Leadership1 distinct publisher3 min readUpdated
A UniCredit data executive argues agents are capped by the data foundations they reason over, the same bottleneck banks were forced to pay for after 2008. The budget implication is unglamorous.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Barney Krishnan, a data executive at UniCredit, argues in a Forbes Tech Council post that beneath the agent interface sits a plain constraint: AI agents are only as reliable as the data foundations they reason over [1][18][2]. He frames it as deja vu, because after the 2008 financial crisis global banks were pushed into the same structural problem by BCBS 239 for risk data aggregation and CCAR for capital stress testing, mandates that established you cannot calculate capital adequacy or report systemic risk on fragmented, untraceable pipelines [3][4].
That analogy is the useful part of the piece, and it lands on the budget rather than the architecture diagram. Krishnan's account of the history is that governance began in the early 1990s as administrative control and schema management, was pushed into the executive spotlight by the mid- to late 2000s, and then consumed large amounts of capital mapping technical metadata, business glossaries, taxonomies, ontologies and lineage [5][6]. The result he reports is the awkward one: despite decades of effort and millions in capital expenditure, true end-to-end lineage across a mosaic of custom builds and commercial off-the-shelf products stayed out of reach, working well only inside a single vendor's ecosystem [7].
Read that against the agent pitch. The capability claim is that advanced agents can scan legacy solutions, analyse code footprints, parse partially written requirements and profile underlying data to reconstruct enterprise logic [15]. The reconstruction is drawn from the same fragmented sources that defeated lineage projects, so the ceiling on agent output is set where the last programme stopped. Krishnan's own framing concedes the point: the objective is identical to the compliance era and only the consumer has changed, from regulators to what he calls deterministic AI [8].
What he proposes is two pillars. The schematic layer covers tables, columns, data types and API definitions, increasingly standardised through the Model Context Protocol so agents can discover schemas, understand tool exposures and connect to diverse sources [9][10]. The semantic layer interprets business context, profiles legacy code and watches data in motion, and he insists it cannot be a static catalogue [11]. His mechanism for keeping it live, which he calls Interaction Certification, is a continuous loop that monitors, verifies and logs every discrete interaction between an agent and a dataset [12]. The security half is the same shift: broad role-based access control, where a human analyst with read access could query any table in a database, does not survive contact with autonomous agents, and unmonitored breadth invites security exposure [13][14].
Strip the coinages and this is a metering, logging and access-mediation build with a permanent operating cost, and the column supplies no figures for it beyond the historical "millions" [17]. It is one practitioner's argument, not measured evidence.
Watch three things. Whether firms can produce lineage across COTS boundaries where earlier, better-funded attempts failed [7]. Whether MCP tool exposures get inventoried and revoked with the discipline of a permissions regime rather than a discovery convenience [10]. And whether any agent programme discloses the split between model and inference spend and spend on metadata, lineage and runtime authorisation, because that ratio is the honest cost of the programme.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Barney Krishnan is a Data Executive at UniCredit with expertise in financial services, digital banking, AI and data modernization platforms.
The article was published on forbes.com as a Forbes Tech Council contributor post headlined 'The Data Governance Deja Vu: Why Agentic AI Is Forcing Us To Rebuild The Data Foundations'.
In the wake of the 2008 financial crisis, global banking institutions were forced to confront this structural bottleneck through mandates such as BCBS 239 for risk data aggregation and CCAR for capital stress testing.
Those frameworks established a hard, expensive truth: you cannot calculate capital adequacy or report systemic risk on fragmented, untraceable pipelines.
Data governance emerged in the early 1990s from a basic need for administrative control and schema management, and by the mid- to late 2000s, accelerated by the global financial crisis, was thrust into the executive spotlight.
Regulations forced enterprises to spend massive amounts of capital and resources mapping out technical metadata, business glossaries, taxonomies, ontologies and data lineage.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One practitioner column, no data
Everything in the cluster comes from a single Forbes Tech Council contributor post by one bank data executive. The verifiable content is historical and definitional (BCBS 239/CCAR, the 1990s-2000s governance arc, RBAC's breadth); the forward-looking core - the two-pillar foundation, Interaction Certification and runtime micro-governance - is asserted with no implementation, benchmark, incident data or second source.
No adoption signal supplied
The cluster contains no release, deployment, benchmark, pricing or usage disclosure. MCP is described as 'increasingly standardized' and LLM adoption as growing, but no named implementation, customer, deployment or figure is given - including nothing about UniCredit's own estate - so adoption cannot be measured without inventing facts.
Prescription ahead of proof
The framing is deliberately anti-hype - spend on plumbing, not models - which pulls the gap toward zero. It still lands positive because named constructs (Agentic Data Foundation, Interaction Certification, runtime micro-governance) and superlatives ('the only technology fast enough and smart enough', cataloging legacy structures 'in seconds') are presented as settled requirements with zero measurement, cost or pilot behind them, and because the column's own history section concedes that decades of similar spend never delivered end-to-end lineage.
Practitioner thought leadership favoring governance spend
The author is a serving data executive at a large bank writing in a paid-membership contributor channel, and the argument's conclusion - that data governance, metadata and runtime control are the prerequisite for AI - directly elevates the strategic and budgetary standing of the function he leads. No vendor is promoted and no product is sold, and the historical regulatory material is neutral, which keeps this short of a pure marketing incentive.
Low - single voice, unverified prescriptions
Confidence is limited by one publisher, one author, no adoption evidence and no quantification. What can be stated with reasonable confidence is narrow: the article exists as described, its author's affiliation, the post-2008 mandate precedent, and the fact that its architectural and security prescriptions are untested within the supplied material.
leadership
Human-in-the-loop is being retired, and the assurance burden shifts to machine identity1 distinct publisher
build
Rate limit your MCP servers, because a retrying agent turns one error into a billing incident1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
build
The only way to prove a contract test can fail is to ship a server that lies1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026