Complete inventory
Models, agents, applications, use cases, MCP servers, providers and data classes — including AI the central team did not build.
ENTERPRISE AI GOVERNANCE · MODELS · AGENTS · APPLICATIONS
Inventory every AI system, assign ownership and risk, approve what may run, enforce policy on live traffic, and keep the audit evidence current — from one control plane in your own infrastructure.
Or email sales@kosmoy.com.
AI governance is not a policy document and it is not only an AI gateway. It is the operating system that connects what the enterprise has approved to what its models, applications and agents actually do in production.
Kosmoy starts with the record: AI use cases, systems, models, agents, MCP servers, owners, data classes and lifecycle state. Risk classification and approval workflows turn that inventory into policy. The AI Gateway and Action Capsules then enforce the policy on live traffic and high-autonomy workloads.
Every approval, call, guardrail decision, override, cost event and agent action returns to the same evidence trail. That is how governance stays current after launch — and how the EU AI Act, ISO/IEC 42001 and NIST AI RMF become operating controls rather than annual documentation exercises.

Enterprise buying criteria
A vendor can call a registry, a gateway or a compliance workflow “AI governance”. The buying test is whether the platform connects the full chain from discovery to runtime consequence and evidence.
Models, agents, applications, use cases, MCP servers, providers and data classes — including AI the central team did not build.
A named business owner, technical owner, approval state and lifecycle for every AI system and agent.
Repeatable classification by use case, role, autonomy and data sensitivity, linked to the controls that follow.
Approved models, tools, data access, budgets and human-review gates expressed as enforceable policy rather than guidance.
Identity, guardrails, routing, budgets, tool access and containment applied while calls and agent actions are happening.
Every decision and exception recorded with system, actor, time and outcome and mapped into framework-specific evidence.
The control plane sits between the enterprise record and the live AI estate. Policy becomes useful only when it changes what a model or agent is allowed to do.
What the enterprise runs
Business purpose, owner, users and expected outcome
Hosted models, private models, copilots and RAG systems
Agents, MCP servers, APIs and systems of record
Kosmoy governance control plane
Know what exists
Make accountability explicit
Classify systems and data
Approve models, tools and actions
Enforce on every live call
Keep the audit record current
What the enterprise gets
The right model, tool or agent is available to the right workload.
Risky calls are blocked, redacted, routed for approval or contained.
Every decision, override and runtime event remains attributable.
Commercial clarity
Commercial scope depends on which control layers are required and where they run. A registry-and-compliance deployment is different from a full runtime control plane with gateways and contained agents.
The main sizing factors
An enterprise AI governance platform connects six jobs that are often split across spreadsheets and point tools: inventory every AI system, assign accountable owners, classify risk, define approval and access policy, enforce that policy on live AI traffic, and keep the evidence current. Kosmoy does this for models, agents, applications, MCP servers and AI use cases in one control plane.
The gateway is the runtime policy point: it authenticates, guardrails, routes, budgets and logs live AI calls. The governance platform is broader. It also contains the registries, ownership, use-case approvals, risk classification and compliance evidence that tell the gateway what policy to enforce and prove what happened afterwards.
Yes. The Agents Master Registry inventories agents across Azure AI Foundry, AWS Bedrock, Google Vertex AI, Salesforce, ServiceNow and private runtimes. Gateway policy applies to agent traffic that routes through Kosmoy, while Action Capsules add runtime containment, short-lived credentials and a kill switch for high-autonomy agents.
Kosmoy maps the same operational evidence to the EU AI Act, ISO/IEC 42001 and NIST AI RMF. Frameworks change the control mapping and evidence export; the underlying inventory, classification, approvals and runtime event record remain the same.
Yes. Kosmoy runs single-tenant in the customer's Kubernetes on Azure, AWS, GCP or on-premises, including isolated environments. Models can be public, private or self-hosted. The enterprise keeps the control plane, prompts, responses, logs and credentials inside its chosen boundary.
The record includes system and agent ownership, risk classification, approvals, model and tool access, policy decisions, guardrail events, overrides, cost, human review and lifecycle changes. Each event remains attributable to a system, actor, time and outcome and can be exported into framework-specific evidence bundles.
Enterprise proof
Kosmoy works with regulated and operationally critical organizations, including Banca d’Italia and Leonardo.


Bring one real model, application or agent estate. We will walk from inventory and ownership through policy enforcement and audit evidence.
Or email sales@kosmoy.com.