Loading…
Building an open ecosystem for AI governance with Unity AI Gateway
David Nasi, Kelly Albano, Ashish Kathapurkar
- Source
- Databricks
- Published
- Added to Yomu
Summary
Databricks announced the Unity AI Gateway partner ecosystem, extending enterprise AI governance beyond models to runtime interactions among models, agents, MCP servers, skills, and AI tools. Built on Unity Catalog, the gateway lets organizations apply policies, monitor activity, manage spend, and govern AI across providers and frameworks, while integrating security, identity, and governance products they already use. The announcement groups the integrations into runtime AI security, observability and guardrails; agent identity and access governance; and AI observability and risk monitoring. Named integrations include Alice, CrowdStrike Falcon AI Detection and Response, Cyera, HiddenLayer, Netskope, Noma Security, Obsidian Security, Openlayer, Okta, Ping Identity, SailPoint, and Saviynt, with described capabilities including prompt-injection detection, data-loss prevention, agent discovery, authorization, and lifecycle governance.
Context
As organizations move AI from experimentation to production, governance requirements extend beyond models. Enterprises need visibility into AI use, controls over agent access, protection against emerging AI threats, and identity systems that govern both human and non-human actors.
Approach / What changed
Unity AI Gateway, built on Unity Catalog, governs runtime interactions among models, agents, MCP servers, skills, and AI tools. Its open partner ecosystem connects security, identity, observability, data protection, threat detection, and guardrail providers to governed AI workflows across providers and frameworks.
Takeaways
- Unity AI Gateway extends governance to runtime interactions involving models, agents, MCP servers, skills, and AI tools, rather than governing only models and data assets.
- The announced ecosystem includes runtime protections for prompts, responses, tool calls, and agent actions, including detection or blocking of prompt injection, unsafe content, data exposure, and malicious tool use.
- Okta, Ping Identity, SailPoint, and Saviynt integrations address agent identity, authorization, ownership, access governance, accountability, and lifecycle controls.