WSO2 — “WSO2 Agent Manager Brings Sovereign AI Governance to Enterprise Agent Sprawl” (15 September 2026)
Tag: S-2026-09-15-wso2-agent-manager-ga Type: article (vendor press release, GlobeNewswire, 15 Sep 2026; fetched in full) Author(s): WSO2, Inc. (quote: Dr. Rania Khalaf, chief AI officer) Date of source: 2026-09-15 Date ingested: 2026-09-16 Authority weight: medium — dated GA announcement from a self-interested vendor; specific, checkable capability list and licence terms (Apache 2.0, open source); analyst mention is a landscape listing, not a ranking; no regulation, standard or customer named Raw file: /_raw_sources/S-2026-09-15-wso2-agent-manager-ga.md
What it claims
WSO2 — an open-source integration, API-management and identity vendor, not an AI-governance pure-play — announced general availability of WSO2 Agent Manager, “an open control plane that governs AI agents across any framework, model, or deployment”. It launched in beta in June 2026. GA adds “per-agent, per-environment agent identity controls, MCP-level governance and a sandboxed runtime”. The pitch is separation of governance from agent logic: “swapping models, frameworks, or deployments without rebuilding agent governance”, and “sovereignty” — Apache 2.0 licence, self-hosted or managed SaaS, “sovereignty over where agent data lives and runs”.
Stated capabilities: a federated agent inventory across any model/framework/runtime and cloud/on-prem/hybrid; agent identity (verifiable identity, RBAC, delegation, token exchange, instant revocation); 40+ built-in guardrails (PII masking, rate limiting) enforced at agent, MCP and LLM levels; lifecycle management (versioned dev→staging→production, one-click suspension); observability and evaluation (OpenTelemetry tracing, continuous evals at trace or agent level, rule-based or LLM-as-a-judge monitors for token spend or accuracy drift); a sandboxed Kubernetes-native runtime with real-time suspension; and an open, framework-agnostic foundation (OpenTelemetry, MCP, OAuth2; LangChain, CrewAI, Amazon Bedrock Strands, Microsoft Agent Framework named).
The release argues agents “are still squeezed into identity categories built for people, and the moment one calls a tool or an MCP server, there’s often no policy layer at all”, and that provider churn (terms, throttling, deprecations) makes vendor-independent agent governance a resilience need. It relays Gartner’s prediction of “more than 150,000 agents” per average Fortune 500 firm by 2028 and that “only 13% of organizations think they have the right AI agent governance in place”. WSO2 says it is “included among notable vendors” in Forrester’s Agent Control Plane Landscape, Q2 2026, co-authored the OpenID Foundation whitepaper Identity Management for Agentic AI and an OAuth 2 extension for MCP, and joined the Agentic AI Foundation.
Notable quotes
- “When governance is separated from agent logic, it can scale across frameworks instead of being locked into one ecosystem.” — Dr. Rania Khalaf
- “Left unmanaged, that scale becomes agent sprawl: agents nobody can fully see, govern, or shut down.” (para 4)
- “Identity has to be central to any control plane, not an afterthought bolted on later.” (para 5)
What’s speculative vs. asserted
Asserted (reliable as event facts): GA date; beta since June 2026; Apache 2.0 licence; self-hosted and SaaS options; the named framework integrations; Forrester landscape inclusion (as stated by WSO2).
Vendor-asserted / unverified: every capability in the list; “consistent compliance enforcement”; “complete sovereignty”; the OpenID/OAuth co-authorship claims; award.
Relayed third-party figures: Gartner 150,000-agents / 13% (not fetched); Forrester report not read.
Not stated (gaps): any regulation, standard or regulator; any customer, regulated or otherwise; whether the guardrails or evals map to any external framework; how it relates to OWASP’s Agent Control Standard (not mentioned); pricing for the managed offering; EU data-residency specifics beyond “deployable anywhere”.
Vault inference (not a source claim): an open-source, self-hostable control plane combining inventory, identity, guardrails, lifecycle and evals is the first such stack at GA in the vault; the sovereignty framing speaks to DORA ICT-concentration and exit-strategy concerns and to EU AI Act Art. 12 logging / Art. 14 oversight for agents, but none of that is claimed by the vendor.
Topics this feeds
- AI Governance Platforms — adds an open-source, sovereignty-positioned agent control plane alongside the hyperscaler (AWS AgentCore, Microsoft Foundry), security-incumbent (Broadcom AgentMinder) and governance-vendor (Credo Agent Governor, ValidMind Atryum) runtime-control loci; second data point after OWASP ACS that open standards (OpenID, OAuth2 for MCP, OpenTelemetry) are the claimed basis for agent identity and tracing.
Open questions raised
- Does WSO2 Agent Manager implement or intend to implement OWASP’s Agent Control Standard, or is it another parallel runtime-control model?
- Would an open-source, self-hosted control plane satisfy a supervisor’s expectations for agent logging and oversight evidence, and who supports it under DORA’s contractual requirements — WSO2 (managed SaaS) or the firm?
- Is there any EU/UK regulated reference — none is named.
- What does Forrester’s Agent Control Plane Landscape, Q2 2026 actually contain, and which other vault vendors are in it? (Report not read; candidate for a future source.)