Updated October 6, 2026. Part 7 of APERION's Agent Platforms series.
The rest of the agent market splits into two groups, and each is governed differently. Hosted platforms such as Google Gemini Enterprise and ServiceNow AI Agents run agents inside the vendor's service, so you govern them through the vendor's identity, gateway and registry controls and through the tool calls that leave the platform. Developer SDKs from OpenAI, Anthropic, Google and LangChain run in your own code, so you choose where every model call and tool call goes, and you can route both through a control point you run. Most enterprises have both kinds.
This guide covers Google, ServiceNow, OpenAI, Anthropic and LangChain, with short notes on IBM, UiPath, Workday, Databricks and Snowflake. Earlier guides in the series cover CrewAI, Glean, Salesforce, Amazon and Microsoft.
| Vendor | Agent products | Native governance | Where you can add a control |
|---|---|---|---|
| Gemini Enterprise, Gemini Enterprise Agent Platform, Agent Development Kit | Agent Identity, Agent Gateway, Model Armor, Agent Registry | ADK model endpoint; Agent Gateway authorization hooks; MCP servers agents call | |
| ServiceNow | AI Agents, AI Agent Studio, Action Fabric | AI Control Tower | MCP servers agents call; ServiceNow's MCP server when outside agents call in |
| OpenAI | Agents SDK, Agents API, workspace agents, Frontier | Guardrails library, Compliance Logs and API | SDK model client; MCP servers; trace processors |
| Anthropic | Claude Agent SDK, Claude Code, Claude Managed Agents | Managed settings, Compliance API, OpenTelemetry | ANTHROPIC_BASE_URL; MCP servers |
| LangChain | LangChain and LangGraph, LangSmith Deployment | Guardrail middleware, LangSmith tracing | Model provider endpoint; MCP servers; OpenTelemetry |
Google launched Gemini Enterprise on October 9, 2025 (Google Cloud), and on April 22, 2026 introduced Gemini Enterprise Agent Platform, stating that "all Vertex AI services and roadmap evolutions will be delivered exclusively through the Agent Platform" (Google Cloud). Its governance rests on two pieces. Agent Identity gives each agent a SPIFFE-based identity with certificate-bound tokens (Google Cloud IAM). Agent Gateway sits on agents' HTTP traffic, including MCP and A2A, and applies IAM policy, Model Armor screening, registry allowlists and third-party authorization hooks (Agent Gateway). In May 2026, Google made Agent Identity for Agent Runtime, and IAM allow and deny policies for agent identities, generally available, while other agent identity features remained in preview (Google Cloud, May 2026).
For agents built with the Agent Development Kit, the model endpoint is yours to set: ADK can call a custom endpoint through LiteLlm(api_base=...) (ADK documentation), and its traces use OpenTelemetry (ADK observability). GeminiJack, disclosed in December 2025, used a poisoned shared document, calendar invite or email to make Gemini Enterprise send corporate data out with no click by the user. Google fixed it in the retrieval pipeline (Security Affairs, December 2025).
ServiceNow
ServiceNow's AI Control Tower inventories "any AI agent, model, and MCP server," tracks AI identity and access, and maps controls to frameworks including the EU AI Act and the NIST AI RMF (ServiceNow). Action Fabric provides ServiceNow's MCP servers, an MCP client and A2A support (ServiceNow). ServiceNow's community documentation states that bring-your-own-key for spokes and bring-your-own-model options are not currently supported for AI Agents, so agent model calls run on the ServiceNow-managed connection or on ServiceNow's integrated providers with your own key (ServiceNow Community).
BodySnatcher (CVE-2025-12420), rated 9.3 under CVSS 4.0 and disclosed in January 2026, let an unauthenticated attacker impersonate users through the Virtual Agent API and Now Assist AI Agents. ServiceNow patched most hosted instances on October 30, 2025, and self-hosted customers had to upgrade (TechRadar, January 2026). An identity flaw in an agent platform becomes an agent flaw.
OpenAI
OpenAI's agent products changed quickly. AgentKit launched on October 6, 2025, with Agent Builder, a Connector Registry and an open-source Guardrails library. In June 2026 OpenAI deprecated Agent Builder, with shutdown set for November 30, 2026, and pointed users to the Agents SDK (OpenAI). Frontier, launched February 5, 2026 to a limited set of customers, gives each AI coworker "its own identity, with explicit permissions and guardrails" (OpenAI). Workspace agents in ChatGPT entered research preview in April 2026 (OpenAI), and the Agents API entered public beta in September 2026 (OpenAI).
Three details matter for governance. Agents SDK tracing is on by default and sends traces to OpenAI's dashboard; set OPENAI_AGENTS_DISABLE_TRACING or add your own trace processor (Agents SDK tracing). The Guardrails library checks for PII, jailbreaks, prompt injection and unsafe URLs as a wrapper around the client (OpenAI Guardrails). ChatGPT app calls are recorded in OpenAI's Compliance Logs (OpenAI Help), which keep 30 days (OpenAI Help). ShadowLeak, reported in 2025, showed that an email could make ChatGPT's Deep Research agent send Gmail data out from OpenAI's servers; OpenAI fixed it in August 2025 (The Record).
Anthropic
Claude Code and the Claude Agent SDK run in your environment and send model calls to the endpoint in ANTHROPIC_BASE_URL, which Anthropic documents for use with an LLM gateway (Claude Code documentation). Managed settings let administrators set policy that users cannot override. Claude Code exports OpenTelemetry metrics and events, including tool decisions, with prompt text redacted by default (Claude Code monitoring). For Enterprise customers, the Compliance API covers chats, files and projects, with session transcripts from Claude Code and Claude's other agent surfaces (Compliance API).
Claude Managed Agents, in beta, runs agents in an Anthropic-hosted or self-hosted sandbox. Anthropic's documentation states that it is not currently eligible for zero data retention or a HIPAA business associate agreement (Claude Managed Agents), which matters for regulated data.
LangChain
LangChain and LangGraph reached version 1.0 on October 22, 2025 (LangChain), and LangGraph Platform became LangSmith Deployment (LangChain). LangChain's guardrail middleware redacts, masks, hashes or blocks PII and adds human-in-the-loop approval (LangChain guardrails). LangSmith accepts OpenTelemetry traces, and an OpenTelemetry Collector can send the same traces to LangSmith and other tools (LangSmith). CVE-2025-68664, rated 9.3 by GitHub and 8.2 by NVD and disclosed in December 2025, allowed secret extraction through crafted serialized data; it is fixed in langchain-core 1.2.5 and 0.3.81 (GitHub advisory).
Other Platforms in Brief
- IBM watsonx Orchestrate governs agents "wherever they are built or run" (IBM), and watsonx.governance maps controls to the EU AI Act, NIST and ISO 42001 (IBM).
- UiPath routes model traffic through its AI Trust Layer, which masks PII and keeps audit trails (UiPath).
- Workday's Agent System of Record registers Workday agents and third-party agents (Workday).
- Databricks governs models, external providers and MCP tools through Unity Catalog permissions in Unity Gateway, its AI gateway (Databricks).
- Snowflake Cortex Agents run under Snowflake roles, with MCP connectors and traces (Snowflake).
Five Rules for Governing Agents on These Platforms
1. Know which group each agent is in
For hosted agents, list the controls the vendor gives you and the paths that leave the platform. For SDK agents, the model endpoint and tool path are yours, so route them through a control point.
2. Turn off default telemetry you have not approved
Check where each SDK sends traces by default. The OpenAI Agents SDK sends traces to OpenAI unless you disable or redirect them. Send traces to your own collector.
3. Track deprecations and preview status
OpenAI's Agent Builder shuts down on November 30, 2026. Several Google identity features are still in preview. Record the status of every feature you rely on, with the date you checked it.
4. Match data terms to the data
Confirm zero-retention and business associate terms for each agent product before regulated data reaches it. Terms differ between products from the same vendor.
5. Put the tool path under one set of rules
Every major platform here supports MCP. Front the MCP servers your agents call with one gateway, so tool rules, approvals and the audit record are the same whichever vendor's agent made the call.
Operating Limits
- Hosted agents keep model calls inside the vendor. Govern them through the vendor's controls and the tool path.
- Preview features change. Date every dependency.
- Default trace destinations may be the vendor's servers.
- Identity flaws in a platform become agent flaws. Patch platform identity components on the vendor's schedule.
How APERION Fits
For SDK agents from OpenAI, Anthropic, Google and LangChain, APERION's Smartflow can serve as the model endpoint: it serves OpenAI-compatible and Anthropic-compatible APIs, applies a per-agent key with model and route allowlists, and validates the user's OIDC token. For hosted platforms, its MCP gateway fronts the tools agents call and sends out-of-authority calls to a person with approval rights. Both paths write one hash-chained record. Talk to APERION.
More in This Series
- How to govern AI agents across platforms
- CrewAI security and governance
- Glean agents governance
- Agentforce governance
- Amazon Bedrock AgentCore governance
- Microsoft Copilot agent governance
Frequently Asked Questions
How do you govern Gemini Enterprise agents?
Use Agent Identity for per-agent identities, Agent Gateway to apply IAM policy, Model Armor screening and registry allowlists to agent traffic including MCP and A2A, and the Agent Registry for inventory. For ADK agents in your code, set the model endpoint yourself.
What is ServiceNow AI Control Tower?
AI Control Tower is ServiceNow's governance hub for AI. It inventories AI agents, models and MCP servers, tracks AI identity and access, and maps controls to frameworks such as the EU AI Act and the NIST AI RMF.
Is OpenAI Agent Builder being discontinued?
Yes. OpenAI deprecated Agent Builder in June 2026 and set its shutdown for November 30, 2026, directing users to the Agents SDK.
Can Claude Code use an enterprise LLM gateway?
Yes. Set ANTHROPIC_BASE_URL to the gateway's endpoint. Anthropic documents gateway configuration for Claude Code, and managed settings let administrators set policy users cannot override.
Does the OpenAI Agents SDK send traces to OpenAI?
By default, yes. Disable it with OPENAI_AGENTS_DISABLE_TRACING, or register your own trace processor to send traces elsewhere.
Does LangChain have guardrails?
Yes. LangChain's middleware can redact, mask, hash or block PII and add human-in-the-loop approval before tool calls run.
Which agent platforms support MCP?
Google, ServiceNow, OpenAI, Anthropic and LangChain all support MCP, as do Microsoft, Salesforce, Amazon, Glean and CrewAI. That makes the MCP tool path the one control point every platform shares.
Craig Alberino is the CEO and Founder of APERION, which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. Learn more about Smartflow →
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs