Nuts and Bolts of Teradata AI Studio

—

by

in

Teradata recently released a new solution called Teradata AI Studio. In this post, I will discuss it from a platform architecture perspective. You will find relevant Data Science terms I mentioned in the Data & AI Glossary within this blog. Open the terms in the glossary; I have elaborated on some in detail and included diagrams where needed.

Whenever you open the AI Studio user interface, you will see the AI Studio UI group Data Science functionality in a way that’s meaningful for users and helps them navigate AI Studio. However, I haven’t organised this post into the UI categories. The AI Studio modules in the cluster don’t always match the categories; for example, the ModelOps module shares components with the AgentOps module, such as observability. Furthermore, some categories do map to a specific module in the AI Studio cluster, but I don’t necessarily find them relevant from a platform architecture perspective. For example, the notebooks we see in the AI Studio UI.

Without further ado, let’s start with Teradata AI Studio.

Teradata’s Offering

For many years, Teradata has been well known for providing an enterprise-level solution for Data Lakehouses. Their solution allows you to store and analyse large amounts of data. Now, they include some agentic AI functionality. So, to give some context, the following diagram shows their current portfolio, which is called the Teradata Autonomous Knowledge Platform.

Teradata Autonomous Knowledge Platform

The diagram below shows how AI functionality fits within a Teradata ecosystem.

AI Functionality within a Teradata ecosystem

Another way to put it is as the diagram below shows: the functional components available to make a Teradata intelligent Platform.

Teradata Knowledge Platform Components

Teradata AI Studio

Teradata AI Studio is a solution that allows you to use three key interfaces:

The agent framework also lets you deploy and monitor custom agents that you create with the Agent Builder.

AI Studio runs in a cluster separated from the Teradata Database. It can access the Teradata Trusted Parallel Architecture (TPA) nodes for data, such as the Teradata Enterprise Vector Store or in-database functions. It can also query files in blob storage buckets, for example, OTF tables.

Teradata AI Capabilities

Teradata AI Studio is part of the Teradata Agentic Platform, along with Teradata Enterprise Vector Store.

Teradata Agentic Platform

AI Studio Modules

The diagram below shows the modules that comprise the AI Studio cluster.

Teradata AI Studio Modules

I will elaborate on some large, important modules later in this article. Now, I will briefly comment on simpler modules from the platform architecture perspective:

  • Agent Builder — A module that allows users to create agents using both no code/low code (Wisdom.AI and, not available yet, Karini AI) and pro-code (LangGraph). It also allows you to edit, deploy, and monitor agents.
    • Pro-Code — Python-like experience for coding agents, leveraging frameworks like LangChain and LangGraph for advanced agent workflows.
    • Low-Code — Wisdom.AI provides a BI-based agent tool.
    • Data Scientists can use Teradata’s native Jupyter notebook to perform their tasks with agents.
  • Agent runtime — The execution environment for deployed agents, supporting scalable, secure, monitored agent workloads.
  • Agent governance — Security, role-based access control (RBAC), audit logging, and compliance controls to ensure safe, governed agent operation and data access.
  • Agent observability — Users can enable observability and track all their traces and spans, token usage, and failures across the agents they deployed in AgentOps.
  • Agent playground — A web-based user experience for playing around with the agent deployed in the AgentRuntime for the agent definition.

Tera

Tera is a complex module which performs several critical tasks, as shown in the diagram below. You can connect different agents to Tera to add functionality. For example, if you connect Tera with an agent that provides Conversational AI capabilities, you can type a query in your language, and it transforms it into SQL and runs it on the database.

Tera

Additionally, the Tera Context Engine is the Teradata Knowledge Platform’s core knowledge layer.

  • It ingests reference model definitions, your data sources, optional documents you may provide, Object Metadata Service metadata or lineage integration, and your source metadata,
  • Enriches that information with business context and embeddings,
  • Stores it in a context graph, and
  • Makes that context available to the user interface, agents, and downstream AI Studio modules and third-party applications, such as the OneTeradata user interface, Tera, context MCP clients, future context-consuming agents and services, and Wisdom.AI-related flows.
    • OneTeradata is Teradata’s unified platform and experience initiative that brings together previously separate interfaces, infrastructure, and tools into a single, seamless ecosystem.

In other words, the Context Engine turns raw metadata and business definitions into a governed, queryable knowledge layer.

The Context Engine works as follows:

  1. The reference model load service ingests a reference model and writes its definitions and embeddings to the graph.
  2. One of your sources is registered, schema metadata is discovered, descriptions and embeddings are generated, and the source structure is written to the graph.
  3. Your elements are matched to reference-model elements and mapping edges are created in a semantic mapping process.
  4. A user confirms or corrects the mappings through the review experience.
  5. OneTeradata UI reads governed context through the Context API.
  6. Tera and other agents access the same underlying context through the Context MCP and consume the output.

AgentOps

AI Studio module for managing the full lifecycle of AI agents — Deployment and monitoring of agents, including registration, observability, autoscaling, and operational management for both Wisdom.AI and Python-based agents. It allows you to evaluate agents on Teradata’s managed infrastructure.

AgentOps Capabilities in Teradata AI Studio

Users create their agents with the following modules:

  • Models available in the AI Model Hub in AI Studio. This option provides an easy Integration.
  • Your own LLM. You must whitelist those LLMs in the network setup for AI Studio access.

Separately, only an authorised AI Studio user can invoke the agents deployed on AgentOps.

The prerequisites to use AgentOps are:

  1. Access to Teradata AI Studio.
  2. At least one LLM configured in AI Model Hub.
  3. Python 3.10+ (only if using the SDK).
  4. teradata_agentstack package (optional — only needed for SDK/notebook workflows).

On another front, the workflow to deploy a minimal LangChain agent that calls an LLM and returns a response in AgentOps is as shown in the next diagram.

AgentOps - Steps to create an agent in Teradata AI Studio
Agent Lifecycle in Teradata AI Studio
Example of a Multi-Agent Architecture in AI Studio with Claude

Teradata MCP Server

The Teradata MCP server implements the Model Context Protocol, connecting MCP clients (AI-powered applications) to Teradata databases through a standardised interface. It allows MCP clients to perform database operations, address data quality, and read and write to the Teradata Database. There are two flavours:

  • Community edition: Open-source backend MCP server. It uses a single identity configuration for access to Teradata. The Community MCP server provides a collection of tools and is provided by the Teradata community for prototyping and early access. Additionally, it allows you to build the functionality you need to connect your AI agents to the Teradata database. It is not part of Teradata AI Studio, which requires the Enterprise edition.
  • Enterprise edition: It runs with Teradata AI Studio or standalone and provides a wide range of data sources, tools, and prompts to AI models and other clients. With the MCP Enterprise server, you can interact with external systems and perform actions using natural language commands:
    • Quietly enforces safe access to tools and systems for the Teradata Database.
    • Lets agents dynamically discover and use tools, resources, and prompts without hard‑coded integrations.
    • Enterprise control plane for agents, as it embeds security, governance, and consistency into agent workflows.
Teradata Enterprise MCP Server
Teradata Enterprise MCP Server - Key Features
Teradata Enterprise vs Community MCP server
Enterprise MCP Tools Categories
  • Enterprise MCP exposes capabilities only through MCP tools.
  • These tools have a standardised interface, pre-defined, verified prompts, and are semantically mapped and context-aware.
  • Every tool executes on behalf of an authenticated user.
  • RBAC and database permissions determine which tools are visible and executable.
Teradata Enterprise MCP Tools Categories
Enterprise MCP Server: Security and access control
  • Users access Teradata Enterprise MCP with individual credentials, limiting data access to authorised users. As a result, Teradata Enterprise MCP embeds identity, RBAC, and controlled tool access into the execution path.
    • Teradata Enterprise MCP enforces authentication before creating a session.
    • It validates identity before exposing any tools, prompts, or resources.
    • MCP explicitly separates authentication (who you are) from authorisation (RBAC, what you can do).
    • No anonymous, implicit, or model‑initiated execution paths.
  • SSL is always enabled and configurable.
  • The Enterprise MCP Server supports several authentication methods. Furthermore, it relies on enterprise identity providers, not agent-supplied identity.
    • JWT (default, recommended for production) via enterprise IdPs(Microsoft Entra ID, Okta, Auth0).
      • The Enterprise MCP server validates JWT tokens before establishing a session.
      • MCP validates required JWT claims: iss, sub, aud, exp, jti.
      • JWT is passed via the authorisation — bearer token header.
      • After validation, the Enterprise MCP Server establishes a user‑bound database session.
      • Tool discovery (tools/list) happens only after successful authentication.
    • TD2 basic authentication (username/password, BASE64).
    • LDAP authentication via Teradata database LDAP integration.
  • Authorisation uses RBAC to manage MCP tool discovery and execution.
  • There is protection against SQL injection.
Teradata AI Studio Access Control

More on Security

  • Teradata Cloud 3.4 introduces Global Identity as an OIDC-based identity path across supported Teradata Cloud Services, including AI Studio. Existing SAML SSO customers remain on PingFederate unchanged.
    • AI Studio 1.4 pairs with Teradata Cloud 3.4, and it will use Global Identity as well.
    • Global Identity’s Identity Brokering supports only OpenID Connect (OIDC), an extension of open authorisation (OAuth) 2.0.
    • Teradata customers can use any supported OIDC Identity Provider (IdP) to authenticate.
    • A new Teradata Cloud site onboards directly to Global Identity.
    • For releases before 1.4, AI Studio uses Keycloak for authentication.
    • Global Identity will be rolled out to all Teradata platforms as new versions are deployed in the field.
  • Customer-Managed Encryption Keys (CMEK) support:
    • Available in AWS starting with AI Studio 1.3 Update 1. In this version and on this platform, the following resources are encrypted: EBS Volumes, EFS file systems, and EKS control-plane secrets.
    • Pending to know further details on encrypted resources, AI Studio versions and Cloud Service Providers.
    • In the backlog with the infrastructure POD for Azure. We expect to support CMK on Azure with AI Studio 1.4, although this is not confirmed.
    • AI Studio reads and writes from object store buckets (AWS S3, Azure Blob Storage) and other file stores. Once we support CMEK keys, customers will be able to use their own CMEK keys in any storage that AI Studio uses.
  • Logging AI Studio activity:
    • Agents use the TD2 or JWT identity associated with the user that invokes them. So, DBQL registers agent activity on the database associated with that identity.
    • While users deploy agents through AgentOps, they have a logging tab available in AgentOps.
Teradata Identity Service

AI Studio: Networking

To access the AI Studio Console, use your existing Teradata Cloud account connection or a Private Link endpoint (AWS PrivateLink or Azure Private Link).

If you want to use a Private Link:

  • You only need to set up this endpoint before deploying the first Console in the environment. If Console connectivity already exists, you don’t need an additional endpoint. Otherwise, AI Studio uses the connectivity already established for Teradata Cloud.
  • AI Studio has only one dedicated Private Link when using this connection flavour. All the modules within AI Studio use the same endpoint.
  • You must share the endpoint IP address with Teradata so they can update the DNS entries on the Teradata Cloud account.

On a separate note, AI Studio can only connect to the Active Compute associated with the Teradata Cloud site it is deployed on.

Presently, AI Studio can only be deployed to the same region as the Teradata Cloud site it connects to. Teradata currently does not support cross-region AI Studio deployments.

Incidentally, Teradata deploys AI Studio within the VPC of an existing Teradata Cloud site.

AI Studio: Information to Work with the Components

AI Studio capabilities are constantly evolving. To get the most up-to-date information about each component and its features, you should review the latest version of the Teradata® AI Studio — Getting Started online documentation. There you can find:

Other online documentation you may find useful is:

Additionally, Teradata maintains Python packages on PyPI, the official repository for Python packages. For example, you can find teradatamodelops and teradata-etl-mcp-server among those packages.


References

OpenID Foundation. (n.d.). What is OpenID Connect. OpenID website. Accessed on 30 August 2026, from https://openid.net/developers/how-connect-works/

Teradata.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *