Databricks Updates AI Security Framework for Autonomous Agent Risks

    Databricks20 Mar 2026

    Why it matters

    Why it matters: Autonomous AI agents that take real-world actions introduce liability, data breach, and compliance exposures most security programs haven't yet addressed.

    The brief

    Summary

    Databricks released version 3.0 of its AI Security Framework (DASF), adding controls specifically for agentic AI — systems that autonomously plan, decide, and act. These agents can access data, call APIs, and execute code without human approval, creating new attack surfaces. Organizations deploying AI agents without updated security controls face uncontrolled data access, prompt injection attacks, and unauditable automated decisions.

    Key takeaways

    • 01**Audit** all AI agents in production for autonomous action scope and data access privileges.
    • 02**Enforce** least-privilege controls — agents should only access what each task requires, nothing more.
    • 03**Implement** prompt injection defenses and input validation before agents interact with external data sources.
    • 04**Adopt** DASF v3.0 as a baseline governance document for AI security reviews and board reporting.

    Bottom line

    The bottom line: If your AI agents can act autonomously, your security perimeter has already expanded — update your controls before your adversaries do.

    Read the full article at Databricks

    Original reporting © Databricks. This page carries Matthew Carr's editorial summary.

    Related AI Security