ADG | Adopt · Defend · Govern
AI Security Governance Framework · Enhanced Working Draft · April 2026
Why ADG
Enterprise AI is shipping into production faster than governance can absorb. Engineering teams are deploying agents that act on tools, consume retrieved context, run multi-step plans, and chain to other agents — often before the people accountable for risk have seen the system, let alone approved it. Boards are asking questions control departments cannot answer. Regulations are taking effect—the EU AI Act first, with others to follow. And the standards every organization has invested in — ISO/IEC 42001, NIST AI RMF, the EU AI Act itself — tell you what to think about, but not who decides, who builds, who breaks, who signs, or what evidence belongs in front of a regulator on Monday morning.
That is the gap ADG closes. ADG is not another standard. It is the operating model that sits underneath the standards you already have and makes them executable — written by a practitioner advisory board across financial services, healthcare, manufacturing, telecommunications, energy, and technology, in regulated and less-regulated jurisdictions across North America, Europe, and Asia-Pacific. Credentials and curricula are downstream of the framework, not the reason for it.
The architecture is three pillars — ADOPT (execute and deliver), DEFEND (secure and validate), and GOVERN (oversee, assure, decide) — that scale unchanged from the board to the engineer. The same three words frame a board paper, organize a release gate, label a red-team report, and structure an incident playbook. Beneath those pillars sit nine governance surfaces (the points where engineers instrument and attackers act); 12 Minimum Controls (MC-1 through MC-12), each with a named evidence artifact your auditor can hold; nine deployment overlays for the patterns AI actually ships in today — agentic orchestration, tools and Model Context Protocol (MCP), multi-agent interoperability, multi-modal and composite stacks, long-context architectures; three autonomy tiers (human in the loop [HITL], human on the loop [HOTL], human out of the loop [HOOTL]) tied directly to the controls; and a four-phase roadmap that takes an organization from inventory to continuous assurance in 24 months.
ADG is built for alignment, not competition. Every Minimum Control maps cleanly into NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE) and ISO/IEC 42001 Annex A — the framework's §11.2 crosswalk does it explicitly. MC-1 produces the AI inventory ISO 42001 A.6 demands and EU AI Act Art. 49 will register. MC-9 produces the post-market log Art. 73 inspectors will request. MC-11 produces the bias evidence Art. 10 requires. Organizations pursuing ISO/IEC 42001 certification or EU AI Act conformity use ADG to operationalize what those frameworks describe abstractly. The work is the same; ADG removes the translation layer.
ADG also goes where the standards do not. Agentic systems, MCP-connected tools, multi-agent interoperability, long-context architectures, and composite multi-modal stacks each carry an additive deployment overlay that composes with the same twelve Minimum Controls. Move from one copilot to a fleet of agents without rewriting a single control.
One element of ADG sits where peer frameworks generally do not: the AI Governance Council. Every framework tells you to govern AI. ADG tells you who breaks the tie when delivery and safety disagree — the Council resolves ADOPT-DEFEND tension, sets go/no-go thresholds, owns the exception register, and ties decision rights to MC-3 (Separation of Duties) and MC-10 (Periodic Governance Review). The mechanism, not the abstract requirement, is what is rarely named in peer frameworks — and it is where most production AI risk actually lives.
ADG is built for boards, CISOs and AI red teams, platform and AI engineers, risk and compliance, and procurement. Each audience reads a different path; the artifacts are the same. The framework was forged with senior AI, security, and governance leaders running production AI inside top Fortune 500, Fortune Global 500, and Big Four firms — including Salesforce, Microsoft, Citi, JPMorgan Chase, NTT DATA, KPMG, ServiceNow, BNP Paribas, Prudential, GE Healthcare, BASF, and Jio — the practitioners who own the failure modes this framework governs.
Who's reading this?
ADG is dense by design. Pick the role that matches you and jump to the path written for it. Each path is 4–5 sections out of 13 — you don't have to read everything.
Board & Executive
What we approve, what we own.
“Can we sign off this AI system, and what evidence will the auditor want?”
§2 Executive Summary · §4 Triad · §6 Harm Taxonomy · §11 Controls · §12 Regulatory
Security & AI Red Teams
What can break, how we defend.
“Where are the attack surfaces, and which controls fire when?”
§5 Surfaces · §6 Harm Taxonomy · §9 Lifecycle · §10 Overlays · §11 Controls
Engineering & Platform
How we build, what we ship.
“Which controls bind to my CI/CD, my MCP servers, my prompt repo?”
§4 Triad · §5 Surfaces · §8 People/Process/Tech · §9 Lifecycle · §10 Overlays
Risk & Compliance
What we must prove.
“How does this map to ISO 42001, NIST AI RMF, EU AI Act?”
§6 Harm Taxonomy · §7 Shared Responsibility · §12 Regulatory · Appendix A
1.Background
1.1 Origin and Positioning
ADG began with a mission at EC-Council: the AI governance space was fragmenting into point standards, vendor playbooks, and academic frameworks — none of which gave enterprise boards and engineering teams a single, practitioner-tested operating model for deploying AI safely at scale. EC-Council set out to build that missing operating model: a framework built around three enduring functions—ADOPT, DEFEND, and GOVERN—that scales from the board to the engineer.
To avoid building in a vacuum, EC-Council convened an Advisory Board of practitioners from mature enterprises that have actually deployed AI in production. The initial draft was circulated to senior AI, security, and governance leaders across global organizations in financial services, technology, manufacturing, healthcare, telecommunications, energy, and consulting — covering both regulated and less-regulated sectors, and spanning North America, Europe, and Asia-Pacific.
Advisory Board Impact
ADG was not drafted in a conference room. It was forged with the senior AI, security, and governance leaders running production AI inside Fortune 500, Fortune Global 500, and Big Four firms — across regulated and less-regulated sectors, from design through implementation.
Their input drove eight structural enhancement clusters: an expanded harm taxonomy with Responsible AI integration, coverage beyond LLMs (diffusion, multi-modal, composite systems), a shared responsibility model for vendor/SaaS AI, deeper strategic treatment of the GOVERN pillar, a measurable metrics & evidence framework, multi-agent interoperability governance, explicit regulatory mapping (EU AI Act, NIST AI RMF, ISO 42001), and post-deployment continuous governance.
Framework Leadership

Jay Bavisi
Chairman & CEO
EC-Council Group
Karthik S.
Framework Architect & Lead Author · Practice Head, SecureAI
EC-Council Global ServicesThank you to the Advisory Board
The practitioners below gave their time, scrutiny, and hard-won experience to review ADG. Their comments, corrections, and counterpoints are the reason this framework is field-tested rather than aspirational.
Adam Spearing
VP of AI GTM EMEA
ServiceNow
Andrei Son
Head of AI Transformation
AUMOVIO
Anish Mitra
Director
KPMG
Anita Lacea
Head of AI Transformation, Azure Hardware Infrastructure
Microsoft
Dinesh Bhogle
Head of AI/ML Platform
Black & Veatch
Dr. Sayed Peerzade
EVP, Cloud, AI & Government Initiatives
Jio
Edoardo Tealdi
Executive Head of AI Transformation, Business Engagement and Growth Units
NTT DATA, Inc.
Kathy Baxter
VP/Principal Architect, Responsible AI & Tech
Salesforce
Lewis V. Adams
VP, Enterprise AI & Capital Productivity Transformation
Citi
Lily Rachmawati
Director, Head of Applied AI
BNP Paribas
Malik Hussain
AI Enablement Lead, Data & AI Academy
BASF
Mark Ritcey
VP, AI & Automation Delivery
Latent Bridge
Naveen Upadhyay
VP, AI/ML Product Management – Machine Learning & Intelligence Operations
JPMorgan Chase & Co.
Oscar Jarabo
Global Head of AI Product & Strategy
TKE
Pavan Kristipati
Head of AI Engineering & Transformation | Enterprise AI Adoption, Governance & Platform
Huntington Bank
Raghunandan Mishra
AI & Data Engineering Leader
Raji Bhimireddy
VP Cloud, AI, Architecture, FinOps & Business Value
Prudential
Sanjoy K. Saha
Head of AI Portfolio and Governance & Chief of Staff CDAO
GE Healthcare
ShanShan Pa
Global Head of AI & Data Governance
GlobalLogic
Sophia Katrenko
VP of AI/ML
EcoVadis
Sruthi Pakanati
Head of AI & Data Transformation, National Quality & Risk
Deloitte Australia
Sudarson Roy Pratihar
Founder and Principal
A2IQ
Yashwinder Chhikara
Sr. VP, AI, Analytics, and Product Management
iSON Xperiences
This version is the result — the iterative output of that collaboration. ADG is not a one-and-done document. It is a living framework, designed to be enhanced as AI deployment patterns evolve and as new practitioners join the conversation.
1.2 Framework Purpose: The RE³ Trust Model
ADG is purpose-built to operationalize four non-negotiable properties of trustworthy enterprise AI — captured in the RE³ Trust Model: Responsible, Ethical, Efficient, Explainable AI.
Responsible AI
Clear Accountability, Every Layer
Every AI action traces back to a human decision-maker. Delivered by: MC-1 (AI System Inventory), MC-3 (Separation of Duties), Agent Authority Statements, Shared Responsibility Model (§7), and the AI Governance Council escalation path.
Ethical AI
Fairness, Safety, and Human Oversight
Protection from bias, manipulation, and harm across four classes (Technical, Societal, Operational, Systemic). Delivered by: the Four-Class Harm Taxonomy, Seven Responsible AI (RAI) Principles embedded in every surface, MC-11 (Fairness & Bias Evaluation), the Safety Layer surface, and Autonomy Tier controls scaled to risk.
Efficient AI
Reliable Delivery at Enterprise Scale
Governance that enables velocity rather than slowing it down. Delivered by: the four-phase implementation roadmap, Tier 1 — Control Effectiveness Metrics, the LLMOps Overlay for cost/performance monitoring, reusable Operating Artifacts, and one unified control set spanning Homegrown, API, and SaaS deployments.
Explainable AI
Traceable, Replayable, Defensible
Every output can be justified to a regulator, a board, or a customer. Delivered by: the Telemetry surface, MC-6 (Context Policy with provenance tracking), MC-7 (Tool/MCP audit logging), MC-8 (Runtime Monitoring), and MC-9 (Incident Response with forensic replay).
1.3 Core Thesis
Answer capsule
Why do AI systems need a different governance framework?
Traditional cybersecurity and software governance assumes deterministic execution, fixed inputs, and visible logic. AI breaks all three: it generates novel behavior, acts through external tools, consumes dynamic context, and shifts with every model update. ADG closes that gap through role separation, surface-based control ownership, deployment-pattern overlays, lifecycle governance, and a structured harm taxonomy.
Scope Coverage — AI System Architecture with Agentic Hardening
Every class of AI system ADG covers, and the agentic harness wrapped around them. Hover any segment for what it includes.
ADG governs all layers
1.4 Scope and System Coverage
ADG governs all AI systems as defined by the OECD AI Policy Observatory and the EU AI Act, including LLMs and transformer-based generative AI, diffusion models, multi-modal systems, classical machine learning, composite AI systems that orchestrate multiple model types, and emerging architectures such as world models and neuromorphic systems. The governance surfaces, overlays, and controls in this framework are architecture-neutral by design — not limited to LLM-centric systems.
1.5 Distinction: Standards vs. Regulations
Answer capsule
Is ISO/IEC 42001 a standard or a regulation?
ISO/IEC 42001 is a voluntary standard you certify against, not a law. The EU AI Act is a regulation: legally binding, with fines up to 7% of global annual turnover for prohibited AI practices. NIST AI RMF and the OWASP Top 10 are voluntary frameworks and guidance. ADG maps both kinds, so meeting the standards builds the evidence regulations demand.
2.Executive Summary
Answer capsule
What is the ADG framework?
ADG (Adopt, Defend, Govern) is EC-Council Global Services' enterprise framework for AI security and responsible AI governance. Three pillars form a board-to-engineering operating model: Adopt delivers AI capabilities, Defend secures them against four harm classes, and Govern oversees, assures, and resolves tensions. ADG maps to NIST AI RMF and ISO/IEC 42001.
Framework Architecture — How the Layers Connect
Nine governance surfaces, three pillars, 12 minimum controls, joined only where the framework publishes a link.
9 surfaces · 3 pillars · 12 controls. Surfaces join a pillar through their published ADG alignment; controls through the pillar recorded in the §11.2 crosswalk. No surface-to-control edge is drawn — the framework does not publish one.
Key framework components
Pillars — The ADG Triad
Harm Classes — Four-Class Harm Taxonomy
RAI Principles — Responsible AI Principles
Governance Surfaces — What Must Be Governed
Foundational Principles — The Durable Standards
Minimum Controls — MC-1 through MC-12
Deployment Overlays — Pattern-Specific Controls
Autonomy Tiers — HITL / HOTL / HOOTL
Implementation Phases — Roadmap to Maturity
Layer-by-Layer Reference
Concrete definitions and one example per element — the quick-reference key for the rest of the document.
3 Pillars
| Pillar | Definition | Example |
|---|---|---|
| ADOPT | Execute and deliver AI capabilities. Owns selection, integration, deployment, operations. | An LLMOps team rolling out a customer-support copilot to production. |
| DEFEND | Secure and validate. Owns adversarial testing, guardrails, runtime detection, fairness evaluation, AI incident response. | A red team running prompt-injection scenarios against the copilot before launch. |
| GOVERN | Oversee, assure, decide. Owns policy, decision rights, regulatory alignment, board accountability. | An AI Governance Council approving the copilot for high-risk customer interactions and setting escalation thresholds. |
9 Governance Surfaces
| Surface | Definition |
|---|---|
| Model | Foundation models, fine-tuned models, adapters, routers, versions, diffusion models, composite model chains |
| Prompt | System prompts, templates, policies, agent instructions, prompt libraries, multi-modal input validation |
| Context | Retrieval sources, session state, memory, hidden context, user metadata, cross-session data |
| Tools | APIs, plugins, actions, code execution, file access, transactional endpoints, MCP capabilities |
| Orchestration | Planners, workflow graphs, retry logic, multi-agent flows, model routing, agent-to-agent communication |
| Identity | Credentials, service accounts, delegated authority, secrets, trust relationships, agent identity |
| Safety Layer | Guardrails, policy engines, semantic filters, classifiers, circuit breakers, harm detectors |
| Telemetry | Logs, traces, evaluations, replay data, alerts, governance evidence, fairness metrics |
| Learning Loop | Pre-training sources, post-training alignment, feedback loops, retraining updates, RLHF data |
12 Minimum Controls
| Control | Definition | Example |
|---|---|---|
| MC-1 | Maintain an inventory of all AI systems with an accountable owner, risk classification, and autonomy tier. | Published inventory, reviewed quarterly, with named owner per system. |
| MC-2 | Classify each AI system by data sensitivity, autonomy, external exposure, harm potential, and business criticality. | Documented classification per system using a standardized risk taxonomy. |
| MC-3 | Separate deployment ownership, security validation, and approval authority across ADOPT, DEFEND, and GOVERN. | Responsible, accountable, consulted, and informed (RACI) matrix per AI system; no single function holding all three roles. |
| MC-4 | Complete quality, safety, security, fairness, and failure-mode testing before any production deployment. | Signed evaluation report covering all four harm classes before go-live. |
| MC-5 | Manage changes to prompts, tools, models, and retrieval sources through a governed change process. | Change log with approval records; no uncontrolled production changes. |
| MC-6 | Define provenance, retention, access restrictions, and trust ordering for all context inputs. | Published context policy per system; annual review. |
| MC-7 | Maintain a register of all tools and MCP capabilities with trust tiering and invocation controls. | Published register with per-tool risk assessment and approval status. |
| MC-8 | Monitor for abuse, drift, data leakage, unsafe actions, bias emergence, and configuration drift in production. | Active monitoring with defined alert thresholds and response SLAs. |
| MC-9 | Maintain AI-specific incident response procedures with replayable evidence capture. | Documented playbook; at least one tabletop exercise per year. |
| MC-10 | Conduct governance reviews with exception handling and board reporting for high-risk systems. | Review records with findings, decisions, and exception dispositions. |
| MC-11 | Evaluate AI systems for discriminatory outcomes using representative test data and established fairness metrics. | Fairness evaluation report; re-evaluation after model or data changes. |
| MC-12 | For vendor or SaaS AI, document accountability boundaries, contractual obligations, and assurance requirements. | Signed responsibility matrix; vendor due diligence records. |
4 Harm Classes
| Class | Definition | Example |
|---|---|---|
| Technical | Security, reliability, and system integrity failures. | Prompt injection causing the copilot to leak its system prompt or run unintended tool calls. |
| Societal | Bias, discrimination, fairness, and human-rights impacts. | A loan-decision agent denying credit at a higher rate to one demographic group. |
| Operational | Reliability, accuracy, and business-impact failures. | The copilot hallucinating a refund policy that does not exist, leading to disputes. |
| Systemic | Emergent risks from AI-to-AI interaction and scaled deployment. | Two negotiation agents from different vendors colluding on an unfavorable deal because their guardrails do not catch joint behavior. |
4 Industry Threat Catalogs
ADG does not invent its own threat list — it consumes the four canonical industry catalogs as input and maps each threat into the Minimum Control Set and the deployment overlays.
| Catalog | What it provides | How ADG consumes it |
|---|---|---|
| MITRE ATT&CK | Enterprise adversary techniques abused via or against AI-enabled systems — phishing, credential theft, lateral movement, exfiltration, persistence. | MC-8 (Runtime Monitoring) detection rules, MC-9 (Incident Response) playbooks, and red-team scenarios in MC-4. |
| MITRE ATLAS | 84+ adversarial ML/AI techniques and real-world case studies — model evasion, ML supply chain, model extraction, prompt injection at the model layer. | MC-4 pre-production adversarial eval suites, MC-8 detection signatures, MC-9 forensic replay test cases. |
| OWASP Top 10 for LLM (2025) | LLM01 Prompt Injection, LLM02 Sensitive Info Disclosure, LLM03 Supply Chain, LLM04 Data & Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector & Embedding Weaknesses, LLM09 Misinformation, LLM10 Unbounded Consumption. | MC-4 evaluation checklist, MC-6 (Context Policy) for LLM03/04/08, MC-8 runtime guardrails, MC-11 fairness checks for LLM09. |
| OWASP Top 10 for Agentic (2026) | T1 Memory Poisoning, T2 Tool Misuse, T3 Privilege Compromise, T4 Resource Overload, T5 Cascading Hallucinations, T6 Intent Breaking, T7 Misaligned/Deceptive Behavior, T8 Repudiation, T9 Identity Spoofing, T10 HITL Overwhelm. | Agentic Hardening overlay (§10.4) directly. MC-7 (Tool & MCP Register), MC-8 (Runtime Monitoring), MC-9 (Incident Response). |
9 Deployment Pattern Overlays
| Overlay | Definition | Example |
|---|---|---|
| LLMOps | Versioning, evaluation, release management, rollback, cost control, performance monitoring for LLM-based services. | A production RAG chatbot with rollback, eval suite, per-token cost tracking, and a release gate. |
| Agentic Orchestration | The planner / loop layer of a single agent — multi-step reasoning, retries, subtask decomposition, stop conditions. | An agent that decomposes "book my trip" into flights → hotel → calendar with retry budgets. |
| Agent | The agent as a class of system — business mission, action boundaries, liability model, segregation of duties. | A travel-booking agent authorized to spend up to USD 2,500 per booking on behalf of the user. |
| Agentic Hardening | Defensive controls bolted onto agents — authority bounds, action isolation, kill switches, forensic replay, semantic firewalls. | Dry-run mode for irreversible actions with human approval required before the booking is committed. |
| Tools & MCP | Tool discovery, capability registration, trust tiering, per-invocation policy for tools and MCP servers. | An MCP server registered as "trust tier 2" — read-only access to corporate wiki, no write actions allowed. |
| Context & Long-Window | Session history, retrieved enterprise knowledge, persistent memory, multi-turn poisoning resistance. | A copilot with persistent memory that flags conflicting facts injected mid-conversation. |
| Pre / Post-training | Model provenance, fine-tuning, alignment, RLHF data, retraining governance. | A LoRA adapter trained on internal docs — training data licensed, evaluated for leakage, version-controlled. |
| Multi-Agent Interop | Emergent risks when multiple agents interact — agent-to-agent trust, value alignment, collusion detection, cascading failure prevention. | A purchasing agent talking to a vendor's quoting agent, with circuit breakers if they loop or agree on out-of-policy terms. |
| Multi-Modal / Composite | Cross-model risks when LLM + diffusion + classifier + retrieval combine in one product. | An assistant that takes a screenshot, classifies it, retrieves docs, and generates a response — system-level eval required, not per-model. |
3 Autonomy Tiers
| Tier | Definition | Example |
|---|---|---|
| HITL — Assistive | AI recommends or drafts; a human approves every output before it takes effect. | A copilot that drafts emails for the user to review and send. |
| HOTL — Conditional | AI acts within pre-approved limits; a human monitors and can intervene. | A trading agent executing within position limits, with humans monitoring exposure dashboards. |
| HOOTL — Autonomous | AI executes multi-step goals with limited or delayed human review. | An overnight data-pipeline agent that processes batches and reports results in the morning. |
4-Phase Roadmap
| Phase | Definition | Example |
|---|---|---|
| Foundation (0–3 months) | Inventory, owners, ADG roles, criticality classification, AI Governance Council established. | Quarter 1: publish AI inventory, name owners, charter the Governance Council. Controls: MC-1, MC-2, MC-3. |
| Control Deployment (3–9 months) | Release gates, change control, context policies, monitoring, adversarial testing, fairness evals, vendor due diligence. | Quarter 2–3: implement MC-4 through MC-9 plus MC-11/MC-12 across all high-risk systems. |
| Agentic Readiness (9–15 months) | Authority statements, tool trust tiering, MCP governance, circuit breakers, multi-agent governance, forensic replay. | Quarter 4–5: agentic hardening overlay deployed for all production agents. |
| Maturity (15–24 months) | Continuous evaluation, persistent adversarial monitoring, drift governance, RAI measurement, board-level reporting. | Quarter 6–8: automated weekly red-team runs, quarterly board AI risk review, formal assurance review. |
3.Document Usage
This section provides guidance on how to read, apply, and implement the ADG framework.
3.1 Target Audience
| Audience | Reading path |
|---|---|
| Board & Executive Sponsors | §2 Executive Summary · §4 ADG Triad & Operating Model · §6 Harm Taxonomy & RAI · §11 Controls & Board-Level Indicators · §12 Regulatory & Roadmap |
| Security & AI Red Teams | §5 Governance Surfaces · §6 Harm Taxonomy & RAI · §9 Lifecycle Governance · §10 Deployment Overlays · §11 Controls & Measurement |
| Engineering & Platform Teams | §4 ADG Triad & Operating Model · §5 Governance Surfaces · §8 People, Process, Tech & Data · §9 Lifecycle Governance · §10 Deployment Overlays |
| Risk & Compliance | §6 Harm Taxonomy & RAI · §7 Shared Responsibility · §12 Regulatory & Roadmap · Appendix A Definitions |
| All Stakeholders | §1 Background · §2 Executive Summary · §3 Document Usage |
3.2 Foundational Principles
ADG is built on nine foundational principles — durable standards that apply across industries, deployment patterns, and regulatory regimes.
01
Separation of Powers
Independent validation is mandatory
02
Authority Must Be Explicit
Implicit authority is a control gap
03
Context Is Attack Surface
Governed assets need provenance & access control
04
Tool Use Is Highest Risk
Risk escalates from output to real-world action
05
Graduated Oversight
Higher autonomy needs stronger controls
06
Lifecycle Governance
No single gate is sufficient
07
Evidence Is Mandatory
If it can't be evidenced, it can't be relied upon
08
RAI Embedded, Not Appended
Structural requirements across all three pillars
09
Shared Responsibility
Accountability must be documented & enforced
4.The ADG Triad and Operating Model
Answer capsule
What are the three pillars of the ADG framework and who owns each?
ADG has three pillars. Adopt executes and delivers business value safely, owned by AI product owners, ML and prompt engineers, and DevSecOps. Defend secures and validates by preventing harmful behavior, owned by Red Team and Security Engineers. Govern oversees and decides, justifying and approving AI use at board level via the chief AI officer (CAIO), legal, and risk officers.
Operating Model — Five Dimensions, Three Pillars
What each pillar asks, decides and owns. Hover a cell for that pillar's answer.
Color identifies the pillar — cells are not scored, because the operating model ranks nothing.
Foundational Principles — Nine Durable Standards
Equal-sized tiles on purpose: the framework ranks none of these above another. Hover for each principle's standard.
Execute and Deliver
“Deliver business value safely”
- Primary question
- Can we deploy it effectively?
- Decision focus
- Capability, performance, delivery, reliability
- Stakeholders
- AI Product Owner · ML Engineers · Prompt Engineers · DevSecOps · App Architects · Enterprise Architects
- Core outputs
- Deployed service · Runbooks · Baselines · Releases
- Success measure
- Value delivery with controlled operations
- Escalation
- Escalates blockers to GOVERN
Secure and Validate
“Identify, prevent, detect harmful behavior”
- Primary question
- Can it be abused, fail dangerously, or cause harm?
- Decision focus
- Security, resilience, fairness, abuse resistance, containment
- Stakeholders
- AI Red Team · Security Engineers · Bias Auditors · Incident Response · Guardrail Engineers · Detection Engineers
- Core outputs
- Test results & detections · Guardrails · Fairness evaluations · Incident playbooks
- Success measure
- Risk reduced across all four harm classes
- Escalation
- Escalates unresolved risks to GOVERN
Oversee, Assure, and Decide
“Justify, approve, evidence AI use at board level”
- Primary question
- Should we approve it, under what conditions, and at what risk?
- Decision focus
- Risk appetite, legality, accountability, ethics, oversight
- Stakeholders
- CAIO / Ethics Lead · Legal & Compliance · Risk Officers · Board / C-Suite · Privacy Counsel · Compliance Lead
- Core outputs
- Policies, approvals, risk thresholds · Exceptions & evidence · Board reports
- Success measure
- Defensible use with auditable, measurable governance
- Escalation
- Resolves ADOPT-DEFEND tension; defines go/no-go and exception policy
Strategic functions
- Define organizational AI risk appetite
- Establish decision rights and escalation paths
- Own the AI Governance Council charter
- Define board-level reporting requirements
- Set investment justification criteria
- Maintain regulatory mapping
4.4 Operating Model
ADG uses a simple rule: Adopt builds and operates, Defend breaks and protects, Govern authorizes and oversees.
| Dimension | Adopt | Defend | Govern |
|---|---|---|---|
| Primary question | Can we deploy it effectively? | Can it be abused, fail dangerously, or cause harm? | Should we approve it, under what conditions, and at what risk? |
| Decision focus | Capability, performance, delivery, reliability | Security, resilience, fairness, abuse resistance, containment | Risk appetite, legality, accountability, ethics, oversight |
| Core outputs | Deployed service, runbooks, baselines, releases | Test results, detections, guardrails, fairness evaluations, incident playbooks | Policies, approvals, risk thresholds, exceptions, evidence, board reports |
| Success measure | Value delivery with controlled operations | Risk reduced across all four harm classes | Defensible use with auditable, measurable governance |
| Tension resolution | Escalates blockers to GOVERN | Escalates unresolved risks to GOVERN | Resolves ADOPT-DEFEND tension; defines go/no-go and exception policy |
5.Governance Surfaces
Answer capsule
What are the governance surfaces in the ADG framework for securing an AI system?
ADG organizes governance into nine surfaces that define what must be governed regardless of model vendor, architecture, or deployment pattern. Along the request flow they include Prompt, Context, Model, Tools, and Orchestration, each marked with the responsible Adopt, Defend, or Govern pillars. Input and output are not governed surfaces themselves.
Governance Surfaces — Request Flow
The nine surfaces in the order a request crosses them, colored by the pillar that owns each. Hover for scope and control objective.
| Surface | Scope | ADG Alignment | Control Objective |
|---|---|---|---|
| Model | Foundation models, fine-tuned models, adapters, routers, versions, diffusion models, composite model chains | A+G | Use only approved models with known risk posture, provenance, and change traceability |
| Prompt | System prompts, templates, policies, agent instructions, prompt libraries, multi-modal input validation | A+D | Prevent unmanaged behavior changes and unsafe instruction patterns |
| Context | Retrieval sources, session state, memory, hidden context, user metadata, cross-session data | G+D | Prevent poisoning, leakage, cross-session contamination, and privacy violations |
| Tools | APIs, plugins, actions, code execution, file access, transactional endpoints, MCP capabilities | D | Enforce least privilege, strong validation, sandboxing, and full audit logging |
| Orchestration | Planners, workflow graphs, retry logic, multi-agent flows, model routing, agent-to-agent communication | A+D | Bound agent behavior, prevent cascading failures, ensure deterministic control |
| Identity | Credentials, service accounts, delegated authority, secrets, trust relationships, agent identity | G+D | Prevent privilege misuse, preserve accountability, trace agent actions to human authority |
| Safety Layer | Guardrails, policy engines, semantic filters, classifiers, circuit breakers, harm detectors | D | Block unsafe content, unfair outputs, and unauthorized actions before impact |
| Telemetry | Logs, traces, evaluations, replay data, alerts, governance evidence, fairness metrics | D+G | Make behavior observable, reviewable, provable, and measurable |
| Learning Loop | Pre-training sources, post-training alignment, feedback loops, retraining updates, RLHF data | G+A | Control data provenance, drift, alignment stability, and undocumented behavior change |
Where ADG meets MITRE and OWASP
The nine surfaces above describe what must be governed. The four industry threat catalogs describe what attackers do. ADG consumes them as input — every surface inherits its detection rules, eval scenarios, and runtime guardrails from these sources, then maps the resulting controls to NIST AI RMF and ISO/IEC 42001.
6.Harm Taxonomy and Responsible AI Integration
Answer capsule
What harm taxonomy does the ADG framework use to govern AI risks beyond security?
ADG uses a four-class harm taxonomy covering Technical, Societal, Operational, and Systemic harms, paired with seven Responsible AI principles. The classes map into every governance surface, lifecycle stage, and deployment overlay, and are plotted by detection difficulty and impact scope so governance addresses attacks, bias, reliability, and emergent multi-agent risk.
Responsible AI Principles — Seven Embedded Standards
The seven principles ADG embeds alongside its harm classes. Equal-sized tiles: the framework ranks none above another.
Harm Classification
Four harm classes and the harm types inside each. Hover a segment to see the class definition and its detection/scope quadrant.
Hover a class for its definition and harm types.
6.1 Harm Classification
The four harm classes plotted by detection difficulty and impact scope. Each carries the threats it covers, the pillars that own it, and the Minimum Controls that detect it.
Operational — Easy detect · Individual scope
Reliability, accuracy, business-impact failures
Owned by: ADOPT, DEFEND · Detected by: MC-4, MC-5, MC-8
Technical — Easy detect · Systemic scope
Security, integrity, system reliability failures
Owned by: DEFEND · Detected by: MC-7, MC-8, MC-9
Societal — Hard detect · Individual scope
Bias, discrimination, human-rights impacts
Owned by: GOVERN, DEFEND · Detected by: MC-2, MC-10, MC-11
Systemic — Hard detect · Systemic scope
Emergent risk from AI-to-AI interaction
Owned by: GOVERN, DEFEND · Detected by: MC-8, MC-9, MC-10
6.2 Responsible AI Principles
Every governance surface must account for seven responsible AI dimensions, embedded across all three pillars rather than appended as a separate track.
Fairness & Non-Discrimination
Outputs must not disadvantage groups
Transparency & Explainability
Explainable to its risk tier
Privacy & Data Protection
Minimize. Comply with data law
Accountability
Operator to executive sponsor
Human Oversight
Scaled to autonomy and harm potential
Robustness & Safety
Tested under adversarial conditions
Sustainability & Well-Being
Environmental & societal impact
Integration rule: Responsible AI is not a separate track. It is embedded into every ADG pillar — ADOPT, DEFEND, and GOVERN — and must be reflected in all certification curricula, operating artifacts, and governance reviews.
8.People, Process, Technology, and Data
Answer capsule
What roles and process steps does ADG define across the People and Process layers?
ADG requires explicit capability ownership across People, Process, Technology, and Data layers. The People layer assigns dedicated roles to Adopt, Defend, and Govern, plus a cross-functional AI Governance Council for escalation. The Process layer formalizes a nine-step backbone spanning the three pillars, from inventory and deployment gates to board reporting.
Process Backbone — Nine Steps Across Three Pillars
The governance process end to end, with each step colored by the pillar accountable for it.
8.1 People Layer
ADOPT roles
DEFEND roles
GOVERN roles
AI Governance Council
8.2 Process Layer — the Nine-Step Backbone
8.3 Technology Layer
- Model gateway and routing layer
- Retrieval, memory, and context management layer
- Tool registry and MCP trust layer
- Policy engine, guardrail layer, and harm detection layer
- Runtime telemetry, replay, and fairness measurement layer
- Training, tuning, and evaluation pipeline layer
- Input validation and sanitization layer (covering prompts, RAG inputs, and multi-modal inputs)
8.4 Data Layer
Traditional enterprise data architecture separates data into distinct tiers — structured databases, warehouses, lakes, file stores, and APIs. AI systems fundamentally disrupt this separation: an agent consuming enterprise data through retrieval pipelines, MCP connections, or tool invocations does not distinguish a SQL record from a Slack thread — all of it collapses into a single text-token consumption surface.
Access control at the storage layer alone is no longer sufficient. Organizations must govern the full pipeline from source data through retrieval, embedding, context assembly, and AI consumption — across four dimensions:
8.4.1 Data People
- Data Stewards for AI: extending traditional data stewardship to govern the full text-based data surface that AI systems can access
- AI Data Engineers: bridging data engineering and AI operations, responsible for RAG indexing, embedding generation, knowledge base curation
- Context Architects: designing what data flows into AI context windows, in what priority order, with what trust ranking
- Knowledge Base Curators: responsible for freshness, accuracy, deduplication, and retirement of enterprise knowledge assets
8.4.2 Data Process
- AI-aware data classification: extending beyond storage-tier access control to include AI-readability rules
- Provenance tracking across the text pipeline: maintaining a verifiable chain from any AI output back through the retrieval step to the source document
- Cross-source inference governance: policies governing when AI systems may combine information from multiple data sources
- Text-based policy management: AI system configurations governed as controlled documents with versioning, approval workflows, and rollback
- Knowledge base lifecycle management: content ingestion, quality validation, freshness review, conflict resolution, deduplication, and retirement
- Data minimization for AI: ensuring context windows contain only data necessary for the task
- Consent and lawful basis tracking: maintaining records of lawful basis for processing each data category
8.4.3 Data Technology
- Vector stores and embedding infrastructure: governed data infrastructure requiring access controls, encryption, backup and recovery
- Enterprise knowledge graphs: structured representations enabling context assembly with awareness of entity relationships
- Context assembly engines: systems that select, rank, truncate, filter, and compose text from multiple sources
- MCP and tool registries as data access layers: governed as data access infrastructure with the same rigor as database connections
- Text-based configuration stores: GitOps-style repositories for all AI system configurations
- Data lineage and output attribution: technology to trace which source documents contributed to a specific AI output
- Embedding pipeline governance: validation testing, drift monitoring, and re-indexing governance
8.4.4 Data × Surface Intersection
- Model: Training data provenance, fine-tuning data governance, model card data documentation
- Prompt: System prompt versioning and change control as governed text artifacts
- Context: Retrieval source classification, context assembly governance, cross-source inference controls
- Tools: MCP servers as data access gateways; tool-retrieved data classified and logged
- Orchestration: Data flow governance across multi-step agent workflows; inter-agent data sharing rules
- Identity: Data access tied to agent identity and delegated authority; no implicit data access
- Safety Layer: Guardrail configurations as governed text; data-driven harm detection models governed as data assets
- Telemetry: Logs and traces as sensitive data requiring retention, redaction, and access governance
- Learning Loop: Feedback data, RLHF inputs, and retraining datasets governed as controlled data assets with provenance
9.Lifecycle Governance
Answer capsule
What are the lifecycle stages in the ADG AI governance framework?
ADG applies controls across six lifecycle stages: Pre-training/Sourcing, Post-training/Alignment, Build/Integrate, Deploy/Authorize, Run/Monitor, and Retire/Learn. The lifecycle is explicitly circular, so lessons from Retire/Learn feed back into sourcing decisions. Each stage assigns distinct Adopt, Defend, and Govern responsibilities.
Lifecycle Governance — Six-Stage Circular Flow
Drawn as a ring because the framework publishes it as one: governance returns to sourcing rather than ending at deployment. Hover a stage for its Adopt, Defend and Govern responsibilities.
Stage 6 returns to stage 1 — governance does not end at deployment.
| Stage | Adopt | Defend | Govern |
|---|---|---|---|
| Pre-training / Sourcing | Select suppliers & datasets fit for purpose; assess training data for representation and bias | Assess provenance abuse, contamination risk, and training data bias | Approve sourcing constraints, licensing, jurisdictional requirements, and data ethics |
| Post-training / Alignment | Tune for use-case quality and operational fit | Test for regressions, bypasses, safety degradation, and fairness drift | Review alignment objectives, documentation sufficiency, and RAI criteria |
| Build / Integrate | Assemble workflows, prompts, tools, retrieval; integrate DevSecOps controls | Validate interfaces, secrets, attack surfaces, and input validation coverage | Classify use case, approve controls, define oversight requirements and risk tier |
| Deploy / Authorize | Release through controlled change process with rollback readiness | Confirm pre-production testing, monitoring readiness, and fairness evaluation | Grant formal deployment approval or exception with documented conditions |
| Run / Monitor | Operate service, maintain SLAs, track quality and cost | Detect abuse, failures, drift, unsafe actions, and bias emergence; continuous red teaming | Review incidents, exceptions, compliance posture, and configuration drift |
| Retire / Learn | Decommission services and roll forward lessons | Preserve evidence, investigate failures, validate closure | Update policy, records, accountability decisions; feed lessons into sourcing cycle |
9.1 Post-Deployment Continuous Governance
- Configuration drift detection: verify that the system in production matches what was approved (models, prompts, tools, context sources)
- Usage authorization monitoring: confirm that approved users are using the system for approved purposes within approved boundaries
- Feature and capability change governance: new model versions, prompt updates, tool additions, and retrieval source changes post-deployment must go through change control
- Continuous automated evaluation: scheduled adversarial testing, fairness benchmarking, and accuracy regression testing on production systems
- Ongoing governance of the product roadmap: feature additions to deployed AI systems require re-evaluation against the original risk classification and approval conditions
10.Deployment Pattern Overlays
Answer capsule
How does ADG decide which governance overlays apply to a given AI deployment?
ADG adds deployment-specific overlays so governance matches the actual architecture, and overlays are additive: you select all that apply. An applicability matrix maps overlay families across deployment classes (Homegrown, FM API, SaaS) and autonomy tiers (HITL, HOTL, HOOTL), marking each Required, Recommended, Optional, or Not applicable.
Overlay Applicability
Which overlays are Required, Recommended, Optional or N/A for each deployment class and autonomy tier.
| Overlay | Homegrown | FM API | SaaS | HITL | HOTL | HOOTL |
|---|---|---|---|---|---|---|
| LLMOps | Required | Required | Recommended | Required | Required | Required |
| Agentic Orchestration | Recommended | Recommended | N/A | Optional | Required | Required |
| Agent | Recommended | Recommended | Optional | Optional | Required | Required |
| Agentic Hardening | Required | Required | Recommended | Optional | Required | Required |
| Tools & MCP | Recommended | Required | Optional | Required | Required | Required |
| Context & Long-Window | Required | Required | Recommended | Required | Required | Required |
| Pre/Post-training | Required | Optional | N/A | Recommended | Recommended | Required |
| Multi-Agent Interop | Recommended | Recommended | Optional | Optional | Recommended | Required |
| Multi-Modal / Composite | Recommended | Recommended | Optional | Optional | Recommended | Required |
Overlays are additive — select all that apply.
10.1
LLMOps Overlay
Versioning, evaluation, release management, rollback, cost control, and performance monitoring for LLM-based services.
- Adopt
- Structures model onboarding, baseline evaluation, config versioning, rollback readiness, and operational SLOs
- Defend
- Structures adversarial testing, abuse simulation, leakage testing, denial-of-wallet controls, monitoring coverage, and bias evaluation
- Govern
- Structures use-case approval, vendor due diligence, deployment thresholds, exception management, and LLMOps cost governance
10.2
Agentic Orchestration Overlay
Planners, loops, retries, multi-step reasoning, subtask decomposition, and multi-agent coordination.
- Adopt
- Defines mission scope, stop conditions, retry budgets, and workflow boundaries
- Defend
- Validates loop abuse resistance, prompt chaining resistance, recursion limits, and kill-switch behavior
- Govern
- Approves autonomy tier, escalation path, and legal accountability for delegated decisions
10.3
Agent Overlay
AI systems that act on behalf of a user, team, or enterprise process rather than merely generating content.
- Adopt
- Defines business mission, action boundaries, and acceptable failure modes
- Defend
- Tests transaction safety, impersonation resistance, and unsafe action prevention
- Govern
- Defines liability model, mandatory approvals, record retention, and segregation-of-duty requirements
10.5
Tools and MCP Overlay
Tool discovery, capability registration, trust mediation, and policy-controlled invocation of tools and context providers.
- Adopt
- Justifies why each tool or MCP capability is needed and what business task boundary it serves
- Defend
- Enforces authentication, authorization, parameter validation, rate limiting, sandboxing, and audit logging
- Govern
- Maintains approval policy, third-party assurance criteria, trust tiers, and data-sharing restrictions
10.6
Context and Long-Window Overlay
Session history, retrieved enterprise knowledge, hidden orchestration instructions, persistent memory, and context overflow handling.
- Adopt
- Defines the minimum context required for task quality
- Defend
- Tests for context poisoning, leakage, overflow abuse, cross-session contamination, and multi-turn attack patterns
- Govern
- Defines provenance rules, retention, data-class handling, trust ranking, and lawful-use constraints
10.7
Pre-training and Post-training Overlay
Model provenance, fine-tuning, adapters, preference alignment, safety tuning, feedback loops, and retraining.
- Adopt
- Structures fine-tuning objectives, experiment tracking, rollback, and operational performance baselines
- Defend
- Structures regression testing, jailbreak retesting, alignment failure analysis, fairness drift monitoring, and bias evaluation
- Govern
- Structures provenance review, licensing, cross-border constraints, GDPR compliance for training data, documentation, and approval of learning-loop inputs
10.4 Agentic Hardening — Required control themes
- Delegated authority bounds
- Action-layer isolation and dry-run modes
- Semantic firewalls before tool use and before response release
- Memory hygiene and state reset controls
- Human override and emergency stop pathways
- Forensic replay of prompts, retrieved context, policy decisions, and tool calls
10.5 Minimum MCP requirements
- Approved server inventory
- Capability trust tiering
- Per-invocation policy evaluation
- Auditable request and response traces
- Explicit rejection of implicit trust in tool-supplied instructions
10.8 Multi-Agent and Agent Interoperability
Multi-agent systems create emergent governance challenges that single-agent controls do not address:
- Agent-to-agent trust boundaries: each agent interaction must enforce explicit trust verification; no agent should implicitly trust another agent's outputs or instructions.
- Value alignment verification: agents with different guardrail configurations, different training, or different vendors may have incompatible safety policies. Cross-agent interactions must be tested for value alignment conflicts.
- Collusion and deception detection: monitoring for patterns where agents coordinate to bypass controls, produce misleading outputs, or exploit gaps between their respective guardrails
- Cascading failure and amplification risk: a failure or bias in one agent can be amplified through a chain of dependent agents. Circuit breakers must exist at agent-to-agent boundaries.
- Cross-agent audit trails: every agent-to-agent interaction must be logged with sufficient detail for forensic replay.
- Sycophancy degradation prevention: in agent-to-agent interactions, sycophantic behavior can devolve into harmful feedback loops. Detection and interruption mechanisms are required.
- Interoperability governance: when agents from different organizations or vendors interact, a shared governance protocol must define minimum safety, logging, and accountability requirements.
11.Controls, Artifacts, and Measurement
Answer capsule
What is the minimum control set required to implement the ADG framework?
ADG defines 12 Minimum Controls (MC-1 through MC-12) as the implementation baseline, each with an evidence requirement to ensure measurability. They span AI system inventory, risk classification, separation of duties, pre-production evaluation, change control, context policy, tool and MCP register, runtime monitoring, incident response, governance review, fairness evaluation, and shared responsibility documentation.
Control Crosswalk — NIST AI RMF & ISO/IEC 42001
Every Minimum Control mapped to the NIST function and ISO/IEC 42001 Annex A clause it satisfies. Filter by pillar, hover to trace a mapping, click a control for its full standards detail.
Click any control to see its full mapping. Ribbon width is uniform — the framework asserts that a mapping exists, not how strong it is.
Threat → Control → Standard Flow
ADG consumes four industry threat catalogs rather than publishing its own. Each technique routes through the Minimum Control Set and on to NIST and ISO — pick a catalog and follow any path end to end.
MITRE ATT&CK · Enterprise (AI-relevant) — 10 techniques answered by 6 of the 12 minimum controls, most often MC-8 (8).
Hover to trace a full path; click a threat for its detail. ADG consumes these catalogs as input — it does not publish a threat list of its own.
11.3 Required Operating Artifacts
| Artifact | Purpose | ADG Alignment |
|---|---|---|
| AI System Profile | Documents system architecture, risk classification, autonomy tier, harm classes, and deployment pattern | ADOPT |
| ADG RACI Matrix | Maps control ownership across ADOPT, DEFEND, and GOVERN for each AI system | GOVERN |
| Agent Authority Statement | Defines what an agent may access, decide, execute, and escalate | GOVERN+ADOPT |
| Context Policy | Specifies approved sources, retention, redaction, trust ordering, and privacy controls | GOVERN |
| Tool and MCP Register | Catalogs tools, trust tiers, invocation policies, and third-party assurance status | DEFEND |
| AI Release Gate Checklist | Pre-deployment verification covering security, fairness, safety, and governance approval | ADOPT+DEFEND |
| AI Incident Evidence Pack | Forensic capture package for AI-specific incidents | DEFEND |
| Model and Prompt Change Log | Tracks all changes to models, prompts, and system configurations with approval records | ADOPT |
| Governance Exception Register | Records all governance exceptions with justification, risk acceptance, and expiration | GOVERN |
| Vendor AI Due Diligence Record | Documents vendor AI assessments, contractual AI clauses, and shared responsibility boundaries | GOVERN |
| Fairness Evaluation Report | Records fairness and bias testing methodology, results, and remediation actions | DEFEND+GOVERN |
11.4 Measurement and Evidence Framework
Measurement and Evidence — Three Tiers
Tiers aggregate upward: per-control KPIs roll into outcome metrics, which roll into the executive set. Width is the published metric count.
Width is the number of published metrics in each tier. Hover for the metrics themselves.
ADG requires measurable governance. Three measurement tiers ensure controls are not just documented but demonstrably effective.
Tier 1 — Control Effectiveness Metrics
Per-control KPIs · Operational
- AI systems with completed risk classification
- AI systems with documented RACI matrix
- Mean time from model change to governance approval
- Tool/MCP capabilities with current trust assessment
- Production AI systems with active runtime monitoring
- Uncontrolled production changes detected per quarter
- High-risk AI systems with completed fairness evaluation
Tier 2 — Outcome Metrics
Cross-surface governance effectiveness
- Mean time to detect AI-specific incidents (MTTD)
- Mean time to contain AI-specific incidents (MTTC)
- AI governance exceptions open beyond expiration date
- AI systems operating within approved config (no drift)
- AI-related compliance findings from internal/external audit
- Fairness metric trends across production systems (QoQ)
Tier 3 — Board-Level Indicators
Executive reporting · aggregated
- AI risk posture score (composite across all surfaces)
- AI compliance coverage (systems with current governance review)
- Exception backlog trend (open, aging, risk-weighted)
- AI incident trend (frequency, severity, resolution time)
- Vendor AI risk exposure (third-party model dependencies)
- Responsible AI compliance rate (fairness, transparency, accountability)
12.Regulatory Alignment and Roadmap
Answer capsule
How does the ADG framework map to the EU AI Act, NIST AI RMF, and ISO/IEC 42001?
ADG maps its components to major regulations and standards — e.g., Risk Classification (MC-2) to EU AI Act Art. 6–7, NIST MAP, and ISO/IEC 42001 6.1.2; Incident Response to Art. 73 and ISO 10.2. The mapping is indicative, not exhaustive — it provides a governance backbone that facilitates but does not guarantee compliance.
12.1 Regulatory and Standards Alignment
Regulatory Coverage
Where each ADG component carries an obligation under the EU AI Act, NIST AI RMF and ISO/IEC 42001. Hover for the exact article or clause.
Each cell shows the article or clause; hover for the full mapping. Cells are not weighted — the framework states that a mapping exists, not how strong it is.
| ADG Component | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| Risk Classification (MC-2) | Art. 6-7: Risk categorization | Map: Risk identification and analysis | 6.1.2: AI risk assessment |
| Pre-Production Eval (MC-4) | Art. 9: Risk management system | Measure: AI risk measurement | 8.1: Operational planning and control |
| Runtime Monitoring (MC-8) | Art. 72: Post-market monitoring | Manage: Continuous monitoring | 9.1: Monitoring, measurement, analysis and evaluation |
| Fairness Eval (MC-11) | Art. 10: Data governance and bias prevention | Map: Bias identification | A.7: Data for AI systems + A.5: Impact assessment |
| Incident Response (MC-9) | Art. 73: Serious incident reporting | Manage: Incident response | 10.2: Nonconformity and corrective action |
| AI System Inventory (MC-1) | Art. 49 + Art. 71: Registration in EU database | Govern: Inventory and categorization | 7.5: Documented information |
| Human Oversight (Tiers) | Art. 14: Human oversight requirements | Govern: Human-AI teaming | A.9: Use of AI systems + A.5: Impact assessment |
| Transparency (Telemetry) | Art. 13: Transparency requirements | Govern: Transparency and documentation | A.8: Information for interested parties |
Note: this mapping is indicative, not exhaustive. Organizations must conduct their own regulatory compliance assessment.
12.2 Implementation Roadmap
Adoption Timeline
The four phases on a real month axis, drawn from each phase's own published window.
| Phase | Definition | Example |
|---|---|---|
| Foundation (0–3 months) | Inventory, owners, ADG roles, criticality classification, AI Governance Council established. | Quarter 1: publish AI inventory, name owners, charter the Governance Council. Controls: MC-1, MC-2, MC-3. |
| Control Deployment (3–9 months) | Release gates, change control, context policies, monitoring, adversarial testing, fairness evals, vendor due diligence. | Quarter 2–3: implement MC-4 through MC-9 plus MC-11/MC-12 across all high-risk systems. |
| Agentic Readiness (9–15 months) | Authority statements, tool trust tiering, MCP governance, circuit breakers, multi-agent governance, forensic replay. | Quarter 4–5: agentic hardening overlay deployed for all production agents. |
| Maturity (15–24 months) | Continuous evaluation, persistent adversarial monitoring, drift governance, RAI measurement, board-level reporting. | Quarter 6–8: automated weekly red-team runs, quarterly board AI risk review, formal assurance review. |
13.Workforce Capability
Answer capsule
What is the cost of the AI skills gap, and how does ADG address workforce capability?
IDC (2024) estimated that IT skills shortages could cost organizations USD 5.5 trillion in delays and lost competitiveness. ADG answers via EC-Council's Enterprise AI Credential Suite — a four-part ladder of role-aligned credentials mapped to the Adopt, Defend, and Govern pillars and the Minimum Control Set.
The Capability Bridge — Ladder Rung to Credential
Each credential grouped by the rung of the capability ladder it serves. Hover a credential for what it certifies.
- Literacy baseline — a shared AI vocabulary for every practitioner, technical or not, so governance conversations can happen at enterprise speed. Anchored by the Artificial Intelligence Essentials (AI|E) program.
- Role-aligned capability — three flagship credentials mapped 1:1 to the ADG pillars: C|AIPM for Adopt, C|OASP for Defend, C|RAGE for Govern. Each credential certifies execution-grade competence for the people accountable for that pillar.
- Extended core skills — CEH v13 restructured to integrate AI modules across all five phases of ethical hacking, extending existing security practitioners into the AI attack surface without a role change.
- Operational readiness — each credential crosswalks to the framework's Minimum Control Set (MC-1 through MC-12), turning certification into deployable evidence that auditors, regulators, and boards can accept.
13.1 The AI Skills Gap
The defining constraint on enterprise AI is not the technology — it is the workforce. AI is scaling into production faster than the people who must run, secure, and govern it can be trained, credentialed, and deployed. IDC (2024) estimated that IT skills shortages could cost organizations USD 5.5 trillion in delays, quality issues, and lost competitiveness. Without workforce capability, every control in this framework remains theoretical.
“AI is moving from experimentation to infrastructure, and the workforce has to move with it. Security leaders are now accountable for systems that learn, adapt, and influence outcomes at speed.”
— Jay Bavisi, Chairman & CEO, EC-Council Group
The Adopt gap
The Defend gap
The Govern gap
13.2 The Capability Bridge
EC-Council's answer is the Enterprise AI Credential Suite — a portfolio of role-aligned credentials mapped directly to the ADG framework, structured as a four-part capability ladder:
- Literacy baseline — a shared AI vocabulary for every practitioner, technical or not, so governance conversations can happen at enterprise speed. Anchored by the Artificial Intelligence Essentials (AI|E) program.
- Role-aligned capability — three flagship credentials mapped 1:1 to the ADG pillars: C|AIPM for Adopt, C|OASP for Defend, C|RAGE for Govern. Each credential certifies execution-grade competence for the people accountable for that pillar.
- Extended core skills — CEH v13 restructured to integrate AI modules across all five phases of ethical hacking, extending existing security practitioners into the AI attack surface without a role change.
- Operational readiness — each credential crosswalks to the framework's Minimum Control Set (MC-1 through MC-12), turning certification into deployable evidence that auditors, regulators, and boards can accept.
13.3 Credential Portfolio
Each links to its official EC-Council program page for the syllabus, prerequisites, and enrollment.
Artificial Intelligence Essentials↗
Non-technical AI literacy covering core principles, prompt engineering, AI ethics, and tool fluency. Five hands-on modules, no coding prerequisites.
Audience: All practitioners · educators · learning and development (L&D) teams
Certified AI Program Manager↗
Translates AI strategy into execution — strategy, governance, and enterprise AI lifecycle delivery for program leaders accountable for ROI.
Audience: AI program managers · transformation leads
Certified Offensive AI Security Professional↗
End-to-end AI red-teaming — prompt injection, model evasion, data poisoning, model exploitation, agentic/model-to-model attacks, and AI supply-chain attacks.
Audience: Security engineers · AI red team
Certified Responsible AI Governance & Ethics↗
AI risk management, NIST AI RMF / ISO/IEC 42001 alignment, and accountability across the AI lifecycle for governance and compliance leaders.
Audience: CISOs · governance · compliance leads
Certified Ethical Hacker (AI-integrated)↗
Restructured to integrate AI across the full ethical hacking lifecycle, closing the AI skills gap for existing security practitioners without a role change.
Audience: Ethical hackers · pentesters
Appendix A: Definitions
| Term | Definition |
|---|---|
| AI System | A machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions (aligned with OECD/EU AI Act). |
| AI Agent | An AI system that can autonomously plan, execute multi-step tasks, invoke tools, and take actions in physical or digital environments on behalf of a user or organization. |
| Foundation Model | A general-purpose AI model trained on broad data that can be adapted to a wide range of downstream tasks (e.g., GPT, Claude, Gemini, Llama, Stable Diffusion). |
| Model | Any machine learning artifact — including LLMs, diffusion models, classifiers, regressors, and reinforcement learning agents — used within an AI system. |
| High-Risk AI System | An AI system whose failure or misuse could cause significant harm to health, safety, fundamental rights, or critical infrastructure (aligned with EU AI Act Article 6). |
| Composite AI System | An AI system that orchestrates multiple models (potentially of different architectures) within a single workflow or product. |
| Agentic AI | AI systems exhibiting autonomous behavior: planning, tool use, multi-step execution, and environmental interaction with limited or delayed human review. |
| HITL | Human-in-the-Loop: a human reviews and approves every AI output before it takes effect. |
| HOTL | Human-on-the-Loop: a human monitors AI operations and can intervene, but does not approve each individual output. |
| HOOTL | Human-out-of-the-Loop: AI operates autonomously with periodic governance review rather than real-time human oversight. |
Executive Conclusion
This version turns the original ADG concept into a full enterprise AI security and responsible AI governance framework. It keeps the simplicity of ADOPT, DEFEND, and GOVERN, but adds the structure required to govern contemporary AI systems — across people, process, technology, deployment pattern, lifecycle, harm class, and regulatory environment.
This version was forged with senior AI, security, and governance leaders running production AI inside Fortune 500, Fortune Global 500, and Big Four firms — practitioners working from design through implementation across regulated and less-regulated sectors. It addresses eight major gap clusters identified through systematic review, and extends the framework to cover multi-agent systems, multi-modal architectures, shared responsibility, responsible AI, and measurable governance.
From a framework standpoint, this version is suitable as the basis for:
- Consulting assessments and maturity reviews
- Enterprise AI governance programs
- Certification architecture and training design across all three ADG pillars
- Board-facing AI security, responsible AI, and assurance discussions
- Regulatory preparation and compliance gap analysis
- Vendor AI due diligence and procurement governance
Shape what comes next.
ADG is not a finished product. It is iteratively shaped by the practitioners who actually deploy AI in production — across Fortune 500, Fortune Global 500, and Big Four firms. Every comment, every red-team finding, every regulatory shift becomes the next version.
What we're tracking
EU AI Act, high-risk obligations now in effect.
Status: conformity assessments, post-market monitoring (Art. 72), and serious-incident reporting (Art. 73) live across the EU. ADG MC-1, MC-4, MC-8, and MC-9 map directly.
CSA STAR for AI, attestation pathway live since Oct 2025.
What it means: the first auditable attestation regime for AI controls maps the CSA AI Controls Matrix (243 control objectives) against ISO 42001, NIST AI RMF, and EU AI Act. ADG composes underneath it.
Singapore IMDA, Agentic AI MGF released January 2026.
Why it matters: first state-backed framework with first-class agentic coverage. ADG's Multi-Agent Interop overlay aligns to the IMDA principles; AI Verify is the testing toolkit underneath.
OWASP Top 10 for Agentic Applications 2026.
What changed: first-class agentic threats — goal hijack, tool misuse, identity abuse, multi-agent collusion. ADG's Agentic Hardening overlay (10.4) consumes this as input.
NIST AI 600-1 GenAI Profile in active use.
Status: companion profile to the AI RMF for generative-AI risks. ADG's §11.2 crosswalk maps every Minimum Control to NIST RMF GOVERN / MAP / MEASURE / MANAGE.
MITRE ATLAS v5.4, agentic case studies expanded.
Why it matters: 84+ adversarial techniques with real-world AI incident case studies. ADG MC-8 (Runtime Monitoring) and MC-9 (Incident Response) cite ATLAS as the threat catalog input.
See how the pillars map to certification.
Each pillar has its own credential track and topic map.
