Author: Mayank Mishra: VP – Delivery & Solutions
I spend a lot of my time with platform, security, and finance leaders who are being asked the same question by their boards this year: Can we let AI agents loose on our systems safely? It is the right question, and the honest answer depends on something most enterprises have not built yet. An agent is not a user in the traditional sense. In under a second it can call a model, invoke a tool through a Model Context Protocol (MCP) service, read sensitive data, spend real money, and take an action that changes a system of record. That makes it the most useful actor in the business and, without the right controls, the most exposed.
At KPI Partners, we see this shift every day with enterprises that are moving from AI pilots to governed production. As a Databricks partner, our role is to help organizations design the data governance, security, FinOps, and agentic AI foundations that make runtime control practical before agents scale. The discipline that keeps it safe is not the access control we already have. It is runtime control, and that is the gap Unity AI Gateway is built to close.
For decades, enterprise security has been organized around a single question: Who is allowed to reach what? Role-based access control (RBAC), identity management, and data permissions all answer that question well. An agent breaks that model, because the risk is no longer only about access, it is about action. The same agent that is correctly permitted to read a customer record can also be talked into exfiltrating it, can send personally identifiable information (PII) to an external model, or can invoke a tool it was never meant to touch. Knowing who an agent is tells you very little about what it is doing right now.
The data on this gap is sobering. In its 2025 Cost of a Data Breach report, IBM found that 97 percent of organizations that suffered an AI-related breach lacked proper AI access controls, that 63 percent had no AI governance policies at all, and that unmanaged shadow AI added around 670,000 US dollars to the average breach. AI adoption is outpacing the controls meant to govern it, and the gap is already being paid for.
When agents move from demo to production, three problems surface at once.
None of this is hypothetical. Gartner predicts that more than 40 percent of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls. Two of those three causes, cost and risk controls, are governance problems rather than model problems. The agents are not failing; The management around them is.
Unity AI Gateway, now generally available and built on Unity Catalog, is Databricks' answer to those problems in a single runtime control plane. Rather than governing only who can access data, it governs what models, agents, MCP services, and tools do while they are running, across providers, without locking teams into one model or vendor and it works along the two dimensions the problem demands.
The platform capability is only one part of the answer. KPI Partners helps enterprises decide how those controls should be designed, prioritized, configured, and monitored across real teams, business units, and regulatory environments.
The value of that becomes concrete under regulation. Picture a bank running an agent against customer and transaction data. The same set of controls does several jobs at once: Account numbers and personal data are redacted before any external model sees them, attempts to prompt-inject the agent into revealing data are blocked, spend is capped per team, and the agent is permitted to read but must get a human sign-off before it writes to a system of record or initiates anything that moves money. Every step is logged, so when an examiner asks what the agent did and why, the answer is a query rather than a forensic reconstruction.
Now picture a life sciences firm whose agents touch protected health information (PHI). Under the Health Insurance Portability and Accountability Act (HIPAA) and validated-system expectations, PHI has to be redacted before it reaches an external model, the agent has to be restricted to approved tools, and every request and response needs to be captured as a governed record for audit. In both cases the principle is identical: The controls are not a compliance afterthought; they are what makes it possible to put an agent near regulated data at all.
This is the heart of the matter, and where I push my clients hardest. Governance and security for agents cannot be a cleanup phase you get to after adoption. If you scale first and govern later, you spend the intervening months accumulating exactly the exposure IBM measured, and you make yourself a candidate for the cancellation rate Gartner projects. The controls have to exist before the agents do.
The encouraging part is that this is now practical rather than aspirational. With Unity AI Gateway generally available, the runtime control plane is something you can stand up first and build on, not a capability you are still waiting for. Adopt it early, get the controls in place, and let agents scale into a governed environment rather than out of an ungoverned one. It is far cheaper to grow inside guardrails than to retrofit them around a fleet of agents already in production.
Standing up that control plane well is not a switch you flip; It is a design decision that spans data governance, security policy, cost management, and the realities of a specific regulatory environment. That is the work my team does.
KPI Partners helps regulated enterprises establish the combined governance and security foundation for agents on the Databricks Lakehouse, configuring Unity Catalog and Unity AI Gateway together so that guardrails, spend controls, MCP service policies, and observability are in place before agents reach production. Our agentic AI practice pairs that foundation with the model and tooling choices a given use case actually needs, and the KPI Partners and Databricks partnership is where governed data and safely governed agents come together.
The new power user in your enterprise is an agent that can act in a second, and the organizations that will trust it in production are the ones that decide, up front, to govern and secure it as one thing at runtime. Access control tells you who is at the door. Runtime control tells you what they are allowed to do once they are inside, and for an actor that moves this fast and reaches this far, that is the control that counts. Put it in place first, and scaling agents safely stops being a leap of faith and becomes a matter of design.
Ready to Transform Your Data Strategy? Talk to our experts and discover how KPI Partners can accelerate your data and analytics initiatives.
Talk to Our Experts | Book a demo