On July 14, Oracle announced an AI-native builder experience for Oracle AI Agent Studio for Fusion Applications, spanning no-code, low-code, and pro-code development at what Oracle states is no additional cost to Fusion customers. Per Oracle, the experience would enable customers and partners to create and run Fusion Agentic Applications, a class of outcome-driven applications executed by coordinated teams of specialized AI agents, natively inside Oracle Fusion Cloud Applications.
Greyhound Research sorts this announcement against what Oracle AI Agent Studio for Fusion Applications already offers, and the sort yields four grades: the new, the extended, the expanded, and the established.
New: the AI Studio Skill. Per the release, the Skill anchors the pro-code path, bringing Visual Studio Code, Git-based command-line workflows, and AI coding assistants including Codex and Claude Code into Fusion-native development. A skill packages the platform knowledge that guides coding assistants.
In Greyhound Research’s view, Oracle’s intent is to bring agentic development closer to a conventional software lifecycle, with local validation and pipeline-based release replacing configurations trapped in an administration console; whether the resulting artifacts prove portable, reversible, and consistently governed across both build paths remains to be demonstrated.
Extended: the ecosystem, via GitHub. A promised public GitHub repository is slated to carry templates, starter projects, and reference architectures, together with sample applications and reusable assets, giving partners and developers a common starting point that Oracle’s studio tooling has not offered before.
Our read of the intent: Oracle is seeding a developer ecosystem around Fusion rather than a studio alone, because public code is how a platform recruits builders; the seriousness of that ambition will be measured by whether the repository arrives live, populated, and actively maintained over time.
Expanded: a marketplace of applications. The AI Agent Marketplace is set to grow from a catalog of individual agents to one of complete agentic applications, sitting alongside the existing portfolio of Oracle, partner, and third-party agents customers can already deploy inside Fusion.
Greyhound Research reads the intent as distribution at scale, turning partner-built applications into catalog products rather than one-off implementations; an application that installs from a catalog and runs as a governed Fusion artifact can travel through Oracle’s channel and partner network in a way bespoke builds never could.
Established: the studio and portfolio. Oracle AI Agent Studio launched in 2025; the natural-language and low-code builders, the approval workflows, and the interoperability protocols are documented capabilities, as are testing and observability, while Oracle’s own counts put the current portfolio at 22 Fusion Agentic Applications, 1,000-plus embedded agents, and 80,000 certified experts trained in the studio.
The intent, as we read it, is continuity: this release does not introduce its agentic direction; it attempts to turn that direction into a broader development and distribution model, built on capabilities Oracle already ships. The centre of gravity shifts from building or customising agents to building and running governed applications natively inside Fusion.
Table 1 grades the announcement in one view.

Greyhound Standpoint: At Greyhound Research, we believe the significance of this announcement is not more agents; the market is already saturated with those. The enterprise agent race has quietly changed shape, and the contest is no longer over who builds the smartest agent but over who owns the governed runtime in which agents are permitted to act. Oracle’s architectural claim is that agents born inside the system of record inherit the security, approvals, and auditability that agents built outside it must reconstruct at great expense.
Why This Matters To CIOs
Greyhound Fieldnotes, drawn from Greyhound Research’s advisory work, confirm that the problem Oracle is aiming at is the real one. Across our 2026 advisory work, we have repeatedly found that the hardest problem in enterprise AI is not building an agent; it is operating one. When agents are built outside the enterprise system, the organization must separately solve identity, approvals, and audits, along with the observability and lifecycle plumbing beneath them, and that is precisely where pilots stall.

Greyhound Research believes Oracle’s claim is credible because it attacks the hardest problem in enterprise AI. On detail, spanning identity semantics, logging depth, and reversibility, it remains unproven. Whether it holds will be decided by the technical documentation Oracle publishes, not by the announcement.
Greyhound Fieldnotes record a consistent pattern: the demonstration wins the room, and the deployment then dies in the corridor between the innovation team and the controller’s office. The agent may perform the task, but production stalls because machine actors were never provisioned within the identity model, the approval matrix, or the audit trail. That corridor is the difference between real governance and dashboard governance.

Greyhound CIO Pulse 2026, across more than 1,000 technology leaders, finds fewer than one in three can point to measurable outcomes across most of their funded AI portfolio. Adoption is not value. Pilots are not production. In agentic systems, the distance between the two is filled by identity, controls, auditability, and the uncomfortable question of who remains accountable when software begins to act.
Every major vendor is racing to own the answer, each positioning from its own center of gravity. Microsoft is building outward from productivity and the Power Platform, with an administrative control plane spanning its estate. Salesforce is anchoring on customer data, wrapping agent actions in its trust layer and CRM context. ServiceNow is treating the workflow itself as the governing structure, extending its control-tower discipline to agents. SAP is grounding agents in harmonized processes and business-data context across its suite, while Workday is positioning the agent as a governed object inside its system of record for people and money. Beyond the suites sit two further archetypes: independent orchestration platforms, which offer breadth across models and tools yet must reconstruct enterprise controls from the outside, and automation-led alternatives, which execute reliably within scripted boundaries and reason poorly beyond them.
Greyhound Standpoint: At Greyhound Research, we believe Oracle is making the same bet as its rivals, just deeper. Oracle is betting on the depth of Fusion-native business objects, transactional workflows, and inherited application controls as the foundation for agentic execution; the argument is that the control plane belongs inside the application runtime because that is where the approval chains and audit trails already live. If that claim holds, the payoff is practical: a company can move from AI that recommends an action to AI that takes the action itself, under the controls it already trusts, without first building the governance plumbing from scratch.
What Oracle Must Still Prove
Greyhound Research’s position is that five questions decide whether the governance claim survives contact with a real-world customer deployment.
Identity. Does each agent operate as a distinct principal under least privilege, or does it borrow the entitlements of a human user?
The record. What is logged, from prompts and tool calls to the model version behind each action, and can the customer export it?
Reversibility. A bad chain of actions must be unwound through compensating transactions once it has executed; what mechanism exists, and who triggers it?
Model governance. Oracle documents customer choice across its own curated models and external ones, which makes substitution a routine event; a swap beneath a live application needs to be approved, traced, and benchmarked.
Third-party participation. How are external agents arriving over the MCP and A2A interoperability protocols authenticated, sandboxed, and revoked?
The marketplace adds a sixth question. Oracle publishes a 21-point enterprise readiness checklist for partner-built agents, an unusually concrete disclosure by the standards of this market, yet the harder questions begin after inspection: who carries liability when a partner-built application misfires inside a customer’s ledger, how updates are controlled once that application is live, and what commercial terms bind Oracle, the partner, and the customer when something breaks.
Lest we forget, certification is a gate and accountability is a contract.

A Word Of Caution For CIOs
Greyhound Research cautions that a native runtime relocates complexity; it does not cancel it. What such a runtime genuinely removes is the bolt-on burden: security, approvals, and audits can be reused rather than rebuilt around the agent because the application platform already carries them. What remains moves to harder ground, domain by domain, and our work with buying organizations shows the year-one bill takes a different shape in every estate, with none of the shapes zero.
Employee services run light; employment decisions run heavy. Bounded services such as policy guidance and scheduling carry the lightest lift, because authority stays narrow and approvals explicit. Employment, compensation, and promotion decisions sit at the other end, touching identifiable human beings and converting software defects into legal and reputational events; they fall in the EU AI Act’s high-risk category for employment under Annex III, whose enforcement the newly adopted Digital Omnibus defers to December 2, 2027, while anti-discrimination and data protection laws bind them today. The map is wider than Brussels: the United States runs a patchwork of state, sectoral, and consumer-protection enforcement rather than one omnibus regime, and India’s Digital Personal Data Protection framework, its rules notified in November 2025, is moving through phased implementation to full enforcement by 13 May 2027, which puts personal-data duties on agentic deployments now, not at some future enforcement date.
Finance’s value comes with priced-in controls and audits. The heaviest controls burden sits here: the value in close acceleration and collections is real, and so is the cost of controls engineering, audit sign-off, and process redesign, because a controller will not accept a trace that cannot be walked. Reversibility matters most in this domain, since a single bad chain of postings must be unwound through compensating transactions, with a named owner for the trigger, before the auditors arrive.
Customer errors are intolerable but visible; pilot here. The bill arrives in integration and override design, since the tolerance for a wrong promise made to a paying customer is close to nil. The compensating advantage is visibility: unlike supply-chain errors, a customer-facing mistake surfaces immediately and hands to a human naturally, which is why service escalations sit among the very first sensible pilots, provided the override path is designed well before the agent ever speaks to a customer.
Stale records cap autonomy; cleanup comes before automation. Master data quality becomes the ceiling on autonomy, because an agent acting at machine speed compounds a single stale supplier record into a cascade of confident, well-logged mistakes, and the physical world reports them late. The first bill is therefore data remediation, and the sequencing follows from it: exception handling belongs strictly after the cleanup, not before, because autonomy built on stale records automates the error rather than the business process.
The riskiest failures hide at the cross-suite seams. Almost no enterprise is a single-suite estate, so real work crosses runtime boundaries as a matter of course, and at each crossing the agent’s identity, its authority and its audit trail change jurisdiction. Drift at those seams combines the highest impact with the lowest detectability of any failure mode in this category, and in the largest estates, partner fees, governance boards, and change management quickly overtake the software line itself.
Zero Oracle cost is not zero customer cost. Oracle states the capabilities arrive at no additional cost to Fusion customers, and the subscription genuinely bundles the studio. Oracle’s own marketplace documentation is explicit that agents deployed from partner-built templates count as custom AI and carry a separate subscription fee. The full year-one bill still arrives through implementation and controls engineering, partner and integrator fees, and infrastructure consumption at scale; the bundling decision therefore changes which budget carries the spend rather than eliminating the spend itself. The boundary between them is a contracting question, taken up in the engagement conversations below.
One caution outlasts the list: the AI Act deferral moves the enforcement date without moving the accountability. And one question spans every row above: whose control plane governs the agent whose task crosses three vendors’ runtimes? No vendor racing for this category has answered, and the buyer who asks first negotiates from strength.

How CIOs Should Engage Oracle: Six Conversations
Greyhound Research advises Fusion customers weighing Oracle AI Agent Studio and Fusion Agentic Applications to structure the Oracle engagement around six conversations, each of which can begin with the account team this quarter.
Scope the first Oracle pilot. Ask the account team to help stand up a use case that is bounded, measurable, and reversible, where governance inherits from day one. Collections and service escalations meet those tests today; hold the financial close to advisory or exception-led mode until transaction traceability and compensating controls are demonstrated, and let supply chain exception handling wait for clean master data. A pilot chosen on these criteria produces evidence; a pilot chosen on enthusiasm produces a demo.
Put five questions in writing. Ask the account manager for written answers to the questions this note itemizes: whether each agent operates as a distinct principal under least privilege or borrows a human’s entitlements; what is logged, from prompts and tool calls to the model version behind each action, and whether you can export it; what compensating-transaction mechanism unwinds a bad chain of actions and who triggers it; how a model swap beneath a live application is approved, traced, and benchmarked; and how external agents arriving over MCP and A2A are authenticated, sandboxed, and revoked. Add the cross-suite question: Which control plane is the plane of record when an agent’s task crosses into your Salesforce, Workday, or ServiceNow estates. Any platform that asks to act inside your ledger owes the same answers, so the list travels to every suite vendor, including those yet to announce.
Demand AI Studio Skill specifics. If your developers will build rather than configure, ask for the Skill’s documentation, access to the promised repository, and a working demonstration before committing engineering time: how a Fusion Agentic Application is represented as an artifact under Git, how the same artifact behaves across the no-code and pro-code paths, and how local validation and pipeline-based release interact with Fusion’s runtime governance. The documentation should also show versioning, rollback semantics, agent identity boundaries, approval threshold configuration, transaction integrity across multi-step actions, and reasoning trace access. Whether those artifacts prove portable, reversible, and consistently governed is the announcement’s central open question; have Oracle answer it in your environment, not in a keynote.
Define what the bundle covers. The subscription bundles the studio; the year-one bill still arrives through implementation and controls engineering, partner and integrator fees, and infrastructure consumption at scale. Ask which of the 22 Fusion Agentic Applications and the 1,000-plus embedded agents your existing subscription already includes, which arrive with partner commercials attached, and which budget carries each line, in writing, before deployment rather than after.
Settle partner-application liability before installing. The marketplace questions raised above become a contracting conversation here: before installing a partner-built application, get written answers on who carries liability when it misfires inside your ledger, how its updates are controlled once live, and which commercial terms bind Oracle, the partner, and you when something breaks. Inspection is Oracle’s gate; the accountability contract is yours to negotiate, and it is negotiated before installation, not at the incident review.
Negotiate the exit before entry. Native governance is real, and it is also non-portable. Every agentic application built as a Fusion runtime artifact deepens platform gravity, so a buyer exchanging model-vendor optionality for application-platform dependency should arrive at the signature with exit clauses drafted and portability already tested. Ask the account team to demonstrate export: what leaves with you, in what format, and what remains behind.
None of these conversations require waiting for Oracle’s documentation, for a regulator, or for the market to settle. Each converts a buyer from a spectator of this contest into a participant who sets terms, and together they prepare an enterprise for the larger transition this announcement belongs to.
The Final Greyhound Research Standpoint
Greyhound Research holds that enterprise software is moving from recording work to executing it, and the transition will be won by the vendor that makes autonomy boringly governable. “Boring” is not a small word in this market; it is the highest compliment an enterprise system can earn, because “boring” means predictable, inspectable, and reversible, and those are the qualities a controller, an auditor, and a regulator will sign their names against.
The test is simple, and it travels well beyond Oracle.
Name the identity. Every agent runs as its own principal, holding the least privilege its task allows, never borrowing a human’s credentials.
Read the log. Every prompt, tool call, approval, and model version behind an action can be inspected and exported by the customer, not only by the vendor.
Bound the authority. Approval thresholds are set by the enterprise as policy on the transactions that matter and cannot be quietly widened.
Reverse the action. A bad chain of decisions can be unwound through compensating transactions, with a named owner for the trigger.
A buyer who cannot do these four things does not have an agentic application; it has an ungoverned employee with system access.

Oracle starts from a position of genuine strength. Against that test on day one, the public record is already strong where it matters first: agents acting on native business objects, under approval thresholds the enterprise sets. The remaining verbs, the full log, a distinct agent identity, and a demonstrated reversal remain open proof points: the public record neither establishes them nor establishes their absence, and the documentation will settle it. Across the leading vendors’ public material reviewed for this note, none yet documents all four in full, so the gap belongs to the category, not to Oracle. What it measures is how young this category still is and how much of its story will be written in documentation rather than announcements.
For Oracle, the path from here is concrete and entirely within its control: publish the technical documentation, bring the promised repository live, put named customers into production with measured outcomes, produce external audit artefacts, and give buyers the pricing and audit clarity they can carry into their own governance processes. Each of those steps converts the announcement’s promise into proof, and Oracle brings credible assets to the path: Fusion’s transactional depth, an established partner network, and its certified training base. Greyhound Research will track that evidence as it lands, and a full examination of the governed-runtime category will follow. Over three years, the market will split between platforms that can prove governed action inside systems of record and platforms that remain glorified orchestration layers.
Greyhound Standpoint: At Greyhound Research, we believe the prize in this market is accountable autonomy: agents that act under the controls an enterprise already trusts, with a named owner when they act wrongly. Oracle has moved the contest onto the ground where that prize is decided, and it has done so with the machinery of a runtime rather than the language of a demonstration. The evidence will now do the talking. Everything else is a demonstration.
Important Disclaimer
Greyhound Research are industry analysts, not equity analysts. This note is a demand-side assessment of Oracle’s announcement, architecture, and buyer implications; it is not investment advice, and nothing in it should be read as a view on securities. This note draws on pre-briefing materials provided under embargo by Oracle and on Greyhound Research’s own analysis; the announcement became public on July 14, 2026, and key figures were re-verified against public sources on July 19, 2026.
This is a strictly independent analysis: Oracle has not commissioned, paid for, reviewed, or influenced this note in any form, and Greyhound Research has received no compensation from Oracle or any other party for its production. The views expressed are Greyhound Research’s alone.
This note draws on Greyhound CIO Pulse 2026 and Greyhound Fieldnotes. Our full archive is available at greyhoundresearch.com.
Sources And References
Every load-bearing claim in this note traces to one of the sources below, presented in Harvard reference format and grouped by class. In-text author-date citations are deliberately omitted, as they serve academic writing rather than research intended for the executive desk. All sources accessed 19 July 2026.
Company and vendor disclosures
Oracle (2026a) Oracle Introduces AI-Native Builder Experience to Create and Run Agentic Applications in Oracle Fusion Applications. Oracle Newsroom, 14 July. Available at: https://www.oracle.com/news/announcement/oracle-introduces-ai-native-builder-experience-2026-07-14/
Oracle (2026b) Oracle Introduces Fusion Agentic Applications. Oracle Newsroom, 24 March. Available at: https://www.oracle.com/news/announcement/oracle-introduces-fusion-agentic-applications-2026-03-24/
Oracle (2026c) Oracle Expands AI Agent Studio for Fusion Applications with Agentic Applications Builder and New Intelligent Workflow Tools. Oracle Newsroom, 24 March. Available at: https://www.oracle.com/news/announcement/oracle-expands-ai-agent-studio-for-fusion-applications-with-agentic-applications-builder-2026-03-24/
Oracle (2026d) What You Need To Know About MCP, A2A In Fusion Apps. Oracle Fusion Insider blog, March. Available at: https://blogs.oracle.com/fusioninsider/what-you-need-to-know-about-mcp-a2a-in-fusion-apps
Oracle (2025a) Oracle Launches Fusion Applications AI Agent Marketplace to Accelerate Enterprise AI Adoption. Oracle Newsroom, 15 October. Available at: https://www.oracle.com/news/announcement/ai-world-oracle-launches-fusion-applications-ai-agent-marketplace-to-accelerate-enterprise-ai-adoption-2025-10-15/
Oracle (2025b) Introducing AI Agent Marketplace. Oracle Fusion Insider blog, November. Available at: https://blogs.oracle.com/fusioninsider/introducing-ai-agent-marketplace
Government, legal, and regulatory reporting
Fisher Phillips (2026) India’s New Data Privacy Rules Are Here: 8 Steps for Businesses as Key Compliance Deadlines Approach, February. Available at: https://www.fisherphillips.com/en/insights/insights/indias-new-data-privacy-rules-are-here
Out-Law, Pinsent Masons (2026) Rules on ‘high-risk’ AI to be delayed under EU ‘omnibus’ deal, May. Available at: https://www.pinsentmasons.com/out-law/news/rules-high-risk-ai-delayed-under-eu-omnibus-deal
Greyhound Research proprietary evidence
Greyhound Research (2026a) Greyhound CIO Pulse 2026. Proprietary survey of more than 1,000 enterprise technology leaders.
Greyhound Research (2026b) Greyhound Fieldnotes. Advisory engagements with enterprise technology buyers, 2026.

Analyst In Focus: Sanchit Vir Gogia
Sanchit Vir Gogia, or SVG as he is popularly known, is a globally recognised technology analyst, innovation strategist, digital consultant and board advisor. SVG is the Chief Analyst, Founder & CEO of Greyhound Research, a Global, Award-Winning Technology Research, Advisory, Consulting & Education firm. Greyhound Research works closely with global organizations, their CxOs and the Board of Directors on Technology & Digital Transformation decisions. SVG is also the Founder & CEO of The House Of Greyhound, an eclectic venture focusing on interdisciplinary innovation.
Copyright Policy. All content contained on the Greyhound Research website is protected by copyright law and may not be reproduced, distributed, transmitted, displayed, published, or broadcast without the prior written permission of Greyhound Research or, in the case of third-party materials, the prior written consent of the copyright owner of that content. You may not alter, delete, obscure, or conceal any trademark, copyright, or other notice appearing in any Greyhound Research content. We request our readers not to copy Greyhound Research content and not republish or redistribute them (in whole or partially) via emails or republishing them in any media, including websites, newsletters, or intranets. We understand that you may want to share this content with others, so we’ve added tools under each content piece that allow you to share the content. If you have any questions, please get in touch with our Community Relations Team at connect@thofgr.com.
Discover more from Greyhound Research
Subscribe to get the latest posts sent to your email.
