Skip to main content

AI Governance

Note: AI Governance is in Preview. It’s under active development, and some areas of this guide will change as the feature matures.
AI Governance is a governance layer over the AI systems your organization actually uses: AI Applications, LLM Models, and MCP Servers. It gives you a single place to register those assets, catch usage that was never registered (“shadow AI”), classify risk under regulatory frameworks like the EU AI Act, route new assets through an approval workflow, and export audit-ready evidence.

Before You Start

  • Collate AI (AskCollate) must be installed and enabled in your workspace. AI Governance is part of the AI experience, and its pages aren’t reachable until AskCollate is on.
  • AI Governance lives inside the Governance module, under a dedicated AI Assets section, not as its own top-level product area.

Access AI Governance

  1. In the left navigation bar, select Governance.
  2. Under the AI Assets section, select Overview. AI Governance Overview page
The AI Assets section contains seven pages:

Overview Page

The Overview page is a dashboard summarizing your AI estate’s registration and compliance status. It has four parts.

Summary Banner

A one-line summary of items needing attention is followed by EU AI Act readiness, the number of assets classified High risk, and the number of currently unregistered AI assets. The Configure Risk Council link on the right takes you to the Approvals page, where reviewers approve or reject pending assets.

Stat Cards

Five cards summarize the current state of your AI estate: The current interface labels the Shadow AI figure “last 14 days” in the banner and “Last 7 days” on its card. The Pending Approvals and EU AI Act Readiness cards also say “Last 7 days.” These figures aren’t filtered by those time windows. The catalog card’s “this week” count is a fixed zero, and the High-risk card’s “awaiting owner” count displays pending approvals.
Note: Readiness percentages reflect how far your assessments have progressed, not a declaration that your organization is legally compliant. Treat them as a progress indicator for your governance work, not a compliance attestation.

Risk Classification

A matrix of your AI estate’s EU AI Act risk levels (Unacceptable, High, Limited, Minimal) against estimated affected-user-count bands (<1k, 1k-10k, 10k-100k, >100k). Each non-empty cell shows the asset count and, for a small count, the asset name. Click Live to refresh the matrix against current data.

Framework Readiness

A compliance summary per enabled framework (for example, EU AI Act, NIST AI RMF, or ISO/IEC 42001), showing controls met out of the total and a percentage readiness bar. A framework can carry a FOCUS badge to flag it as the framework you’re currently prioritizing. Select All frameworks to open the full Frameworks page.

What You Can Do

  • Register an AI Application through a guided intake wizard that captures its type, deployment stage, data access, and EU AI Act risk classification.
  • Review AI usage detected outside the registration process and register or dismiss it.
  • Approve or reject assets pending review, with automatic intake checks for an owner, risk classification, fairness evidence, a data protection impact assessment (DPIA) reference, and transparency disclosure.
  • Enable built-in regulatory frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001, and others), or create a custom one.
  • Review built-in AI policies, such as personally identifiable information (PII) access and fairness checks, and see which assets breach them.
  • Export an audit pack: a PDF and/or JSON evidence bundle scoped to your whole estate, a domain, or a single asset.

Role-Based Access Control (RBAC)

AI Governance doesn’t have its own role model. Permissions come from Collate’s standard resource/operation system, applied to six resources: AI Application, LLM Model, and MCP Server (the AI asset types themselves), plus AI Governance Framework, AI Governance Policy, and Audit Report. Whether a user can register, edit, approve, reject, or delete depends on the Create, Edit, and Delete permissions granted on these resources through their roles. There’s no separate “reviewer” or “risk council” permission. Anyone with edit access to an asset’s resource type can approve or reject it in the Approvals queue. To create rules and attach policies to roles, see Roles and Policies.