Decube targets AI agent sprawl with governance layer for regulated firms
Decube, a Singapore-based data and AI governance platform, has launched a pair of capabilities designed to close what it describes as a critical blind spot in enterprise AI deployment: the inability of regulated organisations to track, catalogue, and audit the autonomous agents now acting on their most sensitive data.
The new Agent Registry automatically discovers AI agents operating across cloud environments including Azure AI Foundry, Snowflake Cortex Agents, and Databricks Agent Bricks, without requiring manual registration. Agent Lineage then maps precisely which data assets, pipelines, and compliance zones each agent accesses, extending the column-level data lineage Decube already provides to the agent layer sitting on top of it.
The scale of the governance gap
The timing is pointed. An IBM enterprise survey presented at Think 2026 found that large enterprises will run an average of more than 1,600 AI agents by the end of this year. Yet the same research found only 18% of executives maintain a complete, current inventory of the agents already running inside their organisations, and just 12% have a centralised platform to manage agent sprawl. Separately, research from Smarsh and FTI Consulting found 55% of enterprises are actively deploying AI while only 26% say their governance keeps pace, and only 30% can detect shadow AI running outside approved workflows.
For a bank or insurer, that is not an abstract technology risk. It is a regulatory exposure. Decube's platform already serves compliance frameworks including MAS, FCA, APRA, BCBS 239, and the EU AI Act. On that last point, the company is careful to note that while the EU AI Act's high-risk system deadline was pushed to December 2027, Article 50 transparency obligations took effect on 2 August 2026 as originally scheduled. Regulated firms that interpreted the headline delay as a wider reprieve are, in Decube's framing, governing against the wrong deadline.
"Every AI roadmap I see from a regulated enterprise has the same blind spot," said Jatin Solanki, Decube's founder. "The agents get approved. The data behind them doesn't get governed. Agent Registry and Agent Lineage close that gap without asking teams to manually track something that changes every week."
Convergence implications: governance as the new infrastructure layer
The Decube announcement sits at the intersection of two converging forces that matter well beyond the data governance niche. First, the proliferation of agentic AI is moving faster than the compliance infrastructure built to contain it. Gartner estimates more than 40% of agentic AI projects are at risk of cancellation by 2027, with data quality cited as the leading blocker. A separate industry survey found over a third of organisations admitted they could not shut down a rogue AI agent if one emerged in production. That is a systemic risk disclosure sitting inside a software launch.
Second, the regulatory architecture governing agentic AI is fragmenting across jurisdictions at precisely the moment enterprises are scaling deployment across them. For a regional bank operating under MAS in Singapore, APRA in Australia, and the FCA in the UK simultaneously, the ability to produce a single auditable record of agent activity is less a product feature and more a licence-to-operate requirement. The market for this governance layer, sitting between the AI model providers and the regulated enterprise, is one that hyperscalers have so far left largely unaddressed, creating an opening for specialist platforms.
Decube is making the Agent Registry module available immediately, with expanded agent observability to follow later in 2026. For the first twelve months, the company is waiving the add-on fee, a pricing move that signals it is prioritising adoption in the current land-grab phase of a market that is only beginning to consolidate.