What’s new in Databricks Platform security and compliance at Data + AI Summit 2026
Summary
Databricks announced significant security and compliance enhancements for its platform at Data + AI Summit 2026, addressing challenges in scaling data and AI innovation securely. Key updates include the General Availability of Automatic Identity Management (AIM) for Microsoft Entra ID on AWS and GCP, with AIM for Okta in Public Preview, simplifying user and service principal provisioning for Genie and AI applications. Context-Based Ingress, now in Public Preview across AWS, Azure, and Google Cloud, enables granular, zero-trust access policies for specific Databricks experiences like Genie and dashboards. For serverless and operational workloads, Databricks introduced Private Network Gateway in Private Preview on Azure, offering a single, secure connection to private networks, alongside expanded Private Link support for Lakebase. Additionally, compliance coverage has broadened with new serverless certifications, KSA, ISMAP, and HITRUST availability across clouds, expanded AWS GovCloud support for AI features, and upcoming FedRAMP High support on Azure Commercial.
Key takeaway
For AI Architects and IT Professionals scaling Databricks environments, these updates simplify securing AI innovation and maintaining compliance. You should evaluate Automatic Identity Management for streamlined user provisioning and implement Context-Based Ingress to apply granular, zero-trust access policies for AI applications. Consider Private Network Gateway for secure, simplified connectivity of serverless workloads to private data sources, ensuring your deployments meet evolving regulatory standards like HITRUST and FedRAMP High.
Key insights
Databricks enhances platform security and compliance to enable scalable, context-aware AI innovation across diverse cloud environments.
Principles
- Automate identity management for AI scale.
- Implement zero-trust access based on context.
- Consolidate private network connections.
Method
Databricks' approach involves automating identity provisioning, applying context-dependent access controls, and simplifying private network integration for serverless and operational workloads, alongside expanding global compliance certifications.
In practice
- Utilize AIM for Entra ID on AWS/GCP for user onboarding.
- Configure Context-Based Ingress for granular AI access.
- Explore Private Network Gateway for serverless private connectivity.
Topics
- Databricks Platform
- AI Security
- Identity Management
- Network Security
- Cloud Compliance
- Serverless Analytics
- Zero Trust
Best for: CTO, VP of Engineering/Data, Director of AI/ML, AI Security Engineer, AI Architect, IT Professional
Related on AIssential
Editorial summary, takeaway, and curation by AIssential. Original article published by Databricks.