Artificial intelligence is becoming part of everyday life and increasingly influences decisions about work, money, health, services and business operations. As that happens, it is no longer enough for an organisation to say that protections exist. What matters is whether those protections can actually be used when something goes wrong.
The AI Protection Tests are a practical set of checks designed to answer that question. They focus on whether people and organisations still have meaningful control, whether important decisions can be challenged, whether businesses can protect themselves from over-dependence on AI providers, and whether oversight bodies can genuinely examine and act on failures.
The framework contains four separate tests. The Control Test looks at people who choose to use AI and asks whether they understand what happens to their information, whether they can limit access, check important answers, stop the AI acting and leave the service without losing something important. The Accountability Test looks at people affected by AI they did not choose, such as someone applying for a job, loan or essential service. It asks whether they know AI is being used, can correct wrong information, obtain evidence, challenge a decision and seek meaningful redress.
The Business Test looks at organisations that depend on AI providers. It asks whether the business understands which important operations depend on the provider, whether it can retrieve records and evidence, continue operating if the service fails, move to an alternative and end the relationship without unacceptable damage.
The Oversight Test looks at auditors, regulators and other organisations responsible for checking AI systems. It asks whether they are sufficiently independent, whether they can obtain the evidence they need, report uncomfortable findings, be challenged themselves and ensure that serious failures lead to action.
Each question is answered YES or NO. A YES means the protection can be demonstrated through evidence, practical capability or an effective process. A NO means that the protection has not been established. The tests do not produce a score or maturity rating and they do not prescribe one particular solution. Their purpose is simpler: to establish whether a protection that should exist actually exists in practice.
Standardized Definition of AI Governance
A public reference standard that defines AI governance as a measurable structural condition, moving beyond policy statements to test whether control, accountability, traceability and integrity can be demonstrated in practice across the AI lifecycle.
A quantitative AI governance metric designed to measure how much of an AI system remains provable when models, APIs, vendors or other upstream dependencies change. ERR focuses on traceability, reconstructability, version fidelity and dependency proof to assess whether governance can survive change.
External AI Withdrawal and Geopolitical Disruption Test
A practical governance test examining whether a business can maintain critical services if access to an external AI provider is suddenly restricted or withdrawn because of provider decisions, government action, sanctions, trade restrictions or geopolitical disruption.
A public reference framework for testing whether important AI protections actually work in practice, focusing on control, accountability, business dependence and effective oversight rather than relying on policies, promises or formal safeguards alone.