What does AI gateway governance control?
AI gateway governance controls five decisions: which exact model is approved, which provider and region can receive traffic, who may change that scope, which evidence is still current, and what happens when an incident or retirement notice arrives. NIST AI 600-1 places supplier risk assessment, approved-provider inventories, contract review rights, and continuous monitoring in the governance function.
Source: NIST AI 600-1, Generative AI Profile · Source A · standards authority · published 2024-07; rechecked 2026-08-21
Operator judgment: the useful unit is a decision record, not a policy page. A reviewer should be able to answer who approved model-id, which endpoint received traffic, when the source was checked, and which event forces a new review. If one field is missing, the approval has an unowned edge.
The record format follows the dated-source discipline of the SteadyGateway freshness ledger · latest board evidence verified 2026-08-18