Vendor Metrics, Standards and Rules: The Building Blocks of Enterprise AI Agents
As AI agents move into business workflows, three developments are shaping how companies buy and deploy them: what software vendors report in their results, the open standards that let agents connect to business systems, and the regulations that govern their use. This post summarises the latest public information on each.
What vendors are reporting
No official body yet measures spending on AI agents directly, so quarterly disclosures from listed software companies are one of the best available indicators of customer demand. Three large vendors reported agent-related figures in their most recent results.
Salesforce. For the quarter ended 31 July 2026, Agentforce annual recurring revenue exceeded $1.5 billion, up more than 240% year on year. Combined Agentforce and Data 360 annual recurring revenue reached nearly $3.9 billion. Customers generated 3.2 billion Agentic Work Units in the quarter, up 97% from the previous quarter. From this quarter, Salesforce includes Slackbot and Headless 360 in its Agentforce figure.
ServiceNow. For the quarter ended 30 June 2026, ServiceNow said agentic deployments of its AI had grown ninefold in nine months. Its AI annual contract value passed $1 billion, against a target of $1.5 billion by the end of 2026. The company ended the quarter with 658 customers paying more than $5 million in annual contract value.
Microsoft. Microsoft reported more than 30 million paid
Microsoft 365 Copilot seats at the end of its fiscal year on 30 June 2026, with net seat additions more than doubling quarter on quarter. Earlier in the fiscal year, it said more than 80% of Fortune 500 companies had active agents built with its low-code tools.

Figure 1: Agent-related metrics disclosed by three software vendors. Sources: company results.
The vendors are also building tools to manage agents at scale. Microsoft introduced Agent 365 to extend its existing identity, security, and management controls to agents, and said partners including Adobe, Databricks, SAP, ServiceNow, and Workday were integrating it.
ServiceNow launched Otto, which combines Now Assist and Moveworks and routes work to the right agent. Salesforce said bookings of its premium Agentforce editions for sales and service more than doubled quarter on quarter.
Each company defines its metrics differently, so you can't add the figures together or compare them directly.
Open standards for connecting agents
For agents to act, they need reliable ways to connect to data, tools, and other agents. Neutral organizations now manage several of these connection standards.
- Model Context Protocol (MCP). In December 2025, the Linux Foundation formed the Agentic AI Foundation, with Anthropic's MCP, Block's Goose framework, and OpenAI's AGENTS.md as founding projects. Platinum members include Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI.
- Agent2Agent (A2A). Google's protocol for communication between agents from different vendors moved to the Linux Foundation in June 2025.
- Universal Commerce Protocol. Unveiled by Google at the National Retail Federation conference in January 2026, it is designed to let shopping agents discover products and complete transactions across retailers.
U.S. standards work on security and identity
On 17 February 2026, the U.S. National Institute of Standards and Technology (NIST) launched the AI Agent Standards Initiative through its Center for AI Standards and Innovation. The initiative has three pillars: supporting industry-led standards, fostering open-source protocol development, and research on agent security and identity. NIST held listening sessions in April 2026 on barriers to AI adoption in healthcare, finance, and education.
NIST's National Cybersecurity Center of Excellence also published a concept paper in February 2026 on agent identity and authorization, proposing that existing standards such as OAuth 2.0 and OpenID Connect be applied to AI agents.
The EU AI Act timeline
In Europe, the Digital Omnibus on AI entered into force on 27 July 2026 and changed several AI Act dates. High-risk obligations for stand-alone Annex III systems now apply from 2 December 2027, and those for AI embedded in regulated products under Annex I from 2 August 2028.
Watermarking obligations for providers under Article 50(2) were moved to 2 December 2026, while other transparency duties applied from 2 August 2026. The Omnibus also added a prohibition on AI systems used to generate non-consensual intimate imagery and child sexual abuse material.

Figure 2: Selected standards and EU AI Act milestones. Sources: Linux Foundation; NRF; NIST; EU.
How companies are using AI today
Official data show that AI use inside companies is still limited in scope. The U.S. Census Bureau's 2026 AI supplement found that 57% of AI-using firms apply AI in three or fewer business functions, and 66% use it only to augment tasks. AI-related employment decreases were reported by 2% of firms.

Figure 3: Breadth and depth of AI use among U.S. firms. Source: U.S. Census Bureau.
Key takeaways
- Salesforce, ServiceNow and Microsoft now report agent-related metrics in their quarterly results.
- Key agent connection standards, including MCP and A2A, are now hosted by the Linux Foundation.
- NIST launched a dedicated AI Agent Standards Initiative in February 2026.
- EU high-risk AI obligations now apply from December 2027 and August 2028.
For the full data set, see the Epignosis Insights report, Enterprise AI Agents Market Outlook: Adoption Trends Across Industries.