All 13 vendors assessed in Gartner's inaugural Magic Quadrant for AI Governance Platforms, plus the tools shortlisted alongside them — and an honest account of what none of them covers.
How this page is sourced
Company facts here — funding, headquarters, quadrant placement, and whether a vendor publishes pricing — are corroborated against independent sources, and each entry carries the date it was checked. What you will not find is a scored feature matrix. Vendor capability claims could not be verified against vendor documentation, and a grid built from marketing copy would imply a precision that does not exist. Where a claim is the vendor's own, it is described as such.
What the whole market is missing
These hold across every vendor, and none of them appears on a vendor's own page.
Only one vendor publishes a price
Of seventeen platforms checked, Fiddler alone publishes a figure — $0.002 per trace on its developer tier. Every other vendor quotes on request. Figures circulating on procurement and comparison sites are third-party estimates, not vendor pricing, and are not reproduced here.
No vendor is certified against the standard it sells compliance with
None of these platforms holds an ISO/IEC 42001 certification for the governance product itself, and none has a third-party attestation of its framework mappings. Supporting a regime is not the same as being assessed against it. The one ISO 42001 certification found anywhere covers SAP's own AI services, not a customer-facing feature.
Two live regulatory duties are covered by nobody
Transparency labelling and watermarking, and training-data provenance, produced no evidence at any vendor — Relyance AI is the single partial exception on provenance. Both are obligations organisations actually carry, so this is a gap buyers have to fill elsewhere.
Two AI standards are almost entirely absent
ISO/IEC 23894 on AI risk management and ISO/IEC 42005 on impact assessment go essentially unmentioned across the market. ISO 42005 appears once, inside SAP's description of its own internal governance.
Bias testing is rarer than the marketing suggests
Several platforms assess and document bias through questionnaires and evidence collection rather than running tests. Holistic AI, Fiddler, Credo AI through its open-source Lens library, and Asenion are the ones with evidenced testing capability.
What regulators actually require
The capabilities below are not a vendor feature list. Each is derived from the obligations written into the compliance frameworks tracked on this site, with the count showing how many regimes demand it. It is the rubric a platform should be judged against.
Transparency & disclosure · 27 frameworks
Telling people they are dealing with AI: chatbot disclosure, deepfake labelling, machine-readable marking of generated content.
Bias & fairness testing · 22 frameworks
Testing outputs for discriminatory effect across demographic groups, before deployment and on a continuing basis.
Watching deployed systems for drift and failure, and reporting serious incidents to the authority within the deadline the regime sets.
Data governance & provenance · 19 frameworks
Governing training, validation and test data — quality, representativeness, lawful basis, and provenance of what went into the model.
Technical documentation · 18 frameworks
Producing and maintaining the technical record a regulator or auditor can ask for — Annex IV documentation, model cards, instructions for use.
Accuracy & robustness testing · 15 frameworks
Evaluating accuracy, resilience to error and adversarial manipulation, including red-teaming for general-purpose models.
Risk classification & tiering · 14 frameworks
Placing each system in the tier a regime defines — the AI Act's prohibited/high-risk/limited/minimal being the strictest example — because the tier decides which duties apply.
Security · 14 frameworks
Protecting systems against unauthorised access, data poisoning and model extraction, increasingly overlapping with product-security law.
Human oversight · 12 frameworks
Ensuring a trained person can monitor, interpret, override and stop the system, with the authority to do so in practice.
AI inventory & registry · 10 frameworks
Keeping a complete register of the AI systems an organisation builds, buys or deploys. Nearly every obligation downstream depends on knowing what exists.
Third-party & supply chain · 10 frameworks
Assessing AI acquired from others, and the duties that fall on a deployer rather than the provider of a system.
Impact & rights assessment · 9 frameworks
Structured assessment of the effect on people: fundamental rights impact assessments under the AI Act, DPIAs under GDPR, algorithmic impact assessments elsewhere.
Policy, roles & AI literacy · 8 frameworks
Internal policy, named accountable roles, and the AI literacy duty that regimes increasingly place on organisations.
Logging & audit trail · 7 frameworks
Automatic, tamper-evident logs of decisions, inputs and changes, retained long enough to reconstruct what a system did.
Gartner screened more than 100 vendors and assessed these 13in the Magic Quadrant published on 16 June 2026. Nine confirmed their placement in their own announcements; the four marked “reported” did not, and their placement rests on analyst commentary rather than the vendors themselves.
IBM watsonx.governance
Leader
The strongest technical evaluation layer of the Leaders: bias, drift and explainability monitoring with published red-teaming notebooks, wrapped in GRC workflow through OpenPages. Governs non-IBM models, including OpenAI, AWS and Meta.
Headquarters
Armonk, New York, United States
Founded
1911 (IBM)
Funding
Public company (NYSE: IBM)
Pricing
Not publicly disclosed for the enterprise tier
Reviewers on Gartner Peer Insights describe integration effort and user experience as weak points. IBM's documentation features a bank called Golden Bank, which is a fictional tutorial company rather than a customer.
The broadest discovery reach of any platform here: 30 connectors spanning AWS, Google Cloud, Azure, SAP, Oracle and Workday, so the inventory extends well beyond ServiceNow's own environment.
Headquarters
Santa Clara, California, United States
Founded
2004 (ServiceNow)
Funding
Public company (NYSE: NOW)
Pricing
Not publicly disclosed
CIO's independent analysis criticises cost visibility, describing a 'hazy view of spend'. Several 2026 governance enhancements only reached general availability around August 2026.
By far the smallest of the three Leaders. Combines data-privacy tooling with AI governance, and delivers AI governance training through its own LMS. Offers up to $1M in financial protection for qualified customers under its Truyo Trust programme.
Headquarters
Phoenix metro, Arizona, United States
Founded
AI governance line from 2023; brand renamed from GDPR Edge in 2019
Funding
A product line of IntraEdge; no separate venture funding found
Pricing
Not publicly disclosed
Almost the entire capability picture is self-described; no independent technical review was found, which makes the Leader placement its main independent signal.
Process and inventory breadth, built on the privacy programme organisations already run — an existing GDPR and DPIA practice carries over directly. Continuous discovery of models, datasets and agents was extended in March 2026.
Headquarters
Atlanta, Georgia, United States
Founded
2016
Funding
Private; figures not established
Pricing
Not publicly disclosed
Evidence of native bias or robustness testing is thin; the platform assesses and documents rather than testing. TitanOS appears alongside OneTrust in search results as a consent-management reference, not an AI Governance customer.
Policy-pack architecture: laws and standards translated into structured requirements and controls that drive approval workflows. Pairs with Credo AI Lens, an open-source assessment library independently catalogued by the OECD — a rare piece of corroboration that is not vendor-owned.
Headquarters
Palo Alto, California, United States
Founded
2020
Funding
$21M Series B, July 2024
Pricing
Not publicly disclosed
Named customers: Booz Allen Hamilton, Mastercard independently corroborated
Booz Allen Hamilton is confirmed on Booz Allen's own site, making it one of the few independently corroborated customer relationships in this market. Claims elsewhere that Microsoft, Amazon and Databricks are customers trace to a competitor's blog and are not supportable.
Governs by enforcement at runtime rather than by documentation after the fact: requests from AI applications and agents route through Airia, so policy is applied inline. Architecturally distinct from the assessment-workflow tools it shares a quadrant with.
Headquarters
Atlanta, Georgia, United States
Founded
2024
Funding
$100M funded by co-founder John Marshall ($50M deployed, $50M pledged), September 2025
Pricing
Not publicly disclosed for the enterprise platform
The $100M is not a venture round but capital from a co-founder, so it carries no external investor diligence or valuation signal. Founded in 2024, and Gartner did not score market track record in this first edition, so the placement rests on product and vision alone.
The deepest audit trail found in this market: versioned point-in-time policy snapshots, so a reviewer can reconstruct which policy applied to which AI system on which date. Auto-generates model cards and audit artefacts.
Headquarters
Chicago, Illinois, United States
Founded
2018
Funding
$16M total; $10M Series B led by Baird Capital, August 2024
Pricing
Not publicly disclosed
Named customers: RBC Capital Markets, Fidelity Investments
Its Gartner Peer Insights rating of 4.9 rests on only three reviews. Heritage is model operations rather than rights-based compliance.
Built for examiner-facing proof rather than dashboards, across four modules covering policy, decision records, monitoring and audit evidence. Its control library maps to the NAIC AI model bulletin, giving it US insurance depth that generalist platforms lack.
Headquarters
Boston, Massachusetts, United States
Founded
2019
Funding
$6M Series A led by Cultivation Capital, May 2024
Pricing
Not publicly disclosed
A third-party review flags that EU AI Act and non-US framework mapping is not clearly documented and should be checked during procurement. Narrow sector focus outside insurance and financial services.
The deepest technical testing layer in this market — 40+ test types spanning robustness, explainability, toxicity, prompt injection, jailbreak and adversarial testing — and the only platform with a dedicated NYC Local Law 144 bias-audit product.
Headquarters
London, United Kingdom
Founded
2020
Funding
$35M, May 2024 (round name and lead investor not established)
Pricing
Not publicly disclosed
Named customers: Unilever
The sole Challenger in the quadrant. Claims that Adidas is a customer are not supportable. No evidence was found of third-party or vendor AI assessment, unlike several peers.
Security-led rather than policy-led. Builds an AI Bill of Materials, scans for exposed model and inference endpoints, and runs adversarial red-teaming that extends into the third-party AI supply chain — something most policy-first platforms do not attempt.
Headquarters
Short Hills, New Jersey, United States
Founded
2023, spun out of KPMG Studio
Funding
$25M Series A led by Telstra Ventures, October 2023; no later round found
Pricing
Not publicly disclosed
Impact assessments, human oversight workflow and bias testing produced no evidence, which plausibly explains the placement. KPMG retains a minority stake, giving an advisory channel most startups lack.
The most data-native platform here. Its Data Journeys mechanism tracks data in motion rather than static lineage, and impact assessments are pre-filled from observed data flows instead of questionnaires — a materially different approach to DPIAs.
Headquarters
San Mateo, California, United States
Founded
2020
Funding
$32.1M Series B led by Thomvest Ventures with M12, October 2024; ~$59M total
Pricing
Not publicly disclosed
Model-level governance is thin: no evidence of bias, robustness or red-team testing. Holds its own SOC 2 Type II, which is the vendor's compliance posture rather than a customer-facing feature.
Knowledge-graph architecture: risks, controls, policies and models are linked, so a registered system inherits its obligations automatically and they update as the system changes. The strongest public-transparency story here — it has built and operated public AI registers with government.
Headquarters
Helsinki, Finland
Founded
Not established
Funding
€1.75M seed led by Crowberry Capital, October 2023, including a €250k Business Finland grant
Pricing
Not publicly disclosed
Named customers: Scottish Government, Deloitte independently corroborated
The Scottish Government relationship is corroborated by a Scottish Government FOI release rather than a vendor case study, making it the best-evidenced customer claim in this market. Saidot's own marketing figures are internally inconsistent between pages, so they are not quoted here.
SAP markets no standalone AI governance product. Governance sits as a layer inside the SAP Business AI Platform, which makes it hard to buy for a non-SAP organisation — the structural reason for the placement.
Headquarters
Walldorf, Germany
Founded
1972
Funding
Public company (NYSE: SAP)
Pricing
Not publicly disclosed
Which product Gartner assessed could not be determined. SAP AI Agent Hub, the closest functional match, was slated for general availability in Q3 2026, while the Magic Quadrant required availability by 1 April 2026. SAP's framework coverage — EU AI Act, NIST, ISO 42001 and ISO 42005 — describes how SAP governs its own AI, not a customer-facing capability, and the two should not be conflated.
These come up constantly in the same buying conversations without appearing in the Magic Quadrant. Trustible and LatticeFlow AI were mentioned in the report rather than positioned in it — a distinction their marketing does not always make obvious.
Fiddler AI
Runtime observability and inline guardrails rather than governance paperwork. Scores prompts and responses for hallucination, toxicity, PII, prompt injection and jailbreak using purpose-built low-latency evaluator models.
Headquarters
Palo Alto, California, United States
Founded
2018
Funding
$30M Series C led by RPS Ventures, January 2026
Pricing
$0.002 per trace (Developer tier); free guardrails tier; enterprise not publicly disclosed
Named customers: Integral Ad Science
The only vendor across this entire market that publishes a price. Independent reviewers praise the LLM monitoring and criticise the learning curve. No AI inventory of record and no risk tiering, so it does not stand alone against EU AI Act documentation duties.
Model risk discipline for regulated finance, through SAS Model Risk Management and SAS AI Governance Manager. Chartis named SAS a category leader in AI governance and placed it second overall in RiskTech100 2026.
Headquarters
Cary, North Carolina, United States
Founded
1976
Funding
Privately held
Pricing
Not publicly disclosed
A notable negative finding: SAS markets around model-risk practice rather than named regulatory regimes, and no SAS page was found enumerating EU AI Act, NIST or ISO 42001 control mappings — unlike its competitors. Product boundaries between its several AI governance offerings are unclear.
Cross-framework control mapping — document a control once and map it across regimes — aimed at legal and compliance teams rather than ML engineers. Names Colorado SB 205 explicitly, and sells role-based AI literacy training delivered as SCORM into an existing LMS, which speaks directly to the EU AI Act's AI literacy duty.
Headquarters
Arlington, Virginia, United States
Founded
2023
Funding
$4.6M seed led by Lookout Ventures, June 2025
Pricing
Not publicly disclosed
Mentioned in the Magic Quadrant but not one of the 13 assessed vendors. No evidence it runs bias, fairness or robustness tests itself; these appear as mitigations it recommends others perform.
Adversarial testing wired into the build pipeline: simulated attacks run in CI so a build fails when too many succeed. Also operates as an independent external auditor for NYC Local Law 144 bias audits, which is a service rather than software.
Headquarters
Kitchener–Waterloo, Ontario, Canada, with a Swedish arm
Founded
2020 (as Fairly AI)
Funding
$2.2M seed reported by aggregators; no primary announcement found
Pricing
Not publicly disclosed
Fairly AI acquired Sweden's anch.AI on 18 June 2025 and the combined company rebranded as Asenion; anyone researching the old name will find two identities. Least independently verified vendor covered here — almost every capability claim traces to the vendor or a partner.
Software that helps an organisation inventory the AI systems it builds, buys and uses, classify them by risk, assess them against regulatory requirements, route approvals, collect evidence, and monitor deployed systems. Gartner created the category formally in June 2026 with its first Magic Quadrant for AI Governance Platforms, screening more than 100 vendors and assessing 13.
Which AI governance platforms did Gartner name as Leaders in 2026?
IBM, ServiceNow and Truyo were named Leaders in the inaugural Magic Quadrant for AI Governance Platforms, published on 16 June 2026. OneTrust, Credo AI, Airia, ModelOp and Monitaur were Visionaries, Holistic AI was the sole Challenger, and Cranium AI, Relyance AI, Saidot and SAP are reported as Niche Players.
How much does an AI governance platform cost?
Almost none of them say. Fiddler is the only vendor of the seventeen covered here that publishes a price, at $0.002 per trace on its developer tier with a free guardrails tier. Every other vendor requires a sales conversation, which makes budgeting and self-qualification difficult for buyers.
Do AI governance platforms make you EU AI Act compliant?
No platform delivers compliance on its own. None of them is certified against ISO/IEC 42001 for the governance product itself or holds a third-party attestation of its regulatory mappings, and two duties that organisations genuinely carry — transparency marking of AI-generated content, and training-data provenance — are not covered by any of them. Treat these tools as a way to run a programme, not as a substitute for one.
Which AI governance platform is best for a regulated insurer?
Monitaur has the clearest insurance specificity: its control library maps to the NAIC AI model bulletin, which generalist platforms do not. SAS brings long-established model risk management practice for regulated finance. Both are narrower than the horizontal platforms, which is the point.
Start from the obligations, not the vendors
Which platform you need depends on which regimes bind you. The compliance library sets out each one, with deadlines, penalties and official sources.