How does an AI registry relate to AI risk management?
The registry is where risk classifications, assessments, and approval decisions are recorded against each system, making it the reference point for [AI Risk Management](/glossary/ai-risk-management). It records the outcomes of that work but doesn't replace the assessments themselves.
Related terms
AI Risk (Risk Vectors)
The potential for data exposure, privacy violation, or non-compliance created when sensitive information is processed by AI without safeguards.
AI Risk Management
Knowing an AI system exists is not the same as knowing what could go wrong with it — risk management is the discipline that turns visibility into an actual assessment of exposure, and exposure into something an organization can act on.
Hallucination (AI Hallucination)
An AI model generating output that's fluent, confident, and entirely wrong — not a bug that occasionally slips through, but a structural property of how these models work, which means the real question isn't whether hallucination happens, but what catches it before someone acts on it.
HIPAA (Health Insurance Portability and Accountability Act)
The US law governing how protected health information can be used, stored, and shared — and one of the clearest examples of a regulation written decades before AI existed that now has to be applied, without modification, to AI tools its drafters never anticipated.
How does agent governance relate to an audit trail?
An audit trail is one of the concrete outputs agent governance typically requires — a record of what an agent did, when, and under what authorization, which supports both internal accountability and the kind of documented oversight regulators increasingly expect for autonomous, multi-step AI systems.
How is AI agent governance different from AI governance generally?
AI Governance covers policies and oversight across an organization's entire AI footprint. AI agent governance is a narrower, more specific discipline focused on the particular risks agents introduce — autonomous decision-making, tool use, and chained multi-step actions — that general AI policies weren't originally built to address.
See How does an AI registry relate to AI risk management? in practice
Questa AI anonymizes sensitive data before it reaches any AI model — across documents and live prompts, with governance and data-residency control.