TLDRocket
Sign in

When agents act on their own, governance has to live in the data layer

VentureBeat Covered by 5 sources

Agents are getting permission to act on their own, and that makes old policy layers too slow. The fix, EDB says, is to enforce rules in the data layer where the action actually happens.

Based on reporting by VentureBeat — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

As enterprises let AI agents plan, decide, and act across systems without a human clicking approve each time, the hard problem stops being model quality and starts being control. If an agent reaches for something it was never meant to touch, what actually blocks it in the moment? That’s the question EDB is pushing to the center of the architecture review.

The argument is simple: rules written on paper, or layered above the model, are too easy to outrun when software is acting in milliseconds. A policy that only gets checked before the fact cannot keep up with autonomy. And once an agent is touching data across systems, the place that matters most is not the chat interface or the orchestration layer. It’s the data layer.

That’s where EDB says governance has to become executable. The controls the company points to are familiar ones — role- and attribute-based access, row- and column-level security, classification and masking, policy as code, and audit trails. But the key change is identity. The agent has to be treated as a principal in its own right, with its own identity and a declared purpose at session start. That way the system can decide, at the point of access, whether the action fits the policy.

EDB lays this out as nine controls under three buckets: enforce it, see it and prove it, and unify and harden. That includes query-time access control for agents as well as users, dynamic column masking, audit logging that records which agent acted for which user and under what purpose, lineage across pipelines, centralized policy management, and encryption at rest and in transit. The company also says the controls need to work consistently across on-prem, cloud, and sovereign or air-gapped setups.

There’s a plain-spoken line in the pitch that cuts through the rest: agents are useful only if they’re scoped. Not locked out, not trusted on vibes, just bounded. The point isn’t to slow them down. It’s to make them safe enough that security teams stop treating them like a fire drill with a product demo attached.

My take — AI-written commentary, not fact-checked reporting

This is the right instinct, and it’s overdue. Everyone keeps trying to govern agentic AI from the top of the stack, which is a bit like trying to control a dog by arguing with its reflection. The real test is whether the database can say no, cleanly, at the moment of access. Open systems win here because they leave the enforcement where it can actually be inspected, not hidden behind marketing fog.

Read more about this at: VentureBeat

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.