# Databricks Unity Catalog Automates Data Security _Databricks Unity Catalog achieves general availability for ABAC policies, governed tags, and data classification, automating sensitive data protection._ **Updated:** 2026-08-22 **Published:** 2026-05-13 **Source:** https://www.startuphub.ai/ai-news/technology/2026/databricks-unity-catalog-automates-data-security --- Databricks is pushing its Unity Catalog further into automated data governance with the general availability of Attribute-Based Access Control (ABAC) policies for row filtering and column masking. This move, alongside the GA of governed tags and automated data classification, aims to streamline how organizations protect sensitive data. Manual Data Governance IssuesDriver repetitive, prone to inconsistencies, security gaps in data estatesFrom the article 3 mentionsManual data governance and access controls have long struggled to keep pace with growing data estates.solvesDatabricks Unity CatalogCoreunified framework for automated data governance and protectionFrom the article 2 mentionsDatabricks is pushing its Unity Catalog further into automated data governance with the general availability of Attribute-Based Access Control (ABAC) policies for row filtering and column masking.introducesABAC Policies GACoreattribute-based access control for row filtering and column maskingFrom the article 4 mentionsABAC policies allow access rules to be defined dynamically based on data attributes, rather than static object configurations.Governed Tags GACoreFrom the article 5 mentionsThis move, alongside the GA of governed tags and automated data classification, aims to streamline how organizations protect sensitive data.Data Classification GACoreautomated identification of sensitive data across the estateFrom the article 9+ mentionsConfiguring rules on a per-table basis is repetitive, prone to inconsistencies, and often creates security gaps, especially as data producers focus on creation rather than meticulous classification.Automated Data SecurityEffectdynamic, scalable protection of sensitive dataFrom the article 5 mentionsThis automated scanning ensures that any new sensitive data introduced is promptly identified and tagged.Streamlined GovernanceOutcomereduces manual effort and improves consistencyFrom the article 3 mentionsThese integrated capabilities promise to shift data governance from a manual, bottleneck-prone process to an automated, scalable system that ensures consistent, real-time protection across an organization's entire data estate.Reduced Security GapsOutcomeensuring sensitive data is protected effectivelyFrom the articleConfiguring rules on a per-table basis is repetitive, prone to inconsistencies, and often creates security gaps, especially as data producers focus on creation rather than meticulous classification. Manual data governance and access controls have long struggled to keep pace with growing data estates. Configuring rules on a per-table basis is repetitive, prone to inconsistencies, and often creates security gaps, especially as data producers focus on creation rather than meticulous classification. ## Automated Governance Takes Center Stage The new capabilities in [Unity Catalog](https://www.databricks.com/blog/abac-row-filtering-and-column-masking-policies-governed-tags-and-data-classification-are-now) aim to address these challenges by providing a unified framework. ABAC policies allow access rules to be defined dynamically based on data attributes, rather than static object configurations. This means a single policy can apply to numerous tables that share specific tags, ensuring that protection follows the data automatically. Governed tags serve as the foundation for ABAC policies, providing an account-level vocabulary for standardizing data descriptions. These tags, which can be key-value pairs like `sensitivity:confidential` or `pii:ssn`, attach to catalogs, schemas, tables, and columns, inheriting down the hierarchy. Complementing these features is agentic data classification, which automatically identifies sensitive data like PII and PHI. Built-in classifiers cover standards such as GDPR and HIPAA, with the ability to extend detection to custom, business-specific patterns. This automated scanning ensures that any new sensitive data introduced is promptly identified and tagged. ## Enterprise-Scale Enhancements At general availability, ABAC policies have been scaled for enterprise deployments, with policy limits significantly increased. Key enhancements include session identity evaluation for views and functions, ensuring users see data strictly according to their own permissions, even through indirect access methods. A single masking function now supports multiple numeric and STRUCT column types, reducing policy maintenance overhead. Governed tags now feature full lifecycle management across SQL, APIs, and the UI, alongside stronger administrative controls and improved visibility into tag coverage and inheritance. Agentic data classification has expanded compliance coverage and accuracy controls, including a human-in-the-loop validation process to continuously refine detection accuracy and manage false positives. These integrated capabilities promise to shift data governance from a manual, bottleneck-prone process to an automated, scalable system that ensures consistent, real-time protection across an organization's entire data estate. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.