Skip to main content

AI Now Interacts With Production Databases in 96.5% of Organizations as Governance Automation Lags

Ryan McCurdy
Liquibase

AI is already part of the production data path. It is not waiting on the sidelines.

In a 2026 survey conducted by Liquibase, the research found that 96.5% of organizations reported at least one AI or LLM interaction with their production databases, often through analytics and reporting, training pipelines, internal copilots, and AI generated SQL. Only a small fraction reported no interaction at all.

That means the database is no longer a downstream system that AI "might" reach later. AI is already there. The operating question is now control: as AI increases automation and the number of actors touching data, can organizations still standardize change and prove governance at the database layer? The research suggests most can't. Only 28.1% report database change governance that is standardized and consistently enforced, which means the unmanaged risk surface is growing fast.

Database Change Has Reached AI Speed

The research found database change is already operating at AI scale. 68.1% of organizations deploy database changes weekly or faster, and about 30% deploy daily or more. Delivery is no longer episodic. It is continuous.

This matters because governance models built for slower change break at high velocity. When change runs weekly, daily, or multiple times per day, checklists and ticket-driven processes turn into queues. Under pressure, gates get bypassed. Controls become inconsistent. Evidence becomes something teams reconstruct after an incident or audit.

AI does not create that behavior. It amplifies it.

The Real AI Failures Start at the Schema and Data Layer

When people talk about AI risk, the discussion often centers on models: hallucinations, prompt injection, and agent behavior. The research found a more fundamental failure mode: the schema and data layer.

When respondents were asked about AI related risks around database change, the top answers were rooted in data governance: 64.3% cited data quality issues as a top AI related risk, and 46.5% worried about ungoverned AI generated SQL. A significant share also flagged regulatory non compliance for AI workloads and schema drift disrupting pipelines.

These aren't model tuning problems. They are change control and data integrity problems. If schemas are inconsistent, drifted, or unverifiable, the outputs of AI systems become less trustworthy, less explainable, and harder to defend when something goes wrong.

Complexity Makes Consistency Harder

The research found modern database estates are heterogeneous by default. On average, organizations run five database or data platform types, and almost one third (29.1%) manage ten or more. Some operate more than fifteen.

Every additional platform is another environment where approvals can be inconsistent, drift can go undetected, and evidence can go missing. At ten or fifteen platforms, every missing standard doesn't stay contained. It multiplies. And when the organization is shipping database changes weekly or faster, that multiplication happens fast.

Pipeline scale compounds the same issue. A meaningful share of organizations now manage hundreds of CI/CD pipelines, and some manage thousands. At that scale, one missing approval standard isn't one gap. It's hundreds or thousands of gaps.

"Sometimes" Governance Is the Real Risk

One of the clearest signals in the data is a maturity mismatch.

On paper, governance can look mature. A majority of organizations say they have defined policies and approval workflows. But the research found only 28.1% have reached maturity levels where governance is standardized and consistently enforced, and only 7.7% report fully policy-as-code governance with real-time enforcement.

This is the difference between documented intent and system enforced reality. In an AI operating environment, "sometimes" is not a control. A control that runs sometimes is a preference.

Audit pressure compounds the challenge. The research found 95.3% of respondents undergo multiple compliance or database audits per year, and over one fifth face seven or more. Audit teams increasingly want answers that manual processes struggle to produce at speed: did the control run, what changed, and where is the evidence?

What to Do Next: Standardize, Enforce, Prove

The direction of travel is clear. Teams want enforcement, visibility, and evidence to become properties of the system, not heroic efforts by individuals.

At a minimum, three requirements show up as foundational for AI scale database change:

1. Standardize change definitions. Changes need to be represented in machine-readable, reviewable forms that can be promoted consistently across environments and platforms.

2. Enforce policy as code. Rules that used to live in documentation must run automatically before changes reach production, so governance doesn't depend on memory or manual queues.

3. Generate evidence by default. Every change should produce a structured record of what changed, who approved it, where it ran, and what the outcome was, so audits and incident reviews begin from data, not reconstruction.

The research suggests leaders need a scorecard to measure governance at AI scale and manage it as an operating discipline, not a periodic compliance exercise. It points to practical measures that make governance measurable at scale: Mean Time to Detect (MTTD), Mean Time to Recover (MTTR), and coverage metrics for automated controls, audit evidence, and AI-governed change.

The Takeaway

AI is already interacting with production databases. The question is whether the database layer can support AI scale change with credible control.

Organizations that standardize database change, enforce policy automatically, and produce audit-ready evidence as part of delivery will be positioned to let AI accelerate work on top of a foundation they can trust. Organizations that continue to rely on manual gates and "sometimes" controls will find that AI doesn't just increase speed. It increases material risk to AI investment outcomes, uptime, and reputation.

Ryan McCurdy is VP of Marketing at Liquibase

Hot Topics

The Latest

For decades, enterprise networks were designed around a simple assumption: work happened inside the office. Applications lived in centralized data centers, employees connected through internal infrastructure, and security focused on protecting the perimeter that surrounded everything ... But the way organizations operate today bears little resemblance to that environment. Cloud platforms host critical applications, employees connect from homes and airports as often as they do from offices, and partners collaborate through shared systems that exist far beyond corporate walls. In short, the corporate network no longer resembles the environment it was designed to protect ...

As an analyst who researches how IT organizations design, build, and operate their networks, I find that network data is a constant source of pain. Network teams struggle with data quality, fragmentation, authority, access, and trust. And these issues undermine everything they try to do. Here are the numbers: Only 45% of network teams are completely confident in the accuracy of their network source of truth, which documents the intent of their network ...

The 2026 Global Data Center Survey from Uptime Institute reveals an industry navigating workforce constraints, escalating outage expenses, even as rising costs remain the top concern for management teams ...

The next observability gap may not be in the code. It may be under the rack. That sounds strange until you think about how AI incidents actually feel in the middle of an investigation ... The application dashboard may be accurate. It may also be stopping at the wrong boundary. AI systems depend on software, but they also depend on a dense physical stack: racks, power paths, thermal margin, maintenance activity and, in many environments, liquid cooling. Those physical dependencies can change slowly before they look like a software incident ...

Certificate expiration is the rare outage you can see coming. Every TLS certificate carries the date it stops working, so the moment it will begin breaking connections is knowable in advance. That's what makes an expired certificate such a frustrating way to lose a service. What's changing now is how often that date comes around ...

Enterprises operate different combinations of workloads across cloud, hybrid and multicloud environments. For business-critical workloads, teams need to consider monitoring and observability early so they can detect health issues, investigate failures, and understand operational impact. Organizations place workloads on cloud platforms based on a combination of technical requirements, economics, existing dependencies, organizational standards, and business priorities. Their monitoring priorities therefore depend on what they operate and where those systems run. Those priorities will not look the same for every organization ...

Top-performing businesses prioritize data-driven decision making, enabling leaders to move from intuition and gut feel towards evidence-based judgment. But that judgment is only sound when the data underpinning decisions is accurate. With incident management, data accuracy is particularly important. Long-term revenue, customer trust, and operational stability depend on high-quality data that enables teams to quickly identify and address the root cause of major incidents. Against this backdrop, governance becomes a critical endeavor to ensure the right data drives the right action ...

In MEAN TIME TO INSIGHT Episode 26, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses network compliance ... 

Most production autonomous agents do not run in a vacuum. They run inside cloud infrastructure: virtual machines, containers, pods, managed clusters or private servers. That is where most operations teams start monitoring. Is the VM alive? Is the container running? Did the pod restart? Is memory stable? Is CPU too high? Did the health check pass? Those signals are useful. They tell you whether the shell around the agent is alive. They do not tell you whether the agent inside is actually operational ...

Enterprise IT environments have never been more observable ... Yet many organizations still grapple with outages, lengthy incident resolution cycles, and increasing complexity. Most teams do not suffer from a shortage of data. They struggle to determine what deserves attention and what action to take next ... Enterprise IT operations must move beyond monitoring and visibility. The next stage of maturity is decision operations, an approach that helps teams make faster, better-informed decisions ...

AI Now Interacts With Production Databases in 96.5% of Organizations as Governance Automation Lags

Ryan McCurdy
Liquibase

AI is already part of the production data path. It is not waiting on the sidelines.

In a 2026 survey conducted by Liquibase, the research found that 96.5% of organizations reported at least one AI or LLM interaction with their production databases, often through analytics and reporting, training pipelines, internal copilots, and AI generated SQL. Only a small fraction reported no interaction at all.

That means the database is no longer a downstream system that AI "might" reach later. AI is already there. The operating question is now control: as AI increases automation and the number of actors touching data, can organizations still standardize change and prove governance at the database layer? The research suggests most can't. Only 28.1% report database change governance that is standardized and consistently enforced, which means the unmanaged risk surface is growing fast.

Database Change Has Reached AI Speed

The research found database change is already operating at AI scale. 68.1% of organizations deploy database changes weekly or faster, and about 30% deploy daily or more. Delivery is no longer episodic. It is continuous.

This matters because governance models built for slower change break at high velocity. When change runs weekly, daily, or multiple times per day, checklists and ticket-driven processes turn into queues. Under pressure, gates get bypassed. Controls become inconsistent. Evidence becomes something teams reconstruct after an incident or audit.

AI does not create that behavior. It amplifies it.

The Real AI Failures Start at the Schema and Data Layer

When people talk about AI risk, the discussion often centers on models: hallucinations, prompt injection, and agent behavior. The research found a more fundamental failure mode: the schema and data layer.

When respondents were asked about AI related risks around database change, the top answers were rooted in data governance: 64.3% cited data quality issues as a top AI related risk, and 46.5% worried about ungoverned AI generated SQL. A significant share also flagged regulatory non compliance for AI workloads and schema drift disrupting pipelines.

These aren't model tuning problems. They are change control and data integrity problems. If schemas are inconsistent, drifted, or unverifiable, the outputs of AI systems become less trustworthy, less explainable, and harder to defend when something goes wrong.

Complexity Makes Consistency Harder

The research found modern database estates are heterogeneous by default. On average, organizations run five database or data platform types, and almost one third (29.1%) manage ten or more. Some operate more than fifteen.

Every additional platform is another environment where approvals can be inconsistent, drift can go undetected, and evidence can go missing. At ten or fifteen platforms, every missing standard doesn't stay contained. It multiplies. And when the organization is shipping database changes weekly or faster, that multiplication happens fast.

Pipeline scale compounds the same issue. A meaningful share of organizations now manage hundreds of CI/CD pipelines, and some manage thousands. At that scale, one missing approval standard isn't one gap. It's hundreds or thousands of gaps.

"Sometimes" Governance Is the Real Risk

One of the clearest signals in the data is a maturity mismatch.

On paper, governance can look mature. A majority of organizations say they have defined policies and approval workflows. But the research found only 28.1% have reached maturity levels where governance is standardized and consistently enforced, and only 7.7% report fully policy-as-code governance with real-time enforcement.

This is the difference between documented intent and system enforced reality. In an AI operating environment, "sometimes" is not a control. A control that runs sometimes is a preference.

Audit pressure compounds the challenge. The research found 95.3% of respondents undergo multiple compliance or database audits per year, and over one fifth face seven or more. Audit teams increasingly want answers that manual processes struggle to produce at speed: did the control run, what changed, and where is the evidence?

What to Do Next: Standardize, Enforce, Prove

The direction of travel is clear. Teams want enforcement, visibility, and evidence to become properties of the system, not heroic efforts by individuals.

At a minimum, three requirements show up as foundational for AI scale database change:

1. Standardize change definitions. Changes need to be represented in machine-readable, reviewable forms that can be promoted consistently across environments and platforms.

2. Enforce policy as code. Rules that used to live in documentation must run automatically before changes reach production, so governance doesn't depend on memory or manual queues.

3. Generate evidence by default. Every change should produce a structured record of what changed, who approved it, where it ran, and what the outcome was, so audits and incident reviews begin from data, not reconstruction.

The research suggests leaders need a scorecard to measure governance at AI scale and manage it as an operating discipline, not a periodic compliance exercise. It points to practical measures that make governance measurable at scale: Mean Time to Detect (MTTD), Mean Time to Recover (MTTR), and coverage metrics for automated controls, audit evidence, and AI-governed change.

The Takeaway

AI is already interacting with production databases. The question is whether the database layer can support AI scale change with credible control.

Organizations that standardize database change, enforce policy automatically, and produce audit-ready evidence as part of delivery will be positioned to let AI accelerate work on top of a foundation they can trust. Organizations that continue to rely on manual gates and "sometimes" controls will find that AI doesn't just increase speed. It increases material risk to AI investment outcomes, uptime, and reputation.

Ryan McCurdy is VP of Marketing at Liquibase

Hot Topics

The Latest

For decades, enterprise networks were designed around a simple assumption: work happened inside the office. Applications lived in centralized data centers, employees connected through internal infrastructure, and security focused on protecting the perimeter that surrounded everything ... But the way organizations operate today bears little resemblance to that environment. Cloud platforms host critical applications, employees connect from homes and airports as often as they do from offices, and partners collaborate through shared systems that exist far beyond corporate walls. In short, the corporate network no longer resembles the environment it was designed to protect ...

As an analyst who researches how IT organizations design, build, and operate their networks, I find that network data is a constant source of pain. Network teams struggle with data quality, fragmentation, authority, access, and trust. And these issues undermine everything they try to do. Here are the numbers: Only 45% of network teams are completely confident in the accuracy of their network source of truth, which documents the intent of their network ...

The 2026 Global Data Center Survey from Uptime Institute reveals an industry navigating workforce constraints, escalating outage expenses, even as rising costs remain the top concern for management teams ...

The next observability gap may not be in the code. It may be under the rack. That sounds strange until you think about how AI incidents actually feel in the middle of an investigation ... The application dashboard may be accurate. It may also be stopping at the wrong boundary. AI systems depend on software, but they also depend on a dense physical stack: racks, power paths, thermal margin, maintenance activity and, in many environments, liquid cooling. Those physical dependencies can change slowly before they look like a software incident ...

Certificate expiration is the rare outage you can see coming. Every TLS certificate carries the date it stops working, so the moment it will begin breaking connections is knowable in advance. That's what makes an expired certificate such a frustrating way to lose a service. What's changing now is how often that date comes around ...

Enterprises operate different combinations of workloads across cloud, hybrid and multicloud environments. For business-critical workloads, teams need to consider monitoring and observability early so they can detect health issues, investigate failures, and understand operational impact. Organizations place workloads on cloud platforms based on a combination of technical requirements, economics, existing dependencies, organizational standards, and business priorities. Their monitoring priorities therefore depend on what they operate and where those systems run. Those priorities will not look the same for every organization ...

Top-performing businesses prioritize data-driven decision making, enabling leaders to move from intuition and gut feel towards evidence-based judgment. But that judgment is only sound when the data underpinning decisions is accurate. With incident management, data accuracy is particularly important. Long-term revenue, customer trust, and operational stability depend on high-quality data that enables teams to quickly identify and address the root cause of major incidents. Against this backdrop, governance becomes a critical endeavor to ensure the right data drives the right action ...

In MEAN TIME TO INSIGHT Episode 26, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses network compliance ... 

Most production autonomous agents do not run in a vacuum. They run inside cloud infrastructure: virtual machines, containers, pods, managed clusters or private servers. That is where most operations teams start monitoring. Is the VM alive? Is the container running? Did the pod restart? Is memory stable? Is CPU too high? Did the health check pass? Those signals are useful. They tell you whether the shell around the agent is alive. They do not tell you whether the agent inside is actually operational ...

Enterprise IT environments have never been more observable ... Yet many organizations still grapple with outages, lengthy incident resolution cycles, and increasing complexity. Most teams do not suffer from a shortage of data. They struggle to determine what deserves attention and what action to take next ... Enterprise IT operations must move beyond monitoring and visibility. The next stage of maturity is decision operations, an approach that helps teams make faster, better-informed decisions ...