Summary
- Collibra announced machine-readable Agent Contracts and Guardian Agents that can supervise agent behaviour and flag, escalate, redirect or block actions at runtime; both are due through AI Command Center by the end of October 2026.
- The announcement shifts the competitive question from keeping an inventory of AI systems to controlling the moment an agent uses data, calls a tool or changes a business state.
- Buyers should require a named policy principal, rule precedence, shadow-mode evidence, a signed intervention receipt, explicit failure behaviour, local override, rollback and exportable history before treating runtime supervision as a durable control plane.
Enterprise AI governance has spent much of its short life looking backwards. A catalogue records which model exists. An assessment records what somebody expected it to do. A dashboard reports what happened. These objects are useful, but an agent can cross a permission boundary in the interval between policy and review.
Collibra’s 23 September launch proposes a more consequential layer. Agent Contracts are intended to translate governance requirements into reusable machine-readable controls. Global contracts provide fleet-wide rules; specialised contracts add requirements by function, risk class or operating context. Guardian Agents are meant to compare actual runtime behaviour with those rules and respond by flagging, escalating, redirecting or, in block mode, stopping an unauthorised action.
That is a different product category from a register. It sits on the path between an agent’s intention and a business consequence. The closer software comes to that path, the less sufficient it is to say that the rule is “governed.” The market needs to know who authorised the rule, which rule wins when several apply, what evidence caused an intervention and who bears the cost when the guardian is wrong.
The announcement is a direction, not a production result
The timing matters. Collibra says Agent Contracts and Guardian Agents will be available through AI Command Center by the end of October. Live Map is opening this quarter to a small design-partner group. Maestro is available, with Maestro Studio and Maestro Assistant in public preview. The company says configurable Maestro tools require human approval before an action. That design cannot yet be read as proof of how every third-party agent will be supervised.
Collibra also says Maestro Assistant has achieved AIUC-1 certification. The AIUC-1 overview describes certification as a scoped process involving evaluation, audit and continued testing; it does not guarantee that a probabilistic system is safe. The relevant scope here is the named assistant. It does not automatically cover Guardian Agents, Agent Contracts, every Collibra product or a customer’s implementation.
No production benchmark in the reviewed public material reports intervention latency, false blocks, missed violations, runtime overhead or third-party runtime coverage. No customer deployment, pricing, contract value or realised saving is disclosed for the forthcoming controls. This is not evidence that the controls lack those capabilities. It is a boundary on what the announcement proves.
A contract needs a principal before it needs a parser
Collibra’s Agent Contracts description is strongest where it separates a common baseline from specialised rules. A procurement agent and a clinical-research agent should not inherit identical operating rights merely because both use the same orchestration platform. The difficult part begins when rules overlap.
Suppose a global contract forbids disclosure of restricted information, a finance contract permits an approved payment tool, and an incident rule authorises emergency action. Which owner can create the exception? Does the most restrictive rule win, the most specific, the newest or the one issued by a higher corporate authority? Can the agent owner alter the contract that is supposed to constrain that owner? A machine-readable format makes the answer executable; it does not make it legitimate.
The public product material calls Agent Contracts open and independent of a specific runtime. In the reviewed material, however, there is no public schema, versioning protocol, conformance suite, licence, governance process or cross-runtime demonstration. Buyers should treat openness as a testable claim. A contract that can be read only through one vendor’s compiler, or whose intent semantics cannot survive export, remains a switching boundary even if its file is downloadable.
This is where authority and liability have to meet. A governance team may own the policy vocabulary, but the business principal bears the operational consequence. A platform team may operate the guardian, but it should not silently acquire the right to determine procurement, customer, safety or employment decisions. Each consequential rule needs a named principal, a technical enforcement owner and a remediation owner. If those are different people, the handoff belongs in the evidence.
Monitoring is not the same as permission to intervene
The distinction is reinforced by NIST. Its concept paper on software and AI agent identity and authorisation frames identification, authentication, authorisation, auditing and non-repudiation as practical problems when agents gain access to data, tools and applications. NIST AI 800-4 says post-deployment monitoring is necessary because controlled evaluation cannot reproduce the full behaviour of deployed systems and their surrounding components.
The same report is careful about what remains unsettled. It asks who monitors, who remediates incidents, who can act on a finding, what cadence is right and how automated monitoring should be balanced with human validation. Those are not endorsements of Collibra. They are a useful warning against compressing observation, judgment and authority into one word: control.
A buyer therefore needs an intervention receipt, not merely a violation count. The receipt should bind the attempted action and agent identity to the applicable contract version, relevant runtime evidence, decision made by the guardian, human escalation if any, final action, override, rollback state and named remediation owner. It should be possible to prove both that an action was stopped and that a permitted action was not improperly blocked.
Before block mode, a shadow period should compare proposed interventions with real decisions. False blocks have an economic cost: delayed orders, unanswered customers, stalled maintenance or an emergency path that cannot run. Missed violations have a different cost. The acceptable trade-off depends on the action class. Viewing a record, drafting a recommendation and sending money should not share one threshold or one failure policy.
The survey describes pressure, not product efficacy
Collibra’s market framing draws on a Harris Poll survey commissioned by the company. Among 306 US director-level or higher decision-makers in data management, privacy or AI, 76% reported critical roadblocks moving agents from pilot to production, 87% said teams regularly re-verify context and 51% reported significant staff time reviewing and correcting outputs before release. The poll ran online from 5 to 11 August and reports a ±6.4-point credible interval at 95% confidence.
Those figures are evidence of how this respondent group describes the problem. They are not a global failure rate, and they do not establish that a control-plane product removes the cost. In fact, runtime supervision can create a second verification burden if every intervention needs manual checking. The commercial win comes only when the guardian safely shifts labour from universal review to well-defined exceptions.
Evidence boundary
The factual launch, availability and certification claims come from Collibra’s announcement, the company’s posts on Agent Contracts, Guardian Agents and Maestro, plus the sponsored survey methodology. AIUC-1 supplies certification scope context. The two NIST publications provide independent analytical context, not product validation. The buyer tests in this article are editorial proposals.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
