started · updated
Microsoft shifts AI governance from policy to runtime execution
Microsoft is shifting its artificial intelligence governance strategy from advisory policies to enforceable, technical runtime controls. This new framework aims to provide organizations with measurable security across identity, data, runtime, gateways, and monitoring to support the deployment of AI applications and autonomous agents in production environments.
The architecture focuses on nine governance domains, including data, model, security, and agent governance. By integrating services such as Microsoft Foundry, Microsoft Purview, Microsoft Entra ID, and Defender, the system creates a runtime boundary for authentication, token limiting, and policy execution. A key component is the AI gateway, which allows for centralized management of tools and agents without requiring code modifications to the underlying servers.
For managed service providers (MSPs), this shift offers practical tools to manage agent sprawl, enforce identity-based access, and implement human-in-the-loop requirements for high-risk actions. The framework emphasizes a continuous operational loop where policies define rules, runtime controls execute them, observability captures behavior, and assessments verify quality and safety, ultimately turning telemetry into audit evidence.
Entities
Microsoft · Microsoft Entra ID · Microsoft Foundry · Microsoft Purview · NIST