77 percent of enterprises wrote AI agent policies. Only 26 percent can enforce them.

That 51-point gap is not a statistic about effort. It is a crisis of trust with a hard deadline. On June 23, 2026, at the Confidential Computing Summit in San Francisco, OPAQUE launched its 3.0 platform, a direct response to that gap. The company, born from UC Berkeley's RISELab, is not a household name. But its release forces a permanent structural change in how AI governance works: from writing policies you cannot enforce to generating cryptographic proof you cannot refute.
This is not a security story. It is an accountability story. Security is a checkbox. Accountability is a liability shield. OPAQUE 3.0 does not make agents safer in the sense of preventing attacks. It makes it possible to prove, with cryptographic certainty, what an agent did and whether it was authorized to do it. In a regulatory environment where the Colorado AI Act is enforceable now and the EU AI Act hits in August, a policy document without an enforcement log is worse than useless. It is evidence that you knew the risks and chose not to verify whether your controls worked.

What an Agent Is, What It Did, and Who Signed Off
OPAQUE 3.0 launches with two core components: Agent Manifest and Confidential MCP. Agent Manifest is an open standard for verifiable AI agent identity, built on Microsoft's open-source Agent Governance Toolkit, the framework created by Imran Siddique and introduced on April 2, 2026. Confidential MCP is the first Model Context Protocol implementation that is both verifiably governed and secured through confidential computing.
Together, they answer four questions that policy documents alone cannot. What is this agent? What is it allowed to do? What did it actually do? Were governance policies enforced? As Rajesh Beri of beri.net put it, "For the first time, an enterprise can prove — not assert, not promise, prove — what an AI agent is, what it is allowed to do, what it actually did, and whether governance policies were enforced."
The mechanism runs on hardware-signed identity, confidential computing enclaves, and post-quantum cryptography contributed by the Technology Innovation Institute (TII), a founding partner in the standard. AMD and NVIDIA provide hardware support. The enforcement is deterministic and sub-millisecond, a property Microsoft highlighted when it described the Agent Governance Toolkit as "the first toolkit to address all 10 OWASP agentic AI risks with deterministic, sub-millisecond policy enforcement."
The Regulatory Clock Is Ticking
The timing is not accidental. The Colorado AI Act becomes enforceable this month, June 2026. The European Union AI Act's high-risk AI obligations take effect in August 2026. The United States issued executive orders directing federal agencies to accelerate migration to post-quantum cryptography. And in May 2026, Anthropic published "Zero Trust for AI Agents," a security framework that stopped at architectural governance but did not reach runtime verification.
Policy documents do not satisfy audit requirements. A 50-page governance framework that cannot produce a single cryptographic attestation of enforcement is worth nothing to a regulator. It is worth nothing in litigation. The enterprises that wrote policies for 77 percent of their agents but enforce them for only 26 percent are not lagging. They are exposed.
Not a Dashboard. A Runtime Infrastructure Layer.
This is not a policy editor with a nicer UI. OPAQUE 3.0 is a runtime infrastructure layer. Agent Manifest gives every agent a hardware-signed identity. Confidential MCP ensures that when an agent acts, it does so inside a confidential computing enclave that logs what happened and whether it was permitted. The output is a cryptographic attestation, not a compliance report.
Anthropic's Zero Trust framework asked enterprises to assume every agent is compromised until proven otherwise. OPAQUE 3.0 provides the mechanism to do the proving. The distinction matters. Zero Trust without runtime verification is a philosophy. With Confidential MCP, it is an operational capability.
The Agent Governance Toolkit v3.6.0, released on May 12, 2026, and published on May 18, shipped 319 fixes in a security hardening sprint. It sits at 4,000 GitHub stars and has millions of deployments. It is available in Python, TypeScript, Rust, Go, and .NET. The toolkit is already the substrate. OPAQUE 3.0 adds the verification layer on top.
The Stack Absorbs This. Here Is the Mechanism.
Within 12 to 18 months, at least three major cloud providers — AWS, Azure, and Google Cloud — will embed verifiable agent identity and confidential computing into their default agent orchestration stacks. The reason is not that OPAQUE 3.0 is superior technology, though it is. The reason is that every cloud provider with an agent platform now faces the same auditability problem, and OPAQUE 3.0 solves it in a way that is open-source and already integrated with Microsoft's toolkit. Embedding the solution is cheaper than building a parallel one and defending it to regulators who have already seen that cryptographic attestation is possible.
The Agent Governance Toolkit will surpass 50,000 GitHub stars and become a dependency in every major agent framework. It is already at 4,000 stars with millions of deployments and five-language support. The trajectory from utility to infrastructure is well-established. The toolkit's OWASP-complete coverage makes it the obvious integration point. When a cloud provider embeds it, every agent framework that wants to run on that cloud will depend on it. The dependency graph compresses. The toolkit becomes a requirement, not an option.
Enterprises that fail to adopt verifiable governance by mid-2027 will be locked out of high-value contracts in finance, healthcare, and defense. These sectors do not accept policy promises as evidence of compliance. They require audit trails. OPAQUE 3.0 provides the trail. Companies that cannot produce one will lose deals to those that can. This is not speculation. It is the procurement logic of regulated industries. If two vendors bid on a contract and one can produce a cryptographic attestation of agent behavior while the other produces a PDF, the PDF loses.
Startups offering pure policy writing without enforcement face a binary outcome: pivot or die. The market for AI governance splits into two tiers. One tier can prove compliance. The other can only claim it. The second tier becomes uninsurable and unbuyable in regulated verticals. The mechanism is straightforward: insurers price risk based on verifiable controls. If you cannot verify your controls, you cannot get insured. If you cannot get insured, you cannot get contracts.
The second-order consequence: regulators begin requiring cryptographic attestations as a condition of deployment. The EU AI Act's high-risk obligations will start with documentation requirements, but the gap between a written policy and a verified enforcement log is too wide to ignore. Once a regulator sees that proof is possible, they will demand it. The precedent exists in financial services, where SOC 2 reports evolved from self-attestation to mandatory third-party audits. AI governance will follow the same path, compressed into months instead of years.
The third-order consequence: OPAQUE 3.0's approach becomes the de facto standard for regulated industries. It is open-source, backed by Microsoft's toolkit, and supported by TII, AMD, and NVIDIA. The coalition is too broad to be displaced by a proprietary alternative. The standard is set. What would falsify this? If a major cloud provider announces a competing verifiable governance standard within six months that is not built on the Agent Governance Toolkit. That is possible but unlikely, given the toolkit's adoption trajectory and Microsoft's first-mover advantage in open-sourcing it.
Reallocate Budget Now
Reallocate budget. The money currently spent on writing and updating agent policies must shift to verifiable enforcement infrastructure within the next 12 months. This is not a gradual transition. The regulatory deadlines are here. The Colorado AI Act is enforceable now. The EU AI Act hits in August.
Audit current agent deployments. Identify every agent in production that lacks runtime governance. That gap is a liability. Evaluate OPAQUE 3.0 or an equivalent verifiable governance stack. Prepare for regulatory audits that will demand cryptographic proof, not policy binders.
The enterprises that wrote policies for 77 percent of their agents but enforce only 26 percent are not incompetent. They were operating in a world where policy writing was the best available option. That world ended on June 23, 2026.
If You Cannot Prove It, It Did Not Happen
The 51-point gap is closing. Not because more policies are being written. Because enforcement is becoming verifiable. The era of trust-based governance is ending. The new standard is unforgiving: if you cannot prove it, it did not happen.