What September told us: in enterprise AI, the model is no longer the hard part
Twenty announcements in one month, read together. Runtimes became infrastructure, custody moved to the front, evaluation became the control surface. Our synthesis, and what we are watching in October.
Listen to this article · 5 min
AI-generated narration of the full article.

Over the last month we analyzed twenty enterprise AI developments, from OpenAI, AWS, Microsoft, Google, Anthropic, Salesforce, Palantir, IBM, Snowflake, Databricks and Cohere. Read one by one, they look like a busy product season. Read together, they tell a clearer story: the model stopped being the hard part.
This is the first of our monthly syntheses. Its job is to connect what we published, say what we now believe, and name what we will watch next.
1. The agent runtime became infrastructure
In a few weeks, the layer most teams were still building by hand became a product. OpenAI now operates the agent loop behind its Agents API. AWS put identity, durable sessions, approvals and audit into Bedrock Managed Agents. Microsoft moved to host and operate the apps Copilot generates. Google released an execution runtime for fleets of agents.
What we believe now: building your own agent loop is rarely where the value is. The value is in what the runtime cannot decide for you: scope, approvals, evidence and ownership.
2. Custody moved to the front
Self-hosted IBM Bob, the multiple delivery paths for Claude, Anthropic’s governed access for life sciences and its split of safety monitoring all answered the same question: who holds what. We developed that argument in our piece on custody.
What we believe now: agents create new copies of sensitive data in sessions, snapshots, traces and indexes. A custody map belongs in every design, before the security review.
3. Evaluation became the control surface
Palantir’s AIP Evolve lets agents propose changes to AI systems, which only works with strong evals. Snowflake’s agent observability brings quality judgments onto live traffic. Cohere’s retrieval metric argues for measuring search separately from answers.
What we believe now: an AI system you cannot measure, per task and per component, is not ready to change, scale or hand over.
4. The best agents are disappearing into existing processes
Google’s security agents live inside code review. Snowflake’s accounts payable system uses AI only where the input is unstructured. Gemini now acts inside Microsoft 365, where people already work.
What we believe now: the agents that reach production fastest have no chat window. They feed a decision an existing process already knows how to handle, next to deterministic checks.
5. Cost and ownership became operating-model questions
Copilot Autopilot raised the question of who owns an agent’s actions after its user logs off. Snowflake and Google shipped spend quotas and caps, and IBM reported CFOs taking a larger role in AI decisions. Salesforce’s harness pushed the question of which layers to own once, across vendors.
What we believe now: every production agent needs a named owner, a budget and a decision about what happens at the limit.
Core layers
- Business application & experience
- Agent runtime: orchestration & state
- Tools, actions & integrations
- Enterprise context: data & grounding
- Models
Cross-cutting controls
- Identity & authorization
- Policy & security
- Evaluation
- Human approval
- Observability & audit
- Lifecycle & deployment
- Operating ownership: who is accountable after go-live
Moved toward products in SeptemberBecame the differentiator, still decided by the enterprise
The signal from Brazil
One more development stands out for us: Databricks’ R$1.5 billion investment in Brazil. It is a sign that enterprise AI demand outside the US is about production, not translation. Many of the questions above, custody first among them, look different under the LGPD, and we will keep covering them from both sides.
What we are watching in October
- Previews moving to general availability, and the pricing that comes with them. Several services we covered are still in preview or private beta, including Bedrock Managed Agents and Cohere’s Compass Cloud.
- Regional availability, especially in São Paulo and in Europe, which decides whether many of these services are usable with regulated data.
- Snowflake’s agent observability launch, planned for October 22, and whether open telemetry conventions hold across vendors.
- Vendors publishing custody details without being asked: where sessions, traces and indexes live, and for how long.
- Retrieval as a managed layer, after Compass Cloud and Embed 5, and whether permission enforcement holds up in real deployments.
The bottom line
September did not bring a new model that changed enterprise AI. It brought platforms that absorbed the generic engineering, and with it a clearer view of what remains the enterprise’s job: custody, evaluation, approvals, cost and ownership. That is where we will keep looking. The full map of those layers is in our 2026 enterprise AI stack guide.