Back to Home
The Framework

ADG | Adopt · Defend · Govern

AI Security Governance Framework · Enhanced Working Draft · April 2026

Why ADG

Enterprise AI is shipping into production faster than governance can absorb. Engineering teams are deploying agents that act on tools, consume retrieved context, run multi-step plans, and chain to other agents — often before the people accountable for risk have seen the system, let alone approved it. Boards are asking questions control departments cannot answer. Regulations are taking effect—the EU AI Act first, with others to follow. And the standards every organization has invested in — ISO/IEC 42001, NIST AI RMF, the EU AI Act itself — tell you what to think about, but not who decides, who builds, who breaks, who signs, or what evidence belongs in front of a regulator on Monday morning.

That is the gap ADG closes. ADG is not another standard. It is the operating model that sits underneath the standards you already have and makes them executable — written by a practitioner advisory board across financial services, healthcare, manufacturing, telecommunications, energy, and technology, in regulated and less-regulated jurisdictions across North America, Europe, and Asia-Pacific. Credentials and curricula are downstream of the framework, not the reason for it.

The architecture is three pillars — ADOPT (execute and deliver), DEFEND (secure and validate), and GOVERN (oversee, assure, decide) — that scale unchanged from the board to the engineer. The same three words frame a board paper, organize a release gate, label a red-team report, and structure an incident playbook. Beneath those pillars sit nine governance surfaces (the points where engineers instrument and attackers act); 12 Minimum Controls (MC-1 through MC-12), each with a named evidence artifact your auditor can hold; nine deployment overlays for the patterns AI actually ships in today — agentic orchestration, tools and Model Context Protocol (MCP), multi-agent interoperability, multi-modal and composite stacks, long-context architectures; three autonomy tiers (human in the loop [HITL], human on the loop [HOTL], human out of the loop [HOOTL]) tied directly to the controls; and a four-phase roadmap that takes an organization from inventory to continuous assurance in 24 months.

ADG is built for alignment, not competition. Every Minimum Control maps cleanly into NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE) and ISO/IEC 42001 Annex A — the framework's §11.2 crosswalk does it explicitly. MC-1 produces the AI inventory ISO 42001 A.6 demands and EU AI Act Art. 49 will register. MC-9 produces the post-market log Art. 73 inspectors will request. MC-11 produces the bias evidence Art. 10 requires. Organizations pursuing ISO/IEC 42001 certification or EU AI Act conformity use ADG to operationalize what those frameworks describe abstractly. The work is the same; ADG removes the translation layer.

ADG also goes where the standards do not. Agentic systems, MCP-connected tools, multi-agent interoperability, long-context architectures, and composite multi-modal stacks each carry an additive deployment overlay that composes with the same twelve Minimum Controls. Move from one copilot to a fleet of agents without rewriting a single control.

One element of ADG sits where peer frameworks generally do not: the AI Governance Council. Every framework tells you to govern AI. ADG tells you who breaks the tie when delivery and safety disagree — the Council resolves ADOPT-DEFEND tension, sets go/no-go thresholds, owns the exception register, and ties decision rights to MC-3 (Separation of Duties) and MC-10 (Periodic Governance Review). The mechanism, not the abstract requirement, is what is rarely named in peer frameworks — and it is where most production AI risk actually lives.

ADG is built for boards, CISOs and AI red teams, platform and AI engineers, risk and compliance, and procurement. Each audience reads a different path; the artifacts are the same. The framework was forged with senior AI, security, and governance leaders running production AI inside top Fortune 500, Fortune Global 500, and Big Four firms — including Salesforce, Microsoft, Citi, JPMorgan Chase, NTT DATA, KPMG, ServiceNow, BNP Paribas, Prudential, GE Healthcare, BASF, and Jio — the practitioners who own the failure modes this framework governs.

Who's reading this?

ADG is dense by design. Pick the role that matches you and jump to the path written for it. Each path is 4–5 sections out of 13 — you don't have to read everything.

Board & Executive

What we approve, what we own.

“Can we sign off this AI system, and what evidence will the auditor want?”

§2 Executive Summary · §4 Triad · §6 Harm Taxonomy · §11 Controls · §12 Regulatory

Security & AI Red Teams

What can break, how we defend.

“Where are the attack surfaces, and which controls fire when?”

§5 Surfaces · §6 Harm Taxonomy · §9 Lifecycle · §10 Overlays · §11 Controls

Engineering & Platform

How we build, what we ship.

“Which controls bind to my CI/CD, my MCP servers, my prompt repo?”

§4 Triad · §5 Surfaces · §8 People/Process/Tech · §9 Lifecycle · §10 Overlays

Risk & Compliance

What we must prove.

“How does this map to ISO 42001, NIST AI RMF, EU AI Act?”

§6 Harm Taxonomy · §7 Shared Responsibility · §12 Regulatory · Appendix A

1.Background

1.1 Origin and Positioning

ADG began with a mission at EC-Council: the AI governance space was fragmenting into point standards, vendor playbooks, and academic frameworks — none of which gave enterprise boards and engineering teams a single, practitioner-tested operating model for deploying AI safely at scale. EC-Council set out to build that missing operating model: a framework built around three enduring functions—ADOPT, DEFEND, and GOVERN—that scales from the board to the engineer.

To avoid building in a vacuum, EC-Council convened an Advisory Board of practitioners from mature enterprises that have actually deployed AI in production. The initial draft was circulated to senior AI, security, and governance leaders across global organizations in financial services, technology, manufacturing, healthcare, telecommunications, energy, and consulting — covering both regulated and less-regulated sectors, and spanning North America, Europe, and Asia-Pacific.

Advisory Board Impact

ADG was not drafted in a conference room. It was forged with the senior AI, security, and governance leaders running production AI inside Fortune 500, Fortune Global 500, and Big Four firms — across regulated and less-regulated sectors, from design through implementation.

Their input drove eight structural enhancement clusters: an expanded harm taxonomy with Responsible AI integration, coverage beyond LLMs (diffusion, multi-modal, composite systems), a shared responsibility model for vendor/SaaS AI, deeper strategic treatment of the GOVERN pillar, a measurable metrics & evidence framework, multi-agent interoperability governance, explicit regulatory mapping (EU AI Act, NIST AI RMF, ISO 42001), and post-deployment continuous governance.

Framework Leadership

Jay Bavisi

Jay Bavisi

Chairman & CEO

EC-Council Group
Karthik S.

Karthik S.

Framework Architect & Lead Author · Practice Head, SecureAI

EC-Council Global Services

Thank you to the Advisory Board

The practitioners below gave their time, scrutiny, and hard-won experience to review ADG. Their comments, corrections, and counterpoints are the reason this framework is field-tested rather than aspirational.

Adam Spearing

Adam Spearing

VP of AI GTM EMEA

ServiceNow

Andrei Son

Andrei Son

Head of AI Transformation

AUMOVIO

Anish Mitra

Anish Mitra

Director

KPMG

Anita Lacea

Anita Lacea

Head of AI Transformation, Azure Hardware Infrastructure

Microsoft

Dinesh Bhogle

Dinesh Bhogle

Head of AI/ML Platform

Black & Veatch

Dr. Sayed Peerzade

Dr. Sayed Peerzade

EVP, Cloud, AI & Government Initiatives

Jio

Edoardo Tealdi

Edoardo Tealdi

Executive Head of AI Transformation, Business Engagement and Growth Units

NTT DATA, Inc.

Kathy Baxter

Kathy Baxter

VP/Principal Architect, Responsible AI & Tech

Salesforce

Lewis V. Adams

Lewis V. Adams

VP, Enterprise AI & Capital Productivity Transformation

Citi

Lily Rachmawati

Lily Rachmawati

Director, Head of Applied AI

BNP Paribas

Malik Hussain

Malik Hussain

AI Enablement Lead, Data & AI Academy

BASF

Mark Ritcey

Mark Ritcey

VP, AI & Automation Delivery

Latent Bridge

Naveen Upadhyay

Naveen Upadhyay

VP, AI/ML Product Management – Machine Learning & Intelligence Operations

JPMorgan Chase & Co.

Oscar Jarabo

Oscar Jarabo

Global Head of AI Product & Strategy

TKE

Pavan Kristipati

Pavan Kristipati

Head of AI Engineering & Transformation | Enterprise AI Adoption, Governance & Platform

Huntington Bank

Raghunandan Mishra

Raghunandan Mishra

AI & Data Engineering Leader

Raji Bhimireddy

Raji Bhimireddy

VP Cloud, AI, Architecture, FinOps & Business Value

Prudential

Sanjoy K. Saha

Sanjoy K. Saha

Head of AI Portfolio and Governance & Chief of Staff CDAO

GE Healthcare

ShanShan Pa

ShanShan Pa

Global Head of AI & Data Governance

GlobalLogic

Sophia Katrenko

Sophia Katrenko

VP of AI/ML

EcoVadis

Sruthi Pakanati

Sruthi Pakanati

Head of AI & Data Transformation, National Quality & Risk

Deloitte Australia

Sudarson Roy Pratihar

Sudarson Roy Pratihar

Founder and Principal

A2IQ

Yashwinder Chhikara

Yashwinder Chhikara

Sr. VP, AI, Analytics, and Product Management

iSON Xperiences

This version is the result — the iterative output of that collaboration. ADG is not a one-and-done document. It is a living framework, designed to be enhanced as AI deployment patterns evolve and as new practitioners join the conversation.

1.2 Framework Purpose: The RE³ Trust Model

ADG is purpose-built to operationalize four non-negotiable properties of trustworthy enterprise AI — captured in the RE³ Trust Model: Responsible, Ethical, Efficient, Explainable AI.

Responsible AI

Clear Accountability, Every Layer

Every AI action traces back to a human decision-maker. Delivered by: MC-1 (AI System Inventory), MC-3 (Separation of Duties), Agent Authority Statements, Shared Responsibility Model (§7), and the AI Governance Council escalation path.

Ethical AI

Fairness, Safety, and Human Oversight

Protection from bias, manipulation, and harm across four classes (Technical, Societal, Operational, Systemic). Delivered by: the Four-Class Harm Taxonomy, Seven Responsible AI (RAI) Principles embedded in every surface, MC-11 (Fairness & Bias Evaluation), the Safety Layer surface, and Autonomy Tier controls scaled to risk.

Efficient AI

Reliable Delivery at Enterprise Scale

Governance that enables velocity rather than slowing it down. Delivered by: the four-phase implementation roadmap, Tier 1 — Control Effectiveness Metrics, the LLMOps Overlay for cost/performance monitoring, reusable Operating Artifacts, and one unified control set spanning Homegrown, API, and SaaS deployments.

Explainable AI

Traceable, Replayable, Defensible

Every output can be justified to a regulator, a board, or a customer. Delivered by: the Telemetry surface, MC-6 (Context Policy with provenance tracking), MC-7 (Tool/MCP audit logging), MC-8 (Runtime Monitoring), and MC-9 (Incident Response with forensic replay).

1.3 Core Thesis

Answer capsule

Why do AI systems need a different governance framework?

Traditional cybersecurity and software governance assumes deterministic execution, fixed inputs, and visible logic. AI breaks all three: it generates novel behavior, acts through external tools, consumes dynamic context, and shifts with every model update. ADG closes that gap through role separation, surface-based control ownership, deployment-pattern overlays, lifecycle governance, and a structured harm taxonomy.

1.3

Scope Coverage — AI System Architecture with Agentic Hardening

Every class of AI system ADG covers, and the agentic harness wrapped around them. Hover any segment for what it includes.

ADG governs all layers

1.4 Scope and System Coverage

ADG governs all AI systems as defined by the OECD AI Policy Observatory and the EU AI Act, including LLMs and transformer-based generative AI, diffusion models, multi-modal systems, classical machine learning, composite AI systems that orchestrate multiple model types, and emerging architectures such as world models and neuromorphic systems. The governance surfaces, overlays, and controls in this framework are architecture-neutral by design — not limited to LLM-centric systems.

1.5 Distinction: Standards vs. Regulations

Answer capsule

Is ISO/IEC 42001 a standard or a regulation?

ISO/IEC 42001 is a voluntary standard you certify against, not a law. The EU AI Act is a regulation: legally binding, with fines up to 7% of global annual turnover for prohibited AI practices. NIST AI RMF and the OWASP Top 10 are voluntary frameworks and guidance. ADG maps both kinds, so meeting the standards builds the evidence regulations demand.

2.Executive Summary

Answer capsule

What is the ADG framework?

ADG (Adopt, Defend, Govern) is EC-Council Global Services' enterprise framework for AI security and responsible AI governance. Three pillars form a board-to-engineering operating model: Adopt delivers AI capabilities, Defend secures them against four harm classes, and Govern oversees, assures, and resolves tensions. ADG maps to NIST AI RMF and ISO/IEC 42001.

2.

Framework Architecture — How the Layers Connect

Nine governance surfaces, three pillars, 12 minimum controls, joined only where the framework publishes a link.

9 surfaces · 3 pillars · 12 controls. Surfaces join a pillar through their published ADG alignment; controls through the pillar recorded in the §11.2 crosswalk. No surface-to-control edge is drawn — the framework does not publish one.

Key framework components

Pillars — The ADG Triad

ADOPT executes and delivers AI capabilities. DEFEND secures and validates against all harm classes. GOVERN oversees, assures, and resolves tensions between the other two pillars.

Harm Classes — Four-Class Harm Taxonomy

Technical, Societal, Operational, and Systemic harms — ensuring governance extends beyond security to cover bias, fairness, reliability, and emergent multi-agent risks.

RAI Principles — Responsible AI Principles

Fairness and non-discrimination, transparency and explainability, privacy and data protection, accountability, human oversight, robustness and safety, and sustainability and societal well-being.

Governance Surfaces — What Must Be Governed

Model, Prompt, Context, Tools, Orchestration, Identity, Safety Layer, Telemetry, and Learning Loop — defining what must be governed regardless of architecture.

Foundational Principles — The Durable Standards

Separation of powers, explicit authority, context as attack surface, tool use as highest-risk control plane, graduated oversight, lifecycle governance, mandatory evidence, embedded RAI, and defined shared responsibility.

Minimum Controls — MC-1 through MC-12

Each control includes an evidence requirement to ensure measurability. Together they form the baseline every production AI system must meet.

Deployment Overlays — Pattern-Specific Controls

LLMOps, Agentic Orchestration, Agent, Agentic Hardening, Tools & MCP, Context & Long-Window, Pre/Post-training, Multi-Agent Interop, and Multi-Modal/Composite systems.

Autonomy Tiers — HITL / HOTL / HOOTL

Assistive (Human-in-the-Loop), Conditional (Human-on-the-Loop), and Autonomous (Human-out-of-the-Loop) — determining the minimum governance required per system.

Implementation Phases — Roadmap to Maturity

Foundation (0–3 months), Control Deployment (3–9), Agentic Readiness (9–15), and Maturity (15–24) — a staged path from inventory to continuous assurance.

Layer-by-Layer Reference

Concrete definitions and one example per element — the quick-reference key for the rest of the document.

3 Pillars

PillarDefinitionExample
ADOPTExecute and deliver AI capabilities. Owns selection, integration, deployment, operations.An LLMOps team rolling out a customer-support copilot to production.
DEFENDSecure and validate. Owns adversarial testing, guardrails, runtime detection, fairness evaluation, AI incident response.A red team running prompt-injection scenarios against the copilot before launch.
GOVERNOversee, assure, decide. Owns policy, decision rights, regulatory alignment, board accountability.An AI Governance Council approving the copilot for high-risk customer interactions and setting escalation thresholds.

9 Governance Surfaces

SurfaceDefinition
ModelFoundation models, fine-tuned models, adapters, routers, versions, diffusion models, composite model chains
PromptSystem prompts, templates, policies, agent instructions, prompt libraries, multi-modal input validation
ContextRetrieval sources, session state, memory, hidden context, user metadata, cross-session data
ToolsAPIs, plugins, actions, code execution, file access, transactional endpoints, MCP capabilities
OrchestrationPlanners, workflow graphs, retry logic, multi-agent flows, model routing, agent-to-agent communication
IdentityCredentials, service accounts, delegated authority, secrets, trust relationships, agent identity
Safety LayerGuardrails, policy engines, semantic filters, classifiers, circuit breakers, harm detectors
TelemetryLogs, traces, evaluations, replay data, alerts, governance evidence, fairness metrics
Learning LoopPre-training sources, post-training alignment, feedback loops, retraining updates, RLHF data

12 Minimum Controls

ControlDefinitionExample
MC-1Maintain an inventory of all AI systems with an accountable owner, risk classification, and autonomy tier.Published inventory, reviewed quarterly, with named owner per system.
MC-2Classify each AI system by data sensitivity, autonomy, external exposure, harm potential, and business criticality.Documented classification per system using a standardized risk taxonomy.
MC-3Separate deployment ownership, security validation, and approval authority across ADOPT, DEFEND, and GOVERN.Responsible, accountable, consulted, and informed (RACI) matrix per AI system; no single function holding all three roles.
MC-4Complete quality, safety, security, fairness, and failure-mode testing before any production deployment.Signed evaluation report covering all four harm classes before go-live.
MC-5Manage changes to prompts, tools, models, and retrieval sources through a governed change process.Change log with approval records; no uncontrolled production changes.
MC-6Define provenance, retention, access restrictions, and trust ordering for all context inputs.Published context policy per system; annual review.
MC-7Maintain a register of all tools and MCP capabilities with trust tiering and invocation controls.Published register with per-tool risk assessment and approval status.
MC-8Monitor for abuse, drift, data leakage, unsafe actions, bias emergence, and configuration drift in production.Active monitoring with defined alert thresholds and response SLAs.
MC-9Maintain AI-specific incident response procedures with replayable evidence capture.Documented playbook; at least one tabletop exercise per year.
MC-10Conduct governance reviews with exception handling and board reporting for high-risk systems.Review records with findings, decisions, and exception dispositions.
MC-11Evaluate AI systems for discriminatory outcomes using representative test data and established fairness metrics.Fairness evaluation report; re-evaluation after model or data changes.
MC-12For vendor or SaaS AI, document accountability boundaries, contractual obligations, and assurance requirements.Signed responsibility matrix; vendor due diligence records.

4 Harm Classes

ClassDefinitionExample
TechnicalSecurity, reliability, and system integrity failures.Prompt injection causing the copilot to leak its system prompt or run unintended tool calls.
SocietalBias, discrimination, fairness, and human-rights impacts.A loan-decision agent denying credit at a higher rate to one demographic group.
OperationalReliability, accuracy, and business-impact failures.The copilot hallucinating a refund policy that does not exist, leading to disputes.
SystemicEmergent risks from AI-to-AI interaction and scaled deployment.Two negotiation agents from different vendors colluding on an unfavorable deal because their guardrails do not catch joint behavior.

4 Industry Threat Catalogs

ADG does not invent its own threat list — it consumes the four canonical industry catalogs as input and maps each threat into the Minimum Control Set and the deployment overlays.

CatalogWhat it providesHow ADG consumes it
MITRE ATT&CKEnterprise adversary techniques abused via or against AI-enabled systems — phishing, credential theft, lateral movement, exfiltration, persistence.MC-8 (Runtime Monitoring) detection rules, MC-9 (Incident Response) playbooks, and red-team scenarios in MC-4.
MITRE ATLAS84+ adversarial ML/AI techniques and real-world case studies — model evasion, ML supply chain, model extraction, prompt injection at the model layer.MC-4 pre-production adversarial eval suites, MC-8 detection signatures, MC-9 forensic replay test cases.
OWASP Top 10 for LLM (2025)LLM01 Prompt Injection, LLM02 Sensitive Info Disclosure, LLM03 Supply Chain, LLM04 Data & Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector & Embedding Weaknesses, LLM09 Misinformation, LLM10 Unbounded Consumption.MC-4 evaluation checklist, MC-6 (Context Policy) for LLM03/04/08, MC-8 runtime guardrails, MC-11 fairness checks for LLM09.
OWASP Top 10 for Agentic (2026)T1 Memory Poisoning, T2 Tool Misuse, T3 Privilege Compromise, T4 Resource Overload, T5 Cascading Hallucinations, T6 Intent Breaking, T7 Misaligned/Deceptive Behavior, T8 Repudiation, T9 Identity Spoofing, T10 HITL Overwhelm.Agentic Hardening overlay (§10.4) directly. MC-7 (Tool & MCP Register), MC-8 (Runtime Monitoring), MC-9 (Incident Response).

9 Deployment Pattern Overlays

OverlayDefinitionExample
LLMOpsVersioning, evaluation, release management, rollback, cost control, performance monitoring for LLM-based services.A production RAG chatbot with rollback, eval suite, per-token cost tracking, and a release gate.
Agentic OrchestrationThe planner / loop layer of a single agent — multi-step reasoning, retries, subtask decomposition, stop conditions.An agent that decomposes "book my trip" into flights → hotel → calendar with retry budgets.
AgentThe agent as a class of system — business mission, action boundaries, liability model, segregation of duties.A travel-booking agent authorized to spend up to USD 2,500 per booking on behalf of the user.
Agentic HardeningDefensive controls bolted onto agents — authority bounds, action isolation, kill switches, forensic replay, semantic firewalls.Dry-run mode for irreversible actions with human approval required before the booking is committed.
Tools & MCPTool discovery, capability registration, trust tiering, per-invocation policy for tools and MCP servers.An MCP server registered as "trust tier 2" — read-only access to corporate wiki, no write actions allowed.
Context & Long-WindowSession history, retrieved enterprise knowledge, persistent memory, multi-turn poisoning resistance.A copilot with persistent memory that flags conflicting facts injected mid-conversation.
Pre / Post-trainingModel provenance, fine-tuning, alignment, RLHF data, retraining governance.A LoRA adapter trained on internal docs — training data licensed, evaluated for leakage, version-controlled.
Multi-Agent InteropEmergent risks when multiple agents interact — agent-to-agent trust, value alignment, collusion detection, cascading failure prevention.A purchasing agent talking to a vendor's quoting agent, with circuit breakers if they loop or agree on out-of-policy terms.
Multi-Modal / CompositeCross-model risks when LLM + diffusion + classifier + retrieval combine in one product.An assistant that takes a screenshot, classifies it, retrieves docs, and generates a response — system-level eval required, not per-model.

3 Autonomy Tiers

TierDefinitionExample
HITL — AssistiveAI recommends or drafts; a human approves every output before it takes effect.A copilot that drafts emails for the user to review and send.
HOTL — ConditionalAI acts within pre-approved limits; a human monitors and can intervene.A trading agent executing within position limits, with humans monitoring exposure dashboards.
HOOTL — AutonomousAI executes multi-step goals with limited or delayed human review.An overnight data-pipeline agent that processes batches and reports results in the morning.

4-Phase Roadmap

PhaseDefinitionExample
Foundation (0–3 months)Inventory, owners, ADG roles, criticality classification, AI Governance Council established.Quarter 1: publish AI inventory, name owners, charter the Governance Council. Controls: MC-1, MC-2, MC-3.
Control Deployment (3–9 months)Release gates, change control, context policies, monitoring, adversarial testing, fairness evals, vendor due diligence.Quarter 2–3: implement MC-4 through MC-9 plus MC-11/MC-12 across all high-risk systems.
Agentic Readiness (9–15 months)Authority statements, tool trust tiering, MCP governance, circuit breakers, multi-agent governance, forensic replay.Quarter 4–5: agentic hardening overlay deployed for all production agents.
Maturity (15–24 months)Continuous evaluation, persistent adversarial monitoring, drift governance, RAI measurement, board-level reporting.Quarter 6–8: automated weekly red-team runs, quarterly board AI risk review, formal assurance review.

3.Document Usage

This section provides guidance on how to read, apply, and implement the ADG framework.

3.1 Target Audience

AudienceReading path
Board & Executive Sponsors§2 Executive Summary · §4 ADG Triad & Operating Model · §6 Harm Taxonomy & RAI · §11 Controls & Board-Level Indicators · §12 Regulatory & Roadmap
Security & AI Red Teams§5 Governance Surfaces · §6 Harm Taxonomy & RAI · §9 Lifecycle Governance · §10 Deployment Overlays · §11 Controls & Measurement
Engineering & Platform Teams§4 ADG Triad & Operating Model · §5 Governance Surfaces · §8 People, Process, Tech & Data · §9 Lifecycle Governance · §10 Deployment Overlays
Risk & Compliance§6 Harm Taxonomy & RAI · §7 Shared Responsibility · §12 Regulatory & Roadmap · Appendix A Definitions
All Stakeholders§1 Background · §2 Executive Summary · §3 Document Usage

3.2 Foundational Principles

ADG is built on nine foundational principles — durable standards that apply across industries, deployment patterns, and regulatory regimes.

01

Separation of Powers

Independent validation is mandatory

02

Authority Must Be Explicit

Implicit authority is a control gap

03

Context Is Attack Surface

Governed assets need provenance & access control

04

Tool Use Is Highest Risk

Risk escalates from output to real-world action

05

Graduated Oversight

Higher autonomy needs stronger controls

06

Lifecycle Governance

No single gate is sufficient

07

Evidence Is Mandatory

If it can't be evidenced, it can't be relied upon

08

RAI Embedded, Not Appended

Structural requirements across all three pillars

09

Shared Responsibility

Accountability must be documented & enforced

4.The ADG Triad and Operating Model

Answer capsule

What are the three pillars of the ADG framework and who owns each?

ADG has three pillars. Adopt executes and delivers business value safely, owned by AI product owners, ML and prompt engineers, and DevSecOps. Defend secures and validates by preventing harmful behavior, owned by Red Team and Security Engineers. Govern oversees and decides, justifying and approving AI use at board level via the chief AI officer (CAIO), legal, and risk officers.

4.4

Operating Model — Five Dimensions, Three Pillars

What each pillar asks, decides and owns. Hover a cell for that pillar's answer.

Color identifies the pillar — cells are not scored, because the operating model ranks nothing.

3.2

Foundational Principles — Nine Durable Standards

Equal-sized tiles on purpose: the framework ranks none of these above another. Hover for each principle's standard.

4.1 · adopt

Execute and Deliver

“Deliver business value safely”

Primary question
Can we deploy it effectively?
Decision focus
Capability, performance, delivery, reliability
Stakeholders
AI Product Owner · ML Engineers · Prompt Engineers · DevSecOps · App Architects · Enterprise Architects
Core outputs
Deployed service · Runbooks · Baselines · Releases
Success measure
Value delivery with controlled operations
Escalation
Escalates blockers to GOVERN
4.2 · defend

Secure and Validate

“Identify, prevent, detect harmful behavior”

Primary question
Can it be abused, fail dangerously, or cause harm?
Decision focus
Security, resilience, fairness, abuse resistance, containment
Stakeholders
AI Red Team · Security Engineers · Bias Auditors · Incident Response · Guardrail Engineers · Detection Engineers
Core outputs
Test results & detections · Guardrails · Fairness evaluations · Incident playbooks
Success measure
Risk reduced across all four harm classes
Escalation
Escalates unresolved risks to GOVERN
4.3 · govern

Oversee, Assure, and Decide

“Justify, approve, evidence AI use at board level”

Primary question
Should we approve it, under what conditions, and at what risk?
Decision focus
Risk appetite, legality, accountability, ethics, oversight
Stakeholders
CAIO / Ethics Lead · Legal & Compliance · Risk Officers · Board / C-Suite · Privacy Counsel · Compliance Lead
Core outputs
Policies, approvals, risk thresholds · Exceptions & evidence · Board reports
Success measure
Defensible use with auditable, measurable governance
Escalation
Resolves ADOPT-DEFEND tension; defines go/no-go and exception policy

Strategic functions

  • Define organizational AI risk appetite
  • Establish decision rights and escalation paths
  • Own the AI Governance Council charter
  • Define board-level reporting requirements
  • Set investment justification criteria
  • Maintain regulatory mapping

4.4 Operating Model

ADG uses a simple rule: Adopt builds and operates, Defend breaks and protects, Govern authorizes and oversees.

DimensionAdoptDefendGovern
Primary questionCan we deploy it effectively?Can it be abused, fail dangerously, or cause harm?Should we approve it, under what conditions, and at what risk?
Decision focusCapability, performance, delivery, reliabilitySecurity, resilience, fairness, abuse resistance, containmentRisk appetite, legality, accountability, ethics, oversight
Core outputsDeployed service, runbooks, baselines, releasesTest results, detections, guardrails, fairness evaluations, incident playbooksPolicies, approvals, risk thresholds, exceptions, evidence, board reports
Success measureValue delivery with controlled operationsRisk reduced across all four harm classesDefensible use with auditable, measurable governance
Tension resolutionEscalates blockers to GOVERNEscalates unresolved risks to GOVERNResolves ADOPT-DEFEND tension; defines go/no-go and exception policy

5.Governance Surfaces

Answer capsule

What are the governance surfaces in the ADG framework for securing an AI system?

ADG organizes governance into nine surfaces that define what must be governed regardless of model vendor, architecture, or deployment pattern. Along the request flow they include Prompt, Context, Model, Tools, and Orchestration, each marked with the responsible Adopt, Defend, or Govern pillars. Input and output are not governed surfaces themselves.

5.

Governance Surfaces — Request Flow

The nine surfaces in the order a request crosses them, colored by the pillar that owns each. Hover for scope and control objective.

AdoptDefendGovernColor shows the first pillar in each surface’s ADG alignment — hover for the full scope.
SurfaceScopeADG AlignmentControl Objective
ModelFoundation models, fine-tuned models, adapters, routers, versions, diffusion models, composite model chainsA+GUse only approved models with known risk posture, provenance, and change traceability
PromptSystem prompts, templates, policies, agent instructions, prompt libraries, multi-modal input validationA+DPrevent unmanaged behavior changes and unsafe instruction patterns
ContextRetrieval sources, session state, memory, hidden context, user metadata, cross-session dataG+DPrevent poisoning, leakage, cross-session contamination, and privacy violations
ToolsAPIs, plugins, actions, code execution, file access, transactional endpoints, MCP capabilitiesDEnforce least privilege, strong validation, sandboxing, and full audit logging
OrchestrationPlanners, workflow graphs, retry logic, multi-agent flows, model routing, agent-to-agent communicationA+DBound agent behavior, prevent cascading failures, ensure deterministic control
IdentityCredentials, service accounts, delegated authority, secrets, trust relationships, agent identityG+DPrevent privilege misuse, preserve accountability, trace agent actions to human authority
Safety LayerGuardrails, policy engines, semantic filters, classifiers, circuit breakers, harm detectorsDBlock unsafe content, unfair outputs, and unauthorized actions before impact
TelemetryLogs, traces, evaluations, replay data, alerts, governance evidence, fairness metricsD+GMake behavior observable, reviewable, provable, and measurable
Learning LoopPre-training sources, post-training alignment, feedback loops, retraining updates, RLHF dataG+AControl data provenance, drift, alignment stability, and undocumented behavior change

Where ADG meets MITRE and OWASP

The nine surfaces above describe what must be governed. The four industry threat catalogs describe what attackers do. ADG consumes them as input — every surface inherits its detection rules, eval scenarios, and runtime guardrails from these sources, then maps the resulting controls to NIST AI RMF and ISO/IEC 42001.

6.Harm Taxonomy and Responsible AI Integration

Answer capsule

What harm taxonomy does the ADG framework use to govern AI risks beyond security?

ADG uses a four-class harm taxonomy covering Technical, Societal, Operational, and Systemic harms, paired with seven Responsible AI principles. The classes map into every governance surface, lifecycle stage, and deployment overlay, and are plotted by detection difficulty and impact scope so governance addresses attacks, bias, reliability, and emergent multi-agent risk.

6.2

Responsible AI Principles — Seven Embedded Standards

The seven principles ADG embeds alongside its harm classes. Equal-sized tiles: the framework ranks none above another.

6.1

Harm Classification

Four harm classes and the harm types inside each. Hover a segment to see the class definition and its detection/scope quadrant.

Hover a class for its definition and harm types.

6.1 Harm Classification

The four harm classes plotted by detection difficulty and impact scope. Each carries the threats it covers, the pillars that own it, and the Minimum Controls that detect it.

Operational — Easy detect · Individual scope

Reliability, accuracy, business-impact failures

HallucinationModel driftGrounding failureData quality degradationLack of explainability

Owned by: ADOPT, DEFEND · Detected by: MC-4, MC-5, MC-8

Technical — Easy detect · Systemic scope

Security, integrity, system reliability failures

Prompt injectionData exfiltrationModel theftJailbreakingDenial of wallet

Owned by: DEFEND · Detected by: MC-7, MC-8, MC-9

Societal — Hard detect · Individual scope

Bias, discrimination, human-rights impacts

Algorithmic discriminationStereotypingOpportunity denialManipulationSurveillance

Owned by: GOVERN, DEFEND · Detected by: MC-2, MC-10, MC-11

Systemic — Hard detect · Systemic scope

Emergent risk from AI-to-AI interaction

Agent collusionValue misalignment amplificationCascading failuresSycophancy loops

Owned by: GOVERN, DEFEND · Detected by: MC-8, MC-9, MC-10

6.2 Responsible AI Principles

Every governance surface must account for seven responsible AI dimensions, embedded across all three pillars rather than appended as a separate track.

Fairness & Non-Discrimination

Outputs must not disadvantage groups

Transparency & Explainability

Explainable to its risk tier

Privacy & Data Protection

Minimize. Comply with data law

Accountability

Operator to executive sponsor

Human Oversight

Scaled to autonomy and harm potential

Robustness & Safety

Tested under adversarial conditions

Sustainability & Well-Being

Environmental & societal impact

Integration rule: Responsible AI is not a separate track. It is embedded into every ADG pillar — ADOPT, DEFEND, and GOVERN — and must be reflected in all certification curricula, operating artifacts, and governance reviews.

7.Shared Responsibility Model

Answer capsule

How does AI governance ownership differ across self-hosted, foundation-model API, and SaaS deployments?

ADG defines three deployment responsibility classes. Homegrown self-hosted stacks put all nine governance surfaces on the organization. Foundation Model APIs leave the organization owning seven surfaces, with model governance shared and the model and training vendor-owned. SaaS or embedded AI shifts most surfaces to the vendor, leaving the organization four.

7.

Shared Responsibility — Control Ownership by Deployment Class

Who owns which of the nine governance surfaces as you move from self-hosted to vendor-embedded AI.

  • Ownership shifts right as you move toward vendor-embedded AI — but accountability for use never fully transfers.
  • MC-12 (Shared Responsibility Documentation) requires every deployment to map control boundaries explicitly.

7.1 Deployment Responsibility Classes

ClassDescriptionOrganization OwnsSharedVendor Owns
Homegrown / Self-HostedOrganization trains, hosts, and operates the full AI stackAll 9 surfaces, full lifecycleNone (full ownership)Infrastructure SLAs only
Foundation Model APIConsumes a foundation model via API (e.g., OpenAI, Anthropic, Google)Prompt, Context, Tools, Orchestration, Identity, Safety Layer, TelemetryModel governance, Learning LoopModel training, alignment, infrastructure, API availability
SaaS AI / Embedded AIAI embedded in a vendor product (e.g., Copilot, Einstein, ServiceNow)Context, Identity, Telemetry, GOVERN policySafety Layer, Prompt customizationModel, Orchestration, Tools, Runtime stack, Learning Loop

7.2 Vendor AI Due Diligence Requirements

  1. Require vendor disclosure of model provenance, training data policies, alignment methods, and known limitations
  2. Establish contractual AI governance clauses covering incident notification, data handling, model change management, and liability allocation
  3. Conduct independent evaluation of vendor-provided safety controls rather than relying solely on vendor claims
  4. Maintain consumer-side telemetry and monitoring regardless of vendor monitoring capabilities
  5. Include AI governance questions in procurement processes and vendor risk assessments
  6. Define rollback and exit strategies for vendor AI dependencies

8.People, Process, Technology, and Data

Answer capsule

What roles and process steps does ADG define across the People and Process layers?

ADG requires explicit capability ownership across People, Process, Technology, and Data layers. The People layer assigns dedicated roles to Adopt, Defend, and Govern, plus a cross-functional AI Governance Council for escalation. The Process layer formalizes a nine-step backbone spanning the three pillars, from inventory and deployment gates to board reporting.

8.2

Process Backbone — Nine Steps Across Three Pillars

The governance process end to end, with each step colored by the pillar accountable for it.

ADOPTDEFENDGOVERN

8.1 People Layer

ADOPT roles

AI product owner · accountable AI service owner · LLMOps lead · orchestration engineer · prompt designer · platform engineer · enterprise architect · DevSecOps engineer

DEFEND roles

AI red team lead · guardrail engineer · detection engineer · AI security architect · incident commander · forensic analyst · responsible AI scientist · bias/fairness auditor

GOVERN roles

model risk officer · privacy counsel · compliance lead · data steward · AI ethics and sociotechnical oversight lead · executive approver · procurement governance lead

AI Governance Council

Every organization deploying AI systems should establish a cross-functional AI Governance Council with representation from ADOPT, DEFEND, and GOVERN — the escalation path and tension-resolution mechanism from §4.4.

8.2 Process Layer — the Nine-Step Backbone

1Inventory— AI System Inventory and criticality classificationADOPT
2Deployment Gate— Deployment gate and approval workflow, including pre-deployment fairness and safety evaluationDEFEND
3Change Management— Prompt, model, and tool change managementADOPT
4Continuous Evaluation— Continuous evaluation, drift review, and fairness monitoringADOPT
5Oversight Tier— Human oversight model selection — HITL/HOTL/HOOTL with documented rationaleGOVERN
6Incident Response— AI-specific incident response and evidence retentionDEFEND
7Remediation— Post-incident remediation with retest and governance reviewDEFEND
8Vendor Due Diligence— Vendor AI due diligence and ongoing assuranceADOPT
9Board Reporting— Board-level reporting cycle for high-risk AI systemsGOVERN

8.3 Technology Layer

  1. Model gateway and routing layer
  2. Retrieval, memory, and context management layer
  3. Tool registry and MCP trust layer
  4. Policy engine, guardrail layer, and harm detection layer
  5. Runtime telemetry, replay, and fairness measurement layer
  6. Training, tuning, and evaluation pipeline layer
  7. Input validation and sanitization layer (covering prompts, RAG inputs, and multi-modal inputs)

8.4 Data Layer

Traditional enterprise data architecture separates data into distinct tiers — structured databases, warehouses, lakes, file stores, and APIs. AI systems fundamentally disrupt this separation: an agent consuming enterprise data through retrieval pipelines, MCP connections, or tool invocations does not distinguish a SQL record from a Slack thread — all of it collapses into a single text-token consumption surface.

Access control at the storage layer alone is no longer sufficient. Organizations must govern the full pipeline from source data through retrieval, embedding, context assembly, and AI consumption — across four dimensions:

8.4.1 Data People

  • Data Stewards for AI: extending traditional data stewardship to govern the full text-based data surface that AI systems can access
  • AI Data Engineers: bridging data engineering and AI operations, responsible for RAG indexing, embedding generation, knowledge base curation
  • Context Architects: designing what data flows into AI context windows, in what priority order, with what trust ranking
  • Knowledge Base Curators: responsible for freshness, accuracy, deduplication, and retirement of enterprise knowledge assets

8.4.2 Data Process

  • AI-aware data classification: extending beyond storage-tier access control to include AI-readability rules
  • Provenance tracking across the text pipeline: maintaining a verifiable chain from any AI output back through the retrieval step to the source document
  • Cross-source inference governance: policies governing when AI systems may combine information from multiple data sources
  • Text-based policy management: AI system configurations governed as controlled documents with versioning, approval workflows, and rollback
  • Knowledge base lifecycle management: content ingestion, quality validation, freshness review, conflict resolution, deduplication, and retirement
  • Data minimization for AI: ensuring context windows contain only data necessary for the task
  • Consent and lawful basis tracking: maintaining records of lawful basis for processing each data category

8.4.3 Data Technology

  • Vector stores and embedding infrastructure: governed data infrastructure requiring access controls, encryption, backup and recovery
  • Enterprise knowledge graphs: structured representations enabling context assembly with awareness of entity relationships
  • Context assembly engines: systems that select, rank, truncate, filter, and compose text from multiple sources
  • MCP and tool registries as data access layers: governed as data access infrastructure with the same rigor as database connections
  • Text-based configuration stores: GitOps-style repositories for all AI system configurations
  • Data lineage and output attribution: technology to trace which source documents contributed to a specific AI output
  • Embedding pipeline governance: validation testing, drift monitoring, and re-indexing governance

8.4.4 Data × Surface Intersection

  • Model: Training data provenance, fine-tuning data governance, model card data documentation
  • Prompt: System prompt versioning and change control as governed text artifacts
  • Context: Retrieval source classification, context assembly governance, cross-source inference controls
  • Tools: MCP servers as data access gateways; tool-retrieved data classified and logged
  • Orchestration: Data flow governance across multi-step agent workflows; inter-agent data sharing rules
  • Identity: Data access tied to agent identity and delegated authority; no implicit data access
  • Safety Layer: Guardrail configurations as governed text; data-driven harm detection models governed as data assets
  • Telemetry: Logs and traces as sensitive data requiring retention, redaction, and access governance
  • Learning Loop: Feedback data, RLHF inputs, and retraining datasets governed as controlled data assets with provenance

9.Lifecycle Governance

Answer capsule

What are the lifecycle stages in the ADG AI governance framework?

ADG applies controls across six lifecycle stages: Pre-training/Sourcing, Post-training/Alignment, Build/Integrate, Deploy/Authorize, Run/Monitor, and Retire/Learn. The lifecycle is explicitly circular, so lessons from Retire/Learn feed back into sourcing decisions. Each stage assigns distinct Adopt, Defend, and Govern responsibilities.

9.

Lifecycle Governance — Six-Stage Circular Flow

Drawn as a ring because the framework publishes it as one: governance returns to sourcing rather than ending at deployment. Hover a stage for its Adopt, Defend and Govern responsibilities.

Stage 6 returns to stage 1 — governance does not end at deployment.

StageAdoptDefendGovern
Pre-training / SourcingSelect suppliers & datasets fit for purpose; assess training data for representation and biasAssess provenance abuse, contamination risk, and training data biasApprove sourcing constraints, licensing, jurisdictional requirements, and data ethics
Post-training / AlignmentTune for use-case quality and operational fitTest for regressions, bypasses, safety degradation, and fairness driftReview alignment objectives, documentation sufficiency, and RAI criteria
Build / IntegrateAssemble workflows, prompts, tools, retrieval; integrate DevSecOps controlsValidate interfaces, secrets, attack surfaces, and input validation coverageClassify use case, approve controls, define oversight requirements and risk tier
Deploy / AuthorizeRelease through controlled change process with rollback readinessConfirm pre-production testing, monitoring readiness, and fairness evaluationGrant formal deployment approval or exception with documented conditions
Run / MonitorOperate service, maintain SLAs, track quality and costDetect abuse, failures, drift, unsafe actions, and bias emergence; continuous red teamingReview incidents, exceptions, compliance posture, and configuration drift
Retire / LearnDecommission services and roll forward lessonsPreserve evidence, investigate failures, validate closureUpdate policy, records, accountability decisions; feed lessons into sourcing cycle

9.1 Post-Deployment Continuous Governance

  1. Configuration drift detection: verify that the system in production matches what was approved (models, prompts, tools, context sources)
  2. Usage authorization monitoring: confirm that approved users are using the system for approved purposes within approved boundaries
  3. Feature and capability change governance: new model versions, prompt updates, tool additions, and retrieval source changes post-deployment must go through change control
  4. Continuous automated evaluation: scheduled adversarial testing, fairness benchmarking, and accuracy regression testing on production systems
  5. Ongoing governance of the product roadmap: feature additions to deployed AI systems require re-evaluation against the original risk classification and approval conditions

10.Deployment Pattern Overlays

Answer capsule

How does ADG decide which governance overlays apply to a given AI deployment?

ADG adds deployment-specific overlays so governance matches the actual architecture, and overlays are additive: you select all that apply. An applicability matrix maps overlay families across deployment classes (Homegrown, FM API, SaaS) and autonomy tiers (HITL, HOTL, HOOTL), marking each Required, Recommended, Optional, or Not applicable.

10.

Overlay Applicability

Which overlays are Required, Recommended, Optional or N/A for each deployment class and autonomy tier.

N/AOptionalRecommendedRequired
OverlayHomegrownFM APISaaSHITLHOTLHOOTL
LLMOpsRequiredRequiredRecommendedRequiredRequiredRequired
Agentic OrchestrationRecommendedRecommendedN/AOptionalRequiredRequired
AgentRecommendedRecommendedOptionalOptionalRequiredRequired
Agentic HardeningRequiredRequiredRecommendedOptionalRequiredRequired
Tools & MCPRecommendedRequiredOptionalRequiredRequiredRequired
Context & Long-WindowRequiredRequiredRecommendedRequiredRequiredRequired
Pre/Post-trainingRequiredOptionalN/ARecommendedRecommendedRequired
Multi-Agent InteropRecommendedRecommendedOptionalOptionalRecommendedRequired
Multi-Modal / CompositeRecommendedRecommendedOptionalOptionalRecommendedRequired

Overlays are additive — select all that apply.

10.1

LLMOps Overlay

Versioning, evaluation, release management, rollback, cost control, and performance monitoring for LLM-based services.

Adopt
Structures model onboarding, baseline evaluation, config versioning, rollback readiness, and operational SLOs
Defend
Structures adversarial testing, abuse simulation, leakage testing, denial-of-wallet controls, monitoring coverage, and bias evaluation
Govern
Structures use-case approval, vendor due diligence, deployment thresholds, exception management, and LLMOps cost governance

10.2

Agentic Orchestration Overlay

Planners, loops, retries, multi-step reasoning, subtask decomposition, and multi-agent coordination.

Adopt
Defines mission scope, stop conditions, retry budgets, and workflow boundaries
Defend
Validates loop abuse resistance, prompt chaining resistance, recursion limits, and kill-switch behavior
Govern
Approves autonomy tier, escalation path, and legal accountability for delegated decisions

10.3

Agent Overlay

AI systems that act on behalf of a user, team, or enterprise process rather than merely generating content.

Adopt
Defines business mission, action boundaries, and acceptable failure modes
Defend
Tests transaction safety, impersonation resistance, and unsafe action prevention
Govern
Defines liability model, mandatory approvals, record retention, and segregation-of-duty requirements

10.5

Tools and MCP Overlay

Tool discovery, capability registration, trust mediation, and policy-controlled invocation of tools and context providers.

Adopt
Justifies why each tool or MCP capability is needed and what business task boundary it serves
Defend
Enforces authentication, authorization, parameter validation, rate limiting, sandboxing, and audit logging
Govern
Maintains approval policy, third-party assurance criteria, trust tiers, and data-sharing restrictions

10.6

Context and Long-Window Overlay

Session history, retrieved enterprise knowledge, hidden orchestration instructions, persistent memory, and context overflow handling.

Adopt
Defines the minimum context required for task quality
Defend
Tests for context poisoning, leakage, overflow abuse, cross-session contamination, and multi-turn attack patterns
Govern
Defines provenance rules, retention, data-class handling, trust ranking, and lawful-use constraints

10.7

Pre-training and Post-training Overlay

Model provenance, fine-tuning, adapters, preference alignment, safety tuning, feedback loops, and retraining.

Adopt
Structures fine-tuning objectives, experiment tracking, rollback, and operational performance baselines
Defend
Structures regression testing, jailbreak retesting, alignment failure analysis, fairness drift monitoring, and bias evaluation
Govern
Structures provenance review, licensing, cross-border constraints, GDPR compliance for training data, documentation, and approval of learning-loop inputs

10.4 Agentic Hardening — Required control themes

  1. Delegated authority bounds
  2. Action-layer isolation and dry-run modes
  3. Semantic firewalls before tool use and before response release
  4. Memory hygiene and state reset controls
  5. Human override and emergency stop pathways
  6. Forensic replay of prompts, retrieved context, policy decisions, and tool calls

10.5 Minimum MCP requirements

  1. Approved server inventory
  2. Capability trust tiering
  3. Per-invocation policy evaluation
  4. Auditable request and response traces
  5. Explicit rejection of implicit trust in tool-supplied instructions

10.8 Multi-Agent and Agent Interoperability

Multi-agent systems create emergent governance challenges that single-agent controls do not address:

  • Agent-to-agent trust boundaries: each agent interaction must enforce explicit trust verification; no agent should implicitly trust another agent's outputs or instructions.
  • Value alignment verification: agents with different guardrail configurations, different training, or different vendors may have incompatible safety policies. Cross-agent interactions must be tested for value alignment conflicts.
  • Collusion and deception detection: monitoring for patterns where agents coordinate to bypass controls, produce misleading outputs, or exploit gaps between their respective guardrails
  • Cascading failure and amplification risk: a failure or bias in one agent can be amplified through a chain of dependent agents. Circuit breakers must exist at agent-to-agent boundaries.
  • Cross-agent audit trails: every agent-to-agent interaction must be logged with sufficient detail for forensic replay.
  • Sycophancy degradation prevention: in agent-to-agent interactions, sycophantic behavior can devolve into harmful feedback loops. Detection and interruption mechanisms are required.
  • Interoperability governance: when agents from different organizations or vendors interact, a shared governance protocol must define minimum safety, logging, and accountability requirements.

11.Controls, Artifacts, and Measurement

Answer capsule

What is the minimum control set required to implement the ADG framework?

ADG defines 12 Minimum Controls (MC-1 through MC-12) as the implementation baseline, each with an evidence requirement to ensure measurability. They span AI system inventory, risk classification, separation of duties, pre-production evaluation, change control, context policy, tool and MCP register, runtime monitoring, incident response, governance review, fairness evaluation, and shared responsibility documentation.

11.2

Control Crosswalk — NIST AI RMF & ISO/IEC 42001

Every Minimum Control mapped to the NIST function and ISO/IEC 42001 Annex A clause it satisfies. Filter by pillar, hover to trace a mapping, click a control for its full standards detail.

Click any control to see its full mapping. Ribbon width is uniform — the framework asserts that a mapping exists, not how strong it is.

11.2.1

Threat → Control → Standard Flow

ADG consumes four industry threat catalogs rather than publishing its own. Each technique routes through the Minimum Control Set and on to NIST and ISO — pick a catalog and follow any path end to end.

MITRE ATT&CK · Enterprise (AI-relevant) — 10 techniques answered by 6 of the 12 minimum controls, most often MC-8 (8).

Hover to trace a full path; click a threat for its detail. ADG consumes these catalogs as input — it does not publish a threat list of its own.

11.3 Required Operating Artifacts

ArtifactPurposeADG Alignment
AI System ProfileDocuments system architecture, risk classification, autonomy tier, harm classes, and deployment patternADOPT
ADG RACI MatrixMaps control ownership across ADOPT, DEFEND, and GOVERN for each AI systemGOVERN
Agent Authority StatementDefines what an agent may access, decide, execute, and escalateGOVERN+ADOPT
Context PolicySpecifies approved sources, retention, redaction, trust ordering, and privacy controlsGOVERN
Tool and MCP RegisterCatalogs tools, trust tiers, invocation policies, and third-party assurance statusDEFEND
AI Release Gate ChecklistPre-deployment verification covering security, fairness, safety, and governance approvalADOPT+DEFEND
AI Incident Evidence PackForensic capture package for AI-specific incidentsDEFEND
Model and Prompt Change LogTracks all changes to models, prompts, and system configurations with approval recordsADOPT
Governance Exception RegisterRecords all governance exceptions with justification, risk acceptance, and expirationGOVERN
Vendor AI Due Diligence RecordDocuments vendor AI assessments, contractual AI clauses, and shared responsibility boundariesGOVERN
Fairness Evaluation ReportRecords fairness and bias testing methodology, results, and remediation actionsDEFEND+GOVERN

11.4 Measurement and Evidence Framework

11.4

Measurement and Evidence — Three Tiers

Tiers aggregate upward: per-control KPIs roll into outcome metrics, which roll into the executive set. Width is the published metric count.

Width is the number of published metrics in each tier. Hover for the metrics themselves.

ADG requires measurable governance. Three measurement tiers ensure controls are not just documented but demonstrably effective.

Tier 1 — Control Effectiveness Metrics

Per-control KPIs · Operational

  • AI systems with completed risk classification
  • AI systems with documented RACI matrix
  • Mean time from model change to governance approval
  • Tool/MCP capabilities with current trust assessment
  • Production AI systems with active runtime monitoring
  • Uncontrolled production changes detected per quarter
  • High-risk AI systems with completed fairness evaluation

Tier 2 — Outcome Metrics

Cross-surface governance effectiveness

  • Mean time to detect AI-specific incidents (MTTD)
  • Mean time to contain AI-specific incidents (MTTC)
  • AI governance exceptions open beyond expiration date
  • AI systems operating within approved config (no drift)
  • AI-related compliance findings from internal/external audit
  • Fairness metric trends across production systems (QoQ)

Tier 3 — Board-Level Indicators

Executive reporting · aggregated

  • AI risk posture score (composite across all surfaces)
  • AI compliance coverage (systems with current governance review)
  • Exception backlog trend (open, aging, risk-weighted)
  • AI incident trend (frequency, severity, resolution time)
  • Vendor AI risk exposure (third-party model dependencies)
  • Responsible AI compliance rate (fairness, transparency, accountability)

12.Regulatory Alignment and Roadmap

Answer capsule

How does the ADG framework map to the EU AI Act, NIST AI RMF, and ISO/IEC 42001?

ADG maps its components to major regulations and standards — e.g., Risk Classification (MC-2) to EU AI Act Art. 6–7, NIST MAP, and ISO/IEC 42001 6.1.2; Incident Response to Art. 73 and ISO 10.2. The mapping is indicative, not exhaustive — it provides a governance backbone that facilitates but does not guarantee compliance.

12.1 Regulatory and Standards Alignment

12.1

Regulatory Coverage

Where each ADG component carries an obligation under the EU AI Act, NIST AI RMF and ISO/IEC 42001. Hover for the exact article or clause.

Each cell shows the article or clause; hover for the full mapping. Cells are not weighted — the framework states that a mapping exists, not how strong it is.

ADG ComponentEU AI ActNIST AI RMFISO/IEC 42001
Risk Classification (MC-2)Art. 6-7: Risk categorizationMap: Risk identification and analysis6.1.2: AI risk assessment
Pre-Production Eval (MC-4)Art. 9: Risk management systemMeasure: AI risk measurement8.1: Operational planning and control
Runtime Monitoring (MC-8)Art. 72: Post-market monitoringManage: Continuous monitoring9.1: Monitoring, measurement, analysis and evaluation
Fairness Eval (MC-11)Art. 10: Data governance and bias preventionMap: Bias identificationA.7: Data for AI systems + A.5: Impact assessment
Incident Response (MC-9)Art. 73: Serious incident reportingManage: Incident response10.2: Nonconformity and corrective action
AI System Inventory (MC-1)Art. 49 + Art. 71: Registration in EU databaseGovern: Inventory and categorization7.5: Documented information
Human Oversight (Tiers)Art. 14: Human oversight requirementsGovern: Human-AI teamingA.9: Use of AI systems + A.5: Impact assessment
Transparency (Telemetry)Art. 13: Transparency requirementsGovern: Transparency and documentationA.8: Information for interested parties

Note: this mapping is indicative, not exhaustive. Organizations must conduct their own regulatory compliance assessment.

12.2 Implementation Roadmap

12.2

Adoption Timeline

The four phases on a real month axis, drawn from each phase's own published window.

PhaseDefinitionExample
Foundation (0–3 months)Inventory, owners, ADG roles, criticality classification, AI Governance Council established.Quarter 1: publish AI inventory, name owners, charter the Governance Council. Controls: MC-1, MC-2, MC-3.
Control Deployment (3–9 months)Release gates, change control, context policies, monitoring, adversarial testing, fairness evals, vendor due diligence.Quarter 2–3: implement MC-4 through MC-9 plus MC-11/MC-12 across all high-risk systems.
Agentic Readiness (9–15 months)Authority statements, tool trust tiering, MCP governance, circuit breakers, multi-agent governance, forensic replay.Quarter 4–5: agentic hardening overlay deployed for all production agents.
Maturity (15–24 months)Continuous evaluation, persistent adversarial monitoring, drift governance, RAI measurement, board-level reporting.Quarter 6–8: automated weekly red-team runs, quarterly board AI risk review, formal assurance review.

13.Workforce Capability

Answer capsule

What is the cost of the AI skills gap, and how does ADG address workforce capability?

IDC (2024) estimated that IT skills shortages could cost organizations USD 5.5 trillion in delays and lost competitiveness. ADG answers via EC-Council's Enterprise AI Credential Suite — a four-part ladder of role-aligned credentials mapped to the Adopt, Defend, and Govern pillars and the Minimum Control Set.

13.2

The Capability Bridge — Ladder Rung to Credential

Each credential grouped by the rung of the capability ladder it serves. Hover a credential for what it certifies.

  • Literacy baseline — a shared AI vocabulary for every practitioner, technical or not, so governance conversations can happen at enterprise speed. Anchored by the Artificial Intelligence Essentials (AI|E) program.
  • Role-aligned capability — three flagship credentials mapped 1:1 to the ADG pillars: C|AIPM for Adopt, C|OASP for Defend, C|RAGE for Govern. Each credential certifies execution-grade competence for the people accountable for that pillar.
  • Extended core skills — CEH v13 restructured to integrate AI modules across all five phases of ethical hacking, extending existing security practitioners into the AI attack surface without a role change.
  • Operational readiness — each credential crosswalks to the framework's Minimum Control Set (MC-1 through MC-12), turning certification into deployable evidence that auditors, regulators, and boards can accept.

13.1 The AI Skills Gap

The defining constraint on enterprise AI is not the technology — it is the workforce. AI is scaling into production faster than the people who must run, secure, and govern it can be trained, credentialed, and deployed. IDC (2024) estimated that IT skills shortages could cost organizations USD 5.5 trillion in delays, quality issues, and lost competitiveness. Without workforce capability, every control in this framework remains theoretical.

“AI is moving from experimentation to infrastructure, and the workforce has to move with it. Security leaders are now accountable for systems that learn, adapt, and influence outcomes at speed.”

— Jay Bavisi, Chairman & CEO, EC-Council Group

The Adopt gap

Program and transformation leaders cannot translate AI strategy into measurable, governed delivery — stalling pilots before they reach production.

The Defend gap

Security organizations lack adversarial AI expertise — prompt injection, model evasion, data poisoning, and multi-agent exploitation are not yet standard tradecraft.

The Govern gap

Risk, compliance, and board leaders lack the vocabulary, evidence protocols, and regulatory mapping (EU AI Act, NIST AI RMF, ISO/IEC 42001) to hold AI systems to account.

13.2 The Capability Bridge

EC-Council's answer is the Enterprise AI Credential Suite — a portfolio of role-aligned credentials mapped directly to the ADG framework, structured as a four-part capability ladder:

  1. Literacy baseline — a shared AI vocabulary for every practitioner, technical or not, so governance conversations can happen at enterprise speed. Anchored by the Artificial Intelligence Essentials (AI|E) program.
  2. Role-aligned capability — three flagship credentials mapped 1:1 to the ADG pillars: C|AIPM for Adopt, C|OASP for Defend, C|RAGE for Govern. Each credential certifies execution-grade competence for the people accountable for that pillar.
  3. Extended core skills — CEH v13 restructured to integrate AI modules across all five phases of ethical hacking, extending existing security practitioners into the AI attack surface without a role change.
  4. Operational readiness — each credential crosswalks to the framework's Minimum Control Set (MC-1 through MC-12), turning certification into deployable evidence that auditors, regulators, and boards can accept.

13.3 Credential Portfolio

Each links to its official EC-Council program page for the syllabus, prerequisites, and enrollment.

Appendix A: Definitions

TermDefinition
AI SystemA machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions (aligned with OECD/EU AI Act).
AI AgentAn AI system that can autonomously plan, execute multi-step tasks, invoke tools, and take actions in physical or digital environments on behalf of a user or organization.
Foundation ModelA general-purpose AI model trained on broad data that can be adapted to a wide range of downstream tasks (e.g., GPT, Claude, Gemini, Llama, Stable Diffusion).
ModelAny machine learning artifact — including LLMs, diffusion models, classifiers, regressors, and reinforcement learning agents — used within an AI system.
High-Risk AI SystemAn AI system whose failure or misuse could cause significant harm to health, safety, fundamental rights, or critical infrastructure (aligned with EU AI Act Article 6).
Composite AI SystemAn AI system that orchestrates multiple models (potentially of different architectures) within a single workflow or product.
Agentic AIAI systems exhibiting autonomous behavior: planning, tool use, multi-step execution, and environmental interaction with limited or delayed human review.
HITLHuman-in-the-Loop: a human reviews and approves every AI output before it takes effect.
HOTLHuman-on-the-Loop: a human monitors AI operations and can intervene, but does not approve each individual output.
HOOTLHuman-out-of-the-Loop: AI operates autonomously with periodic governance review rather than real-time human oversight.

Executive Conclusion

This version turns the original ADG concept into a full enterprise AI security and responsible AI governance framework. It keeps the simplicity of ADOPT, DEFEND, and GOVERN, but adds the structure required to govern contemporary AI systems — across people, process, technology, deployment pattern, lifecycle, harm class, and regulatory environment.

This version was forged with senior AI, security, and governance leaders running production AI inside Fortune 500, Fortune Global 500, and Big Four firms — practitioners working from design through implementation across regulated and less-regulated sectors. It addresses eight major gap clusters identified through systematic review, and extends the framework to cover multi-agent systems, multi-modal architectures, shared responsibility, responsible AI, and measurable governance.

From a framework standpoint, this version is suitable as the basis for:

  • Consulting assessments and maturity reviews
  • Enterprise AI governance programs
  • Certification architecture and training design across all three ADG pillars
  • Board-facing AI security, responsible AI, and assurance discussions
  • Regulatory preparation and compliance gap analysis
  • Vendor AI due diligence and procurement governance
Living framework · Open call

Shape what comes next.

ADG is not a finished product. It is iteratively shaped by the practitioners who actually deploy AI in production — across Fortune 500, Fortune Global 500, and Big Four firms. Every comment, every red-team finding, every regulatory shift becomes the next version.

What we're tracking

EU AI Act, high-risk obligations now in effect.

EU regulation

Status: conformity assessments, post-market monitoring (Art. 72), and serious-incident reporting (Art. 73) live across the EU. ADG MC-1, MC-4, MC-8, and MC-9 map directly.

CSA STAR for AI, attestation pathway live since Oct 2025.

Attestation

What it means: the first auditable attestation regime for AI controls maps the CSA AI Controls Matrix (243 control objectives) against ISO 42001, NIST AI RMF, and EU AI Act. ADG composes underneath it.

Singapore IMDA, Agentic AI MGF released January 2026.

Standard

Why it matters: first state-backed framework with first-class agentic coverage. ADG's Multi-Agent Interop overlay aligns to the IMDA principles; AI Verify is the testing toolkit underneath.

OWASP Top 10 for Agentic Applications 2026.

Threat catalog

What changed: first-class agentic threats — goal hijack, tool misuse, identity abuse, multi-agent collusion. ADG's Agentic Hardening overlay (10.4) consumes this as input.

NIST AI 600-1 GenAI Profile in active use.

NIST update

Status: companion profile to the AI RMF for generative-AI risks. ADG's §11.2 crosswalk maps every Minimum Control to NIST RMF GOVERN / MAP / MEASURE / MANAGE.

MITRE ATLAS v5.4, agentic case studies expanded.

Threat intel

Why it matters: 84+ adversarial techniques with real-world AI incident case studies. ADG MC-8 (Runtime Monitoring) and MC-9 (Incident Response) cite ATLAS as the threat catalog input.

See how the pillars map to certification.

Each pillar has its own credential track and topic map.

View the Certification Pathway →