Strategy Recognized in the Gartner® Hype Cycle™ for AI Governance Technologies, 2026
Why deterministic answers and secure execution are not enough without shared business meaning
Quick Answer
Gartner named Strategy a Vendor in the Composite Semantic Layer profile of the 2026 Hype Cycle for AI Governance Technologies.
Deterministic retrieval makes enterprise answers repeatable, while execution-path governance makes agent actions controllable.
When agents cross systems, neither is sufficient without semantic governance that determines which business meaning is authoritative.
LLMs are probabilistic, but business logic can't be. As Strategy CPO Saurabh Abhyankar explains in AI and Gambling: Probabilities Aren't in Your Favor, you can't gamble on a plausible revenue calculation when you need the right number. In my last article, When AI Agents Access Enterprise Data, Governance Has to Run in the Execution Path, I argued that governance also has to run directly in the execution path. But what happens when an agent crosses multiple governed systems, each with a legitimate but different definition of the same business concept?
Imagine a customer-retention agent that is properly authenticated. Every tool call is authorized. The CRM, finance system, and product-usage platform are each protected. Yet those systems use different definitions of an “at-risk customer.” The agent combines them, prioritizes the wrong accounts, and triggers an expensive offer.
Nothing was hacked. No permission was bypassed. Every local control worked.
The agent was secure. The decision was still wrong.

Figure 1: Three governed systems define “at-risk customer” differently, causing an authorized retention agent to prioritize the wrong accounts.
This brings me to why Gartner's latest Hype Cycle for AI Governance Technologies caught my attention.
What we consider the Gartner recognition means
Gartner named Strategy a Vendor in the Composite Semantic Layer profile and rates the category's benefit as Transformational, placing it at the Innovation Trigger. But in our opinion, the most interesting line in the report wasn't about us. It was this observation:
Gartner writes: “The vision of a universal semantic layer remains unrealized due to current technological limits and vendor walled gardens.”
My reading is not that enterprises should give up on universal meaning. It is that they should stop confusing a universal outcome with one monolithic implementation.
Business meaning already lives across warehouses, lakehouses, BI platforms, catalogs, data products, and domain-owned models. AI agents will not wait for companies to replace all of that with one repository.
Universal is the outcome. Composite is the architecture.
“Universal” should describe the outcome every consumer can rely on: authoritative business meaning resolved consistently for the relevant user, purpose, and context. “Composite” describes how the semantic layer can deliver that outcome across systems that remain distributed.
Composite cannot mean that every semantic model becomes equally authoritative. A workable architecture still needs ownership, discovery, versioning, conflict resolution, and rules that determine which definition applies to a given user, purpose, and moment. Federation without authority is just distributed ambiguity.
A composite architecture shouldn't simply merge every available definition. If Finance defines an “at-risk customer” by overdue receivables while Product defines risk by declining usage, a governed retention model might combine both under an approved definition owned by Customer Success. Which definition applies should follow explicit authority and context rules, not whichever source the agent happens to find first. And if no approved rule resolves the conflict, the safer behavior is to stop and surface the ambiguity for explicit resolution rather than silently combine incompatible meanings.

Figure 2: Semantic governance resolves authoritative business meaning across distributed semantic sources for BI, applications, APIs/MCP, and AI agents.
Runtime security sets execution boundaries. Semantic governance resolves business meaning.
For enterprise data access, I think of agent governance across three interacting control domains: policy and accountability, runtime security, and semantic governance. Each addresses a different failure mode, and all three need to be observable at execution time.
Semantic governance can be one of the easiest controls to overlook. An agent can be fully authorized and technically compliant while still acting on the wrong business meaning. Governance therefore cannot stop at deciding whether an individual tool call is allowed. It also has to determine which semantic authority applies, whether definitions conflict, and what context may be combined for this user, purpose, and moment.

Figure 3: From Policy to Proof: The Control Layers of Agent Governance
From policy to proof
In my reading, related Gartner research points toward the same operating standard: controls must work in practice, persist during machine-speed execution, and integrate with existing governance frameworks rather than creating parallel ones.
For me, that establishes a higher bar. A semantic model that exists only in PowerPoint does not prove an agent used it. A quarterly review does not prove policy held during a machine-speed workflow.
That leads to three practical questions:
Did the agent use the approved business definition for this purpose?
Were identity, permissions, and policy preserved across every hop?
Can the organization reconstruct the semantic version, decision path, action, and outcome?
If the answer to the third question is no, the organization has a policy, not proof.
Where Strategy Mosaic and Mosaic Sentinel fit
Strategy Mosaic works across the data stack enterprises already have, connecting warehouses, BI tools, semantic models, and data products so authoritative business definitions can be governed and reused across applications and AI agents.
MCP and APIs make that governed context available to AI tools, while Mosaic Sentinel adds visibility, auditability, and controls around how data and semantics are being accessed.
The boundary matters. Mosaic does not replace model security, prompt-injection defenses, nonhuman identity management, endpoint security, or broader agent runtime protection. Enterprises need those controls too.
Runtime security constrains what the agent can do. Semantic governance determines which approved business meaning should guide the action.
The next governance gap
AI agents turn semantic inconsistency into operational inconsistency. A conflicting metric that once produced two dashboards can now produce two actions, two prices, or two customer decisions.
That is why I see the Composite Semantic Layer as part of the AI governance stack. The goal is not to force every team into one physical model. It is to make distributed business meaning authoritative, reusable, enforceable, and provable as agents cross platforms, tools, and domains.
I believe, Strategy's inclusion as a Sample Vendor is meaningful because it reflects a problem Mosaic is designed to address. But the requirement is larger than any one product.
That is the difference between connecting AI to the enterprise and trusting it to act on the enterprise’s behalf.
Gartner Disclaimer & Attribution
Attribution: Gartner, Hype Cycle for AI Governance Technologies, 2026, Priya Sundararaman, Lauren Kornutick, Sumit Agarwal, Svetlana Sicular, 7 August 2026.
Additional Gartner research referenced: Build Cyber Resilience Through Threat-Informed Risk Assessment and Decisions, Lampis Alevizos, 5 January 2026; Buyer’s Guide for Cybersecurity Continuous Compliance Automation, Pedro Pablo Perea de Duenas, Arthur Sivanathan, Lampis Alevizos, 25 February 2026; Cyber GRC Practices Must Evolve to Manage AI Risk, Pedro Pablo Perea de Duenas, Lampis Alevizos, Deepti Gopal, 27 April 2026.
Trademark Line: GARTNER and HYPE CYCLE are trademarks of Gartner, Inc. and/or its affiliates.
Objectivity Disclaimer: Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.






