AI Governance Platform
Every Agent Registered, Every Decision Auditable
An AI governance platform is software that enforces who may run which AI agents and models, on which data and with what approvals, and records every prompt, tool call, retrieval and output as evidence. VDF AI builds governance into the runtime itself: policy, role-based access, approval gates and an immutable audit vault, deployable on-premises or in a sovereign cloud.
Governance you can query, not a policy you hope people follow.
Built for CISOs, compliance officers and heads of risk.
We map your controls to what production and regulators require.
Four questions a regulator will ask
- Who triggered this agent, under which role, and was that role entitled to?
- What data did it read, and did that data ever leave your controlled environment?
- Which model produced the output, which version, and who approved that model for this use?
- Did a human review the action before it took effect, and can you show the review?
How VDF AI answers them
- Identity and entitlements from your directory, enforced per agent and per tool
- Data boundaries by deployment mode, with egress control you can verify
- Model policy in the router, with evaluation history in the evaluation suite
- Approval gates with decision receipts in the Vault
- The framework behind it: what AI agent governance is
Governance on Paper
or Governance in the Loop
Governance as a document
- An AI policy that engineers have not read since onboarding
- A spreadsheet of AI systems that was accurate last quarter
- Approvals in email threads nobody can find
- Logs scattered across vendors in different formats
- A guardrail library bolted on to one application
- An audit that starts with an all-hands data hunt
Governance as a platform
- Policy evaluated on every request before the model runs
- A live registry that cannot fall out of date
- Approvals recorded with the run they authorised
- One immutable Vault for prompts, retrievals, tools and outputs
- Controls applied to every agent, including registered third-party ones
- An evidence pack generated from the same store
Register. Approve.
Prove.
Register and control
Every agent, network and model has an owner, a purpose and a risk class in the registry. Role-based access decides which tools and knowledge sources each may use, and the MCP tool registry makes the grant explicit.
Approve and oversee
Autonomy levels set what an agent may do alone. Consequential actions wait at an approval gate for a named person, and the review, the reviewer and the elapsed time are stored with the run.
Prove
The Vault keeps a cryptographically durable record of each execution. Decision receipts bind prompt, sources, model, tools and outcome, and an evidence pack for the EU AI Act or a sector audit assembles from it.
Where governance can live
| Control | Cloud AI suite guardrails | Bolt-on observability tool | VDF AI governance platform |
|---|---|---|---|
| Inventory of agents and models | Within that suite | What it can see | Complete, including registered third-party agents |
| Data boundary | The vendor's cloud | Not enforced | Enforced per deployment mode, air-gapped included |
| Model choice policy | Vendor's models only | Observed, not enforced | Enforced by the router per step |
| Human oversight | Application-specific | Alerts after the fact | Approval gates before the action |
| Evidence export | Vendor log export | Traces | Regulation-mapped evidence pack |
| Containment | Per application | None | Kill switch for agent, network or model |
Eight evidence artifacts an AI governance platform must produce
If a platform cannot generate these from its own records, governance is still a manual exercise. The twelve-control matrix that sits behind this list is in the AI agent governance guide, and the regulation-by-regulation mapping is in the governance framework for regulated industries.
- Agent and model inventoryA registry of every agent, network and model in use, with an owner, a purpose, a risk class and a version, exportable on request.
- Access and entitlement recordsWho may invoke which agent, which tools it may call and which knowledge sources it may read, resolved from your directory.
- Data boundary attestationProof of where prompts, embeddings and outputs were processed and stored, per deployment mode, with no hidden egress.
- Human oversight logEvery approval gate, who approved, what they saw and how long it waited, mapped to the oversight duties of high-risk use.
- Decision receiptsFor each consequential output, the prompt, retrieved sources, model, tool calls and final action bound together and hashed.
- Model change historyWhen a model was introduced, evaluated, promoted or retired, with the evaluation results that justified it.
- Incident and kill-switch recordContainment actions taken, when, by whom, and the state preserved for the post-incident review.
- Regulation mappingEach control tied to the article or clause it satisfies, so an evidence pack for the EU AI Act, DORA or a sector regulator assembles from the same data.
Governance resources and deployment options
Reference material for compliance teams and the deployment modes where the evidence stays inside your jurisdiction.
- EU AI Act compliance roadmapTen enterprise use cases from inventory to impact assessment.
- EU AI Act governance agentsClassification, literacy, bias audit and reporting agents.
- Governance and security handbookIdentity records, permission order, tool contracts and trace schema.
- Register an existing agentBring Copilot or watsonx agents under one governance layer.
- On-Premises AI GovernanceControls and architecture for this deployment mode.
- Sovereign AI GovernanceControls and architecture for this deployment mode.
- Trust centreSecurity architecture, residency options and compliance posture.
- AI agent platformThe platform these controls govern.
Questions about AI governance platforms
What is an AI governance platform?
An AI governance platform is software that enforces who may run which AI agents and models, on which data and with what approvals, and records every prompt, retrieval, tool call and output as evidence. It differs from a policy document, which describes intent, and from an observability tool, which watches after the fact: a governance platform decides at runtime and keeps the proof.
What is the difference between AI governance, AI agent governance and model governance?
Model governance covers how models are selected, evaluated, versioned and retired. AI agent governance covers what an agent may access and do, and how its actions are approved and attributed. AI governance is the programme that spans both, plus data, people and regulation. VDF AI implements all three layers in one runtime so the evidence for each comes from the same source.
Does VDF AI cover EU AI Act obligations for deployers?
It covers the technical obligations a deployer must evidence: an inventory of AI systems with risk classification, human oversight for high-risk use, logging that can reconstruct a decision, data governance and residency, and the ability to suspend a system. The compliance roadmap on this site maps ten enterprise use cases to those obligations, and the EU AI Act agent catalogue automates the classification and reporting work.
Can an AI governance platform govern agents we built with other tools?
Yes. Agents built with frameworks such as LangChain or CrewAI, or assistants running in Microsoft Copilot or IBM watsonx, can be registered so their tool access, approvals and audit run through VDF AI. The registration playbook walks through it. Governance that only applies to agents built inside one product leaves the rest of the estate ungoverned.
Is VDF AI a responsible AI platform or a secure AI platform?
It is both in practice, because the same controls deliver them. Responsible AI needs transparency, human oversight and traceable decisions; a secure AI platform needs scoped credentials, prompt-injection containment, data boundaries and containment controls. VDF AI treats these as one governance layer, deployable on-premises or in a sovereign cloud so the evidence never leaves your jurisdiction.
Is your AI governance audit-ready?
Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.