<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=8366258&amp;fmt=gif">
Skip to content

Governing and Securing the New Power User: Why AI Agents Need Runtime Control

Author: Mayank Mishra: VP – Delivery & Solutions 

 

Key takeaways:

  • In the enterprise, an artificial intelligence (AI) agent is now an actor, not just a user: It calls models, invokes tools, spends money, and touches sensitive data in real time.
  • Unity AI Gateway, built on Unity Catalog and now generally available, treats governance and security as one runtime control plane, and putting it in place before agents scale is the precondition for scaling them safely.
  • For enterprises adopting Databricks, KPI Partners helps translate Unity AI Gateway from a platform capability into an operating model: policies, guardrails, cost controls, observability, and implementation patterns that fit regulated production environments.

 

I spend a lot of my time with platform, security, and finance leaders who are being asked the same question by their boards this year: Can we let AI agents loose on our systems safely? It is the right question, and the honest answer depends on something most enterprises have not built yet. An agent is not a user in the traditional sense. In under a second it can call a model, invoke a tool through a Model Context Protocol (MCP) service, read sensitive data, spend real money, and take an action that changes a system of record. That makes it the most useful actor in the business and, without the right controls, the most exposed.

 

At KPI Partners, we see this shift every day with enterprises that are moving from AI pilots to governed production. As a Databricks partner, our role is to help organizations design the data governance, security, FinOps, and agentic AI foundations that make runtime control practical before agents scale. The discipline that keeps it safe is not the access control we already have. It is runtime control, and that is the gap Unity AI Gateway is built to close.

 

Why Access Control Was Never Going to Be Enough

For decades, enterprise security has been organized around a single question: Who is allowed to reach what? Role-based access control (RBAC), identity management, and data permissions all answer that question well. An agent breaks that model, because the risk is no longer only about access, it is about action. The same agent that is correctly permitted to read a customer record can also be talked into exfiltrating it, can send personally identifiable information (PII) to an external model, or can invoke a tool it was never meant to touch. Knowing who an agent is tells you very little about what it is doing right now.

 

The data on this gap is sobering. In its 2025 Cost of a Data Breach report, IBM found that 97 percent of organizations that suffered an AI-related breach lacked proper AI access controls, that 63 percent had no AI governance policies at all, and that unmanaged shadow AI added around 670,000 US dollars to the average breach. AI adoption is outpacing the controls meant to govern it, and the gap is already being paid for.

 

The Three Problems Agents Create in Production

When agents move from demo to production, three problems surface at once.


  • The first is cost. Token-based spend grows quickly and unpredictably, and most organizations have no way to see what a given model, team, or agent is actually costing them, let alone cap it.
  • The second is control. Agents expose sensitive data, can be steered by prompt injection, and can take actions no one authorized, while the traces they generate quietly accumulate secrets and PII.
  • The third is choice. Real teams use many models and providers, from commercial to open source, and any governance that forces them onto a single stack will either be circumvented or will hold the business back.

None of this is hypothetical. Gartner predicts that more than 40 percent of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls. Two of those three causes, cost and risk controls, are governance problems rather than model problems. The agents are not failing; The management around them is.

 

What Unity AI Gateway Actually Does and How KPI Partners Helps Operationalize it

Unity AI Gateway, now generally available and built on Unity Catalog, is Databricks' answer to those problems in a single runtime control plane. Rather than governing only who can access data, it governs what models, agents, MCP services, and tools do while they are running, across providers, without locking teams into one model or vendor and it works along the two dimensions the problem demands.


  • On cost and reliability, Unity AI Gateway supports traffic management and smart routing across governed AI services, helping teams balance cost, quality, and availability. For a financial operations (FinOps) leader, that turns unpredictable AI spend into something budgeted and attributable rather than discovered after the fact.
  • On security, its guardrails inspect model inputs and outputs in real time to detect and redact PII such as account numbers and identifiers before they ever reach an external model, to block prompt injection and unsafe content, and to prevent data exfiltration. Service policies control which tools an agent may invoke based on identity and request context, agents act on-behalf-of (OBO) the user and inherit that user's permissions, and genuinely sensitive actions can require a human sign-off before they execute. Unity AI Gateway centralizes AI observability by tracking usage, cost, payloads, guardrail activity, and traces, giving governance, security, and FinOps teams a more complete audit trail across AI interactions. Governance and security stop being two separate programs and become one control plane.

The platform capability is only one part of the answer. KPI Partners helps enterprises decide how those controls should be designed, prioritized, configured, and monitored across real teams, business units, and regulatory environments.

 

What This Looks Like Under Real Regulatory Pressure

The value of that becomes concrete under regulation. Picture a bank running an agent against customer and transaction data. The same set of controls does several jobs at once: Account numbers and personal data are redacted before any external model sees them, attempts to prompt-inject the agent into revealing data are blocked, spend is capped per team, and the agent is permitted to read but must get a human sign-off before it writes to a system of record or initiates anything that moves money. Every step is logged, so when an examiner asks what the agent did and why, the answer is a query rather than a forensic reconstruction.

 

Now picture a life sciences firm whose agents touch protected health information (PHI). Under the Health Insurance Portability and Accountability Act (HIPAA) and validated-system expectations, PHI has to be redacted before it reaches an external model, the agent has to be restricted to approved tools, and every request and response needs to be captured as a governed record for audit. In both cases the principle is identical: The controls are not a compliance afterthought; they are what makes it possible to put an agent near regulated data at all.

 

Why This Has to Come Before Scale, Not After

This is the heart of the matter, and where I push my clients hardest. Governance and security for agents cannot be a cleanup phase you get to after adoption. If you scale first and govern later, you spend the intervening months accumulating exactly the exposure IBM measured, and you make yourself a candidate for the cancellation rate Gartner projects. The controls have to exist before the agents do.

 

The encouraging part is that this is now practical rather than aspirational. With Unity AI Gateway generally available, the runtime control plane is something you can stand up first and build on, not a capability you are still waiting for. Adopt it early, get the controls in place, and let agents scale into a governed environment rather than out of an ungoverned one. It is far cheaper to grow inside guardrails than to retrofit them around a fleet of agents already in production.

 

Where KPI Partners Comes In

Standing up that control plane well is not a switch you flip; It is a design decision that spans data governance, security policy, cost management, and the realities of a specific regulatory environment. That is the work my team does.

 

KPI Partners helps regulated enterprises establish the combined governance and security foundation for agents on the Databricks Lakehouse, configuring Unity Catalog and Unity AI Gateway together so that guardrails, spend controls, MCP service policies, and observability are in place before agents reach production. Our agentic AI practice pairs that foundation with the model and tooling choices a given use case actually needs, and the KPI Partners and Databricks partnership is where governed data and safely governed agents come together.

 

Runtime Control Is the Decision That Matters

The new power user in your enterprise is an agent that can act in a second, and the organizations that will trust it in production are the ones that decide, up front, to govern and secure it as one thing at runtime. Access control tells you who is at the door. Runtime control tells you what they are allowed to do once they are inside, and for an actor that moves this fast and reaches this far, that is the control that counts. Put it in place first, and scaling agents safely stops being a leap of faith and becomes a matter of design. 

 

 

Ready to Transform Your Data Strategy? Talk to our experts and discover how KPI Partners can accelerate your data and analytics initiatives.

 

Talk to Our Experts | Book a demo

 

 

 

 

kpi-top-up-button
Chat with us