Graften Docsgraften.io
Docs / Knowledge Base / AI Governance

AI Governance

AI Governance

AI Governance is a billed add-on covering five related tools for managing a client's AI tool exposure and regulatory readiness. An admin turns it on via Settings → Add-ons → AI Governance (POST /api/v1/billing/aigov/checkout).

AI Inventory

Tracks which AI tools are in use, fingerprinted against a known list — Microsoft Copilot, ChatGPT, Google Gemini, Claude, GitHub Copilot, Grammarly, Midjourney, Notion AI, Jasper AI and Otter.ai — each with a vendor and risk tier. Scan (POST /api/v1/ai/inventory/scan) checks a connected Microsoft 365 tenant two ways: Copilot's own audit log operation, and — for the other tools — whether Microsoft Defender's URL scanning has actually seen traffic to that tool's domains, not just whether the domain exists. Without an M365 connection, the scan seeds the known-tools list for manual review instead of silently reporting zero. Tools can also be added or removed by hand.

Shadow AI Detection

A separate, more cautious sweep aimed specifically at unsanctioned AI use. Each detected tool gets a data-risk classification and an approval workflow (unknown → approved/rejected) rather than being added straight to inventory — tools flagged high-risk or of unknown risk are held back from auto-approval regardless of how confidently they were detected.

AI Model Bill of Materials (MBOM)

A structured record per AI tool in use: model name, model provider, inference infrastructure, training data source, data classification, and use case — exportable as CSV (GET /api/v1/ai/mbom/export) for a client's own AI risk register or a customer's due-diligence request.

EU AI Act Readiness

A short questionnaire (POST /api/v1/ai/euaiact) that produces a risk tier (minimal/limited/high/unacceptable, per the Act's own categories) based on the client's answers, stored against the client for later reference.

AI Supply Chain

Cross-references AI Inventory and MBOM entries against known vendor risk data to surface AI-specific vendor concentration and dependency risk (GET /api/v1/ai/supply-chain).

AI Regulatory Alerts

The same regulatory alert feed as Security Intelligence's Regulatory Alerts, filtered down to AI-specific items — an update only appears here if it actually concerns AI regulation (checked against the alert's full title, body and framework text, not a loose substring match that would catch unrelated words like "chain" or "again").

Compliance framework auto-assessment

Two controls are automatically marked from AI Inventory contents rather than left for manual review: ISO 42001's inventory/risk-tiering controls, and the EU AI Act's Article 6 (high-risk system classification) and NIST AI RMF's MAP 3 (risk categorisation) controls — all four carry an ⚡ AUTOMATED badge on their respective Compliance pages once AI Inventory has real data behind it.

Open in the interactive docs