Score
Operational practices and governance measures for deploying and using AI responsibly, including integrating generated interpretive text as provisional artifacts, and managing monitoring, security, and responsible-use considerations at scale.
This paper identifies a core dilemma in organizational responsible AI governance: ambiguous responsibility boundaries across AI lifecycle stages and a lack of role- and stage-appropriate operational tools. Methodologically, the study systematically reviews over 220 responsible AI tools and proposes a novel two-dimensional (Actor, Stage) classification framework, integrating systematic review, meta-analysis, and qualitative coding. It identifies three critical governance gaps: (1) unclear accountability attribution, (2) absence of empirical validation for most tools, and (3) severe coverage imbalance across actors and stages. Results show that >80% of tools target developers during data and modeling phases; tools for leadership, deployers, end users, and stages such as value proposition definition and deployment are virtually absent. Moreover, >90% of tools lack empirical evidence. The study establishes a theoretically grounded, empirically benchmarked framework to advance actor–stage–aligned AI governance tool ecosystems.
Current AI governance research lacks systematic integration of diverse frameworks and practices, with notable gaps in the operationalizability of key mechanisms and the implementation of inclusive, stakeholder-centered approaches. To address this, we conduct a rapid three-tier literature review, systematically synthesizing nine authoritative IEEE/ACM reviews published between 2020 and 2024. We introduce the novel “thematic semantic synthesis” analytical paradigm to identify high-frequency governance frameworks (e.g., the EU AI Act, NIST AI Risk Management Framework), core principles (e.g., transparency, accountability), and stakeholder role distributions. Our analysis reveals four critical knowledge gaps in AI governance scholarship and practice. Based on these findings, we propose a rigorously grounded, organizationally feasible governance roadmap—bridging theoretical advancement and real-world implementation. This work contributes both empirical evidence and methodological innovation to advance AI governance research and practice.
Responsible Artificial Intelligence (RAI) governance faces significant implementation challenges in globally distributed organizations, primarily due to the limited applicability of existing frameworks under complex organizational structures and decentralized decision-making authority. Method: This study proposes ARGO—a novel, adaptive, three-tier RAI governance framework that integrates centralized coordination with local autonomy and supports modular, context-sensitive deployment. Its design and efficacy were rigorously evaluated through a multi-case, cross-departmental assessment spanning diverse business units and AI application domains. Contribution/Results: The evaluation identified four recurrent barrier patterns impeding RAI implementation. Empirical findings demonstrate that ARGO significantly enhances accountability mechanisms, standardization consistency, and local adaptability. By reconciling global coherence with contextual flexibility, ARGO establishes a new governance paradigm for decentralized organizations seeking scalable, operationally viable RAI oversight.
AI system deployment faces three critical governance gaps: absence of use-case-level risk assessment, misalignment between high-level principles and operational controls, and lack of scalable mechanisms for governance integration. To address these, this paper introduces the Trust Integration Pillars (TIPS)—a structured governance framework that pioneers a four-dimensional closed-loop paradigm: risk profiling, control mapping, quantitative measurement, and role-based collaboration—achieving engineering-ready AI governance four years prior to the NIST AI Risk Management Framework (RMF). TIPS integrates Governance, Risk, and Compliance-as-Code (GRC-as-Code), risk-driven use-case classification matrices, multi-tier compliance dashboards, and role-specific governance dashboards to embed governance throughout the AI development lifecycle. Empirical evaluation demonstrates 100% governance coverage across cross-functional AI projects, a 47% improvement in critical risk identification accuracy, and 68% automation of governance actions—successfully deployed at scale in high-stakes domains including healthcare and finance.
This study addresses the empirical gap in evaluating whether AI systems fulfill post-deployment regulatory obligations concerning monitoring, reporting, and impact assessment. Drawing on an AI incident database spanning 2020–2026, it presents the first systematic quantification of compliance gaps across nine post-deployment provisions of the EU AI Act, the NIST AI Risk Management Framework, and the GDPR. Employing a multi-regulatory coding scheme and statistical modeling of compliance, the analysis reveals that 77.1% of incidents lack evidence of post-market monitoring and 99.6% show no data protection impact assessments. Internal monitoring is found to significantly improve compliance rates. Building on these findings, the study proposes a four-stage Proactive AI Governance Compliance Framework (PAGCF), emphasizing continuous monitoring and cross-framework validation to establish an evidence-based foundation for post-deployment accountability and governance.
This study responds to the UN’s interim report on AI governance, addressing the dual challenge of harnessing AI to advance the Sustainable Development Goals (SDGs) while mitigating associated risks—including exacerbation of social inequality, ethical and environmental harms, and misalignment with international law and human rights standards. Method: It pioneers an integrative governance pathway embedding AI regulation within international legal frameworks, human rights norms, and the SDGs, employing interdisciplinary policy analysis, multilevel governance modeling, consistency assessment against international law, and socio-technical impact diagnostics. Contribution/Results: The project proposes a dual-track governance paradigm emphasizing legally binding instruments alongside AI literacy capacity-building. It formulates an actionable global AI governance principles framework and delivers 12 cross-border collaborative recommendations—subsequently adopted by multiple UN entities as policy reference benchmarks.
Rapid AI advancement poses novel governance challenges, necessitating a rigorous, technically grounded approach to AI governance. Method: This work introduces “technical AI governance” as a distinct paradigm and establishes the first interdisciplinary analytical framework—integrating AI safety, mechanism design, policy modeling, and governance theory—to systematically address three core problem domains: risk identification, evaluation of intervention effectiveness, and compliance mechanism design. Adopting a problem-driven methodology, it clarifies how technical tools can concretely support governance practice. Contributions/Results: (1) A formal, structured definition of technical AI governance and a taxonomy of its core problems; (2) The first publicly available, extensible open-problems catalog for technical AI governance, bridging methodological gaps between technical and policy communities; and (3) An actionable, problem-oriented investment guide for researchers and funding agencies to prioritize high-impact technical governance research.
This work addresses the limitations of existing AI governance frameworks, which rely on static metrics and post-hoc audits and thus lack the capacity for dynamic, real-time assessment of deployment readiness in high-risk systems—particularly regarding fairness discrepancies, threshold sensitivity, and remediation progress. To bridge this gap, the paper proposes the Operational AI Deployment Assurance (OADA) framework, which uniquely models governance uncertainty as an operational challenge within the deployment pipeline. OADA introduces mechanisms such as deployment assurance scores, readiness categorization, threshold stability zones, and governance escalation states to enable closed-loop, dynamic governance from evaluation to deployment. By integrating the Fairness Discrepancy Index (FDI) and FairRisk-FDI with threshold sensitivity analysis and repair-aware assurance evolution, OADA successfully identifies models deemed “compliant” by conventional metrics yet operationally unstable, offering a scalable deployment assurance paradigm for high-stakes domains like medical AI.
This study addresses the challenge enterprises face in effectively governing and verifying compliance of emergent AI systems, which creates a trust gap between regulatory expectations and operational capabilities. To bridge this gap, the work proposes a continuous, autonomous AI governance architecture that translates compliance requirements into real-time telemetry mechanisms at the operating system layer. By leveraging a zero-trust telemetry boundary, ephemeral read-only probes, and AI observability agents—integrating LangSmith and Datadog LLM telemetry—the approach automatically discovers AI systems, collects control assertions, and continuously generates verifiable evidence without accessing source code or sensitive payloads. Validated against major regulatory frameworks including ISO/IEC 42001, the EU AI Act, SOC 2, GDPR, and HIPAA, this method enables a fundamental shift from document-based policy trust to empirically grounded architectural trust.
This study addresses the persistent challenge of operationalizing AI governance requirements within software development practice, particularly at the team level. Through an embedded action research approach in an AI startup, the authors construct a translational pipeline that bridges regulatory texts and concrete engineering actions. They propose a governance implementation framework grounded in practitioners’ cognitive orientations—convergence, alignment with existing practices, and disengagement—to shift governance responsibility from externally imposed mandates toward collective team accountability. By integrating legal text analysis, cross-functional collaboration, and collective assessment, the project surfaces developers’ authentic attitudes toward regulation, identifies compliance priorities anchored in user and developer needs, and renders implicit governance work explicit and institutionalized.
This work addresses the surge in AI agent–generated contributions to open-source projects and the consequent challenges faced by maintainers due to the absence of coordinated governance mechanisms for risk assessment, evidence provision, and review. The paper proposes a project-level governance infrastructure that conceptualizes AI-mediated contributions as governable boundary objects. Central to this framework is the Agent Governance Manifesto (AGM), a bilateral contract linking contributors’ evidence preparation with maintainers’ verification authority. Evaluated through GitHub audits, user studies, and structured validation, the AGM significantly improves risk-label recovery rates (37/38 versus 15/37) and perceived reviewer support (6.14 versus 3.27), while enabling high-fidelity expression of governance state and structural compliance.
This study addresses critical challenges in Security Operations Centers (SOCs)—including alert fatigue, tool fragmentation, and insufficient cross-source event correlation—by proposing the first open-source platform that integrates AI governance with security agents. Built on a layered architecture, the platform combines LangGraph-based agent orchestration, LLM fine-tuning for rule generation, Louvain community detection, and Bayesian scoring, augmented by a human-in-the-loop feedback mechanism and a dual-layer guardrail system (regex-based filtering and Llama Prompt Guard 2). Experimental results demonstrate strong performance in event correlation (F1=87%), attack chain reconstruction (accuracy=87.5%), threat detection (F1=91.0%), and governance compliance (guardrail F1=98.1% with zero false positives). The system achieves a 96.2% rule deployment acceptance rate and a mean time to detection (MTTD) of only 1.58 seconds.