Skip to main content

AI Now Interacts With Production Databases in 96.5% of Organizations as Governance Automation Lags

Ryan McCurdy
Liquibase

AI is already part of the production data path. It is not waiting on the sidelines.

In a 2026 survey conducted by Liquibase, the research found that 96.5% of organizations reported at least one AI or LLM interaction with their production databases, often through analytics and reporting, training pipelines, internal copilots, and AI generated SQL. Only a small fraction reported no interaction at all.

That means the database is no longer a downstream system that AI "might" reach later. AI is already there. The operating question is now control: as AI increases automation and the number of actors touching data, can organizations still standardize change and prove governance at the database layer? The research suggests most can't. Only 28.1% report database change governance that is standardized and consistently enforced, which means the unmanaged risk surface is growing fast.

Database Change Has Reached AI Speed

The research found database change is already operating at AI scale. 68.1% of organizations deploy database changes weekly or faster, and about 30% deploy daily or more. Delivery is no longer episodic. It is continuous.

This matters because governance models built for slower change break at high velocity. When change runs weekly, daily, or multiple times per day, checklists and ticket-driven processes turn into queues. Under pressure, gates get bypassed. Controls become inconsistent. Evidence becomes something teams reconstruct after an incident or audit.

AI does not create that behavior. It amplifies it.

The Real AI Failures Start at the Schema and Data Layer

When people talk about AI risk, the discussion often centers on models: hallucinations, prompt injection, and agent behavior. The research found a more fundamental failure mode: the schema and data layer.

When respondents were asked about AI related risks around database change, the top answers were rooted in data governance: 64.3% cited data quality issues as a top AI related risk, and 46.5% worried about ungoverned AI generated SQL. A significant share also flagged regulatory non compliance for AI workloads and schema drift disrupting pipelines.

These aren't model tuning problems. They are change control and data integrity problems. If schemas are inconsistent, drifted, or unverifiable, the outputs of AI systems become less trustworthy, less explainable, and harder to defend when something goes wrong.

Complexity Makes Consistency Harder

The research found modern database estates are heterogeneous by default. On average, organizations run five database or data platform types, and almost one third (29.1%) manage ten or more. Some operate more than fifteen.

Every additional platform is another environment where approvals can be inconsistent, drift can go undetected, and evidence can go missing. At ten or fifteen platforms, every missing standard doesn't stay contained. It multiplies. And when the organization is shipping database changes weekly or faster, that multiplication happens fast.

Pipeline scale compounds the same issue. A meaningful share of organizations now manage hundreds of CI/CD pipelines, and some manage thousands. At that scale, one missing approval standard isn't one gap. It's hundreds or thousands of gaps.

"Sometimes" Governance Is the Real Risk

One of the clearest signals in the data is a maturity mismatch.

On paper, governance can look mature. A majority of organizations say they have defined policies and approval workflows. But the research found only 28.1% have reached maturity levels where governance is standardized and consistently enforced, and only 7.7% report fully policy-as-code governance with real-time enforcement.

This is the difference between documented intent and system enforced reality. In an AI operating environment, "sometimes" is not a control. A control that runs sometimes is a preference.

Audit pressure compounds the challenge. The research found 95.3% of respondents undergo multiple compliance or database audits per year, and over one fifth face seven or more. Audit teams increasingly want answers that manual processes struggle to produce at speed: did the control run, what changed, and where is the evidence?

What to Do Next: Standardize, Enforce, Prove

The direction of travel is clear. Teams want enforcement, visibility, and evidence to become properties of the system, not heroic efforts by individuals.

At a minimum, three requirements show up as foundational for AI scale database change:

1. Standardize change definitions. Changes need to be represented in machine-readable, reviewable forms that can be promoted consistently across environments and platforms.

2. Enforce policy as code. Rules that used to live in documentation must run automatically before changes reach production, so governance doesn't depend on memory or manual queues.

3. Generate evidence by default. Every change should produce a structured record of what changed, who approved it, where it ran, and what the outcome was, so audits and incident reviews begin from data, not reconstruction.

The research suggests leaders need a scorecard to measure governance at AI scale and manage it as an operating discipline, not a periodic compliance exercise. It points to practical measures that make governance measurable at scale: Mean Time to Detect (MTTD), Mean Time to Recover (MTTR), and coverage metrics for automated controls, audit evidence, and AI-governed change.

The Takeaway

AI is already interacting with production databases. The question is whether the database layer can support AI scale change with credible control.

Organizations that standardize database change, enforce policy automatically, and produce audit-ready evidence as part of delivery will be positioned to let AI accelerate work on top of a foundation they can trust. Organizations that continue to rely on manual gates and "sometimes" controls will find that AI doesn't just increase speed. It increases material risk to AI investment outcomes, uptime, and reputation.

Ryan McCurdy is VP of Marketing at Liquibase

Hot Topics

The Latest

Pilots are everywhere, stakeholders are seeking results, businesses are pushing for new tools, and IT teams are being asked to make AI secure, reliable, and useful at scale. But as organizations move from testing AI to operationalizing it, many are discovering that the biggest barrier is not the model, the use case, or even the budget. It is the file data foundation within ...

Fast or cheap? For most of my career in engineering, speed and quality sat on opposite ends of a seesaw. The "OR" in "fast or cheap" was non-negotiable. It was expected that pushing for faster releases meant that something in quality would give way. Tightening quality controls meant the schedule slipped. Every engineering leader I know has lived some version of that tradeoff ... The seesaw is starting to level out ...

I have been building enterprise software for more than 20 years ... One thing stays true across all of it: You do not find out your foundation is wrong during the crisis. You find out when the debt comes due. For a lot of organizations, that bill is arriving now. New research ... puts hard numbers on something practitioners have been sensing for a while. The telemetry problem isn't coming. It's already here ...

The rapid growth of AI workloads is pushing traditional log management approaches to their limits, according to The State of Log Management 2026 report from Dynatrace. Modern logs have become critical to understanding, validating, and securing AI-driven decisions, helping organizations ensure reliability, compliance, and performance at scale. However, the volume and complexity of AI telemetry are overwhelming legacy tools ...

For years, secure connectivity has relied on a familiar pattern: route traffic back to centralized gateways, inspect it, and then allow access. This model worked when applications lived in a handful of data centers and users were largely confined to offices. That model is now under strain. Applications are distributed across clouds, users connect from everywhere, and real-time workloads demand performance that centralized inspection points struggle to deliver. As traffic volumes grow and latency expectations shrink, routing everything through a small number of control points has become both a performance bottleneck and a resilience risk. The future of secure connectivity requires a different approach ...

The AI experimentation phase is over, and the private cloud is where enterprise AI workloads are being deployed for security and scale, according to Private Cloud Outlook 2026, a new report from Broadcom ... 2026 marks an acceleration into a full AI tipping point. The shift is being shaped by three forces — costs, complexity, and control — that public cloud environments are increasingly failing to address for production AI at scale. Key findings from the report include ...

44% of organizations have reported an outage in the past year tied to suppressed or ignored alerts, and 78% had at least one incident where no alert was fired at all ... Engineers learned about failures from customers. That gap between what our tools report and what our customers experience is the problem DevOps teams have been quietly solving with GenAI tooling, even as most enterprises continue to run their NOCs on manual alert triage ...

Cloud outages are usually described as technical failures. When a service goes down, a dependency breaks, or a region has issues, the focus immediately shifts to infrastructure. But if you look closely at how these incidents actually unfold, the root cause is rarely the technology itself. It is almost always tied to decisions made earlier, during design, implementation, or day-to-day operations. The system behaves the way it was built. The real question is how it was built ...

77% of leaders say their teams need AI skills urgently. 64% say their organization plans to train current employees rather than hire new ones. So far, so reasonable. The part that surprised me is who's been put in charge: 34% of those leaders say IT and engineering own the AI skills mandate. Learning and Development or HR own it at 7% of organizations. That's roughly five-to-one in favor of the people who understand the tools, over the people whose actual job is teaching adults how to learn new ones ...

In the ever-evolving digital landscape, enterprises are increasingly focused on enhancing their observability stacks to gain deeper insights into their IT environments. Observability has become a cornerstone of modern IT operations, enabling organizations to monitor, diagnose, and optimize their systems with unprecedented precision. However, a critical piece of the puzzle often goes unnoticed in this transformation: IBM i ...

AI Now Interacts With Production Databases in 96.5% of Organizations as Governance Automation Lags

Ryan McCurdy
Liquibase

AI is already part of the production data path. It is not waiting on the sidelines.

In a 2026 survey conducted by Liquibase, the research found that 96.5% of organizations reported at least one AI or LLM interaction with their production databases, often through analytics and reporting, training pipelines, internal copilots, and AI generated SQL. Only a small fraction reported no interaction at all.

That means the database is no longer a downstream system that AI "might" reach later. AI is already there. The operating question is now control: as AI increases automation and the number of actors touching data, can organizations still standardize change and prove governance at the database layer? The research suggests most can't. Only 28.1% report database change governance that is standardized and consistently enforced, which means the unmanaged risk surface is growing fast.

Database Change Has Reached AI Speed

The research found database change is already operating at AI scale. 68.1% of organizations deploy database changes weekly or faster, and about 30% deploy daily or more. Delivery is no longer episodic. It is continuous.

This matters because governance models built for slower change break at high velocity. When change runs weekly, daily, or multiple times per day, checklists and ticket-driven processes turn into queues. Under pressure, gates get bypassed. Controls become inconsistent. Evidence becomes something teams reconstruct after an incident or audit.

AI does not create that behavior. It amplifies it.

The Real AI Failures Start at the Schema and Data Layer

When people talk about AI risk, the discussion often centers on models: hallucinations, prompt injection, and agent behavior. The research found a more fundamental failure mode: the schema and data layer.

When respondents were asked about AI related risks around database change, the top answers were rooted in data governance: 64.3% cited data quality issues as a top AI related risk, and 46.5% worried about ungoverned AI generated SQL. A significant share also flagged regulatory non compliance for AI workloads and schema drift disrupting pipelines.

These aren't model tuning problems. They are change control and data integrity problems. If schemas are inconsistent, drifted, or unverifiable, the outputs of AI systems become less trustworthy, less explainable, and harder to defend when something goes wrong.

Complexity Makes Consistency Harder

The research found modern database estates are heterogeneous by default. On average, organizations run five database or data platform types, and almost one third (29.1%) manage ten or more. Some operate more than fifteen.

Every additional platform is another environment where approvals can be inconsistent, drift can go undetected, and evidence can go missing. At ten or fifteen platforms, every missing standard doesn't stay contained. It multiplies. And when the organization is shipping database changes weekly or faster, that multiplication happens fast.

Pipeline scale compounds the same issue. A meaningful share of organizations now manage hundreds of CI/CD pipelines, and some manage thousands. At that scale, one missing approval standard isn't one gap. It's hundreds or thousands of gaps.

"Sometimes" Governance Is the Real Risk

One of the clearest signals in the data is a maturity mismatch.

On paper, governance can look mature. A majority of organizations say they have defined policies and approval workflows. But the research found only 28.1% have reached maturity levels where governance is standardized and consistently enforced, and only 7.7% report fully policy-as-code governance with real-time enforcement.

This is the difference between documented intent and system enforced reality. In an AI operating environment, "sometimes" is not a control. A control that runs sometimes is a preference.

Audit pressure compounds the challenge. The research found 95.3% of respondents undergo multiple compliance or database audits per year, and over one fifth face seven or more. Audit teams increasingly want answers that manual processes struggle to produce at speed: did the control run, what changed, and where is the evidence?

What to Do Next: Standardize, Enforce, Prove

The direction of travel is clear. Teams want enforcement, visibility, and evidence to become properties of the system, not heroic efforts by individuals.

At a minimum, three requirements show up as foundational for AI scale database change:

1. Standardize change definitions. Changes need to be represented in machine-readable, reviewable forms that can be promoted consistently across environments and platforms.

2. Enforce policy as code. Rules that used to live in documentation must run automatically before changes reach production, so governance doesn't depend on memory or manual queues.

3. Generate evidence by default. Every change should produce a structured record of what changed, who approved it, where it ran, and what the outcome was, so audits and incident reviews begin from data, not reconstruction.

The research suggests leaders need a scorecard to measure governance at AI scale and manage it as an operating discipline, not a periodic compliance exercise. It points to practical measures that make governance measurable at scale: Mean Time to Detect (MTTD), Mean Time to Recover (MTTR), and coverage metrics for automated controls, audit evidence, and AI-governed change.

The Takeaway

AI is already interacting with production databases. The question is whether the database layer can support AI scale change with credible control.

Organizations that standardize database change, enforce policy automatically, and produce audit-ready evidence as part of delivery will be positioned to let AI accelerate work on top of a foundation they can trust. Organizations that continue to rely on manual gates and "sometimes" controls will find that AI doesn't just increase speed. It increases material risk to AI investment outcomes, uptime, and reputation.

Ryan McCurdy is VP of Marketing at Liquibase

Hot Topics

The Latest

Pilots are everywhere, stakeholders are seeking results, businesses are pushing for new tools, and IT teams are being asked to make AI secure, reliable, and useful at scale. But as organizations move from testing AI to operationalizing it, many are discovering that the biggest barrier is not the model, the use case, or even the budget. It is the file data foundation within ...

Fast or cheap? For most of my career in engineering, speed and quality sat on opposite ends of a seesaw. The "OR" in "fast or cheap" was non-negotiable. It was expected that pushing for faster releases meant that something in quality would give way. Tightening quality controls meant the schedule slipped. Every engineering leader I know has lived some version of that tradeoff ... The seesaw is starting to level out ...

I have been building enterprise software for more than 20 years ... One thing stays true across all of it: You do not find out your foundation is wrong during the crisis. You find out when the debt comes due. For a lot of organizations, that bill is arriving now. New research ... puts hard numbers on something practitioners have been sensing for a while. The telemetry problem isn't coming. It's already here ...

The rapid growth of AI workloads is pushing traditional log management approaches to their limits, according to The State of Log Management 2026 report from Dynatrace. Modern logs have become critical to understanding, validating, and securing AI-driven decisions, helping organizations ensure reliability, compliance, and performance at scale. However, the volume and complexity of AI telemetry are overwhelming legacy tools ...

For years, secure connectivity has relied on a familiar pattern: route traffic back to centralized gateways, inspect it, and then allow access. This model worked when applications lived in a handful of data centers and users were largely confined to offices. That model is now under strain. Applications are distributed across clouds, users connect from everywhere, and real-time workloads demand performance that centralized inspection points struggle to deliver. As traffic volumes grow and latency expectations shrink, routing everything through a small number of control points has become both a performance bottleneck and a resilience risk. The future of secure connectivity requires a different approach ...

The AI experimentation phase is over, and the private cloud is where enterprise AI workloads are being deployed for security and scale, according to Private Cloud Outlook 2026, a new report from Broadcom ... 2026 marks an acceleration into a full AI tipping point. The shift is being shaped by three forces — costs, complexity, and control — that public cloud environments are increasingly failing to address for production AI at scale. Key findings from the report include ...

44% of organizations have reported an outage in the past year tied to suppressed or ignored alerts, and 78% had at least one incident where no alert was fired at all ... Engineers learned about failures from customers. That gap between what our tools report and what our customers experience is the problem DevOps teams have been quietly solving with GenAI tooling, even as most enterprises continue to run their NOCs on manual alert triage ...

Cloud outages are usually described as technical failures. When a service goes down, a dependency breaks, or a region has issues, the focus immediately shifts to infrastructure. But if you look closely at how these incidents actually unfold, the root cause is rarely the technology itself. It is almost always tied to decisions made earlier, during design, implementation, or day-to-day operations. The system behaves the way it was built. The real question is how it was built ...

77% of leaders say their teams need AI skills urgently. 64% say their organization plans to train current employees rather than hire new ones. So far, so reasonable. The part that surprised me is who's been put in charge: 34% of those leaders say IT and engineering own the AI skills mandate. Learning and Development or HR own it at 7% of organizations. That's roughly five-to-one in favor of the people who understand the tools, over the people whose actual job is teaching adults how to learn new ones ...

In the ever-evolving digital landscape, enterprises are increasingly focused on enhancing their observability stacks to gain deeper insights into their IT environments. Observability has become a cornerstone of modern IT operations, enabling organizations to monitor, diagnose, and optimize their systems with unprecedented precision. However, a critical piece of the puzzle often goes unnoticed in this transformation: IBM i ...