Agentic AI is changing how enterprise data is accessed and used. Large enterprises draw on data held across systems and jurisdictions, while AI agents can switch context in seconds – moving from reading a file to querying a database, calling an API or generating code. As enterprises move from AI-assisted analytics towards autonomous agents, the assumptions underpinning existing data governance models are being tested. One example is purpose drift: data being transformed, combined or repurposed for uses beyond those for which it was originally collected.
Existing research and standards show that information about purpose and context, permissions and constraints, and other governance requirements can be represented in machine-readable form and used to help determine how data may be accessed and used. Agentic AI creates a further challenge: governance decisions depend on information about the agent, the data it is using, what it is trying to do, and the context in which it is operating. This complexity raises questions around whether static rules are still fit for purpose.
In our latest IDEA project, we will explore technical mechanisms that enable organisations to govern how AI agents access and use enterprise data through policy-as-code: representing regulatory and operational constraints in machine-readable form so that they can be evaluated within data infrastructure. In particular, we’ll investigate whether enterprise-relevant rules, such as purpose limitation, can be expressed using existing machine-readable vocabularies or policy frameworks, and evaluated or enforced when an AI agent queries or acts upon data.
We are collaborating with practitioners across a range of sectors to develop worked examples based on realistic agentic AI use cases for enterprise data. These examples will use established data, privacy and domain vocabularies – such as the Open Digital Rights Language (ODRL), Data Privacy Vocabulary (DPV) and industry frameworks such as the Financial Industry Business Ontology (FIBO) – to examine how well they can support governance decisions as agents access and use data, and identify where gaps remain.
Alongside these worked examples, we are conducting a landscape review to establish the state of the art in policy-as-code and agentic AI governance in enterprise settings. We will examine how existing and emerging approaches translate data governance policies into technical standards and mechanisms, and how these operate across modern enterprise data architectures, such as data fabrics.
By pairing this landscape review with practical examples, the project will help establish where existing approaches to machine-readable governance can support agentic AI, where important gaps remain, and what these findings mean for organisations seeking to implement dynamic governance in practice. Organisations will gain an accessible introduction to the core concepts, explanations of the underlying vocabularies and policy engines, and practical lessons from the worked examples.
If you would like to be involved with this research, or the IDEA programme as a whole, or would like to find out more, please contact [email protected]. To ensure you receive updates on this work, please sign up to the community.