---
title: "AI Governance"
description: "63 posts about AI Governance, summarised, each linking to the original."
---

# AI Governance
> 63 posts about AI Governance, summarised, each linking to the original.

## Articles

### [AI governance at Data + AI Summit 2026: What’s new with Unity AI Gateway](https://yomu.fyi/post/ai-governance-at-data-ai-summit-2026-what-s-new-with-unity-ai-gateway.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: David Nasi, Stefania Leone, Ahmed Bilal, Kevin Stumpf, Martin Grund, Vladimir Kolovski, Kelly Albano
- Published: Jun 16, 2026

Databricks announces new Unity AI Gateway capabilities for governing enterprise AI as organizations operate multi-model, multi-agent, and multi-vendor estates connected to models, MCP services, APIs, and tools. The update adds unified spend visibility, granular attribution, hard spend caps, and smart routing, alongside Unity Catalog support for registering and governing models, MCP services, agents, and skills. Contextual Service Policies, in Beta, can allow, deny, or require approval for actions based on users, agents, models, tools, services, or request and response contents, with guardrails for risks such as PII exposure and prompt injection. The announcement also covers end-to-end tracing, coding-agent analysis with Genie, incident investigation with Lakewatch, ecosystem integrations, and Managed Omnigent on Databricks in Beta.


### [What is Human-in-the-Loop (HITL)?](https://yomu.fyi/post/what-is-human-in-the-loop-hitl.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Jun 8, 2026

Human-in-the-loop (HITL) is an AI and machine learning approach that places people in training, supervision, or decision-making to improve accuracy, safety, and ethical alignment. Its feedback loop can include data labeling, output review, escalation, approval, override, and continuous feedback, with confidence thresholds and risk scoring routing only selected decisions to people. The explainer distinguishes HITL, where review occurs before flagged actions, from human-on-the-loop monitoring and human-over-the-loop governance, and separates HITL from RLHF, a training-specific technique. It describes uses in medical imaging, moderation, autonomous vehicles, financial services, and AI agents handling consequential actions. Databricks Agent Bricks is presented as supporting governed traces and Agent Learning from Human Feedback, including a case where 32 feedback items improved instruction-following from roughly 12% to 80%.


### [What is Explainable AI (XAI)?](https://yomu.fyi/post/what-is-explainable-ai-xai.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Jun 5, 2026

Explainable AI (XAI) comprises techniques that help people understand how AI systems produce specific outputs, particularly when machine-learning and deep-learning models operate as black boxes. It distinguishes intrinsically interpretable models, such as decision trees and linear or logistic regression, from post-hoc methods including SHAP, LIME, counterfactuals, saliency maps and Grad-CAM. A typical workflow selects a model and prediction, applies a method suited to the model and audience, reviews outputs such as feature scores or heatmaps, and uses them to assess accuracy, fairness, reliability and compliance. The article stresses that post-hoc explanations are approximations rather than definitive proof, so teams should validate them with domain expertise and, where appropriate, combine methods; MLflow and Unity Catalog can preserve explanation artifacts, lineage and auditability.


### [Your guide to the Telecommunications Industry Experience at Data and AI Summit 2026](https://yomu.fyi/post/your-guide-to-the-telecommunications-industry-experience-at-data-and-a.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Elena Tesser, Nevash Pillay
- Published: Jun 4, 2026

Data + AI Summit 2026 presents a Telecommunications Industry Experience for operators responding to surging network traffic, regulatory pressure, cybersecurity threats, competition, and customer churn. The event, scheduled for June 15–18 in San Francisco, positions unified data and AI, governed workflows, and production use cases as the basis for operationalized, AI-native telecom models. Its June 17 Telecommunications Industry Forum features keynotes, presentations, and executive panels on customer experience, autonomous network operations, fraud prevention, secure agent deployment, and the return from modernizing legacy data warehouses. Breakout sessions cover automated metadata generation for Genie, conversational AI/BI, Lakeflow pipelines with Agent Bricks, and data exfiltration protection with egress monitoring. The industry lounge will demonstrate Model as a Service and agentic real-time decisioning, while the agenda emphasizes peer examples and architectural blueprints for scaling AI under telecom governance and compliance.


### [AI Governance Maturity Model: Matrix, Assessment, and Roadmap](https://yomu.fyi/post/ai-governance-maturity-model-matrix-assessment-and-roadmap.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Jun 2, 2026

The AI governance maturity model assesses how deeply governance practices are embedded across an organization’s data, process, and people dimensions, using five stages from Ad Hoc to Optimized. It frames the model as a diagnostic and roadmap for boards and executive sponsors, while a five-dimension matrix separately scores strategy and leadership, policy and ethics, risk management, data governance, and monitoring and observability. The progression moves from discovery and basic ownership through standardized controls, quantified risk, real-time indicators, lineage tracking, and automated, context-aware enforcement. The recommended roadmap starts with a baseline within 30 days, targets Level 3 across the five dimensions within 12 months, runs a 90-day pilot on two or three high-priority systems, then scales effective controls through CI/CD integration and monitoring, with quarterly reviews and annual reassessment.


### [How enterprise leaders are scaling AI agents across their organization](https://yomu.fyi/post/how-enterprise-leaders-are-scaling-ai-agents-across-their-organization.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Christy Maver, Aly McGue
- Published: May 28, 2026

Executives from Danone, Capital One, Warner Bros. Discovery, Ford Credit, Gilead Sciences, and Databricks discuss scaling AI agents for measurable business value while maintaining governance, trust, and cost control. They describe deployment as only the first step, followed by monitoring, observability, performance assessment, and continuous learning, with risk reviews and ongoing evaluation integrated into the agent lifecycle. Organizations are shifting from single-task automation toward specialized multi-agent orchestration for complex workflows, while shadow capabilities and controlled sandboxes test accuracy without exposing live operations. Leaders recommend building momentum through low-risk wins such as Capital One’s Chat Concierge, training employees to prompt, and providing natural-language interfaces, certified data, consistent guardrails, and a secure architecture for deployment and monitoring.


### [Governing AI agents at scale with Unity Catalog](https://yomu.fyi/post/governing-ai-agents-at-scale-with-unity-catalog.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: David Nasi, Stefania Leone
- Published: May 20, 2026

With AI agents proliferating across organizational functions, governance must answer which agents access sensitive data and how they act. Traditional approaches either scatter logs and permissions across systems or restrict deployment, while agents require controls over autonomous tool use and runtime behavior. Unity Catalog and Unity AI Gateway address this through four pillars: delegated access, data-centric governance, cost intelligence, and open interoperability. The design passes user identity through agents with on-behalf-of tokens, evaluates MCP tool calls with Service Policies, applies inline guardrails, and records model, access, trace, and usage data in lakehouse tables. It also connects data quality, classification, spend, and outcomes, while supporting multiple frameworks and model providers through shared governance.


### [How to safeguard AI workloads with Unity AI Gateway Guardrails](https://yomu.fyi/post/how-to-safeguard-ai-workloads-with-unity-ai-gateway-guardrails.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Tim Lortz
- Published: May 19, 2026

Unity AI Gateway’s beta LLM Guardrails extend earlier Gateway guardrails with LLM-powered evaluation, pre-built protections, and tunable custom rules for AI security, compliance, and sensitive-data protection. An Acme marketing scenario maps policies to PII redaction on inputs, jailbreak and prompt-injection blocking, unsafe-content blocking on outputs, and a custom rule that blocks competitor references. Teams configure these guardrails on an endpoint, optionally use Log mode, select evaluator endpoints, and test representative requests while tracking activity in inference tables. Built-in controls behave as expected in the examples, while the custom rule initially performs unreliably until a more specific prompt and gpt-5-4-mini evaluator improve triggering without degrading other tests. Inference tables record request outcomes, evaluator calls, latency, statuses, token counts, and shared request\_id values for auditing and refinement.


### [What’s new in Unity AI Gateway: service policies, guardrails, observability, and cost controls for AI agents and MCPs](https://yomu.fyi/post/what-s-new-in-unity-ai-gateway-service-policies-guardrails-observabili.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: David Nasi, Kelly Albano
- Published: May 19, 2026

Unity AI Gateway is expanding runtime governance for production AI agents, model calls, and MCP tool interactions as teams face rising costs, unclear behavior, and limited control. The Beta adds LLM-based guardrails, token-level cost attribution with per-user alerts and hard budget limits, payload logging, and MCP service policies. Guardrails use a model and prompt to evaluate inputs, outputs, or both in real time, while inference tables and Unity Catalog system tables centralize governed records of usage and interactions. For MCPs, administrators can define SQL policies as Unity Catalog functions using agent identity, user context, and request parameters to constrain tool access and sensitive actions. The capabilities are available in Beta, with payload logging and service policies offered through gated enrollment, and are intended to improve observability, compliance, and cost control.


### [Responsible AI Governance: A Practical Framework for Business Leaders](https://yomu.fyi/post/responsible-ai-governance-a-practical-framework-for-business-leaders.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: May 6, 2026

Responsible AI governance is presented as an operational framework for leaders overseeing systems that can produce biased outputs, expose sensitive data, and create regulatory, financial, or reputational harm. It draws on the NIST AI RMF and OECD AI principles, maps to EU AI Act requirements, and uses human dignity, fairness, privacy, accountability, transparency, and security as governance values. The program starts with a living inventory recording purpose, ownership, training-data sources, affected populations, review dates, model lineage, and third-party status, followed by risk classification and assessments based on potential impact. It calls for lifecycle controls including bias mitigation, security testing, human review, drift monitoring, audits, incident exercises, and confidential concern reporting. The roadmap recommends piloting governance on a highest-risk product line, scaling controls across business units, and reviewing the framework annually or after major incidents, regulatory updates, or portfolio changes.


### [The foundation of AI scalability: One team, one platform, one operating model](https://yomu.fyi/post/the-foundation-of-ai-scalability-one-team-one-platform-one-operating-m.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Aly McGue
- Published: May 4, 2026

Albertsons Companies describes a centralized AI strategy for scaling decisions across merchandising, labor, supply chain, and customer experience across approximately 2,300 stores. The model combines one central AI core, the Databricks Data + AI Platform, and a shared operating model spanning data engineering, ML, governance, and analytics. Reusable ingestion pipelines, templates, feature-store patterns, model monitoring, performance observability, and governance wrappers support local execution, while a company-wide governance committee sets shared standards. Albertsons reports accepting 1.38 million lines of AI-generated code in nine months, with more than 90% of engineers using AI tools, and it provides low-code dashboards, prompt libraries, and conversational agent generation for nontechnical teams. Success is measured through reuse rates, time to deployment, responsible AI compliance, and business outcomes linked to AI uplift, with initiatives required to demonstrate impact before scaling.


### [Generative AI for Business: A Complete Strategy and Implementation Guide](https://yomu.fyi/post/generative-ai-for-business-a-complete-strategy-and-implementation-guid.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: May 1, 2026

Generative AI is presented as an enterprise technology shift with potential value across customer operations, marketing and sales, software engineering, and research and development, which together are described as accounting for approximately 75% of use-case value across industries. The guide distinguishes generative systems, which create text, images, code, audio, or structured data from predictive models, and explains how foundation models and LLMs support open-ended business applications. Its implementation strategy prioritizes reliable data infrastructure, high-impact low-complexity pilots, and governance covering sensitive data, model limitations, monitoring, human review, and compliance. Recommended execution includes a cross-functional squad, predefined KPIs, user training, baseline measurements, and a 90-day executive review with scale, iterate, or discontinue decisions. Retrieval-augmented generation is identified as the most widely adopted way to reduce hallucinations by grounding responses in verified proprietary data, while ROI is expected within six to twelve months for a well-structured pilot.


### [AI Applications: Tools, Use Cases, and Platforms](https://yomu.fyi/post/ai-applications-tools-use-cases-and-platforms.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: May 1, 2026

The guide maps AI applications for data scientists, machine learning engineers, and technical leaders, covering predictive AI, generative AI, conversational AI, and autonomous agents across consumer, developer, and enterprise settings. It distinguishes consumer-facing tools from developer platforms and describes production concerns including model lifecycle management, vector search, data lineage, deployment, monitoring, governance, and evaluation. Generative systems create text, images, code, audio, and video from prompts, while large language models and mixture-of-experts architectures are presented as important foundations for enterprise applications; open models offer control over weights, governance, and deployment. The guide recommends defining use cases, assessing data readiness, and building privacy, bias-auditing, and monitoring controls before production, while noting that agents coordinate multi-step workflows across tools, APIs, and databases.


### [Agentic AI vs Generative AI: Comparing Autonomy, Workflows, and Use Cases](https://yomu.fyi/post/agentic-ai-vs-generative-ai-comparing-autonomy-workflows-and-use-cases.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: May 1, 2026

Agentic AI and generative AI differ primarily in whether a system autonomously pursues a multi-step goal or produces content in response to a prompt. The post defines agentic systems through a perceive-plan-act cycle: agents maintain memory and state, decompose goals, call tools or sub-agents, evaluate conditions, and recover from errors, while generative AI typically performs bounded, reactive inference. It presents workflow examples such as sales follow-up and market-intelligence summarization, showing how APIs connect agents to CRMs, databases, communication platforms, and news services while LLMs provide text generation or reasoning at individual steps. RAG can ground generative outputs in external knowledge, but agentic deployments add operational concerns around repeated inference loops, human oversight, provenance logging, and access controls. The conclusion recommends choosing by task structure: generative AI for single-turn creation or summarization, agentic AI for autonomous coordination, and both together for complex enterprise workflows.


### [Agents are ready, but your architecture probably isn't](https://yomu.fyi/post/agents-are-ready-but-your-architecture-probably-isn-t.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Catherine Brown
- Published: Apr 29, 2026

Enterprise AI initiatives often produce activity rather than value because organizations start with technology instead of a defined outcome and overlook data architecture, governance, and semantic context. Agentic systems add risk when they can send messages, update records, place orders, or delete records, making permissions and situational controls essential. The discussion argues that dashboards and batch pipelines are poorly matched to low-latency, high-scale agent workloads, which require transactional infrastructure alongside existing analytics. Lakebase is presented as that transactional foundation, while AgentBricks, Databricks Apps, and Genie provide agent development and monitoring, application delivery, and conversational data access. The recommended path is to define success first, isolate a focused pilot, learn what works, and redesign underlying processes rather than merely add AI to them.


### [Operationalizing AI for public sector fraud prevention](https://yomu.fyi/post/operationalizing-ai-for-public-sector-fraud-prevention.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Johnathan Tafoya, Kacey Hertan
- Published: Apr 28, 2026

Public-sector agencies face fraud methods including synthetic identities, deepfake-enhanced documentation, and personalized social engineering, while legacy controls remain fragmented and difficult to scale. The fictional Services Bureau demonstrates an operating model that combines Databricks Apps, Lakebase, Unity Catalog, Delta Sharing, Agent Bricks, and AI/BI Genie in a single fraud-operations environment. Governed data lands in Delta tables; Unity Catalog applies attribute-based access control, masks PII by role, and provides lineage, while agents connect live lakehouse queries, agency policies, and external fraud signals through MCP. Analysts review evidence and recommendations, then approve, override, or escalate cases, keeping human judgment central. The described workflow turns weeks of manual investigation into a day, supports dashboards and conversational SQL, and is presented as making fraud decisions faster, more secure, transparent, and defensible.


### [Inside one of the first production deployments of Lakebase: LangGuard's agentic workflow governance engine](https://yomu.fyi/post/inside-one-of-the-first-production-deployments-of-lakebase-langguard-s.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Venkat Raghavan, Jason Keirstead, Ravi Srinivasan, Nina Williams, Amelia Westberg
- Published: Apr 27, 2026

LangGuard is presented as a runtime enforcement layer for enterprise agentic workflows, monitoring actions, decisions, tools, credentials, and intent across connected systems. Its GRAIL data fabric records multidimensional trace data, builds a live knowledge graph, and evaluates allow/deny/modify decisions against policy before tools, datasets, or models are accessed. The deployment uses Databricks Lakebase as the operational system of record, relying on PostgreSQL, serverless autoscaling, scale-to-zero, compute-storage disaggregation, hot-data caching, and copy-on-write branching for policy testing. LangGuard chose this architecture to handle bursty trace writes and low-latency enforcement reads without provisioning for peak demand, while keeping operational data available to Databricks analytics and AI capabilities without additional ETL. The stated next step is predictive governance: training behavioral models on historical traces to flag anomalous agent behavior before a policy violation.


### [Model risk management in 2026: A banker's guide to the revised interagency guidance](https://yomu.fyi/post/model-risk-management-in-2026-a-banker-s-guide-to-the-revised-interage.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Pavithra Rao, Jennifer Miller, Chaitanya Varanasi, Kim Hatton
- Published: Apr 25, 2026

The post presents the April 17, 2026 revision to model risk management guidance as a shift toward risk-based, principles-driven oversight, replacing several earlier issuances from the Federal Reserve, FDIC, and OCC. It identifies five operational changes: materiality tiering, end-to-end lifecycle governance, reproducible effective challenge, continuous drift and performance monitoring, and application of MRM principles to GenAI and agentic systems. Its proposed response is a Databricks reference architecture built on Unity Catalog, Delta Lake, Lakeflow Declarative Pipelines, Feature Store, MLflow, Model Registry, Model Serving, and assurance tools. The design makes tiering metadata-driven and turns lineage, validation, approvals, monitoring, documentation, and retirement records into evidence generated during normal model work. The stated conclusion is that a unified substrate can reduce integration and manual evidence work, allowing regulatory changes to become configuration exercises rather than multi-quarter programs.


### [A Modern AI Risk Management Framework](https://yomu.fyi/post/a-modern-ai-risk-management-framework.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Apr 22, 2026

AI systems introduce probabilistic behavior, model drift, adversarial manipulation, bias, and auditability challenges that traditional IT risk practices may not address. The framework described combines NIST AI RMF, EU AI Act, and ISO/IEC 23894:2023, using Govern, Map, Measure, and Manage as its operational structure while recognizing regulatory and societal context. It recommends cross-functional governance, clear risk ownership, an AI-BOM covering systems, data flows, dependencies, and accountability, plus continuous measurement of fairness, explainability, data quality, security vulnerabilities, and harm likelihood and severity. Across the AI lifecycle, the text identifies risks including data poisoning, model drift, malicious library injection, prompt injection, hallucinations, and platform vulnerabilities, and points to the AI RMF Playbook for checklists, timelines, and governance artifacts.


### [What is Generative AI in Marketing?](https://yomu.fyi/post/what-is-generative-ai-in-marketing.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Apr 16, 2026

Generative AI in marketing creates content, insights and recommendations that can personalize experiences, optimize campaigns and improve performance. Unlike traditional analytics, which mainly reports on past results, it produces net-new outputs such as ad copy, audience segments, product recommendations, visual assets and strategic summaries. A typical workflow prepares campaign, customer and brand data, grounds or fine-tunes models, generates outputs, applies targeting and optimization, and uses human review and refinement. It distinguishes pretrained tools such as ChatGPT, Claude and Perplexity from customized models and broader AI transformation, noting trade-offs between speed, investment, relevance and strategic alignment. Successful adoption depends on high-quality, consented data, governance, privacy controls, human oversight, monitoring and cross-functional ownership; the conclusion presents AI as a force multiplier rather than a replacement for human creativity and judgment.


[Newer posts](https://yomu.fyi/topic/ai-governance/page/2.md) · [Older posts](https://yomu.fyi/topic/ai-governance/page/4.md)
