The short answer
Choose by the question you need to answer, not by the feature list. If the question is “which AI tools are being used in my company, by whom and at what risk?”, you need a usage governance platform: technical discovery, a catalog with classified risk, a policy with acknowledgement and audit evidence. If the question is “how do I document, test and monitor the models we build?”, you need model governance. They are different purchases with different buyers, and putting one product from each family in the same comparison table only creates confusion.
This guide gives ten criteria for comparing usage governance platforms, the question to ask the vendor on each one and the red flag that exposes a weak answer. At the end there is a scoring table to fill in during the pilots.
68%
of organizations that suffered a breach had no AI governance in place to manage AI or detect shadow AI, according to the 2026 report. It is a figure about organizations that were breached, not a forecast for yours.
First: what problem are you buying to solve?
The market uses the same name for products that solve different problems. Before asking for any demo, find your case:
| Family | Question it answers | Who buys | Sign it is yours |
|---|---|---|---|
| Model governance | How do we document, test and monitor the models the company builds or fine-tunes? | Data, ML and product teams | You train or fine-tune your own models and need model cards, metrics and versioning. |
| Usage governance | Which AI tools do people use, with what data and under which policy? | IT, security, DPO and compliance | Your employees use ChatGPT, copilots and extensions and nobody has the complete map. |
| GRC or privacy platform with an AI module | How do we organize risks, controls and audits, including AI ones? | Compliance and legal | You already have a GRC platform and want to extend it, knowing it relies on manual entry. |
The rest of the guide covers the second family, which is the one most companies need first: it is hard to govern your own models when you still do not know which third-party tools are already inside the company. If that is your starting point, begin with what Shadow AI is and how to build an AI inventory.
1. Vendor independence
Ask: does the platform see and govern AI from any vendor, or only from its own ecosystem?
AI vendors tend to offer administrative controls for their own products, but not visibility into competitors’ products. A company that uses three or four tools from different vendors ends up with three or four consoles and no single view. “Independent” here means only this: the product does not depend on the company using a particular ecosystem.
Red flag: the demo only shows the vendor that sells the platform, or third-party coverage appears as “integration on the roadmap”.
2. How the platform discovers what is in use
Ask: where does the usage data come from, and what is left out?
There are three main paths, and each one sees part of the problem:
| Method | What it sees well | What tends to escape |
|---|---|---|
| Agent on workstations | Use on any network, including remote, with the device and the person identified. | Devices without the agent: personal phones, third-party equipment. |
| Firewall, SSE or SIEM logs | A central view of the network, with nothing installed on the machines. | Traffic outside the corporate network and people on mobile data. |
| Browser extension | Detail of what is typed or pasted, when the extension inspects content. | Desktop apps and browsers without the extension. Mind item 4. |
No single method covers everything, and an honest vendor says so. The useful question is which combination the platform accepts and how it handles overlap between sources, so that the same use is not counted twice.
Red flag: a promise of “100% visibility” or of detecting “all” of the company’s AI. No serious platform promises that.
3. Catalog and risk classification
Ask: what is each detected signal compared against, and who keeps that base up to date?
Detecting a domain is not enough: you need to know which tool it represents and what risk it carries. The size of the catalog matters less than three questions: what risk criterion it uses and whether that criterion is public; whether it records what matters for your case (vendor country, retention policy, use of data for training, the difference between the paid and the free version); and how often it is reviewed, because tools appear, change terms and disappear every week. Ask also whether tools that went offline stay in the base: an inactive domain can come back, and the recorded risk is what makes it possible to audit an old event.
One way to test it: ask to look up three tools you know well during the demo. Our own public catalog works without signing up, and any vendor that refuses to show theirs is not giving you what you need to evaluate it.
Red flag: risk classification with no explained criterion, or a count of cataloged tools presented as if it were the argument.
4. Privacy of the monitoring itself
Ask: does the platform collect the content of what people type, or only the record that a tool was used?
This is the most important and most underestimated architectural decision. Collecting the content of conversations and files widens what the platform sees, and at the same time creates a new repository of sensitive data, with the privacy, leakage and employment-relationship risks that come with it. Recording only which tool was used, when and on which workstation narrows the reach of the monitoring and greatly reduces exposure. There is no universally right answer, but there is a universal requirement: the vendor must say clearly what it collects and what it does not, and that must be in the contract.
Red flag: a vague answer, or “it depends on the configuration”. If what is collected is an option, ask what the default is and who can change it.
5. From inventory to action
Ask: what happens after a tool is detected?
An inventory with no consequence is a report that ages. The cycle that matters has five steps: classify the tool under the company policy (allowed, restricted or prohibited), record the policy acknowledgement from the people who use it, turn each deviation into a task with an owner and a deadline, resolve the task automatically when the deviation disappears, and keep the history. If the product ends at the inventory screen, action keeps depending on spreadsheets and email. A good starting point for the policy is the annotated 10-section template.
Red flag: the demo ends at the list of detected tools.
69%
of organizations already suspect or have evidence that employees use prohibited public generative tools. Suspecting is not inventorying: the platform exists to turn the suspicion into a list, and the list into a task.
Gartner, Previsão sobre incidentes de Shadow AI até 2030 (Infosecurity Magazine)
6. Frameworks and evidence
Ask: against which frameworks does the platform measure, and is the evidence reused across them?
What the company needs to show tends to repeat across frameworks: the inventory serves ISO/IEC 42001 as well as the NIST AI RMF and the LGPD. A platform that makes you attach the same evidence three times does not save you time. Also check which frameworks are relevant to your case: the NIST AI RMF is voluntary and ISO/IEC 42001 is certifiable, while the EU AI Act is a regulation with obligations by risk category.
Red flag: “guarantees compliance”, “certifies your company” or any variation. Software gathers evidence and shows gaps; a certification body certifies, and the company decides compliance.
7. Auditor view and export
Ask: how does an external auditor see the evidence, and can I take my data with me?
An auditor needs to see the evidence per control, dated, without being given access to the whole platform. Ask whether there is a restricted, time-limited viewing mode. Ask also what happens to your data if you leave: export format, retention period and deletion period.
Red flag: the evidence exists only inside PDF reports generated by the vendor, without the trail behind them.
8. Where the data lives and who the subprocessors are
Ask: where is the data stored, which subprocessors take part, and what independent reports can the vendor itself show?
You are hiring a governance tool, and it becomes a vendor of sensitive data itself. Ask for the list of subprocessors, the country of storage and what will be in the data processing agreement. If the vendor claims a certification or audit report (SOC 2, ISO/IEC 27001), ask for the document and check its scope and date. A subprocessor’s certification, such as the cloud the product runs on, is not the vendor’s own certification, and a transparent vendor makes that distinction on its own.
Red flag: a compliance badge on display with no corresponding document.
9. Time to first result and total cost
Ask: how long until I see the first real inventory, and what else goes into the cost besides the license?
Compare by time to the first useful result, not by deployment promise. Check whether there is public pricing or only “talk to sales”, how pricing scales (per workstation, per user, per tool) and whether training, integrations and support are charged separately. A trial with your own data is worth more than any presentation.
Red flag: a deployment timeline measured in quarters for a result the discovery method can produce in days.
10. Fit with the local regulatory context
Ask: does the platform handle the LGPD, the ANPD and my sector’s rules, and does support work in my language and time zone?
For a Brazilian company this means more than translating the interface. It means understanding the LGPD and ANPD regulation, sector rules (financial, insurance, health) and the demands foreign customers place on your company, such as those of the EU AI Act. Tools designed for another market tend to cover NIST well and local legislation poorly.
Red flag: local frameworks treated as “coming soon”.
How to compare: a scoring table
Give 0 (does not meet), 1 (partly meets) or 2 (meets, with evidence in the demo) for each criterion. Ask for proof on screen, not in the presentation. The weights below are a starting point: raise the one that matters most in your case.
| Criterion | Suggested weight | Vendor A | Vendor B |
|---|---|---|---|
| 1. Vendor independence | 2 | ||
| 2. Discovery (method and coverage) | 3 | ||
| 3. Catalog and risk criterion | 3 | ||
| 4. Monitoring privacy | 3 | ||
| 5. From inventory to action | 2 | ||
| 6. Frameworks and evidence | 2 | ||
| 7. Auditor view and export | 1 | ||
| 8. Data and subprocessors | 2 | ||
| 9. Time to result and cost | 2 | ||
| 10. Local regulatory context | 1 |
Five red flags
- A promise of completeness. “100% of tools” or “all of the company’s AI”.
- A promise of compliance. “Guarantees” or “certifies” frameworks.
- A vague answer on content collection. What is collected has to be stated and contracted.
- A demo without your tools. If the vendor only shows a sample environment, you have not seen the product yet.
- The catalog as the only argument. A tool count with no criterion, no review frequency and no open lookup.
51%
of organizations that use AI have already had at least one negative consequence from it, according to McKinsey’s 2025 survey (1,993 respondents in 105 countries). It is the backdrop against which the purchase decision happens.
The pilot: what to measure in 14 days
Do not sign before running a pilot with your own data. Define what success means before you start:
| What to measure | How to measure it | Expected result |
|---|---|---|
| Discovery | How many tools the platform found that you already knew existed, and how many you did not. | All the known ones, plus a number of new ones that justifies the project. |
| Attribution | Can you tell which workstation and which department used each tool? | Yes, without identifying content. |
| Classification | Does the risk classification of the tools you know match your judgment? | Divergences explained by the criterion. |
| Action | Does a detected prohibited tool become a task with an owner and a deadline? | Yes, with no manual work. |
| Evidence | Can an auditor see the evidence for one control without access to the rest? | Yes, with date and history. |
Tangerin AI’s free assessment, at /diagnostico, works as a thermometer before the pilot: nine questions, no signup, and the result shows where to start.
Apply this list to us too
Disclosure: Tangerin AI sells a platform for governing AI usage, and this guide was written by it. That is why the criteria above are phrased as questions you can put to any vendor, including us. Our agent and log ingestion, our public catalog, the decision not to collect conversation content, and the list of what we do and do not hold in certifications are described on the catalog and security pages. If one of our answers does not survive your scoring, the guide has done its job.
Frequently asked questions
What is an AI governance platform?
It is the software that helps a company know which AI tools are in use, assess the risk of each one, apply a policy and keep evidence that the rule is followed. There are two families: those that govern models the company builds (lifecycle, testing, technical documentation) and those that govern how the people who work there use AI (tool discovery, policy, acknowledgement, evidence). Before comparing vendors, decide which problem is yours.
What is the difference between AI governance and an ordinary GRC platform?
A GRC platform organizes risks, controls and audits on any topic, but it cannot see what is being used: it depends on someone entering the data. An AI governance platform adds technical discovery of the tools in use and a risk classification for each. In practice the two complement each other, and the evidence from the second feeds the controls of the first.
Do I need a platform, or is an inventory spreadsheet enough?
A spreadsheet works to get started and for small companies with a few known tools. It stops working once use happens among people nobody consulted: the spreadsheet only records what someone remembered to declare. If your auditor's first question is "how do you know the list is complete?", a spreadsheet does not answer it.
How long does it take to deploy?
It depends on the discovery method. An agent installed on workstations usually produces a first inventory within days. Integration with firewall, SSE or SIEM logs depends on access and format, and can take weeks. Ask the vendor for a pilot with a defined deadline and success criteria before signing.
Does an AI governance platform guarantee compliance with the LGPD or the EU AI Act?
No, and be wary of anyone who says it does. The platform gathers evidence and shows gaps against the frameworks' requirements; compliance depends on the company's decisions and processes. Frameworks such as the NIST AI RMF are voluntary and not certifiable, and ISO/IEC 42001 certification is granted by a certification body, not by software.
Sources
- IBM / Ponemon Institute — Cost of a Data Breach Report 2026 (2026). https://www.ibm.com/reports/data-breach
- Gartner — Previsão sobre incidentes de Shadow AI até 2030 (2025). via Infosecurity Magazine. https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/
- McKinsey & Company — The State of AI: Global Survey (2025). https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
- NIST — AI Risk Management Framework 1.0 (2023). https://www.nist.gov/itl/ai-risk-management-framework
- ISO/IEC — ISO/IEC 42001:2023 — AI management systems (2023). https://www.iso.org/standard/81230.html
- União Europeia — Regulamento (UE) 2024/1689 — EU AI Act (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj