In brief
Software that carries AI policies through four steps: a register of AI systems, controls that enforce the policies, evidence that the controls worked, and reports for auditors. See the lesson What is an AI governance platform.
Governance applied to what AI agents do, not only what they say: which tools they may call, with what data, and with what record of each action.
Go deeper: Lesson 2: Agentic AI governance: what changes when AI takes actions
They overlap. Governance covers policy, ownership, registers and reports; security covers testing and runtime protection. The platforms on this site sit at different points between the two, which the control maps show.
Most frameworks assume one, so many programs start there. Programs whose first risk is a customer-facing assistant often start with testing and a runtime control, and build the register alongside.
Go deeper: Lesson 3: AI inventory and registers: knowing what AI you run
Inventory-first platforms start by finding and registering AI and reporting against frameworks. Enforcement-first platforms start by testing an application and putting a control in front of it. On our scores, Credo AI and Holistic AI are inventory-first; Pillar Security, Alice, SPLX and Lasso are enforcement-first.
Go deeper: Briefing: Inventory first or enforcement first: two ways to start AI governance
No. Software can keep records, enforce controls and produce reports. Compliance depends on the organization's decisions, documentation and oversight, which an auditor or regulator assesses.
Go deeper: Lesson 4: EU AI Act compliance software: what it needs to do
Help classify systems by risk and role, record risk management and testing, log behavior automatically, support human oversight and produce technical documentation and post-market monitoring records.
Go deeper: Lesson 4: EU AI Act compliance software: what it needs to do
Software that keeps the records an ISO/IEC 42001 AI management system needs: scope, risk and impact assessments, controls, monitoring, audits and corrective actions.
Go deeper: Lesson 5: ISO 42001 software: what an AI management system tool should cover
No. NIST describes the AI RMF as voluntary. Many organizations use its four functions, Govern, Map, Measure and Manage, as the structure of their program.
Go deeper: Lesson 6: NIST AI RMF: the four functions and what each needs from a platform
On our framework mapping criterion, Credo AI, Holistic AI and Pillar Security score highest with 9. Alice maps WonderFence guardrails to five frameworks: the EU AI Act, ISO 42001, NIST, MITRE ATLAS and OWASP.
Go deeper: Lesson 7: One control, many frameworks: mapping AI governance evidence once
Not in this lineup. SPLX publishes plan contents and refers to a free tier but quotes prices; the other five do not publish pricing.
Go deeper: Briefing: AI governance platform pricing: what is published as of October 2026
SPLX's pricing page refers to a free tier, and SPLX publishes Agentic Radar as open source on GitHub. None of the other five describes a free tier on the pages we read.
Pick one real system, write three to five policies for it, and ask each vendor to show the policy, the control, a piece of evidence and the report line for each. Our briefing sets out a 30-day plan.
Go deeper: Briefing: A 30-day proof of concept plan for an AI governance platform
Pillar Security with 6.88 on our published weights, followed by Alice (6.22) and Credo AI (6.00).
Three products: WonderBuild for pre-launch red teaming, WonderFence for runtime guardrails and WonderCheck for ongoing post-launch red teaming.
On AI discovery and inventory (2/10), third-party AI (1/10) and pricing transparency (1/10). Its pages do not describe an inventory or third-party register, and it does not publish prices.
Credo AI, which names a Third-party AI Registry on its product page.
Go deeper: Lesson 10: Third-party AI risk: governing AI you did not build
Alice and Pillar Security score 9 on policy to runtime enforcement.
In this lineup, SPLX states it is now part of Zscaler. Our consolidation briefing lists the other ownership changes shown on vendor pages in the wider market.
Go deeper: Briefing: AI governance vendor consolidation in 2026: who now belongs to whom
Alice states coverage in 100+ languages on its platform page. The other five do not state a language count on the pages we read.
Go deeper: Briefing: Multilingual and multimodal AI governance: why coverage belongs in the policy
Each platform gets 0 to 10 on eight weighted criteria from its own public pages. Total = sum of score x weight / 100, computed in code.
No. This is desk research from public vendor material, read on 1 October 2026. There was no hands-on testing.
Yes. The readiness score page re-weights the ranking from your answers, and every weight can be adjusted with a slider.