When agents act on their own, governance has to live in the data layer

| Source: VentureBeat AI

Tags: AI agents, enterprise AI, governance, data security, agentic AI, compliance

A sponsored VentureBeat piece (by EDB) argues that AI agent governance can't live in abstract policies or prompt-layer guardrails — it must be enforced at the operational data layer, in context, at the exact moment agents query or modify data.

Details

As enterprises deploy AI agents with greater autonomy — the ability to plan, decide, and act across systems without human approval — the question of what actually enforces limits on agent behavior becomes critical. This VentureBeat piece, sponsored by EDB (EnterpriseDB), argues that current approaches to governance are structurally insufficient. The core problem: guardrails implemented at the agent or prompt layer depend on the agent's output being predictable, but autonomy is precisely the property that makes output hard to predict. An agent acting in milliseconds across multiple systems cannot be governed by policies that require pre-action human review. The article's central insight is that rules must be context-sensitive — the same rule ('never open the car door') can require opposite actions depending on situation (car on fire, someone injured). Static policies can't handle this; governance must be executable in the moment. The proposed solution is data-layer enforcement: rules embedded in the operational data infrastructure that apply at query time, in context, catching agent actions before they execute. Note this is sponsored content by EDB, whose commercial product is a Postgres-based enterprise database — the framing naturally favors database-level controls. Evaluate the general principle separately from the vendor-specific recommendation.