Microsoft has outlined an AI governance architecture that treats policy as a set of controls and evidence running alongside production applications, rather than a document checked only before launch. The framework covers nine areas, including data, models, security, identity, evaluations, audit and agent governance.
Its operating loop has four functions: policy defines requirements, controls enforce them, visibility records behavior and proof turns telemetry into audit evidence. Microsoft Foundry's AI Gateway can apply authentication, token quotas, rate limits and other rules to traffic among users, agents, models, APIs and Model Context Protocol tools. Evaluations can run before release and continue against production behavior.
The approach addresses a real gap: organizations cannot prove that an agent followed a rule if they cannot see its tool calls and access decisions. Much of the implementation uses Microsoft services such as Purview, Entra ID, Defender and Azure API Management, so teams on mixed infrastructure will need equivalent controls or integrations. A governance diagram is not assurance by itself; operators must configure, test and review the enforcement points continuously.