Your AI does 99% of the work.
Your signature carries 100% of the liability.
AI now reads the documents, drafts the reports, screens the records and reconciles the data — the cognitive work upstream of every decision. Your signature at the end is what supervisors treat as evidence of effective challenge. The question your regulator is about to ask: does that assumption still hold when the upstream work is AI work, on data you never governed?
Which level is your organization actually driving at?
Borrow the autonomy scale. It tells you exactly where liability sits — and where the market is quietly steering you.
The AI drives most of the way. A human keeps hands on the wheel and signs. If it goes wrong, the human is liable — even though the human read a fraction of what the AI did. The signature is the control. Nobody has proven the control actually works.
The AI operates autonomously across ungoverned data. The signature disappears as a meaningful control. If you cannot reconstruct what the agent read, under whose authority, and against which sources — you cannot supervise it. And you are being sold it now.
The work happens where you have no governance.
Iceberg tables, SQL, warehouses, dbt models. Governable today.
PDFs, contracts, Excel, email, Confluence, model docs. No schema. No owner. No contract.
Lakekeeper governs the data your AI reads — and makes its work auditable.
Access control across your structured and unstructured data — and a durably-recorded, append-only audit trail — are deployable today. The AI Contract object and per-run zero-trust credentials for agents are what we're building with design partners. We're honest about what ships now and what's still in development.
Access is decided at the catalog, deny-by-default — at table/view level for tables and at dataset level for files registered as generic datasets over object storage (v0.13). Structured and unstructured, one authority.
Each agent run gets a short-lived, scoped credential — no static keys, no standing access — bound to that run so access is inseparable from its audit record. Built on Lakekeeper’s per-request credential vending; the per-run binding lands with the AI Contract.
Every read and write is emitted as a durably-recorded, append-only event — tied to the identity that made it and the policy that was applied. The event is the artefact supervisors trust, not the agent.
A first-class catalog object declaring which agent, which model, which task, which sources and which outputs. The contract — not the table or file — becomes the unit of governance: the anchor that binds credentials to a run and adds agent identity, run ID, model version and prompt/output hashes to every audit event.
Lakekeeper does not just manage data.
It manages liability.
Bring whoever owns AI risk and whoever owns data governance — the conversation lands when both are in the room.