AI governance tools are software that keep an inventory of an organisation's AI systems, run risk and compliance workflows against frameworks such as the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, and enforce controls on models and agents while they run. No product covers every layer equally well, so most enterprises end up combining two or three.
Four layers AI governance software can cover
Search for AI governance software and you will find products that share a category name and little else. A privacy suite, a data catalogue, an ML model registry and an agent runtime can each call itself a governance tool, and each is accurate about its own slice. The useful question for a buyer is which layer a product actually governs.
- Inventory and registry. What AI exists, who owns it, which version is live and what it was built from. This ranges from ML model registries to enterprise-wide discovery of third-party and shadow AI.
- Risk and compliance workflow. Assessments, approvals, policy libraries and evidence mapped to a framework. EU AI Act, ISO/IEC 42001 and NIST AI RMF templates live here.
- Runtime and agent controls. What a model or agent may do at the moment it acts: which tools it may call, which data it may read, which actions wait for a person, and what gets written to the audit trail.
- Data governance. Classification, lineage, retention and loss prevention for the data that trains, grounds and passes through AI systems.
The frameworks decide what evidence each layer must produce. The European Commission’s AI Act page, updated on 3 August 2026, says rules for high-risk areas such as biometrics, critical infrastructure, education and employment apply from 2 December 2027, and from 2 August 2028 for AI built into regulated products, after the AI Omnibus entered into force on 27 July 2026. NIST released AI RMF 1.0 in January 2023 as a voluntary framework built around Govern, Map, Measure and Manage, and states that it is being revised. ISO/IEC 42001 sets requirements for establishing, running and continually improving an AI management system. How those regimes translate into platform behaviour, control by control, is covered in our regulation-to-control mapping.
AI governance tools compared
The table places each product in the layer its own site leads with. The frameworks column lists only what the vendor names on the page cited in the sources, so a blank means we did not find it stated, not that support is missing. Verified September 2026.
| Tool | Main layer | What the vendor says it covers | Frameworks named by the vendor | Delivery, where stated |
|---|---|---|---|---|
| Credo AI | Risk and compliance workflow | AI registry with discovery of agents, models and shadow AI; risk scoring; regulatory packs with evidence generation; runtime monitoring with human escalation | EU AI Act, NIST AI RMF, ISO 42001, SOC 2 | SDKs, APIs and 30+ ecosystem integrations |
| IBM watsonx.governance | Lifecycle, risk and compliance | Lifecycle governance, risk management, continuous monitoring, governance of agentic AI | EU AI Act, NIST, ISO 42001 | Cloud and on-premises |
| Holistic AI | Discovery, testing and compliance | Discovery across cloud, code and SaaS; 40+ tests for bias, hallucination, privacy and robustness; red teaming; Guardian Agents for runtime oversight | EU AI Act, NIST AI RMF, ISO/IEC 42001 | |
| OneTrust AI Governance | Inventory, risk and policy | Discovery of systems, models, agents, datasets and vendors; assessments; policies turned into controls; an SDK that blocks or redacts sensitive data | EU AI Act, NIST AI RMF, ISO 42001 | |
| ServiceNow AI Control Tower | Enterprise inventory and workflow | Discovery through integrations with AWS, Google Cloud, Azure, SAP, Oracle and Workday; risk frameworks; an AI Gateway for MCP transactions | NIST, EU AI Act | Part of the ServiceNow AI Platform |
| Microsoft Purview | Data security and compliance for AI use | DSPM for AI, DLP, sensitivity labels, audit, eDiscovery and retention for Copilot and other AI apps | EU AI Act, ISO/IEC 23894, ISO/IEC 42001, NIST AI RMF (Compliance Manager) | Microsoft Purview portal |
| Collibra AI Governance | Data lineage and use-case registry | System of record for AI use cases, models and agents; lineage from data to decisions; an AI Trust Score | EU AI Act, NIST AI RMF, AI UC-1 | |
| MLflow Model Registry | Model registry | Versions, aliases, tags, annotations and lineage to the run that produced each model | Open source (Apache 2.0); also managed on Databricks | |
| NVIDIA NeMo Guardrails | Runtime guardrails in one app | Input, dialog, retrieval, execution and output rails for LLM applications | Open source (Apache 2.0) | |
| VDF AI | Runtime governance for orchestrated agents | Agent and model registry, per-role tool grants, human approval gates, an audit trail of tool calls, regulation-mapped evidence | EU AI Act, DORA, NIS2, GDPR, ISO 42001 | On-premises, private cloud or air-gapped |
Risk and compliance workflow platforms
These products start from the compliance team’s questions. Which AI systems do we have, what risk class is each one, and can we prove the required assessments happened? They are strongest at registers, questionnaires, approvals and evidence, and several added monitoring features during 2026.
Credo AI
Credo AI says it was built for AI governance from the start rather than adapted from a general GRC product. Its product page lists an AI registry that auto-discovers agents, models and shadow AI across cloud environments, dynamic risk scoring, regulatory packs for the EU AI Act, NIST AI RMF, ISO 42001 and SOC 2 with automated evidence, and agent governance with dependency mapping and trace-level monitoring. It names more than 30 ecosystem partners, among them AWS, Azure, GCP, Databricks, ServiceNow and GitHub.
IBM watsonx.governance
IBM frames watsonx.governance around real-time visibility, enterprise controls and continuous accountability for AI systems. The product page names the EU AI Act, NIST and ISO 42001, describes continuous monitoring for compliance and operational issues, and covers agentic AI with embedded assistants that automate onboarding. It is one of the few products here whose page states both cloud and on-premises deployment, which matters when governance records themselves cannot sit in a vendor’s cloud.
Holistic AI
Holistic AI combines discovery, testing and compliance in one platform. It says it finds models, agents and AI applications across cloud, code and SaaS, runs more than 40 tests for bias, hallucination, privacy and robustness alongside red teaming, and maps controls to the EU AI Act, NIST AI RMF and ISO/IEC 42001. Its Guardian Agents are described as watching agent actions, checking them against policy and intervening when a threshold is crossed.
OneTrust AI Governance
OneTrust brings AI into a platform that many privacy and risk teams already operate. Its page covers continuous discovery of AI systems, models, agents, datasets and vendors, assessments built from EU AI Act, NIST AI RMF and ISO 42001 templates, and policies expressed as controls across in-house and third-party AI. The AI Guard SDK is described as blocking, redacting or restricting sensitive data before it reaches a model. Named integrations include Amazon Bedrock, Microsoft Azure Foundry, Google Vertex, Databricks and Jira.
ServiceNow AI Control Tower
ServiceNow places governance inside the platform where IT already runs its workflows. Its 5 May 2026 announcement added discovery of AI assets outside ServiceNow through 30 new integrations spanning AWS, Google Cloud, Azure, SAP, Oracle and Workday, five risk frameworks aligned to NIST and the EU AI Act, and an AI Gateway that applies real-time controls to customers’ MCP transactions. ServiceNow said the Control Tower enhancements were expected to reach general availability in August 2026.
Data and security governance for AI
A second group governs AI from the data side. These tools are the natural anchor when the main risk is what employees paste into AI apps, or what those apps retrieve on their behalf.
Microsoft Purview
Purview extends Microsoft’s information protection and compliance controls to AI use. Microsoft’s documentation covers Data Security Posture Management for AI, sensitivity labels that AI apps respect, endpoint DLP that can warn or block users pasting sensitive data into third-party generative AI sites, audit records of prompts and responses, eDiscovery and retention. Coverage spans Microsoft 365 Copilot and Copilot Studio, enterprise AI apps such as Microsoft Foundry, ChatGPT Enterprise and Anthropic Claude Enterprise, and other AI apps detected through browser activity. Compliance Manager adds four premium AI templates: the EU AI Act, ISO/IEC 23894, ISO/IEC 42001 and NIST AI RMF 1.0. Its reach is widest where the estate is already built on Microsoft.
Collibra AI Governance
Collibra comes at AI from the data catalogue. Its page describes a single system of record for AI use cases, models and agents, lineage that follows data from source through training, inference and deployment, and assessment templates for the EU AI Act, NIST AI RMF and the emerging AI UC-1 standard. An AI Trust Score rolls documentation, data integrity, lifecycle status and regulatory signals into one readiness figure per system. AWS, Azure, Databricks, Google Cloud and MLflow are among the platforms it lists.
Model registries and open-source building blocks
Open-source components handle individual controls well. What they do not supply on their own is the programme around them: owners, approvals, risk classes and evidence a regulator can read.
MLflow Model Registry is documented as a centralised model store, set of APIs and UI for managing a model’s lifecycle. It tracks versions, supports aliases such as @champion, tags and Markdown annotations, and links each version back to the run that produced it. MLflow is Apache 2.0 licensed, and its repository now also describes tracing, evaluation and an AI gateway. A registry answers which version is live and where it came from, which every governance programme needs, but it is not a risk workflow.
NVIDIA NeMo Guardrails is an Apache 2.0 toolkit for adding programmable guardrails to LLM applications through input, dialog, retrieval, execution and output rails. It helps an application resist jailbreaks, prompt injection and off-topic answers. It keeps no inventory and maps nothing to a regulation, so it sits beside a governance platform rather than standing in for one.
Runtime governance for AI agents
The newest layer decides, at the moment an agent acts, whether it may. Agents that call tools update records, send messages and start workflows, so the control has to sit in the execution path. A dashboard that reports an unapproved action the next morning documents a failure; it did not prevent one.
Runtime governance for agents usually covers five things. Per-role grants decide which tools and data an agent may use. Approval gates hold consequential actions for a named reviewer. Model policy restricts which models a workload may call. An audit record binds the prompt, retrieval, tool call and outcome together. And a stop control can halt an agent, a workflow or a model quickly. Tool traffic increasingly passes through an MCP gateway, and model traffic through an AI gateway.
Workflow vendors are moving into this layer. Credo AI lists runtime monitoring with human-in-the-loop escalation, OneTrust an SDK that blocks or redacts data before a model sees it, Holistic AI agents that intervene on threshold breaches, and ServiceNow a gateway for MCP transactions. When you evaluate them, ask whether each control is enforced before the action or observed after it, and where the enforcement point runs relative to your data. Our twelve-control agent governance checklist gives that test a structure.
How to choose AI governance software
Begin with the evidence you will be asked to produce, then work back to the tool.
- List the AI you actually run. Copilots and SaaS assistants, in-house ML models, and agents that act on internal systems each lean on a different layer. Many estates have all three.
- Name the evidence owner. When compliance owns the register and the assessments, a workflow platform is the anchor. When security owns data loss and oversharing, begin with data governance. When platform engineering is putting agents into production, runtime controls come first.
- Decide where governance records may live. Prompts, retrieved passages and tool outputs in an audit log are sensitive data in their own right. Check whether a product runs in your environment or only as SaaS; few vendor pages say so clearly.
- Ask for an exported evidence pack, not a demo. Choose one real use case and ask each shortlisted vendor to produce the assessment, the approval record and the log extract a supervisor would request.
- Test the handover between layers. A register entry should point to the runtime policy that enforces it, and a runtime incident should trace back to the owner in the register. The gaps between tools are where most governance and compliance problems appear.
A rough guide by starting problem:
| If your first problem is | Start with | Then add |
|---|---|---|
| Nobody knows which AI systems exist | An inventory and workflow platform such as Credo AI, OneTrust, ServiceNow or Holistic AI | Runtime controls for the agents the inventory finds |
| Sensitive data flowing into Copilot or public chatbots | Data security controls such as Microsoft Purview | A register for the AI apps you approve |
| Model sprawl across data science teams | A model registry such as MLflow, with lineage from a catalogue such as Collibra | A risk workflow for high-risk uses |
| Agents about to act on production systems | Runtime governance: tool grants, approval gates, audit | A workflow platform for assessments and sign-off |
How VDF AI fits
VDF AI sits in the runtime layer. The VDF AI governance platform registers every agent, network and model with an owner, purpose, risk class and version. An administrator grants tools per role, so an agent can reach only the tools its role holds. Consequential steps in VDF AI Networks can wait at a human approval gate, and every tool call is written to the audit trail with the agent that made it. Decision receipts bind the prompt, sources, model, tool calls and outcome of each consequential output, and evidence packs for the EU AI Act or a sector audit are assembled from those same records. It deploys on-premises, in a private cloud or air-gapped.
Its scope is the agents VDF AI orchestrates. Agents already built on watsonx, Copilot Studio or other platforms can be registered as tools and called from a governed VDF AI Network, so those calls pass through the same tool grants and audit trail. It does not replace a GRC questionnaire suite, a data catalogue or Purview’s controls over Copilot use, and many organisations will run it alongside one of those. For classification and reporting work closer to the compliance layer, see the EU AI Act agents.
Sources
- Credo AI product page
- IBM watsonx.governance
- Holistic AI platform
- OneTrust AI Governance
- ServiceNow AI Control Tower announcement, May 2026
- Microsoft Purview protections for AI apps
- Compliance Manager AI regulation templates
- Collibra AI Governance
- MLflow Model Registry documentation
- MLflow repository and licence
- NeMo Guardrails repository
- EU AI Act, European Commission
- NIST AI Risk Management Framework
- ISO/IEC 42001 summary, Microsoft Learn