Product Launch2 min read

Databricks Launches AI Agent Governance Controls in Unity Catalog

June 2, 2026Synthesized from 1 source: Databricks

Databricks has extended its Unity Catalog data platform to govern AI agents, adding identity-aware access controls, spending limits, content guardrails, and a full audit trail, addressing a growing problem where companies are running thousands of agents with no central oversight.

There is a real problem underneath this product launch, and it is getting bigger fast.

Gartner estimates that the average large enterprise will have more than 150,000 AI agents running by 2028, up from fewer than 15 in 2025. Every department is building them independently: sales, support, finance, marketing, operations. Each one connects to company data. Most use shared login credentials that give them far broader access than any individual employee would be allowed. And most companies currently have no central record of what any of these agents are doing.

According to Salesforce research, about half of enterprise AI agents today operate in isolated silos with no unified governance. Around 27% of the connections linking these agents to business systems have no audit trail, no access controls, and no compliance checks. Over three million agents are estimated to be running globally in business environments, and only around half are actively monitored.

That is the condition Databricks is trying to help companies fix.

The product they have extended is Unity Catalog, which has been their core tool for managing data access since 2021. The new capability treats AI agents the way the system already treats human employees: an agent can only access the data its requesting user is entitled to see. If you cannot open a customer file, neither can an agent acting on your behalf. Every action logs both identities, yours and the agent's, so when something goes wrong, there is a clear record.

Three layers sit on top of that basic access control. The first is policy enforcement: before an agent executes a specific action, such as merging a file or sending a message, the system checks whether that specific action is allowed in that specific context. It can block the action, permit it, or ask the user to confirm. The second layer is content guardrails that inspect what goes in and out of AI responses in real time, blocking sensitive personal data from being exposed and flagging suspicious inputs. The third is cost tracking: every AI request is logged by team and project, with actual cost attached, not just token counts.

The spending controls matter more than they might appear. Most operations and finance teams currently find out what AI costs them when the invoice arrives and no one can explain it. The new tooling lets administrators set monthly limits per team and get alerts before spending becomes a problem.

Databricks has also made an architectural choice worth understanding. The governance here is attached to the data and the services, not to any specific AI framework or tool. An agent built on one platform and an agent built on a completely different one will both be subject to the same rules as long as they access data through Unity Catalog. That means companies are not locked into rebuilding their policies every time a new AI framework arrives.

Companies with formal AI governance in place deploy twelve times more AI into production than those without it. The friction most businesses associate with governance, the slowdowns and reviews, turns out to be much smaller than the friction caused by ungoverned agents that teams stop trusting.

For any business currently running AI agents in production, this is the right moment to ask a simple question: if someone asked you today which agents have access to customer data, how long would it take you to answer? If the answer is more than a few minutes, that is the gap this kind of tooling addresses.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable