The mouse cursor has been a tyrant of sorts. For five decades, it enforced a simple rule: one person, one screen, one thread of work at a time. That paradigm—born in March 1973 when Xerox PARC engineers powered up the Alto, and immortalized by Douglas Engelbart's "Mother of All Demos" five years earlier—proved remarkably durable. It survived the mainframe era, the personal computing revolution, the rise of mobile. But now, quietly and in fits and starts, it's breaking.
A new breed of platform is arriving where humans and artificial intelligence operate in the same digital workspace, each juggling tasks simultaneously, each with dedicated computing muscle. The shift raises a question that sounds almost quaint until you consider its implications: Is enterprise IT actually ready for this?
Signs of a Shift
By late May of this year, a San Francisco startup called ProjectX emerged from Y Combinator's spring cohort with something it called Infinity OS—an "agent native workspace for heavy parallel workflows on the web." The pitch was blunt. Every application runs on its own virtual machine with dedicated GPU resources. Windows and Linux apps coexist in a browser-based environment. AI agents orchestrate workloads right alongside human users. Cold start times clock in under a minute. No ceiling on concurrency.
Founded in 2022 by Rounak Adhikary, Bishal Karmakar, and Sourya Majumder, ProjectX reported early traction that turned heads, at least according to figures the founders shared on their Y Combinator profile in early June: 20,000 signups in the first 15 days of preview access, with half that volume arriving in the final week alone. These figures are founder-provided and pending third-party validation. Whether those numbers hold up under scrutiny is one question. That they reflect a broader appetite is harder to dispute.
ProjectX isn't operating in a vacuum. Moxt launched in June with the tagline "the agent-native workspace where your AI team works 24/7," positioning agents as "foundation, not a feature." That same month, Syncolab debuted with a platform to "hire AI agents," bundling sandboxed filesystems, browsers, terminals, code editors, and Model Context Protocol runtimes into a single orchestrated system. Aryx calls itself a "control room for Copilot-powered work," with persistent sessions and live visibility into multi-agent coordination. Then there's Caipi, AgentTF, Cogitae, InfiniteWorkspace, Buda, Superpaper—some shipping production code, others still vaporware. All share the same thesis: workspaces should be designed from the ground up for agents, not retrofitted around them as an afterthought.
The enterprise giants aren't sitting idle. At Build this year, Microsoft unveiled Project Solara, which it described as an "agent-first platform" built on a lightweight edge OS and what the company called a "chip-to-cloud stack." Nvidia followed at Computex with RTX Spark, a Superchip marrying an Arm CPU, Blackwell GPU, and 128GB of unified memory—designed, Nvidia said, to "turn Windows into an agentic AI OS." First systems are expected fall 2026, according to the announcement made in late May/early June 2026. Apple announced "new intelligence frameworks" on June 8, with Xcode 27 gaining "agentic coding" features, including compatibility with Model Context Protocol and Agent Client Protocol. Google positioned its Gemini Enterprise offering as "Workspace Intelligence" and launched an Agent Platform. A pattern, then: the operating system layer is being reimagined to treat AI agents as first-class citizens, not glorified plugins.
Three Forces Converging

The technical capability is the first piece. Benchmark progress tells part of the story. OSWorld, a benchmark designed to measure how well AI can actually use a desktop computer, saw performance leap from 12 percent accuracy in March of last year to 66 percent this March, according to industry tracking. Secondary coverage suggests GPT-5.4 may have hit 75 percent on a verified version of the same test by March, though those figures should be cross-checked against official leaderboards rather than taken at face value. Anthropic's Claude models gained desktop control features for macOS and Windows in March and April—mouse, keyboard, application orchestration, the whole kit. OpenAI's Computer Use tool remains in beta but is functional. The agents, in short, can now actually use the software.
Then there's the business case. Grand View Research pegged the AI agents market at $7.63 billion last year, projecting growth to nearly $183 billion by 2033—a compound annual growth rate just shy of 50 percent. This estimate is proprietary and should be understood as subject to the methodologies used by the research firm. BCC Research, in a January forecast, offered a more conservative estimate: $8 billion in 2025 climbing to $48.3 billion by 2030. Methodologies differ, and these are proprietary estimates from research firms with products to sell. But the directionality is consistent. McKinsey's November report on the state of AI found 23 percent of organizations scaling at least one agentic system, with another 39 percent running experiments. Tech functions lead adoption, according to McKinsey's briefs published this year.
The cost structure is the third force, and perhaps the most persuasive. IDC noted in June that 70 percent of high-end DRAM is flowing to AI datacenters, creating supply constraints that contributed to PC shipments falling 5 to 11 percent year-over-year in early 2026. Meanwhile, ProjectX's model runs everything in the cloud with per-app GPU allocation, sidestepping local hardware dependencies entirely. ServiceNow, in a May announcement, reported that its L1 IT Service Desk AI Specialist resolves assigned cases "99 percent faster than human agents." This is a vendor-reported claim and should be considered pending independent validation. But the implication is hard to ignore: if you can shift compute-intensive work to agents operating around the clock in cloud workspaces, the math changes.
Interoperability and Its Discontents
None of this functions without standards. Anthropic's Model Context Protocol, first announced in November 2024 and refined through this year, has become something approaching a de facto standard for connecting agents to tools and data sources. Zendesk announced MCP client and server support in May, with the client in early access and server rollout planned for summer. ServiceNow went further, releasing its MCP Server to general availability across IT, HR, customer service, security, risk, and app development functions. The company also partnered with Google Cloud on a multi-agent interoperability framework spanning agent-to-agent communication, agent-to-UI integration, and MCP connectivity.
But standardization brings exposure. In April and May, OX Security disclosed remote code execution vulnerabilities in multiple MCP server implementations. Patches shipped for LiteLLM and Bisheng; Windsurf was still listed as "reported" two months later. LangChain and LangGraph—widely used frameworks for building agent systems—saw their own vulnerabilities surface in March, including path traversal, deserialization, and SQL injection flaws.
The security posture is evolving in real time, and not always gracefully. In May, CISA, NSA, and intelligence agencies from Australia, Canada, New Zealand, and the UK issued joint guidance titled "Careful Adoption of Agentic AI Services." The document outlined five risk classes: privilege escalation, design and configuration issues, behavioral misalignment, structural cascading failures, and accountability gaps. The agencies recommended selective use in sensitive contexts—diplomatic language for "tread carefully." The Cloud Security Alliance followed with analysis mapping the guidance to enterprise controls, and published a research note in April warning that non-human identities, including agents, often receive excessive, persistent privileges. One in eight AI breaches are now linked to agentic systems, according to a HiddenLayer survey cited by CSA.
A March CSA survey at RSA Conference found 73 percent of respondents expect agents to be vital within a year. Yet 68 percent said they cannot clearly distinguish agent activity from human actions in their logs. That's a problem when compliance frameworks demand audit trails.
The Governance Gap

Gartner projects that 40 percent of enterprise applications will embed agents by the end of 2026, up from under 5 percent in 2025. The same firm predicts that more than 40 percent of agentic AI projects will be canceled by next year due to cost, value, or risk concerns. Both forecasts can be true simultaneously. Embedding an agent is straightforward; operationalizing it at scale with proper governance is something else entirely.
Deloitte's annual State of AI report, published in April and May, found only around a fifth of enterprises have mature governance frameworks for autonomous agents. McKinsey's briefs this year highlight persistent trust and governance gaps, particularly in healthcare, where agentic systems are emerging but regulatory clarity remains elusive. Forrester noted in June coverage that many enterprises remain unprepared to operationalize agentic AI despite considerable enthusiasm.
ServiceNow's approach offers one model: an "agent of agents" architecture where a Context Engine draws from a Service Graph and Knowledge Graph to govern decisions. Its Build Agent reached general availability in Studio and extended support to Cursor, Windsurf, Claude Code, and GitHub Copilot. UiPath launched "UiPath for Coding Agents" to bring orchestration and governance to coding workflows. Automation Anywhere introduced Agentic Process Automation with AI Evaluations and a Context Intelligence Graph slated for release in the third quarter. These are enterprise platforms attempting to layer control atop inherently autonomous systems.
The tension is structural, not incidental. Agents derive their value from autonomy. Enterprises require guardrails. The sweet spot is narrow—and likely to remain that way.
Compliance and Hardware
The EU AI Act looms. The Council agreed in March to adjust application timelines: application deadlines for high-risk standalone and embedded systems are set for December 2, 2027, and August 2, 2028, respectively, per the latest Council agreement undergoing usual legislative processes. US federal agencies continue implementing OMB Memorandum M-24-10, issued in March 2024, which mandates minimum practices for AI systems. ISO/IEC 42001 certification for AI management systems, finalized in December 2023, is seeing broader uptake this year. NIST's AI Risk Management Framework, published in January 2023, remains the reference point for many US enterprises. Compliance, in other words, is becoming table stakes.
Hardware is adapting in parallel. Nvidia's Agent Toolkit, bundled with Nemotron-3 models tuned for agent workloads, shipped in March. Dell announced "Deskside Agentic AI" at Dell Technologies World, pairing high-performance workstations with Nvidia's stack. HPE added the Agent Toolkit to its AI Factory in mid-June. Microsoft's Project Solara introduces what it calls a "liminal" OS concept, where agents exist between device and cloud, supported by presence sensors and desktop companion hardware. These aren't prototypes; first systems arrive this fall.
The Uncertain Horizon

The single-cursor era didn't end overnight. It's ending now. In fits and starts, yes, with promising demos and production disasters playing out simultaneously across the industry. Agent-native workspaces are no longer speculative—they're shipping. The infrastructure layer is being rewritten to support them. Standards are emerging, even as security researchers surface critical flaws. Enterprises are embedding agents in applications while struggling to govern them effectively.
Perhaps the more revealing question isn't when agents will be ubiquitous. It's whether the enterprises adopting them today will still be running them come 2027. Gartner's cancellation forecast suggests many won't make it that far. The ones that do, however, may find themselves operating in a fundamentally different computing paradigm. Not point-and-click. Not even chat-and-wait. Something closer to orchestrate-and-monitor, where work happens in parallel across humans and machines, each with dedicated resources, distinct tasks, separate cursors.
After fifty years, the metaphor is finally breaking. What replaces it remains an open question—one that thousands of engineers, product managers, and IT leaders are trying to answer in real time, with varying degrees of success and more than a little improvisation along the way.
