TL;DR — Key Takeaways
– CData Software launched the CData Connect AI Gateway to apply governance and security controls across AI models, agents, tools and enterprise data.
– The gateway uses a self-learning context engine and schema-aware connectors to understand enterprise systems and enforce permissions down to the record level.
– It can route requests to the most efficient AI model while attributing and budgeting spending by team, agent, model and tool.
CData Software today added an artificial intelligence (AI) gateway through which governance policies and other controls can be applied to models, tools, agents and the data they access.
The CData Connect AI Gateway is based on a self-learning context engine designed to give AI agents access to live enterprise systems in a way that enforces permissions down to the record level. It understands the schemas, objects and relationships of interconnected systems using a context engine that continuously improves with every prompt, tool call and approved correction. Schema-aware tools then filter, join, and aggregate data at the source to more efficiently manage context windows.
Additionally, the gateway routes each request to the most efficient model for the task to enable organizations to reduce costs. Spend is attributed and budgeted by team, agent, model, and tool.
The CData Connect AI Gateway itself is based on hundreds of schema-aware connectors that CData previously developed to define structure, relationships and semantics across applications, databases, data warehouses, on-premises systems and legacy environments. A Model Context Protocol (MCP) server that makes those applications, tools and platforms accessible to AI agents and applications has been built into the CData Connect AI Gateway.
Every request carries two identities. The first is the person it serves while the second belongs to the agent acting for them. The CData Connect AI Gateway leverages those identities and the context it understands about the IT environment to enforce controls in a way that is auditable.
The goal is to provide organizations with a single control point for adding a governance layer to AI workflows, says Marie Forshaw, senior vice president of product marketing for CData. “It’s all policy driven,” she adds.
It’s not clear how quickly organizations are moving to apply security and governance controls to agentic AI workflows, but there is a clear need to not only rein in potential rogue behavior but also capture the knowledge and assumptions used to drive them. Otherwise, the most any organization is able to do is observe AI agent behavior after a decision has been made or a task has been executed. To achieve their governance goals, organizations need to know which systems an agent accessed, what data it used, which policies governed the interaction, and what actions were performed, noted Forshaw.
Hopefully, governance and security controls will eventually catch up with the current state of agentic AI. While it’s arguable that AI agents have been programmed too aggressively, the fact remains they are already showing up in IT environments by the score. As it’s unlikely those AI agents will be pulled from those environments, the onus now falls to the organization that deployed them to govern them. Each organization naturally will need to determine how best to ultimately achieve that goal but, arguably, one of the most straightforward methods would be to deploy a gateway through which all AI agent activity is routed. Otherwise, it’s not so much a question of whether there will be an incident involving AI agents as how many incidents there will be.

