The state of the Agentic Enterprise in July 2026
"Agentic arbitrage", AI Act deferrals, delegation gap and agentic e-commerce
In July 2026, two long-awaited stories from the AI world were assigned with numerical data and specific dates. Gartner put a dollar amount on what agents will do to the SaaS business model - up to $234 billion of enterprise application spending exposed by 2030. And the European Union completed, signed, and prepared for publication the first substantive amendment to the AI Act, ie. the Digital Omnibus, moving the high-risk obligations that everyone had planned for August 2, 2026 - including me, in my first article on this Substack: Processes Before Prompts - why agentic CRM will be won on the process layer.
Gartner’s $234 billion - the pricing anxiety I wrote about in May now has a name
In my May roundup I described Salesforce running three pricing models simultaneously (per conversation, per action, per user) that reflected the fact that the market had not settled on how to purchase agentic outcomes. On July 1, Gartner estimated that up to $234 billion of enterprise application software spending is exposed to what it calls „agentic arbitrage“ between now and 2030, roughly 20% of enterprise application SaaS spending by the end of the decade.1
Agentic arbitrage is Gartner’s name for what happens when agents complete tasks across multiple systems and the humans stop opening the interfaces those systems charge seats for.
“Agentic AI changes the economics of software”
according to George Brocklehurst, Managing VP at Gartner, because agents deliver outcomes directly and some software apps simply become invisible. So, the link between user growth and revenue growth breaks (Gartner Says $234 Billion in Enterprise Application Software Spend Is at Risk from Agentic AI).
Two things are worth noting about agentic arbitrage.
First, the $234 billion is not spending that will vanish. It is spending that gets repriced away from seats, toward consumption and outcomes. That is exactly the transition Salesforce’s three parallel pricing models and Microsoft’s “seats as entitlement to consumption” are.
Second, we need to notice where the arbitrage happens. It pertains to AI agents completing work across multiple systems, so the value does not leak out of any single application. It leaks out of the seams between applications - the re-entering data, the “let me check in the other system.” Which means the companies most exposed are not the ones with the worst software. They are the ones with the least-designed processes spanning the most systems.
The seat model is not being killed by better AI. It is being killed by the process layer that will finally get an execution engine in the form of agents.
If you run a system of record, eg CRM, the question your 2027 budget should answer is no longer “how many licenses.” Instead it should be:
“Which processes will agents execute end-to-end, and what are we actually paying for when they do?”
The AI Act moved
In my first article I wrote that enforcement of the AI Act’s high-risk obligations begins on August 2, 2026 and that companies deploying agents on undocumented processes would “spend 2027 paying lawyers what they should have spent in 2026 paying process designers”. The first half of that sentence is now outdated and the second half aged better.
The European Commission proposed the Digital Omnibus on AI in November 2025. Parliament and Council reached provisional agreement on May 7, 2026. Parliament formally endorsed it on June 16, the Council gave final approval on June 29, and the final act was signed on July 8, with publication in the Official Journal expected before the original August 2 deadline, precisely so the amendment takes legal effect in time.2
And this change means slightly different and unclear things to the AI Act in Europe:
Some things are deferred
Mainly, the heavy high-risk compliance machinery. Stand-alone high-risk systems under Annex III, the list that covers employment decisions, credit scoring, access to essential services now come due on December 2, 2027 (a 17-month extension). High-risk AI embedded in regulated products (Annex I) moves to August 2, 2028 (2 years).
Some things are not deferred
Article 50 transparency obligations, disclosing to people that they are interacting with an AI system, marking synthetic content, labeling deepfakes, still take effect on August 2, 2026. So do the Commission’s enforcement powers over general-purpose AI models. Penalties in this tier reach 15 million EUR or 3% of global annual turnover, whichever is higher.
So, now, as of August 2, 2026, the timeline looks as follows:

Now if we read this change through Agentic CRM and Agentic Enterprise lens (service bots, voice agents, outbound sequences drafted by AI), then the obligation that applies to them is the one that was not delayed. The heavy machinery that got pushed to 2027 mostly governs a different class of systems.
The delegation gap is getting its own product category
In June I defined the delegation gap (the distance between the identity that requests an agent action and the identity that executes it) and I wrote that authorization, not hallucination, is the agent risk that actually materializes in production:
In July, the market started shipping infrastructure to cover that gap. On July 16, 1Password announced an integration that lets AI agents, starting with Anthropic’s Claude, securely use a person’s credentials without exposing those credentials to the model itself. It is de facto a dedicated credential layer for AI delegation - the agent can act as a user without ever holding what makes it that user.
So, secrets management for humans officially became a product category (Vault, Key Vault, 1Password). Credential brokering for agents validates the architectural claim underneath the delegation gap: the fix is not a more careful prompt or a more cautious model. It is a separate, auditable layer that owns the mapping between requesting identity and executing identity. Microsoft’s addition of Azure Key Vault credential management to computer-using agents in May was the platform version of the same move; 1Password’s launch is the cross-platform version.
If your AI agent still handles this with a service account that the agent uses for everything, you are on the wrong side of the tooling.
Agentforce goes shopping: agents enter the buying channel
The platform move of the month (actually announced in the end of June) came from Salesforce: Agentforce Commerce reached general availability, with three named agents (Shopper, Buyer, and Merchant)3 and planned native integrations into ChatGPT and Gemini channels.
The three-agent split maps to the three parties in a commerce transaction, but the integration plan is the strategic part. Salesforce is accepting that the conversation surface where buying decisions happen may not be a Salesforce property and is positioning its agents to execute inside someone else’s channel. That is the same logic as Gartner’s arbitrage argument, run in reverse: if outcomes detach from interfaces, then a vendor’s defensible asset is not the storefront UI. It is the agent that can check inventory, confirm the cutoff, and close the transaction against the system of record, wherever the customer happens to be typing.
For CRM practitioners this extends the migration path I described in May. Wave 1 was front-office copilots. Wave 2 was back-office operations (Agentforce Operations, April).
Wave 3 begins now, and it is agents operating in channels the enterprise does not own.
Every question from my previous articles about permissions, scope, and process ownership gets harder in Wave 3 because the execution environment is only half yours.
Summary of the current state of Agentic Enterprise
July was a pretty important month for Agentic AI.
The price tag indicates that the seat-license model incurs up to 20% of enterprise SaaS spending to agents who execute across various systems. This translates to a staggering $234 billion, highlighting the shift in value towards the process layer.
On the legal front, the transparency rules for customer-facing AI are set to take effect on August 2, 2026, while the complex high-risk machinery is deferred to December 2027.
Both stories reward the same behavior: knowing your processes well enough to know where the agents, the money, and the obligations actually are. The vendors will keep shipping, analysts will keep pricing and the regulators will keep deferring / enforcing. What is still optional for a few more quarters is whether your organization does the inventory before the incident does it for you.
“Gartner Says $234 Billion in Enterprise Application Software Spend Is at Risk from Agentic AI”, July 2026, https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence
“Timeline for the Implementation of the EU AI Act”, July 2026, https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
“As AI Agents Transform Commerce, Salesforce Unleashes Its Biggest Agentforce Commerce Release Yet”, June 2026, https://www.salesforce.com/news/stories/agentforce-commerce-announcement/

