Stream: Value & Workflows
In April 2026, SAP published API Policy v4/2026. Section 2.2.2 prohibits API use for "(semi-) autonomous or generative AI systems that plan, select, or execute sequences of API calls" against SAP estates outside SAP-endorsed architectures. Most customers are still working out what it actually means.
The policy landed into a landscape where the gap between AI adoption and AI governance is widening fast. Gartner estimates 40% of enterprise applications will embed agents by end of 2026, up from less than 5% in 2025. The DSAG Investment Survey 2026 reports that 3% of SAP customers run Joule in production today, while 77% of AI-active SAP enterprises use Microsoft Copilot. Most agents reaching SAP estates today do so through Copilot, custom builds or third-party tooling, usually with a service account and no operating model for what happens next.
This session takes an architectural view of the problem. It reads what Section 2.2.2 actually requires, sets out what good looks like inside the SAP perimeter (Joule, the Agent Gateway, AI Agent Hub), what good looks like outside it where agents reach SAP from other platforms and how the two compose into a coherent operating model between now and the second half of 2026, when SAP's own enforcement architecture is expected to ship.
The argument rests on three pillars: the distinction between stochastic and deterministic systems; a close reading of Joule and the SAP Agent Gateway; and an extension of the boundary thinking in SAP's own Integration Solution Advisory Methodology to the agent case. The session draws on the institutional response forming across NIST, OWASP, CoSAI, CSA, and SANS, the public incident record including the Mexico government breach of late 2025, and pattern adoption underway at multiple enterprise SAP customers building governed MCP-server architectures against SAP estates today.
Delegates leave with a five-step readiness frame they can use on Monday morning to inventory and govern the agents already pointed at their SAP estate.