Skip to content
06Explore by AI architecture

Governance depends on what you're actually deploying.

An employee assistant, a RAG search, and an agent fleet share a framework but not a risk profile. Open the architecture your customer is building — each entry says what is distinctive, which layers work hardest, and where the incidents have been.

A general-purpose assistant for the whole workforce, usually with enterprise-data grounding.

The widest blast radius by population: every employee becomes a model operator, and the assistant inherits every permission problem in your document estate.

Where governance concentrates
7. People

Rollout gated by training; acceptable use named in behaviors; usage telemetry watched.

2. Data

Permissions cleanup before grounding; label/IRM exclusions; DLP on prompts and uploads.

6. Runtime

Tenant restrictions vs. personal accounts; audit logs of employee AI activity.

Data leakageShadow AIHallucination & grounding failure
How Google Cloud approaches this

Gemini Enterprise is the governed surface: admin agent allowlists, Workspace label/IRM enforcement, context-aware access, usage audit logs — with Chrome Enterprise Premium covering the shadow long tail.