An AI governance framework for everyone who touches the stack.
Twelve controls, mapped today to NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Extended tomorrow as new national and sector regulations come online.· Evidenced
· Input → output
· Covered end-to-end
· Adopt · Defend · Govern
Assess your organization's AI readiness.
Do you maintain a complete, current inventory of every AI system running in production?
Most organizations land at Tier 2. Illustrative reading from 1 of 12 controls, the full assessment scores all twelve and returns a 30/60/90-day roadmap.
Your board-ready roadmap, in about 5 minutes.
Build Your 90-Day Roadmap →
~20 minutes to an EC-Council badge and your path.
Earn Your EC-Council Badge →
Three pillars.
One operating model.
Every place an AI
can fail. ADG covered.
An AI governance framework for everyone
who touches the stack.
Practitioner-led.
Vendor-neutral. By design.
What enterprise AI leaders say about ADG.
Enterprise AI has outpaced governance, and most frameworks still operate at the level of principles, not decisions. ADG changes that. It defines who builds, who validates, and who ultimately decides.
The ADG Framework offers enterprises a credible, practical, and forward-looking blueprint for responsible AI adoption. I am confident it will serve as a global benchmark.
The ADG Framework is the operating model that enterprise AI has been missing. It turns abstract standards into auditable practices and resolves the real tension between delivery speed and safety.
AI governance fails when it is built by theorists for theorists. ADG was built by practitioners who deploy AI in production every day, and that difference is everything.
The future of enterprise AI will be determined by how responsibly it is governed, not merely how quickly it is deployed. ADG provides a timely, much-needed foundation to scale AI with confidence, control, and trust.
The industry does not lack AI frameworks; it lacks operational clarity. ADG helps organizations move from high-level principles to actionable, trackable AI risk management.
FAQ - AI Governance
Find answers to the most common questions.
Many people mistakenly think of an AI governance framework as the rulebook nobody reads until something breaks. In reality, it's the policies, controls, and accountability chains that decide how an organization actually builds, ships, and keeps watch over its AI systems - who signs off before a model goes live, what has to be checked before and after that happens, and how any of it gets proven to a regulator or the board when they come asking. Given the rapid pace of change in the world of AI, a viable AI governance framework needs to be a flexible, living document focused on robust implementation, not on checking the box on some corporate compliance form.
ADG stands for Adopt, Defend, Govern — a free and open AI governance framework developed by EC-Council, in collaboration with a distinguished advisory board of AI leaders from around the world. Most AI governance frameworks quietly stop at policy. ADG doesn't: it bolts on a dedicated Defend pillar for the technical side of AI security, so governance and security end up working off the same evidence instead of running as two programs that never quite talk to each other.
Not quite, though people mix them up constantly. AI governance is the policy side that determines who is allowed to approve a use case and how it is audited. AI security is the technical side: defending against threats specific to AI, such as prompt injection or someone quietly extracting your model. ADG doesn't make you pick one. Govern sets the policy, Defend enforces it, and together they operate as a single operating model rather than two teams working past each other.
All twelve of ADG's minimum controls align with NIST AI RMF, ISO/IEC 42001, and the EU AI Act, and new national or sector regulations will be incorporated as they emerge. The point is, you're not maintaining three separate compliance programs. Audit and compliance teams work off one control set instead of chasing every standard on its own.
Three different kinds of people at once. 1. Students and new practitioners who are still working out what AI governance looks like, once you get past the theory. 2. Security and AI leaders – the people actually responsible for implementing responsible AI. 3. Executives like CISOs, CIOs, and board members who drive corporate-level strategy and risk management and need audit-grade documentation and evidence.
Take the ADG AI Readiness Assessment — it benchmarks your organization against ADG's twelve controls and hands you a 30/60/90-day roadmap to work from.
EC-Council Global Services runs the point on it, backed by a 38-member AI Advisory Board — CISOs, CIOs, and AI engineering leads from organizations such as Microsoft, Salesforce, JPMorgan Chase, and Citi. Everything is versioned publicly (currently v1.0), and community feedback genuinely shapes what comes next.
Yes, genuinely free and not "free trial" free. ADG is an open AI governance framework: the twelve controls, the regulatory crosswalks, the whitepaper, the self-assessment tools — all of it is free to access and implement. EC-Council stewards it through its AI Advisory Board rather than selling it as a licensed product.