AI Business

Accenture Demonstrates How Oracle's Deep Data Security Shifts Trust to the Database Layer

As AI agents increasingly handle application logic, traditional security models break down. Accenture's work with Oracle shows how database-level access controls can enforce authorization policies regardless of what queries an AI system generates.

·2 min read
Accenture leverages Oracle’s Deep Data Security for database-driven trust boundaries
Accenture leverages Oracle’s Deep Data Security for database-driven trust boundaries

Oracle Corp.'s Deep Data Security rests on a fundamental insight about modern enterprise security: the moment an AI agent becomes the application layer, the trust boundary can no longer stay there. Instead, it must move down to the database itself.

Roger Cornejo, technology innovation principal director of gen AI/AI at Accenture Enkitec Group, has released research demonstrating this approach in practice. Working with Oracle's Deep Data Security, Cornejo's team built an application where the database enforces access policies regardless of what Structured Query Language the agent constructs.

We speak to a client, and we walk them through our security model, including the layered security. I can tell you, every person that we have shown this application to, [with] this level of security, has not seen anything like it. They can trust the application is not going to expose their data to people who aren't authorized to see it.

Roger Cornejo

Cornejo discussed the work during an appearance at Oracle's "AI Cyberattacks Are Escalating: How to Secure Your Data Now" event, speaking with Dave Vellante in an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. The conversation centered on how Oracle's solution embeds end-user-specific privacy rules directly inside the database.

Defining boundaries in enterprise security

Within Accenture's Oracle practice, Cornejo's team operates a Model Context Protocol server that gives AI agents access to a knowledge repository containing more than 925,000 documents spread across 27 Oracle product namespaces. Each agent operates with different authorization levels, and Deep Data Security defines those boundaries in SQL, with the database enforcing them on every query from every agent.

https://www.youtube.com/embed/CIIbV_VNV5Q?feature=oembed

When we were tasked to build this application out, it needed to be multi-tenant, it needed to scale, it needed to be robust in terms of security. We implemented this all with database security. We have dozens, probably 40 or more agents that are hitting this application. We needed to make sure it would scale as well. Right now, we have tested it to scale to 300 simultaneous queries returning the results, most of the results, in 15 seconds or less.

Roger Cornejo