MLflow

Linux Foundation (MLflow project)

Open Source

Open-source AI engineering platform with OpenTelemetry-compatible GenAI tracing, LLM-judge evaluation, prompt registry and AI gateway.

Curated by Tiberiu ArvaVerified

Apache 2.0Version 3.16.1Released 2026-09-17

Strengths

  • Tracing supports OpenTelemetry GenAI conventions
  • Prompt registry with automated optimization
  • Managed on Databricks, SageMaker and Azure ML

Practitioner note

The natural choice for teams already running MLflow for classic ML, since GenAI traces, evals and prompts sit beside existing experiments and models. Upgrade self-hosted servers to 3.16.1 or later, which removed a default basic-auth admin password.

Governance posture

Reviewed 2026-09-30
YesData residency

Self-hosted: trace data is stored on the operator's own infrastructure. Managed variants follow the hosting cloud's region.

Source
YesDeployment model

Self-hosted OSS server, or managed through Databricks, AWS SageMaker, Azure Machine Learning or Red Hat OpenShift AI. (self-hosted, saas)

Source
UnknownAudit logging

The GenAI docs describe trace capture but not a native user or admin audit log for the OSS server. Managed platforms may add their own.

N/ASOC 2

Self-hosted open-source software. SOC 2 applies to the operator or the managed-service provider, not the package.

N/AISO 27001

Self-hosted open-source software. ISO 27001 applies to the operator's ISMS, not the package.

N/AISO 42001

Self-hosted open-source software. ISO 42001 applies to the deploying organisation.

N/AEU AI Act

Developer and observability tooling, not an AI system placed on the market. Obligations rest with the deployer. (role: not-applicable)

YesLicense risk

Apache 2.0, a permissive OSI-approved license. (low)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from MLflow's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Change history

Source-backed and auto-detected events for this tool, newest first.

  1. Release

    MLflow 3.16.1 removed the default basic-auth admin password (a security fix for self-hosted servers) and added scorer timeouts.

    Release v3.16.1 · mlflow/mlflow

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.