Swift Media

Blog

AI headlines for business this week (Sep 25, 2026)

EU AI Act deadlines are live, runtime control planes move enforcement into the path, Databricks Unity Gateway unifies multi-vendor AI governance, and agent FinOps becomes a board conversation.

Published · By Matt Potter · 3 min read

Late September and the governance conversation shifted again: regulators want evidence, vendors want to sit in front of agent actions, and finance teams are asking why token spend has no owner.

The deep dive unpacks what EU AI Act deadlines that kicked in this summer actually mean if you are running agents against customer or employee data.

1. EU AI Act: high-risk and transparency obligations now in force

Most remaining EU AI Act obligations became applicable on 2 August 2026, including transparency duties and rules for high-risk AI systems. Penalties for serious violations can reach EUR 35 million or 7% of global turnover. Governance consultants are telling enterprises to document assessment, approval, monitoring, and audit trails for every production AI system, not just the flagship chatbot.

Why it matters for business: even Canadian operators selling into the EU or processing EU resident data need a defensible inventory. Agentic systems add tool calls and API actions to the audit surface. If you cannot list what your agents access and who approved each workflow, you are behind the compliance clock.

Solytics: Enterprise AI Governance 2026

2. Databricks Unity Gateway: one governance layer across models and agents

Databricks is positioning Unity Gateway as a centralized runtime layer for models, coding agents, MCP servers, and external LLMs. It applies Unity Catalog permissions, budgets, rate limits, and contextual guardrails across Databricks-hosted and third-party AI, with full tracing of prompts, tool calls, and policy decisions in MLflow.

Why it matters for business: if your data team already lives in Databricks, this is the "control plane inside the warehouse" play. You get one place to answer "which agent touched which table and what did it cost?" without forcing every team onto a single model vendor.

Databricks: Unity Gateway

3. Runtime control planes: enforcement in the path, not beside it

Vendors like Alterion Draco and Waxell Observe market agent runtime control: discover shadow agents, profile behavior, block or escalate actions before they execute, and export audit evidence for SOC 2, ISO 42001, and EU AI Act reviews. The pitch is consistent: logging after the fact is not governance. Policy must sit between the agent and the tool call.

Why it matters for business: this is the technical answer to "how do we stop an agent from paying an invoice or emailing a client without approval?" If your security team only has SIEM logs of API traffic, you need either a gateway in the path or a very tight tool allowlist.

Alterion Draco · Waxell Observe

4. Agent FinOps: token spend needs an owner and a cap

Integration vendors and analysts keep flagging agent token cost variability as a board-level risk. Boomi's Agent Control Plane narrative includes model routing between frontier, cloud, and on-prem models as governed policy, not a developer's weekend experiment. FinOps teams are being asked to forecast spend when every workflow can spawn ten tool calls per user question.

Why it matters for business: assign a budget owner per agent or per department before you scale. Route cheap tasks to smaller models by policy. Surprise five-figure API bills are how pilots get shut down.

ERP Today on Boomi Agent Control Plane

5. Shadow agents: discovery before policy

Multiple governance platforms now lead with shadow agent discovery: find unsanctioned copilots, browser extensions, and SaaS agents before you write policy. The pattern mirrors early cloud security: you cannot govern what you have not inventoried. Discovery scans that need no SDK changes are selling because IT cannot wait for every team to register their experiments.

Why it matters for business: run a one-hour inventory this week. List every tool that can act on your data (not just chat). Unknown agents are where compliance and security incidents start.

What I would do this week

  • Map which workflows touch EU data and whether they qualify as high-risk under the AI Act.
  • Ask vendors where enforcement sits: in the path, or only in logs?
  • Put a monthly token budget and an owner on each production agent.
  • Read the deep dive on EU AI Act deadlines before your next security review.

Next post is the long read on EU AI Act deadlines and agentic systems. Want blog updates? Join the notify list.

Matt Potter · Swift Media