Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

Enterprise AI agents get a control plane, a permission algebra and an identity layer

OpenClaw open-sourced a control plane for persistent AI agents on 30 September. Two other projects published deterministic guardrails and an agent identity protocol the same day. All three are aimed at the same gap: agents are easy to run and hard to audit.

AI & modelsExplainerRachel NwosuPublished: 30 September 20266 min readSources 9
Enterprise AI agents get a control plane, a permission algebra and an identity layer

The newest piece of enterprise agent plumbing landed on 30 September. That day the OpenClaw Foundation published OpenClaw Enterprise (OCE), an open source, vendor-neutral control plane for persistent agents. The project says it is being built in the open ahead of a 1.0 release later this year. You can self-host it today with docker-compose or Kubernetes.

OCE started inside OpenAI and was donated to the OpenClaw Foundation, where Red Hat and NVIDIA now develop it alongside the foundation, according to the project's blog post. The same post says OCE is being piloted internally at Red Hat and OpenAI. OpenAI already runs OpenClaw agents with full access to codebases and plugins, the post adds. That detail shows how far the company has moved from treating agents as a demo.

Governance is the blocker, not capability

The framing in that post is worth reading closely. OpenClaw admits that almost a year after launch, "the actual deployment of persistent agents remains limited," and that IT in most organizations defaults to banning agentic platforms outright. OCE is meant to answer a narrow question: how do you deploy capable agents in a sensitive environment without stripping the capabilities that made them useful. The answer on offer is multi-tenancy, hard security boundaries between trusted and untrusted workloads, sandboxing, LLM-based reviews, fine-grained permissions, and auditability across the agent lifecycle. It is a long list, and every item carries its own operational cost.

Gartner makes a related, blunter argument. In research covered by The Register on 30 September, the consultancy predicts that by 2028, 70 percent of enterprises will abandon agentic AI systems built with vendor assistance as costs climb and customers struggle to modify the technology without outside help. Gartner's target is what it calls forward-deployed engineering, where a vendor embeds engineers with a customer to build and deploy software to its requirements. Rapid early progress, the argument goes, can leave the customer dependent on expensive external expertise.

"The best-scoped FDE engagements have clear guidelines on governance, business value delivery, IP ownership, project co-ownership, knowledge transfer, and an exit strategy from day one," Gartner senior director analyst Mukul Saha said, according to The Register.

Gartner also predicts that through 2028, fewer than 20 percent of these engagements will turn recurring customer requirements into features in the vendor's core product. It warns of "FDE washing," where ordinary consulting is marketed as something more specialized. The Register notes this is not Gartner's first warning of the kind. Earlier forecasts covered generative AI projects exceeding budgets and 40 percent of AI agent deployments being scaled back or decommissioned over governance problems.

Two more attempts to make agents answerable

Also on 30 September, a project called OpenAPPA published deterministic guardrails that sit between an agent and its tools. They answer one question before every action: is this data allowed to go to this destination. The GitHub repository describes the system as powered by APPA, an Agentic Permissions Policy Algebra. APPA tracks the sensitivity and trust of everything an agent reads, then checks each tool call against that record before the call runs. The pitch is that classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.

The project's own benchmark numbers, published on the repository, claim no scored attack succeeded against OpenAPPA in 1,320 evaluations while it completed 88 to 90 percent of tasks. The same table puts Microsoft FIDES at 41 percent task completion with 31 percent of attacks succeeding, and Claude Code auto mode at 90 percent completion with 10 successful attacks across two suites. Those are vendor-published figures on the vendor's own benchmarks. The repository says the work is a preview and an RFC, with config and wire surfaces that may break without shims. The underlying paper was accepted to the NeurIPS 2026 Workshop on Agents in the Wild.

A third project, UAI, went up the same day with an open protocol for agent identity, authorization and independently verifiable accountability. It splits the problem into four artifacts. A UAI-ID for who the agent is. A credential binding it to an owner. A passport for time- and jurisdiction-bounded authorization. And signed action attestations recording what it actually did. The README is careful about what this does not do. "UAI does not claim that an AI agent is safe," it says, only that actions become attributable and checkable. The design deliberately avoids a single global authority and points instead at federated registries. The browser verifier is meant to validate evidence locally rather than asking the registry whether its own evidence is valid.

The market is moving faster than the controls

Consumer-facing agents are already shipping at a different tempo. DoorDash announced on 30 September a text-to-order agent that lets users place orders through Apple Messages, handling prompts like "order my usual" and group orders with mixed dietary preferences, according to TechCrunch. The company is opening a US waitlist and separately said it will begin testing delivery drones with select restaurants in Northern California. DoorDash is positioning the agent against Uber Eats and Grubhub.

Meta's Muse, announced earlier in September, is the other big consumer-to-enterprise push. Tailscale's blog on 30 September offers the most concrete look at how such an agent gets fenced in. Muse runs in a Linux virtual machine walled off from user data and external services by default, with connectors for calendar, contacts, smart home devices, Gmail, Outlook, Spotify and Meta's own apps. Tailscale's integration makes Muse a node on a user's tailnet, where the usual grants, tags and access controls apply. Tailscale also flags the obvious risk: prompt injection will still slip through, and connecting an agent that can see self-hosted services and use SSH raises questions users should answer deliberately.

Elsewhere on 30 September, a self-hosted inference engine called Magnitude launched on GitHub. It claims up to 2x faster than llama.cpp with 92 percent faster decode on Metal and 19 percent on CUDA, and 27 percent less memory per agent. A tool called git-dedup, published the same day, claims large checkouts 6x faster and a 70 percent cut in Git storage, from 35.5 GB to 11.1 GB across 117 checkouts, aimed squarely at fleets of coding agents. DevNavigator reported on Vercel's 25 September State of agent skills report, which says skills.sh reached more than one million listings and nearly 280 million recorded installs in seven months. It notes those figures describe registry activity rather than proven business value.

The through-line is unglamorous. The capability side is crowded and moving weekly. The accounting side, who owns the agent, what it may touch and who can prove what it did, is where the newest work is landing. Whether any of these three protocols gets adopted is a different question. Two of them are previews, one is an early single-vendor pilot, and Gartner's forecast gives enterprises until 2028 to decide.

Comments 0

Sources

9
  1. 01OpenClaw Enterprise – The Open Agent PlatformEN
  2. 027 in 10 enterprises expected to abandon vendor-built agentic AI by 2028EN
  3. 03OpenAPPA: Deterministic guardrails that don't break agentsEN
  4. 04UAI – An open protocol for identity and accountability of AI agentsEN
  5. 05DoorDash launches an AI agent you can text to order foodEN
  6. 06Agent, your network: How Meta's Muse agent works with TailscaleEN
  7. 07Launch HN: Magnitude (YC S25) – Self-optimizing inference engine for agentsEN
  8. 08Git-dedup – faster and smaller checkouts for agentic workflowsEN
  9. 09Agent Skills: 4 Powerful Ways to Improve Enterprise AIEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.