Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI infrastructure at Databricks Summit 2026: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19415
Topic starter  

TL;DR: Databricks Data + AI Summit 2026 signals that enterprise AI is shifting from pilots to production, with OpenSharing, Federated Catalog, and Lakebase aimed at cross-cloud asset sharing, governed data federation, and transactional agent workloads, according to Trust3. The governance gap is now the harder problem: organisations need visibility into agent scope, access, and runtime behaviour, not just more infrastructure.

NHIMG editorial — based on content published by Trust3: Databricks Data + AI Summit 2026 coverage and its implications for production AI infrastructure

By the numbers:

  • The event features more than 800 sessions across four days, underscoring the scale of production AI discussion.
  • Databricks presented more than 65 partner awards before the sessions began, reflecting a broad ecosystem focus around production AI.

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do data governance gaps become identity risk for AI programmes?

A: Because AI systems inherit trust from the identities that access and route data into them.

Q: What breaks when AI asset sharing does not include provenance controls?

A: Recipients may trust an AI model, skill, or file without knowing who produced it, what it contains, or which permissions were attached to it.

Practitioner guidance

  • Define AI asset trust boundaries Classify models, agent skills, and unstructured AI artefacts as governed assets with explicit owner, consumer, and approval metadata before enabling cross-organisational sharing.
  • Map external catalog entitlements end to end Verify that identity mappings, access checks, and audit trails remain consistent when data is queried through federated catalogs such as AWS Glue and Snowflake.
  • Treat agent write permissions as privileged access Scope agentic systems to the narrowest possible operational records, require approval for write-capable workflows, and review revocation paths before production rollout.

What's in the full article

Trust3's full article covers the operational detail this post intentionally leaves for the source:

  • The full Summit breakdown of OpenSharing, including how the protocol extends sharing to AI models, agent skills, and unstructured assets.
  • The practical governance implications of catalog federation across AWS Glue and Snowflake, including how access and auditing are expected to work.
  • The Lakebase details on transactional AI workloads, including throughput claims and why write-heavy agent applications change database governance.
  • The source article's framing of production AI infrastructure, partner ecosystem context, and what Databricks expects practitioners to prioritise next.

👉 Read Trust3's analysis of Databricks Summit 2026 and production AI governance →

Agentic AI infrastructure at Databricks Summit 2026: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19006
 

Open standards for AI assets are becoming an identity governance issue. OpenSharing matters because it turns models, agent skills, and unstructured AI artefacts into portable objects that move across organisations and clouds. That improves interoperability, but it also expands the trust boundary that IAM and PAM teams must govern. The practical conclusion is that AI asset portability now needs provenance, entitlement checks, and recipient validation as first-class controls.

A question worth separating out:

Q: How do security teams decide whether an AI agent needs PAM-style controls?

A: Use PAM-style controls when the agent can reach sensitive systems, modify data, trigger administrative actions, or inherit privileges that exceed its task scope. The deciding factor is not whether the system is called an AI agent, but whether its actions can change operational state in ways that need tighter approval and session control.

👉 Read our full editorial: Databricks Summit 2026 shows agentic AI needs governance



   
ReplyQuote
Share: