Tag: agentic AI

  • AI Agents as Digital Actors: Governance Lags Adoption

    AI Agents as Digital Actors: Governance Lags Adoption

    Info-Tech Research Group, an IT research and advisory firm, published new research on 28 August 2026 from Arlington, Virginia, arguing that enterprise AI agents should be governed as a distinct class of digital actor rather than as ordinary IT assets or as earlier generative AI models. The blueprint, Govern Enterprise AI Agents While Preserving Innovation, sets out a three-phase framework for managing agent identity, access, autonomy limits and ongoing oversight.

    The firm names five governance gaps it says organizations hit as agent use spreads: shadow AI, capability mismatch, runtime drift, unmanaged access and ambiguous ownership. The blueprint ships with a governance playbook, a charter example, an executive dashboard template and a glossary. Info-Tech says it serves more than 30,000 IT, HR and marketing leaders and has operated for nearly 30 years.

    Executive Summary

    The core claim is narrow and worth taking seriously: an AI agent does not merely produce output, it takes action. It can call systems, trigger workflows and make decisions on its own, at machine speed. That breaks the assumption underneath most enterprise AI governance to date, which is that a human reviews and approves a model’s output before anything consequential happens. Info-Tech’s position is that one-time approval gates cannot govern something that keeps operating after the gate.

    Altaz Valani, principal advisory director at Info-Tech, frames the problem in the release as a mismatch on both sides: agents cannot be governed like IT assets because they act across systems, and they cannot be governed like employees because, in the firm’s words, they move quicker and lack emotions, conscience and consequences. The practical translation is that the controls that work on people — training, incentives, accountability, the fear of being fired — have no purchase here. What is left is identity, credentials, permissions, monitoring and a defined kill switch.

    That is not a new discipline. It is the same control discipline that regulated supply chains already run under. On the same day, Nelson Miller Group announced it had earned Cybersecurity Maturity Model Certification (CMMC) Level 2, the US Department of Defense standard that obliges defense manufacturers to demonstrate control over access to sensitive information. The difference is that defense suppliers are made to prove those controls by contract, while most enterprises are deploying agents years ahead of anything comparable.

    Approval Gates Do Not Govern Things That Keep Moving

    Most enterprise AI governance was designed for a request-and-response world. A team proposes a use case, a committee reviews it, a model is approved, and a human checks the output before it becomes a decision. That control model has a hidden dependency: the risk sits still long enough to be reviewed. An agent breaks the dependency because the approval happens once and the behaviour continues indefinitely, across systems, with credentials attached.

    Info-Tech’s five named gaps are really five ways that assumption fails. Shadow AI means agents created outside sanctioned tools that IT does not know exist — the same problem as unsanctioned SaaS, except the unsanctioned thing holds credentials and acts. Capability mismatch means an agent’s autonomy and access outrun the validation and monitoring applied to it. Runtime drift means an agent quietly expands its scope as tools, prompts and permissions change, so the thing running in month six is not the thing that was approved in month one. Unmanaged access means service accounts and permissions let an agent do more than anyone intended. Ambiguous ownership means that when something goes wrong, no one is clearly accountable.

    None of these are exotic. They are the standard failure modes of any privileged non-human identity, which is why the useful reading of this research is deflationary rather than alarming: agentic AI is largely an identity and access management problem wearing new clothes. The genuinely new part is speed and volume. As Valani notes in the release, many people will have multiple agents working for them — which means identity populations that were once measured in employees start being measured in some multiple of employees.

    The CMMC Parallel: Regulated Sectors Already Do This, Under Contract

    The comparison worth drawing is with the defense industrial base. CMMC is the US Department of Defense’s framework for verifying that contractors and subcontractors protect sensitive government information; Level 2 aligns with the NIST SP 800-171 control set for controlled unclassified information, covering access control, identification and authentication, audit and accountability, configuration management and incident response. Nelson Miller Group’s 28 August 2026 announcement that it earned Level 2 certification is, in commercial terms, a supply chain credential: it is how a manufacturer stays eligible for programs that handle protected data.

    Strip away the acronym and the CMMC control families read like a specification for governing agents: know every identity, prove who owns it, restrict what it can reach, log what it did, detect when it drifts, and be able to respond. The defense supplier does this because a contracting officer requires it and an assessment verifies it. The enterprise deploying a fleet of agents has no equivalent forcing function — no customer withholding a purchase order, no assessor arriving to check the evidence.

    That asymmetry is the real story. Control discipline in enterprise technology almost never arrives because it is a good idea; it arrives because a contract, a regulator or an insurer demands proof. Agentic AI is currently in the window between capability and requirement. Firms in regulated supply chains have an unusual advantage here: the muscle memory of proving controls to a third party transfers directly to governing non-human identities. Firms without that history are building the practice from a standing start, and doing it while the agents are already running.

    What the Release Substantiates, and What It Does Not

    This is analyst research promoting a paid deliverable, and it should be read as such — evenly, without either deference or dismissal. What is substantiated is a structured method. The three phases are specific and sequenced: Phase 1 establishes governance authority, decision rights and a small set of enforceable guardrails; Phase 2 maps the agent lifecycle, discovers agents wherever they are created, classifies them by risk and defines runtime monitoring and intervention actions by risk tier; Phase 3 assigns accountability across business owners, technical owners, AI governance and enterprise risk, then defines metrics, executive dashboard reporting and a phased rollout. The named artifacts — playbook, charter example, executive dashboard, glossary — are the ordinary output of this kind of advisory engagement and are reasonable to expect.

    What is not substantiated is the scale of the problem the framework addresses. The release describes a widening gap between adoption and governance but offers no survey data, no incidence rates for shadow agents, no measured cost of a runtime-drift failure and no baseline for how many organizations currently classify agents by risk at all. It refers to case studies without naming an organization or an outcome. The assertion that agents “lack conscience and cannot be morally incentivized” is a framing device rather than a finding; it is intuitively correct and empirically untested as stated here.

    That is not a criticism of the firm — vendor and analyst releases are marketing documents by design, and this one is unusually specific about method for the genre. It does mean a buyer should treat the framework as a hypothesis to be tested against their own environment rather than as evidence that their environment is on fire. The prudent question for a CIO is not whether the five gaps sound plausible, but which of them they can actually measure in their own estate this quarter.

    Who Gains: Identity Vendors, Platform Owners and Whoever Owns the Log

    If agent governance becomes an identity problem, the commercial gravity moves toward whoever already holds the identity layer. Identity and access management providers, privileged access management vendors and cloud platforms that issue and rotate machine credentials are positioned to extend existing products rather than sell new categories. Security operations vendors benefit from the runtime monitoring requirement, since drift detection is a telemetry problem before it is a policy problem. Governance, risk and compliance platforms gain a new object type to track.

    The harder position belongs to business units that have deployed agents quickly using departmental budgets and low-code tooling. Info-Tech’s Phase 2 — find agents wherever they are created — is the phase that generates conflict, because discovery inevitably surfaces work that was never registered with IT. Organizations that treat that discovery as an audit failure will drive the remaining agents further underground; the ones that treat it as an inventory exercise will get better data.

    For infrastructure operators specifically, there is a second-order consequence worth noting. Agents that act autonomously across systems generate authentication events, API calls and audit records continuously rather than in bursts tied to human working hours. Logging, retention and monitoring costs scale with that behaviour. Governance frameworks tend to be discussed as policy; the bill arrives as storage, egress and detection capacity.

    Background

    Info-Tech Research Group is an IT research and advisory firm that publishes structured methodologies — it calls them blueprints — covering IT strategy, security and governance, alongside affiliates McLean & Company for HR research and SoftwareReviews for software buying data. Its business model is subscription advisory, so its research releases both inform the market and market the firm; that dual purpose is standard for the analyst sector and is worth holding in mind when reading any single publication.

    The wider context is a two-year shift from generative AI, where models produce content a human then uses, to agentic AI, where software is granted credentials and permitted to act. That shift moves AI from a content-quality question into an access-control question, territory enterprise security teams have worked in for decades under frameworks such as NIST SP 800-171 and, for defense suppliers, the Department of Defense’s CMMC program. The unresolved issue is timing: regulated supply chains prove their controls because contracts require it, while most enterprises are deploying agents without an equivalent obligation.

    Source: AI Agents Must Be Governed as Persistent Digital Actors, Advises Info-Tech Research Group — the firm’s 28 August 2026 announcement of its Govern Enterprise AI Agents While Preserving Innovation blueprint, with background from Nelson Miller Group’s same-day CMMC Level 2 certification release.

  • Qualcomm’s Dragonfly Bid: A Third Path in AI Inference Silicon

    Qualcomm’s Dragonfly Bid: A Third Path in AI Inference Silicon

    On June 24, 2026, Qualcomm announced a comprehensive data center roadmap built around a new product family it calls Dragonfly, positioning the portfolio for what the company describes as the agentic AI era — workloads where AI systems act autonomously across chained tasks rather than answering single prompts.

    The announcement marks Qualcomm’s most explicit push yet into data center silicon, a market currently dominated by Nvidia with AMD as the principal challenger.

    Executive Summary

    Qualcomm is best known for smartphone modems and mobile system-on-chip designs. With Dragonfly, the company is signaling that it intends to translate its low-power, inference-oriented engineering heritage into a full data center accelerator roadmap aimed at agentic AI — inference workloads that are longer-running, more memory-intensive, and more sensitive to cost-per-token than the training runs that made Nvidia’s H100 and Blackwell generations famous.

    Why it matters: hyperscalers, sovereign cloud buyers, and neocloud operators have been vocal about wanting a viable third source for AI accelerators to ease supply constraints and pricing power. A credible Qualcomm entry, alongside AMD’s Instinct line and in-house silicon from AWS, Google, and Microsoft, would reshape purchasing leverage across the data center stack. Whether Dragonfly clears that bar depends on details the June 24 release does not fully disclose.

    For infrastructure operators, the immediate question is not whether Qualcomm can build competitive silicon — it has a strong NPU (neural processing unit) track record in mobile — but whether it can deliver the software stack, systems integration, and multi-year supply commitments that hyperscale procurement demands.

    Why Inference, and Why Now

    The AI silicon market has bifurcated. Training the largest models remains a specialized, capital-intensive workload where Nvidia’s CUDA software moat and networking assets (NVLink, InfiniBand via Mellanox) give it a durable lead. Inference — actually running trained models to serve users — is a larger and faster-growing spend line, and it is more fragmented technically. Different model sizes, latency targets, and cost envelopes favor different silicon architectures. Qualcomm’s positioning of Dragonfly around agentic inference is a rational reading of where the addressable market is opening up: agentic workloads chain many inference calls together, making cost-per-token and energy-per-token the metrics that matter most to operators.

    Qualcomm’s mobile heritage is genuinely relevant here. The company has shipped billions of NPU-equipped chips optimized for running neural networks under tight power budgets — a discipline the data center now needs as grid capacity, not GPU supply, becomes the binding constraint on AI buildouts.

    The Third-Source Thesis

    Buyers of AI infrastructure have made no secret of wanting alternatives to Nvidia. AMD has partially filled that role with its Instinct MI300 and successor accelerators, and hyperscalers have invested heavily in custom silicon — AWS Trainium and Inferentia, Google TPU, Microsoft Maia. Qualcomm’s Dragonfly enters a field that is crowded but still supply-constrained, and where any credible merchant-silicon alternative can command attention simply by existing. The commercial question is whether Qualcomm can win design wins at hyperscalers that already have in-house programs, or whether its natural customers are tier-two clouds, sovereign AI initiatives, and enterprise on-premises deployments where a turnkey vendor stack is more valuable than bespoke silicon.

    The competitive risk cuts both ways. If Dragonfly ships on schedule with competitive performance-per-watt and a workable software stack, it pressures Nvidia’s pricing on inference SKUs and validates AMD’s playbook. If it slips or underdelivers on software, it joins a long list of ambitious accelerator programs — from Intel’s Gaudi to various startups — that failed to convert silicon competence into share.

    Software Is Where Accelerator Roadmaps Live or Die

    The unspoken subject of any new AI silicon announcement is the software stack. Nvidia’s advantage is not primarily transistors; it is CUDA, cuDNN, TensorRT, and a decade of framework integration that makes developers productive on day one. Any Dragonfly evaluation by a serious buyer will focus on how well Qualcomm supports PyTorch, vLLM, TensorRT-equivalent inference runtimes, and increasingly the open standards like OpenAI-compatible APIs and the emerging agentic frameworks. The June 24 release frames Dragonfly as a portfolio and roadmap rather than a single product, which suggests Qualcomm is aware that ecosystem depth matters as much as peak throughput numbers.

    For infrastructure operators evaluating Dragonfly, the practical checklist is well-established: what models run out of the box, what quantization formats are supported, how does the compiler handle novel architectures, and what is the update cadence when a new model family lands. None of these are answered in the announcement itself.

    Power, Density, and the Data Center Fit

    Modern AI accelerators are increasingly constrained by rack-level power and cooling rather than chip-level cost. A meaningful Dragonfly value proposition would show up in performance-per-watt at realistic inference batch sizes, and in the thermal envelope that determines whether the parts drop into air-cooled facilities or require liquid cooling retrofits. Qualcomm’s mobile pedigree suggests an efficiency-first design philosophy, which aligns with where the industry’s power problem is heading, but the announcement does not disclose the numbers that would let operators model total cost of ownership.

    Background

    Qualcomm built its business on wireless modems and Snapdragon system-on-chip designs that power much of the global smartphone market. Its neural processing units have delivered on-device AI in mobile phones for years, giving the company deep expertise in low-power inference. A prior effort to enter the server market with the Centriq Arm CPU in the late 2010s was ultimately discontinued, making Dragonfly the company’s most substantial data center push since.

    The AI accelerator market took its current shape after 2022, when generative AI demand made Nvidia’s data center GPUs the scarcest resource in enterprise computing. AMD’s Instinct MI300 series became the primary merchant-silicon alternative, while AWS, Google, and Microsoft accelerated in-house silicon programs. Buyers across hyperscale, sovereign cloud, and enterprise segments have consistently signaled that a credible third source would be welcome — the question Dragonfly will answer over the coming quarters is whether Qualcomm can be that source.

    Source: Qualcomm Unveils Comprehensive Data Center Roadmap for the Agentic AI Era with New Qualcomm Dragonfly Portfolio — Qualcomm’s June 24, 2026 announcement of its Dragonfly data center product family for agentic AI inference.

  • NVIDIA Blackwell Tops the First Agentic AI Infrastructure Benchmark

    NVIDIA Blackwell Tops the First Agentic AI Infrastructure Benchmark

    NVIDIA announced on June 12, 2026, via its corporate blog, that its Blackwell GPU platform leads the results of what the company describes as the first infrastructure benchmark designed for agentic AI — artificial-intelligence systems that plan, call tools, and execute multi-step tasks rather than answering a single prompt. The announcement positions Blackwell as the performance standard for the next wave of inference-focused data center buildouts.

    Executive Summary

    The claim itself is narrow but consequential: a new benchmark category now exists for agentic AI infrastructure, and NVIDIA says its current flagship platform sits at the top of it. Benchmarks matter in this industry because they are how buyers — cloud providers, enterprises, and the operators building gigawatts of AI capacity — translate marketing claims into procurement decisions. Being first on the first test of a new workload class is a statement about where NVIDIA believes demand is heading.

    It is worth being precise about what is and is not substantiated here. The source available to us is NVIDIA’s own announcement headline distributed through Google News; the underlying methodology, the benchmark’s governing body, competitor submissions, and the specific metrics behind the word “leads” are not detailed in the material we can verify. That does not make the result wrong — NVIDIA has a long, independently audited record of topping industry benchmarks — but it does mean the announcement should be read as a vendor-reported result until the full submission data is examined.

    Why Agentic AI Broke the Old Yardsticks

    Traditional AI inference benchmarks measure a straightforward transaction: a prompt goes in, a response comes out, and the system is scored on throughput (how many requests per second) and latency (how fast each answer arrives). Agentic AI does not work that way. An agent handling a single user request may make dozens of chained model calls — reasoning about a plan, querying tools and databases, checking its own work — with each step depending on the last. That workload stresses infrastructure differently: long context windows strain memory, sequential call chains magnify every millisecond of latency, and the interconnect fabric between GPUs becomes as important as the GPUs themselves.

    A benchmark purpose-built for this pattern is therefore a genuine industry milestone, whoever leads it. It gives infrastructure buyers a shared vocabulary for a workload class that, by mid-2026, is driving much of the growth in inference demand. The open question — one the announcement’s headline alone cannot answer — is whether this benchmark was defined by a neutral industry consortium with multi-vendor participation, or shaped around the strengths of the hardware that now leads it. That distinction determines how much weight the result deserves.

    First Place on a First Test Is Also a Marketing Position

    There is a well-worn dynamic in infrastructure markets: the vendor that helps define a new benchmark tends to win it, and winning it early lets that vendor set the terms of comparison for everyone who follows. NVIDIA has earned real credibility here — its results in established suites like MLPerf have been submitted, peer-reviewed, and reproduced for years, and Blackwell’s rack-scale systems were explicitly engineered for exactly the long-chain inference work agentic AI demands. The leadership claim is consistent with that track record and should not be dismissed.

    At the same time, a fair reading asks the questions any buyer would: Did AMD, custom cloud silicon, or other accelerator vendors submit results to be compared against? Is “leads” measured per chip, per rack, per watt, or per dollar? Normalization matters enormously — a platform can lead on absolute throughput while trailing on cost- or energy-efficiency, and for operators paying for power by the megawatt, those are the numbers that decide deployments. None of this is a criticism of the result; it is the standard scrutiny any first-of-its-kind benchmark claim should invite, from any vendor.

    What It Signals for the Inference Buildout

    The larger story is the one this benchmark’s existence confirms: the center of gravity in AI infrastructure spending is shifting from training frontier models to serving them at scale, and agentic workloads multiply the compute consumed per user interaction. For data center operators, that shift has physical consequences — sustained high utilization rather than bursty training runs, rack power densities that push liquid cooling from optional to standard, and network architectures where east-west GPU-to-GPU traffic dominates. Facilities planned around last generation’s assumptions will feel that pressure first.

    For buyers, the practical takeaway is not to change procurement based on one headline, but to recognize that agentic inference performance is now a measurable, comparable dimension — and to demand full methodology, competitor data, and efficiency-normalized results before treating any leaderboard position as decisive. Benchmarks are the beginning of an evaluation, not the end of one.

    Background

    NVIDIA transformed itself from a graphics-chip maker into the dominant supplier of AI computing infrastructure, and its Blackwell architecture — announced in 2024 as the successor to the Hopper generation that powered the first ChatGPT-era buildout — anchors that position. Blackwell’s signature is rack-scale integration: systems that connect large numbers of GPUs over high-bandwidth links so they behave as a single accelerator, a design aimed at the long, chained inference workloads that agentic AI produces.

    Benchmarking has long been the industry’s proving ground: consortium-run suites such as MLPerf established the norm of peer-reviewed, multi-vendor performance submissions, and NVIDIA has consistently led those results. The emergence of a benchmark dedicated to agentic AI infrastructure reflects how quickly that workload class has grown from research curiosity to a primary driver of data center demand.

    Source: NVIDIA Blackwell Leads on First Agentic AI Infrastructure Benchmark — NVIDIA corporate blog announcement, June 12, 2026, distributed via Google News.

  • NVIDIA Pushes Security Into Silicon: DOCA and the Agentic AI Factory

    NVIDIA Pushes Security Into Silicon: DOCA and the Agentic AI Factory

    NVIDIA published a technical blog on May 30, 2026 making the case for “in-silicon security” for agentic AI infrastructure, delivered through DOCA — the software framework for its BlueField data processing units (DPUs). The pitch: as AI systems shift from answering prompts to autonomously taking actions, the security controls protecting AI data centers should move out of host software and into dedicated hardware at the network edge of every server.

    Executive Summary

    The post positions DOCA, NVIDIA’s development framework for BlueField DPUs, as the security layer for what the company calls AI factories — data centers purpose-built to produce AI inference at scale. A DPU is a programmable processor that sits on the server’s network card and handles networking, storage, and security tasks so the CPU and GPU don’t have to. Running security there, rather than in the operating system, means the enforcement point survives even if the host itself is compromised.

    The timing tracks the industry’s pivot to agentic AI — systems that plan, call tools, and act on other systems with limited human supervision. That autonomy multiplies machine-to-machine traffic inside the data center and widens the blast radius of any single compromised workload, which is precisely the traffic that perimeter firewalls never see. NVIDIA’s argument is that the enforcement point has to move to where that east-west traffic actually flows: the server’s own network interface.

    It matters because NVIDIA is not a neutral party here. If security becomes a silicon feature of the AI stack, the company that already supplies the GPUs, the networking, and the DPUs consolidates one more layer of the platform. The blog is a technical argument, not a product launch — and readers should weigh it as both engineering guidance and strategic positioning.

    Agentic AI Breaks the Perimeter Model

    Traditional data center security assumes a hard shell and a soft interior: inspect traffic at the boundary, trust most of what happens inside. Agentic AI erodes that assumption. When autonomous agents call APIs, query databases, spin up jobs, and message other agents, the overwhelming majority of traffic is east-west — server to server inside the facility — and it is generated by software identities, not humans logging in.

    That shifts the useful control point from the perimeter to the individual server. Zero trust — the model in which no connection is trusted by default and every request is verified — has been the stated direction of enterprise security for years, but enforcing it on every packet between thousands of GPU servers is computationally expensive. NVIDIA’s framing of the DPU as the natural place to do that enforcement is a coherent answer to a real architectural problem, whatever one concludes about the specific product.

    Why the DPU Is an Attractive Security Boundary

    Putting security in the DPU buys two things. First, isolation: the DPU runs its own software stack, so firewalling, encryption, and telemetry keep operating even if an attacker gains root on the host — a meaningful property when the host is running semi-autonomous agents whose behavior is hard to fully predict. Second, offload: security processing done in dedicated silicon doesn’t consume the CPU cycles or GPU time that the facility exists to sell.

    That second point is the quiet economic argument. In an AI factory, every host cycle spent on packet inspection is margin lost. In-silicon security is thus pitched not only as safer but as cheaper per unit of useful work — an argument that will resonate with operators watching utilization dashboards. The trade-off is operational: security teams gain a new hardware layer to program, patch, and monitor, and DOCA skills are far scarcer than firewall administration skills.

    Platform Consolidation Cuts Both Ways

    For NVIDIA, embedding security into DOCA deepens an already formidable platform position spanning GPUs, interconnects, and networking. For buyers, that is simultaneously the appeal and the risk. A vertically integrated stack where security is co-designed with the fabric can genuinely outperform bolted-on alternatives; it also concentrates dependency on a single vendor for compute, networking, and now the control plane that polices both.

    Incumbent security vendors face a positioning question rather than immediate displacement: several already ship DPU-accelerated versions of their products, and the realistic outcome is DOCA as a substrate that third-party security software runs on, rather than a wholesale replacement. Infrastructure operators — including colocation and cloud providers hosting AI workloads — should read this as directional: the security perimeter of AI infrastructure is migrating into the server itself, and facility-level offerings will need to interoperate with it.

    Background

    NVIDIA transformed from a graphics chip maker into the dominant supplier of AI data center infrastructure, with its GPUs powering the large-scale model training and inference boom. Its 2020 acquisition of Mellanox brought high-performance networking in-house, yielding the BlueField DPU line and the DOCA framework introduced alongside it. Since then NVIDIA has steadily pitched a full-stack vision — compute, networking, software — for what it brands AI factories.

    The security angle gained urgency through 2025 and 2026 as enterprises moved from chatbot-style AI to agentic deployments, where autonomous software acts on live business systems. That shift has pushed the industry’s long-running zero-trust conversation from corporate networks into the AI cluster itself, making the question of where enforcement lives — perimeter, host, or silicon — a live architectural debate.

    Source: Advancing AI Infrastructure for Agentic AI with NVIDIA DOCA In-Silicon Security — NVIDIA Technical Blog post arguing for DPU-layer, in-silicon security as the foundation for agentic AI data centers.

  • CoreWeave Pushes Beyond GPU Rental With Unified Agentic AI Platform

    CoreWeave Pushes Beyond GPU Rental With Unified Agentic AI Platform

    On May 28, 2026, CoreWeave — the Nasdaq-listed GPU cloud provider often described as the leading “neocloud” — announced a unified agentic AI platform aimed at what the company calls continuous agent improvement. The announcement positions CoreWeave as a provider not just of raw GPU compute but of the software layer used to build, evaluate, and iteratively refine AI agents.

    The release, distributed by CoreWeave itself, was headline-level in the version available to us: it did not detail pricing, availability, named customers, or the specific components bundled into the platform.

    Executive Summary

    CoreWeave built its business renting large fleets of NVIDIA GPUs to AI labs and enterprises — a capital-intensive model in which the product is fundamentally access to scarce hardware. This announcement signals a deliberate move up the stack: a “unified” platform for agentic AI, meaning software systems in which AI models autonomously plan and execute multi-step tasks, and for the tooling loop — evaluation, monitoring, and retraining — that makes such agents improve over time rather than remain static after deployment.

    Why it matters: raw GPU capacity is becoming easier to procure as supply catches up, which pressures rental pricing across the neocloud sector. Platform software is how an infrastructure provider differentiates, deepens customer lock-in, and defends margins. CoreWeave has been assembling the ingredients for this for over a year — it acquired the machine-learning tooling company Weights & Biases in 2025 and reinforcement-learning startup OpenPipe later that year — and a unified agentic platform is the logical product of those deals.

    What the announcement does not yet establish is substance: the release headline promises unification and continuous improvement, but the available text offers no technical detail, benchmarks, or customer evidence against which those claims can be tested.

    From GPU Landlord to Platform Company

    CoreWeave’s core business — leasing GPU clusters by the hour or under multi-year contracts — is lucrative when accelerators are scarce, but it is structurally exposed to commoditization. Competitors ranging from hyperscalers (AWS, Microsoft Azure, Google Cloud) to fellow neoclouds can offer the same NVIDIA silicon, so price becomes the battleground as supply normalizes. Software platforms change that equation: a customer who builds its agent development, evaluation, and retraining workflow on a provider’s tooling is far harder to dislodge than one renting interchangeable compute.

    This is a well-worn playbook. The hyperscalers long ago wrapped raw infrastructure in managed AI services — Amazon Bedrock, Azure AI Foundry, Google Vertex AI — precisely because services carry better margins and stickiness than instances. CoreWeave following the same path is a sign of the neocloud category maturing: the first wave of competition was about who could deploy GPUs fastest; the next is about who owns the developer workflow that runs on them.

    The Continuous-Improvement Loop Is the Real Product

    The phrase “continuous agent improvement” is worth unpacking. AI agents — systems that use large language models to autonomously carry out tasks like coding, research, or customer support — are notoriously hard to keep reliable in production. They fail in long-tail ways that only surface in real usage. The emerging answer is a feedback loop: capture production behavior, evaluate it systematically, and feed the results back into the agent through techniques such as reinforcement learning, in which a model is trained on reward signals rather than static examples.

    CoreWeave’s prior acquisitions map directly onto that loop. Weights & Biases is one of the most widely used platforms for experiment tracking and model evaluation; OpenPipe specialized in reinforcement-learning fine-tuning for agents. If the new platform genuinely unifies those capabilities with CoreWeave’s training and inference infrastructure, it would offer something the raw-compute competitors do not: a closed loop from deployment telemetry back to GPU-powered retraining, all in one vendor. Whether the integration is that deep, or the platform is initially a bundling of existing products under one name, is not answerable from the release.

    Winners, Losers, and the Lock-In Question

    If the platform gains traction, the clearest beneficiary is CoreWeave itself — agent training and continuous retraining are compute-hungry workloads that would drive utilization of its fleet, and platform revenue could diversify a business that has historically depended on a small number of very large customers. Enterprises adopting agents could also benefit from an integrated stack that reduces the engineering burden of assembling evaluation and retraining pipelines from separate vendors.

    The trade-off for buyers is concentration risk. A unified platform that works best on one provider’s cloud is, by design, a lock-in mechanism. Organizations weighing it should ask whether the tooling layer remains portable — Weights & Biases historically ran across all major clouds — or whether the “unified” version ties workflows to CoreWeave capacity. For the broader market, the launch raises the bar for other neoclouds, which must now decide whether to build competing software layers, partner for them, or compete purely on price and availability — a difficult position if agent workloads become the dominant demand driver.

    Background

    CoreWeave began in 2017 as Atlantic Crypto, an Ethereum-mining venture, and repurposed its GPU expertise into a specialized AI cloud after crypto economics soured. Backed by NVIDIA and fueled by the post-2022 generative-AI boom, it grew into the most prominent of the “neoclouds,” signing multibillion-dollar capacity deals with major AI labs and completing a closely watched Nasdaq IPO in March 2025. Through 2025 it expanded aggressively beyond hardware, acquiring Weights & Biases for ML tooling and OpenPipe for reinforcement-learning-based agent training.

    The broader market context is a shift in AI workloads from one-off model training toward deployed agents that must be monitored and improved continuously — a shift that rewards providers who control the software loop as well as the silicon it runs on.

    Source: CoreWeave Launches Unified Agentic AI Platform for Continuous Agent Improvement — CoreWeave press release dated May 28, 2026, announcing an agentic AI platform on its GPU cloud.

  • NSA and Allies Issue First Joint Guidance on Securing Agentic AI Systems

    NSA and Allies Issue First Joint Guidance on Securing Agentic AI Systems

    The U.S. National Security Agency (NSA) has joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other partner agencies to release joint guidance on agentic artificial intelligence systems — AI that doesn’t just answer questions but autonomously plans and executes tasks. Announced April 29, 2026, it is the first major multi-government security framework aimed specifically at AI agents, arguably the fastest-growing new attack surface in enterprise technology.

    Executive Summary

    According to the announcement, the NSA — alongside ASD’s ACSC and other unnamed partner agencies — has published guidance on agentic AI systems: software built on large language models that can take actions on a user’s behalf, such as browsing, writing code, calling APIs, or operating other software. That autonomy is precisely what makes agents useful, and precisely what makes them dangerous when compromised: an attacker who subverts an agent inherits everything the agent is allowed to do.

    The release matters less for any single recommendation than for what it signals. When signals-intelligence agencies from multiple allied nations co-sign a document about a technology category, that category has crossed a threshold — from experimental tooling to infrastructure that governments believe adversaries are actively probing. Enterprises deploying AI agents now have an authoritative reference point, and vendors selling them have a bar to be measured against.

    Autonomy Changes the Threat Model

    A conventional chatbot that gets manipulated produces bad text. An agentic system that gets manipulated produces bad actions — because agents are wired to tools, credentials, file systems, and APIs. The security community has spent two years documenting how techniques like prompt injection (hiding malicious instructions in content an AI reads, such as a webpage or email) can redirect an agent’s behavior. When the agent can send messages, move money, or modify infrastructure, a manipulated input stops being an embarrassment and becomes the equivalent of a compromised employee account.

    That is why agentic AI merits its own guidance rather than a footnote to existing AI security advice. Earlier frameworks focused on securing models, training data, and deployment pipelines. Agents add a different problem: the model’s outputs are now inputs to real systems, so classic security disciplines — least privilege, sandboxing, audit logging, human approval for consequential actions — must be rebuilt around a component that behaves probabilistically rather than deterministically.

    The Allied Playbook: Guidance Before Regulation

    This release fits a well-established pattern. The NSA, ASD’s ACSC, and partners including the UK’s NCSC and the U.S. CISA have jointly published a sequence of AI security documents since late 2023 — guidelines for secure AI development, for deploying AI systems securely, and for AI data security. Each followed the same model: non-binding, principles-based guidance issued jointly so that multinational enterprises face one aligned reference instead of a patchwork.

    Non-binding does not mean toothless. In practice, joint government guidance tends to become a de facto procurement standard — government buyers cite it in contracts, insurers and auditors reference it, and regulators later treat it as evidence of what “reasonable” security looked like at the time. Vendors of agent platforms and the enterprises deploying them should read this release as an early draft of tomorrow’s compliance expectations, arriving while the market is still young enough to adapt cheaply.

    What It Means for Enterprise and Infrastructure Operators

    For organizations already piloting AI agents, the immediate implication is organizational: agent deployments now belong in the security team’s scope, not just the innovation team’s. That means treating agents as privileged identities — with scoped credentials, network segmentation, activity logging, and defined blast radius — rather than as features of a productivity suite. Buyers evaluating agent platforms gain a useful question set: how does the vendor constrain what the agent can do, log what it did, and contain it when it misbehaves?

    For infrastructure providers — data centers, cloud and connectivity operators — agentic AI is both a workload to host and a tool their customers will point at their own environments. Isolation, observability, and identity infrastructure become selling points as enterprises look for places to run agents with enforceable boundaries. Government attention at this level tends to accelerate, not chill, enterprise adoption: clear security expectations reduce the uncertainty that keeps cautious industries on the sidelines.

    Background

    Governments began issuing coordinated AI security guidance almost as soon as generative AI reached enterprises: allied agencies including the NSA, CISA, the UK’s NCSC, and ASD’s ACSC jointly published guidelines for secure AI system development in November 2023, guidance on deploying AI systems securely in April 2024, and AI data security guidance in 2025. The NSA’s Artificial Intelligence Security Center, created in 2023, has anchored the U.S. side of that effort.

    Over the same period, the industry’s center of gravity shifted from chatbots to agents — AI that can use tools, browse, code, and act with limited supervision — driven by rapid capability gains in frontier models. Security researchers flagged early that autonomy plus tool access creates a fundamentally new attack surface; this April 2026 release is the first time that concern has been addressed head-on at the multi-government level.

    Source: NSA joins the ASD’s ACSC and Others to Release Guidance on Agentic Artificial Intelligence Systems — National Security Agency announcement of joint international guidance on securing agentic AI, published April 29, 2026.