AI Governance Frameworks: Standards and Voluntary Codes
Voluntary standards and reference frameworks organizations use to structure an AI governance program, from NIST AI RMF to ISO/IEC 42001.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Singapore's AI Verify Testing Framework
IMDA developed this voluntary AI governance framework and toolkit. Organizations use its standardized technical tests and process checks to demonstrate responsible AI practices.
America's AI Action Plan
America’s AI Action Plan sets the White House’s priorities for advancing and governing AI. It directs federal work on AI security infrastructure, agency coordination, and cybersecurity readiness. The plan primarily covers federal agencies and their AI operators. Federal AI contractors and suppliers may also be affected.
Australia AI Ethics Framework
Australia’s voluntary national framework sets eight ethical principles. They guide organizations designing, developing, and deploying AI systems.
European Commission Enforcement Powers for Advanced AI Models under the AI Act
The European Commission can enforce EU AI Act requirements against providers of advanced general-purpose models meeting its capability thresholds. Coverage applies regardless of incorporation location. Powers include information requests, model access for evaluation, required mitigations, and penalties reaching 3 percent of worldwide annual turnover.
Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure
President Trump’s Executive Order 14318 directs federal agencies to accelerate data center permitting for domestic AI development. It covers agencies responsible for relevant land use, environmental reviews, and energy approvals. The administration identified permitting delays as barriers to AI infrastructure growth.
Executive Order 14319: Preventing Woke AI in the Federal Government
President Trump’s Executive Order 14319 directs agencies to avoid AI with ideological bias or viewpoint-discriminatory outputs. It covers federal procurement, deployment, and contracting. The order rescinds or modifies earlier guidance viewed as imposing political or ideological constraints on AI development.
EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence coordinates EU efforts to secure AI systems. It covers developers and deployers subject to the AI Act, particularly advanced or high-risk systems. The plan creates a secure testing platform and EU-level evaluation capability for advanced models.
EU AI Act Harmonised Standard prEN 18286, Quality Management Systems for AI
Draft standard prEN 18286 is under public enquiry. It addresses AI quality management systems supporting conformity with the EU AI Act. It targets developers and deployers seeking standardized compliance evidence. Conformity with a harmonized standard creates a presumption of conformity for the corresponding requirements it covers.
AI Act Governance and Enforcement Framework
EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.
EU Code of Practice on Transparency of AI-Generated Content
The European Commission published this voluntary Code of Practice to support Article 50 compliance under the EU AI Act. It addresses generative AI providers and deployers serving the EU. The Code covers content labeling, provenance controls, and disclosure workflows.
Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence
This US presidential directive sets federal requirements for safe AI development and deployment. It includes frontier-model safety reporting, NIST standards development, and coordination across agencies.
Artificial Intelligence Compliance Plan
The FTC's Artificial Intelligence Compliance Plan describes how the agency governs its own internal adoption of AI tools and sets expectations for AI transparency and accountability in regulated markets. It applies to FTC operations and signals enforcement priorities relevant to enterprises deploying AI in consumer-facing products and services. Organizations subject to FTC jurisdiction should treat this plan as an indicator of the standards against which AI-related conduct may be measured.
U.S. General Services Administration AI Strategies and Compliance Plan
The GSA AI Strategies and Compliance Plan establishes governance for internal agency AI use. An AI Governance Board and oversight committee review and approve use requests. Requirements cover privacy controls, security reviews, use-case intake, and compliance evidence.
IMDA Model AI Governance Framework
Singapore’s IMDA and PDPC issued this voluntary AI governance framework. It guides responsible deployment through human oversight, decision accountability, and operational transparency.
ISO/IEC 42001:2023 - Artificial Intelligence Management System
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
ISO/IEC 23894 AI Risk Management
ISO/IEC 23894 explains how to integrate AI risks into enterprise risk management. It adapts ISO 31000 terminology and processes for AI characteristics. These include emergent behavior, data dependency, opacity, and sociotechnical complexity.
ISO/IEC 24028 AI Trustworthiness
ISO/IEC 24028:2020 explains AI trustworthiness concepts, characteristics, and threats. It provides technical and organizational approaches for assessing and improving trustworthiness throughout the lifecycle.
ISO/IEC 24029 Robustness of Neural Networks
ISO/IEC 24029 covers formal methods and practical assessments of artificial neural network robustness. Its parts address adversarial inputs, distribution shifts, and other failure modes relevant to trustworthy deployment.
ITU Focus Group on Trust and Identity for Humans and Agentic AI
ITU launched a Focus Group on trusted digital identity and accountable behavior throughout agentic AI lifecycles. It addresses agent identification, credentials, authorization, and agent-to-agent interactions. The work concerns organizations developing or deploying agents with delegated authority or external system access.
Japan's Basic Plan for Artificial Intelligence
Japan’s Cabinet approved the Basic Plan for Artificial Intelligence in December 2025. It makes governance leadership and trustworthy AI government priorities. The plan directs public agencies and shapes expectations for private AI development and deployment.
Japan's Principles Code (tentative) on the Protection of Intellectual Property and Transparency for Appropriate Use of Generative AI (Draft)
Japan released this draft principles code on December 26, 2025 for generative AI developers and providers. Its voluntary guidance addresses intellectual property protection and transparency about AI use. Public comments closed January 26, 2026. A final version has not yet been adopted.
MAS Guidelines on Artificial Intelligence Risk Management
MAS is finalizing supervisory AI guidelines for regulated financial institutions. They cover all AI uses, including agents, with expectations for board oversight, risk frameworks, and lifecycle controls. Institutions should prepare model governance, approval workflows, monitoring, and audit trails for formal requirements.
NIST AI 600-1 Generative AI Profile
This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.
NIST Artificial Intelligence Risk Management Framework Playbook
The NIST AI RMF Playbook translates the AI Risk Management Framework Core into a structured set of suggested actions organized under the four functions: Govern, Map, Measure, and Manage. It is designed for organizations deploying or developing AI systems who need practical implementation guidance rather than high-level principles. Compliance teams can use it to build risk workflows, establish control checkpoints, and produce governance documentation aligned to the AI RMF.
NIST Artificial Intelligence Technology Evaluation Program
NIST’s AITE program organizes federal AI testing, benchmarking, and validation, particularly for high-impact applications. It serves developers, agencies, and enterprises seeking standardized evaluations. Topics include testing methods, provenance controls, data governance, and enterprise validation.
OECD AI Principles
The OECD AI Principles were the first intergovernmental AI standard. They set five values-based principles and five government recommendations supporting trustworthy AI, human rights, and democratic values.
OECD Report: Governing with Artificial Intelligence
This OECD report examines government AI use across member and partner countries. Public-service improvements account for 57% of documented applications, while 45% support administrative decisions. Identified risks include biased training data, limited transparency, and overreliance on automated outputs.
OWASP Top 10 for Large Language Model Applications
OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.
The Role of Investors in AI Governance
Oxford Martin’s AI Governance Initiative examines investor responsibilities for AI safety and accountability. It covers financing and oversight by institutional investors, venture capital, and private equity. Investors can use it in due diligence, stewardship, and portfolio management.
Singapore Consensus on Global AI Safety Research Priorities
The Singapore Consensus sets shared international priorities for AI safety research. It emerged from a government-convened multilateral summit involving governments and organizations. The non-binding agenda guides national safety programs and research funding bodies.
Singapore Global AI Assurance Sandbox
Singapore’s Global AI Assurance Sandbox lets enterprises and developers test safety, reliability, and accountability before or during deployment. Participants operate under regulatory oversight and defined conditions. Temporary compliance relaxations are exchanged for testing commitments and reporting.
Singapore National AI Strategy 2.0
Singapore’s updated national AI blueprint sets its development and governance ambitions. It prioritizes trusted, responsible AI and building national expertise.
UK AI Opportunities Action Plan
The UK published its AI Opportunities Action Plan in January 2025. It sets the Labour government’s adoption and infrastructure agenda for public bodies, developers, and AI enterprises. Commitments include AI Growth Zones, expanded computing infrastructure, and a National Data Library for development access.
UK-Canada AI Computing Power Collaboration Agreement
The UK and Canada signed an AI computing cooperation agreement on April 27, 2026. It provides for shared resources and joint investment supporting research and development. Government agencies and publicly supported researchers are its primary audience. Enterprises working within either national AI strategy may also be affected.
Global Dialogue on AI Governance (UN General Assembly Resolution A/RES/79/325)
UN Resolution A/RES/79/325 established the Global Dialogue on AI Governance. The forum welcomes member states, civil society, private businesses, and other stakeholders. Submissions through April 30, 2026 will inform discussions of global AI challenges and priorities.
UN Independent International Scientific Panel on AI: Preliminary Report on Agentic AI Governance
The UN Independent International Scientific Panel on AI issued preliminary governance expectations for agents taking consequential actions. The report covers autonomous and semi-autonomous deployments. It calls for documented intervention thresholds, standardized incident registers, audit trails, and verifiable provenance for decision outputs.
Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
Executive Order 14179 directs agencies to develop an AI Action Plan prioritizing US development and deployment leadership. It shapes conditions for private AI businesses operating in the US. The order revokes earlier safety-focused directives and emphasizes deregulation and competitiveness.
U.S. Executive Order: Ensuring a National Policy Framework for Artificial Intelligence
The December 11, 2025 executive order directs a unified national AI policy and challenges to conflicting state laws. It requires Commerce’s state-law evaluation and an FTC statement on unfair or deceptive AI practices within 90 days. It also establishes an AI Litigation Task Force. Federal agencies and entities subject to challenged state rules may be affected.
Treasury Department AI Risk Management Framework for Financial Services
Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.
Veritas Consortium AI Fairness Testing Methodology
MAS and a financial-sector consortium developed this assessment method for responsible AI. It applies fairness, ethics, accountability, and transparency principles to financial services.
White House Artificial Intelligence Oversight Framework
Reporting describes an advanced-model oversight framework finalized by the White House in August 2026. It sets pre-deployment evaluation expectations for developers and deployers operating within or supplying the federal government. The full text was unavailable at the reporting date, leaving its precise scope and requirements unconfirmed.
