EdgeRed

Home Technology Why Databricks is becoming an AI governance tool

Why Databricks is becoming an AI Governance Platform, not just a data platform

AI governance in Australia is often approached as a policy exercise first and an infrastructure decision second. In practice, the organisations building sustainable AI capabilities are treating governance as a platform capability rather than a standalone framework. Instead of relying solely on documented policies, they embed governance directly into the systems that manage AI, automatically enforcing access controls, recording activity, and maintaining auditability. That is the level of governance that stands up under operational and regulatory scrutiny.

Databricks is a solid example of this shift. Unity Catalog was originally designed as a governance layer for data, providing centralised access control, lineage, classification, and auditing. Increasingly, it performs the same role for AI models and other AI assets. As AI moves into production, this convergence of data and AI governance is becoming significantly more important than many discussions around AI governance in Australia currently acknowledge.

What’s at stake now

Most AI governance problems in Australia aren’t really about the AI itself. They’re about models sitting outside the systems that already govern everything else. A model gets its own infrastructure, its own access rules, and its own audit process, separate from the one covering the rest of the data estate.

That gap is about to get more visible. From December 2026, new Privacy Act rules require organisations to disclose, in plain terms, when an automated system uses personal data to make decisions that affect people. Working out whether a given model even triggers that disclosure, and writing it accurately, is a legal and business judgement call, not something a platform can make for you. But that judgement gets a lot harder to make if nobody can say where the model sits, who built it, who can access it, or what data it touches. Governance data doesn’t answer the compliance question. It’s what you need on hand before you can even start answering it properly.

Databricks handles the first part of that by keeping the model inside Unity Catalog, the same system that already governs the rest of the data: same access rules, same record of who touched what, same audit trail as any other table or pipeline. It’s what happens when the model was never treated as a special case in the first place. Other platforms are moving in the same direction, Microsoft Purview and Snowflake both extend governance to models in similar ways, but the underlying point holds regardless of platform: if the model isn’t inside your normal governance system, you’re starting December 2026 with a harder problem than you need to.

What this looks like in practice

That’s the exact test a recent build had to pass. The client had strict security requirements: an air-gapped, FIPS-hardened environment with no public internet access at all. We staged an open-source language model inside Unity Catalog as a governed asset, served it through a single GPU node rather than a Spark cluster, and gave three different types of access, via notebooks, apps, or batch pipelines, all under the same governance the client already used for the rest of their data. No separate system, no side door, no exception carved out for “the AI thing.”

That’s not an unusual requirement. It’s a preview of what a lot of organisations with sensitive data will expect from any AI platform within the next year or two.

The practical test for any organisation evaluating this

If you’re weighing up AI platforms, don’t ask “can it run a model.” Most platforms can. Ask this instead: if your governance team audited your AI system tomorrow, using the exact same process they use for the rest of your data estate, would it hold up? That’s a fair test regardless of which platform you’re on, and it’s the question worth asking before committing to any of them.

Where this is heading

Generative AI is moving from pilot to production across Australia, and regulation is starting to catch up with what’s actually being deployed. In that environment, the platforms that hold up will be the ones where governance was never separate from infrastructure in the first place. Databricks and Unity Catalog are one clear example of what that looks like done properly. It won’t be the only one, but it’s a useful benchmark for anyone building an AI governance strategy from scratch.

Thinking about how your AI platform would hold up under real governance scrutiny? EdgeRed helps Australian organisations design and build AI systems where governance is part of the platform, not a policy. Get in touch to talk through what that looks like for your environment.

This blog was written by Harsh Tiwari.

About EdgeRed

EdgeRed is an Australian AI and data consultancy, part of The Omnia Collective group, with teams in Sydney and Melbourne. We build things that work in production – agentic AI, machine learning, data engineering, and Microsoft Fabric implementation. 250+ projects. 100+ clients. 100% Australian onshore team.