AI Agent Governance: Why Open Standards Won’t Save You From Vendor Lock-In

AI

The Agent Economy Has a Neutral Referee. Don’t Confuse That With a Neutral Market. AI is undergoing a significant shift. Anthropic, OpenAI, Google, Microsoft, and AWS, companies competing aggressively for the future of enterprise AI, are participating as members and contributors in open-standards bodies like the Linux Foundation to help steward shared agent infrastructure. This development appears reassuring. However, it also warrants a degree of caution.

The Agentic AI Foundation (AAIF), established under the Linux Foundation, brings together a broad ecosystem of enterprise and technology organisations. Its governing structure includes participation from major cloud and AI providers. More broadly, key agent interoperability protocols, including Anthropic’s Model Context Protocol (MCP) and the Google-originated Agent2Agent (A2A) protocol, are now hosted within the Linux Foundation ecosystem. This is a positive development for enterprises. However, open infrastructure does not guarantee an open market. This distinction is where the discussion becomes more relevant.

First, What Exactly Are MCP and A2A?

Fundamentally, these protocols address two distinct challenges.

MCP helps an AI agent connect to things. Databases. Applications. APIs. Files. Enterprise systems. MCP reduces the need for bespoke point-to-point integrations by providing a standardised method for connecting AI applications to tools, data, and enterprise systems.

A2A helps AI agents connect. An agent can describe what it can do, discover another agent, delegate work to it, and receive the result. A2A introduces capabilities including standardised task delegation, protocol-version negotiation, Agent Cards for capability and endpoint discovery, and support for cryptographically signing those cards to establish their integrity and provenance.

MCP serves as a standardised interface between agents and tools, while A2A establishes a shared communication protocol between agents.

Combining these protocols enables significant advancements. A company could theoretically have an OpenAI agent interacting with enterprise applications via MCP, delegating part of a task to an agent running on Google Cloud via A2A. In contrast, another specialist agent elsewhere in the workflow performs a separate task. This approach can substantially reduce the need for organisations to develop bespoke point-to-point connectors for every integration. This represents a substantial improvement.

Interoperability Reduces Friction. It Does Not Remove Competition.

The standard interpretation of this development is that interoperability reduces vendor lock-in. I partially agree with this perspective. If enterprises can move information, tools, and tasks between agents using common protocols, switching providers becomes easier. At least technically.

However, it is important to distinguish between open protocols and an open market. The history of technology has taught us this lesson several times. When infrastructure is standardised, competition persists but shifts to new areas. The internet standardised networking. Cloud computing standardised large parts of infrastructure. APIs standardised how applications communicate. None of those developments eliminated powerful technology platforms. These changes shifted the areas of competition.

A similar shift may occur with agentic AI. We can already see this dynamic emerging. ServiceNow, for example, supports both MCP and A2A across its agent infrastructure, enabling external agents to connect into ServiceNow workflows while allowing its own agents to interact with third-party systems and agents. Its strategic advantage therefore does not depend on owning the interoperability protocol. It increasingly depends on owning the enterprise workflow, business context, governance, and execution layer through which those agents operate.

If everybody agrees on how agents communicate, the differentiation moves upwards into:

  • models

  • orchestration

  • enterprise data

  • identity and security

  • agent marketplaces

  • developer ecosystems

  • workflow ownership

  • proprietary applications

  • distribution

Ultimately, ownership of the enterprise relationship becomes critical. Therefore, when leading AI and cloud companies collaborate to govern shared infrastructure, it does not indicate the end of competition. Instead, it signals where future competitive advantages may emerge.

In fact, open interoperability may increase the strategic importance of platforms such as ServiceNow. If agents become increasingly portable, the scarce asset may no longer be the agent itself. It may be the governed enterprise workflow through which that agent is permitted to act.

The Procurement Question Is More Important Than the Protocol Question

Enterprise leaders should also consider a more immediate implication. Many AI procurement models still assume something close to a single-provider relationship. Choose the model. Assess the vendor. Review its security. Review its data practices. Negotiate the contract. Monitor the provider.

Agentic architectures are making this assumption less viable. Imagine a customer-service agent from Vendor A accessing a CRM through MCP, invoking an analytics agent from Vendor B through A2A, then asking another agent running in Vendor C’s cloud to initiate an action.

Whose risk are you assessing? Whose permissions apply? Which system is responsible when an action crosses organisational boundaries? Where is the audit record? And perhaps the most important question: Who had authority to do what?

A2A does not answer all of these questions. Nor does MCP. A2A provides mechanisms for agent discovery, identity-related metadata, authentication requirements, and secure communication, including support for signed Agent Cards. However, it does not determine an enterprise’s authorisation policy. Organisations must still determine agent permissions and manage actions that cross systems, organisations, and trust boundaries.

At this point, interoperability transitions from an architectural issue to a governance concern.

Singapore Offers an Interesting Clue

This issue is especially relevant in the Asia-Pacific region. On 3 July 2026, the Monetary Authority of Singapore and industry partners published the Safeguards for Agentic Finance at Runtime (SAFR) as part of the BuildFin.ai initiative.

The underlying premise is significant. When autonomous agents operate faster than meaningful human intervention can occur, governance cannot be limited to the pre-deployment phase. Governance must occur during runtime.

SAFR introduces controls around agent identity, mandates, proposed actions, policy boundaries, intervention, and auditability before an agent’s action is executed. Its Governance Envelope captures the proposed action, how the agent arrived at it, the relevant context, and the applicable constraints. SAFR is not regulatory guidance or a formal supervisory requirement. It is an industry reference approach, an important distinction for financial institutions evaluating it.

When SAFR is considered alongside MCP and A2A, a compelling architectural framework emerges. Open protocols determine how agents connect. Enterprise governance determines whether they are allowed to act.

This separation may become increasingly important. An institution should not need completely different governance logic simply because one agent happens to come from Microsoft and another from Google. The governance layer should be controlled independently of the vendor layer.

In fact, SAFR explicitly anticipates this reality. Its gateway deployment model can intercept outbound API calls from existing or third-party agents without requiring the organisation to rewrite the agent itself. This approach aligns with the direction enterprise agent governance is likely to take.

Vendor-neutral interoperability should be paired with organisation-controlled governance. Do not rely solely on the agent. Do not rely solely on the model provider. Trust the implemented controls.

What Should Leaders Do With This Today?

Most CMOs do not need to learn protocol specifications immediately. However, one question should be included in the 2027 MarTech roadmap: Can the agents we are buying operate across an open ecosystem, or are we quietly recreating platform lock-in?

For founders developing agent infrastructure, interoperability should be integrated into product strategy. While supporting open standards does not guarantee success, declining to adopt emerging open protocols may become increasingly difficult to justify to enterprise clients.

For CIOs, CDOs, boards, and procurement teams, the implications are more immediate. I would start asking:

  • Protocol portability: Does this platform support recognised interoperability standards such as MCP and A2A?

  • Identity: Can every agent, including delegated agents, be uniquely identified?

  • Authorisation: Who determines what an agent can actually do once another agent calls it?

  • Auditability: Can we reconstruct the complete chain of actions across vendors?

  • Revocation: Can permissions be withdrawn centrally without redesigning the workflow?

  • Accountability: When an agent delegates a task, where does responsibility ultimately sit?

The first question is about interoperability. The other five are about governance. It is important not to conflate these two concepts.

The Bigger Shift

The agent economy is beginning to develop its own shared infrastructure. That is positive. Standards can reduce integration costs, improve portability, and prevent every enterprise from repeatedly rebuilding the same plumbing.

However, open infrastructure should not lead to complacency among business leaders. In fact, the opposite is true. Once infrastructure becomes interchangeable, competitive advantage shifts to other areas.

For vendors, that means the battle increasingly shifts toward orchestration, applications, data, distribution, workflow ownership, and enterprise trust. For platforms such as ServiceNow, this could be particularly significant. If agents from multiple providers can operate across common protocols, the value of controlling the enterprise workflow and execution environment may become even greater.

For enterprises, procurement must evolve from evaluating individual AI vendors to governing ecosystems of interacting agents. For boards, the focus shifts from selecting a specific model to broader governance considerations.

It becomes: When agents from different companies begin acting together inside our organisation, do we still know who has permission to do what, and can we prove it?

This question should be addressed before considering vendor lock-in resolved.

Jamshed Wadia

Business and Marketing Advisor @AIdeate | Advisory Board @CMO Council | AI Ethics & Governance @Mavic.AI | Startup Mentor @Eduspaze & @Tasmu | MarTech & AI Practitioner

https://aideatesolutions.com/
Next
Next

ABM in the AI Era: Why Intelligence Beats Automation