BACK TO BLOG

AI usage policy and agentic AI governance: what recent AI news means for you

Every two weeks, we round up a few AI stories that matter for the people responsible for AI strategy, and add our take on what each one means for you. This edition centers on a question we keep running into with clients: what does a real AI usage policy look like once agentic tools are involved.

This edition: wider access to agentic AI and why it raises the governance question, AI cost management, and a new player in AI security.

Google's wider Gemini Spark rollout raises the agentic AI governance question

What happened

Google is expanding access to Gemini Spark, its agentic AI platform, announced at Google I/O earlier this year. As of July 23, 2026, it's available to Google AI Pro subscribers in the US, and rolling out worldwide to Google AI Ultra subscribers with local language support. Its most autonomous agent feature, once limited to US Ultra subscribers, is now part of that wider rollout.

In short: agentic AI, tools that can take multi-step actions on their own instead of just answering prompts, is moving from limited preview to a mainstream subscription tier. A lot more employees are about to have access to it inside tools they already use, often without IT ever making that call.

Our take

Every time a major platform widens access to agentic AI, we see the same gap: employees get the tool before anyone sets a policy for how it should be used.

Agents are different from chatbots in a way that matters for governance. A chatbot answers a question. An agent can take a sequence of actions with much less human review at each step. That's what makes it useful, and what makes ungoverned access risky. Once an agent can draft, send, or change things on someone's behalf, IT needs real answers: what data can it see, what can it do without approval, and how do you check what it did afterward.

A rollout like this is a good moment to check whether your AI usage policy actually covers agents specifically, not just generative AI in general. Most policies were written before agents existed and don't say anything about action-taking tools. A handful of leading solutions for enforcing AI usage policies exist now, but a tool only works once you've decided what it should be enforcing.

That decision is really what an agentic AI governance framework is: a clear answer to what an agent can access, what it can do on its own, and where a human still has to sign off. If your team is about to get broader agent access and hasn't put one in place, that's worth doing now, not after the fact. It's why our own agentic AI work always starts with a short discovery phase, mapping out exactly that, before access goes wide.

Source: The Verge, "Google's expanding access to Gemini Spark"

Related: Agentic AI services | Agentic Process Automation discovery sprint

Stripe is reportedly in talks to acquire OpenRouter for $10 billion

What happened

Stripe is in talks to buy OpenRouter, a platform that helps companies switch between different AI models, for around $10 billion, according to a Wall Street Journal report cited by Axios on July 24, 2026. OpenRouter was valued at $1.3 billion earlier this year, so this would be a big jump in a short time.

OpenRouter charges a fee on top of what each AI model costs, similar to how a payments company works. That's part of why Stripe is interested: it fits Stripe's push to become the infrastructure behind how money and AI usage flow together. Other companies are building similar tools, including Ramp, Cursor, and Databricks. When several companies build the same kind of tool at once, that's usually a sign of a real, shared problem.

Our take

Strip away the deal size, and this is a simple story: most companies have no clean way to see or control what they're spending on AI across different providers.

We see this constantly. One team adopts a model for one task, another team picks a different one, and within months nobody has a full picture of total AI spend or a way to compare cost against results. Tools like OpenRouter help, but only if there's a policy behind them: which tasks justify which model, who approves new spend, and how you know a model is worth what it costs.

It's the same problem as SaaS sprawl, just with a new name. Companies already struggle to track 300-plus SaaS tools, who's using them, and what they cost. AI spend is heading the same way, faster, since one team can adopt a new model in an afternoon. Getting ahead of it takes the same basics: a real inventory, clear ownership, and ongoing visibility. That's the same work behind our SaaS Managed Services, and why we treat AI spend as part of that same problem rather than a separate one.

Before shopping for a routing tool, know what you're optimizing for: cost, speed, or accuracy. Without that, routing just makes it easier to spend inconsistently across more providers.

Source: Axios, "What's behind Stripe's OpenRouter move"

Related: SaaS Managed Services | AI Risk and Readiness Assessment | Generative AI services

AI security startup Glow raises $180 million at a $1.2 billion valuation

What happened

Glow, an AI security startup, came out of stealth with a $180 million raise at a $1.2 billion valuation, positioning itself as a new take on endpoint security built for the AI era, according to TechCrunch's July 22, 2026 report. A raise and valuation that size signals real investor confidence that traditional endpoint security wasn't built for how AI tools get used today.

Our take

Traditional endpoint security was built around known applications and known data flows. AI tools break that. An employee using an AI coding assistant, a browser-based agent, or a third-party AI plugin opens new paths for data to move that older tools were never built to see.

We're not surprised a well-funded startup is targeting this. In client conversations, security teams already sense the blind spots but haven't mapped them. That mapping has to come first. Before any security tool, AI-specific or not, is worth buying, you need a clear picture of which AI tools are in use, what data they touch, and where your current stack sees nothing at all, which is exactly the gap our SaaS Security Management work closes.

That groundwork is what makes a security investment worth making. Skip it, and you risk buying a fix for the gaps you already knew about while missing the ones you didn't. It's also why this needs to be ongoing, not a one-time check: AI usage changes too fast for a point-in-time review to stay accurate for long.

Source: TechCrunch, "Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era"

Related: SaaS Security Management | AI Risk and Readiness Assessment | Regulated and security-sensitive systems

The pattern across all three

Different stories, same shift: AI is becoming infrastructure that's already running under the business, often before policy, budget, or security review catch up.

If any of these raised a question about where your organization stands, that's worth a conversation.

Let's talk

Share this post:

Book a meeting

Our Fractional CTOs are strategic, innovative team leaders. They’ll apply their technical knowledge and business strategy to help your company succeed.
talk to a cto
A Trusted Partner for all your digital needs

Meet the Band of Coders Community