Tesseris logo
TESSERIS
Enterprise Agents Move From Pilots to Production

Enterprise Agents Move From Pilots to Production

Microsoft, Anthropic, AWS, ServiceNow and SAP are operationalizing AI agents across enterprise workflows. Identity, runtime control and verifiable outcomes now determine scale.

12 min read
Date: Jul 15, 2026
Tag: Market Insights

Executive Signal: Enterprise AI Agents Are Entering Production

The July 15 evidence set shows enterprise AI agents crossing an important threshold.

Microsoft is connecting agent creation to organizational data, persistent memory, inventory, evaluation and production lifecycle management. Anthropic is adding stronger enterprise administration and runtime instruction control. AWS is packaging identity, authorization, deployment and lifecycle management into an enterprise agent platform. ServiceNow is embedding agent access controls into operational workflows. SAP is linking agentic AI adoption to measurable business returns.

Together, these developments show that the enterprise market is moving beyond isolated demonstrations and toward controlled agent execution across real systems.

Tesseris signal: Building an agent is no longer the primary enterprise constraint. The harder problem is establishing which agent is acting, what authority it holds, which policies governed its execution, what outcome it produced and who remains accountable.

Execution is becoming operational. Trust remains fragmented.

Key Signals Across Enterprise Agent Platforms

  • Enterprise adoption: Agent platforms are moving from experimental builders toward managed production environments.
  • Organizational context: Agents are gaining access to enterprise data, people, communications, workflows and business semantics.
  • Identity and access: Runtime permissions are becoming distinct from the permissions used to build or administer agents.
  • Governance: Agent inventory, evaluations, lifecycle management, policy controls and observability are becoming standard platform requirements.
  • Economics: Enterprises increasingly expect agentic AI to produce measurable returns rather than experimental productivity gains.
  • Trust: Most platforms govern activity inside their own environments, but identity, authority, execution evidence and outcomes remain difficult to verify across platforms.

Why Production Enterprise Agents Change the Trust Problem

A pilot agent can operate inside a controlled test environment with limited tools, synthetic data and close human supervision.

A production agent is different.

It may access private organizational information, call external tools, modify records, communicate with customers, approve transactions or coordinate work across several systems.

That transition changes the central enterprise question. The question is no longer whether the agent can complete the task. The questions become which agent performed the action, which software version was active, who authorized it, what permissions applied, which data and tools it accessed, which policies governed its decisions, what evidence proves what occurred and who is accountable when the result is wrong.

The July 15 evidence suggests that major platforms are beginning to solve the first operational layer. They can build, deploy, constrain and observe enterprise agents.

The broader trust layer remains incomplete.

1. Microsoft Connects Agent Creation to the Production Lifecycle

Source: Microsoft Copilot Studio release notes

Microsoft listed a production-ready preview of its new Copilot Studio agent experience by the July 15 coverage window. The experience uses an enhanced orchestration runtime and allows agents to connect to organizational information through Microsoft IQ, including emails, calendar events, files, Teams messages and people data.

Microsoft also added reusable agent skills, persistent memory, an organizational agent inventory schema, consolidated readiness information and generally available agent evaluations. Multi-turn testing allows organizations to evaluate agent behavior across realistic interactions rather than isolated prompts.

Microsoft 365 Copilot release notes for the July 15 window also described a path for moving agents from Agent Builder into Copilot Studio, where authors can use more advanced capabilities, publishing controls and lifecycle management.

Market signal: Agent creation is becoming the entry point to a managed production lifecycle.

Early enterprise agent tools concentrated on making agent creation easier. The Microsoft architecture increasingly treats creation as only one stage. An enterprise must also connect the agent to approved data, extend it with controlled capabilities, test its behavior, publish it, monitor readiness and maintain an inventory of deployed agents.

An agent that exists only inside an experimental builder is a prototype. An agent that appears in an organizational inventory, uses persistent context, accesses enterprise data and passes repeatable evaluations is becoming an operational software actor.

Tesseris read: Platform inventory establishes where an agent is managed. Persistent identity establishes which agent acted across systems and over time.

A persistent agent identity should remain connected to the agent controller, represented user or organization, deployed version, approved capabilities, active mandate, execution environment, evaluation history, incident history, lifecycle status and evidence produced during each consequential action.

2. Anthropic Adds Runtime Steering and Enterprise Administration

Source: Anthropic Claude release notes

On July 15, Anthropic made mid-conversation system messages available across supported Claude models on the Claude API, Amazon Bedrock and Google Cloud. This allows applications to introduce new system instructions during an ongoing conversation rather than limiting all system-level instructions to the beginning of the interaction.

Anthropic had also introduced an Admin API beta for Claude Enterprise organizations on July 14. Enterprise administrators can use it to list members, change roles, manage invitations, organize groups and read custom roles.

Market signal: Runtime control is becoming dynamic rather than fixed at deployment.

A long-running agent may encounter changing conditions. A policy may change. A risk threshold may be reached. A human may narrow the scope of a task. A new tool may become available. An incident may require an immediate restriction.

The ability to change system instructions during an active interaction gives developers a mechanism for adapting agent behavior without restarting the complete session. Enterprise administration also provides clearer organizational control over who can access and manage the underlying platform.

Tesseris read: Dynamic runtime instructions should be treated as versioned control events.

Every consequential execution should preserve the original mandate, initial policy state, material instruction changes, actor that authorized each change, tools available before and after the change, actions performed under each policy state and final outcome.

Without this record, runtime flexibility can weaken accountability. A production agent needs more than current instructions. It needs reconstructible authority.

3. AWS Packages Identity, Authorization and Lifecycle Management Around AgentCore

Source: AWS open source blog on Loom for AWS

AWS released Loom for AWS as an enterprise platform for building agents with Strands Agents and deploying them on Amazon Bedrock AgentCore Runtime.

Loom provides a unified management interface and API with identity provider integration, scope-based authorization and lifecycle management for agents, memory, Model Context Protocol servers and Agent2Agent integrations. It also integrates with the AWS Agent Registry for discovery and governance and tracks model and compute usage.

AWS describes Amazon Bedrock AgentCore as infrastructure for building, deploying and operating agents in production at scale. Loom adds an opinionated operating layer around those underlying services.

Market signal: Enterprise agent deployment is becoming a platform engineering discipline.

The components listed by AWS resemble the control requirements of a production software platform: authentication, authorization, deployment, runtime isolation, memory management, tool integration, agent discovery, lifecycle management, usage measurement and governance.

This is evidence that production agents cannot be managed as isolated prompts or model calls. They require an operational layer that coordinates identity, permissions, runtime resources, integrations and observability.

Tesseris read: Deployment control secures the local runtime. Federated identity secures interaction across the Agent Economy.

A production agent should be able to prove its canonical identity, controller, current status, approved capabilities, delegated authority, software version, configuration version, security posture, execution history, economic reputation and the provenance of every external mapping across environments.

4. ServiceNow Makes Agent Permissions Part of Workflow Control

Source: ServiceNow Autonomous Workforce announcement

By the July 15 coverage date, ServiceNow had production AI specialists available for service desk, customer relationship management and employee service workflows. Additional specialists for information technology, security and risk were moving through staged availability.

ServiceNow's AI Skill Kit documentation distinguishes three separate permission concepts: roles required to build and manage a skill, roles required for a user to invoke a published skill and roles under which the skill operates at runtime. Runtime roles determine which data and actions the skill can access on behalf of the user.

ServiceNow also continued developing AI Control Tower as a central system for discovering, observing, governing, securing and measuring artificial intelligence deployed across enterprise systems. Expanded Control Tower capabilities were still moving toward expected general availability in August rather than being fully available on July 15.

Market signal: Agent governance is moving into the workflow and access-control layers.

The person who creates an agent does not necessarily need permission to activate it. The person who invokes the agent does not automatically give it access to every resource available to that person. The agent itself should operate under explicitly restricted permissions.

That separation is necessary when agents begin acting across production workflows.

Tesseris read: Enterprise access control and economic authorization should be connected but not confused.

Runtime permissions can enforce part of a mandate. Execution evidence must establish whether the complete obligation was satisfied. Access control determines whether an action is technically permitted. Verification determines whether the outcome should be trusted.

Sources: SAP AI adoption research | SAP Joule Studio announcement

SAP published research with Oxford Economics on July 15 based on a survey of 2,600 business leaders across 13 countries.

The research found that participating businesses expected an average return on artificial intelligence investment of 21 percent during the current year, compared with 16 percent in the previous year. Respondents expected that figure to reach 38 percent within two years.

Agentic AI was central to those expectations. The survey estimated that average returns from agentic AI could reach USD 17.6 million within two years, compared with USD 4.3 million in the previous year.

These figures represent survey expectations rather than independently verified future returns.

SAP's broader production architecture supports that adoption thesis. Joule Studio is designed to manage the lifecycle of agents, applications and workflows grounded in enterprise data, business processes and organizational semantics. SAP describes a managed runtime with isolated agent environments, configurable policies, observability, lifecycle management and persistent memory.

Market signal: Enterprise agent adoption is shifting from capability demonstrations toward economic outcomes.

The value of an enterprise agent will increasingly be judged through revenue created, costs reduced, cycle time shortened, errors prevented, cases resolved, risk reduced, customer outcomes improved and human time released for higher-value work.

The strongest agent will not necessarily be the one with the highest benchmark score. It will be the one that reliably produces attributable business value within approved risk boundaries.

Tesseris read: Economic reputation should be based on attributable outcomes rather than self-reported activity.

A credible agent performance record should connect agent identity, software version, represented principal, task mandate, runtime actions, execution evidence, verification result, human intervention, final business outcome and settlement or reward.

The production Agent Economy will require proof of value, not only evidence of usage.

Strategic Read: The Production Agent Stack Is Separating Into Six Layers

The July 15 evidence set reveals a production agent stack with six emerging layers.

1. Agent Construction

Platforms are making agents easier to create through natural language, reusable skills and developer environments.

2. Enterprise Context

Agents are gaining controlled access to organizational data, communications, processes, people and business semantics.

3. Orchestration and Runtime

Agents can plan tasks, invoke tools, retain memory and execute across extended workflows.

4. Identity and Permissions

Platforms are adding authentication, access restrictions, organizational roles and runtime authorization.

5. Governance and Observability

Enterprises are gaining agent inventories, evaluations, readiness checks, lifecycle controls, audit information and usage measurement.

6. Outcome Trust

The final layer must connect identity, delegated authority, execution evidence, verified outcomes, accountability and settlement.

The first five layers are rapidly becoming platform capabilities. The sixth remains fragmented.

That produces the central Tesseris thesis: enterprise agents are moving into production, but production readiness is not the same as accountable agency. An agent becomes an economic actor only when its identity, authority, execution and outcomes remain verifiably connected.

Market Conclusion: Production Tooling Is Advancing Faster Than Trust Readiness

  • Enterprise adoption: Accelerating.
  • Production tooling: Advancing rapidly.
  • Organizational context: Improving.
  • Runtime governance: Becoming operational.
  • Cross-platform identity: Fragmented.
  • Outcome verification: Underdeveloped.
  • Primary opportunity: Persistent accountable agency.

The July 15 evidence does not mean that autonomous enterprise operations have fully arrived. It shows that the infrastructure required to deploy agents into real workflows is becoming available.

The next competitive boundary will not be agent creation. It will be the ability to operate agents safely, prove what they did and connect their actions to accountable economic outcomes.

What to Watch Next in Enterprise Agent Infrastructure

  • Whether Microsoft moves its new Copilot Studio agent experience from production-ready preview to general availability.
  • Whether agent inventories preserve identity across version changes, ownership changes and platform migrations.
  • Whether Anthropic exposes durable provenance for runtime instruction and policy changes.
  • Whether AWS Loom gains meaningful production adoption outside demonstration environments.
  • Whether delegated identity remains intact across Model Context Protocol and Agent2Agent interactions.
  • Whether ServiceNow runtime roles become linked to task-specific mandates rather than broad platform permissions.
  • Whether ServiceNow AI Control Tower can govern agents created outside its own platform.
  • Whether SAP customers realize the returns described in enterprise surveys.
  • Whether agent evaluation systems measure real outcomes rather than only test performance.
  • Whether the market develops shared standards for execution evidence and outcome verification.

Frequently Asked Questions About Enterprise AI Agents

What does it mean for an enterprise AI agent to move from pilot to production?

A pilot agent operates in a limited test environment. A production agent interacts with real organizational data, tools, users and workflows. It requires authentication, permissions, monitoring, evaluation, lifecycle management, incident handling and accountability.

Which companies are building production platforms for enterprise AI agents?

Microsoft, Anthropic, AWS, ServiceNow and SAP are among the major companies building agent development, runtime, orchestration, data access and governance capabilities for enterprise use. Their approaches differ, but each is moving beyond simple conversational assistance toward agents that can execute controlled work.

Why does an AI agent need its own identity?

A human login identifies the user associated with a system. It does not necessarily identify the software agent, model, version, configuration and capability set that performed a particular action. A persistent agent identity makes actions attributable to the specific software actor that produced them.

What is runtime governance for AI agents?

Runtime governance applies permissions and policies while an agent is operating. It can restrict data access, limit tools, block actions, require human approval, change instructions or record decisions before an action affects a production system.

Is runtime governance the same as outcome verification?

No. Runtime governance asks whether the agent was permitted to perform an action. Outcome verification asks whether the completed work satisfied the intended requirement. An action can be permitted but still produce an incorrect, incomplete or commercially invalid result.

What trust layer is still missing from enterprise AI agents?

The market lacks a broadly adopted method for connecting persistent agent identity, represented principal, delegated authority, runtime policies, software version, tool calls, execution evidence, verified outcomes, liability, settlement and economic reputation.

Final Take: Enterprise Agents Need Accountable Execution

Enterprise agents are moving from pilots into production.

Major platforms now provide the tools required to create agents, connect them to organizational data, control their permissions, deploy them into workflows and monitor their operation.

That is a major transition. It is not the end of the trust problem.

Platform controls remain divided across separate ecosystems. Agent identity is rarely portable. Delegated authority is not consistently represented. Runtime records do not automatically prove successful outcomes. Economic reputation remains difficult to attribute.

The next phase of enterprise agent adoption will therefore be defined by accountable execution.

The systems that prove which agent acted, under whose authority, with which evidence and with what result will determine how far autonomous agents can be trusted to scale.