Every business that has moved beyond a single AI tool and into multiple AI agents now faces the same headache. The agents connect to different AI models from different providers, pull data from internal systems, and trigger actions in tools like Slack, Google Drive, or GitHub. Nobody has a clear picture of what is running, what it costs, or what the agents are actually allowed to do. Databricks launched Unity AI Gateway to be the answer to that.
The product sits in the middle of all AI activity inside an organization. Think of it as a switchboard operator who logs every call, checks permissions before connecting, routes to the cheapest available line, and cuts off any call that breaks the rules. At its Data + AI Summit this week, Databricks significantly expanded what that switchboard can do.
The headline feature for finance and operations leaders is cost control. AI spending is notoriously hard to predict because charges pile up every time an agent calls an external AI model, and agents can chain dozens of these calls together in a single task. One study found that only 15% of organizations can forecast their AI costs to within 10% accuracy. Databricks now lets administrators set hard spending caps, see exactly which team, application, or agent is generating charges, and automatically route requests to a cheaper AI model when a high-powered one is not necessary.
For legal and compliance teams, the more important feature is what Databricks is calling Contextual Service Policies. Traditional access controls only govern who can open a door. These new controls govern what happens once someone is inside. An administrator can now require human approval before an AI agent pushes code to a repository, restrict agents from writing to sensitive file folders, or block any request that contains regulated personal data. These rules can be set based on the user, the specific agent, the tool being called, or even the content of what the agent is trying to do.
The security angle is serious. Research from Gartner puts the share of enterprise applications with embedded AI agents at under 5% in 2025, rising to 40% by the end of 2026. Each of those agents is a potential liability. Breaches involving employees using unsanctioned AI tools now cost organizations an average of $4.63 million per incident. Databricks has brought in ten major security firms as integration partners, including CrowdStrike, Palo Alto Networks, and Zscaler, along with identity providers Okta and Ping Identity, to make Unity AI Gateway part of their existing security checks.
The context here matters. Databricks already has more than 14,000 organizations running Unity Catalog for data governance. The strategy is straightforward: those organizations already trust the platform with their data rules, so extending the same rules to AI agents is a natural upgrade. Competitors including Snowflake, Collibra, and Alation have announced similar roadmaps expected in the second half of 2026, so Databricks is moving to establish this as the standard before the rest of the market catches up.
For any organization already on Databricks, this release removes the main excuse for not governing AI properly. For those not on Databricks, the release signals that every major data platform vendor will soon offer this kind of control layer, and asking your current vendor when their version ships is a reasonable question to put to them now.
The companies that will struggle are those treating AI governance as a future problem. Gartner forecasts that AI governance platform spending will reach $492 million globally in 2026 and surpass one billion dollars by 2030. The spending is moving because the risk is real, not because vendors are selling fear.