AI governance is often discussed in terms of principles, policies and responsible behaviour. These are important, but they do not by themselves prove that an AI system can actually be controlled, challenged or held accountable when something goes wrong.
The Standardized Definition of AI Governance provides a common starting point for answering that problem. It defines AI governance as the system of principles, policies, processes, accountability mechanisms and continuous measurement used to direct and control artificial intelligence throughout its full lifecycle, from design and development through deployment, operation, change and eventual decommissioning.
The framework applies across organisations, industries and jurisdictions. Its purpose is to move AI governance beyond statements of intent and make it something that can be tested and demonstrated. It asks whether an AI system preserves human authority, whether responsibility can be identified, whether decisions can be traced, whether risks are managed and whether governance continues to function as the system changes.
The framework identifies a number of core conditions for effective governance. These include accountability, transparency, human oversight, risk management, ethical foundations, legal compliance, lifecycle continuity and structural solvency. In simple terms, an organisation should be able to show who is responsible, explain how important decisions are made, allow authorised people to intervene, manage risks continuously and maintain governance throughout the life of the system.
A central part of the framework is the principle that governance claims should be verified rather than simply accepted. It therefore combines binary tests with continuous measurement. The tests ask whether essential protections and controls exist. The metrics examine whether those protections continue to work over time and under changing conditions.
Verification is organised across three areas. Structural Integrity looks at whether an AI system can actually be controlled and held accountable. Epistemic Integrity looks at whether its knowledge and reasoning can be trusted. Systemic Integrity looks at whether governance continues across technical, organisational and jurisdictional boundaries.
The framework therefore provides the foundation for the wider body of work. Its basic question is straightforward: if an organisation says an AI system is governed, can it demonstrate that governance in practice?
Standardized Definition of AI Governance
A public reference standard that defines AI governance as a measurable structural condition, moving beyond policy statements to test whether control, accountability, traceability and integrity can be demonstrated in practice across the AI lifecycle.
A quantitative AI governance metric designed to measure how much of an AI system remains provable when models, APIs, vendors or other upstream dependencies change. ERR focuses on traceability, reconstructability, version fidelity and dependency proof to assess whether governance can survive change.
External AI Withdrawal and Geopolitical Disruption Test
A practical governance test examining whether a business can maintain critical services if access to an external AI provider is suddenly restricted or withdrawn because of provider decisions, government action, sanctions, trade restrictions or geopolitical disruption.
A public reference framework for testing whether important AI protections actually work in practice, focusing on control, accountability, business dependence and effective oversight rather than relying on policies, promises or formal safeguards alone.