Microsoft Shifts AI Governance from Policy to Runtime Enforcement
Microsoft has introduced an AI governance architecture that shifts focus from written policies to runtime enforcement. The framework, which spans nine governance domains and four functions, aims to ensure that AI system operation aligns with governance requirements.
The architecture treats governance as a continuous operational loop. Policies establish requirements and risk classifications, controls translate them into access and runtime rules, observability captures system behavior, and evaluations test quality and safety. Audit processes then turn operational telemetry into evidence for compliance and incident investigation.
Microsoft identifies nine governance domains: policy, data governance, model governance, observability, evaluations, security, identity and access, audit and compliance, and agent governance. Runtime controls can span interactions among users, agents, models, tools, APIs, MCP servers, and enterprise systems.