Skip to content
worth noting AI agents

EDB: governance of autonomous AI agents must be enforced at the data level, not just in model instructions

only one source so far

EDB recommends that governance of autonomous AI agents (role-based access, row-level security, masking, audit trail) be enforced directly in the data layer, because relying on the model to follow rules is insufficient, according to the company.

In a paid article on VentureBeat, EDB argues that as AI agents become more autonomous — able to plan, decide and act across systems without human approval at every step — governance based solely on instructions, policies and monitoring above the model is insufficient. According to the company, such controls are reliable only to the extent that agent behavior is predictable, and autonomy is precisely the property that undermines predictability. According to EDB, governance must therefore be enforced where the agent actually works with data — in the operational data layer, at the moment the action occurs — rather than checked after the fact.

EDB describes nine specific controls grouped into three areas: role- and attribute-based access control enforced at query time (for agents as well, not just users), dynamic column masking governed by the same policy, agent identity as a separate entity with a declared purpose bound at the start of the session and a retained link to the acting user, data classification and tagging that govern policy, session-level audit logging (who acted, on whose behalf and with what declared purpose), traceability (lineage) across data pipelines, centralized and portable policy management, encryption of data at rest and in transit, and consistent enforcement across on-premise, cloud, sovereign or air-gapped environments.

According to Priyanka Jain, VP of product management for data and AI governance at EDB, the key point is that the declared purpose of the agent becomes an attribute that the access layer evaluates in the same decision-making process as a role or row-level security — the enforcement mechanism does not change; what changes is that the purpose of the agent is part of both the evaluation and the subsequent audit record. EDB adds that its solution is built on open source Postgres, which, according to the company, is intended to allow organizations to retain control over where data resides and who may access it without handing governance over to a layer they do not own or cannot inspect — something the company describes as a prerequisite for deploying agents in regulated industries.

You can find details in the source article.

What changed

Why it matters

For teams deploying agents, this is a specific architectural recommendation on how to prevent unauthorized actions at the moment an agent accesses data to carry them out — instead of relying on the agent to “decide" to follow a rule. For companies in regulated industries, EDB says this is a prerequisite for auditability and accountability for agent actions, and thus a condition for safer and faster production deployment.

Two audiences, two different impacts

What this means

01

For individuals

According to the recommendation from EDB, developers and architects designing agent systems should not rely on the agent following rules written in a prompt or policy, but should implement access control (who, to which data, for what purpose) directly at the database and identity levels.

What to do When designing or assessing agent systems, verify that key permissions are enforced by the database, not just by instructions in the agent prompt.
More practical updates →
02

For a business

Companies deploying autonomous agents face the risk that an agent will perform an unauthorized action before a human or an application-level policy can check it; according to EDB, the solution is to move rule enforcement (RBAC, row-level security, masking, policy-as-code) directly into the database and manage the agent in the identity system as a separate actor with its own…

Risks and compliance
What to decide Before deploying autonomous AI agents to production, verify whether data access is enforced at the database level (role-based access, row-level security, masking) and whether there are audit records tied to the identity of the agent and…
More business impacts →
AI agents autonomy data security Governance access permissions

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
VentureBeat AI independent context · first detected When agents act on their own, governance has to live in the data layer