Framework Dimension 5 of 6
Governance & Risk
Policies, EU AI Act risk-tier mapping, runtime guardrails, and responsible-AI practice at inference time.
The Governance & Risk dimension measures whether your GenAI systems are auditable, compliant with binding regulation, and defended against runtime attacks — or whether you have written policies that live on Confluence and are unenforced at inference time.
Framework v2026.1 · Updated · machine-readable spec
Why this dimension matters
The EU AI Act, NIST AI RMF, and ISO 42001 all impose overlapping obligations that require both written policy AND runtime enforcement. Organizations that treat governance as a paper exercise fail conformity assessments and face fines up to 7% of global revenue under the EU AI Act.
Signals we look for
- AI system inventory mapped to EU AI Act risk tiers
- Runtime guardrails (input/output filtering, PII redaction)
- Model-card equivalents for production systems
- Aligned to NIST AI RMF / ISO/IEC 42001
What this dimension looks like at each maturity level
No AI-specific policy. Governance handled ad-hoc by legal on request.
Written AI policy exists. First risk assessments for high-risk use cases.
Every production deployment passes documented risk / bias / compliance review. Runtime input/output filtering in place.
AI system inventory mapped to EU AI Act risk tiers. Model cards standard. Cross-mapping to NIST AI RMF and ISO 42001.
Governance is a competitive advantage — externally audited, referenced in procurement conversations. Real-time risk signals mitigated automatically.
Regulator-recognized posture. Governance capabilities exported as a product to peers or regulators.
Common blockers
- AI policy written but no runtime enforcement — the policy lives on Confluence, not in the request path.
- Model cards optional rather than required for production launch.
- EU AI Act risk-tier classification done once at project start, not maintained as scope changes.
How to move up a level
- Implement runtime guardrails (input filtering, output validation, PII redaction) at the API gateway.
- Make a completed model card a launch prerequisite.
- Maintain an AI system inventory with periodic risk-tier re-classification.
- Cross-map controls across EU AI Act, NIST AI RMF, and ISO 42001 (use /tools/compliance-mapper).
Related standards & regulation
Related on this site
Call this framework and its tools from your own agent via the Model Context Protocol (MCP) server. Works with Claude Desktop, Cursor, Zed, Continue, and the OpenAI Agents SDK.