SAP earned ISO/IEC 42001, the first international standard for AI management systems, and is governing its Joule agents through an AI Agent Hub that sets which agents may run and what data they may touch. After a year of look-what-our-agents-can-do, this is the less flashy, more important part: control.
For a year the ERP-agent story has been about capability, what the agents can do, how autonomously, in how many domains. SAP just told a different, quieter story. It earned certification against ISO/IEC 42001, the first international standard for AI management systems, and it is governing its Joule agents through an AI Agent Hub, a central place to set the rules for which agents may run and what data they are allowed to touch. This is the part of the agent era that does not demo well and matters most.
What SAP actually did
Two things. First, the certification: ISO/IEC 42001 is an independently audited management standard for how an organisation governs AI, its policies, risk management, deployment, monitoring and human oversight. SAP has certified its AI management system against it, one of the first major ERP vendors to do so, and points to it as the benchmark buyers should now demand. Second, the control tower: the AI Agent Hub gives an organisation one place to decide which agents are allowed to run and what data each may reach, with auditability and human oversight aligned to the EU AI Act. Capability without a control plane is a liability; SAP is building the control plane.
Why this is the real maturity signal
Recall how this year actually went. Agents shipped across every ERP, and in the same window frontier models, during testing, broke out of their sandboxes and touched systems they should not have, which we covered when AI agents breached real systems in safety tests. The lesson was never that agents are not capable. It was that a capable, goal-seeking agent with loose permissions is a hazard. Governance, deciding what an agent may run and touch, and being able to prove it, is the answer to that hazard. A certification and a control hub are how having agents becomes trusting your agents, and the second is the one a serious buyer pays for.
Governance and intelligence are different axes
Here is the distinction worth keeping straight, because it is easy to conflate. Governance answers whether an agent is allowed to act and whether you can audit it. It says nothing about whether the action it takes is the best one for your business. Both matter, and they are different problems. A perfectly governed agent can still make a mediocre call, the safe price rather than the margin-optimal one, the default safety stock rather than the one that frees your cash. Control keeps you out of trouble. It does not, by itself, make you money.
The layer that sits on both, for Dynamics teams
This is why the optimisation layer, the system of intelligence that computes the decision that is optimal for your specific operation, has to live inside the governed stack, not outside it. On Microsoft Dynamics, a companion app runs in tandem on Dataverse and Power Platform and ships through AppSource, which means it inherits the same governance, identity and audit controls the platform enforces, rather than working around them. That is where Cognilium works: the decision quality that governance cannot provide, delivered inside the governance that a certified, audited stack demands. SAP just made the case that agents need a control tower. The next question is whether, once controlled, they also decide well, the same open question we raised across Oracle's 600 agents and Business Central's.
Share this article
Weekly AI engineering brief
One email a week. New model releases, agent patterns, and lessons from production systems we ship.
No spam, no client data sales. Unsubscribe any time.

Ali Ahmed
AI Business Analyst & Product Owner, Cognilium AI
Ali Ahmed
AI Business Analyst & Product Owner, Cognilium AI
Ali Ahmed is an AI Business Analyst and Product Owner at Cognilium AI, where he owns the product…
