惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
U
Unit 42
罗磊的独立博客
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
aimingoo的专栏
aimingoo的专栏
Vercel News
Vercel News
N
Netflix TechBlog - Medium
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
小众软件
小众软件
博客园 - 【当耐特】
H
Help Net Security
The GitHub Blog
The GitHub Blog

Databricks

Using AI_Functions in Your Data Warehouse: Top Use Cases How Scottish Water Made Its Capital Investment Data Conversational With Databricks Genie What are AI Hallucinations? Smart Routing in Unity AI Gateway: Match frontier quality with 30%+ lower cost per task Databricks Network Configuration delivery to Tens of Millions of Serverless VMs How Amtrak is building the data backbone for its largest transformation in over 50 years How a major freight railroad scaled pipeline creation with Genie Code The Future of Data Analytics: Why AI is rewriting the Analyst’s Job Description Taking AUTO CDC to the next level: Solving the hardest real-world use cases Open-sourcing Metals v2: Databricks’ Java and Scala language server for multi‑million line codebases Modern Risk Demands a Real-Time Foundation: The CRO’s Mandate Electric joins Databricks to bring WASM Postgres to AI agent sandboxes How to ground Genie Agents in both structured data and documents without losing governance Innocent until combined: Blocking the lethal trifecta with Omnigent Contextual Policies Introducing FILE type: a native column type for multimodal data Managing AI Coding Costs at Scale What is an AI Assistant? What are Agentic Workflows? What is Tool Calling? Kimi K3 from Moonshot AI is now available on Databricks through Unity AI Gateway Introducing OfficeQA Pro V2: A New Benchmark for Enterprise Grounded-Reasoning BigQuery to Databricks: A Strategic Framework for Modern Migration Unity AI Gateway is Generally Available Granular Usage Attribution for dbt Pipelines with Query Tags - Cloned The New Monday Morning Report: How Generative AI can deliver the insights your executives need. Ingest semi-structured data faster and more efficiently with Variant - Now Generally Available Databricks Completes Acquisition of Panther: Accelerating the Security Lakehouse Era Backstage with Lakebase, part 3 Foundations for an AI-forward healthcare organization Agentic media buying cannot scale without the right foundation. See how buyers and sellers get there on Databricks.
Databricks joins the Open Secure AI Alliance to advance A...
Katie Cummiskey, Maria Pere-Perez, Arun Pamulapati, Nishith Sinh · 2026-08-04 · via Databricks

Databricks is a sponsor at Black Hat USA 2026 this week. Find us at Booths #5106 / #2167, and read how our acquisition of Panther accelerates the Security Lakehouse era.

The case for open AI safety and security

As AI systems grow more capable and autonomous, two challenges are converging: securing AI systems themselves against new classes of attack, and using AI to strengthen cyber defense. Both require openness because critical security intelligence locked inside a small number of closed systems leaves the broader ecosystem exposed. Databricks supports both mission sides: open frameworks for securing AI systems, and open data via Lakewatch, the Open Security Lakehouse powering agentic threat detection and response at scale.

That's why Databricks is proud to be a founding member of the Open Secure AI Alliance, alongside NVIDIA and other industry leaders. The alliance is built on a simple but powerful premise: AI safety and security research should be shared openly, and the tools it produces should be built on open systems. That work spans AI safety, AI security, and AI-enabled cyber defense, strengthening enterprises, software, and critical systems worldwide. Members are contributing into the open: open models, model weights, open harnesses, open tooling, and the learnings behind them, to accelerate the development of new cybersecurity tools and techniques.

Why openness matters: beyond models

An AI agent isn't just a model. It's a complex system built from models, harnesses, and guardrails that govern what the agent is allowed to do. While much attention has focused on securing open-weight models within enterprise boundaries, model weights are only one layer. Security in the agentic era requires an open execution stack: from the runtime and guardrails underneath, to the harness that orchestrates agents and their tools, to the frameworks that define risks and controls, to the governance layer that ensures enterprise security, auditability and accountability.

Open systems allow the broadest community of defenders to study, test, and strengthen every component of this stack. The result is trust built on assurances, visibility, evidence, participation, and choice.

What Databricks brings to the alliance

The alliance spans more than 75 organizations across chips, models, security, and infrastructure. NVIDIA contributes accelerated computing and open AI infrastructure. Databricks brings governed data, model and agent capabilities, and open tools and frameworks for security, governance, red teaming, and cyber defense.

  • Omnigent composes and controls how agents use models and tools.
  • Databricks AI Security Framework (DASF) maps AI risks to practical safeguards.
  • Databricks AI Governance Framework (DAGF) defines accountability and governance.
  • BlackIce tests AI systems against real-world attacks.
  • Lakewatch powers agentic detections and hunting across unified data.

Together with contributions from across the alliance, this work helps strengthen the full agent stack.

Omnigent: an open agent meta-harness

The Open Secure AI Alliance advocates for open models, harnesses, and guardrails so defenders can inspect, audit, and govern agent behavior across the full AI stack. Omnigent (Apache 2.0) is Databricks' answer to this call, an open-source meta-harness. Omnigent gives developers choice of harness and model, allowing composition and secure sharing, while enforcing policies, spend caps, and sandbox isolation across 13+ harnesses, both open and closed.

Omnigent's contextual policies enable agent behavior governance by tracking session state, blocking slow-burn attacks, and enforcing intent-based authorization. These are exactly the kinds of open, inspectable controls the alliance envisions.

Omnigent is designed to support NVIDIA OpenShell as a governance backend, pairing policy controls with kernel-level isolation for layered, auditable protection from agent authorization through host execution.

DASF 3.0: an actionable AI security framework mapping risks to controls

The DASF 3.0 catalogs 97 technical security risks across 13 components and maps them to 73 mitigation controls, all cross-referenced to MITRE ATLAS, OWASP, NIST, AIUC-1, HITRUST, ISO and CSA. Released under CC BY-SA 4.0, version 3.0 introduces dedicated coverage for Agentic AI threats (including memory poisoning, goal manipulation, and insecure MCP connections), providing defenders with an open, vendor-agnostic blueprint to move from risk identification to mitigation.

Because DASF connects risk taxonomy to enforceable, vendor-agnostic controls, it gives defenders a concrete path from "named risk" to "deployed mitigation." It offers a common taxonomy for agentic threats and mitigations available to any organization in the community.

DAGF: enterprise governance for AI systems

The DAGF defines who is accountable and how the enterprise manages it. This framework outlines five pillars for building a responsible and resilient AI program, offering practical insights for decision-making and execution. It addresses core areas, such as AI governance, ethical compliance, risk management, and operational oversight. This helps manage AI programs transparently, securely, and effectively while fostering collaboration across people, processes and technology. In the context of the alliance, DAGF helps enterprises govern how NVIDIA's accelerated computing and AI infrastructure is selected, deployed, and managed, and ensures that open technology is adopted responsibly at scale. Released under the Creative Commons Attribution-ShareAlike 4.0 International License, DAGF is vendor-agnostic and already aligned to the standards the community uses.

BlackIce: open-source AI red teaming

BlackIce is Databricks' open-source, containerized red-teaming toolkit. It bundles 14 widely used AI security tools into a single reproducible environment, mapped to MITRE ATLAS and DASF, so a security team can test a system against prompt injection, data leakage, and supply-chain attacks without wiring up each tool by hand.

This lowers the bar for AI red teaming. Standing up 14 tools individually takes time and deep expertise, which puts serious adversarial testing out of reach for most teams. With over 6,000 downloads to date, it is already in the hands of teams that could not have assembled these tools on their own.

Building on the Security Lakehouse

On the AI-enabled cyber defense side of the alliance's mission, our commitment to openness extends beyond frameworks. Databricks pioneered the Security Lakehouse, an open, governed architecture that unifies security, IT, and business data so defenders can run detection, investigation, and response at petabyte scale.

With Lakewatch, Databricks’ Open Security Lakehouse, security teams can deploy AI agents that actively triage alerts, conduct threat hunts, and refine detection logic, all on top of open data formats that prevent vendor lock-in. This is the same philosophy that drives the Open Secure AI Alliance: defenders should own their data, their tools, and their intelligence.

The governance foundation for that architecture is Unity Catalog, which Databricks open-sourced under Apache 2.0 and donated to the Linux Foundation. The catalog is the layer that decides which agent can reach which data, model, or tool, and enforces it. Leaving that layer proprietary while everything above it is open would put the most security-critical control point beyond inspection. With an open catalog, meaning open APIs, open table formats, and an open implementation, defenders can audit and extend the enforcement point itself, and security data stays portable across engines rather than locked to one vendor's control plane.

Databricks' open-source heritage

Our commitment to open security builds on a deep open-source heritage that goes back to our founding. Apache Spark, Delta Lake, and MLflow were all built on the principle that foundational technology should be open, inspectable, and community-driven, and we extended that principle to the governance layer when we open-sourced Unity Catalog. Apache Spark alone has now passed two billion downloads. The Open Secure AI Alliance extends that same philosophy to AI safety and security.

What's next

The Open Secure AI Alliance is a movement to develop and share relevant AI safety and security research transparently. Over time, the alliance will produce a growing body of practical, open capabilities that organizations can inspect, adopt, and build on.

We're excited to stand alongside NVIDIA and the broader alliance in this mission and to continue making open code, open frameworks, and open research available to the community as we secure the agentic era together.

Learn more about Lakewatch, the Open Security Lakehouse and how Databricks is redefining security operations for the agentic era.

Get started with Omnigent to run the open agent meta-harness, its contextual policies, and sandbox isolation in your own environment.

Explore the Databricks AI Security Framework (DASF) 3.0 to understand the risks and controls for securing your AI systems.

Download the Databricks AI Governance Framework (DAGF) to learn about accountability and oversight across your AI program.

Check out our BlackIce GitHub Repo to learn more about the integrated tools, find examples for running them with Databricks-hosted models, and access all Docker build artifacts.