Most AI governance platforms document what your company intends to do. Once an agent acts on its own, someone will ask what it actually did — and a policy library cannot answer that.
Knowing which one you are shopping for saves a quarter. They are bought by different people, for different questions.
Proves your organisation is well run.
Policy libraries, control mapping, vendor questionnaires, evidence collection for SOC 2 and ISO 27001. Bought by security and compliance leads who need a certificate. Vanta, Drata and Sprinto live here.
Answers: is this company trustworthy?
Proves what a specific agent did.
Every model call, tool call, decision and approval, written as it happens into a record where a later edit is computable. Bought by whoever has to answer a regulator, an auditor, or a customer's security review. Auditant is this.
Answers: what did it do, and who allowed it?
You may well need both. They are not substitutes, and a vendor who tells you otherwise is selling the one they have.
Ask these of anyone selling AI governance, including us. The answers sort the category faster than a feature matrix.
Three jurisdictions want a record of what your agents did, and none of them accept a policy document as one.
Automatic logging over a high-risk system's lifetime
Keep personal data safe, and report it when you do not
Retain records of consequential decisions for three years
Each is answered from the same record — and it only counts if you were already keeping it when they asked. How the record works →
Including the one that sometimes costs us the sale: whether you need this at all yet.
Software that keeps a company accountable for what its AI does. In practice the label covers two different products: tools that document your policies and controls so you can pass a certification, and tools that record what your models and agents actually did. Both get called governance. Only the second answers “what did it do on the fourteenth”.
SOC 2 says your company runs sound controls. It does not say what your agent did to a particular customer on a particular day, and an examiner asking that question will not accept a certificate as the answer. They are different artefacts for different questions.
No. Observability answers “is the model behaving” for engineers, on logs built to be cheap and short-lived. Governance answers “prove what it did, and that nobody edited the record” for the person who signs. Observability logs are usually mutable and expire in weeks; the obligations they would have to satisfy run for years.
Article 12 requires automatic logging over the lifetime of a high-risk system, from 2 December 2027. Article 50 requires telling people they are interacting with a machine, already in force. Article 99 sets penalties at €15M or 3% of worldwide turnover, whichever is higher.
Most cannot — they describe after the fact. Enforcement means the rule is evaluated before the action executes, and the refusal is recorded beside it. That is the difference between evidence of control and evidence of activity.