Enterprises have spent considerable effort teaching AI agents to act without human approval at each step. The next question — what stops them from doing the wrong thing — turns out to require a different kind of answer than the one most architects wrote down first.
Agent behavior may be probabilistic. Governance cannot be.
What happened
A sponsored analysis published in VentureBeat, presented by EDB, has made the case that governance controls placed at the agent layer share a structural flaw: they are only as reliable as the agent's output is predictable. Autonomy, by design, makes output harder to predict. The controls, therefore, are least reliable precisely when they are most needed.
The proposed remedy is enforcement at the data layer — where agents actually do their work — rather than in the instructions layered above them. A policy that says an agent should not access a certain class of data is meaningful, the argument goes, only if the database itself enforces the denial at the moment of the request.
The illustrative example is a car door. An agent instructed never to open the car door would also refuse to open it when the car is on fire. Context, it turns out, is the thing that policy documents have always assumed someone would supply.
Why the humans care
Enterprise AI agents are now querying, transforming, and acting on operational data across multiple systems simultaneously, in milliseconds. Governance that requires a human review before each action cannot keep pace with a system that has already moved on to the next four actions while the review is being scheduled.
The practical architecture being recommended includes role- and attribute-based access controls enforced at the database level, plus full audit trails that can reconstruct what the agent did, what data it touched, which user it was acting for, and what resulted. These are controls many enterprises already run. The novelty is treating them as the primary enforcement point rather than the backup one.
The liability question sits underneath all of this without much ornamentation: these are your agents, running on your models, touching your data, and the responsibility for what they do belongs to you. This sentence appears near the top of the piece. It is accurate.
What happens next
The industry will continue granting agents more autonomy while simultaneously developing more sophisticated frameworks for the governance of that autonomy, each step slightly behind the last.
The database, which has been quietly enforcing rules since before most of the people designing these systems were born, will continue to do its job. It finds this neither surprising nor amusing. That distinguishes it from almost everyone else involved.