The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Tuesday, June 30, 2026 · Issue #23

Hey there 👋

Q2 ends today. Look back ninety days and the story isn’t a single launch — it’s a line item. Agents stopped being the thing you demo in a meeting and became the thing you budget for next quarter.

You can see it in where the money went this week. Not into a bigger model. Into agents that spend money, agents that get watched, and the migration that moves a whole company onto them. Three different bets, one direction: the agent layer is now where the enterprise dollar is heading.

But here’s the catch, and it’s the through-line for today: the budget is running ahead of the deployments. Plenty of money, plenty of pilots — far fewer agents actually in production. So the edge this quarter isn’t having the budget. It’s closing the gap between the budget and something that ships. Let’s get into it.


The Big Thing

When your agents start spending money, the controls are the product

Here’s a question that was theoretical a year ago and is operational now: how does an agent pay for something without it going off the rails? Airwallex just raised $320 million to answer it — and the answer is worth copying even if you never touch their product.

The round values Airwallex at $11 billion, up from $8 billion in December, led by returning investor Addition. The headline is the money. The signal is what they’re building with it: two AI-native products aimed squarely at agents that transact. T:0, a platform pitched to run a company’s finance function end to end — bookkeeping, forecasting, taxes, compliance. And Airi, an agent wallet designed around three features that should grab every operator’s attention: delegated agent payments, spend limits, and permission controls.

Read that feature list again, because it’s the whole lesson. When a human spends company money, the guardrails are obvious — a card limit, an approval chain, a manager who signs off. When an agent spends, those guardrails don’t exist by default. You have to design them. Airwallex is betting the company that the defensible layer in agentic finance isn’t the model deciding what to buy — it’s the permission system deciding whether it’s allowed to.

That’s the part you own, and it’s the part that fails loudly if you skip it. A model that picks the wrong vendor is an annoyance. An agent with your corporate card and no spend cap is an incident. So the move, whether or not agents touch money in your business yet: design the controls layer first. What can this agent spend, on what, up to how much, and who approves the exception? Treat delegated payments, hard limits, and permission scopes as the schema you build before you wire up the autonomy — not the thing you bolt on after the first surprise charge.

A few numbers to hold loosely. Airwallex says it hit $1.3 billion in annualized revenue in March, up 74% year over year, on $287 billion of annualized transaction volume. Those are the company’s own operating figures, not audited disclosures, so read them as direction, not gospel. T:0 and Airi are early — Airi is described as wallet infrastructure that will evolve into broader agentic-commerce rails — so this is a “watch the products, copy the pattern” story.

Ship it? The pattern — DEPLOY NOW. If an agent will ever buy, refund, or move money in your business, design the delegated-payment + spend-limit + permission layer this quarter; it’s cheap to build before you have autonomy and expensive to retrofit after. The products (T:0, Airi) — WATCH. They’re newly funded and rolling out; let someone else find the rough edges while you steal the architecture.

Source: Business Wire — Airwallex Series H


Tour de Headlines

Airwallex is one bet on the agent layer. Here are three more from the same week — the size of the prize, the cost of leaving it unguarded, and the incumbents selling the move.

💸 The agent layer is the fastest-growing line in enterprise software

Put a number on the trend. Gartner forecasts spending on purpose-built agent software jumping from about $86.4 billion in 2025 to roughly $206.5 billion in 2026 — a ~139% leap, nearly triple the 47% growth of the overall AI market, on the way to $376.3 billion in 2027. (Those figures are reported from Gartner’s forecasts; treat them as analyst projection, not gospel.) Then the cold shower, also from Gartner: only about 17% of organizations have actually deployed agents, and as many as 40% of agentic projects may be cancelled by the end of 2027. That gap is the opportunity. The budget is no longer the constraint — production is. The teams that win this year aren’t the ones with the biggest agent line item; they’re the ones who get a pilot into production and can prove per-task ROI before the budget committee asks. Instrument outcomes now, so you’re not in the 40%. More here.

🛡️ You can’t manage the agents you can’t see

As teams ship agents faster than they can govern them, “what’s actually running in here?” becomes a real question. Straiker raised a $64 million Series A (about $85 million total) to answer it — led by Marathon Management Partners, Citi Ventures, Illuminate Financial, and Workday Ventures. The platform does three plain things: discover the agents across your environment, test them before they launch, and monitor them while they run. The founder ran Palo Alto Networks’ Prisma Cloud business, so this is the cloud-security playbook pointed at agents. The takeaway costs nothing to copy: inventory the agents you already have, gate every launch on a test, and watch them in production. The company says its run-rate revenue is up 15x in under a year — its own figure, but the direction tracks the trend. Details.

🏢 The incumbents are now selling the migration itself

The fastest way to grow the agent layer is to sell the move onto it. ServiceNow and Accenture launched a joint offering that does exactly that: AI agents for proactive risk and compliance on the ServiceNow AI Platform, plus an Accenture solution that automates migrating off legacy risk tooling. The blocker for most enterprises was never desire — it was the cost and mess of leaving the old platform. Package that away and the question flips from “should we modernize?” to “do we let an agent do the modernizing?” They frame the urgency around risk: they cite the average data breach hitting $10.22 million in 2025, up 9%. The signal for the rest of us: when your platform vendor offers an agent-led migration, the agent layer has stopped being an add-on and become the upgrade path. Read it.


Sponsor

You’re about to govern every agent that spends. Who’s measuring the humans who close?

You’d never let an agent move money without spend limits and approvals. Your sales and customer calls run with none of that — no read on whether your team actually connected. RapportScore measures the human communication signals in every conversation and scores how well your people build rapport. Deterministic measurement, not vibes. Govern the agents and the humans on the same standard.

See your team’s score →

Tool of the Day

🧰 Microsoft Copilot Cowork — the agent that keeps working when your laptop’s closed

What it’s for: hand off longer, multi-step work across Office, Teams, and Outlook to a cloud-hosted agent that runs in the background — even when your device is off.

Copilot Cowork went generally available worldwide for Microsoft 365 Copilot tenants on June 16, so this isn’t 24-hour-fresh — but it’s the most broadly deployable agent most teams now have sitting inside a tool they already pay for. It runs in a secure cloud environment, ships with about 13 built-in skills, and works across browser, desktop, and mobile. Two honest labels before you flip it on. It’s off by default — an admin has to enable it, which is the right call. And it’s metered: pay-as-you-go at $0.01 per Copilot Credit, or a prepaid plan. That metering is the actual lesson here. The unit of cost is the task, not the seat, so an agent left running on a vague instruction can quietly rack up credits. Price the agent session, set a budget, and watch the first week’s usage before you scale it across the team.

See Copilot Cowork →


Worth a Click

  • Google ships agent guardrails: Model Armor for Agent Gateway hits GA — Same theme as the rest of today: the controls are shipping next to the agents. Google’s Model Armor on the Agent Gateway — runtime guardrails against prompt injection and sensitive-data leakage — is now generally available, and its Deep Research Agent (a managed, multi-step research agent that returns cited reports) is in Preview. If you’re on Gemini Enterprise, the governance layer just got a default.
  • Tavant debuts a three-layer agentic AI platform — Another “agent layer as a product” entry: agentic engineering tools, an optional runtime, and domain-specific automation, sold as one stack. The agent-platform land grab is reaching the systems-integrator and enterprise-build vendors — worth a glance if you’re deciding whether to buy the stack or assemble it.

Q2 closes tonight, and the scoreboard is clear: the agent layer became the fastest-growing line in enterprise software. The money this week funded three sides of the same bet — agents that spend (Airwallex), agents that get watched (Straiker), and the migration onto agents (ServiceNow and Accenture). But money isn’t deployment. Gartner says most of these projects haven’t shipped, and a big share will be cancelled. So Q3, which starts tomorrow, belongs to whoever turns a pilot into a governed, measured, in-production line of business. The budget is the easy part now. Build the controls, prove the ROI on one real task, and ship it. Boring controls beat shiny demos.

Stay sharp — The Agent Stack
Built for people who ship AI, not people who tweet about it. Published weekday mornings by Pixiu Media Holdings LLC.

You’re receiving this because you subscribed to The Agent Stack. · Unsubscribe