Collibra Platform 2026.06 release notes — MCP/OAuth GA, AI-agent operating model, lifecycle management preview

Tag: S-2026-06-28-collibra-202606-release-notes Type: report (vendor product release notes) Author(s): Collibra (Product Resource Center) Date of source: 2026-06-28 (release available in all environments; pre-production 2026-06-07; release-notes document dated 2026-05-29) Date ingested: 2026-07-27 Authority weight: medium — primary vendor documentation, authoritative for availability status and dates, but self-interested on capability descriptions; no independent verification. Raw file: S-2026-06-28-collibra-202606-release-notes.md. External URL: https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/Archive/ref_release-202606.htm

What it claims

The 2026.06 Collibra Platform release (all environments 28 June 2026) makes the Collibra MCP server externally consumable at GA: OAuth 2.0 authorization code grant now lets “MCP-compliant AI tools and agents” — the notes name Claude Desktop, Databricks, Microsoft Copilot and Snowflake Cortex — securely query Collibra for data definitions, ownership, lineage and compliance information (DEV-167157, GA). The AI Command Center / AI Governance operating model gains AI Agent Version and AI Agent Tool asset types plus an AI Agent Deployment complex relation between an agent version and an AI endpoint, with attributes including Traffic Split Percentage (DEV-175781, private preview). The out-of-the-box AIUC-1 Compliance Assessment is now wired into the AI Agent asset lifecycle — mandatory at “Under Review”, optional at “Accepted” (DEV-174704, GA). Lifecycle management extends to all asset types in public preview, with required/recommended activity gates (assessments, sign-offs) before stage transitions (DEV-164486). Smart checks (real-time metadata-quality validation, planned to replace Validation Rules and Articulation Score) enter public preview (DEV-137311). In Data Quality & Observability, AI-suggested DQ rules (“Suggest Rules”, with plain-language explanations and generated SQL) are listed as private preview (DEV-164339), and DQ scores now surface on Column/Table/Data Product assets (DEV-166608, GA). The Vertex AI integration now ingests vendor foundation models from Model Garden when a customer model derives from them, establishing lineage from the custom model back to the foundation model and its publisher (DEV-178894). A workflow-engine security vulnerability allowing Groovy-script OS command injection by users with workflow-deployment permissions is fixed (DEV-175353).

Notable quotes

“Collibra now supports OAuth 2.0 authorization code grant, enabling MCP-compliant AI tools and agents to connect securely to Collibra.” — DEV-167157

“The out-of-the-box AIUC-1 Compliance Assessment is now configured in the ‘Lifecycle’ tab of the global assignment of the AI Agent asset type.” — DEV-174704

“[Collibra] Establishes lineage between your custom model and the foundation model it was based on.” — DEV-178894

What’s speculative vs. asserted

  • Asserted (release-notes fact): availability dates and release-stage labels (GA / public preview / private preview) for each item; the security fix.
  • Vendor framing: that these capabilities constitute effective governance of AI agents; effectiveness and auditability are not evidenced.
  • Not stated: any EU/UK FS reference customer; any explicit BCBS 239 / EU AI Act mapping — regulatory relevance recorded on the Collibra page is inference.

Topics this feeds

  • Collibra — company page updated with 2026.06 release detail.
  • EU AI Act — agent inventory/lifecycle assessment and foundation-model lineage are candidate high-risk-governance evidence mechanisms [inference].
  • BCBS 239 and Data Lineage — DQ scoring on assets and AI-suggested DQ rules bear on data-quality control automation [inference].

Open questions raised

  • ⚠️ Tension with S-2026-07-06-collibra-release-announcements: that source recorded (search-derived) “AI suggested rules” reaching GA in July 2026 in DQ&O, while these 2026.06 notes mark “Suggest Rules” (DEV-164339) as private preview. Possibly different release trains (DQ&O cloud releases vs. platform release notes) or a preview→GA progression within weeks. Status: unresolved.
  • Whether the MCP/OAuth GA gives client-scoped, role-filtered access adequate for regulated-FS data-access governance (token scoping detail not in the notes).
  • Whether AIUC-1 assessment completion records are exportable as audit evidence.