Microsoft Shifts AI Governance to Runtime Enforcement
Microsoft has introduced a new AI governance architecture designed to enforce safety and compliance rules during runtime, helping organizations safely scale production-ready AI agents.

Microsoft's new framework transitions AI governance from static, written policies to active runtime enforcement, continuous evaluation, and automated auditing. The architecture is structured around four primary functions—policy, control, visibility, and proof—and spans nine distinct governance domains. These domains include policy, data governance, model governance, observability, evaluations, security, identity and access, audit and compliance, and agent governance. By treating governance as an active operational loop, the system translates high-level risk classifications into real-time access and execution rules.
To implement this framework, Microsoft integrates several of its enterprise services, including Microsoft Purview, Microsoft Entra ID, Defender, and Azure API Management. At the center of this runtime boundary is the Microsoft Foundry AI Gateway, which manages authentication, enforces token limits and quotas, and applies policy restrictions. The gateway also governs Model Context Protocol (MCP) tools, providing centralized rate limiting, IP restrictions, and audit logging without requiring developers to modify their underlying agent code or MCP servers.
For autonomous systems, the company introduced the open-source Agent Governance Toolkit alongside an Agent Control Specification. This setup establishes critical checkpoints across agent inputs, model calls, tool executions, and final outputs, allowing organizations to mandate human approval for high-impact actions. Additionally, Microsoft Foundry supports pre-deployment and production-level evaluations against custom datasets, enabling developers to continuously monitor safety and quality.
This operational shift addresses a common hurdle in enterprise AI deployment. As Microsoft Principal Cloud Advocate Anthony Bartolo noted on LinkedIn, "Your AI policy is not governance until production can prove it." Rather than relying on vendor-specific silos, the architecture maps directly to the NIST AI Risk Management Framework and Generative AI Profile, translating abstract compliance guidelines into concrete platform controls and telemetry.
This is our own summary of reporting by InfoQ AI



