Governance for AI Agents and Models

AI Governance Platform
Every Agent Registered, Every Decision Auditable

An AI governance platform is software that enforces who may run which AI agents and models, on which data and with what approvals, and records every prompt, tool call, retrieval and output as evidence. VDF AI builds governance into the runtime itself: policy, role-based access, approval gates and an immutable audit vault, deployable on-premises or in a sovereign cloud.

Governance you can query, not a policy you hope people follow.
Built for CISOs, compliance officers and heads of risk.

10 EU AI Act use cases mapped
100% Actions attributable
0 Bytes outside your perimeter

We map your controls to what production and regulators require.

Controls mapped to
EU AI Act DORA NIS2 GDPR ISO 42001

Four questions a regulator will ask

  • Who triggered this agent, under which role, and was that role entitled to?
  • What data did it read, and did that data ever leave your controlled environment?
  • Which model produced the output, which version, and who approved that model for this use?
  • Did a human review the action before it took effect, and can you show the review?

How VDF AI answers them

Governance on Paper
or Governance in the Loop

Governance as a document

  • An AI policy that engineers have not read since onboarding
  • A spreadsheet of AI systems that was accurate last quarter
  • Approvals in email threads nobody can find
  • Logs scattered across vendors in different formats
  • A guardrail library bolted on to one application
  • An audit that starts with an all-hands data hunt

Governance as a platform

  • Policy evaluated on every request before the model runs
  • A live registry that cannot fall out of date
  • Approvals recorded with the run they authorised
  • One immutable Vault for prompts, retrievals, tools and outputs
  • Controls applied to every agent, including registered third-party ones
  • An evidence pack generated from the same store

Register. Approve.
Prove.

Register and control

Every agent, network and model has an owner, a purpose and a risk class in the registry. Role-based access decides which tools and knowledge sources each may use, and the MCP tool registry makes the grant explicit.

Approve and oversee

Autonomy levels set what an agent may do alone. Consequential actions wait at an approval gate for a named person, and the review, the reviewer and the elapsed time are stored with the run.

Prove

The Vault keeps a cryptographically durable record of each execution. Decision receipts bind prompt, sources, model, tools and outcome, and an evidence pack for the EU AI Act or a sector audit assembles from it.

Where governance can live

Control Cloud AI suite guardrails Bolt-on observability tool VDF AI governance platform
Inventory of agents and modelsWithin that suiteWhat it can seeComplete, including registered third-party agents
Data boundaryThe vendor's cloudNot enforcedEnforced per deployment mode, air-gapped included
Model choice policyVendor's models onlyObserved, not enforcedEnforced by the router per step
Human oversightApplication-specificAlerts after the factApproval gates before the action
Evidence exportVendor log exportTracesRegulation-mapped evidence pack
ContainmentPer applicationNoneKill switch for agent, network or model

Eight evidence artifacts an AI governance platform must produce

If a platform cannot generate these from its own records, governance is still a manual exercise. The twelve-control matrix that sits behind this list is in the AI agent governance guide, and the regulation-by-regulation mapping is in the governance framework for regulated industries.

  1. Agent and model inventoryA registry of every agent, network and model in use, with an owner, a purpose, a risk class and a version, exportable on request.
  2. Access and entitlement recordsWho may invoke which agent, which tools it may call and which knowledge sources it may read, resolved from your directory.
  3. Data boundary attestationProof of where prompts, embeddings and outputs were processed and stored, per deployment mode, with no hidden egress.
  4. Human oversight logEvery approval gate, who approved, what they saw and how long it waited, mapped to the oversight duties of high-risk use.
  5. Decision receiptsFor each consequential output, the prompt, retrieved sources, model, tool calls and final action bound together and hashed.
  6. Model change historyWhen a model was introduced, evaluated, promoted or retired, with the evaluation results that justified it.
  7. Incident and kill-switch recordContainment actions taken, when, by whom, and the state preserved for the post-incident review.
  8. Regulation mappingEach control tied to the article or clause it satisfies, so an evidence pack for the EU AI Act, DORA or a sector regulator assembles from the same data.

Questions about AI governance platforms

What is an AI governance platform?

An AI governance platform is software that enforces who may run which AI agents and models, on which data and with what approvals, and records every prompt, retrieval, tool call and output as evidence. It differs from a policy document, which describes intent, and from an observability tool, which watches after the fact: a governance platform decides at runtime and keeps the proof.

What is the difference between AI governance, AI agent governance and model governance?

Model governance covers how models are selected, evaluated, versioned and retired. AI agent governance covers what an agent may access and do, and how its actions are approved and attributed. AI governance is the programme that spans both, plus data, people and regulation. VDF AI implements all three layers in one runtime so the evidence for each comes from the same source.

Does VDF AI cover EU AI Act obligations for deployers?

It covers the technical obligations a deployer must evidence: an inventory of AI systems with risk classification, human oversight for high-risk use, logging that can reconstruct a decision, data governance and residency, and the ability to suspend a system. The compliance roadmap on this site maps ten enterprise use cases to those obligations, and the EU AI Act agent catalogue automates the classification and reporting work.

Can an AI governance platform govern agents we built with other tools?

Yes. Agents built with frameworks such as LangChain or CrewAI, or assistants running in Microsoft Copilot or IBM watsonx, can be registered so their tool access, approvals and audit run through VDF AI. The registration playbook walks through it. Governance that only applies to agents built inside one product leaves the rest of the estate ungoverned.

Is VDF AI a responsible AI platform or a secure AI platform?

It is both in practice, because the same controls deliver them. Responsible AI needs transparency, human oversight and traceable decisions; a secure AI platform needs scoped credentials, prompt-injection containment, data boundaries and containment controls. VDF AI treats these as one governance layer, deployable on-premises or in a sovereign cloud so the evidence never leaves your jurisdiction.

AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Read the governance guide