What Is a Model Council in AI Governance?

Emily Winks, Data Governance Expert, Atlan
Data Governance Expert
Updated:07/22/2026
|
Published:07/22/2026
14 min read

Key takeaways

  • A model council is a governance committee, not the Microsoft/Perplexity multi-model feature of the same name
  • At least a dozen enterprises now run one, and most trade speed for risk
  • Only 39% of Fortune 100 boards disclose AI oversight, per McKinsey
  • Councils that review documents alone miss what a model actually touches

What is a model council?

A model council is the cross-functional committee, typically legal, risk, security, and data science, that reviews and approves AI models before and after production. It is not the multi-model comparison feature Microsoft 365 Copilot and Perplexity ship under the same name. Most councils run on intake forms, risk tiers, and static documents, model cards, risk assessments, policy PDFs, rather than live visibility into what a model actually touches. Atlan's context layer gives a council the lineage and business definitions a document alone cannot show.

A model council typically covers

  • Intake and registration of proposed models or agents before review
  • Risk-tiering that determines review depth
  • Cross-functional review by legal, risk, security, and data science
  • Approval, rejection, or conditional sign-off with required changes
  • Periodic re-review on a calendar or context-drift trigger

Is your data estate AI-agent ready?

Assess Your Readiness

A model council is the cross-functional committee, legal, risk, security, and data science, that reviews and approves AI models before they reach production, not the multi-model comparison feature Microsoft 365 Copilot and Perplexity ship under the same name. Per McKinsey (2025), only 39% of Fortune 100 boards disclose AI oversight, and councils need live visibility into what each model actually touches, not just a folder of documents. Collibra, IBM, OneTrust, and Bitsight all frame the council’s job as reviewing static documents: model cards, risk assessments, policy PDFs.


Atlan’s context layer gives a model council the evidence a document-based review cannot: the Context Lakehouse traces data source, model, and downstream decision in one place instead of scattered spreadsheets and interviews. Context Agents, Orion the Ontologist and Vera the Quality Scorer among them, keep the business definitions a council would otherwise take on faith current and queryable. That turns a council’s review from reading a PDF into inspecting a live graph.

Attribute Detail
What it is The cross-functional committee, legal, risk, security, data science, and business unit leads, reviewing and approving AI models before and after deployment
Not to be confused with Microsoft 365 Copilot’s and Perplexity’s “Model Council” feature, or the 1990s “Compact Model Council” semiconductor standards body
Key benefit Centralizes AI risk decisions so approvals and audit trails trace to one accountable body, not ad hoc, per-team sign-off
Best for Regulated or model-risk-mature enterprises (banking, insurance, healthcare) already running or standing up formal AI governance
Core stages Intake, risk-tiering, cross-functional review, approval or rejection, periodic re-review
Governed by Cross-functional membership plus live visibility into the lineage and context each model touches, not documents alone

What is a model council?

Permalink to “What is a model council?”

A model council is the standing, cross-functional body, legal, risk, security, and data science leaders with an executive sponsor like a Chief Data Officer, that reviews AI models and agents before they go live and periodically after. Per Microsoft’s support documentation (Microsoft, 2026), Microsoft’s and Perplexity’s “Model Council” feature instead runs several LLMs side by side inside Copilot Researcher and reconciles answers with a judge model, unrelated also to the 1990s “Compact Model Council” semiconductor standards body.

No governance vendor uses “model council” as its own term of art; Collibra, IBM, OneTrust, and Bitsight write about “AI governance council” or “model risk committee” instead, though practitioners like LangChain’s Harrison Chase increasingly say “model council” out loud.

“Model council”: three meanings

Meaning Who uses it What it actually is
AI governance body (this page) Enterprises standing up formal AI oversight, including GM Committee reviewing and approving AI models before and after deployment
Multi-model comparison feature Microsoft 365 Copilot Researcher, Perplexity Runs multiple LLMs side by side and reconciles outputs with a judge model
Compact Model Council (unrelated) Semiconductor industry (SPICE modeling, 1990s to present) Standards body for circuit-simulation models, no connection to AI

The rest of this page uses “model council” in the first sense only, and argues that sense has a blind spot most coverage misses. Reviewing a model without inspecting the context layer it depends on is reviewing Intelligence without reviewing Context, and a council can only govern what it can actually see.


Model council vs AI governance board vs model risk committee: what’s the difference?

Permalink to “Model council vs AI governance board vs model risk committee: what’s the difference?”

A reader arriving from a “model risk committee” or “AI governance council” search needs to see how these terms relate.

A model council is a specific instrument inside a broader AI governance program, operationalizing what a broader framework names as AI agent risks and guardrails. Governing the program, policies, roles, accountability, is a different job from governing one model’s approval, though many enterprises run both through the same committee.

“Model risk committee” is the older, banking-specific version, rooted in SR 11-7-style validation and its 2026 successor SR 26-2 (IBM, 2026), predating large language models and assuming a model is a single statistical artifact, not an agent calling tools against live systems. “AI governance council” is the broadest umbrella term, and a model council is one instrument that program runs, alongside risk management.

Whichever label an organization uses, reviewers ask the same question: what does this model actually do, and to what data, only as answerable as the governance context feeding it, what most programs leave undefined.

Council decisions are only as good as their inputs

See how the AI Context Stack brief maps the layers, from data to context to models, that a governance review should actually inspect before approval.

Get the AI Context Stack

How a model council works: intake, tiering, and approval

Permalink to “How a model council works: intake, tiering, and approval”

This page’s research synthesizes a recurring five-stage pattern: intake, risk-tiering, cross-functional review, approval or rejection, and periodic re-review, most of it still running on documents instead of live context.

Intake: a proposed model is registered, often through a questionnaire. The most mature version in this research is a healthcare enterprise’s “AI front door,” which risk-scores every incoming AI idea automatically.

Risk-tiering: the request is tiered low, medium, or high, setting review depth, the same triage logic used to screen incoming privacy risk.

Cross-functional review: legal, risk, security, and data science evaluate the model against policy, including agent memory governance for stateful agents. Bitsight’s AI Leadership Council, led by Chief Risk Officer Derek Vadala, is a public worked example.

Approval or rejection: the council approves, rejects, or conditionally approves with required changes; a conservative default is common among enterprises still building out formal model governance.

Periodic re-review: where a cadence exists, it’s usually calendar-based rather than tied to when the underlying context actually changes, where the document-based pattern breaks down most visibly.

Aspect Document-based council Context-aware council
Primary input Model cards, risk-assessment PDFs, static intake questionnaires Live lineage, business definitions, and data-touch visibility from the context layer
Review basis What the submitting team says the model does What the context graph shows the model actually touches
Re-review trigger Calendar-based, quarterly or annual Context-drift-based, re-triggered when underlying data or lineage changes

The difference is not process maturity, it is what the council is allowed to see: a council with governed context, current training data lineage, and a semantic layer it can trust judges Intelligence against what the model actually touches.

Model council governance flow: intake to periodic re-review

A model council's 5-stage governance flow. Source: Atlan.


Why enterprises are standing up model councils now

Permalink to “Why enterprises are standing up model councils now”

Regulatory pressure is a direct driver. The EU AI Act and Colorado AI Act both create board-level accountability that didn’t exist before large language models, and statutes like GDPR for AI agents and HIPAA add model-specific requirements in healthcare.

In conversations with enterprise data and AI leaders, Atlan has heard from at least 12 organizations across entertainment, sports, financial services, retail, and insurance describing a standing AI or model governance council, most citing friction between speed and risk. GM, whose Chief Data and Analytics organization has spoken publicly about its AI governance work, is one confirmed example; the broader pattern suggests this is now common at the AI-mature enterprise.

Yet the gap at the top is still wide. Per McKinsey’s 2025 board-oversight analysis (McKinsey, 2025), 88% of organizations use AI in at least one function, but only 39% of Fortune 100 companies disclose board-level AI oversight. Per McKinsey’s State of AI Trust research (McKinsey, 2026), roughly one in three enterprises call themselves “governance-ready” for autonomous agents, meaning most councils are forming under time pressure.

This pattern is strongest at regulated, model-risk-mature enterprises, banking, insurance, healthcare, where model risk management predates large language models, why the context gap this page names shows up sharpest in that segment.


How do you build a context-aware model council?

Permalink to “How do you build a context-aware model council?”

Start with risk-tiering, but make the tier itself auditable against live data sensitivity and lineage, not a self-reported checkbox. A tier nobody can verify is a guess with a label on it. Give reviewers who lack ML literacy a context layer to query instead of a PDF; the same gap is why training data bias detection matters to a council.

Decide centralized versus federated deliberately. Per Gartner analyst Shiva Varma (CIO Dive, 2026), uniform controls either over-restrict simple agents or under-restrict autonomous ones, since the council cannot tell them apart without context on what each touches. A centralized AI platform and a shared AI agent harness give a council one place to see that difference.

Adopt hybrid governance: centralized policy, federated approval for low-risk cases. Gartner’s AI TRiSM framework (Gartner, 2026) confirms hybrid is the dominant 2026 approach, without requiring a team to abandon the LLMOps platforms it already runs.

Finally, set a context-drift trigger for re-review, not just a calendar date, so an approval expires when the data behind it changes materially, per context drift detection. For the version history a council approves, see AI model versioning best practices.

How context-mature is your council's review process?

Run the Context Maturity Assessment to see where your organization's model reviews rely on documents versus live context.

Take the Assessment

How to evaluate whether your model council needs more context visibility

Permalink to “How to evaluate whether your model council needs more context visibility”

This section gives a scorecard for auditing an existing council’s context maturity, distinct from building one from scratch, covered above.

Criterion Why it matters What to look for
Context visibility Councils reviewing PDFs alone repeat the gap this page names Live access to lineage and data-touch mapping, not just a model card
Risk-tiering trust Self-reported tiers are only as good as who reports them Tiers checked against actual data sensitivity, not self-assessment
Re-review trigger Calendar-only re-review misses mid-cycle drift A trigger tied to lineage or definition changes, not just a date
Ownership clarity Council-vs-context ownership is unresolved at many enterprises A named owner for context decisions, distinct from the council owner

Organizations that answer these well have usually invested in data management for LLM deployments and a clear owner for metadata’s role in enterprise AI. A council that can’t name who owns the access control policy it just approved has a gap no meetings will close.

A council that scores poorly here is not necessarily a bad council, just one still running on documents. The fix is visibility, not more meetings.


What common mistakes do model councils make?

Permalink to “What common mistakes do model councils make?”

This page’s research surfaces one mistake no competitor states directly: approving models without inspecting the context layer they touch, alongside two related patterns.

  1. Approving based on documents alone. Every governance resource surveyed, Collibra, Bitsight, OneTrust, IBM, and Security Today’s roundup of governance mistakes (Security Today, 2026), frames council inputs as model cards and PDFs, never live lineage. Fix: a context layer to query, not a folder to read.
  2. Uniform review depth for every model. Treating a low-risk chatbot the same as a customer-facing agent touching regulated data either slows delivery or under-scrutinizes risk. Fix: tier by context-verified risk, enforced through guardrails the council can audit.
  3. “Governance theater.” Councils that exist so people can say the committee approved it, not to catch real risk. Fix: make the SLA and re-review trigger explicit and public.

A genuine counter-view exists: some practitioners report that making risk tiers explicit alone already reduces friction. Per Joseph Ours of Centric Consulting (Forbes, 2026), most governance frameworks were designed for models under internal supervision, an assumption agentic systems already break; risk-tiering is only as trustworthy as the data behind the tier, current and governed, not simply labeled.

Ready to give your council more than a PDF?

Use the AI Agent Context Readiness Checklist to see what visibility your team is missing before the next model review.

Get the Readiness Checklist

Real stories from real customers

Permalink to “Real stories from real customers”

"AI initiatives require more context than ever. Atlan's metadata lakehouse is configurable, intuitive, and able to scale to hundreds of millions of assets. As we're doing this, we're making life easier for data scientists and speeding up innovation."

Andrew Reiskind, Chief Data Officer, Mastercard

"Context is the differentiator. Atlan gave our teams the shared vocabulary and lineage to move from reactive data management to proactive AI enablement across CME Group."

Kiran Panja, Managing Director, Data & Analytics, CME Group


Why model councils need a context layer, not just a committee

Permalink to “Why model councils need a context layer, not just a committee”

Model councils are the human decision body. Across the enterprises in this research, reviews run against documents, model cards, risk assessments, static questionnaires, not live visibility into what those models touch. Boards already ask the context questions manually, per use case, evidence that councils want this information but currently gather it by interview instead of by inspecting a governed context layer.

Atlan’s Context Lakehouse and Context Agents, Orion the Ontologist, Sage the Metric Arbiter, Vera the Quality Scorer among them, give a council that same live trace instead of stitched-together spreadsheets and interviews. A model council is a governance instrument inside the broader AI control plane, and it only governs well if the context engineering underneath is itself trustworthy.

GM’s Brian Ames put it directly: “We need to go from pockets of limited AI and ML execution to really building AI into the DNA of GM… we use Atlan for end-to-end visibility from the cloud all the way back to our on-prem.” That visibility turns a council’s review from reading a PDF into inspecting a live graph.

The fix is not a new committee structure. It is giving the committee that already exists a governed context layer to query, so risk-tiering, approval, and re-review all rest on what a model actually touches, not what a form says it touches.


FAQs about model councils

Permalink to “FAQs about model councils”

1. What is a model council in AI governance?

Permalink to “1. What is a model council in AI governance?”

A model council is the cross-functional committee, typically legal, risk, security, and data science, that reviews and approves AI models before and after production. It is not the multi-model comparison feature Microsoft 365 Copilot and Perplexity ship under the same name.

2. What is the difference between a model risk committee and a model council?

Permalink to “2. What is the difference between a model risk committee and a model council?”

A model risk committee is the older, banking-specific term rooted in statistical model validation (SR 11-7 and its successor SR 26-2) that predates large language models. Model council is the emerging, broader term for the same review function across any industry.

3. What is the biggest mistake a model council can make?

Permalink to “3. What is the biggest mistake a model council can make?”

Approving models based only on static documents, model cards, risk assessments, and policy PDFs, without visibility into the actual data and systems a model touches. This is reviewing Intelligence without reviewing Context.


Sources

Permalink to “Sources”
  1. Microsoft Support, “Use Model Council with Researcher in Microsoft 365 Copilot,” 2026: https://support.microsoft.com/en-us/topic/use-model-council-with-researcher-in-microsoft-365-copilot-32e84232-3c62-4144-9ccd-00bb9d9e4ec2
  2. IBM, “What Is Model Risk Management?” 2026: https://www.ibm.com/topics/model-risk-management
  3. Bitsight, “How to Set Up and Run a Workable AI Council to Govern Trustworthy AI,” 2026: https://www.bitsight.com/blog/how-set-and-run-workable-ai-council-govern-trustworthy-ai
  4. McKinsey, “The AI Reckoning: How Boards Can Evolve,” 2025: https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/the-ai-reckoning-how-boards-can-evolve
  5. McKinsey, “State of AI Trust in 2026: Shifting to the Agentic Era,” 2026: https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era
  6. NIST AI Resource Center, “AI RMF Playbook, Govern Function,” 2024: https://airc.nist.gov/airmf-resources/playbook/govern/
  7. CIO Dive, “Enterprises risk agentic AI failure under ‘one-size-fits-all’ governance,” 2026: https://www.ciodive.com/news/Enterprises-agentic-failure-uniform-governance/821153/
  8. Gartner, “AI Governance Needs More Than Policies,” 2026: https://www.gartner.com/en/articles/ai-governance-trism
  9. Forbes Tech Council, “Enterprise AI Governance Is Missing Its Third Layer” (Joseph Ours), 2026: https://www.forbes.com/councils/forbestechcouncil/2026/07/20/enterprise-ai-governance-is-missing-its-third-layer/

Share this article

signoff-panel-logo

Atlan is the Context Layer for AI. It's the control plane that stitches together a business's disparate data infrastructure, enriching data with the business context that AI systems, and the people governing them, need to actually understand what they're working with.

Bridge the context gap.
Ship AI that works.

[Website env: production]