Weekly Briefing — 18 September 2026

Tag: S-2026-09-18-weekly-briefing Type: own-writing Author(s): Paul (Red Strata), via the automated weekly-briefing agent Date of source: 2026-09-18 Date ingested: 2026-09-18 Authority weight: high — own weekly synthesis, compiled entirely from the week’s Open Brain captures Raw file: S-2026-09-18-weekly-briefing

What it claims

A synthesis of the 33 thoughts captured in the 7-day window to 18 September 2026. The week was again almost entirely inbound vendor and regulatory intelligence: roughly 24 vendor-intelligence captures, three substantive regulator items (an FCA financial-crime speech, the EBA/ESAs DORA incident-reporting instructions, and FCA cryptoasset perimeter guidance) plus one “no net-new” regulatory-scan note, one practitioner-research item (net-new to the vault but a February 2026 source, outside the daily-scan window), one internal design note (the Redstrata Knowledge Base build, captured twice), and two weekly roll-up syntheses (the 18 Sep weekly-vendor-synthesis and the prior 11 Sep AI-governance-vendor-synthesis). No live-engagement, CLM or meeting captures appeared [S-2026-09-18-weekly-briefing].

Five themes dominated. (1) Agent control-plane proliferation — in one week Salesforce (AI Control Plane), IBM (watsonx Orchestrate AI Gateway), WSO2 (Agent Manager, open-source GA), Dataiku (Agent Management), Broadcom (AgentMinder) and Archer (Evolv Foundation) all shipped or previewed a cross-vendor “register and govern the agents” layer, and Alation added cross-platform agent lineage; each claims to be the single inventory/oversight system that EU AI Act Art. 12 record-keeping, ISO/IEC 42001 asset inventory and SS1/23 model-inventory expectations point at, turning “which layer is the system of record” into a live buyer decision [S-2026-09-18-weekly-briefing]. (2) Governed context to agents via MCP and open semantic standards — Informatica MCP servers to GA on a second hyperscaler runtime, the Fivetran + dbt Labs Context Layer and dbt Wizard, the Ataccama Apache Ossie converter, and Alation’s MCP support (with its IDC Leader placement), establishing MCP as the default channel by which catalogue, DQ, lineage and transformation metadata reaches agents across at least five vendors [S-2026-09-18-weekly-briefing]. (3) Runtime governance/enforcement as a distinct category — Eve Security’s seed extension, Broadcom AgentMinder, OneTrust’s “governance in the runtime itself” framing, Archer’s runtime Bedrock Guardrails, and the OWASP Agent Control Standard, shifting the centre of gravity from pre-deployment testing to enforcement at the moment the agent acts (the operational counterpart of EU AI Act Art. 14 and Art. 12) [S-2026-09-18-weekly-briefing]. (4) Agentic AI moving inside the assurance function itself — Workiva’s agentic internal-audit/GRC testing and Archer’s “AI Operators” put AI into doing control testing, making the second- and third-line agents themselves in-scope AI systems; the Harness “State of Agent DLC 2026” survey benchmarks the asserted-vs-evidenced control gap (77% confident of a complete agent inventory but 44% run active discovery; 76% believe they could disable an agent in under 15 minutes but 33% have an instant kill switch) [S-2026-09-18-weekly-briefing]. (5) Regulators deploying agentic AI and tightening machine-readable evidence — FCA executive director Steve Smart confirmed the FCA processes “over 56 million records every day” with AI and is exploring “agentic supervision” more broadly, and set the FCA taking on AML supervision of ~60,000 legal/accounting entities at “the backend of 2028”; the EBA/ESAs published field-by-field DORA incident-reporting operational instructions; and Cyera completed its ~$1bn Oasis Security acquisition, the third DSPM / non-human-identity deal tracked in 2026 [S-2026-09-18-weekly-briefing].

Its most useful cross-cutting connection: the FCA is exploring “agentic supervision” in the same week at least six vendors shipped agent control planes to firms — supervisor and supervised are adopting the same agentic-AI class at once, which sharpens the read-across question that whatever human-oversight, accountability and logging evidence the FCA comes to expect of firms is evidence the FCA is itself now having to produce [S-2026-09-18-weekly-briefing]. A second connection notes that Workiva and Archer put agents into the second and third lines the same week the Harness survey measured the gap those agents fall into, so the assurance function’s own new tooling lands in-scope of the very inventory-and-oversight gap it is meant to close [S-2026-09-18-weekly-briefing]. A third locates the testable assurance question in the seam between the two biggest themes: governed metadata now reaches agents via MCP while the control planes register the agents, and neither side clearly closes the gap at the MCP call boundary [S-2026-09-18-weekly-briefing]. Its principal gap finding, repeated from prior weeks: zero captures touched the CLM Transformation Programme / CLM Pilot for at least the third consecutive week, and the Programme Governance Specialist service line and the primary-regulator (BCBS/BIS, EU AI Office) channel were under-fed [S-2026-09-18-weekly-briefing].

Notable quotes

None new to this synthesis — the week’s verbatim external quotes (e.g. Steve Smart’s “over 56 million records every day” and “the potential for agentic supervision”) are preserved on their own source pages (S-2026-09-18-fca-financial-crime-protecting-hive). This briefing is synthesis, not a fresh external source.

What’s speculative vs. asserted

  • Asserted: the capture count (33), window (11–18 Sep) and composition; the vendor and regulatory facts (each carried with its own confidence flags on the underlying daily-scan and weekly-vendor-synthesis source pages and already integrated into AI Governance Platforms, Agentic Data Access Governance, FCA approach to AI and the relevant entity pages by the daily scan); the FCA speech figures and dates; the EBA/ESAs DORA-instructions publication; the Cyera–Oasis completion; the Harness survey figures (a vendor-commissioned, cross-sector survey — a benchmark, not FS-specific evidence).
  • Speculative / interpretive: the five theme groupings and the three connections are the briefing’s own synthesis; the “supervisor and supervised converging on agentic AI” and “assurance tooling lands in-scope of its own gap” readings are interpretive; the “which layer is the system of record” framing is the briefing’s inference across the week’s control-plane releases; the CLM and Programme-Governance under-representation is inferred from capture absence, not from a stated change of priority. All vendor “first”/“trusted”/“compliance-grade”/regulatory-alignment claims remain vendor-asserted, with no verified EU/UK regulated-FS reference customer named in any release this week.

Topics this feeds

  • AI Governance Platforms — the week’s individual control-plane moves are already integrated by the daily-scan source pages; this briefing adds the synthesis claim that ≥6 vendors now claim the cross-vendor register in a single week, promoting the “which layer is the system of record” question to a live buyer/assurance decision. See the new concept Agent Control-Plane System-of-Record.
  • Agentic Data Access Governance — adds the synthesis claim that MCP is now the default context channel across ≥5 vendors and the specific assurance test (what policy, certification and logging travel with the MCP call).
  • FCA approach to AI — adds the read-across connection that the FCA is exploring agentic supervision in the same week vendors ship agent control planes to firms.
  • Model Risk Management and Agentic AI — adds the “agents inside the assurance function are themselves in-scope AI” point, benchmarked by the Harness asserted-vs-evidenced gap.
  • Agent Control-Plane System-of-Record — the durable cross-cutting concept promoted from this week’s synthesis.
  • Practice Build — Phase 1 and Phase 2 Tools — the Redstrata KB build is in flight (design v1.1 approved 13 Sep; 55-task/5-phase build; dedicated-domain decision now settled).
  • AI and Data Assurance Pathway — another inbound-dominated week with no project-advancing captures; the “enforcement-locus / system-of-record” decision frame is logged as a candidate reusable artefact, and the time-critical verification queue is routed here.
  • CLM Transformation Programme — zero CLM Pilot / live-engagement captures again this week; continuing capture gap.
  • Service Line — Independent Governance Assurance — the control-plane, runtime-enforcement and agents-in-assurance threads reinforce the independent-assurance demand thesis.

Open questions raised

  • Whether the time-critical verification queue closes next week: Google Model Armor v3 cut-over (flagged “≤25 Sep”, which lands next week); the Credo-relayed EU AI Act Omnibus deadline dates (2 Dec 2027 / 2 Aug 2028) against the Official Journal before any client-roadmap use; Microsoft’s self-reported ISO/IEC 42001 scope and certifier; AWS AgentCore Consent Portal logging/retention; and the Guardrails hub sunset date.
  • Whether the OneTrust runtime-enforcement claim is substantiated by product documentation (standing open question since the August webinar) and whether the Ataccama Apache Ossie converter ships / is demonstrated in an FS deployment.
  • Whether the slipped roadmap dates (Microsoft Purview departed-user deletion Jul→Nov and network DLP GA; Dataiku Agent Management GA to Oct 2026) hold, so they are not represented as operating controls.
  • Whether a deliberate CLM Pilot / live-engagement capture rebalances a further inbound-dominated week, and whether the “enforcement-locus / system-of-record” decision frame gets drafted as a reusable assurance artefact.