AI
Agentic AI in 2026: what actually changed, and where it goes next for enterprise systems
It is worth separating signal from noise on agentic AI. The important change through 2025 and into 2026 is not that models got better at chatting. It is standardization. Two protocols in particular have moved agents from bespoke demos toward infrastructure that an enterprise can operate, version and secure. That is a bigger deal than any single model release.
MCP and A2A: the two protocols that actually matter
Anthropic introduced the Model Context Protocol in November 2024 as an open protocol for how agents connect to tools and data sources, using JSON Schema for tool definitions and JSON-RPC for invocation. In December 2025 Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation, with OpenAI, Google, Microsoft, AWS and Block among the founding members. By early 2026 more than 10,000 public MCP servers had been published, and the protocol was supported across major model providers and agent frameworks.
Google introduced the Agent2Agent protocol in April 2025 for communication between agents built on different platforms. A2A reached version 1.0 in April 2026 as a stable production standard, shipping with signed Agent Cards for verifiable agent identity, with over 150 organizations reported running it in production.
The plain language reading is this. MCP is a universal port that lets any compliant agent use any compliant tool. A2A is the layer for agents to talk to other agents, with signed identity so a receiving agent can prove who is calling. Together they are what turns agents from clever prototypes into components that a serious IT function can plan for.
Why standardization matters more than a model release
Enterprises do not adopt technology that cannot be operated. A brilliant model with a bespoke integration surface is a science project. The same model behind a standard protocol becomes something a security team can review, an architecture team can approve and a support team can debug. That is the change 2026 has actually delivered, and it is the reason vendor roadmaps have suddenly rearranged themselves around agents.
The number to attribute carefully is the Gartner prediction that 40 percent of enterprise applications will feature task specific AI agents by the end of 2026, up from less than 5 percent in 2025. That is a prediction from an analyst house, not a measured fact. Adoption statistics in this space are noisy and often vendor sourced. Leaders should discount confident numbers and pay attention to whether the protocols and governance are in place, because those are the leading indicators of whether the number, when it lands, will describe useful adoption or shelfware.
What this means specifically for Oracle estates
Oracle's own direction in 2026 points the same way. Oracle Fusion Cloud Release 26B introduced 22 Fusion Agentic Applications across ERP, HCM, SCM and CX, running inside the customer's existing security and governance framework. Oracle APEX 26.1, generally available on 14 May 2026, introduced AI Agents and what Oracle calls governed generative development, keeping agents inside APEX's existing security and workspace model rather than beside it. The direction is consistent: agents belong inside the enterprise's control plane, not outside it.
For any organisation running EBS, Fusion, APEX or a combination, the practical implication is not that you now need to buy an agent. It is that you need to be honest about whether the substrate under your data can support one. Agents are only as good as the data, the semantics and the security model beneath them. That is true in the GCC, in Saudi Arabia, the UAE and Qatar, and it is equally true in the US, UK, Europe and Australia. Regulation differs, the underlying discipline does not.
The unfashionable prerequisites that decide the outcome
The prerequisites for useful enterprise agents are unfashionable, they are not on any product slide, and they are the actual decisive factor.
- Defined business semantics, so a term like revenue means one thing across finance, sales and reporting rather than three subtly different things.
- Curated and trusted datasets that an administrator has approved for use, not a general permission to query the schema.
- Identity and least privilege access for agents, treating an agent as a first class actor with its own principal rather than as an extension of whichever human ran it.
- Complete audit trails for the actions agents take, at the same standard as for human actions, so an auditor can reconstruct what happened.
- Human approval gates on anything financial, irreversible or reputationally sensitive, no matter how confident the model looks.
None of that is exciting. All of it is what separates an agent that helps from an agent that becomes an incident.
Where it goes next, stated with appropriate humility
Predicting the next twelve months in this space with any precision is a mistake, but the direction is reasonably clear.
- More agent to agent delegation across organisational and vendor boundaries, with A2A carrying the identity claims.
- Agent identity becoming a real access management problem, not a science project. Existing IAM stacks will have to represent agents as principals, and existing SIEM tools will have to log their actions in a way a human analyst can read.
- Regulatory attention on accountability when an autonomous chain of agents causes harm. This will land unevenly across jurisdictions, and organisations that already have complete audit trails will find the transition much cheaper.
- A widening gap between organisations with clean, governed data and those without. Agents amplify whatever they are pointed at, which means the return on data discipline goes up sharply.
A grounded position for enterprise leaders
The scarce input is still domain understanding and data discipline. That has not changed and it is not going to. The sensible enterprise posture on agentic AI is to adopt where the process is well defined and reversible, keep humans on the decisions that carry consequence, and invest in data and semantics now because that is the part no protocol will do for you.
That is the position we take with clients. Where APEX or Oracle Fusion agents are a good fit for a well defined internal process, they are worth adopting deliberately, with senior review and governance in place from day one. Where the data or the semantics are not ready, the honest advice is to fix that first. Our APEX Development page describes how we approach AI Agents inside Oracle APEX specifically, and our Capabilities page describes the wider Oracle scope we cover.
Want to talk about this in your environment?
30 minute call with a senior Oracle engineer. No sales layer.
Follow Datpire on LinkedIn for more Oracle engineering notes.