As enterprises deploy autonomous AI agents, experts argue that governance must be enforced directly at the operational data layer rather than relying on agent-level instructions.

Key facts
- •Autonomous AI agents require governance that functions in real-time rather than relying on abstract, paper-based policies.
- •Data-layer enforcement uses existing controls like attribute-based access, classification, and complete audit trails.
- •Priyanka Jain of EDB emphasizes that 'declared purpose' should be treated as a verifiable attribute during access requests.
- •Moving governance to the database level allows organizations to maintain control without ceding oversight to external layers.
- •The approach is designed to help regulated industries put autonomous agents into production securely.
Enterprises are increasingly adopting autonomous AI agents capable of planning and executing tasks across systems without constant human oversight. Because these agents operate in milliseconds and lack human judgment, traditional policy-based guardrails are often insufficient. To maintain security, experts suggest moving governance directly into the operational data layer where agents interact with information.
Enforcing Governance at the Data Layer
Governance mechanisms that rely on reviewing actions before they occur struggle to keep pace with autonomous systems. By shifting control to the data layer, organizations can enforce policies such as role-based access, row-level security, and data masking at the exact moment an agent requests information. This approach ensures that security remains a property of the database itself rather than a promise made by the agent.
Identity and Declared Purpose
Effective governance requires treating AI agents as distinct principals with their own identities. Priyanka Jain, VP of product management for data and AI governance at EDB, notes that binding an agent's 'declared purpose' to its identity allows policy engines to evaluate actions based on intent. This creates an auditable record that tracks not only who acted and what data was touched, but also the stated purpose of the session.
Operational Benefits for Enterprises
Enforcing governance at the data layer allows enterprises to adopt AI more quickly by providing security, risk, and leadership teams with a reliable operating model. Platforms like EDB Postgres AI aim to unify transactional and analytical workloads while maintaining data sovereignty. This framework is particularly relevant for regulated industries that require strict control over data access and auditability.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by VentureBeat AI.



