On ServiceNow's latest earnings call, Bill McDermott said, "There are 2.2 billion agents entering the enterprise globally. That's 2.2 billion new identities."
That is the most important statement made about enterprise AI security (and perhaps enterprise IT as a whole) on an earnings call this year. Not because it's new; anyone leveraging AI has seen the wave coming. But because when ServiceNow names Agent Identity as the central enterprise challenge as the center of its strategy, the category has officially arrived.
McDermott went further, outlining the architecture ServiceNow is building around this reality: AI Control Tower plus Armis plus Veza. Every AI in the enterprise is visible, governed, and secured in one command center. Device tracking at scale. Entitlement mapping. Unified visibility.
He's right. And he's pointing at exactly the right problem.
What I want to add to complete the picture is the layer that comes after visibility. The one that makes the command center's promise real.
The Validation
Visibility is the right starting point. You cannot govern what you cannot see. ShadowAI is real and a crucial priority we are also focusing on at aizome. An enterprise with 2.2 billion agents entering its environment and no systematic way to discover, classify, and map them is not doing security - it's doing hope.
Entitlement mapping is the right second step. Understanding what every agent is authorized to access, who owns it, and what its permission scope looks like is the foundation that everything else is built on. Without it, governance decisions are made in the dark.
The command center framing is the right aspiration. Every security leader should want a single place where every AI actor in their environment is visible, mapped, and monitored. The fragmentation that comes from governing agents in one tool, assistants in another, and copilots in a third is exactly how incidents hide.
ServiceNow is building the visibility and entitlement layer at scale. That is genuinely important work. And it is half the answer.
Where the Gap Opens
Here is the question that visibility and entitlement mapping cannot answer:
Is this agent doing what it was built to do - right now, in this session, in this chain, at this moment in the execution?
That question is not answered by knowing the agent exists. It is not answered by knowing what it is entitled to access. It is answered by a governance layer that observes the agent's behavior at the point of execution and evaluates it against the organizational intent that authorized the agent in the first place.
The gap between entitlement grant and action execution is not a monitoring gap. It is a governance gap. And it is precisely where enterprise AI agent risk accumulates in production environments.
Let me make this concrete. An agent is visible in the command center. Its entitlements are mapped. Its human owner is documented. Its permission scope is correctly defined.
Six days after provisioning, that agent is three hops into a workflow nobody designed, invoked by a supervisor agent, operating on a delegation chain that has abstracted the original human authorization entirely. Its actions are technically within its entitlement scope. They are completely inconsistent with the organizational intent that established that scope.
The command center sees the agent. It sees the entitlements. It does not see that what the agent is attempting to do right now has diverged from what it was built to do.
That divergence is not a visibility failure. It is an intent governance failure. And it is the failure mode that matters most at the scale McDermott is describing.
The Missing Layer: Runtime Intent Governance
When you are talking about 2.2 billion agent identities, the governance architecture has to operate at machine speed. Not periodic reviews. Not access certifications that run quarterly. Continuous evaluation at the moment of execution - before the action completes, not after it produces an outcome nobody authorized.
This is what ARISE - Agentic Runtime Identity Security Enforcement - is built to provide. Three capabilities that complete the command center McDermott is describing:
Organizational intent capture. Every agent needs more than an entitlement map. It needs a structured definition of what it was built to do, what business function it serves, what systems it should touch, what data it should handle, what actions it is authorized to take. This becomes the baseline against which everything that follows is evaluated. Not a rule set that tries to enumerate every prohibited action. A statement of purpose that everything the agent does is measured against.
Runtime behavioral governance. Every action the agent takes - every tool call, every data access, every delegation hop - is evaluated in real time against the organizational intent baseline. Not "does this agent have permission to do this" but "is this specific action, in this context, consistent with what this agent was built to do." Those are different questions. Only the second one closes the gap between entitlement grant and governance.
Intent drift detection. Agents don't stay static. Workflows change. Models get updated. New integrations expand what agents can reach. An agent whose behavior progressively diverges from its organizational intent, not in ways that trigger permission violations, but in ways that represent meaningful drift from purpose, needs to be caught before the drift produces an incident. Continuous behavioral evaluation against the intent baseline, at the session level and the trend level, is what catches it.
These three capabilities are not adjacent to visibility and entitlement mapping. They are the next layer in the stack - the one that governs what happens between the entitlement grant and the action, at the speed agents actually operate.
The Full Stack
McDermott's architecture - visibility, device tracking, entitlement mapping, unified command center - is the right foundation for governing 2.2 billion agent identities at enterprise scale.
The full governance stack that makes that foundation operational requires one more layer:
Discover and classify every agent in the environment, including the ones nobody approved and the ones built by employees solving problems. That's the visibility layer.
Map entitlements and ownership - every agent tied to a human owner, every permission scope defined, every agent visible in the command center. That's the entitlement layer.
Capture organizational intent - not just what agents are allowed to do, but what they were built to do. The structured statement of purpose that becomes the governance baseline for everything that follows. That's the foundation of ARISE.
Govern at runtime - every action evaluated against organizational intent before it executes. Intent drift detected continuously. Cross-chain accountability maintained across every delegation hop. That's the layer that makes the command center's promise real.
What This Moment Means
When ServiceNow's CEO names 2.2 billion agent identities as the central enterprise challenge on an earnings call, something has shifted.
The conversation is no longer about whether AI agent governance matters. It matters. The Fortune 500 has said so. The investors have heard it. The boards are asking about it.
The conversation now is about whether the governance architecture being built is sufficient for the problem being described. Visibility and entitlement mapping are necessary. They are not sufficient. The runtime intent governance layer - the one that evaluates what agents are actually doing against what they were built to do - is the layer that completes the stack. That is the layer aizome is building.
2.2 billion new identities. The command center that governs them needs to see them, map them, and know in real time whether what they are doing is what they were built to do.
The first two are being built at scale. The third is where the magic happens.
Amir Ofek is CEO and Co-Founder of aizome, an Enterprise AI Agent Identity Fabric Platform and a founding player in the ARISE - Agentic Runtime Identity Security Enforcement - category.