author: "ibl.ai Engineering"
date: "2026-10-09 11:00:00"
category: "Premium"
topics: "AI agent security, agent identity, Uber ADR, Microsoft Entra Agent ID, Gemini agent, agent governance, enterprise AI, sandbox network policies"
summary: "Agent security stopped being a policy conversation and became production infrastructure over five months of 2026, not in a single week. This post gives the real dates for Uber's ADR, Microsoft Entra Agent ID, OpenAI's textGrain and Google's Gemini agent, maps each human-era control to what replaces it, and shows that the enforcement tier is the part vendors withhold."
banner: ""
thumbnail: ""
linkedin: |
  Agent security is being written up as a single dramatic week. It was not. The real timeline is five months long, and the dates are the interesting part.

  → 1 May 2026: Microsoft Entra Agent ID reached general availability. Agent identities as first-class constructs, OAuth 2.0, MCP and A2A, lifecycle governance, audit logging.
  → 31 July 2026: Uber open-sourced ADR, which stands for Agentic AI Detection and Response, under Apache 2.0. Its MLSys paper reports deployment across 7,200+ hosts and 10,000+ agent sessions a day.
  → 5 October 2026: OpenAI published textGrain, a statistical watermark in generated text, for EU AI Act provenance. API opt-in is live worldwide; the ChatGPT and Codex rollout in the EU is still "over the coming weeks."
  → 8 October 2026: Google Cloud previewed Gemini agent at Gemini at Work 2026. Private preview, not GA.

  Why the timeline matters: capability did not outrun governance by a few days. The controls have been shipping for months, and most organizations have adopted none of them.

  Now the part worth arguing about. Look at what each vendor kept.

  Uber published ADR Discovery, the Sensor, ADR-Bench and the Detector. Prevention, the tier that actually blocks an agent, is absent, and so is the offline ADR Explorer engine that hardens the detector through pre-deployment red teaming. Microsoft gives agent identity to all Entra customers, but extending Entra's security features to agents, Conditional Access included, requires Microsoft Agent 365, licensed per user. Google's own description is that "Gemini is the agent, and the model underneath it is a separate choice," which means the routing decision now sits inside a product you do not operate.

  Two cases, not a law, and worth stating narrowly: in both of 2026's most-cited agent-security releases, the tier that blocks is the tier you cannot get for free. Microsoft's is even metered per seat, on a stack whose job is governing software that does not occupy seats.

  Enforcement can be built at the identity and network edge, and both of these vendors do exactly that. The question is not whether an external control can work. It is who holds the policy, who can read the audit trail, and whether you keep either when the contract ends. That is answered at procurement, not at deployment.

  With ibl.ai you own all the code and the data, self-hosted inside your own perimeter, model-agnostic across any LLM, usage-based with no per-seat pricing, deployable anywhere from your own cloud to a fully air-gapped network.

  #iblai #AgenticAI #EnterpriseAI #AIGovernance #InfoSec #ZeroTrust
---

## The Short Answer

**AI agent security became shipped infrastructure over five months of 2026, not in a single week: Microsoft's Entra Agent ID reached general availability on 1 May, Uber open-sourced its ADR detection system on 31 July, and Google previewed its Gemini agent on 8 October. The enforcement tier is the part vendors withhold or license, which is why on ibl.ai you own all the code and the data.**

The circulating version of this story compresses all of it into one dramatic week. The dates do not support that, and the real timeline carries a better warning.

Capability did not outrun governance by a few days. The controls have been available for months, and most organizations have deployed none of them.

## When did AI agent security actually become shipped infrastructure?

Between May and October 2026, in four separate releases that are usually reported as one.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Date</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What shipped</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Status</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem; font-variant-numeric:tabular-nums;">1 May 2026</td>
      <td style="padding:0.75rem;"><strong>Microsoft Entra Agent ID</strong>, identity and access management for agents</td>
      <td style="padding:0.75rem;">Generally available</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem; font-variant-numeric:tabular-nums;">31 July 2026</td>
      <td style="padding:0.75rem;"><strong>Uber ADR</strong>, Agentic AI Detection and Response</td>
      <td style="padding:0.75rem;">Open source, Apache 2.0</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem; font-variant-numeric:tabular-nums;">5 October 2026</td>
      <td style="padding:0.75rem;"><strong>OpenAI textGrain</strong>, statistical watermarking of generated text</td>
      <td style="padding:0.75rem;">API opt-in live; EU rollout in progress</td>
    </tr>
    <tr style="background:#f0f9ff; border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem; font-variant-numeric:tabular-nums;">8 October 2026</td>
      <td style="padding:0.75rem;"><strong>Google Gemini agent</strong>, a universal agent for work</td>
      <td style="padding:0.75rem;">Private preview</td>
    </tr>
  </tbody>
</table>

Only the last two are genuinely this week's news. [Microsoft Entra Agent ID reached general availability](https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id) in May, after a public preview announced a year earlier.

[Uber's ADR](https://github.com/uber/ADR) was open-sourced at the end of July, and its research paper was submitted in May.

If a vendor tells you agent security is a problem that emerged last week, they are describing their own product calendar rather than yours.

## What is Uber's ADR, and what did Uber not open-source?

ADR stands for **Agentic AI Detection and Response**, and the part Uber kept back is the part that stops an agent.

The [repository](https://github.com/uber/ADR) describes it as an enterprise security system for AI agents, covering employee-facing agents such as Cursor, Claude Code, Codex and GitHub Copilot CLI, and also customer-facing agents such as AI support agents. It is released under Apache 2.0.

The scale in [Uber's MLSys 2026 industry-track paper](https://arxiv.org/abs/2605.17380) is what makes it worth reading rather than admiring: deployment across **7,200+ hosts**, **10,000+ agent sessions daily**, and an ADR-Bench evaluation spanning **302 tasks**, **17 attack techniques** and **133 MCP servers**.

On ADR-Bench the paper reports **67% attack detection with zero false positives**.

Separately, from the ten-month production deployment rather than the benchmark, it reports **97.2% precision** on credential detection across 206 detected credentials, a figure belonging to the prevention layer.

Note the shape of those numbers. Two thirds of attacks detected is a real result for a young discipline, and it is also a third of attacks missed.

Now the withheld tier. The repository publishes ADR Discovery, the ADR Sensor, ADR-Bench and the ADR Detector. **Prevention is absent, and so is the offline ADR Explorer engine**, which the README describes as hardening detection through pre-deployment red teaming.

So the published system finds agents on your network, watches what they do, scores itself against a benchmark, and flags risky behavior. The component that blocks the action stayed inside Uber, along with the engine used to harden the detector.

That is not a criticism of Uber, which published more than anyone else has. It is the pattern worth naming: detection gets published, enforcement does not.

## Why do existing security controls fail on AI agents?

Because every one of them encodes an assumption about a human user, and an agent violates a different assumption in each case.

This is the mapping that matters more than any single product announcement.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Control</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What it assumes about the user</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What an agent does instead</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What has to replace it</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>IAM</strong></td>
      <td style="padding:0.75rem;">A person holds a role and reaches resources</td>
      <td style="padding:0.75rem;">Chains tools in an order nobody granted</td>
      <td style="padding:0.75rem;">An identity scoped to <em>actions</em>, not only resources</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>SIEM</strong></td>
      <td style="padding:0.75rem;">Logins, file access, network connections</td>
      <td style="padding:0.75rem;">Tool calls and reasoning steps</td>
      <td style="padding:0.75rem;">Per-run traces recording retrieved context, not just the result</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>Firewall</strong></td>
      <td style="padding:0.75rem;">Traffic shaped by human-paced apps</td>
      <td style="padding:0.75rem;">Direct API calls at machine speed</td>
      <td style="padding:0.75rem;">Deny-by-default egress, allowlisted per agent</td>
    </tr>
    <tr style="border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>DLP</strong></td>
      <td style="padding:0.75rem;">Someone copies a file</td>
      <td style="padding:0.75rem;">Summarizes the file and passes the summary onward</td>
      <td style="padding:0.75rem;">Limits on where context may travel, not on file movement</td>
    </tr>
    <tr style="background:#f0f9ff; border-bottom:1px solid #e5e7eb;">
      <td style="padding:0.75rem;"><strong>Secrets management</strong></td>
      <td style="padding:0.75rem;">A person is trusted to hold a key</td>
      <td style="padding:0.75rem;">Can print anything in its own environment</td>
      <td style="padding:0.75rem;">Keys the agent can call with but never read</td>
    </tr>
  </tbody>
</table>

The DLP row is the one most teams underestimate. An agent that reasons over a sensitive document and passes a summary to the next tool has moved the information without moving the file, so a control watching file movement sees nothing.

We argued the structural version of this case in [AI agent security is an infrastructure problem, not a feature](/blog/ai-agent-security-infrastructure-problem-not-a-feature). The 2026 release calendar has since turned that argument into a purchasing decision.

## Does giving an agent a formal identity solve the problem?

It solves attribution, which is necessary and not sufficient, and on most stacks it now carries a licensing condition.

[Microsoft Entra Agent ID](https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id) is the most complete implementation shipped: agent identities as purpose-built constructs, agent identity blueprints as templates with parent-child relationships, standard protocols including **OAuth 2.0, MCP and A2A**, and lifecycle governance with full sign-in and audit logging.

That is the right design, and it reached general availability on **1 May 2026**, which means it has been buyable for five months.

The condition is in the licensing.

Agent ID is available to all Microsoft Entra customers, but extending Entra's security features to agents, Conditional Access included, requires **Microsoft Agent 365**, included with M365 E7 and sold as an add-on to E5, A5 and Business Premium, or to the Defender and Purview suites.

Note how that is metered: Agent 365 requires a licence for each user. The enforcement tier is priced per seat, on a stack whose job is to govern software that does not occupy seats.

Set it beside Uber withholding prevention and the honest generalization is narrow. In both of 2026's most-cited agent-security releases, the tier that blocks is the tier you cannot get for free. That is two cases, not a law.

Identity also answers only the question of *who* acted. It does not constrain what the agent could reach, which is the firewall and secrets problem, and it does not record what the agent read, which is the SIEM problem.

## What does Google's Gemini agent change about the security perimeter?

It moves model selection inside a product, which adds a decision to govern that most threat models do not contain.

Google Cloud introduced [Gemini agent](https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026) at Gemini at Work 2026 on **8 October 2026**, described as a universal agent for work. It is in [**private preview**](https://9to5google.com/2026/10/08/gemini-agent-google-cloud/), not generally available; Google's own post states preview status only for the Financial Services and Legal specializations.

Google's own framing is the security-relevant sentence:

"Gemini is the agent, and the model underneath it is a separate choice.

It runs each job on the model that fits best, orchestrating across our Gemini family of models and Claude models from Anthropic today, and other leading private and open models in the future, to deliver optimal quality and lower your costs."

Read that as a security engineer. The agent decides which model receives which job, with which context, at which permission level.

Google's coworker agents also receive their own Workspace account, including an email address on an `@agents.company.com` domain, a calendar, Drive, and a presence in the company directory. The agent operates across web, mobile, CLI, Google Workspace, Microsoft 365 and Slack.

That is a genuinely useful product and a materially larger surface. The orchestration policy, which decides where your context goes, is configuration inside a service you consume rather than a file in a system you run.

## How does ibl.ai put agent security inside the customer's own perimeter?

By shipping the enforcement tier as components you run and own, rather than as a service you call.

With ibl.ai you own all the code and the data.

An agent set to the Virtual Machine Shell sandbox kind runs in a full Linux virtual machine that starts with **no network at all**, and each agent is assigned one of four egress profiles: No Network, Package Registries, Public Internet, or a Custom Allowlist.

A network policy is a named allowlist an organization admin writes once and reuses.

Entries are exact `host:port` pairs with **no wildcards and at most 100 per policy**, and `localhost`, metadata and instance-data hosts, the `.local`, `.internal` and `.localhost` suffixes and reserved IP ranges are refused outright.

Secrets answer the DLP and secrets-management rows directly. Inside the machine, the environment variable holds a placeholder.

The real value is substituted only on encrypted requests to the hosts that secret is allowed to reach, so the agent can call your API and still cannot print, log or leak your key.

A secret can point at a field of a credential the organization already stores, so rotating it once updates every agent that uses it.

The platform also checks the combination: under a Custom profile, every host a secret may reach must also appear in the agent's own network policy, so a secret can never open a path the policy does not.

These have had their own screens since **2 October 2026**, in [an organization-wide Virtual Machine settings tab and a Network Access section on each agent's Sandbox tab](/updates/virtual-machine-settings-policies-and-secrets), with up to 20 secrets per agent.

Creating or changing either is a separate permission that ordinary users do not hold.

On the routing question, [LLM gateway unification](/updates/platform-update-2026-10-02) shipped on 2 October: every endpoint that serves a model, including OpenRouter, Vertex, Foundry, Bedrock and each provider's own API, is a gateway, and a request routes to the highest-priority gateway that can serve it, with your own per-tenant keys preferred over platform keys.

That is the difference the perimeter makes. The routing table is a row in your deployment rather than a policy inside someone else's product.

It is model-agnostic across any LLM, usage-based with no per-seat pricing, and you can deploy anywhere: your own cloud, on-premise, GovCloud, or a fully air-gapped network, where the egress a compromised agent would need does not exist.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY.

---

*Related reading: [AI agent security is an infrastructure problem, not a feature](/blog/ai-agent-security-infrastructure-problem-not-a-feature) for the structural argument, and [the day-one control set for agent governance](/blog/agent-governance-new-shadow-it-day-one-controls) for what to turn on before the first agent reaches production.*

*Sources: ADR's expansion, scope and Apache 2.0 license from [github.com/uber/ADR](https://github.com/uber/ADR), its release date from [the repository's sensor-v1.0.0 release](https://github.com/uber/ADR/releases), and the deployment and ADR-Bench figures from [Uber's MLSys 2026 paper, arXiv:2605.17380](https://arxiv.org/abs/2605.17380); Entra Agent ID's general availability from [Microsoft Learn](https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id) and its protocols and licensing from [the product overview](https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id); the Gemini agent announcement and quotation from [Google Cloud](https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026), its private-preview status from [9to5Google](https://9to5google.com/2026/10/08/gemini-agent-google-cloud/); textGrain's mechanism, rollout scope and stated limits from [OpenAI's approach to EU text provenance rules](https://openai.com/index/eu-text-provenance/) and [the textGrain paper](https://cdn.openai.com/pdf/e9508624-d767-41b6-a26d-e34ca798ada6/textgrain-entropy-calibrated-watermarking-for-language-model-text.pdf).*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
