Microsoft’s answer to runaway agent deployments is to move governance into the runtime. A new reference architecture from the company turns policy enforcement, evaluation and audit into a continuous operational loop rather than a stack of documents.
The loop runs through five stages. Policies set requirements and risk classes, controls translate them into access and runtime rules, observability records system behavior, evaluations probe quality and safety, and audits convert telemetry into compliance evidence.
The framework spans nine domains, covering policy, data, models, observability, evaluations, security, identity and access, audit and compliance, and the agents themselves. Enforcement can reach across the full interaction chain, from users and agents to models, tools, APIs, MCP servers and enterprise systems.
Microsoft Foundry anchors the blueprint, with Purview, Entra ID, Defender and Azure API Management filling out the stack.
The AI Gateway inside Foundry is where the rules actually bite. Authentication checks, token limits, quotas and policy decisions all happen at that boundary. The same gateway governs MCP tools, layering rate limits, IP restrictions and audit logs over every call.
Cloud solution architect Manasa T. Ramalinga argues production AI demands re-architected foundations, not governance bolted on afterward.