Your AI Agent Doesn’t Know What “At Risk” Means
- By Winston Thomas
- September 21, 2026

“An agent doesn’t know what an at-risk customer is,” says Amy McNee at a recent interview at the sidelines of the Boomi World Forum in Singapore. “Even if the record is clean.”
McNee leads global solution engineering and data management go-to-market at Boomi, an integration software company. A perfect customer record doesn’t tell an agent what “at risk” means. It means one thing to a sales team chasing new customers and another to a team protecting renewals. The agent acts anyway.
People used intuition to catch bad data. “Agents don’t have that,” McNee says. “Now we do see companies taking from their AI budgets to clean up their data.”
That problem sits at the center of enterprise AI’s latest land grab. Microsoft, Salesforce and Boomi all now sell a control plane for agents: software that watches, limits and logs what agents do. These tools focus on stopping forbidden actions, such as reaching the wrong system, leaking data or overspending. Stopping an agent from confidently acting on a wrong answer is a different problem. The first belongs to the chief information security officer and the chief financial officer. The second belongs to the chief data officer.
Everyone sells the brakes
Boomi presented its Sept. 2, 2026, launch to media in Singapore, making it the newest entry. Its Agent Control Plane connects agents to core business systems, governs their actions and caps AI costs. It runs in public cloud, in a customer’s own cloud or on premises. Its gateway technology comes from Lunar.dev, an Israeli AI gateway company that Boomi finished acquiring in late July 2026.
Rivals got there first. Microsoft made Agent 365 generally available May 1, 2026, at USD15 per user per month. Salesforce’s MuleSoft Agent Fabric already offers several of the same controls:
- token budgets (tokens are the units AI models bill by)
- limits on request rates
- redaction of sensitive data
- tracing of agents across Salesforce, Amazon Bedrock and Snowflake
SAP agreed in March to buy Reltio, a master data management vendor, to make its customers’ data ready for AI.
The pressure behind the rush is measurable. Gartner predicts that by 2027, 40% of enterprises will demote or shut down autonomous agents because of governance gaps they find only after something breaks in production. In a Forrester study that Boomi commissioned, 86% of leaders said their organizations had moved past agent pilots, but only 34% trusted the actions their agents take. Finance is watching too: 98% of FinOps practitioners now manage AI spending, up from 31% two years earlier.
“Governance with the big G is about access, policy, enforcement, security. Governance with the little G is about context.” — Amy McNee @ Boomi
Security teams have their own doubts about MCP, the Model Context Protocol many agents use to connect to business software. “I’ve seen companies talk about not adopting MCP because this market is moving so fast that they don’t know if that’s going to be the standard,” McNee says. “MCP just generically is not governed and secure. We’re bringing that to MCP.”
All of that is brakes. So why should a CDO care about one more control plane? Because Boomi puts meaning, not just security, at the center of its pitch.
Big G, little G
McNee splits governance in two. “Governance with the big ‘G’ is about access, policy, enforcement, security,” she says. “Governance with the little ‘G’ is about context.”
Little G covers the definitions and business meaning that CDOs own, and it has long been the neglected half. “The problem with governance in the past is it was a destination,” McNee says. “You had to know where to go and you had to know to go there in the first place.”
Boomi’s March 9 press release introduced Meta Hub to make that context travel with the data. The release said the announced capabilities “are available in March 2026.” In Meta Hub, subject matter experts move each definition through three states: endorsed, pending or deprecated. When an expert endorses a knowledge base for an agent, the agent must use it every time it reasons. “If you deprecate it, then it stops,” McNee says. “It doesn’t get deleted.”
The bigger change is economic. “Because it was really hard to show value of governance tools in the past, nobody invested in them,” McNee says. Agents change that math. “Now, if your agents are using that glossary every time they execute, guess what? It’s valuable. You have to maintain it.”
The proof sits in the agent’s chain of thought, its step-by-step reasoning log. “You can prove that it’s getting used every time because you’ve captured it in the chain of thought,” she says. The data steward finally gets a usage receipt.
The glossaries are also federated, which means each team or market keeps its own, because words change meaning across borders. “You can have a glossary that you attach to your agent that runs in Singapore and a glossary that you attach to your agent that can run in Australia,” McNee says. Data mesh, an earlier architecture idea, also tried to federate governance. As McNee tells it, even its author eventually stopped insisting that teams define everything first. “It takes years to curate an enterprise glossary and you get no value, and by the time you’re done you have to start over.”
The idea is strong. The rest of the context layer, and the enforcement around it, is still catching up.
The unfinished half
Knowledge Hub is the other piece of Boomi’s little G. It feeds agents context from documents and other unstructured sources. Boomi’s documentation places it in an early access program and calls it unsupported and not meant for production. It runs only in U.S. and EU regions.
Enforcement raises a sharper question. Does the control plane only watch agents, or does it stand between them and business systems? “Yeah, both,” says David Irecki, Boomi’s chief technology officer for Asia Pacific and Japan.
“Many enterprises are struggling to just get one agent out of the door, let alone a thousand.” — David Irecki @ Boomi
Boomi’s Sept. 2, 2026, release reads two ways. It says the Agent Control Plane provides “the visibility layer” and that the Boomi AI Gateway, built on Lunar.dev technology, “will act as the enforcement layer.” Its FAQ uses the present tense and says the gateway applies controls “in real time within the traffic path.” Buyers should ask which tense describes the product they can deploy today. Its MCP gateway, the release adds, already applies role-based access control and rate limits to agents’ tool calls.
Irecki describes anomaly detection that learns each agent’s normal behavior over 30 days. When an agent drifts from that baseline, IT can “turn that agent off and then deal with it.” That catches an agent that changes. It cannot catch one that misread “at risk” from day one, because the error is part of its baseline.
Gartner calls all-or-nothing agent governance the root cause of failure and urges controls matched to each agent’s level of autonomy. An agent that is confidently wrong needs little G, not a kill switch. And little G has to live somewhere.
Where the context lives
“Sovereignty trumps features,” McNee says. “There are real fines, monetary implications to getting that wrong.” Rules across the region are diverging. Irecki sees Singapore, the Philippines and Malaysia adopting data-sharing approaches, “and others like Indonesia or Vietnam looking instead to lock down.”
Boomi answers with deployment choice. McNee contrasts its Data Hub with traditional master data management. “If you look at traditional MDM solutions, those records are tied to the infrastructure in the cloud where it sits,” she says. “For us, it’s going to be tied where it makes sense for the customers.”
Boomi applies the same idea to agents. Its Sept. 2, 2026, release says its hybrid runtime runs agents, tools and models inside private networks and regional boundaries. Customers that prefer Boomi to host can use its managed agent runtimes in the U.S., Britain, Japan and Australia. Either way, agent instructions encode business logic. CDOs should ask every vendor where instructions and tool settings are stored, not just where the agent runs.
In May 2026, Singapore’s regulator updated its agentic AI governance framework. It asks companies to assess and bound agent risks up front and to keep humans meaningfully accountable. Sometimes the simplest way to bound the risk is to skip the agent.
The cheapest guardrail
Irecki’s test is payroll. “Do you want an agent to decide if you get paid at the end of the month? No.” Cost has already forced retreats. “We’ve seen instances in our customer base where they’ve rolled those agents back because the human is actually cheaper,” he says.
Risk tolerance, not geography, sets the pace. “It’s not geographically dependent or regionally dependent. It’s dependent on the customers,” Irecki says. Retail can afford mistakes that health care cannot. “It doesn’t matter if you recommend the wrong piece of clothing, but it does and has serious consequences if you recommend the wrong medication.”
Boomi customer Multiquip learned this the hard way. It first loaded its PDFs into a vector database, which matches text by meaning, and got severe hallucinations. It then moved its hardest queries to deterministic systems, which follow fixed rules and return the same answer every time. Support times fell by 75%.
Some financial institutions McNee works with have decided agents are not yet worth the risk: “the juice isn’t worth the squeeze for them, not right now.” Irecki is more direct: “Many enterprises are struggling to just get one agent out of the door, let alone a thousand.” After 18 to 36 months of experiments, McNee says, “Now we need to say should we do it.”
For CDOs whose answer is yes, the next question is which control plane.
Choosing a control plane
On enforcement features alone, the vendors’ lists look alike: token budgets, rate limits, human approvals and audit trails. Microsoft, Salesforce and Boomi all claim to govern agents built on other platforms. The difference is home base.
- Microsoft ties agents to its Entra identity system and Microsoft 365 admin tools.
- MuleSoft describes protecting data before it leaves the Salesforce trust boundary.
- SAP is pulling master data into its own Business Data Cloud.
Boomi has no business application suite to anchor, and it makes that its pitch. Its Sept. 2, 2026, release argues that cloud and model providers each have “a built-in interest in keeping workloads inside its own environment.” McNee states the premise flatly: “No company is ever going to standardize on a single thing.”
Irecki points to a Sydney customer building agents in both Salesforce and Snowflake. “They’re talking to us about providing a single pane of glass around all of those agent providers,” he says. A company committed to one stack may find the native tools enough.
“I’m seeing a lot of governance discussions now about accelerating trust,” Irecki says, “because if you embed governance, surely you get better outcomes from those first and initial AI engagements.”
That makes the CDO’s job less about picking a winner and more about setting the test:
- Who endorses your definitions, and can you prove agents used them?
- Does enforcement sit in the traffic path today?
- Where does your vendor keep your agents’ instructions?
- Which work should never be agentic at all?
The CISO will buy the brakes regardless. The CDO decides whether the agent knows where it’s going.
Image credit: iStockphoto/Jake Lomachevsky
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.