VentureBeat
When agents act on their own, governance has to live in the data layer

Enterprises must enforce AI-agent governance directly in the operational data layer, where policies can be applied at query time and audited in real-time. By treating agents as first-class principals with declared purposes, role- and attribute-based access, dynamic column masking, and policy-as-code can prevent unauthorized data actions and provide complete traceability.