SECURITY Signal 80
Microsoft Outlines AI Governance Architecture With Runtime Enforcement via Foundry AI Gateway
Microsoft has published an AI governance architecture spanning nine domains and four functions that moves governance from documented policy into runtime enforcement, observability, and audit evidence using Microsoft Foundry alongside Purview, Entra ID, Defender, and Azure API Management.
For teams deploying AI agents in production, this architecture describes a concrete control plane where policies become enforceable at runtime rather than remaining documents. The Foundry AI Gateway acts as a boundary for authentication, quotas, rate limiting, and policy enforcement, including governance of MCP tools without modifying server or agent code. Only one feed carried this story, so independent corroboration is absent.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The framework defines nine governance domains and four functions, policy, control, visibility, and proof, treating governance as a continuous operational loop from rule definition through audit evidence.
Microsoft Foundry's AI Gateway provides runtime enforcement for authentication, token limits, quotas, and policy execution, and can govern MCP tools with centralized auth, rate limiting, IP restrictions, and audit logging without modifying MCP servers or agent code.
Microsoft's open-source Agent Governance Toolkit and Agent Control Specification add runtime security for autonomous agents, including checkpoints across inputs, model calls, tool execution, and outputs, with higher-impact actions able to require human approval.
THE READ
What the cluster adds up to.
Microsoft's architecture reframes AI governance as a runtime concern rather than a policy document. The four functions, policy, control, visibility, and proof, form a loop: policies define requirements and risk classifications, controls translate them into access and runtime rules, observability captures system behavior, evaluations test quality and safety, and audit processes convert telemetry into compliance evidence. This mapping means governance is not complete until production can demonstrate enforcement, a point emphasized by Microsoft's own advocates.
The nine governance domains cover policy, data governance, model governance, observability, evaluations, security, identity and access, audit and compliance, and agent governance. Runtime controls are designed to span interactions among users, agents, models, tools, APIs, MCP servers, and enterprise systems. The breadth signals that Microsoft is positioning governance as something that touches every layer of an AI application stack, not just the model endpoint.
The concrete enforcement mechanism is Microsoft Foundry's AI Gateway, which provides a runtime boundary for authentication, token limits, quotas, and policy enforcement. Microsoft documents using the gateway to govern MCP tools specifically, offering centralized authentication, rate limiting, IP restrictions, and audit logging without requiring changes to MCP servers or agent code. This is a practical detail for engineering teams: the gateway sits as an intermediary, meaning governance controls can be applied without refactoring existing agent or tool implementations.
Agent governance receives specific attention through the open-source Agent Governance Toolkit and the Agent Control Specification. The specification defines checkpoints across agent inputs, model calls, tool execution, and outputs, with higher-impact actions able to require human approval. This gives teams interception points for autonomous agents where policy can be enforced before consequential actions execute. Microsoft also positions evaluations both before deployment and in production, with Foundry supporting assessment against datasets using built-in and custom evaluators.
The architecture is tied to Microsoft's platform, Foundry, Purview, Entra ID, Defender, and Azure API Management, but Microsoft references the NIST AI Risk Management Framework and Generative AI Profile as a vendor-neutral foundation. The mapping of NIST concerns into concrete platform controls is the bridge between framework-level guidance and operational implementation. Because only one feed carried this story, there is no independent reporting to confirm adoption patterns or limitations beyond what Microsoft itself has described.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗