# DASF - Databricks AI Security Framework

> DASF is the Databricks AI Security Framework, a map of 62 AI risks and their controls. What it covers, and how to put those controls in the runtime.

Published: 2025-08-22 · Updated: 2026-08-12
Author: Preetham Reddy
Tags: Databricks
Canonical: https://www.techfabric.com/blog/dasf---databricks-ai-security-framework

---

![](/blog-media/fb363250-1.jpg)

A policy document that describes how agents should behave won't stop a send. A control stops the action when the grant is missing, and leaves a record either way.

Databricks publishes the Data and AI Security Framework, DASF, as a map of risks across the AI lifecycle, from the data and the models through serving and the platform underneath. It's a useful map. You don't install it. The work is deciding which of those risks you actually have, then putting a gate in the runtime.

## Where we put the gates

**Data.** Unity Catalog decides who can see what. Agents and apps run under their own service principal, on the same path a person uses. If the catalogue coverage stops halfway, that's a [Health Check](/databricks/health-check) finding, and it will show up in an agent programme later as an incident.

**Models and tools.** Unity AI Gateway is where model serving is governed. Tools an agent can call resolve through the catalogue, so it can't reach a table its principal has no grant for. [TechFabric Harness](/accelerators/harness) is how we deploy that agent as a Databricks App without rewriting it for each target.

**Actions.** Every domain change goes through one mutation pipeline. [TechFabric Platform](/accelerators/platform) makes an illegal transition structurally impossible. An agent actor passes the same policy and state-machine gates as a human one, and the event that explains the change is part of the same transaction.

**Approvals.** Anything that would leave the workspace parks at a ticket a person answers. [Fabric Tower](/accelerators/fabric-tower) is the console. The supervisor can't approve itself.

The DASF PDF already walks the twelve components, and a paraphrase here would be worse than the source. The useful question is whether your agents pass the same gates as your people. A second, weaker path is the incident.

DASF is Databricks' framework, not a certification we hold. We use the surfaces it assumes: Unity Catalog, AI Gateway, Model Serving, Apps. We don't claim a partner specialisation we don't have.

Almost every team that asks us about AI security has not yet written down what a good answer is. Build the rubric first. [Genie Accuracy](/databricks/genie-accuracy) and [TechFabric Experiments](/accelerators/experiments) are that work. Then the gates have something real to protect.

The service line is [AI systems](/services/ai-systems). Troy's line still holds: draw the permissions boundary in the first conversation.
