CoreWeave Forge and the Agent Identity Gap: Enterprise AI Compliance Gets Messy
On 30 September CoreWeave launched Forge, a platform for building and running AI agents, as enterprises keep discovering that governing those agents is harder than deploying them.

CoreWeave unveiled Forge on 30 September at its Fully Connected event in San Francisco, according to Data Center Knowledge. The company calls it an integrated software platform for developing, running and continuously improving AI models and agents. Forge ships in Free, Pro and Enterprise editions, and it unifies existing products with new software for training, inference, evaluation, observability and agent development.
Agent Lens is where the compliance conversation starts. CoreWeave describes it as an observability and continuous improvement tool for production agents that analyzes traces and generates insights.
At a media briefing, Corey Sanders, the company's senior vice president of product management, said CoreWeave has moved from being a provider of AI-centric infrastructure to "delivering a plethora of AI services to enable customers to build AI applications on our platform." The company also introduced a partner network with validated integrations. Early partners include VAST Data, CrowdStrike and ClickHouse, Data Center Knowledge reported. On hardware, CoreWeave said Nvidia's Vera Rubin NVL72 is now available on its cloud platform, and that AI startup Cognition is the first customer to run workloads on it, up and running in two days. IDC analyst Dave McCarthy told the publication that CoreWeave is trying to separate itself from specialized AI cloud providers such as Nebius, Lambda and Vultr while competing with AWS, Google Cloud and Microsoft Azure.
The governance problem is not specific to one vendor. A framework published by The Hacker News on 28 September describes identity and access management for AI agents as a distinct discipline: each agent should be treated as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration and continuous monitoring. The piece points to OWASP's Top 10 for Large Language Model Applications, which names excessive agency as LLM06, meaning an agent granted broad functionality, permissions or autonomy exercises capability beyond its approved task.
Static role assignment cannot bound that behavior, and configuration review cannot measure it, the framework argues. The gap between what identity platforms express as intended access and what agents actually execute is where compliance programs tend to stall.
The article lists five failure modes: absent ownership, long-lived secrets, unbounded delegation, invisible instantiation and no expiration. Not every environment exhibits all five, but each maps to a control layer an agent identity framework has to supply. Regulators are moving on adjacent ground. The Federal Reserve Board on 24 September requested public comment on two proposals related to establishing a regulatory framework for Board-supervised payment stablecoin issuers under the GENIUS Act, according to the Board's press release. The first proposal would require full backing with permissible reserve assets such as short-term Treasury bills and certain other high-quality, liquid assets, plus standardized capital requirements, risk management standards and rules for firms that safekeep the assets backing stablecoins. The second would create a tailored application process for banks seeking to issue payment stablecoins, including a business plan, financial information, appeals and hearings. The comment period closes 60 days after publication in the Federal Register.
Outside finance, the compliance pressure shows up in procurement. A Unite.AI piece published on 1 October argues that procurement is becoming AI's most powerful regulatory tool, as enterprise buyers impose contract terms that regulators have not yet written into law.
The same day, IBM announced self-hosted deployment for IBM Bob to help enterprises advance AI sovereignty and governance, according to IBM's newsroom. Neither announcement came with enforcement powers, but together they describe where enterprise AI compliance is actually being decided: in contracts and deployment architecture rather than in statutes. Infrastructure choices are part of that picture. Enterprises are increasingly choosing colocation data centers to host AI inference, because inference performs best at higher cabinet densities than most legacy corporate data centers support, according to Data Center Knowledge. Modern colocation facilities support 35 kW cabinets with air cooling and 70 to 150 kW cabinets using optional liquid cooling. The same article cites Foundry's 2026 Cloud Computing Study finding that 74% of enterprises accelerated cloud migrations last year, while VMware's Private Cloud Outlook 2026 indicates that 83% of enterprises have completed or are planning to repatriate workloads from the public cloud, driven by security, cost, compliance and performance concerns.
Power is the constraint regulators have already started to test. North Carolina regulators on 19 September rejected Duke Energy's bid to build a 255-megawatt gas plant in Richmond County, a rare denial for a panel that frequently defers to the state's predominant utility, Canary Media reported.
The 23-page order said a license was premature because data center growth was too uncertain and the risk to consumers too great to justify a greenlight for the facility, estimated to cost $584 million. The order also said Duke "needs to demonstrate how the addition of such new generating capacity and its costs will be consistent with the White House Ratepayer Protection Pledge," signed by Duke and more than 200 other utilities in March. The picture is not uniform. The Hacker News framework and the Unite.AI procurement argument both treat governance as a design problem that enterprises can solve internally. The Federal Reserve's stablecoin proposals, by contrast, are a formal rulemaking with a public comment window. And the Duke ruling is a state commission telling a utility that demand forecasts built on data centers are not reliable enough to justify new fossil capacity. Three different regulators, three different mechanisms, one shared subject.
For enterprises deploying agents now, the practical question is what evidence they can produce. The Hacker News framework makes the point bluntly: configuration findings describe possibility, while telemetry describes what occurred.
CoreWeave's Agent Lens is one commercial answer to that requirement. Whether it satisfies auditors, insurers or regulators is a question Forge's early customers will answer in production, not in a launch keynote.
Sources
11- 01CoreWeave Targets Enterprises with Forge PlatformEN
- 02IAM for AI agents: A Practical Enterprise FrameworkEN
- 03Federal Reserve Board requests public comment on two proposals related to establishing a regulatory framework for Board-supervised payment stablecoin issuers unEN
- 04Duke Energy wants to build a new gas plant. Regulators said not so fast.EN
- 05Enterprises Adopt Colocation for AI and Hybrid Cloud InitiativesEN
- 06Sony brings AI graphics upscaling to the regular PS5EN
- 07Intel's next-gen Nova Lake platforms pass compliance at USB and PCIe standards bodies as launch loomsEN
- 08New BEAD round presents complications, uncertain timelineEN
- 09Solar, Wind, Battery Storage, And Politics — It's ComplicatedEN
- 10Space is everyone's business: Economist Enterprise's 4th annual Space Economy Summit returns to OrlandoEN
- 11US regulators back multi-cancer blood test – but Hong Kong doctors remain cautiousEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.