AI Governance Institute

AI Governance Frameworks: Standards and Voluntary Codes

Voluntary standards and reference frameworks organizations use to structure an AI governance program, from NIST AI RMF to ISO/IEC 42001.

41 policies
Risk Tier

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkSingapore

Singapore's AI Verify Testing Framework

IMDA developed this voluntary AI governance framework and toolkit. Organizations use its standardized technical tests and process checks to demonstrate responsible AI practices.

VoluntaryFrameworkUSHigh risk

America's AI Action Plan

America’s AI Action Plan sets the White House’s priorities for advancing and governing AI. It directs federal work on AI security infrastructure, agency coordination, and cybersecurity readiness. The plan primarily covers federal agencies and their AI operators. Federal AI contractors and suppliers may also be affected.

VoluntaryFrameworkAustralia

Australia AI Ethics Framework

Australia’s voluntary national framework sets eight ethical principles. They guide organizations designing, developing, and deploying AI systems.

VoluntaryFrameworkEUHigh risk

European Commission Enforcement Powers for Advanced AI Models under the AI Act

The European Commission can enforce EU AI Act requirements against providers of advanced general-purpose models meeting its capability thresholds. Coverage applies regardless of incorporation location. Powers include information requests, model access for evaluation, required mitigations, and penalties reaching 3 percent of worldwide annual turnover.

VoluntaryFrameworkUS

Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure

President Trump’s Executive Order 14318 directs federal agencies to accelerate data center permitting for domestic AI development. It covers agencies responsible for relevant land use, environmental reviews, and energy approvals. The administration identified permitting delays as barriers to AI infrastructure growth.

VoluntaryFrameworkUS

Executive Order 14319: Preventing Woke AI in the Federal Government

President Trump’s Executive Order 14319 directs agencies to avoid AI with ideological bias or viewpoint-discriminatory outputs. It covers federal procurement, deployment, and contracting. The order rescinds or modifies earlier guidance viewed as imposing political or ideological constraints on AI development.

VoluntaryFrameworkEUHigh risk

EU Action Plan on Cybersecurity and Artificial Intelligence

The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence coordinates EU efforts to secure AI systems. It covers developers and deployers subject to the AI Act, particularly advanced or high-risk systems. The plan creates a secure testing platform and EU-level evaluation capability for advanced models.

VoluntaryFrameworkEUHigh risk

EU AI Act Harmonised Standard prEN 18286, Quality Management Systems for AI

Draft standard prEN 18286 is under public enquiry. It addresses AI quality management systems supporting conformity with the EU AI Act. It targets developers and deployers seeking standardized compliance evidence. Conformity with a harmonized standard creates a presumption of conformity for the corresponding requirements it covers.

VoluntaryFrameworkEUHigh risk

AI Act Governance and Enforcement Framework

EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.

VoluntaryFrameworkEULimited risk

EU Code of Practice on Transparency of AI-Generated Content

The European Commission published this voluntary Code of Practice to support Article 50 compliance under the EU AI Act. It addresses generative AI providers and deployers serving the EU. The Code covers content labeling, provenance controls, and disclosure workflows.

VoluntaryFrameworkUS

Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence

This US presidential directive sets federal requirements for safe AI development and deployment. It includes frontier-model safety reporting, NIST standards development, and coordination across agencies.

VoluntaryFrameworkUSHigh risk

Artificial Intelligence Compliance Plan

The FTC's Artificial Intelligence Compliance Plan describes how the agency governs its own internal adoption of AI tools and sets expectations for AI transparency and accountability in regulated markets. It applies to FTC operations and signals enforcement priorities relevant to enterprises deploying AI in consumer-facing products and services. Organizations subject to FTC jurisdiction should treat this plan as an indicator of the standards against which AI-related conduct may be measured.

VoluntaryFrameworkUS

U.S. General Services Administration AI Strategies and Compliance Plan

The GSA AI Strategies and Compliance Plan establishes governance for internal agency AI use. An AI Governance Board and oversight committee review and approve use requests. Requirements cover privacy controls, security reviews, use-case intake, and compliance evidence.

VoluntaryFrameworkSingapore

IMDA Model AI Governance Framework

Singapore’s IMDA and PDPC issued this voluntary AI governance framework. It guides responsible deployment through human oversight, decision accountability, and operational transparency.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 42001:2023 - Artificial Intelligence Management System

ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 23894 AI Risk Management

ISO/IEC 23894 explains how to integrate AI risks into enterprise risk management. It adapts ISO 31000 terminology and processes for AI characteristics. These include emergent behavior, data dependency, opacity, and sociotechnical complexity.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 24028 AI Trustworthiness

ISO/IEC 24028:2020 explains AI trustworthiness concepts, characteristics, and threats. It provides technical and organizational approaches for assessing and improving trustworthiness throughout the lifecycle.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 24029 Robustness of Neural Networks

ISO/IEC 24029 covers formal methods and practical assessments of artificial neural network robustness. Its parts address adversarial inputs, distribution shifts, and other failure modes relevant to trustworthy deployment.

VoluntaryFrameworkGlobal

ITU Focus Group on Trust and Identity for Humans and Agentic AI

ITU launched a Focus Group on trusted digital identity and accountable behavior throughout agentic AI lifecycles. It addresses agent identification, credentials, authorization, and agent-to-agent interactions. The work concerns organizations developing or deploying agents with delegated authority or external system access.

VoluntaryFrameworkJapan

Japan's Basic Plan for Artificial Intelligence

Japan’s Cabinet approved the Basic Plan for Artificial Intelligence in December 2025. It makes governance leadership and trustworthy AI government priorities. The plan directs public agencies and shapes expectations for private AI development and deployment.

VoluntaryFrameworkJapan

Japan's Principles Code (tentative) on the Protection of Intellectual Property and Transparency for Appropriate Use of Generative AI (Draft)

Japan released this draft principles code on December 26, 2025 for generative AI developers and providers. Its voluntary guidance addresses intellectual property protection and transparency about AI use. Public comments closed January 26, 2026. A final version has not yet been adopted.

VoluntaryFrameworkSingaporeHigh risk

MAS Guidelines on Artificial Intelligence Risk Management

MAS is finalizing supervisory AI guidelines for regulated financial institutions. They cover all AI uses, including agents, with expectations for board oversight, risk frameworks, and lifecycle controls. Institutions should prepare model governance, approval workflows, monitoring, and audit trails for formal requirements.

VoluntaryFrameworkUS

NIST AI 600-1 Generative AI Profile

This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.

VoluntaryFrameworkUSHigh risk

NIST Artificial Intelligence Risk Management Framework Playbook

The NIST AI RMF Playbook translates the AI Risk Management Framework Core into a structured set of suggested actions organized under the four functions: Govern, Map, Measure, and Manage. It is designed for organizations deploying or developing AI systems who need practical implementation guidance rather than high-level principles. Compliance teams can use it to build risk workflows, establish control checkpoints, and produce governance documentation aligned to the AI RMF.

VoluntaryFrameworkUSHigh risk

NIST Artificial Intelligence Technology Evaluation Program

NIST’s AITE program organizes federal AI testing, benchmarking, and validation, particularly for high-impact applications. It serves developers, agencies, and enterprises seeking standardized evaluations. Topics include testing methods, provenance controls, data governance, and enterprise validation.

VoluntaryFrameworkISO/OECD/UN

OECD AI Principles

The OECD AI Principles were the first intergovernmental AI standard. They set five values-based principles and five government recommendations supporting trustworthy AI, human rights, and democratic values.

VoluntaryFrameworkISO/OECD/UNHigh risk

OECD Report: Governing with Artificial Intelligence

This OECD report examines government AI use across member and partner countries. Public-service improvements account for 57% of documented applications, while 45% support administrative decisions. Identified risks include biased training data, limited transparency, and overreliance on automated outputs.

VoluntaryFrameworkGlobalHigh risk

OWASP Top 10 for Large Language Model Applications

OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.

VoluntaryFrameworkGlobal

The Role of Investors in AI Governance

Oxford Martin’s AI Governance Initiative examines investor responsibilities for AI safety and accountability. It covers financing and oversight by institutional investors, venture capital, and private equity. Investors can use it in due diligence, stewardship, and portfolio management.

VoluntaryFrameworkGlobalHigh risk

Singapore Consensus on Global AI Safety Research Priorities

The Singapore Consensus sets shared international priorities for AI safety research. It emerged from a government-convened multilateral summit involving governments and organizations. The non-binding agenda guides national safety programs and research funding bodies.

VoluntaryFrameworkSingaporeHigh risk

Singapore Global AI Assurance Sandbox

Singapore’s Global AI Assurance Sandbox lets enterprises and developers test safety, reliability, and accountability before or during deployment. Participants operate under regulatory oversight and defined conditions. Temporary compliance relaxations are exchanged for testing commitments and reporting.

VoluntaryFrameworkSingapore

Singapore National AI Strategy 2.0

Singapore’s updated national AI blueprint sets its development and governance ambitions. It prioritizes trusted, responsible AI and building national expertise.

VoluntaryFrameworkUK

UK AI Opportunities Action Plan

The UK published its AI Opportunities Action Plan in January 2025. It sets the Labour government’s adoption and infrastructure agenda for public bodies, developers, and AI enterprises. Commitments include AI Growth Zones, expanded computing infrastructure, and a National Data Library for development access.

VoluntaryFrameworkUK

UK-Canada AI Computing Power Collaboration Agreement

The UK and Canada signed an AI computing cooperation agreement on April 27, 2026. It provides for shared resources and joint investment supporting research and development. Government agencies and publicly supported researchers are its primary audience. Enterprises working within either national AI strategy may also be affected.

VoluntaryFrameworkGlobal

Global Dialogue on AI Governance (UN General Assembly Resolution A/RES/79/325)

UN Resolution A/RES/79/325 established the Global Dialogue on AI Governance. The forum welcomes member states, civil society, private businesses, and other stakeholders. Submissions through April 30, 2026 will inform discussions of global AI challenges and priorities.

VoluntaryFrameworkISO/OECD/UNHigh risk

UN Independent International Scientific Panel on AI: Preliminary Report on Agentic AI Governance

The UN Independent International Scientific Panel on AI issued preliminary governance expectations for agents taking consequential actions. The report covers autonomous and semi-autonomous deployments. It calls for documented intervention thresholds, standardized incident registers, audit trails, and verifiable provenance for decision outputs.

VoluntaryFrameworkUS

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179 directs agencies to develop an AI Action Plan prioritizing US development and deployment leadership. It shapes conditions for private AI businesses operating in the US. The order revokes earlier safety-focused directives and emphasizes deregulation and competitiveness.

VoluntaryFrameworkUS

U.S. Executive Order: Ensuring a National Policy Framework for Artificial Intelligence

The December 11, 2025 executive order directs a unified national AI policy and challenges to conflicting state laws. It requires Commerce’s state-law evaluation and an FTC statement on unfair or deceptive AI practices within 90 days. It also establishes an AI Litigation Task Force. Federal agencies and entities subject to challenged state rules may be affected.

VoluntaryFrameworkUSHigh risk

Treasury Department AI Risk Management Framework for Financial Services

Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.

VoluntaryFrameworkSingapore

Veritas Consortium AI Fairness Testing Methodology

MAS and a financial-sector consortium developed this assessment method for responsible AI. It applies fairness, ethics, accountability, and transparency principles to financial services.

VoluntaryFrameworkUSHigh risk

White House Artificial Intelligence Oversight Framework

Reporting describes an advanced-model oversight framework finalized by the White House in August 2026. It sets pre-deployment evaluation expectations for developers and deployers operating within or supplying the federal government. The full text was unavailable at the reporting date, leaving its precise scope and requirements unconfirmed.