Loading…
AI governance at Data + AI Summit 2026: What’s new with Unity AI Gateway
David Nasi, Stefania Leone, Ahmed Bilal, Kevin Stumpf, Martin Grund, Vladimir Kolovski, Kelly Albano
- Source
- Databricks
- Published
- Added to Yomu
Summary
Databricks announces new Unity AI Gateway capabilities for governing enterprise AI as organizations operate multi-model, multi-agent, and multi-vendor estates connected to models, MCP services, APIs, and tools. The update adds unified spend visibility, granular attribution, hard spend caps, and smart routing, alongside Unity Catalog support for registering and governing models, MCP services, agents, and skills. Contextual Service Policies, in Beta, can allow, deny, or require approval for actions based on users, agents, models, tools, services, or request and response contents, with guardrails for risks such as PII exposure and prompt injection. The announcement also covers end-to-end tracing, coding-agent analysis with Genie, incident investigation with Lakewatch, ecosystem integrations, and Managed Omnigent on Databricks in Beta.
Context
As enterprises adopt multiple models, coding agents, custom agents, MCP services, APIs, and enterprise tools, governance challenges extend beyond model access. The stated needs include visibility, runtime controls, security guardrails, and cost management across the entire AI estate.
Approach / What changed
Unity AI Gateway extends Unity Catalog governance to AI assets and governs runtime interactions through centralized access controls, contextual policies, spend management, smart routing, monitoring, and integrations with security and identity providers. The announcement also introduces Managed Omnigent on Databricks in Beta.
Takeaways
- Hard spend caps can automatically stop requests when budgets are exceeded, while budgets can be attributed by user, team, tool, and use case.
- Unity Catalog can register, discover, secure, and audit external model providers, custom MCP services, agents, and skills alongside Databricks-hosted models.
- Contextual Service Policies are in Beta and can require approval for actions such as pushing code or modifying files, or block regulated data in requests and responses.