IBM watsonx Now Governs Agents Across AWS, Azure, and Google
As of October 2, 2026, IBM watsonx Orchestrate can discover and govern agents built on Amazon Bedrock, Microsoft Foundry, and the Google Gemini Enterprise Agent Platform from a single control plane. This makes watsonx the first third-party platform to span all three major hyperscaler agent registries in production. On the same day, IBM moved Agent Identity from private preview to open preview, giving every agent in the estate its own verifiable identity tied to the organization’s existing identity provider.
For enterprise teams running agents on more than one cloud, these two updates together redefine what enterprise AI governance looks like in practice.
The Multi-Cloud Agent Problem Is Now Addressable
Most large enterprises are not building agents on a single platform. A revenue operations team may use Microsoft Foundry for Copilot-connected agents. A data science team deploys on Amazon Bedrock. A newer engineering project runs on Google’s Gemini Enterprise Agent Platform. Each platform provides excellent native tooling for the agents built on it. None of them provides visibility into the others.
That visibility gap has been the core problem in enterprise AI governance. Security teams cannot audit what they cannot see. Finance teams cannot optimize what they cannot count. Operations teams cannot enforce policies that only cover a fraction of the agent estate.
IBM addressed Amazon Bedrock first, making that integration generally available in August 2026. By September 3, IBM confirmed that Microsoft Foundry and Google Vertex AI (the precursor to Google Gemini Enterprise Agent Platform) would follow by end of September. On October 2, IBM confirmed both are now live.
The AI Gateway in watsonx Orchestrate scans connected platforms, discovers running agents, and imports them into the same control plane that governs native agents. The result is a unified inventory where agents from three clouds appear alongside internally built agents in one view.
| Capability | Platform-native tooling | watsonx Orchestrate AI Gateway |
|---|---|---|
| Inventory scope | Agents on that platform only | Agents across AWS, Azure, Google, and native |
| Policy enforcement | Per-platform controls | One set of policies applied cross-cloud |
| Duplicate detection | Not available | Identifies overlapping agents across registries |
| Agent routing | Within platform | Cross-platform intelligent routing |
Agent Identity: Solving the Accountability Gap
Visibility into the agent estate solves one problem. The accountability problem requires something different.
When an agent takes an action on a shared service account, audit logs record the account, not the agent. A breach investigation becomes a search through thousands of actions logged against one credential. Compliance teams cannot demonstrate which agents accessed which sensitive data. Security teams cannot tell whether an unusual pattern reflects a rogue user or a misconfigured agent.
IBM’s response is Agent Identity, now in open preview. Rather than building a separate identity store, watsonx connects agents to the enterprise identity provider the organization already runs. When an agent is created in or registered with watsonx Orchestrate, it can be associated with an identity in IBM Verify or Microsoft Entra. The identity provider remains the source of truth.
The operational model has three properties that matter for enterprise compliance:
Least-privilege access by task. Instead of inheriting all of a user’s permissions, an agent receives a short-lived on-behalf-of token scoped to the specific task it is performing. When the task ends, the token expires. The agent does not accumulate persistent access.
Traceable audit chain. Every action by an agent is logged with four attributes: the originating user, the agent identity, the authorization decision, and the downstream tool or system accessed. An audit record can show that a specific agent accessed Workday to update a field on behalf of a specific employee at a specific time.
Shadow agent control. An agent whose identity is disabled in the connected identity provider can be prevented from executing. Security teams gain a kill switch at the identity layer rather than having to track down and remove embedded API keys or rotate shared credentials across multiple services.
This is a substantial operational advance for any regulated industry where AI agents are touching payroll, legal, or financial systems.
What Enterprises Can Actually Do With This Today
The October 2 release is genuinely in-production capability, not a product roadmap announcement. Here is what is available now:
Cross-cloud inventory. Any organization with active agents on Bedrock, Foundry, or Gemini Enterprise can scan those platforms from watsonx Orchestrate and pull agents into a unified view. Connecting a new platform requires an administrator to establish trust between watsonx and the source platform. Once established, the Gateway scans continuously.
Cross-platform policy enforcement. Controls set at the Gateway level apply to every connected agent, including external agents. An organization that requires all agents to use approved model versions, or that restricts certain tool categories, can enforce those rules without rebuilding agents on individual platforms.
Agent Identity onboarding. Preview participants can configure identity-aware agent onboarding and test on-behalf-of token flows with IBM Verify or Microsoft Entra. IBM is working with preview participants directly to shape configuration patterns and deployment recommendations.
Custom LLM-as-a-Judge metrics. Also released October 2, this feature allows teams to define quality evaluation criteria at runtime, not just at build time. A claims processing agent and a customer onboarding agent can each be evaluated against criteria specific to their function.
For enterprise teams that have been waiting for governance infrastructure before scaling agent deployments, the October release moves that infrastructure from “coming soon” to “available now.”
The Governance Layer Is Emerging as a Category
The IBM release does not happen in isolation. In the past 60 days, multiple organizations have moved to establish governance infrastructure as a recognized enterprise need. OpenAI’s Specialist Dots connect to Microsoft Agent 365 so IT teams can govern AI agents through the same tools used for human employees. Island’s $400M raise explicitly positioned agent control planes as enterprise infrastructure rather than a developer convenience. NVIDIA’s open agent safety platform and IBM’s Agent Identity both address the same underlying problem from different angles: agents need identities, policies, and audit trails the same way employees do.
The converging design pattern is the identity-first control plane. Rather than treating agents as software to be deployed and forgotten, the emerging model treats each agent as a governed entity with an owner, a defined scope of access, an audit history, and a lifecycle that can be terminated at the identity layer.
Enterprise AI leaders who have been holding adoption back because of governance uncertainty now have multiple production platforms to choose from, each covering different parts of the problem. IBM’s October release covers multi-cloud inventory and identity. Microsoft Agent 365 covers endpoint and data security. Vendors like Island and NVIDIA cover runtime behavior. The governance stack for enterprise AI agents is being assembled in real time, and the major pieces are available today.
For organizations planning their agent governance architecture, the question is no longer whether tooling exists. It is which combination of control plane, identity provider, and runtime security covers the specific agent populations and risk profiles their enterprise needs to address. The Enera team works with enterprise AI teams on that architecture.
Sources: IBM October 2026 watsonx update (IBM.com) | IBM Agent Identity announcement (IBM.com) | IBM community: Why agents need identities | IBM August cross-platform discovery GA (IBM.com)