Learning Hub · Glossary

AI Governance, Explained

Regulatory update (April 2026): the Federal Reserve issued SR 26-2, superseding SR 11-7 and SR 21-8 as interagency model risk management guidance. The OCC has stated that generative and agentic AI are novel technologies not themselves within the revised guidance’s scope. References to SR 11-7 on this page describe the historical framework. EVE supports evidence, validation, governance, and control practices that may help institutions operationalize portions of the 2026 guidance; applicability depends on the system, institution, and use case.

Six plain-English explainers on the ideas behind regulated AI — governance, control planes, model risk, audit trails, and the difference between advising and enforcing. Each is the clearest answer we can write to one question.

Definition

What “AI governance” actually means

Two organizations can say “we do AI governance” and mean completely different things. This glossary fixes the vocabulary so the words carry weight.

“AI governance is the set of policies, controls, and evidence that determine what an AI system is allowed to do — and prove those rules were enforced on each decision.”

The Three Parts

Policy, enforcement, evidence

Real governance is not a document or a dashboard. It is three things working together — and the third is the one most teams are missing.

Policy

The rules an AI decision must satisfy — expressed precisely enough to evaluate automatically, not just as a PDF of principles.

Enforcement

A control point that applies the policy before the action runs, so a disallowed decision never reaches production — not a score you read afterward.

Evidence

A signed, reproducible record of each decision that an auditor or examiner can verify independently — not logs you ask them to trust.

Vocabulary

Acronyms & terms

The standards, protocols, and product terms that come up across EVE’s governance, evidence, and compliance surface — defined plainly.

Standards, protocols & compliance

TermMeaning
API / SDK / SaaSApplication Programming Interface / Software Development Kit / Software-as-a-Service
LLMLarge Language Model
MCPModel Context Protocol
A2AAgent-to-Agent protocol
RBACRole-Based Access Control
RLSRow-Level Security
HMACHash-based Message Authentication Code
JWTJSON Web Token
SSO / SAML / OIDCSingle Sign-On / Security Assertion Markup Language / OpenID Connect
SBOM / AI-BOMSoftware / AI Bill of Materials
SLSASupply-chain Levels for Software Artifacts
SPIFFESecure Production Identity Framework For Everyone
OSCALOpen Security Controls Assessment Language
DSSE / in-totoSigning-envelope and attestation formats for tamper-evident evidence
SSEServer-Sent Events
PIIPersonally Identifiable Information
GDPR / CCPAEU / California data-privacy regulations
SOC 2System & Organization Controls 2 — EVE is pursuing Type II (readiness in progress) and provides evidence and readiness packages, not an issued attestation
SR 26-2U.S. Federal Reserve model-risk supervisory guidance (superseding SR 11-7); policy-pack mappings reference the current framework
ECOAEqual Credit Opportunity Act (fair-lending)
EU AI ActEuropean Union Artificial Intelligence Act

EVE product surface

TermMeaning
EVE CoreGuardDeterministic decision-enforcement engine for regulated AI — ALLOWED / BLOCKED / MODIFIED before an action runs
EVE ProofECDSA P-384-signed, offline-verifiable Governed Decision Certificate for each decision
Agent GatewayGoverns an AI agent’s tool and action calls behind CoreGuard before execution
Sovereign SDKTenant-isolated governance-as-a-service for enterprises
Authority LabPublic “run your agent through EVE” scanner with a signed report
Policy CompilerAuthor and validate governance policy packs (draft-only; never auto-activates)
Keep Reading

Start with a definition

Plain-English explainers on the concepts behind regulated AI governance — each one written to be the clearest answer to a single question, and each linking to the products and documentation that put it into practice.

See governance enforced on your own decision

We’ll run one of your real decisions through the deterministic control plane, show you the same verdict twice, and hand you the signed certificate your auditors verify offline.

Direct line: [email protected] · See pricing