Artificial IntelligenceNews

WSO2 Brings Sovereign AI Governance to Enterprise Agent Sprawl

WSO2 has announced the general availability of WSO2 Agent Manager, an open control plane designed to help enterprises govern AI agents across different models, frameworks and deployment environments.

The fully open-source platform is designed to give organisations greater control over their growing AI agent estates without tying governance to a particular AI model or development framework. WSO2 said the approach allows enterprises to separate agent governance infrastructure from the underlying agent logic, making it easier to change models, frameworks or deployment environments without rebuilding governance controls.

Agent Manager was launched in beta in June 2026. The platform provides capabilities covering the broader agent lifecycle, from identity and access controls to runtime security, observability and evaluation. The general availability release adds per-agent and per-environment identity controls, MCP-level governance and a sandboxed runtime.

“Speed and control get treated like a tradeoff. They shouldn’t be,” said Dr. Rania Khalaf, chief AI officer at WSO2. “Teams want the freedom to use the best model or framework for the job at hand and control has to respect that heterogeneity. When governance is separated from agent logic, it can scale across frameworks instead of being locked into one ecosystem. Speed comes because of control that never needs to be rebuilt, and that’s exactly what WSO2 Agent Manager delivers.”

As enterprises deploy increasing numbers of AI agents, organisations are also having to address how those agents are identified, secured, monitored and governed. WSO2 points to Gartner research predicting that the average Fortune 500 enterprise will have more than 150,000 AI agents in use by 2028, while only 13% of organisations believe they currently have the appropriate AI agent governance in place.

Many organisations currently rely on separate tools for different parts of the agent environment, including gateways for traffic management, identity systems for credentials and observability platforms for monitoring. WSO2 argues that this fragmented approach can leave gaps across the agent lifecycle.

Agent identity is another area the company highlights. Agents are often managed using identity models designed primarily for human users, while interactions with tools and MCP servers may lack a consistent policy layer. WSO2’s approach places identity and governance at the centre of the control plane, allowing organisations to apply policies consistently across agents and the tools they interact with.

The company also positions framework and model independence as an important part of enterprise AI sovereignty. As model providers change pricing, availability, terms or product roadmaps, organisations may need to move agents between models or infrastructure providers without rebuilding their governance architecture.

WSO2 Agent Manager brings together a range of capabilities intended to provide a central management layer for enterprise AI agents. The platform provides a federated agent inventory, allowing organisations to manage agents across cloud, on-premises and hybrid environments, regardless of the underlying model, framework or runtime.

Its agent identity and security capabilities include verifiable identities, role-based access, delegation, token exchange and the ability to revoke agent access. Governance controls include more than 40 built-in guardrails, covering areas such as personally identifiable information masking and rate limiting. These controls can be applied at the agent, MCP and LLM levels.

Agent Manager also provides lifecycle management, including versioning across development, staging and production environments, as well as the ability to suspend an agent. For monitoring and evaluation, the platform uses OpenTelemetry for end-to-end tracing and supports continuous evaluations at trace or agent level. Rule-based and LLM-as-a-judge monitors can be used to identify issues such as excessive token consumption and changes in agent accuracy.

The platform also includes a Kubernetes-native, sandboxed runtime designed for secure agent execution, with real-time agent suspension capabilities. WSO2 said Agent Manager is designed to remain framework-agnostic and is built using open-source technologies and standards, including OpenTelemetry, MCP and OAuth 2.0.

The platform can manage agents built using Python or Ballerina frameworks that support OpenTelemetry, including LangChain, CrewAI, Amazon Bedrock Strands and Microsoft Agent Framework. WSO2 has also been involved in work around standards for agent identity and interoperability. The company co-authored the Identity Management for Agentic AI whitepaper with the OpenID Foundation and an OAuth 2 extension for MCP, which WSO2 said contributed to the identity and MCP governance capabilities in Agent Manager.

The company has also joined the Agentic AI Foundation, continuing its involvement in the development of infrastructure and standards for agentic AI. WSO2 was included among the vendors in Forrester’s Agent Control Plane Landscape, Q2 2026 report and was recognised with the Best Innovation in Open Source AI award at the AI Dev Summit’s 2026 AI Tech Awards.

WSO2 Agent Manager is generally available now under the Apache 2.0 licence. The platform can be deployed as a self-hosted solution, giving enterprises control over where their agent data is stored and processed, or accessed as a managed SaaS offering.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button