July 29, 2026
Manage AI Risks Through AI and Data Governance
Artificial intelligence agents require governance that is designed for AI, embedded in data workflows and continuously in effect as a critical activation layer.
Agentic artificial intelligence, or systems capable of autonomous decision-making and action, are accelerating enterprise transformation. But without strong data governance, these systems amplify risk as quickly as they create value. Many organizations have discovered unknown agents in their environments and experienced the consequences of poorly controlled agents. The challenge is that traditional governance models were designed for a completely different landscape, one that focused on outputs, static data and controlled workflows. To leverage AI and AI agents safely, organizations must evolve their governance for AI, shifting from a “control” model to an “activation” model.
Governance as activation means that governance controls and mechanisms are embedded into data and AI systems. Governance lives in pipelines, platforms and decision systems, continuously ensuring that data is ready to be consumed. When organizations establish modern frameworks designed for AI, they can scale AI initiatives with confidence in their security, compliance and risk management.
Agentic artificial intelligence, or systems capable of autonomous decision-making and action, are accelerating enterprise transformation. But without strong data governance, these systems amplify risk as quickly as they create value. Many organizations have discovered unknown agents in their environments and experienced the consequences of poorly controlled agents. The challenge is that traditional governance models were designed for a completely different landscape, one that focused on outputs, static data and controlled workflows. To leverage AI and AI agents safely, organizations must evolve their governance for AI, shifting from a “control” model to an “activation” model.
Governance as activation means that governance controls and mechanisms are embedded into data and AI systems. Governance lives in pipelines, platforms and decision systems, continuously ensuring that data is ready to be consumed. When organizations establish modern frameworks designed for AI, they can scale AI initiatives with confidence in their security, compliance and risk management.
Governance in the Agentic Era
Experts predict that over the next few years, many organizations will be forced to abandon agentic AI and other AI initiatives because their data isn’t up to the task. Gartner has estimated that 60% of projects unsupported by AI-ready data will be halted by the end of 2026. With agentic AI, Gartner has estimated that 40% of projects will be canceled by 2027 because of cost, unclear value or insufficient controls. To a large extent, that lack of control — and of governance more broadly — is the factor holding organizations back.
Organizations are challenged by increasing data velocity, decentralized ownership and growing reliance on unstructured data. In this environment, governance gaps create significant risks: unreliable AI outputs, security vulnerabilities and regulatory violations. These risks are amplified in agentic environments where decisions are made by systems that rely on dynamic data pipelines and act independently with little human intervention. Traditional governance models, built for static reporting and controlled workflows, are no longer sufficient.
Modern data governance has shifted from a control layer to an activation layer. Governance is embedded into data and AI workflows where it continuously ensures that data is usable before it is consumed. Traditional governance served as a review function, a compliance-focused overlay or a last-stage bottleneck that employees had to overcome. Today, organizations must enforce governance where the data lives and is activated, ensuring that data, semantics and tools can be used safely by AI agents, large language model (LLM) analytics and retrieval-augmented generation pipelines that help AI models generate accurate and relevant content.
When governance evolves into an activation layer, it functions when and where it is needed: inside pipelines, platforms and decision systems, supported by platform-native governance and real-time monitoring of data usage. With the right architecture, practices and policies, organizations can adopt and scale AI confidently with the control and visibility that it requires.
62%
The percentage of organizations citing security and risk concerns as the biggest obstacle to fully scaled agentic AI
Source: mckinsey.com, “State of AI Trust in 2026: Shifting to the Agentic Era,” March 25, 2026
Governance in the Agentic Era
Experts predict that over the next few years, many organizations will be forced to abandon agentic AI and other AI initiatives because their data isn’t up to the task. Gartner has estimated that 60% of projects unsupported by AI-ready data will be halted by the end of 2026. With agentic AI, Gartner has estimated that 40% of projects will be canceled by 2027 because of cost, unclear value or insufficient controls. To a large extent, that lack of control — and of governance more broadly — is the factor holding organizations back.
Organizations are challenged by increasing data velocity, decentralized ownership and growing reliance on unstructured data. In this environment, governance gaps create significant risks: unreliable AI outputs, security vulnerabilities and regulatory violations. These risks are amplified in agentic environments where decisions are made by systems that rely on dynamic data pipelines and act independently with little human intervention. Traditional governance models, built for static reporting and controlled workflows, are no longer sufficient.
Modern data governance has shifted from a control layer to an activation layer. Governance is embedded into data and AI workflows where it continuously ensures that data is usable before it is consumed. Traditional governance served as a review function, a compliance-focused overlay or a last-stage bottleneck that employees had to overcome. Today, organizations must enforce governance where the data lives and is activated, ensuring that data, semantics and tools can be used safely by AI agents, large language model (LLM) analytics and retrieval-augmented generation pipelines that help AI models generate accurate and relevant content.
When governance evolves into an activation layer, it functions when and where it is needed: inside pipelines, platforms and decision systems, supported by platform-native governance and real-time monitoring of data usage. With the right architecture, practices and policies, organizations can adopt and scale AI confidently with the control and visibility that it requires.
Data Governance and AI Risk
63%
The percentage of organizations that don’t have or aren’t sure if they have the right data management practices for AI
Source: gartner.com, “Lack of AI-Ready Data Puts AI Projects at Risk,” Feb. 26, 2025
65%
The percentage of organizations that have experienced AI agent-related incidents in the past year, including data exposure, operational disruption and financial losses
Source: cloudsecurityalliance.com, “New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments,” April 21, 2026
60%
The estimated percentage of AI projects unsupported by AI-ready data that organizations will abandon through 2026
Source: gartner.com, “Lack of AI-Ready Data Puts AI Projects at Risk,” Feb. 26, 2025
Data Governance and AI Risk
63%
The percentage of organizations that don’t have or aren’t sure if they have the right data management practices for AI
Source: gartner.com, “Lack of AI-Ready Data Puts AI Projects at Risk,” Feb. 26, 2025
65%
The percentage of organizations that have experienced AI agent-related incidents in the past year, including data exposure, operational disruption and financial losses
Source: cloudsecurityalliance.com, “New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments,” April 21, 2026
60%
The estimated percentage of AI projects unsupported by AI-ready data that organizations will abandon through 2026
Source: gartner.com, “Lack of AI-Ready Data Puts AI Projects at Risk,” Feb. 26, 2025
- A TRUSTED DATA FOUNDATION
- GOVERNANCE AT SCALE
- FUTURE PROOFING AI
Trustworthy data is essential for scalable AI. Organizations need to know that data is accurate, consistent and contextualized. Currently, however, 63% of organizations don’t have (or aren’t sure if they have) proper data management practices for AI. Many still struggle with fragmented governance processes and limited visibility into data lineage.
DATA QUALITY FIRST: Data quality should serve as a governance signal: the precondition for reliable AI across structured and unstructured data alike. Often, however, data quality scores are seen as confirmation of a one-time cleanup after a problem has been identified. They should function instead as a live governance signal, indicating data quality readiness and providing an important gatekeeping measure for critical processes such as data-product certification and access decisions.
THE SEMANTIC LAYER: The semantic layer makes raw data usable to the business, preparing it for analysis by converting it into terms that are consistent and meaningful for the user. The layer may be part of a business intelligence platform, provided by data virtualization tools or data warehouse solutions, or be implemented via custom solutions. As a governance surface, the semantic layer establishes a single definition of every business metric, enabling agents to answer from modeled business logic rather than “guessing” against raw schemas. It is the layer that ensures governance teams and AI agents are working from the same definition of terms such as “revenue,” for example.
PLATFORM-NATIVE: Governance should be enforced where the data already lives — for example, in the platform-native catalog or the open table catalog in a data lake. The catalog itself, not the AI engine, should support the governance contracts, the artifacts related to data lineage, policy, ownership and other areas. In heterogeneous environments where data resides in multiple storage repositories, a cross-platform layer provides a centralized framework for enforcing governance consistently across systems. Wherever practical, however, governance should live as close to the data as possible.
LINEAGE AND PROVENANCE: Data lineage — the metadata tracking the data’s origin, flow and transformation — is crucial. AI agents stitch this lineage together as they work, tracking movement and changes. In the process, they establish the evidence-grade provenance that is becoming a requirement for AI auditability and regulatory compliance. In this context, lineage ceases to be mere documentation and becomes a critical layer of audit readiness.
Click Below To Continue Reading
AI governance has traditionally focused on risks related to outputs, such as taking steps to eliminate bias and ensuring AI-derived results are explainable. Because agentic AI is designed to act independently, however, it poses risks that are arguably even more consequential, including unauthorized access, unintended actions and data exposure. That’s especially concerning given that 82% of organizations have unknown AI agents in their IT infrastructure.
Improperly controlled agents are an unmanaged risk in many organizations, which frequently give AI systems excessive access and otherwise enable them to take actions beyond their intended scope.
Nearly two-thirds of organizations experienced AI agent incidents in the past year, with consequences that included data exposure (61%), operational disruption (43%) and financial losses (35%).
A visibility gap persists, with 68% of organizations believing they have high visibility into AI agents, despite the fact that 41% have discovered unknown agents multiple times.
While practices and policies are crucial, most organizations have yet to establish the data architecture and foundational elements that will enable them to manage risks through the governance-as-activation model.
Most governance programs still operate as late-stage review functions, creating delays and teaching teams to work around governance instead of working alongside it. To scale effectively, organizations must embed governance early in design and execution, operating it as a continuous function and not a point-in-time check.
DATA PRODUCTS: Data products should be owned by the domain and incorporate governance as machine-readable contracts that include schema, quality thresholds, service-level agreements, ownership and enforcement. While a central platform team owns the policy, domains own their products, with contracts making stewardship enforceable instead of aspirational.
SHIFT-LEFT CONTINUITY: When governance is delayed until the end of the development process or agentic workflow, it becomes a checkpoint, typically creating bottlenecks that motivate teams to work around them. Shifting left and embedding governance early in design allows it to run continuously through delivery and operate within continuous integration/continuous development pipelines. By surfacing potential issues sooner, embedded governance allows for earlier resolution and eliminates late-stage bottlenecks.
AGENT ASSISTANCE: Embedded governance can also incorporate AI agents performing data classification, tagging, lineage stitching and quality monitoring on top of active metadata, with humans in a supervisory loop. Traditionally, data stewards performed this work using manual processes; in an agentic environment, stewards review the work of automated systems.
OBSERVABILITY: Observability is key to governance, leveraging telemetry from AI systems to ensure they are producing the right outputs, detect model drift and support explainability. Continuous observability spans every step: data ingestion, transformation, retrieval and response. Anomaly and quality alerts feed access decisions and must be addressed before data products are certified. Accordingly, monitoring becomes a factor that drives governance rather than solely reporting on it.
MEASURABLE OUTCOMES: Governance should be measured by activation: AI accuracy, reuse of data products and time-to-trusted-data metrics. Some organizations become overly reliant on glossary and catalog completeness as key measures without recognizing that these are inputs, not outcomes. Moreover, programs that prioritize completeness scores tend to become compliance “theater,” creating the appearance of effective results without providing insight into real outcomes.
Data governance and AI governance are converging into a single discipline. Future readiness comes from open architecture that the organization can evolve, governed access for agents and a clear path from where a program is today to where it needs to be.
DESIGN FOR PORTABILITY: Build the governance plane on open standards, including open-table formats, semantic definitions compatible with the Open Semantic Interchange (OSI) and evolving open standards for agent access. The enforcement point should outlive any single vendor, allowing the organization to change tools in the future without rebuilding its governance structure.
GOVERNED AGENT ACCESS: Ungoverned agent access is the primary scalability risk for many organizations. Only assets that are governed should be exposed to agents, using Model Context Protocol (MCP) and fronting all LLM traffic with an AI gateway that enforces redaction and content safety. In addition, agents should be bound to the user’s authorization context rather than a service account that bypasses access controls.
CONVERGED GOVERNANCE: Organizations should be working toward a converged approach of managing data governance and AI model governance as a single discipline resting on a shared, active-metadata substrate — not two functions running in parallel. Data catalogs, lineage and stewardship should sit alongside model cards, drift monitoring and audit in the same plane.
STAGED ROADMAP: A staged roadmap helps organizations build programs that are sustainable, tracking their progress toward maturity over time and reducing reliance on the initial enthusiasm that often fades after early momentum. The roadmap should sequence the program in stages — from foundation to activation and then to agentic governance — with explicit thresholds defining advancement at each stage.
- A TRUSTED DATA FOUNDATION
- GOVERNANCE AT SCALE
- FUTURE PROOFING AI
Trustworthy data is essential for scalable AI. Organizations need to know that data is accurate, consistent and contextualized. Currently, however, 63% of organizations don’t have (or aren’t sure if they have) proper data management practices for AI. Many still struggle with fragmented governance processes and limited visibility into data lineage.
DATA QUALITY FIRST: Data quality should serve as a governance signal: the precondition for reliable AI across structured and unstructured data alike. Often, however, data quality scores are seen as confirmation of a one-time cleanup after a problem has been identified. They should function instead as a live governance signal, indicating data quality readiness and providing an important gatekeeping measure for critical processes such as data-product certification and access decisions.
THE SEMANTIC LAYER: The semantic layer makes raw data usable to the business, preparing it for analysis by converting it into terms that are consistent and meaningful for the user. The layer may be part of a business intelligence platform, provided by data virtualization tools or data warehouse solutions, or be implemented via custom solutions. As a governance surface, the semantic layer establishes a single definition of every business metric, enabling agents to answer from modeled business logic rather than “guessing” against raw schemas. It is the layer that ensures governance teams and AI agents are working from the same definition of terms such as “revenue,” for example.
PLATFORM-NATIVE: Governance should be enforced where the data already lives — for example, in the platform-native catalog or the open table catalog in a data lake. The catalog itself, not the AI engine, should support the governance contracts, the artifacts related to data lineage, policy, ownership and other areas. In heterogeneous environments where data resides in multiple storage repositories, a cross-platform layer provides a centralized framework for enforcing governance consistently across systems. Wherever practical, however, governance should live as close to the data as possible.
LINEAGE AND PROVENANCE: Data lineage — the metadata tracking the data’s origin, flow and transformation — is crucial. AI agents stitch this lineage together as they work, tracking movement and changes. In the process, they establish the evidence-grade provenance that is becoming a requirement for AI auditability and regulatory compliance. In this context, lineage ceases to be mere documentation and becomes a critical layer of audit readiness.
Click Below To Continue Reading
AI governance has traditionally focused on risks related to outputs, such as taking steps to eliminate bias and ensuring AI-derived results are explainable. Because agentic AI is designed to act independently, however, it poses risks that are arguably even more consequential, including unauthorized access, unintended actions and data exposure. That’s especially concerning given that 82% of organizations have unknown AI agents in their IT infrastructure.
Improperly controlled agents are an unmanaged risk in many organizations, which frequently give AI systems excessive access and otherwise enable them to take actions beyond their intended scope.
Nearly two-thirds of organizations experienced AI agent incidents in the past year, with consequences that included data exposure (61%), operational disruption (43%) and financial losses (35%).
A visibility gap persists, with 68% of organizations believing they have high visibility into AI agents, despite the fact that 41% have discovered unknown agents multiple times.
While practices and policies are crucial, most organizations have yet to establish the data architecture and foundational elements that will enable them to manage risks through the governance-as-activation model.
Most governance programs still operate as late-stage review functions, creating delays and teaching teams to work around governance instead of working alongside it. To scale effectively, organizations must embed governance early in design and execution, operating it as a continuous function and not a point-in-time check.
DATA PRODUCTS: Data products should be owned by the domain and incorporate governance as machine-readable contracts that include schema, quality thresholds, service-level agreements, ownership and enforcement. While a central platform team owns the policy, domains own their products, with contracts making stewardship enforceable instead of aspirational.
SHIFT-LEFT CONTINUITY: When governance is delayed until the end of the development process or agentic workflow, it becomes a checkpoint, typically creating bottlenecks that motivate teams to work around them. Shifting left and embedding governance early in design allows it to run continuously through delivery and operate within continuous integration/continuous development pipelines. By surfacing potential issues sooner, embedded governance allows for earlier resolution and eliminates late-stage bottlenecks.
AGENT ASSISTANCE: Embedded governance can also incorporate AI agents performing data classification, tagging, lineage stitching and quality monitoring on top of active metadata, with humans in a supervisory loop. Traditionally, data stewards performed this work using manual processes; in an agentic environment, stewards review the work of automated systems.
OBSERVABILITY: Observability is key to governance, leveraging telemetry from AI systems to ensure they are producing the right outputs, detect model drift and support explainability. Continuous observability spans every step: data ingestion, transformation, retrieval and response. Anomaly and quality alerts feed access decisions and must be addressed before data products are certified. Accordingly, monitoring becomes a factor that drives governance rather than solely reporting on it.
MEASURABLE OUTCOMES: Governance should be measured by activation: AI accuracy, reuse of data products and time-to-trusted-data metrics. Some organizations become overly reliant on glossary and catalog completeness as key measures without recognizing that these are inputs, not outcomes. Moreover, programs that prioritize completeness scores tend to become compliance “theater,” creating the appearance of effective results without providing insight into real outcomes.
Data governance and AI governance are converging into a single discipline. Future readiness comes from open architecture that the organization can evolve, governed access for agents and a clear path from where a program is today to where it needs to be.
DESIGN FOR PORTABILITY: Build the governance plane on open standards, including open-table formats, semantic definitions compatible with the Open Semantic Interchange (OSI) and evolving open standards for agent access. The enforcement point should outlive any single vendor, allowing the organization to change tools in the future without rebuilding its governance structure.
GOVERNED AGENT ACCESS: Ungoverned agent access is the primary scalability risk for many organizations. Only assets that are governed should be exposed to agents, using Model Context Protocol (MCP) and fronting all LLM traffic with an AI gateway that enforces redaction and content safety. In addition, agents should be bound to the user’s authorization context rather than a service account that bypasses access controls.
CONVERGED GOVERNANCE: Organizations should be working toward a converged approach of managing data governance and AI model governance as a single discipline resting on a shared, active-metadata substrate — not two functions running in parallel. Data catalogs, lineage and stewardship should sit alongside model cards, drift monitoring and audit in the same plane.
STAGED ROADMAP: A staged roadmap helps organizations build programs that are sustainable, tracking their progress toward maturity over time and reducing reliance on the initial enthusiasm that often fades after early momentum. The roadmap should sequence the program in stages — from foundation to activation and then to agentic governance — with explicit thresholds defining advancement at each stage.