Loading…
What’s new in Databricks Data + AI Platform security and compliance at Data + AI Summit 2026
Jason Wu, Samrat Ray, Filippo Seracini, Alex Esibov, Vijay Raja, Kelly Albano, Robert Zhang, Mia Penfold Lopez
- Source
- Databricks
- Published
- Added to Yomu
Summary
At Data + AI Summit 2026, Databricks announced security and compliance capabilities for scaling Genie, Lakebase, serverless workloads, and AI-powered applications without relying solely on manual provisioning, static network controls, or siloed compliance programs. Automatic Identity Management (AIM) for Microsoft Entra ID is generally available on AWS and Google Cloud, AIM for Okta is in Public Preview, and Context-Based Ingress is in Public Preview across all three clouds for policies based on network source, identity, and access scope. Private Network Gateway, in Private Preview on Azure Databricks, provides one secure connection from serverless workloads to private networks, while expanded Private Link support extends to Lakebase and other services. Compliance additions include Azure Serverless coverage, HITRUST across AWS, Azure, and Google Cloud, ISMAP on Azure and AWS, expanded AWS GovCloud availability, and planned FedRAMP High support on Azure Commercial.
Context
Organizations scaling data and AI need security models that can support Genie, Lakebase, serverless analytics, and AI-powered applications without introducing new risk. The post identifies manual provisioning, static network controls, and siloed compliance programs as limitations, while noting demand for scalable identity management, secure private connectivity, and broader compliance coverage.
Approach / What changed
The announcements combine Automatic Identity Management for identity-provider-based provisioning, Context-Based Ingress policies using network source, identity, and access scope, Private Network Gateway for serverless connections to private networks, expanded Private Link support, and additional cloud, regional, and industry compliance coverage.
Takeaways
- AIM for Microsoft Entra ID is generally available on AWS and Google Cloud, while AIM for Okta is in Public Preview; AIM manages users, groups, and service principals through the identity provider.
- Context-Based Ingress is in Public Preview on AWS, Azure, and Google Cloud, allowing policies for Genie, dashboards, Databricks Apps, and AI Gateway endpoints without exposing the broader workspace.
- Private Network Gateway is in Private Preview on Azure Databricks, and inbound Private Link for Lakebase is generally available on AWS and in Public Preview on Azure.