---
title: "Expanding agent governance with Unity AI Gateway"
description: "Unity AI Gateway extends Unity Catalog’s permissions, auditing, and policy controls to agentic workflows involving LLMs, MCP servers, and APIs. The release addresses limited visibility across multi-step actions with on-behalf-of user execution for MCP calls, configurable guardrails, and consistent governance across model providers without separate configurations for each provider and model choice can vary by task. Guardrails can detect PII, prompt injection, unsafe content, and data exfiltration, while logs capture identities, timestamps, MCP details, dollar costs, payloads, latency, status codes, and errors. OpenAI-compatible APIs, fallback models, and endpoint-, user-, or group-level rate limits support production operation, although some capabilities are in Beta or rolling out and availability is limited to supported Databricks regions."
---

# Expanding agent governance with Unity AI Gateway

[Databricks](https://yomu.fyi/company/databricks) · David Nasi · Apr 15, 2026

**Type:** Announcement

## Summary

Unity AI Gateway extends Unity Catalog’s permissions, auditing, and policy controls to agentic workflows involving LLMs, MCP servers, and APIs. The release addresses limited visibility across multi-step actions with on-behalf-of user execution for MCP calls, configurable guardrails, and consistent governance across model providers without separate configurations for each provider and model choice can vary by task. Guardrails can detect PII, prompt injection, unsafe content, and data exfiltration, while logs capture identities, timestamps, MCP details, dollar costs, payloads, latency, status codes, and errors. OpenAI-compatible APIs, fallback models, and endpoint-, user-, or group-level rate limits support production operation, although some capabilities are in Beta or rolling out and availability is limited to supported Databricks regions.

## Context

AI agents orchestrate multi-step workflows across models and systems, often accessing sensitive data through databases, external APIs, and MCP servers. Existing governance tools operate in silos, leaving limited visibility into authorization, data sharing, policy enforcement, costs, and failures across the full chain of agent actions.

## Approach / What changed

Unity AI Gateway brings LLM and MCP governance into Unity Catalog. It provides permissions, on-behalf-of user execution, configurable guardrails, unified logging, cost tracking, inference tables, provider-neutral APIs, fallback models, and rate limits across models and tools.

## Takeaways

- MCP servers can execute on behalf of the requesting user, applying that user’s exact permissions instead of a shared service account.
- Requests can be logged with actual dollar costs, identity, timestamps, MCP connection details, and—through inference tables—full payloads, latency, status codes, and errors.
- The gateway supports OpenAI-compatible APIs, fallback models, and rate limits at endpoint, user, or group level; some capabilities are in Beta or still rolling out.

**Tags:** [AI Gateway](https://yomu.fyi/topic/ai-gateway), [AI Governance](https://yomu.fyi/topic/ai-governance), [MCP](https://yomu.fyi/topic/mcp), [Observability](https://yomu.fyi/topic/observability)

- Source: [Databricks](https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai)
- Source URL: https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai
- Ingested by Yomu: 2026-08-31T03:43:13.236Z

[Read original post](https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai)
