"The agent has guardrails, so the data is protected." That sentence conflates two things operating on different planes. Guardrails watch what the agent says; they don't govern what it accesses. Only structural, reproducible access control protects the data — because it isn't statistical: it's deterministic.
With agents that hold no seat and open no screens, per-user licenses stop making sense. Salesforce, SAP, and Microsoft are shifting to consumption pricing: charging for every operation an agent runs against the data. The problem is that you generated that data, and now operating on it costs.
There's no enterprise AI strategy without centralizing, relating, describing, and protecting the data. They aren't four good ideas to choose among. They're four conditions, and missing one invalidates the rest.
The proprietary software a company uses every day is itself built, on the inside, on open source. The hyperscalers build their products on open source. It isn't the risky option — it's the most solid, most audited foundation for a sovereign data infrastructure.
Connecting an agent to too many MCPs doesn't make it more capable: it makes it more expensive and less reliable. Half its capacity goes to loading tools, it chooses worse the more it has, and what we call "hallucinations" is almost always a data gap filled with inference. The key isn't more access: it's better data.