For most of the last two years, an AI governance program could be judged by its documents. Was there an acceptable-use policy? A risk framework? A council that met? Those still matter.
What’s changed in 2026 is who’s asking and what they want to see. Regulators and insurers have started asking a narrower question: show us what actually happened.
A policy says what should happen. Only a record says what did.
The calendar, stated carefully
AI regulation dates get repeated loosely, so here they are with some care. None of this is legal advice; take the dates to your counsel.
2 August 2026, EU AI Act. The transparency duties in Article 50 now apply, as do the penalties for providers of general-purpose AI models.1 The standalone high-risk obligations for Annex III systems come later: the Digital Omnibus moved them to 2 December 2027.2 Anyone telling you high-risk enforcement started this summer has the date wrong.
1 January 2027, Colorado. Colorado repealed its original AI Act and replaced it with S.B. 189, the Automated Decision-Making Technology Act. The new law drops the impact assessments and concentrates on three things: notice that an automated decision is being made, a plain-language explanation within 30 days of an adverse decision, and the right to human review.3
The Colorado change is the one worth dwelling on, because it turns governance into a records problem. You can only explain a decision you logged. Thirty days after someone is turned down, you need to say what system acted, on what data, under whose authority. If that was never written down, no amount of policy reconstructs it.
Insurers got there too
The less expected pressure comes from underwriters. In its 2026 Magic Quadrant for AI Governance Platforms, Gartner notes that one reason organizations are buying governance tooling is to satisfy cyber and AI liability insurers, who increasingly want to see strong AI controls before they’ll write cover.4
That puts a price on missing evidence. A regulator’s question arrives occasionally. An insurer’s can arrive at every renewal, with the cover itself depending on the answer.
Evidence is a record written as it happens
Evidence has one defining property: it’s written at the moment of the action, by the system that performed it. A reconstruction assembled after an incident, from memory, Slack threads and three vendors’ exports, is a narrative. Auditors can tell the difference, and so can lawyers.
What should that record contain? One record per action, answering five questions:
- Who asked. The person or process that triggered it.
- Which identity it acted as. The account the action ran under, which may not be the person who asked.
- Which system and which data. What it touched, read or changed.
- What it cost. Model and compute spend, so the record also serves the people paying for it.
- Who owns it. The named person accountable for the agent, app or workflow that acted.
Three kinds of thing generate these actions: agents calling tools, the apps people build with AI assistants, and the workflows and integrations that move data between systems. Each produces actions. Each needs the same five answers.
Three readers, one record
The same record serves three readers, and each reads it for a different reason.
Your security team reads it when something looks wrong. Which agent pulled those records, as whom, and did it have reason to?
Your auditor, or a regulator, reads it to test a claim. The Colorado-style request for an explanation of a decision is exactly this: a question about one action, months later.
Your AI council or governance office reads it in aggregate. What is running, who owns it, what it costs and whether the portfolio matches what the council approved.
If each reader has to go to a different system for their answer, what you have is three partial records. The questions that matter tend to fall in the gaps between them.
Where AI governance platforms fit
There is now a Gartner Magic Quadrant for AI governance platforms, so it’s fair to ask whether one of those solves this. Partly, and the distinction is worth being precise about.
Those platforms hold the registry of AI systems, the risk assessments and the policy. They depend on runtime systems, the places where agents, apps and workflows actually execute, to enforce that policy and to emit the evidence.4 They sit in a different layer. Most organizations with a serious program will likely want both: a governance platform to decide and track, and a runtime that enforces the decisions and writes the record.
Five point tools means five logs
The obvious route is to solve each control with its own product: an MCP gateway for agents, a hosting platform for AI-built apps, an iPaaS for workflows, a masking tool for data and a FinOps dashboard for spend. Each will do its own job.
The problem appears when someone asks for evidence.
| What changes | Solved one tool at a time | One control plane |
|---|---|---|
| Identity | Five identity models, mapped by hand | One identity model for agents, apps and workflows |
| Credentials | Secrets held in several places | One credential store |
| The log | Five logs, five formats, five consoles | One audit trail |
| An auditor asks what an agent did | Someone stitches the answer together | One query |
When the auditor asks what an agent did, as whom, against which system and at what cost, the answer is spread across five consoles, each with its own idea of who a user is. You become the integration layer for your own evidence.
The fair counterpoint deserves a straight answer: “one tool to rule them all” is a pitch you should be suspicious of, from any vendor. The argument here is narrower. Governance as a whole will span several tools, including the governance platforms above. What should share one place is everything that touches your systems, because that’s where identity, credentials and the record have to agree. The gateway in front of every agent is the first piece of that, and it only produces useful evidence if the apps and workflows write to the same trail.
How Tray does it
On Tray, agents, apps and workflows share one identity model, one credential store and one audit trail, on the same foundation. Tray iPaaS runs the integrations, automations and agents, with immutable logs and step replay.
Tray Helix contributes the record for the apps people build in Claude Code, Codex and Cursor: execution logs for every run, an access audit trail, and an app registry entry with a named owner for every app. The evidence is written because the app runs on the platform, whether or not anyone remembered to write it down.
Footnotes
-
Regulation (EU) 2024/1689 (the AI Act), Official Journal of the European Union, 12 July 2024: Article 50 and the application dates in Article 113. Back
-
European Commission, Digital Omnibus on AI, amending the application dates of the high-risk obligations, 2026. Back
-
Colorado S.B. 189, the Automated Decision-Making Technology Act, as summarized by Skadden, Arps, Slate, Meagher and Flom, June 2026. Back
-
Gartner, “Magic Quadrant for AI Governance Platforms,” G00841467, Kornutick, Agarwal, Sundararaman, Henein, Medford, 16 June 2026. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. Back Back
