Datadog AI Automation Targets Risk, but Enterprises Still Hold the Controls
- Olivia Johnson

- 22 hours ago
- 13 min read
Datadog AI automation is moving beyond dashboards, despite enterprise reluctance to let software act independently inside critical systems. The company now presents observability, security, and automated remediation as one response to rising operational risk. Its pitch is especially relevant in Australia, where large organizations often manage cloud services alongside legacy infrastructure and outsourced operations.
That shift changes Datadog’s role. Observability traditionally helped engineers understand what happened after an application slowed, failed, or triggered an alert. Datadog now wants its software to investigate incidents, recommend responses, and perform approved actions using live operational context.
The tension is not whether artificial intelligence can summarize an alert. It is whether enterprises will trust AI agents with production access while maintaining accountability, security, and human oversight. Splunk, Dynatrace, cloud providers, and security vendors are pursuing similar opportunities, so Datadog must prove that unified context produces safer automation.
Datadog AI Automation Moves From Answers to Actions
Datadog is turning its monitoring platform into a controlled operating layer for enterprise AI agents.
The company’s expansion rests on the combination of observability data, security signals, workflow automation, and generative AI. Observability means collecting and connecting information about applications, infrastructure, networks, user experiences, and other technical systems.
Datadog Regional Vice President for Australia and New Zealand Roz Gregory described that convergence as an opportunity to manage cost, AI safety, and compliance. In an ANZ enterprise interview, she argued that fragmented technology stacks make those priorities harder to address through separate tools.
Datadog has expanded from two products to more than 30, according to Gregory. Its platform now covers infrastructure, applications, software delivery, digital experiences, data, security, and AI workloads.
That breadth matters because automated incident handling requires context. An agent cannot safely diagnose a failed checkout using one isolated metric. It needs application traces, infrastructure health, recent deployments, security events, database behavior, and customer-facing performance data.
Bits AI is Datadog’s family of agents for development, security, and operational tasks. Datadog says these agents can investigate incidents, analyze related telemetry, and help teams act within defined controls.
The company expanded that strategy at its DASH conference in June 2026. Its 100-plus product launch included new Bits AI functions, an agent builder, AI security controls, and additional options for managing enterprise data.
Bits Agent Builder lets teams create specialized agents inside Datadog. Those agents can support remediation, reporting, and standards enforcement within boundaries established by the customer.
Agent Console addresses a related management problem. Datadog says it helps organizations observe tools such as Claude Code, Cursor, and GitHub Copilot. Managers can examine usage, tasks, outcomes, and spending instead of treating agent activity as an invisible layer.
Datadog also made its Model Context Protocol server generally available in March 2026. MCP is a standard interface that lets AI applications access approved tools and data sources.
The governed agent access connects external coding agents and development environments with live Datadog telemetry. The company positions this connection as a way to preserve permissions and governance while bringing operational evidence into AI-assisted work.
This architecture creates the article’s central tension. The same access that helps an agent diagnose production problems can increase the consequences of a mistaken or manipulated action.
An agent reading monitoring data presents one level of risk. An agent changing detection rules, creating tickets, suppressing findings, or initiating remediation presents another.
Datadog is therefore selling more than faster incident response. It is selling the claim that automation becomes acceptable when AI operates through a unified source of technical context and established controls.
That claim now has to survive procurement reviews, security testing, and real production failures.
Australia’s Hybrid Systems Raise the Stakes
Australian enterprises are not adopting automation on a clean technical foundation.
Many large organizations still operate traditional infrastructure while adding public cloud services, software-as-a-service applications, and AI systems. Outsourcing agreements add another layer of responsibility and access control.
This environment creates fragmented evidence. An incident can cross application code, cloud infrastructure, identity systems, external providers, and physical or virtual networks.
Teams often use separate products for each part of that path. Those products may generate overlapping alerts without sharing enough context to establish cause and business impact.
Gregory argues that a tool-heavy environment makes AI safety and complexity harder to manage. Her position supports Datadog’s commercial direction, but enterprises will still test whether consolidation reduces risk or simply concentrates it.
The immediate pressure falls on technology operations, security teams, and risk leaders. They must support faster software delivery without losing control of data, credentials, compliance evidence, or production changes.
Developers also face pressure. Coding agents can generate and modify software faster, but that speed increases the volume of changes entering review, testing, and deployment systems.
Security teams must distinguish exploitable problems from lower-priority findings. Operations teams must understand whether a failure came from code, infrastructure, capacity, data, or an AI model provider.
Datadog’s own research illustrates the operational problem. Its AI engineering data found that about 5% of AI model requests failed in production.
Nearly 60% of those failures resulted from capacity limits, according to the company. Datadog analyzed anonymized usage data from thousands of customers running large language models in production.
The report also found that 69% of organizations used at least three models. Agent framework adoption doubled year over year, while the average amount of data sent with each request increased.
These findings come from Datadog’s customer environment, so they should not be treated as a census of every enterprise. They still describe the type of complexity Datadog wants its platform to manage.
Multiple models create more routing decisions, failure modes, usage limits, and vendor dependencies. Agents add workflows whose next action can depend on a model output rather than deterministic application logic.
Australia’s governance environment adds another requirement. The federal government’s AI adoption guidance calls for accountability, risk management, data governance, testing, monitoring, and meaningful human oversight.
The guidance evolved from Australia’s voluntary AI safety standard. It does not create new legal duties by itself, but it helps organizations prepare for current obligations and possible future requirements.
Several practices align closely with observability. Organizations should monitor deployed AI systems, document risks, reassess controls, and track changes in behavior or intended use.
However, collecting telemetry does not automatically satisfy those duties. A dashboard cannot decide an organization’s risk tolerance, identify affected stakeholders, or assign accountability for a harmful outcome.
This distinction matters for Datadog’s pitch. The platform can provide operational evidence, access controls, and technical monitoring. Enterprise leaders must still define which actions an agent can take and who answers for the result.
The Australian market therefore presents both an opportunity and a difficult test. Hybrid environments create demand for unified visibility, but regulation and institutional caution limit how quickly customers will permit autonomous action.
Unified Context Is Datadog’s Main Bet
Datadog is betting that an agent with broader telemetry can act more safely than an assistant trapped inside one specialized tool.
An operations agent needs to reconstruct cause from evidence scattered across a technical stack. Datadog’s platform already gathers much of that evidence for monitoring and troubleshooting.
The company can give an agent access to application traces, logs, infrastructure metrics, deployment events, cloud security findings, and organizational knowledge. Datadog says this context helps Bits AI connect signals that would otherwise require manual investigation.
Winning Group offers a concrete example. The Australian retailer owns Winning Appliances and Appliances Online, whose website serves as the primary customer-facing storefront.
Technical Manager Nick Rivett said the company adopted Datadog partly to make performance information accessible outside engineering. Shared dashboards let more employees examine changes without waiting for an engineer to translate every metric.
Winning Group also uses Bits AI and Datadog’s MCP capabilities. Rivett described an incident that human teams had investigated for hours before Bits AI connected the evidence in about 10 minutes.
That account is a customer report, not an independent benchmark. It nevertheless shows where Datadog AI automation can create value without immediately granting an agent unlimited authority.
Faster investigation reduces the time between an alert and a credible explanation. A human can then review the evidence and choose a response.
Flowstate presents another operational case. The Australian company records surfers and processes video so customers can receive footage shortly after a session.
Downtime directly affects the product because missed recording time can mean lost customer footage. Flowstate uses Datadog to monitor its real-time video infrastructure and identify performance bottlenecks.
Its processing demands have increased as video moved from 4K at 30 frames per second to 4K at 60 frames per second, then 6K at 60 frames per second. Each increase adds data and processing pressure.
This case shows why connected telemetry matters. A performance problem might come from cameras, networks, compute resources, storage, application code, or a processing service.
An agent that examines only application logs sees an incomplete system. Datadog’s advantage depends on whether its platform can correlate enough of that system to identify useful relationships without creating misleading certainty.
The company’s commercial momentum gives it resources to pursue the strategy. Datadog reported second-quarter 2026 revenue of $1.12 billion, up 36% from the prior year.
Its second-quarter results listed about 4,720 customers generating at least $100,000 in annual recurring revenue. That number increased from about 3,850 one year earlier.
Datadog also reported $316 million in operating cash flow and $279 million in free cash flow for the quarter. It had $5 billion in cash, cash equivalents, and marketable securities at the end of June.
Those figures do not prove customer acceptance of autonomous operations. They show that Datadog has a sizable enterprise base and financial capacity to add AI features across an established platform.
This distribution advantage is important. Enterprises may prefer automation attached to monitoring systems they already use instead of introducing another agent with separate permissions and data pipelines.
The platform relationship also creates switching pressure. The more operational history, workflows, dashboards, and security controls a customer keeps in one system, the harder that system becomes to replace.
Datadog must balance this advantage against the concerns created by consolidation. A unified platform can reduce integration work, but a failure, configuration error, or security incident can have a broader impact.
The mechanism is therefore straightforward, even if execution is difficult. Datadog collects context, exposes that context to controlled agents, and uses automation to shorten investigation and response.
Its success depends on context quality, permission design, and the reliability of every action taken after the diagnosis.
Automation Creates a New Control Problem
The largest obstacle is not whether Bits AI can find an incident cause. It is whether enterprises can constrain the agent when its analysis is wrong.
Traditional monitoring tools alert people. Autonomous systems can also initiate actions, creating a larger potential impact from false conclusions or compromised instructions.
An incorrect summary wastes time. An incorrect infrastructure change can interrupt service, weaken a security control, or erase evidence needed for a later investigation.
Prompt injection creates another risk. Prompt injection occurs when hidden or malicious instructions manipulate an AI system into ignoring its intended rules.
Datadog introduced AI Guard to detect suspicious behavior across an agent’s activity. The company says it combines agent tracing with stateful behavioral analysis, which examines behavior across multiple steps instead of reviewing one prompt and response.
That distinction is relevant because agent attacks can unfold over time. An apparently harmless input might cause an agent to retrieve sensitive information, call an external service, or take an unauthorized action several steps later.
Datadog’s claims about AI Guard remain company claims until customers and independent researchers test them under diverse production conditions. No behavioral detector can guarantee that every harmful instruction will be recognized.
Permission boundaries are therefore essential. Agents should receive only the access required for a defined task, and sensitive actions should require additional approval.
A company also needs complete records of what an agent observed, inferred, and changed. Without that trail, teams cannot reconstruct failures or determine responsibility.
Human oversight cannot mean placing a nominal approval button at the end of an opaque process. Reviewers need enough context to understand the proposed action and its likely effect.
Automation speed can work against that requirement. If an agent produces hundreds of recommendations, people may approve them mechanically and create the appearance of control without meaningful review.
Datadog must also manage the risk created by its own integration reach. A platform connected to production telemetry, security findings, developer tools, and remediation workflows becomes an attractive target.
The company can reduce that risk through authentication, authorization, audit logs, data controls, and workload isolation. Customers must configure those controls correctly and maintain them as teams and systems change.
Data residency presents another concern for regulated organizations. Datadog’s Bring Your Own Cloud option responds by placing parts of the platform in a customer-controlled environment and using the customer’s object storage.
That design can help enterprises retain more control over growing log volumes. It does not remove every governance question involving metadata, support access, configuration, or connected services.
Cost can also slow adoption. Observability systems process large amounts of telemetry, and AI workloads can generate new logs, traces, prompts, responses, and agent events.
Customers must decide what to retain, index, analyze, or discard. Excessive filtering can hide the evidence an agent needs, while indiscriminate collection can increase costs and expose sensitive data.
There is also a measurement problem. Faster investigation does not necessarily produce safer operations, and more automated actions do not necessarily produce better business outcomes.
A credible deployment should track incident duration, recurrence, false recommendations, reverted actions, approval rates, and security exceptions. It should also distinguish incidents resolved by an agent from incidents where the agent added confusion.
Datadog’s Agent Console points toward this type of evaluation for coding agents. Enterprises will need similar discipline across every automated operational workflow.
The company’s strategy remains promising because it connects AI with real system evidence. The unresolved question is whether that connection produces dependable judgment or merely faster activity.
Datadog Faces a Crowded Platform Contest
Datadog’s real opponent is fragmented enterprise tooling, but competing platforms are making the same consolidation argument.
Organizations have spent years assembling specialized monitoring, security, ticketing, cloud management, and developer products. Datadog wants to connect more of those functions inside one data and automation layer.
That proposition pressures incumbent tools that own only one part of an incident. It also pressures engineering teams that maintain custom integrations between alerting, investigation, and remediation systems.
However, Datadog does not hold an exclusive claim on unified observability or AI-assisted operations. Dynatrace, Splunk, New Relic, ServiceNow, Microsoft, Google Cloud, and Amazon Web Services all connect AI with operational data.
Cloud providers have a structural advantage inside their own environments. They can connect agents with infrastructure controls, identity services, security products, and billing data.
Service management vendors own approval processes, tickets, asset inventories, and enterprise workflows. Security vendors possess specialized threat information and response capabilities.
Datadog’s defense is neutrality across mixed environments. Large organizations rarely operate one cloud, one programming language, or one security product.
A broadly integrated observability layer can compare behavior across those boundaries. Datadog can also use application and infrastructure telemetry to connect technical failures with customer experience.
Yet neutrality has limits. Every external system introduces an integration boundary, permission model, and possible delay. A cloud provider may access native information that an independent platform receives only through an API.
Open standards such as MCP can reduce integration friction. They can also make it easier for customers to connect competing agents with the same tools.
That means Datadog must compete on the quality of its context, reasoning, controls, and user experience. Merely supporting MCP will not preserve a lasting advantage.
The company must also prove that its growing product range feels unified. Buying fewer vendors helps only when teams can navigate the combined platform without creating another layer of complexity.
Enterprise buyers will examine whether alerts share a consistent data model, whether permissions work across products, and whether automated actions preserve auditability. They will also consider how data consumption affects contractual commitments.
Security leaders may prefer specialized products for high-risk investigations. Operations teams may favor Datadog because it already contains the telemetry needed to diagnose an application failure.
These preferences can produce gradual adoption. A customer might begin with AI-generated summaries, then allow ticket creation, low-risk remediation, and finally more consequential actions.
That progression challenges the idea of a sudden move to autonomous operations. Enterprise adoption is more likely to follow a ladder of trust.
Each successful action can justify broader permissions. Each false diagnosis or unexpected change can send the program back toward recommendation-only use.
Datadog’s opportunity is to make that ladder measurable. Buyers need evidence showing when an agent deserves more authority and when its access should remain limited.
The winner in this contest will not necessarily have the most autonomous demonstration. It will provide the clearest path from useful assistance to accountable action.
What Enterprises Should Watch Next
Three signals will show whether Datadog can turn its automation strategy into trusted enterprise operations.
The first signal is the expansion of production permissions. Datadog has already moved MCP capabilities beyond read-only access in parts of its security toolset.
The important question is how customers use those capabilities. Ticket creation and recommendation generation carry different risks from rule changes, suppressions, or automated remediation.
Evidence of repeatable production deployments would strengthen Datadog’s argument. Those deployments should include permission boundaries, approval requirements, audit records, and documented rollback processes.
A few dramatic incident stories will not be enough. Buyers need aggregated evidence covering false actions, escalation rates, time saved, and outcomes across different environments.
The second signal is adoption across Datadog’s larger customer base. The company’s 4,720 customers with at least $100,000 in annual recurring revenue represent a significant distribution channel.
Future financial reporting may reveal whether AI functions increase the number of products used by existing customers. Management commentary can also show whether Bits AI and Agent Builder support new enterprise commitments.
Revenue growth alone will not answer the question. Datadog sells many products, and customers can increase spending without granting agents broader operational authority.
The stronger signal would combine commercial expansion with disclosed usage. Datadog could report how many customers run Bits AI in production, what actions agents perform, and where human approval remains mandatory.
Limited disclosure would leave buyers dependent on selected customer stories. Transparent operational metrics would make the company’s claims easier to evaluate.
The third signal is the response from regulators and enterprise governance teams. Australia’s guidance emphasizes ongoing risk assessment, testing, monitoring, accountability, and human control.
Procurement processes will translate those principles into technical questions. Buyers will ask how Datadog handles access, sensitive data, model changes, third-party components, incident records, and agent behavior.
New mandatory requirements for high-risk AI would increase demand for evidence and monitoring. They could also slow deployment if Datadog and its customers cannot map agent activity to specific controls.
Competitor responses matter within this signal. Rival platforms will present their own approaches to governance, data residency, and autonomous operations.
If competing products provide clearer control models, Datadog’s broad telemetry advantage will carry less weight. If they remain fragmented, Datadog’s unified strategy becomes more attractive.
Enterprise teams should resist treating autonomy as a binary decision. They can classify actions by impact, test agents in restricted environments, and expand authority only when performance supports it.
They should also preserve human-readable records. An AI knowledge base can help teams retain decisions, incident context, and operating lessons, but it does not replace technical audit logs.
Datadog AI automation is ultimately a governance story disguised as a product expansion. The technology can compress hours of investigation into minutes, according to customer accounts.
The harder task is proving that faster action remains safe when an agent misunderstands a system, encounters manipulated data, or reaches beyond its intended role.
Datadog has the platform reach, enterprise customers, and financial resources to test that proposition at scale. Enterprises should now ask for measurable evidence before they exchange visibility for autonomy.
Which operational actions would your organization trust an agent to perform today, and what evidence would justify granting it the next level of access?


