AI Governance

AI Governance Platforms: The Category Map Nobody Publishes

Search for one and you will find ten listicles, each written by a vendor that ranks itself first. None of them publish prices.

Definition

An AI governance platform is software that gives an organization visibility and control over its AI — what exists, who approved it, how it behaves, and whether it meets policy and regulatory obligations. The term covers at least five distinct product categories that solve different problems, which is why comparison shopping in this market is so frustrating.

Search for one and you will find ten listicles, each written by a vendor that ranks itself first. None of them publish prices. Few of them admit that the products on their list are not substitutes for one another.

This page is the map. It includes where PromptFluent is the wrong answer.

Key takeaways

  • “AI governance platform” is not one category. It is five: model risk and assurance, GRC and privacy platforms extending into AI, data governance platforms extending into AI, AI observability and evaluation, and execution-layer governance. They are complements more often than competitors.

  • No major vendor publishes pricing. We checked IBM, Credo AI, OneTrust and Collibra on 10 September 2026. All four route to “request a demo.”

  • Adoption is going backwards. Among the 602 breached organizations in IBM’s 2026 study, 68% lacked AI governance to manage AI or detect shadow AI — worse than the 63% recorded a year earlier.

  • Among the organizations in that study that did enforce AI governance, only about a third used AI governance technology (33%) — and formal approval processes for AI deployments fell from 45% to 38%.

  • Governance and security teams coordinated in 19% of them.

  • Start from the problem you actually have. The category you need follows from that, not from a vendor’s ranking of itself.

Category Map

The five categories of AI governance platform

Every product below is legitimately described as an AI governance platform by the company that sells it. They govern different objects.

1.Model risk and AI assurance platforms

What they govern:
models, use cases, and the regulatory obligations attached to them. Model registries, risk scoring, bias and fairness testing, documentation, evidence packs mapped to frameworks like the EU AI Act, NIST AI RMF and ISO/IEC 42001.
Who buys:
Chief AI Officers, model risk management, regulated-industry compliance teams.
Representative vendors:
IBM watsonx.governance, which describes itself as helping enterprises “govern any AI, anywhere with real-time visibility, enterprise controls, and continuous accountability.” Credo AI, which describes its product as letting you “Discover, assess, govern, monitor, and report on every AI agent, model, and application across your enterprise.” Holistic AI is another pure-play in this segment.
What they do not do:
tell you whether the prompt someone pasted into an approved tool on Tuesday was the approved version.

2.GRC and privacy platforms extending into AI

What they govern:
organizational risk and compliance posture, with AI added as a new risk domain alongside privacy, third-party risk and security.
Who buys:
the team that already owns GRC. This is usually an expansion of an existing contract rather than a new purchase.
Representative vendor:
OneTrust, whose AI governance product offers to “Turn AI policy into controls that work across homegrown and third-party AI.”
What they do not do:
replace the specialist depth of a model-risk platform on model behavior itself.

3.Data governance platforms extending into AI

What they govern:
data first — catalog, lineage, quality, access — with AI use cases layered on, because AI risk is substantially data risk.
Who buys:
the Chief Data Officer, usually where a data catalog is already deployed.
Representative vendor:
Collibra, which describes its AI governance product as one that “Unifies AI, data and risk teams around a shared system of record for all AI initiatives.”
What they do not do:
govern AI that touches no governed data — which describes most everyday generative AI use.

4.AI observability and evaluation (LLMOps)

What they govern:
model and application behavior in production. Traces, evaluations, drift, latency, cost, regression testing on prompts and chains.
Who buys:
engineering and ML platform teams. Frequently bought without the governance function knowing.
What they do not do:
produce the approval records, ownership and policy evidence an auditor asks for. These are engineering instruments wearing a governance label.

5.Execution-layer governance

What they govern:
how AI work is actually performed by people. The prompts, workflows, versions, approvals and execution records that determine whether AI-assisted work is consistent, attributable and reconstructable.
Who buys:
operations leaders, AI centers of excellence, and functional leaders whose teams use AI daily.
Representative vendor:
PromptFluent. This is our category, and we are ranking ourselves inside it. Treat that with the skepticism it deserves — see Where PromptFluent fits, and where it does not.
What it does not do:
govern models, model risk or model selection. It does not detect AI usage occurring entirely outside the platform.

Category comparison

The five AI governance platform categories compared by what they govern, primary buyer, and which of the two core questions each answers
CategoryGovernsPrimary buyerAnswers “is this model safe?”Answers “what did we actually do with AI?”
Model risk & assuranceModels, use cases, regulatory obligationsCAIO, model risk, complianceYesPartially — at the use-case level
GRC / privacy extending into AIOrganizational risk postureRisk, privacy, compliancePartiallyNo
Data governance extending into AIData, lineage, and AI built on itCDO, data governancePartially — data dimensionNo
AI observability / LLMOpsModel and application behavior in productionEngineering, ML platformPartially — behavior, not policyPartially — at the trace level
Execution-layer governancePrompts, workflows, approvals, execution recordsOperations, AI CoE, function leadsNoYes

Read the last two columns together. Most organizations buy one of the first four and assume the last column is covered. It is not, and the 2026 evidence shows what that costs.

The Evidence

What the 2026 evidence actually says

The most striking finding in this category is not that AI governance is hard. It is that adoption moved in the wrong direction.

IBM and Ponemon’s Cost of a Data Breach Report 2026 studied 602 organizations breached between March 2025 and February 2026, across 17 industries and 16 countries and regions. Among them:

Across all 602 breached organizations studied:

AI governance coverage across all 602 breached organizations, 2026 compared with 2025
Finding20262025
Lacked AI governance to manage AI or detect shadow AI68%63%
Reported they were developing governance policies33%22%

Among those that did enforce AI governance — a subset of the 602, and the more revealing group:

Controls in use among the subset of breached organizations that enforced AI governance, 2026 compared with 2025
Control in use20262025
Required IT approval for AI deployments38%45%
Deployed AI governance technology33%
Deployed AI governance frameworks33%
Coordinated governance and security teams19%not asked

The second table is the one worth reading twice. These are organizations that had already decided to govern AI. Two thirds of them were doing it without governance technology.

Three things worth sitting with.

Governance coverage got worse, not better.

More breached organizations lacked AI governance in 2026 than in 2025. The share actively developing policies rose from 22% to 33% — so intent is up while coverage is down. Policy development is lagging AI adoption, and the gap widened over a year in which every vendor in this category claimed the opposite.

Approval processes are being abandoned.

Among organizations enforcing AI governance, requiring IT approval before deploying AI fell from 45% to 38%. IBM’s own summary is blunter: “Among those that had policies, only about a third had strict approvals for deploying AI.” That is the most basic control in the category, and it is in retreat — most plausibly because an approval queue with nothing behind it becomes a bottleneck teams route around rather than a gate they respect.

19% coordinated governance and security.

Two functions with overlapping mandates, operating separately in four out of five of the organizations that were governing AI at all. IBM notes this can produce “blind spots, policy conflicts and slower response times.”

For context on stakes: breaches involving shadow AI averaged USD 5.39 million against a USD 4.99 million global average in the same study, and shadow AI was involved in 43% of security incidents, up from 20% the prior year.

More on that: what is shadow AI.

Cost

What these platforms cost

Nobody in this category publishes pricing. We checked, and we are naming what we found.

Whether each AI governance platform vendor publishes pricing, and the date checked
VendorPricing published?Checked
IBM watsonx.governanceNo — links to a pricing page without tiers or price points10 Sep 2026
Credo AINo — “Talk to an Expert”10 Sep 2026
OneTrustNo — “scalable packages,” no figures10 Sep 2026
CollibraNo — demo request only10 Sep 2026

PromptFluent does not publish enterprise pricing either. Including ourselves in that table is the point.

What the silence means for your buying process

Opacity is a defensible choice for genuinely configured enterprise software. It is also a tactic. Either way, it has consequences you should plan around:

  1. 1

    Budget without an anchor. You will not get a number until you are in a sales process, which means the first credible figure arrives after you have spent weeks qualifying.

  2. 2

    Every quote is bespoke. Comparison requires running parallel processes with equivalent scope documents, or you are comparing quotes for different things.

  3. 3

    Ask what the price is a function of. Seats, models governed, use cases, API calls, and data volume produce wildly different curves as you scale. The unit matters more than the number.

  4. 4

    Get renewal mechanics in writing at the first quote. Uplift caps and expansion pricing are where the real cost lives, and they are easiest to negotiate before you have deployed.

Any vendor that will not tell you the shape of its pricing model — even without figures — is telling you something.

Requirements

What an AI governance platform actually does

Underneath the category differences, the capability set is reasonably stable. Use this as a requirements checklist rather than a feature-tick exercise.

AI governance platform capabilities and the question each one answers
CapabilityThe question it answers
InventoryWhat AI exists here — models, applications, agents, workflows?
OwnershipWho is accountable for each one?
ApprovalWhat had to happen before this went live, and did it?
Policy definitionWhat rules apply, to what, and who wrote them?
EnforcementAre the rules applied at runtime, or written down and hoped for?
EvidenceCan we reconstruct what happened after the fact, for an auditor or an incident?
MonitoringWhat is behavior doing over time — drift, quality, cost, volume?
Risk assessmentWhat could go wrong, how badly, and how likely?
Regulatory mappingHow do our controls map to the EU AI Act, NIST AI RMF, ISO/IEC 42001?
ReportingCan a board, regulator or customer see posture without a fire drill?

The two that separate real platforms from documentation tools are enforcement and evidence. A policy nobody can enforce is a memo. A control nobody can evidence did not happen, as far as an auditor is concerned.

Selection

How to choose: start from your actual problem

Not from a vendor’s list. Find your sentence.

Which AI governance platform category to start with, by the problem you actually have
If the problem sounds like…Start with
“We are deploying models into regulated decisions and cannot document them”Model risk and assurance
“We need EU AI Act or ISO 42001 evidence and have nowhere to put it”Model risk and assurance, or GRC if you already own one
“Our GRC program has no AI module and audit is asking”GRC extending into AI
“AI risk here is really data risk and our catalog already runs the place”Data governance extending into AI
“Our LLM app quality is drifting and nobody notices until users do”Observability and evaluation
“AI is approved and widely used, and no two people do the same task the same way”Execution-layer governance
“We cannot reconstruct how an AI-assisted output was produced”Execution-layer governance
“People keep going around the sanctioned tool”Both — security tooling to see it, execution governance to fix why

Most enterprises need two of these, not one. A model-risk platform and an execution-layer platform answer different questions and do not overlap much. Any vendor telling you their single product covers all five categories is selling you a roadmap.

The Boundary

Where model governance ends and execution governance begins

Model governance asks whether a system is fit to deploy. Execution governance asks what happened after it was.

Both matter. They fail differently, and the second failure is the one most organizations cannot currently see.

PromptFluent framework showing AI system governance and AI tool governance above the missing execution-governance layer, which governs people, prompts, workflows, versions, approvals, execution records, provenance, quality, and analytics.
Where AI Governance Ends—and Execution Governance Begins. Traditional governance can approve AI systems and control access to tools. Execution governance extends control into how AI-enabled work is actually performed, recorded, measured, and improved. View full size.

A model can be registered, risk-assessed, approved and monitored — and the analyst using it can still be working from a prompt they wrote themselves eight months ago, that nobody reviewed, that produces output three colleagues would produce differently, in a workflow that leaves no record of which version ran. Nothing in that sentence is a model failure. Every part of it is a governance failure.

This is the distinction we develop at length in AI governance vs AI execution governance, and where our own product sits in AI execution governance. The short version: a sanctioned tool is not the same as governed execution. Approving the tool is the beginning of the governance problem, not the end of it.

It is also why the IBM finding on approval processes matters. Approval rates fell. Not because organizations decided governance was unnecessary, but plausibly because an approval gate with no execution layer behind it becomes a queue — and queues get routed around. Governance that operates slower than the work it governs does not get followed.

Disclosure

Where PromptFluent fits — and where it does not

Disclosure: this is our page, and category 5 is our category. Read the rest of this section as an argument we have an interest in, and check it against the alternatives named below.

Where PromptFluent is the wrong answer

Buy something else if your problem is:

Problems PromptFluent does not solve, and what to buy instead
ProblemWhat you need — not us
Model risk, bias testing, model documentationA model-risk and assurance platform
ISO/IEC 42001 certificationAn accredited certification body, and a management system. We do not provide, accelerate or substitute for certification
NIST AI RMF conformance or EU AI Act complianceLegal counsel plus a model-risk or GRC platform. We are not a compliance determination
Enterprise GRCA GRC platform
Detecting AI usage outside sanctioned toolsNetwork and endpoint security tooling — DLP, CASB, SASE. Network-layer discovery is a security function, not ours
Data cataloging and lineageA data governance platform
Model drift and production evaluationAn observability and evaluation platform

That list is longer than the one below. We think that is the honest ratio, and it is the reason to trust the one below.

Where PromptFluent is the right answer

When AI is already approved and widely used, and the problem is that nobody can tell you how the work is being done. Specifically:

  • Prompts are versioned with full change history — roll back, branch, merge
  • Prompts move through defined lifecycle stages: draft, review, approved, deployed, deprecated
  • Approval workflows route work through review before team-wide deployment, with bottleneck detection built in
  • Role-based access control across admin, contributor, reviewer and viewer, where every action is permissioned
  • Runtime enforcement — governance at execution, not on paper
  • Every execution is logged, with full lineage: who used which prompt against which model with what input and output
  • Workflow chains connect multi-step sequences and carry context across every step
  • Execution analytics covering performance, usage patterns, quality scores and adoption

Security posture

AES-256 encryption at rest, TLS 1.2 or higher in transit, SAML 2.0 and OpenID Connect, MFA available, GDPR and CCPA compliant, 99.9% target uptime. Customer prompt libraries, usage data and content created in the platform are never used to train machine learning models. SOC 2 Type II controls implemented (certification on roadmap) — Q2 2027 target.

No customer outcomes, ROI figures or case studies are published on this page, because none have been verified for publication. When they exist, they will appear with names and numbers attached.

FAQ

Frequently asked questions

What is an AI governance platform?

Software that gives an organization visibility and control over its AI — what exists, who owns it, what it is permitted to do, how it behaves, and what evidence exists that policy was followed. In practice the term covers five distinct product categories that solve different problems.

What is the difference between AI governance and model governance software?

Model governance is a subset. It governs models: registration, risk assessment, bias testing, performance, documentation. AI governance as a category is broader and, depending on the vendor, may also cover use cases, data, agents, organizational policy, or execution. Ask any vendor which object their product governs. The answer is more informative than the label on the box.

How much does an AI governance platform cost?

No major vendor publishes it. We checked IBM, Credo AI, OneTrust and Collibra on 10 September 2026 — all four require a sales conversation, and so do we. Ask early what the price is a function of: seats, models, use cases, API calls and data volume scale very differently.

Do I need one if I already have a GRC platform?

Possibly not, for the risk-register dimension. Most major GRC vendors now offer an AI module, and extending a contract you already hold is usually faster and cheaper than a new procurement. What a GRC platform typically will not give you is control at the point of execution — what a specific person did with AI on a specific task.

What should an AI governance platform log?

Enough to reconstruct a consequential AI-assisted output after the fact: which instructions ran, which model, which version, what inputs, what came out, who approved it, and when. If a platform logs that a tool was accessed but not what was done inside it, it is an inventory system, not a governance system.

Can one platform cover models and everyday AI use?

Not well, today. The disciplines differ enough that most organizations run two. Vendors on both sides are expanding toward the middle, so this may change — but buy for the problem you have this year, not the roadmap you were shown.

What is the difference between AI governance and LLMOps tools?

LLMOps tools are built for engineers shipping AI applications: traces, evaluations, latency, cost, regression tests. AI governance platforms are built for the people accountable for AI: approvals, ownership, policy, evidence. They overlap on monitoring and diverge everywhere else. Buying an LLMOps tool to satisfy an auditor rarely ends well.

How long does implementation take?

Vendors do not publish this and we will not invent a number. What we can say is what drives the variance: how much AI you already have, whether an inventory exists, whether ownership is assigned, and whether policy exists to enforce. Organizations that have never inventoried their AI spend most of the timeline on discovery, not configuration. Ask for a reference customer of comparable size and ask them.

Glossary

Glossary

AI governance platform
Software providing visibility and control over an organization's AI: inventory, ownership, approvals, policy, enforcement, evidence and reporting.
Model governance
Governance of AI models specifically: registration, risk assessment, validation, performance monitoring and documentation.
AI execution governance
Governance of how AI-mediated work is actually performed, including prompts, workflows, models, versions, ownership, approvals and execution evidence.
LLMOps
Operational tooling for large language model applications: tracing, evaluation, prompt regression testing, cost and latency monitoring.
Shadow AI
AI used, built or deployed for organizational work outside sufficient organizational approval, visibility or governance. See shadow AI.
Execution evidence
The record that makes an AI-assisted output reconstructable after the fact: instructions, model, version, inputs, outputs, approver, timestamp.
Runtime enforcement
Applying governance rules at the moment work executes, rather than documenting them in a policy that relies on voluntary compliance.

Sources

Every figure on this page, and where it came from

Last evidence verification:

  1. 1

    IBM / Ponemon Institute Cost of a Data Breach Report 2026

    Published 29 July 2026. Research covering 602 organizations breached between March 2025 and February 2026, across 17 industries and 16 countries and regions. Supports, across all 602 organizations studied: 68% lacked AI governance to manage AI or detect shadow AI (vs 63% prior year) and 33% were developing governance policies (vs 22%). Supports, among those enforcing AI governance: 38% required IT approval for AI deployments (down from 45%), 33% deployed AI governance technology and 33% AI governance frameworks, and 19% coordinated governance and security teams. Also supports: USD 4.99 million global average breach cost; USD 5.39 million average for breaches involving shadow AI; shadow AI involved in 43% of security incidents, up from 20%. Verified against the report PDF, pages 45–47.

  2. 2

    IBM watsonx.governance product page

    Source of IBM's own product description, quoted verbatim. Pricing absence confirmed 10 September 2026.

  3. 3

    Credo AI product page

    Source of Credo AI's own product description, quoted verbatim. Pricing absence confirmed 10 September 2026.

  4. 4

    OneTrust AI Governance product page

    Source of OneTrust's own product description, quoted verbatim. Pricing absence confirmed 10 September 2026.

  5. 5

    Collibra AI Governance product page

    Source of Collibra's own product description, quoted verbatim. Pricing absence confirmed 10 September 2026.

Every vendor description on this page is quoted from that vendor’s own published product page. We have not characterized any competitor’s capabilities in our own words.

Find out which category you need

If you are not sure whether your problem is a model problem, a policy problem or an execution problem, the AI Execution Health Check is a free diagnostic that scores how well your organization governs and operates its AI work. It will tell you plainly if the answer is a platform we do not sell.

For teams evaluating execution-layer governance specifically.

Related reading: AI execution governance · What is shadow AI · Prompt governance · AI governance framework