Published: September 17, 2026 • 11 min read

Why We Built AI Governance & Semantic Model Mastering: Notes from 6 Months of Customer Insights

Gianthomas Volpe

Gianthomas VolpeVice President, Product Management, Alation

You're in a meeting. Someone pulls up a dashboard and calls out a number on a topic you know cold and announces a major change. It doesn't sound right. Not slightly off. Completely wrong. So you ask where the number came from, and the answer is: "I pulled it from our database and asked ChatGPT." Not only did they get it wrong, but they've already shared it across the organization.

Anyone who has worked in data for the last decade is familiar with this scenario. The classic version was: “A Tableau dashboard I built told me.” But today’s scale is dizzying. Down the hall from the person asking ChatGPT to analyze a spreadsheet, someone else is using a Claude plugin that defines its own metrics, pick its own joins, and shares weekly insights. A third person is running Cortex based on the semantic model a data engineer developed for a completely different purpose.1 And the scariest part is that the more mature user aren’t just asking questions anymore — they're building agents that do the work based on the agent’s analysis of that data.2

Every scenario represents someone trying to move fast with AI. And every one is a place where you quietly lose the ability to trust the answer — or to see the risk piling up behind it.

The pattern behind the pattern

I've spent most of the last six to nine months talking with customers about this, and I keep hearing the same story in different accents. Nobody wants to slow people down. Cortex, Claude, ChatGPT, native BI — these are good tools, and the people using them are doing exactly what you'd want: getting to answers faster and trying to turn answers into action. 

The problem isn't the tools. It's that every surface invents its own version of the truth. Its own semantics. Its own read on what's governed and what isn't. Its own idea of how "active customer" gets calculated.

The default fix is reasonable: build a semantic model inside the consumption tool. A metric view here, a Snowflake semantic view there, a Power BI model over there.4 It works right up until the surfaces multiply again next quarter. And they will. Most of the teams I talk to have changed their mix of AI consumption tools at least once in the past year.3

So now you're relying on people to keep four or five semantic models fresh, consistent with each other, and in line with your governance policies. By hand. This is much more than another documentation project; it's also a maintenance burden and a risk surface, both growing exponentially.

The ending is predictable: metadata goes stale.5 Stale metadata directly fuels inaccurate AI outputs, feeding LLMs contextually wrong information that leads to bad answers. At scale, those inaccurate outputs trigger a quiet loss of faith in your entire AI enterprise strategy.6

That's the core pain. Everything we're announcing at revAlation this week is designed to cure it, not with a marketing slogan, but with things you can actually use. Here's how I think about what we shipped, organized by the problem it's built to address.

Problem one: The best knowledge is locked in the wrong shape

Ask any team where the real context lives — the stuff that explains why the numbers are what they are — and they'll point at documents: Compliance policies. Manufacturing manuals. Standard operating procedures. Slack threads and Confluence pages and PDFs in SharePoint.

Operationalizing this knowledge means turning these critical policies and metadata into structured context so enterprise AI agents can output accurate guidance. It presents two major challenges: First, it's scattered and siloed, with no unified governance or tracking. Second, and less obvious: There's an overabundance of context without guidance on what to prioritize. Handing all of it to an AI can actually lead to less accurate outputs.7

You pay more, wait longer, and get a blurrier answer, because the signal is diluted in everything that's adjacent to it. What you actually want is the right slice of metadata, scoped to the relevant process, fresh, and governed — not the whole haystack.

Governed Collections solves the silo problem, bringing documents from SharePoint, S3, Confluence, and Google Drive into the catalog as governed objects, with the same metadata, lifecycle tracking, and versioning we apply to a table. Agents consume a Collection by reference, so when the source document changes, the agent reads the current version. No re-upload, no drift between what's in the doc and what the agent thinks is in the doc. (Beta at revAlation.)

Alation Governed collections screenshot
Governed Collections: Documents from S3, SharePoint, and Drive catalogued like tables, with descriptions, lineage, and versions included.

Ontologies deliver the "right slice" of relevant metadata. An Ontology is a scoped, continuously updated map of how data, metrics, and policies connect within a specific business process, extracted by agents from the documents that already describe how the business works, reviewed by the people who know it, and grounded in the catalog's governed context. It gives an agent explicit rules to execute against, relationships to traverse, and constraints to meet rather than having the agent try to infer how to follow a process correctly. It’s built on W3C standards and exportable as an MCP server, so it works with whatever agent runtime you're using. (Beta at revAlation.)

Alation ontologies product screenshot
Ontologies: See how different parts of your business actually connect, with explicit rules for an agent to follow instead of infer.

Problem two: AI is everywhere, and no two tools agree

Recall the fragmentation problem from the beginning of this post: An extract into ChatGPT, a Claude plugin against a live database, Snowflake Cortex, native BI. Each tool works fine on its own. Together, they create five parallel, conflicting definitions of every metric your company relies on, with no thread connecting them.8

Semantic Model Mastering solves this sprawl, and it's now generally available for both Snowflake and Databricks. 

The concept is simple: one place to catalog, enrich, and govern semantic models, treating the data product as the ultimate authority. "Active customer" resolves to one definition. Change it once, and it changes everywhere. Semantic models are promoted to governed data products with real ownership, approval workflows, versioning, evals, and quality contracts — instead of living as loose files in whichever tool built them last. These data products are dynamically maintained: the system automatically proposes new versions based on changes in the source systems, quality failures, new use cases. Once approved, those updates are synced back to your other consumption surfaces. 

Semantic model mastering Alation
Semantic Model Mastering: Deliver one governed definition, synced to Snowflake and back, with a full change history.

The AI compliance blind spot: Governing the use, not the model

Every rung on that consumption ladder isn't just a surface; it's an AI use case. People across your company are using AI to make or influence decisions, and it's happening on tools you may not have inventoried, against data you may not have certified, with a regulatory posture nobody's verified.

That risk doesn't announce itself. It piles up quietly and invisibly. A person who gets a bad extract might notice. An agent that gets a bad extract just acts on it.9

Most tools try to govern the model in isolation by generating static model cards. But regulators, auditors, and boards ask how that model is being used and whether the underlying data can be trusted. When an audit hits or compliance with the EU AI Act is called into question, spending weeks rebuilding evidence packs from spreadsheets and Slack threads is a dangerous posture.10

AI Governance solves this by governing the use, anchoring every model and agent directly to the catalog’s live data foundation, which includes lineage, policies, quality, and ownership.

At revAlation, we are extending this framework to give you complete visibility and audit readiness across your AI estate:

  • Cross-platform AI registry: Register and inventory every model and agent across Databricks, AWS, Azure, Google Cloud, and custom runtimes, linking each asset directly to its business use case and data dependencies.

  • Automated regulatory mapping: Automatically map use cases against major frameworks (including the EU AI Act, NIST AI RMF, ISO 42001, and GDPR), decomposing regulations into risk-tiered, evidence-gated approval workflows.

  • Agent lineage & real-time auditing: Trace an agent's compliance risk directly down to the live quality and policy status of the data it consumes.

Instead of scrambling the week of an audit, you gain continuous, live visibility into your compliance posture, allowing you to prove compliance on demand, not on a deadline. (Available to Alation customers today; expanding at revAlation)

AI governance Alation
AI Governance: See every model and agent across platforms, with owner, governance status, and risk visible before an auditor asks.

Problem three: It rots, and nobody's coming to save it

We all agree context matters. We all agree curation matters. And then someone asks the awkward question: who's actually going to keep this stuff up to date.

For most organizations, the honest answer is nobody. Manual documentation projects simply can't keep pace with changing systems (let alone stay in sync across five).11 

This is where governance and accuracy collide: stale context isn't just a hygiene issue, as it directly fuels inaccurate and inconsistent AI outputs. The moment something goes stale on one surface, conflicting definitions resurface elsewhere. Context freshness is metric consistency.

The only way forward is context that maintains and propagates itself automatically. That principle drives every capability covered here: Governed Collections that read live documents, Ontologies that update continuously, Semantic Model Mastering that syncs to source. 

And it's why we built Intelligent Feeds.

Instead of treating data intelligence as a destination people have to remember to visit, it becomes something that finds them. Insights, analysis, data visualization are delivered as governed signals to the people who need to act on them, where they already work. Every figure traces back to a governed data product, and anyone can ask a follow-up in plain language instead of filing a ticket. (Beta at revAlation.)

Alation intelligent Feeds
Intelligent Feeds: Ensure governed analysis is delivered where people already work, with every figure traced back to a data product.

Back to that meeting

None of this is about slowing people down. They should keep using ChatGPT, or Claude, or Cortex, or whatever's fastest for the question in front of them. 

The goal is ensuring that when they do:

  • Metrics align: The definition pulled in a quick query matches the one presented in the board deck.

  • Context is current: The policies and metadata their AI agents read are always fresh and governed.

  • Risk is visible: Exposure across your AI estate is identified before an auditor or board member asks about it.

You shouldn't have to choose between moving fast and being right. That's what we've been building toward with our customers, and it's what we're shipping this week. To see how Alation can help your company, reach out to us to start a conversation today.

There's more we announced at revAlation — including Console, a rethink of how you work inside Alation itself. That one deserves its own post. Coming soon.


Sources & notes

Every external claim in this post is independently verifiable. The public sources are listed here.

1. Cortex Analyst uses Snowflake semantic views to interpret data and generate SQL.
— Snowflake, "Cortex Analyst," product documentation, accessed 15 September 2026 ↗
https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-analyst

2. Security and risk concerns are now the leading obstacle to reaching fully scaled agentic
AI, named by 62% of organizations — ahead of technical limitations and regulatory
uncertainty, both at 38% (Figure 3.3.10).
— Stanford HAI, 2026 AI Index Report, Chapter 3: Responsible AI, April 2026 ↗
https://hai.stanford.edu/assets/files/ai_index_report_2026_chapter_3_responsible_ai.pdf

3. The author's observation from customer conversations over this period, not a survey
finding. For context on the underlying readiness gap, Gartner found that 63% of
organizations either do not have, or are unsure whether they have, the right data
management practices for AI (survey of 1,203 data management leaders, July 2024).
— Gartner, "Lack of AI-Ready Data Puts AI Projects at Risk," Q&A with Roxane Edjlali,
26 February 2025 ↗
https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk

4. Each major platform maintains its own semantic layer as a distinct product object:
Databricks Unity Catalog metric views, Snowflake semantic views, and Power BI semantic
models. Microsoft's own documentation notes that vendors "use different names for their
semantic model offerings… They target the same use case, but they offer differing levels
of maturity." Vendor documentation, accessed 15 September 2026 ↗
https://docs.databricks.com/aws/en/uc-semantics/metric-views/ ↗
https://docs.snowflake.com/en/user-guide/views-semantic/overview ↗
https://learn.microsoft.com/en-us/power-bi/connect-data/semantic-models-third-party

5. Gartner's guidance states that AI-ready data is "not one and done," that metadata must
evolve from passive to active, and that traditional data management operations are "too
slow, too structured, and too rigid for AI teams."
— Gartner, 26 February 2025 ↗
https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk

6. The share of organizations naming inaccuracy as a relevant AI risk rose from 60% in 2024
to 74% in 2025 — the largest single-year increase of any risk tracked (Figure 3.3.5).
— Stanford HAI, 2026 AI Index Report, Chapter 3, April 2026 ↗
https://hai.stanford.edu/assets/files/ai_index_report_2026_chapter_3_responsible_ai.pdf

7. Language model performance degrades significantly when relevant information must be
retrieved from the middle of a long input context, even in models built specifically for
long contexts. Applies to output accuracy; the cost and latency effects of larger context
windows are separate.
— Nelson F. Liu, Kevin Lin, John Hewitt, Ashwin Paranjape, Michele Bevilacqua, Fabio
Petroni and Percy Liang, "Lost in the Middle: How Language Models Use Long Contexts,"
Transactions of the Association for Computational Linguistics, Vol. 12, pp. 157–173,
February 2024. doi:10.1162/tacl_a_00638 ↗ https://aclanthology.org/2024.tacl-1.9/

8. Semantic layers from different vendors are not designed to reconcile with one another.
Microsoft's documentation states that layering a third-party semantic model with a Power
BI semantic model "is generally not supported," that third-party vendors "typically don't
support layering on top of Power BI semantic models" either, and that combining inferred
relationships across two semantic layers "can yield incorrect values even for simple
measures."
— Microsoft, "Semantic models and third-party compatibility," Power BI documentation,
last updated 6 July 2026, accessed 15 September 2026 ↗
https://learn.microsoft.com/en-us/power-bi/connect-data/semantic-models-third-party

9. Documented AI incidents reached 362 in 2025, up from 233 in 2024 (AI Incident Database).
Among organizations reporting incidents, the share experiencing three to five of them rose
from 30% to 50% in a year, while the share rating their incident response as "excellent"
fell from 28% to 18% (Figures 3.3.3, 3.3.4).
— Stanford HAI, 2026 AI Index Report, Chapter 3, April 2026 ↗
https://hai.stanford.edu/assets/files/ai_index_report_2026_chapter_3_responsible_ai.pdf

10. Timeline note. Following the Digital Omnibus on AI, the EU AI Act's high-risk obligations
under Chapter III, Sections 1–3 now apply from 2 December 2027 for systems classified
high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those under
Article 6(1) and Annex I (recital 40). The Article 50 transparency obligations took effect
on 2 August 2026 as originally scheduled.
— Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026,
published in the Official Journal 24 July 2026, in force 27 July 2026 ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202601744

11. Traditional data management operations are "too slow, too structured, and too rigid for AI
teams"; uses of data are often poorly documented and data is siloed across repositories,
systems and platforms.
— Gartner, 26 February 2025 ↗
https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk

  • AI
  • Alation News
  • Data Catalog
  • Data Governance
  • Data Products
  • Data Quality
  • Digital Transformation
  • Engineering
  • Modern Data Stack
  • Self-Service Business Intelligence
Gianthomas Volpe

Gianthomas Volpe

Vice President, Product Management, Alation

in

GT Volpe is VP of Product at Alation, where he leads the product management team behind the Alation Intelligence Operating System (AIOS), spanning the full platform from catalog and lineage to data products and Agent Studio.

GT joined Alation as an early employee after several years in the business intelligence world, where he saw first-hand how hard it is to balance self-service access, shared semantics, and governance. He started as a sales engineer, helping customers evaluate and adopt the platform, and after moving from the US to the UK led Alation's go-to-market in EMEA before stepping into R&D in a product leadership role.

He is a Princeton graduate, lives in London, and grows bonsai trees, most of which are still alive.

Keep reading

More from the data desk

  • Making Agents Work: Why "Fix the Data First" Is the Wrong Place to Start

    Most teams treat clean data as the prerequisite before agents ship. A Stanford researcher and two CEOs on why that…

  • NIST risk management framework

    OSFI E-21 Compliance After the Deadline: What Supervisors Assess Now

    AI

  • Centralized or Federated? Data Architecture for Agentic AI

    AI

  • Hero image from Alation's metadata management page showing abstract of data to showcase active data management

    Why We Built AI Governance & Semantic Model Mastering: Notes from 6 Months of Customer Insights

    AI

    Your last audit passed on evidence someone reconstructed by hand. Why that model collapses once AI agents are reading…

Let us help you get it right.