TL;DR

For years, permissions were set on the report: a data team decided who could open which dashboard. Anahita Tafvizi, who runs data and AI at Snowflake, argues that arrangement fails the moment any employee can interrogate the database in plain English, because the control was never sitting in the data layer where it needed to be. Gartner’s research points the same way.

The structural problem

The argument survives its commercial framing, which is worth stating plainly: this comes from a supplier launching two governance products. Strip those out and the mechanism holds. If access rules live in the reporting layer, an agent reaching past that layer inherits nothing. Permissions attached to a dashboard do not travel with a question asked in English.

The independent evidence is the more useful part. Gartner has put a number on it: firms reporting the best AI results had invested 30% more in the underlying plumbing — how data is managed and governed — than the firms left disappointed. Its analyst Avivah Litan warns separately that once an agent starts acting, the chain of events it sets off is usually invisible to whoever is nominally accountable. Her prescription is a tamper-proof record of what the agent did, and least-privilege rights enforced through the identity systems a company already operates.

Not everyone accepts a single platform can solve it. Leigh McMullen, a Gartner fellow, reckons no finished off-the-shelf product for governing AI exists yet — and even if one did, handing one vendor’s control plane the job of auditing that same vendor concentrates the risk rather than removing it.

Cost is the other control problem

Gartner found six in ten IT leaders fear agents quietly running up bills, though under half of organisations keep any active grip on AI spending. “The biggest barrier to enterprise AI adoption right now is runaway cost,” Tafvizi said — the pattern being that when every query goes to the priciest frontier model whether or not the task warrants it, rollouts stall. Snowflake says sizing the model to the job handled workloads at up to triple the token efficiency with no quality loss. That is the supplier’s own figure, from a company that also books revenue on the consumption it is offering to reduce.

Looking forward

For UK firms deploying agents, the practical takeaway is a question to put to any supplier: where do your access rules actually live? Tafvizi’s closing point cuts against her own employer as much as anyone — going all-in on one model provider’s ecosystem locks you in at the moment the field is shifting fastest. Her sharper claim is that no amount of model scale absorbs the things that actually matter here — a firm’s own definitions, joins across separate systems, role-based access, an audit trail. That argument will outlast the products announced alongside it.