Walk the expo floor at Gartner IT Symposium/Xpo 2026 and you will hear the same sentence from five different booths: we govern your AI agents. Microsoft will mean agents in the Microsoft estate. AWS will mean agents on Bedrock. Google, Salesforce and ServiceNow will each mean their own. All five are telling the truth — and none of them is answering the question a CIO is actually accountable for, because the estate is all five at once.
This is the structural fact of agent governance in 2026: every platform governs inward. Microsoft Agent 365 puts Entra identities on Copilot Studio and Foundry agents. AWS Bedrock AgentCore isolates each session in its own microVM. ServiceNow's AI Control Tower discovers, traces and kill-switches agents with real authority — strongest for what runs through ServiceNow. Each is deep, credible and bounded by its own walls. Your accountability is not.
The playbook: four moves
The pattern that works is not picking a winner. It is a small set of moves that sit above the platforms — each one something you can start before Barcelona and pressure-test at the booths while you are there.
Move 1 — One registry above five registries
Each platform keeps a list of its own agents. None of them will ever hold the list — the one with every agent, whichever platform it lives on, matched against the use cases your governance board actually approved. That is a master AI agent registry: connectors harvest each platform's agents through its API, every record lands with the same fields (owner, model, tools, risk tier, lifecycle state), and reconciliation against the approved-use-case registry flags the unmatched as shadow AI.
The reconciliation is the point. Discovery by questionnaire finds the agents people remember. Discovery by reconciliation finds the ones they don't — the Salesforce agent a regional team configured in an afternoon, the Vertex prototype that quietly became production.
Move 2 — One policy point for the traffic
Platform-native guardrails protect each platform's own runtime. The policy your regulator asks about — does the PII rule apply to every agent, everywhere? — needs a point the traffic actually crosses. An AI gateway that speaks LLM, MCP and agent-to-agent protocols gives agents one governed exit: guardrails, RBAC and budgets applied identically whether the agent was built in Copilot Studio or CrewAI. Policy configured once beats policy re-implemented five times, drifting in five consoles.
Move 3 — Containment for what acts
Most platform governance watches and revokes: quarantine an identity, deactivate a connection, kill a session. Necessary — and still short of the guarantee a high-autonomy agent needs. For agents that write to systems of record, the control has to be architectural: a sandbox whose egress is physically limited to its gateway, credentials that exist only for the run, and a kill switch that has been rehearsed, not just documented. Prompts are advice. Boundaries are physics.
Move 4 — Evidence as a by-product
Five platforms produce five audit trails in five formats. Assembling them per audit is a quarter of someone's year. The alternative is structural: registry state plus gateway logs generate the EU AI Act, ISO/IEC 42001 and NIST AI RMF evidence as operations run, so the audit reads what the estate already wrote.
What to ask the platform booths
Each vendor deserves the respect of a precise question. Ask Microsoft how deep Agent 365's governance runs for agents on Bedrock and Vertex — the coverage is expanding but newer and partial. Ask AWS what AgentCore sees outside the AWS account boundary. Ask ServiceNow whether the AI Gateway proxies your LLM traffic or your MCP connections. Ask Salesforce and Google where their agent lists end. The honest answers all trace the same wall: the platform's governance ends where the platform ends. Then ask who holds the list of everything — and watch which booths point at a spreadsheet.
For the estate-layer comparison in writing: Kosmoy vs Microsoft Agent 365, Kosmoy vs AWS Bedrock AgentCore, Kosmoy vs ServiceNow AI Control Tower, and the agent management buyer's guide covering all eleven.
Run both — deliberately
None of this argues against the platform tools. If your estate is Microsoft-heavy, Agent 365's Entra-native identity is something no third party can replicate. AgentCore's per-session isolation is one of the strongest containment stories in the market — inside AWS. The architecture that holds up is layered: platform-native depth where each platform is strong, and an independent registry, policy point and evidence layer above all of them. What breaks is pretending either layer covers the other's job.
Bring your agent list to Barcelona
We will be on the expo floor all four days, 9–12 November. Bring the agent list you have — however partial — and we will run the reconciliation exercise live: what a master registry would harvest from your platforms, what would match, and what would light up as shadow AI. Book a meeting before the event, or email sales@kosmoy.com with the days you are on site.
FAQ
Can one platform govern agents built on Microsoft, AWS, Google, Salesforce and ServiceNow?
Each vendor governs its own estate deeply — Agent 365 for Microsoft, AgentCore for AWS, AI Control Tower for ServiceNow. Cross-platform governance needs a layer above them: a master registry that harvests every platform's agents into one list, one policy point for the traffic, and containment for the agents that act. That layer must be independent of the platforms it governs.
What is the difference between platform-native and cross-platform agent governance?
Platform-native governance is deep but bounded: it sees the agents built on that platform, enforces inside that estate, and ends at the console's edge. Cross-platform governance trades some per-platform depth for the property enterprises are actually accountable for — one inventory, one policy, one audit trail across everything, including the agents nobody registered.
How do enterprises find agents their teams shipped without approval?
By reconciliation, not by asking. Harvest each platform's registry through its API into a master list, match every discovered agent against the approved use-case registry, and flag the unmatched as shadow AI for review. The 30-day inventory plan is the working version of this exercise.
Gartner and Gartner IT Symposium/Xpo are trademarks of Gartner, Inc. and/or its affiliates. Kosmoy is an exhibitor at the 2026 Barcelona conference. Gartner does not endorse Kosmoy or its products.