Why AI engineering is replacing experiments
Organizations are shifting from chaotic AI experiments to the "AI Engineering" stage, where agent reliability depends on structural data integrity. According to the Cisco AI Readiness Index 2025, only 13% of companies, known as "Pacesetters," achieve stable results from AI. For most enterprises, the primary obstacle is legacy systems, which remain "black boxes" to agents due to a lack of standardized metadata and security context.
As Microsoft notes in the 2026 Work Trend Index, organizational factors and systematic management have twice the impact on AI implementation results compared to individual employee efforts. Autonomous agents cannot act effectively in environments where business context is hidden.
The role of domain metadata
A significant portion of an AI agent's effectiveness depends on the clarity of domain metadata provided as an enterprise "map." When a model does not understand the structure of objects—such as financial documents or contracts—the risk of errors increases. An architectural approach where business entities and API contracts are clearly defined helps avoid hallucinations and ensures predictability.
From logs to DMN: structuring business logic
Agents often fail when attempting to interpret unstructured logs. According to Object Management Group standards, Decision Model and Notation (DMN) allows for the extraction of decision-making rules from program code. Using DMN tables enables an agent to "read" rules rather than guessing them based on outdated algorithms. Systems that use DMN to describe business processes allow agents to correctly handle approval logic without rewriting code.
Security as a foundation: RLS and LLM risks
Integrating AI agents presents serious challenges: Prompt Injection (LLM01:2025) and sensitive information disclosure (LLM02:2025), as identified by OWASP. A typical risk arises when an agent fails to adhere to Row Level Security (RLS) rules, granting access to data for which the user lacks permissions. According to the NIST AI RMF 1.0, effective risk management is based on four functions: Govern, Map, Measure, and Manage.
Technical basis: UnityBase and domain data management
To build a managed architecture, it is essential to use a platform that provides a unified access layer. The UnityBase platform allows developers to build enterprise systems where domain metadata serves as a common model for data, UI, and API. Solutions built on this platform (such as Megapolis.DocNet or Scriptum) utilize UnityBase mechanisms to ensure RLS, ACL, and auditing. This allows agents to act only within authorized limits, ensuring the security and transparency of every step.
| Maturity Level | Description |
|---|---|
| 1. Unstructured data | High risk of hallucinations, functions only as a search tool |
| 2. Siloed metadata | Limited access, lack of security context |
| 3. Domain modeling | Use of DMN and structured API contracts |
| 4. Governance-First | Full integration with RLS, auditing, and security policies |
FAQ
How can legacy data be prepared for AI agents?
It is necessary to structure data through a unified domain model, implement clear API contracts, and describe business logic in DMN format, which allows agents to operate on data according to company rules.
What role does DMN play in process automation?
DMN allows for the separation of business logic from program code. This makes rules transparent for AI, enabling it to make decisions based on logical tables rather than attempting to interpret outdated software algorithms.
How can AI security be guaranteed through Row Level Security (RLS)?
Security must be implemented at the system's data layer. Using platforms with built-in RLS (such as UnityBase) ensures that an agent only gains access to data for which the current user has authorization.