What happened
Microsoft published microsoft/agent-governance-toolkit (public preview), a pip-installable toolkit intercepting every tool call, message send, and delegation in deterministic code — YAML policy evaluation (deny / require_approval), per-agent attribution, and tamper-evident audit; ships framework adapters plus a Claude Code governance plugin, and upstreams its policy engine to the agent-control-spec. Replaces the deprecated agent-os-kernel distribution.
Why it matters
Microsoft is attacking the core agent-governance hole — prompt-level safety is not a control surface — with deterministic, framework-neutral enforcement and evidence trail. Open-sourcing it (Apache-adjacent, one pip install, any framework) gives enterprises a credible open path to audited agent control and pressures commercial agent-governance gateways on capability and price.
Applicability
Platform/security teams running Python/TypeScript/.NET/Rust agent fleets should pilot the toolkit for tool-level policy enforcement and audit trails; watch for GA and MCP-server integration maturity.