Dipp AI Research · Volume I

The Enterprise Superintelligence Report

Published 10 August 2026. A field study of what enterprises actually deployed, what went wrong, and the architecture the evidence points to.

37 pages · 191 citations · Free to read

Vol. I · p.3Executive summary — headline findings

Contents

  • 01

    The trust gap

    Production adoption at 78% against 28% traceability, and the incidents that followed.

  • 02

    Oversight theater

    Why Human-in-the-Loop fails under volume, bias, timeouts, and missing authority.

  • 03

    Human-in-the-Role

    Binding action to the authority of a named professional, enforced at execution.

  • 04

    The control plane

    Seven components across two layers, and the failure mode each one answers.

  • 05

    Protocols and fabric

    MCP, A2A, ACP, and why interoperability is not authorization.

  • 06

    Economics

    The Big Model Fallacy, a 4,500× price spread, and verified execution as the unit of value.

  • 07

    Standards and outlook

    Regulatory regimes, benchmark gaps, and where accountability settles next.

Headline findings

What the 2026 data showed

78%

of enterprises run agents in production

p.2

54%

reported an agent-related incident

p.2

34.8%

of AI traffic carries sensitive data

p.24

4,500×

price spread across models and providers

p.25

Chapter 04 — the control plane

Seven components, cited passage by passage.

Each component below carries the passage of Vol. I that specifies it. The interactive control-plane map on the Orcher page links directly to these anchors.

  • 01

    Directive Interface

    Vol. I, p.2

    Seventy-eight percent of enterprises run agents in production, and fifty-four percent reported an agent-related incident, yet only thirty-eight percent can name an accountable owner for an agent decision. Accountability cannot be reconstructed from a prompt log after the fact; it has to be recorded as the first act of execution.
  • 02

    Role Identity Fabric

    Vol. I, p.6, p.11, p.22

    Non-human identities now outnumber human identities 144:1, up from 92:1, while ninety-two percent of organizations have no visibility into agent identities and eighty-six percent cannot enforce policy against them. A registry entry records that an agent exists; it does not constitute authorization to act.
  • 03

    Logic Scrubber

    Vol. I, p.6–p.7

    When AI advice was wrong, unaided human accuracy of eighty-two percent fell to forty-five and a half percent. In the analogous security-operations case, 2,992 alerts per day yielded a thirty-seven percent investigation rate, and gateway approvals auto-proceeded after a thirty-second timeout. Verification against a system of record does not fatigue.
  • 04

    Immutable Audit Ledger

    Vol. I, p.5, p.8

    The July 2026 registry-proxy incident produced more than 17,000 attacker actions across a five-day detection gap. Five percent of CISOs are confident they could contain unauthorized agent behaviour, while forty-seven percent have already observed it. Telemetry answers what happened to the system; evidence answers who authorized it.
  • 05

    Data Control Gateway

    Vol. I, p.24

    The share of enterprise AI traffic carrying sensitive data rose from 10.7 percent to 34.8 percent, against 410 million recorded DLP violations and retention exposure of up to seven years under the policies surveyed. A vendor default that changed last quarter is not a control.
  • 06

    Cost Governance

    Vol. I, p.9, p.25

    Across more than 400 models and 70 providers the price spread reaches 4,500×, and sixty-eight percent of enterprise AI programmes run over budget. The Big Model Fallacy is the assumption that the frontier tier is the correct default; stakes, not habit, should select the model.
  • 07

    Observability

    Vol. I, p.6–p.7

    Only twenty-eight percent of organizations can trace an agent action end to end, and roughly sixty percent cannot terminate an agent mid-execution. Single-provider dashboards cannot show the cross-provider path an enterprise directive actually takes — precisely where accountability disappears.

Select a component to reveal its Vol. I excerpt.

Layer 1 — sequential gatesLayer 2 — continuous controls01Directive InterfaceIntent captured02Role Identity FabricAuthority bound03Logic ScrubberAction verified04Immutable Audit LedgerEvidence hashed05Data Control GatewayData boundary + no-training06Cost GovernanceCeilings on autonomy07ObservabilityCross-provider traceOrcher™ · Dipp AI Technologies

Fig. CP-01 · The seven-component control plane

Selected figures

Straight from the report

Vol. I · p.5Documented incident case study
Vol. I · p.6Automation bias: measured accuracy under wrong advice
Vol. I · p.8Incident-to-component mapping
Vol. I · p.10Two letters, one regulation
Vol. I · p.24Vendor training-policy comparison
Fig. ORC-19Orcher Component Schematic v1 — four sequential gates decide whether an action commits; three continuous controls govern data, cost and visibility while it runs.

Download

Take Vol. I with you.#

The complete 37-page PDF, every citation intact. Access is gated: tell us who you are and where to send it, and the download unlocks as soon as the form is submitted — with a copy of the link emailed to you.

Gated download · one form, then the file

Get Vol. I by email

Where should we send it? The download starts immediately and a copy of the link lands in your inbox.

Read it, cite it, challenge it.

Vol. I is free to read and intended to be argued with. If you have a counter-citation, send it.