Glossary
AI governance is the set of controls that decide where AI requests may go, what they may contain, what they may cost and who may send them - and the records that prove the controls were applied. Enforced in a routing layer, it is a control on the path of every request rather than a document beside it.
Organisations write AI policies: which vendors may be used, where data may travel, who may spend what, which requests need a person. The gap is enforcement. A policy that nothing reads at request time is a statement of intent, and the first team to paste customer data into a public model proves it.
A routing layer is the natural enforcement point because every request passes through it before a model is called. Hard constraints - data boundary, region, tenant, allowed and denied targets, cost ceilings, PII handling, payload logging - remove candidates before any scoring; budgets per workspace, tenant and key refuse once reached; a human queue is a routing target for requests that need approval. None of it is a prompt or a weight: a request that would break a rule is refused or re-routed, and the rule is named in the trace.
Proof is the second half. A hash-chained audit trail of decisions and outcomes answers the auditor's question - where did this request go, and why - six months later. A governance report lists every control in force with a posture score and the findings behind it. These are controls an organisation configures for a regulated workload, and they should be described as such; they are not a certification, and a vendor who implies otherwise should be asked for the certificate.
Questions people ask
OpenSmartRoute is open source and the free plan keeps the full trace of every decision. Type a request in the playground and read the ranked candidates.
Free plan, no card. Fifteen thousand decisions a month with the full trace.