Weekly Vendor Synthesis — 31 July 2026

Tag: S-2026-07-31-weekly-vendor-synthesis Type: own-writing Author(s): Paul (Red Strata), via automated weekly vendor-synthesis agent Date of source: 2026-07-31 Date ingested: 2026-07-31 Authority weight: high — own synthesis of Paul’s own week of vendor-intelligence captures; primary reflection of his market-watch focus. (The underlying per-vendor capability claims it synthesises are vendor- or analyst-asserted and weighted accordingly on their own source pages.) Raw file: S-2026-07-31-weekly-vendor-synthesis

What it claims

A synthesis of the 8 vendor-intelligence captures in the week of 27–31 July 2026 (7 distinct moves — the Collibra CLI lineage-harvester End of Life was captured on both 30 and 31 July). Most active vendors: Collibra, Informatica, Microsoft (Purview).

It identifies five themes. (1) Lineage-evidence lifecycle risk: Collibra’s CLI lineage harvester and single-file custom technical lineage option reached official End of Life on 31 July (re-verified on the day, no reprieve), with Edge-based lineage the sole supported path; the 2026.07 release also flips the Import API default to continueOnError=true. The synthesis’s read: vendor product-lifecycle events are now regulatory-evidence events. (2) AI/agent governance absorbed into catalogue incumbents: Collibra 2026.06 (OAuth-secured MCP server, AI Agent asset types, mandatory AIUC-1 assessment at Under Review, AI-suggested DQ rules preview) and Informatica’s July CDGC release (AI Governance Inventory & Workflows, prebuilt MDM catalog scanner) mean both major catalogue incumbents now ship an AI use-case/agent inventory natively — the EU AI Act evidence layer becoming standard catalogue capability rather than a pure-play add-on. (3) Data-security automation/DSPM: Microsoft’s July Purview wave (Data Security Triage Agent via Teams, endpoint DLP for archives and FTP/SFTP, automated leaver-data deletion — secondary-source roadmap summary) and BigID’s Gartner Peer Insights DSPM “Strong Performer” citation; the market moving from finding sensitive data to automatically acting on it. (4) Security capital enters agentic governance: Neo (ex-SentinelOne/Wiz/Palo Alto founders) exited stealth 20 July with $100M from a16z/Bessemer for SecOps-side inventory, posture and policy control over AI agents. (5) Light signal: Ataccama’s first community roadmap event under new CPO Jay Limburn.

Landscape read: no M&A or funding among DG/DM incumbents; Neo the only new entrant (security-led, adjacent); the DG pure-plays (Alation, Atlan, OneTrust, Immuta, Monte Carlo) quiet a fourth consecutive week, with BigID and Ataccama giving only light signals.

Its distinctive practitioner contributions: the Collibra CLI EOL check moves from “prepare” to “confirm done” (completed Edge migration plus re-validated evidence chain, and the continueOnError default flip as a silent ingestion-quality risk to test); “show the retained AI-inventory artefact, assessment record and logs” is now a nameable EU AI Act evidence test against both catalogue incumbents; and DORA ICT-risk scoping conversations should expect security-led vendors claiming the agent-control layer, making control-ownership boundaries an assessment question.

Notable quotes

None — this is a synthesis document; no verbatim quotes preserved beyond those already on the underlying per-vendor source pages.

What’s speculative vs. asserted

  • Asserted: the capture count (8, of which 7 distinct); the named vendor moves and dates (Collibra CLI harvester + single-file definition EOL 31 July, verified effective on the day; Collibra 2026.06 all-environments 28 June; Informatica CDGC July release last week of July; Purview July roadmap wave; BigID Peer Insights citation dated 13 July; Neo stealth exit 20 July with $100M; Ataccama roadmap event 9 July under CPO Jay Limburn); the absence of incumbent M&A/funding; and the continuing absence of any named EU/UK regulated-FS production reference.
  • Speculative / interpretive: “vendor lifecycle events are now regulatory-evidence events” and “the EU AI Act evidence layer is becoming standard catalogue capability” are the synthesis’s own market reads [speculative]; the three engagement implications are Paul’s analytic framing, not claims in any capture; treating Neo’s funding as evidence the agent-control layer is “being claimed from the security side” is an inference from one launch [inference]. Underlying capability claims are vendor release material (Collibra 2026.06 from primary release notes; Informatica via search summaries only — primary pages unfetchable; Purview via a secondary roadmap summary; BigID quoting Gartner Peer Insights data in its own release; Neo via launch coverage), none independently verified.

Topics this feeds

  • Agentic Data Access Governance — records the incumbent-convergence claim (native AI use-case/agent inventory in Collibra and Informatica), the Neo security-side entry, and the fourth consecutive quiet week for the pure-plays.
  • BCBS 239 and Data Lineage — closes the Collibra CLI EOL countdown: the deadline is now effective, and the check moves from “prepare” to “confirm done”.

Open questions raised

  • Did the Credo AI Agent Governor webinar (30 July) disclose capabilities? No capture surfaced this week — carried forward.
  • Do the Purview July roadmap items ship as described? Still secondary-source; verify on Microsoft’s changelog as they land.
  • Do Informatica’s CDGC July claims (MDM scanner, AI Governance Inventory & Workflows) hold up against primary release notes? Source pages were client-rendered; only search-relayed so far.
  • Are the pure-plays (Alation, Atlan, OneTrust, Immuta, Monte Carlo) quiet for a fourth week because of a summer lull or H2 launches? The deliberate H2-launch scan flagged 24 July is still due.
  • Standing gap (unchanged): no independently verified EU/UK regulated-FS production reference for any of this week’s vendor claims.