An AI policy document can be written, approved and filed without any connection to what the running system does. The controls that can be checked live in the product: a telemetry setting someone chose, a record of decisions the application writes, an approval check where the action happens, and an off switch that has been tested. A governance program covers more than these, including who is accountable and which uses are allowed at all, but these are the parts a reviewer can inspect in code.
What Model Telemetry Records by Default
In a .NET application using Microsoft.Extensions.AI, wrapping a chat client with UseOpenTelemetry adds the OpenTelemetryChatClient. It emits spans and metrics following the OpenTelemetry semantic conventions for generative AI, which are still experimental, so model calls appear in the tracing system that already carries web requests and database queries.
What those spans contain by default is metadata. The EnableSensitiveData reference for version 10.9.0 says telemetry includes items such as token counts, but not raw inputs and outputs: message content, function call arguments and function call results. The property defaults to false unless the environment variable OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT is set to "true", and setting the property explicitly in code overrides the variable.
That leaves content capture decided by deployment configuration unless someone pinned it in code. Whether a changed environment variable reaches a process that is already running depends on how the application reads its configuration; plan on a restart or reload and confirm the result in the trace. Turning content on gives you something to reconstruct a disputed answer from, and it also puts customer messages and tool arguments inside the observability stack under that stack's access and retention rules. Set the value in code, where a reviewer can see it.
Before telling a customer your traces follow a published standard, check the source. The convention page the Microsoft documentation links to now says the GenAI semantic conventions have moved to a separate repository.
The Decision Record Beside the Trace
Model telemetry describes model calls. Nothing in the OpenTelemetryChatClient documentation says it records a human override, an approval, or the business outcome of an action, and trace retention is whatever the tracing backend keeps, which may be far shorter than an audit requirement. Those events need their own records, written by the application at the point they happen: who asked, which action was proposed, who approved or overrode it, and what was written. Store them where the retention and access rules are chosen for audit, and put the trace identifier on each row so the two can be joined.
LoggingChatClient, added with UseLogging, writes chat operations to an ILogger. Whether those entries can be queried later depends on the logging provider. The reference also limits what they hold: message contents and options are logged only when the logger enables Trace level, which the documentation says is disabled by default and should never be enabled in production. It is a diagnostic aid and does not supply the content record either.
Someone has to be assigned to read these records, with a stated purpose for each review: override counts, failed actions, and which model handled the traffic.
Where the Approval Check Belongs
A chat client in Microsoft.Extensions.AI is a pipeline of delegating clients. The DelegatingChatClient reference says its default implementation simply passes each call to the inner client, and tool calls are carried out separately, by function-invocation handling that runs the functions and arguments the model requested, as described in the IChatClient guide. A wrapper around the model request sees a request to a model. It does not, by existing, approve the refund or record change a tool later performs.
Put the authorization and approval check where the business action executes, using the actual caller and the validated arguments that will be written. The check should run on every attempt, including calls the function-invocation loop makes after an earlier failure, so each retried call is judged again on the arguments the model chose that time. It should reuse the permission checks the application already applies to a person doing the same action at a screen. Permission to act is not approval of a particular action: where the action needs a person's approval, such as a refund, the tool can prepare it, and the application commits it only after an authorized person approves those exact details on its own screen. A value in the model's output does not count as that approval.
An Off Switch That Has Been Tested
Test an explicit feature flag with a request waiting to run, an action queued for retry and a background job ready to dispatch. With the flag off, each path should refuse the work before any model request or downstream write. Check the model-call and action records to verify the result.
Removing a Use registration from the chat client pipeline is not an off switch. If that registration was the component checking actions, removing it takes the guard away and leaves the underlying model client working.
What NIST and the EU Regulation Say
Two external documents are worth reading directly before answering an AI questionnaire. The NIST AI Risk Management Framework is intended for voluntary use, and it organizes the work into four functions: Govern, Map, Measure and Manage. NIST also published a Generative AI Profile, NIST-AI-600-1, on July 26, 2024. The framework is a way to decide what a review covers. It does not certify a system.
Regulation (EU) 2024/1689, the EU's harmonised rules on artificial intelligence, may apply depending on where a system is offered or used, the company's role, and how the use is classified. That classification is a legal question for counsel working from the regulation text.
Related Reading
What Your Search Index Still Answers After You Revoke Access covers keeping AI answers inside existing permissions. MCP tool permissions in .NET applications covers the authorization boundary when AI reaches other systems.