Skip to content

Context vs control: Why you need both

Enterprise AI conversations tend to focus on one of two priorities.

One says the priority is context: give agents better data, clearer definitions, a real understanding of the business. The other says the priority is control: visibility, ownership, policy enforcement, the ability to audit what an agent did and why.

Both camps are right. Neither is sufficient on its own.

Context without control is exposure. Control without context is paralysis. And most enterprise AI programs are stalling because they've picked a side instead of building both.

Two ways to fail

Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027. Many will trace back to one of two failure modes, and enterprises rarely see which one they're in until it's expensive.

The first failure mode is a context gap. The agent doesn't know what the data means, whether it's current, or what it's allowed to do with it. It guesses, confidently. Anthropic's own research found that without the right skills and business context, analytics accuracy didn’t exceed 21% in its evals. With the context in place, accuracy climbed above 95%. That 74-point swing isn't a model problem. It's what I call the hallucination tax, and it's a context problem wearing a technology costume.

The second failure mode is a control gap. The agent has plenty of context but no oversight around it. Nobody can say which team deployed it, what it's authorized to touch, or what it actually did last week. This is the failure mode enterprises reach for first, because it feels more governable: lock the agent down, restrict its access, require sign-off on every action. It solves the risk by solving the deployment out of existence. The agent stops being useful roughly as fast as it stops being dangerous.

Most organizations solve for whichever failure they were burned by last. The team that got a wrong answer in front of a customer invests in context. The team that got surprised by an agent doing something it shouldn't have invested in control. Both investments are necessary. Neither is sufficient, because they're solving different halves of the same problem.

Why one without the other doesn't hold

An agent needs to answer three questions before it acts on enterprise data: what does this mean, is it trustworthy right now, and what am I allowed to do with it. The first two are a context problem. The third is a control problem. Get context right and control wrong, and you have an agent that understands your business perfectly and acts on it with no accountability. Get control right and context wrong, and you have an agent that's fully auditable and still wrong, just on the record.

I've seen enterprises build an excellent semantic layer, spend a year defining what "customer" and "revenue" mean across the business, and still have no idea which of forty agents in production are using those definitions, which are bypassing them, or which stopped being accurate three months ago when the underlying policy changed. The context was governed. The runtime wasn't. The result is the same ambiguity it was supposed to solve, just discovered later and at higher cost.

The reverse is just as common. A tightly controlled AI Command Center with full lineage, ownership records, and audit trails, wrapped around agents operating on data nobody has validated in months. You can produce a perfect log of an agent confidently doing the wrong thing. Control tells you who's accountable for the failure. It doesn't prevent it.

What this actually requires

Context governance is the discipline of making meaning, trust, and permission reliable enough for an agent to reason over. Control is the operational layer that enforces it in real time: ownership, lifecycle management, policy enforcement, traceability. One without the other isn't a smaller version of the solution. It's a different, incomplete one.

Our own research with The Harris Poll found that 90% of decision-makers agree organizations can't have full confidence in AI-driven insights until the underlying data has been verified through a formal governance framework, and separately, 91% believe human oversight of AI systems remains critical. Read those together and the message isn't "AI isn't ready." It's that trust in enterprise AI has two separate conditions, and most programs are only meeting one of them.

The enterprises that get through this phase won't be the ones with the most sophisticated models, or even the most governed data. They'll be the ones that stop treating context and control as sequential projects, or as a choice between camps, and start building them as the same infrastructure. It's also the reason I think this is the right question for every leader evaluating an agent in production right now: not context or control, but where, specifically, is either one still missing.

Keep up with the latest from Collibra

I would like to get updates about the latest Collibra content, events and more.

There has been an error, please try again

By submitting this form, I acknowledge that I may be contacted directly about my interest in Collibra's products and services. Please read Collibra's Privacy Policy.

Thanks for signing up

You'll begin receiving educational materials and invitations to network with our community soon.