Every AI story this week has the same theme underneath it. Agents are showing up everywhere. Nobody's finished building the fence around them yet. Here's what caught my eye and what I make of it.
Everybody wants an agent, nobody wants to build the fence
McKinsey put out its State of AI 2026 survey this week and one number jumped out at me. Thirty two percent of companies said they skipped buying a piece of software, or a feature, because they figured their own agentic coding tools could just build it in-house. A third of companies. That's not a pilot program anymore, that's a real shift in how work gets done.
Why it matters is simple. Software vendors have spent twenty years selling "don't build it, buy it." Now the build side got a whole lot cheaper because the agent does the grunt work. That flips the math on a lot of SaaS contracts sitting on renewal desks right now.
My take. This is the real story under all the agent hype, not the flashy demos. When a third of buyers start asking "could we just build this ourselves" before they sign a check, that's when an industry changes. I'd rather see that number than any benchmark score.
Google says the real bottleneck is security, not speed
Google Cloud put out a piece tied to its State of AI infrastructure report and the headline is that agent security, not raw capability, is now the thing holding companies back from scaling autonomous workflows. Their fix is more governance. Secure AI frameworks, platform level controls, task level tracking of who did what, and a human still in the loop on the important calls.
Why it matters. Everybody's been racing to give agents more autonomy. Fewer people have been racing to build the guardrails for when that autonomy goes sideways. Google saying it out loud, in a report meant for its own customers, tells you this isn't a hypothetical problem anymore.
My take. I've been saying this for a while and it's nice to see the cloud providers catch up. An agent that can spin up infrastructure or touch customer data needs the same kind of access controls we'd demand from a new employee, not less. Speed without a leash is how you get a bad headline.
Washington is trying to figure out who lets an agent spend your money
There's real policy movement happening on agent identity and permissions. Google has its Agent Payments Protocol out in the wild, NIST is doing early concept work on agent identity standards, and there's a bill in Congress, the AI AGENT Act, aimed at the same problem. All of it boils down to one question. When an agent takes an action on your behalf, especially one that involves money, how does anybody prove it was actually authorized to do that.
Why it matters. Right now that answer is mostly "trust us." That doesn't hold up once agents are booking travel, paying invoices, or moving inventory on their own. You need something closer to a paper trail than a vibe check.
My take. I'd rather this stuff get sorted out now, while the dollar amounts are small, than after some agent racks up a six figure mistake because nobody could tell whether it had permission. Boring plumbing work like this doesn't get headlines but it's the part that actually matters.