> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getcollate.io/llms.txt
> Use this file to discover all available pages before exploring further.

# AI Governance

> Register AI assets, detect shadow AI, track compliance against EU AI Act and other regulatory frameworks, manage approvals, and export audit packs.

# AI Governance

<Note>
  **Note**: AI Governance is in Preview. It's under active development, and some areas of this guide will change as the feature matures.
</Note>

AI Governance is a governance layer over the AI systems your organization actually uses: **AI Applications**, **LLM Models**, and **MCP Servers**. It gives you a single place to register those assets, catch usage that was never registered ("shadow AI"), classify risk under regulatory frameworks like the EU AI Act, route new assets through an approval workflow, and export audit-ready evidence.

## Before You Start

* Collate AI (AskCollate) must be installed and enabled in your workspace. AI Governance is part of the AI experience, and its pages aren't reachable until AskCollate is on.
* AI Governance lives inside the **Governance** module, under a dedicated **AI Assets** section, not as its own top-level product area.

## Access AI Governance

1. In the left navigation bar, select **Governance**.
2. Under the **AI Assets** section, select **Overview**.

   <img src="https://mintcdn.com/collatedocs/w2C-PZRVxOrBSkyU/public/images/ai-2.0/collate-ai/ai-governance/overview.png?fit=max&auto=format&n=w2C-PZRVxOrBSkyU&q=85&s=a73c93dabcac9693f2f094b3a920b69e" alt="AI Governance Overview page" width="2986" height="1622" data-path="public/images/ai-2.0/collate-ai/ai-governance/overview.png" />

The **AI Assets** section contains seven pages:

| Page | What it's for |
| - | - |
| **Overview** | A dashboard of your AI estate's compliance posture (covered on this page) |
| **[AI Asset Registry](/ai-2-0/collate-ai/ai-governance/asset-registry)** | Register an AI Application, and open any asset's detail page |
| **[Shadow AI](/ai-2-0/collate-ai/ai-governance/shadow-ai)** | Review AI usage detected outside the registration process |
| **[Approvals](/ai-2-0/collate-ai/ai-governance/approvals)** | Review and approve or reject assets pending registration |
| **[Frameworks](/ai-2-0/collate-ai/ai-governance/frameworks)** | Enable built-in regulatory frameworks or create custom ones |
| **[Policies & Drift](/ai-2-0/collate-ai/ai-governance/policies-and-drift)** | Review built-in AI policies and the assets that breach them |
| **[Audit Reports](/ai-2-0/collate-ai/ai-governance/audit-reports)** | Export an audit pack of your compliance evidence |

## Overview Page

The Overview page is a dashboard summarizing your AI estate's registration and compliance status. It has four parts.

### Summary Banner

A one-line summary of items needing attention is followed by EU AI Act readiness, the number of assets classified High risk, and the number of currently unregistered AI assets.

The **Configure Risk Council** link on the right takes you to the Approvals page, where reviewers approve or reject pending assets.

### Stat Cards

Five cards summarize the current state of your AI estate:

| Card | What it shows |
| - | - |
| **AI Assets in Catalog** | Total AI Applications, LLM Models, and MCP Servers, regardless of registration status |
| **High-risk Classified** | Assets currently classified High risk |
| **Shadow AI Detected** | AI assets currently unregistered |
| **Pending Approvals** | Assets currently awaiting review |
| **EU AI Act Readiness** | Percentage of applicable EU AI Act controls currently met |

The current interface labels the Shadow AI figure "last 14 days" in the banner and "Last 7 days" on its card. The Pending Approvals and EU AI Act Readiness cards also say "Last 7 days." These figures aren't filtered by those time windows. The catalog card's "this week" count is a fixed zero, and the High-risk card's "awaiting owner" count displays pending approvals.

<Note>
  **Note**: Readiness percentages reflect how far your assessments have progressed, not a declaration that your organization is legally compliant. Treat them as a progress indicator for your governance work, not a compliance attestation.
</Note>

### Risk Classification

A matrix of your AI estate's EU AI Act risk levels (Unacceptable, High, Limited, Minimal) against estimated affected-user-count bands (`<1k`, `1k-10k`, `10k-100k`, `>100k`). Each non-empty cell shows the asset count and, for a small count, the asset name. Click **Live** to refresh the matrix against current data.

### Framework Readiness

A compliance summary per enabled framework (for example, EU AI Act, NIST AI RMF, or ISO/IEC 42001), showing controls met out of the total and a percentage readiness bar. A framework can carry a **FOCUS** badge to flag it as the framework you're currently prioritizing. Select **All frameworks** to open the full Frameworks page.

## What You Can Do

* Register an AI Application through a guided intake wizard that captures its type, deployment stage, data access, and EU AI Act risk classification.
* Review AI usage detected outside the registration process and register or dismiss it.
* Approve or reject assets pending review, with automatic intake checks for an owner, risk classification, fairness evidence, a data protection impact assessment (DPIA) reference, and transparency disclosure.
* Enable built-in regulatory frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001, and others), or create a custom one.
* Review built-in AI policies, such as personally identifiable information (PII) access and fairness checks, and see which assets breach them.
* Export an audit pack: a PDF and/or JSON evidence bundle scoped to your whole estate, a domain, or a single asset.

## Role-Based Access Control (RBAC)

AI Governance doesn't have its own role model. Permissions come from Collate's standard resource/operation system, applied to six resources: **AI Application**, **LLM Model**, and **MCP Server** (the AI asset types themselves), plus **AI Governance Framework**, **AI Governance Policy**, and **Audit Report**. Whether a user can register, edit, approve, reject, or delete depends on the Create, Edit, and Delete permissions granted on these resources through their roles. There's no separate "reviewer" or "risk council" permission. Anyone with edit access to an asset's resource type can approve or reject it in the Approvals queue.

To create rules and attach policies to roles, see [Roles and Policies](/ai-2-0/admin-guide/roles-policies).
