<Post

Microsoft Moves AI Governance from Policy to Runtime Enforcement

Microsoft’s architecture treats AI governance as an operational loop: policies define requirements, runtime controls enforce them, observability records behavior, evaluations test quality and safety, and audit turns telemetry into evidence.

The model spans nine domains—policy, data, model, observability, evaluations, security, identity/access, audit/compliance, and agent governance—and explicitly covers users, agents, models, tools, APIs, MCP servers, and enterprise systems. Foundry’s AI Gateway supplies authentication, quotas, token limits, and policy enforcement; Microsoft’s MCP guidance adds centralized authentication, rate limiting, IP restrictions, and audit logging without changing each MCP server or agent.

The useful shift is from “we have a policy” to “production can prove the policy was applied.” The caveat is that this is Microsoft’s platform architecture, mapping broader NIST risk-management concepts onto Foundry, Purview, Entra, Defender, and Azure API Management. InfoQ provides no source comment section for representative reactions.