AI capabilities
What is AI Usage Governance?
Tracking and setting policy over AI-generated code entering your codebase.
As AI writes a growing share of committed code, organisations increasingly need to answer governance questions about it: how much of this release was model-generated, was it reviewed to the same standard, does any of it violate our policies.
Note the distinction that matters when comparing tools: governing *the code the AI wrote* is a different capability from inventorying *which AI tools your developers use*. Both get marketed as AI governance; only the first tells you anything about your codebase.
Top 4 AI Usage Governance tools
Every tool in the directory documented as supporting AI Usage Governance, with what its own documentation says.
Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
- 1
AI Inventory, AI Risk Hub and org-wide AI Coding Policies govern AI-generated code; Business plan.
- 2
Quality Gates for AI Code govern AI-generated changes in real time across repositories.
- 3
Usage analytics, AI code tracking API, repository/model/MCP access controls, OpenTelemetry usage export.
- 4
Enterprise quality gate and quality profiles specifically govern agentic AI-generated code.
What to look for
- Whether it governs generated code or merely inventories AI tooling
- How AI-authored code is identified in the first place
- Whether policies can be enforced at merge time
- Reporting suitable for an audit or board-level question
Related terms
FAQ
What is AI Usage Governance?
Tracking and setting policy over AI-generated code entering your codebase.
How many tools support AI Usage Governance?
4 of the 20 tools tracked in this directory support AI Usage Governance, including Codacy, CodeScene, Cursor (Bugbot), SonarQube. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
What should you look for in AI Usage Governance?
Whether it governs generated code or merely inventories AI tooling. How AI-authored code is identified in the first place. Whether policies can be enforced at merge time. Reporting suitable for an audit or board-level question.