Oracle Put Agent Orchestration Inside the ERP, and That Changes the Governance Math

Oracle has launched Fusion Claw, which it describes as the first native AI agent orchestration layer embedded directly inside a major ERP platform. The pitch is narrow and telling. Instead of running agents from a separate console and hoping they respect company policy, Fusion Claw lets organizations define standard operating procedures, risk thresholds, and decision rights inside Fusion Applications, where the business logic already lives.
That placement is the story. For two years the agent conversation has been about capability: can the model complete the task. The launches that matter this month answer a different question, which is whether a business can keep an eye on an agent once it is running.
The gap everyone keeps citing
The numbers explaining the shift are now familiar. Around 85% of large companies are experimenting with AI agents, but only about 5% have moved agentic technology into production, and roughly 11% to 14% of pilots scale. Gartner projects that more than 40% of agentic AI projects will be canceled by 2027, and it attributes that to integration and coordination problems rather than model quality. IDC, looking the other way, expects something on the order of 1.3 billion AI agents in use worldwide by 2028.
Put those together and the bottleneck moves. Models are good enough for a lot of work. What is missing is plumbing: identity, permissions, audit trails, and coordination across systems that were never designed to answer to software that acts on its own.
Governance shipped as a product category
Oracle is one entrant in a month that has produced a surprising amount of agent-governance infrastructure. OpenAI launched Presence, an operational layer for deploying voice and chat agents with a defined job scope, limited knowledge access, and approved actions, aimed at billing support, insurance claims, and employee IT requests. Classie Supervise arrived alongside it to give enterprises real-time tracking and accounting for agents already in production.
Salesforce and AWS announced Agentforce 360 for AWS, a joint platform whose Atlas Reasoning Engine runs on Anthropic's Claude models through Amazon Bedrock and, notably, generates immutable audit trails for every agent decision. CrowdStrike is named among early adopters, citing procurement simplicity alongside security, which is a very enterprise way of saying that buying one thing beats assembling five.
Elsewhere, OneTrust expanded its platform with an AI Control Plane and a Governance Command Center, with integrations into ChatGPT, Claude, Copilot, and Glean. Red Hat has been arguing that model-level safeguards are insufficient once agents can execute actions, and pushing for defense in depth across identity, runtime, networking, and infrastructure. Nvidia introduced an Open Agent Safety Platform built with more than 100 partners that is designed to quarantine a rogue agent within milliseconds.
Each of these products attacks the same problem from a different altitude. Oracle's bet is that the audit trail should be the transaction, not a parallel log. If the agent's approved actions are defined as rules inside the ERP, then every decision it takes is already subject to the controls, permissions, and reporting that finance and compliance teams use for everything else.
Why ERP is a natural home
Governance-heavy domains make sense as the first home for production agents because the alternative is worse. A finance team cannot justify handing invoice handling to an agent that exists outside the system of record, takes actions it cannot explain, and produces a log in a different tool. Embedding orchestration in the ERP means the agent inherits the same role-based access, segregation of duties, and audit posture that the rest of the workflow already has.
That is also why Oracle's move puts pressure on its rivals. If the orchestration layer becomes a feature of the core platform, then a standalone agent gateway looks like an extra component to buy, secure, and reconcile. Buyers may find that standardizing on one or two embedded layers beats adding yet another external control plane.
A skeptical read
The governance framing is sound, and it is also good marketing in a market where buyers have been burned by pilots that never shipped. A few cautions are worth carrying into any evaluation. Audit trails only help if someone reads them, and an immutable log of an agent's decisions is not the same as a control that prevents a bad decision in the first place. Embedding orchestration in one vendor's platform also creates a new kind of lock-in, since the agent's history and policy now live inside an application suite. And the cancellation statistics cut both ways: a platform that makes agents easier to deploy does not by itself solve the coordination problem, which lives as much in process ownership as in software.
What to do with this
The practical advice coming out of this month's launches is consistent. Start with one narrow, high-value process, such as invoice handling or access reviews, and put a single agent inside an existing system with strict logging and approvals. Watch how your core vendors respond to Fusion Claw. If they ship their own orchestration layers, standardizing on one or two of them will likely matter more than adding another external gateway.
The larger shift is easy to miss because the announcements sound alike. Agent capability stopped being the headline. The headline is now whether an agent can be given a job, a budget, and a leash, and whether the company can prove, after the fact, exactly what it did.
The consolidation question
Step back from the individual launches and a structural question appears. If every major platform ships its own orchestration layer, buyers will end up with several overlapping control planes, each with its own policy language, its own audit log, and its own way of describing what an agent is allowed to do. That is the opposite of what governance is supposed to provide. Standards bodies and open-source projects are already working on portable agent identity and authorization, but the commercial incentive runs the other way, since a proprietary control plane is a strong reason not to leave.
Oracle's decision to embed the layer in the ERP makes this concrete. A company running Fusion Applications has an obvious reason to use the built-in orchestration and an equally obvious reason to distrust a second, external layer that would have to be reconciled with it. Vendors know this. The question is whether customers will accept a fragmented governance stack, with one control plane per suite, or push for something they can audit across all of them.
The most likely near-term answer is a hybrid. Core systems such as ERP and CRM will own the orchestration for the processes they already govern, because the audit trail belongs next to the transaction. Everything else, including agents that span several systems, will rely on a standalone layer that tries to speak to all of them. Teams evaluating platforms should plan for both, and design their policy definitions so they can be re-expressed if the market consolidates.
What the sellers are not saying
Two claims deserve scrutiny. The first is that an audit trail equals accountability. A log that records every decision an agent made is valuable after an incident, and it is not the same as a control that stops the incident. Immutable records and preventive guardrails are different products, and the launches tend to blur them. The second is that governance is a solved problem once the platform ships it. Most of the failure cases cited this month involved misconfigured permissions, unclear ownership, and processes that no team could describe precisely enough for an agent to follow. Software can enforce a policy. It cannot decide which policy the business actually wants.
For teams that are past the experimentation stage, the useful move is to write down the answers before buying. Which process is the agent allowed to touch, what is the worst thing it can do within its scope, who gets paged when it does, and how is the agent identified when it asks for access. Deploying a single agent inside an existing system with strict logging and approvals, as the current advice goes, tests all four answers at once. The platforms will make that test easier to run. They will not run it for you.
Related articles
The AI Video Price War: Luma Cut Seedance Rates by Up to 73%, and Runway Started Selling Rivals
The engines are close enough now that the invoice is a better guide than the leaderboard.
A 260M Image Model Beat a Rival 6.5x Its Size by Looping the Same Blocks
Adding parameters still works. The more active work is about making a given model do more with less.
Two Voice Models Just Reset the Bar: 50ms to First Audio, and a 99M Model on a Laptop CPU
Quality converged, and the competition moved to where the model runs, how fast it starts, and what it costs per call.
Moonshot's Kimi K2.6 Runs a Thousand Agents at Once and Built a Compiler in Ten Hours
A thousand agents that each need supervision multiply the supervision, not the capacity.