Free at First, Metered Later: Who Owns Your Agent's Map
Two vendors have already shown the pattern: one gives the graph away, the other bills outsiders' agents to read it. The renewal you sign this quarter decides which one you end up with.
The loudest graph vendors hold the least data
The pricing signal arrived before the product matured, and the reason is structural. Atlassian and ServiceNow hold thin slices of customer data, development and collaboration metadata, IT service records, next to what Databricks, Snowflake, Amazon, Salesforce and Microsoft already store. Their graphs are a claim on relevance in an agent-mediated stack, not evidence of ownership, which is why they are the ones signalling a meter. Free access buys the dependency; the meter turns on after switching costs are sunk. ServiceNow already bills customers who point outside agents at its knowledge graph.
A skeptic would call the demand a marketing cycle. Neo4j, valued at $2.4B in 2021, posted a quarter with more revenue than its entire prior fiscal year, and ClickHouse's recurring revenue passed $350M on OpenAI and agent workloads. Beside strong quarters at Databricks and Snowflake, data infrastructure is capturing the spend while application vendors work to prove they still sit in the value chain. A stale 2021 mark plus that growth rate, in a category incumbents want to bundle, makes Neo4j an obvious acquisition target inside four quarters. That conversation is cheaper while still being the buyer.
The second chokepoint is authorization, and it has moved
Anthropic's enterprise-managed authentication for MCP connectors, the standard way agents reach outside tools, is generally available. Authorization runs through the identity provider, and per-user consent disappears: one approval instead of hundreds, plus a permission record that turns an audit into a query rather than a reconstruction project. The stickiness is the point. Model quality churns every two quarters; connector registries and permission histories do not. Scoping to Team and Enterprise tiers is the SSO-tax playbook applied to a layer with far higher switching costs.
Two consequences belong in the architecture review. A model vendor's control plane now decides which tools and which data reach the model. And one compromised administrator equals org-wide tool and data access, so hardware-key authentication on AI admin roles stops being optional hygiene.
Where the sources diverge
All the reporting reviewed agrees value is migrating away from the model: Gemma passed 150 million downloads under Apache 2.0, setting a zero-cost floor, and Kiro credited its spec scaffolding, not the model, for a claimed ~82% lower cost per task. The disagreement is which layer above the model wins. Databricks says its platform beats standalone graphs on completeness and freshness; the application vendors say relationships matter more than volume. Both cases arrive with vendor-sourced numbers and no disclosed methodology. The ~50% token reduction, the 82% figure, and a sponsored report concluding that agent winners have "strong, trusted data foundations" are direction, not planning inputs.
One reason to slow the wiring before widening it: a researcher-built malicious "skill", a configurable instruction set distributed much like a browser extension, coaxed Copilot into pushing Outlook, SharePoint and Teams data to an attacker-reachable proxy, and Microsoft's own skills scanner missed it. The same architecture exists on Claude, ChatGPT and Perplexity. One queryable substrate holding every relationship in a business multiplies blast radius where that detection has already failed once.
Access to your context graph is priced at zero exactly once: while your agents can still do their work without it.
What to do
Add capped or most-favored pricing on AI and agent access to vendor-held data to every enterprise application renewal closing before year end, starting with your two largest.
Name the system of record for agent context by the end of this quarter and require contractual export rights from every app-vendor graph that feeds it.
Require allowlist-only agent skills, egress controls and agent-level data-loss monitoring across Copilot, Claude, ChatGPT and Perplexity before approving further graph connections.