top of page

LATEST INSIGHTS

Expert insights across your SaaS environment

Blogs and papers from the SAASiQ team on enterprise SaaS, cloud and AI.

Oracle Sets Out Runtime Governance for AI Agents in OCI and Its Database

Writer: SAASiQ.ai
SAASiQ.ai
Apr 30
6 min read

Updated: 6 days ago

Title: Oracle Sets Out Runtime Governance for AI Agents in OCI and Its Database

Date: 30 April 2026

Type: Blog

Author: SAASiQ (contact@saasiq.ai)

Word count: 1549 words

Reading time: 6 min

Published: 30-04-2026


Oracle published a governance framework for AI agents on 23 April, arguing that the question to ask of an agent is whether its next action is allowed under current policy, identity, approvals and budget, rather than only whether a model's answer was safe. It sits alongside OCI Enterprise AI, the agent-building service Oracle announced on 24 March, and a set of controls built into Oracle AI Database. In the same week an Oracle research team took first place on the Spider 2.0 Lite text-to-SQL leaderboard, Oracle announced a preview of a natural-language database agent for Google's Gemini Enterprise, and Wedbush began covering the stock with an Outperform rating.


What OCI Enterprise AI includes

Oracle announced OCI Enterprise AI on 24 March as a single service with three layers: models and inference, agents and tools, and governance and security. The OCI release notes date general availability of the agent features to 31 March. The service is compatible with the OpenAI Responses API, so code written against OpenAI's SDKs needs little change, and it offers hosted deployment for agents, so customers do not run the servers themselves. It supports MCP for connecting tools and A2A for agent-to-agent calls, and it is available in nine regions, including London and Frankfurt.


The release notes list the models available through the agent API at launch: OpenAI's open-weight gpt-oss-20b and gpt-oss-120b, several versions of xAI's Grok 3 and Grok 4, and Google's Gemini 2.5 Pro, Flash and Flash-Lite. Work is organised into projects, which keep conversations, files, containers and memory separate, each with its own data retention settings. There is also an NL2SQL component that ingests a database schema and answers questions in plain English, with queries run under database permissions and no copy of the data made.


One of Oracle's own examples is a finance operations agent for accounts payable that reads invoices, validates the fields, obtains the human approvals it needs and updates the ERP system. An agent like that writes to the ledger, which is the kind of action the governance framework Oracle published a month later is meant to control.


The governance framework

The framework was set out on Oracle's AI blog on 23 April by Kishore Pusukuri, under the title 'From Model Safety to Runtime Governance'. Its starting point is that agents keep state, call APIs, update records and delegate work, so reviewing a model and filtering its output no longer covers the risk. Oracle calls the unit it wants to control the 'governed action trajectory': every proposed action, the identity and delegated authority behind it, the budget it consumes and the changes it makes to enterprise data.


The framework has four layers. The top layer holds the rules: risk tiers, approval workflows and promotion gates. The next decides which models, tools, connectors, data sources, regions and identities may be used at all. The third is an Agent Runtime Controller, which checks each proposed action against the active policy, the identity and approval bindings and the current budget before any tool runs, and returns one of four outcomes: ALLOW, ALLOW_WITH_REDACTION, REQUIRE_REVIEW or DENY. The bottom layer records traces, provenance, tool identities and decision records so that any material decision can be replayed later.


The threat model names unauthorised tool use, unsafe data egress, runaway loops that run up costs (which Oracle calls 'denial-of-wallet'), poisoned memory, leakage between sessions and agents acting beyond their delegated authority. The framework says OCI can supply telemetry, registry gating, policy enforcement hooks and evidence interfaces, while customers still set risk appetite, approve the policy packs, accept residual risk and run incident response.


The product documentation lists a narrower set of controls. Oracle's governance page for OCI Generative AI lists IAM policies, private endpoints, API keys, OAuth (the only authentication type supported for agentic tasks), Zero Trust Packet Routing and guardrails applied to inputs and outputs. The guardrails, available through the API for on-demand models since 9 February, cover content moderation, prompt injection and personal data. By default they report what they find and leave the application to decide whether to block it.


Controls inside the database

Oracle's second set of controls sits in Oracle AI Database 26ai, announced at its AI World Tour event in London on 24 March. Deep Data Security applies access rules for each end user inside the database, so an AI agent acting for a user sees only what that user is allowed to see, down to rows, columns and cells. Oracle presents it as a defence against prompt injection: if an agent is manipulated into asking for data its user should not have, the database's rules still apply to the query.


The same announcement included the Private AI Services Container, which runs private instances of AI models, including for embedding generation, in the public cloud, a private cloud or on-premises, air-gapped sites included. Trusted Answer Search takes a different route to accuracy: it matches a user's question to a report that someone has already built and tested, rather than asking a model to write an answer.


Private Agent Factory

Private Agent Factory is a no-code tool for building agents and agent workflows on Oracle AI Database. Oracle's FAQ, published on 29 April, describes it as a containerised application that runs wherever Oracle AI Database runs: on OCI, on Oracle Database@Azure, @Google Cloud and @AWS, and on-premises on Exadata Cloud@Customer, Exadata Database Machine, Oracle Database Appliance, Private Cloud Appliance or ordinary Linux x86-64 servers.


Whether data leaves the building depends on the model chosen. The FAQ lists OCI Generative AI, OpenAI, Gemini, Ollama and self-hosted vLLM endpoints as supported, and says the tool ships with a local embedding model. A customer that picks a local model can keep prompts and data inside its own network, and one that picks a cloud API sends them to that provider. It has three user roles (chat-only users, editors and administrators) and supports single sign-on through Oracle IDCS, Okta, Microsoft Azure AD and others.


There is no separate licence fee. Oracle says Private Agent Factory comes at no additional cost to Oracle AI Database customers, and that the costs that remain are database infrastructure, compute, storage, network, any GPUs and external model usage. Oracle's own documents differ on the pre-built agents: the 24 March press release lists a Database Knowledge Agent, a Structured Data Analysis Agent and a Deep Data Research Agent, while the 29 April FAQ says the March release shipped a Knowledge Agent and a Data Analysis Agent, with those three to follow in the coming weeks.


Plain-English queries

Oracle's OCI AI Science team said on 23 April that its SOMA-SQL method ranked first on the Spider 2.0 Lite leaderboard with 72.02 per cent execution accuracy. Spider 2.0 Lite has 547 questions across BigQuery, Snowflake and SQLite, with schemas that often run past 1,000 columns. SOMA-SQL generates several candidate queries for an ambiguous question, then runs small probing queries against the data to decide between them. Oracle says the work 'will be integrated into the Oracle NL2SQL product', so on 23 April it was research that had not yet reached the product.


At Google Cloud Next on 22 April, Oracle announced a preview of the Oracle AI Database Agent for Gemini Enterprise, sold through Google Cloud Marketplace. A user asks a question in Gemini Enterprise, the request passes to Oracle's agent, and Oracle AI Database translates it into SQL and runs it, with the user's identity carried through to the database so Deep Data Security can limit the rows returned. SiliconANGLE reported that access was limited at first, with broader availability expected in the summer, at no extra cost to Autonomous AI Database customers on Google Cloud.


Monthly security patches

On 29 April Oracle said it would add a monthly Critical Security Patch Update to its quarterly cycle, because frontier AI models are finding vulnerabilities faster than a quarterly release can fix them. Oracle said it uses Anthropic's Claude Mythos Preview and OpenAI's most capable models in its own vulnerability detection. In Oracle-managed services the fixes are applied automatically, and in customer-managed deployments the customer still tests and applies them. Oracle said the first monthly update would come in May.


What Wedbush said

Wedbush initiated coverage of Oracle on 24 April with an Outperform rating and a $225 price target. Investing.com's summary of the note puts the case on AI infrastructure. Wedbush pointed to remaining performance obligations (contracted revenue not yet recognised) of $553 billion, a plan to raise $45 to $50 billion for AI data centres, $30 billion of it already raised, and multicloud database revenue up 531 per cent.


The RPO and multicloud figures come from Oracle's third quarter, reported on 10 March. Revenue was $17.2 billion, up 22 per cent, with cloud infrastructure up 84 per cent to $4.9 billion and cloud applications up 13 per cent to $4.0 billion. Fusion Cloud ERP and NetSuite each brought in $1.1 billion.


What happens next

SAASiQ's view is that Fusion and E-Business Suite customers planning agents should read the 23 April framework against their existing segregation-of-duties rules, since it assumes each agent action is tied to a named identity and an approval that someone can later check.


The first monthly security patch is due in May, and broader availability of the Gemini Enterprise agent is expected in the summer, according to SiliconANGLE.

SAASiQ - Intelligent Solutions for SaaS ©

Optimise your SaaS licences and software subscriptions with SAASiQ

bottom of page