EnableYourData.nl

AI governance

AI governance in practice: who sees what, and who approves.

AI governance is about the rules and controls around AI: which data an AI system may use, who sees which outputs, who approves what and how you demonstrate all that afterwards. ENABLE helps with access profiles and row-level security, AI that only receives metadata, confirmation of every AI suggestion, review of AI-built apps and an activity log. ENABLE does not automatically make you "AI Act compliant".

AI governance is the set of rules, roles and controls an organisation uses to determine how AI is deployed: with which data, by whom, with what oversight and with what evidence afterwards. It is closely linked to data governance, because AI is only as reliable and secure as the data and access underneath it.

In practice, AI governance comes down to five questions: who sees which data, what does the AI get to see, who approves AI outputs, what is logged and how do you switch it off? ENABLE gives a concrete answer to each of those questions within the platform.

What ENABLE is not: a full data catalogue, a lineage tool or a compliance solution for the EU AI Act. Below you can read what those terms mean and what ENABLE contributes.

Key points

AI governance at a glance

Who sees what

Three roles (platform admin, customer admin, user) and access profiles that bundle dashboards and apps. With "view as user" you check what someone sees.

Row-level security

You link profiles or user tags to Power BI roles. No tag means no access: there is no fallback to unfiltered data.

What the AI receives

Only metadata and the user's question, never rows or passwords. Through the permissions of the database user, you decide which tables are visible.

Human confirmation

AI output is validated and only used after a user action: in the SQL Explorer you run the query yourself; in the Dashboard Builder you choose "Apply proposal" or "Discard". The AI never puts anything into effect on its own.

Review before going live

Apps from the AI App Builder (pilot) and releases of custom apps are reviewed by the platform admins. Data sources for the Dashboard Builder (pilot) are approved first.

Activity log

Customer admins see activity in their organisation, such as executed queries and published endpoints. The platform admins have an event log, including embed sessions.

Limits

Queries run read-only, with a 45-second timeout and a limit on the number of queries per minute. Every executed, blocked or failed query is recorded in the audit log.

AI governance in ENABLE: who handles what?

What does the software enforce, and what do you agree on as an organisation? This is how it is divided:

QuestionWhat ENABLE doesWhat you arrange yourself
Who sees which data?Roles, access profiles, RLS on Power BI dashboardsWho gets which role; the RLS roles in your Power BI model
What does the AI get?Only metadata and the question; never data rowsWhich tables ENABLE's database user may see
Who approves?Confirmation per AI suggestion; review of apps and data sourcesWho may publish queries and request apps internally
What is logged?Query audit log, activity log, versions of published endpointsHow often and by whom the logs are reviewed
What can go wrong?Read-only, timeout, rate limitsData quality and definitions in your warehouse

Data governance: definitions, access and data security

Data governance covers the ownership, definitions, quality, access and security of data. Without that foundation, AI governance is difficult: if nobody knows what "revenue" means, an AI can't answer questions about it properly either.

ENABLE is not a data governance platform, but it does enforce part of it. Access is role-based (role-based access control): roles and profiles determine who sees which dashboards, apps and data. On top of that come two-step verification, encrypted secrets (AES-256-GCM) and automatic sign-out after 30 minutes by default.

  • Use one data warehouse as the source for dashboards, AI and apps.
  • Record definitions in views and saved queries, not in stray exports.
  • Grant permissions based on role and profile, as narrowly as the work allows.

Data catalogue and data lineage: what ENABLE does and doesn't offer

A data catalogue is an inventory of your datasets with descriptions, owners and classifications. Data lineage shows where a figure comes from: from source, through transformations, to report. Specialised tools exist for both; ENABLE is not one of them.

What ENABLE does offer helps with traceability within the platform:

TermWhat it isIn ENABLE
Data catalogueInventory with descriptions, owners, classificationsOverview of tables and columns in the SQL Explorer; no owners or classifications
Data lineageOrigin from source to reportThe query sits next to every result; no automatic lineage across your entire data landscape
Data dictionaryDescription of tables, columns and relationshipsThe structure the AI uses to write queries
Version controlWho changed what and whenPublished endpoints and custom dashboards with version history

AI Act compliance: what you need to know now

The European AI regulation (the EU AI Act) entered into force on 1 August 2024 and applies in phases. Since 2 February 2025, the ban on certain AI practices and the obligation to ensure sufficient AI literacy among staff who work with AI have applied. Since August 2025, rules for providers of general-purpose AI models have applied. For other obligations, such as those for high-risk AI systems, the EU is adjusting the schedule, so always check the current timeline.

Which obligations apply to you depends on your role (provider or deployer) and on the risk category of your application. This is not legal advice; have your application assessed by a legal expert if necessary. ENABLE does help you demonstrate which data goes to the AI and that there is human oversight, but it does not automatically make you compliant.

  • Make an inventory of the AI systems your organisation uses, including standalone tools.
  • Ensure AI literacy among staff who work with AI.
  • Record which data goes to which AI provider.
  • Keep human oversight of AI outputs and retain evidence of it.

In ENABLE

How to set up AI governance with ENABLE

  1. 01

    Set up roles and profiles

    Invite users, bundle dashboards and apps into access profiles and switch on row-level security if needed.

  2. 02

    Decide what the AI may see

    Give ENABLE's database user permissions only on the tables it needs. Choose whether regular users get the SQL Explorer with AI.

  3. 03

    Agree on approvals

    Agree who publishes queries and who requests apps. Pilot apps and data sources are reviewed by the platform admins before they go live.

  4. 04

    Monitor with the activity log

    Periodically review the activity log and, together with Data Analytics, clean up unused dashboards and access rights.

FAQ

Frequently asked questions

What is AI governance?

AI governance is the set of rules, roles and controls an organisation uses to determine how AI is deployed: with which data, by whom and with what oversight. It is also about evidence afterwards, such as logs and approvals.

What is the difference between AI governance and data governance?

Data governance covers the ownership, definitions, quality, access and security of data. AI governance builds on that and adds agreements on what an AI system may use, how outputs are checked and who is responsible.

Does ENABLE make us AI Act compliant?

No, not automatically. ENABLE helps with elements such as limiting the data that goes to the AI, human confirmation of AI suggestions and an activity log. Whether you comply with the AI Act depends on your role, your applications and your own policies.

Since when has the AI Act applied?

The AI Act entered into force on 1 August 2024 and applies in phases. The ban on certain AI practices and the AI literacy obligation have applied since 2 February 2025. The EU is adjusting the schedule for later obligations, so check the current timeline.

Does ENABLE have a data catalogue or data lineage?

No, not a full one. ENABLE does show your warehouse's tables and columns in the SQL Explorer, the query next to every result and the version history of published queries. For a catalogue with owners and automatic lineage, you need a separate tool.

Can we see who viewed which data?

Largely, yes. The activity log shows executed queries and published endpoints, among other things, and ENABLE records which user opens which dashboard. ENABLE does not record, click by click, what someone looks at within a dashboard.

Share securely, live fast, no headache

In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.