Collibra has spent eighteen years, by its own count, mapping where enterprise data lives and who owns it. On Monday it bought a startup whose best feature is saying no. Collibra announced the acquisition of trail ML, a Munich AI governance company founded in 2023 by Anna Spitznagel, Nikolaus Pinger and Sven Hölzel (per Collibra). Price: Undisclosed. trail ML revenue and customer count: Undisclosed.
The release has two halves. Only one of them is new.
Half one: compliance automation. trail ML’s agents read the context around an AI system, work out which frameworks apply (EU AI Act, ISO 42001, NIST AI RMF), check whether controls exist and work, and re-run the assessment when the evidence changes. Useful. It turns a once-a-year spreadsheet into a living assessment. It’s also what every GRC platform is building, so on its own it would be a feature.
Half two: runtime enforcement. Collibra says trail ML enforces Collibra policies “directly where agents run” and blocks actions that violate them before they happen. Its own framing: “AI incidents increasingly start with agents taking actions, not models giving answers.” That’s the half a security team should care about. A policy that can’t block is documentation. A policy that can block is a control.
Our POV. AI governance is splitting into people who write policy and people who sit in the path. The money goes to the second group. Collibra is a data catalog with more than 700 customers, including 78 of the Fortune 500 (per Collibra). It owns the context: which data is sensitive, who owns it, which model touched it. What it didn’t own was an enforcement point. Buying trail ML is a bet that context plus a runtime hook beats a runtime hook with no context.
Reasonable bet. Crowded seat. Everyone is claiming the same chokepoint from a different layer:
Identity. Omada bought EmpowerID last month to put runtime authorization for AI agents inside IGA (per BankInfoSecurity).
Network. doxx.net raised a $38M Series A led by Andreessen Horowitz on Monday for private networking with DNS-layer threat blocking for people and their agents, plus a network API with native MCP support (per Help Net Security). Valuation: Undisclosed. It’s consumer-first today, so the enterprise case is early.
Gateways. The AI gateway vendors we covered in September want the same title.
Data and governance. Now Collibra, which literally calls itself “the enterprise AI control plane.”
What this means in your stack. When an agent calls a tool, there are only a few places to stop it: the identity that authorizes the call, the gateway or MCP server that brokers it, the network egress, or the data layer that serves the result. Each vendor above sits at one. The useful question isn’t “which control plane.” It’s “where does the block actually execute, and what can it see from there?” A data-layer veto knows the record is regulated but may never see the tool call. A gateway sees the tool call but may not know the record is regulated. A DNS block sees neither. It sees a destination.
Before you take the demo, map one production agent end to end. List every tool it can call, the identity it calls with, and the data each call returns. Then ask the vendor to show the block on your path, not theirs. Ask where the enforcement code runs (in-process SDK, sidecar, proxy) and what happens when it’s down: fail open or fail closed. If the answer is “the agent framework calls our API to check,” you’ve bought a policy check the agent can skip. Log every block with the agent identity and the tool name, or your SOC can’t tell a misbehaving agent from a misconfigured policy.
Who should worry. Speculation, labeled: standalone AI governance startups that sell assessments only just watched a data-catalog incumbent buy the runtime half. Their pitch now needs enforcement or a buyer. GRC suites will feel pressure to add blocking. AI security startups that only enforce will hear “you don’t have the context” from Collibra reps.
For analysts. No price, no trail ML revenue, no structure. Don’t model it. Model the pattern: incumbents with distribution are buying enforcement instead of building it. EU AI Act enforcement powers arrived August 2 (per The Next Web), which gives compliance buyers a reason to spend now. Whether that budget sits with the CISO or the chief data officer decides who wins this. Right now it’s both. That never stays stable for long.
