Somewhere in the gap between hype and infrastructure, a problem is metastasizing. AI agents—those autonomous software entities now answering customer emails, generating code, and negotiating procurement contracts—are multiplying across enterprises faster than anyone can keep track of them. More troubling: hardly anyone seems to be governing them properly.
A recent analysis by TechRadar Pro, drawing on Deloitte research published in June, put a number on the chaos. According to TechRadar Pro's reporting, only 21% of companies have what could be called mature governance frameworks for their agentic deployments. The rest? They're winging it, even as these agents gain access to payroll systems, execute transactions, and make decisions that cascade through operations.
That governance vacuum has triggered something of a gold rush. Dozens of startups are now racing to solve what might be the most fundamental challenge in agentic AI: giving these things memory and identity before the infrastructure hardens around whatever approach the big players happen to standardize first.
The stakes aren't abstract. An AI agent without memory is effectively starting from scratch with every conversation—it can't learn, can't improve, can't remember what went wrong last time. An agent without verifiable identity, meanwhile, can't be trusted with credentials, can't be audited when things go sideways, and can't be granted permissions in any way that satisfies a compliance officer. As one identity vendor put it earlier this year, the current state of affairs amounts to "growing chaos."
Solving It Backwards
Here's what keeps infrastructure executives up at night: Most organizations deploying agentic systems can't answer basic operational questions. Which agents exist in our environment? What credentials do they hold? What actions have they taken, and can we replay the decision trail when behavior drifts or hallucinates?
The enterprise software establishment has noticed. Okta launched "Okta for AI Agents" in late April, a framework designed to discover and manage autonomous software across corporate networks. IBM showcased identity and runtime security for agentic AI at its Think conference in May. Entrust, in an April blog post, argued that the agentic enterprise requires "a new control plane" rooted in cryptographic trust and what it called "accountable human oversight."
The Cloud Security Alliance went further in May, warning that the industry is solving AI agent identity "backwards"—building bespoke systems instead of aligning with emerging standards before it's too late.
The message from incumbents is remarkably consistent: treat agents as first-class identity subjects, not ephemeral scripts you spin up and forget about.
A Memory Layer Free-for-All
On the memory side, the landscape resembles nothing so much as early-stage competition in a category that hasn't quite solidified yet. Letta, which evolved from the academic project MemGPT, has spent months benchmarking agent memory architectures and publishing research exploring whether a simple filesystem is sufficient or if more sophisticated graph and "engram" structures are required. (Biological metaphors, it turns out, are creeping into software architecture.)
Zep offers what it describes as a temporal knowledge graph architecture—detailed in a February 2025 arXiv paper—that treats agent memory as versioned, queryable context. Mem0, an open-source memory layer highlighted in an April arXiv preprint, has attracted community attention for its approach to scalable long-term retention.
Then there are the newer entrants crowding in. Recallr bills itself as the "#1 memory layer" for agents, though it's unclear who's counting. Revell positions its offering around autonomous agent persistence. Doer, from a company called Donjon Intelligence Systems, promises AI agents with persistent memory. Mnemo and Chorum AI tout similar capabilities—memory that's visible, portable, and travels with agents across sessions and platforms. Hackerware takes a narrower approach with Continuity, a VS Code extension offering what it calls "synthetic memory" scoped to code repositories.
Perhaps the most ambitious recent entry came from EverMind, which launched its EverMemOS platform in late February alongside an $80,000 global competition. The company claims "new state-of-the-art results across multiple benchmarks" and introduces what it describes as an "engram-inspired lifecycle" for agent memory. Whether that's marketing or meaningful innovation remains to be seen.
Community comparisons—like an April "memory shootout" blog post evaluating Mem0, Letta, Zep, and others—reflect a certain practitioner frustration, though such user-driven assessments lack peer review. Each platform makes different trade-offs between retrieval speed, summarization quality, cost, and governance. Clear winners? Not yet.
The Other Half of the Puzzle

Memory persistence, though, is only half the problem. Without cryptographic identity, an agent's memory log is just unverifiable data. It can't be tied to provenance, can't be delegated permissions in a way that satisfies audit requirements, and can't survive the scrutiny of a compliance review.
Several voices have been pushing for standards-based identity substrates. AgentLux, in a May blog post, argued that cryptographic credentials—leveraging OAuth 2.1, OpenID Connect, SPIFFE/SPIRE, and emerging agent-to-agent protocols—will be essential for enterprise deployments by 2026. Strata Identity warned in mid-April that AI agents "will break your identity architecture" unless organizations build agent registries and identity fabrics now. Diagrid echoed the theme in late May, calling AI agent identity "the missing layer in enterprise AI."
Academic work is beginning to catch up. An April arXiv preprint titled "AI Identity: Standards, Gaps, and Research Directions for AI Agents" mapped lifecycle gaps across registration, authentication, authorization, and decommissioning. Another April paper, "Identity as Attractor," presented geometric evidence for persistent identity in what researchers call activation space—suggesting that identity might not be just metadata but could emerge from an agent's learned representations. A May submission on "ECHO: Continuous Hierarchical Memory" proposed multi-tier memory management for vision-language-action models, hinting at how memory and identity architectures might eventually interlock.
Whether any of that theory translates into shipping products is another question.
The Window Is Narrowing
The fragmentation has triggered calls for interoperability, though progress is uneven. References to OWASP's Agentic Top 10, NIST AI frameworks, and IETF efforts appear across vendor blogs and CSA guidance. The Model Context Protocol (MCP) and agent-to-agent specifications get cited frequently as potential common ground, though adoption remains scattered.
What's missing, according to analyses published in recent months, is a widely accepted registry or discovery mechanism. Enterprises deploying multiple agent frameworks—Anthropic's Claude agents, OpenAI's Assistants API, LangChain-based custom systems—have no unified way to enumerate, credential, or audit those agents. Each lives in its own silo, with its own memory store and identity model.
The window to establish norms, as one CSA blog post put it, is "now"—before proprietary lock-in and path dependence make standardization politically intractable. Once enterprises commit to specific platforms and vendors build ecosystems around them, changing course gets expensive fast.
What Enterprises Actually Want

Beneath the vendor pitches and academic proofs-of-concept, enterprise requirements are deceptively straightforward. AI agents need memory that consolidates across sessions. They need forgetting policies that comply with data retention regulations. They need drift detection that flags when behavior diverges from the training envelope. They need cryptographic identities that can be issued, rotated, and revoked. They need runtime scoping—limiting access to only the systems and data a given agent's role requires. And they need audit trails granular enough to reconstruct decisions months later when regulators or internal review boards come asking.
None of the current solutions, it seems, deliver the full stack. Letta, Zep, and Mem0 solve memory but leave identity to the application layer. Okta and IBM address identity governance but don't prescribe memory architectures. The startups promising end-to-end platforms—Recallr, Revell, Doer—have polished websites but limited independent validation of their claims.
The race is on. But it's not entirely clear anyone has crossed the finish line yet—or even agreed on where the finish line is.
