AIAI Governance StackFree kit

84 tools · 5 categories · independently compiled

The independent directory of AI governance platforms

Compare AI governance, monitoring, guardrail and AI-security tools by the framework you have to satisfy — EU AI Act, NIST AI RMF, ISO/IEC 42001 — and by the team that will actually operate them.

Browse by category

The market splits into five distinct jobs. Most organisations end up buying from more than one.

Policy, Compliance & GRC

35

These platforms treat AI governance as an organisational discipline rather than a machine-learning problem. They maintain an inventory of AI use cases, route them through intake and risk assessment, attach policies and controls drawn from regulations like the EU AI Act, and collect the evidence an auditor will eventually ask for. The centre of gravity is workflow and documentation: who approved this system, against which policy, on what evidence, and when it was last reviewed.

Observability & Monitoring

14

Observability tools answer the question governance documentation cannot: is the model actually behaving in production the way it was approved to behave? They track drift, data quality, bias and performance degradation over time, and increasingly extend to LLM-specific concerns like hallucination rates, prompt/response logging and token-level tracing. Their output is the empirical evidence that feeds a governance program's monitoring obligations.

Runtime Enforcement & Guardrails

9

Guardrail systems sit in the request path between users and models, enforcing policy at inference time. They filter prompts and responses for prompt injection, PII leakage, toxicity, off-topic use and ungrounded claims, and can block, redact or rewrite before content reaches a user. Unlike governance documentation, these controls are preventive and measured in milliseconds.

Red-Teaming & AI Security

17

This category attacks your AI before someone else does. Vendors here run automated adversarial testing against models, agents and applications — jailbreaks, prompt injection, data extraction, agent hijacking — and map findings to frameworks like the OWASP LLM Top 10 and MITRE ATLAS. Several also cover the ML supply chain, scanning model artefacts and dependencies for tampering.

Enterprise Incumbents

9

Large data, cloud and ML platform vendors have extended existing catalogues, MLOps suites and GRC modules to cover AI. Their advantage is gravity: the inventory, lineage, identity and access controls already exist, and AI governance becomes another surface on infrastructure you have already bought. The trade-off is that governance depth often trails the pure-play specialists, and coverage can be strongest inside the vendor's own ecosystem.

Start from the obligation

Most buying decisions start with a regulation someone has to satisfy. Pick yours and see which tools map to it.

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.

Most thoroughly documented tools

Ordered by how much verifiable public information exists on each — a transparency proxy, not a quality ranking.

AI observability and evaluation platform for ML models, LLM apps, and agents

Observability & MonitoringSOC 2HIPAAGDPROpen-source

Govern your AI and automate GRC for EU AI Act and ISO 42001 compliance

Policy, Compliance & GRCEU AI ActISO/IEC 42001NIST AI RMF

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

Policy, Compliance & GRCISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

Policy, Compliance & GRCNIST AI RMFISO/IEC 42001GDPR

European compliance automation platform with an ISO 42001 and EU AI Act AI management system

Policy, Compliance & GRCEU AI ActISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

Policy, Compliance & GRCISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

Policy, Compliance & GRCNIST AI RMFISO/IEC 42001EU AI Act

AI developer platform for experiment tracking, model management, and LLM observability

Enterprise IncumbentsSOC 2HIPAA
See all 84 tools →

Buyer guides

Shortlists for the questions people actually search.