WSO2’s agent manager spurs debate on AI guardrails

The Register ↗

The gist

WSO2’s new Agent Manager is igniting fierce debate over whether centralized AI guardrails will tame the chaos of software agents—or just add another layer of red tape.

What to know

  • WSO2’s Agent Manager, now generally available, is a framework-agnostic, open-source control plane that separates agent logic from identity, guardrails, and observability—with support for LangChain, CrewAI, Microsoft Agent Framework, and custom code.
  • As agent sprawl overwhelms manual oversight, regulators are pushing for inventories that most enterprises can’t produce, since a single visible agent may hide five sub-agents.
  • Critics warn that while centralized guardrails promise order, they could become bottlenecks or even 'panic as a service' if not built for fast, context-driven decisions at scale.

Governance Becomes Infrastructure

WSO2’s Agent Manager shifts agent oversight from scattered developer tools to a unified, framework-agnostic infrastructure layer, promising neutrality and scalability for multi-agent environments.

WSO2 is pitching Agent Manager as infrastructure, not as yet another place to assemble agents: Forkast News described the GA as an open-source governance control plane that “separates agent governance from agent logic for the first time at framework scale — identity, guardrails, and observability become an infrastructure layer, not a developer burden.” WSO2 similarly frames Agent Manager as an open-source governance control plane that formalizes agent governance as infrastructure, explicitly separating governance from agent logic. That framing matters because the product is explicitly meant to govern agents built across LangChain, CrewAI, Microsoft Agent Framework, or custom code, and, as WSO2 puts it, “governs AI agents across any framework, model, or deployment” rather than binding teams to a single builder.

The clearest sign that this is a control plane is what WSO2 pulls out of the agent itself: “At the heart of this architecture is the concept of agent identity… agents need a verifiable, machine-readable identity,” implemented through “an OAuth 2 extension for MCP” tied to OpenID Foundation identity work, while execution runs in “a sandboxed, Kubernetes-native runtime that supports over 40 built-in guardrails.” Its neutrality is part of the design, too: “Because it is framework-agnostic and released under an Apache 2.0 license, it aims to provide a neutral foundation for enterprises” across the AI stack. That neutrality and infrastructure positioning are reinforced by its Apache 2.0 open-source licensing and its stated goal to provide a neutral foundation across the AI ecosystem.

Sources

Agents Need Unique Digital IDs

Traditional human-centric identity models leave enterprises blind to autonomous agent actions, driving the need for machine-specific identities and revocable permissions to prevent unchecked access.

WSO2’s premise starts with a basic mismatch: agents are not employees, so governing them with human-centric IAM and scattered scripts leaves enterprises blind to what the software is actually allowed to do. As Resilient Cyber put it, “agency’s not authorization,” and that distinction matters when autonomous systems can act beyond their intended scope; Akamai’s warning that more than 6% of enterprise AI chatbot conversations contain sensitive corporate data, with 47% of interactions occurring via unmonitored personal accounts, shows how quickly governance fails when agent access rides on human context.

What enterprises need instead is an identity and control model built for nonhuman actors: separate identities, scoped permissions, and lifecycle controls that can be revoked when the task or project ends. Dark Reading argues every agent needs a verifiable identity distinct from the user or workload around it, because knowing that ‘Agent 42 accessed payroll’ isn’t enough; security teams must know on whose behalf it acted, while time-bound authorization, current inventories, and kill-switch style revocation prevent the common failure mode of agents running under personal accounts or keeping stale access long after approval should have expired.

Sources

Agent Proliferation Overwhelms Tracking

Enterprises face a visibility crisis as agent sprawl accelerates, with most unable to inventory their autonomous software—let alone control the complex webs of sub-agents operating beneath the surface.

The strongest evidence that agent sprawl is already beyond manual control is that many enterprises cannot even count what they have. In AI for Founders with Ryan Estes, a speaker pointed to a fresh policy push — “5 days ago Congress introduced a bill… [that] asks companies to produce a list of every agent running in their network” — and said “probably very few enterprises can” do so accurately, because the environment is already a “sprawling” “wild west” where one visible agent may actually be composed of five sub-agents.

That visibility gap is getting worse because companies are no longer deploying one assistant at a time but many specialized agents across departments, multiplying handoffs, permissions, and execution paths. Kings Research notes AI use in business functions reached 19.8% nationally and 37% among firms with at least 250 employees, while the multi-agent orchestration market is projected to grow from USD 1,487.7 million in 2025 to USD 16,777.5 million in 2033; Greylock argues that although nonhuman identities may run 50-to-1 or 100-to-1 versus humans, access-governance decisions operate at “more like a million to one.”

Sources

Vendors Race to Govern Agents

Major tech platforms are converging on integrated, policy-driven agent infrastructure, embedding governance directly into orchestration tools to meet regulatory and operational demands.

WSO2’s architecture bet looks less like an outlier than a market waypoint, because other vendors are also fusing agent execution with governance inside the platform itself. PR Newswire UK reported on Sept. 16, 2026 that “RWS launches Tridion agentic platform… bringing governed AI agents into enterprise content workflows” and said it “gives regulated enterprises a governed way to build and run AI agents across” the content lifecycle, while Tridion Connect feeds regulatory signals into workflows and “Tridion Agent and Tridion Connect are now in public preview, ahead of planned general availability in 2027.”

The same pattern appears in products reaching production now, not just in previews or strategy decks. Yahoo Finance said Driven Tech’s Sept. 21 launch “provides a concrete example of the broader market moving toward production-grade governed agent orchestration around the same period as WSO2’s mid-September GA,” adding that “Lasius is generally available beginning September 21, 2026”; the company describes it as a governed orchestration environment that connects agents, models, knowledge, workflows and tools while applying policies, approvals and auditable controls throughout execution rather than bolting governance on afterward.

Sources

Centralized Guardrails Face Scalability Test

Skeptics warn that unless guardrails can make fast, context-aware decisions, centralized controls risk becoming chokepoints that flood teams with noise and slow innovation.

The sharpest skepticism about WSO2’s control-plane approach is not whether enterprises need guardrails, but whether centralizing them simply recreates the old governance problem in a new form: one more gate that developers must wait on. That concern is amplified by enterprise buyers’ allergy to tool sprawl—Todd Graham told The Register that “if I'm a CISO for a Fortune 500 company, no way I'm going to go buy 15 things to do one thing,” and that for agents “someone's going to have to come to us with a solution that does all of the things,” a standard that raises the bar for any platform claiming to simplify control.

The operational test is whether policy can be enforced with enough context and speed to avoid becoming “panic as a service,” where everything is flagged and nothing is triaged, as OX Security warns. That matters because, as SiliconANGLE theCUBE describes it, “the ratio of humans to agents” will expand “from one to… 10 or 100 to one to thousands,” creating “autonomous beings… within your network that are just doing things all the time,” so a centralized layer only works if it can make deterministic, runtime decisions with evidence rather than bury teams in alerts, approvals, and exceptions.

Sources

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.