ADG V1.0 · Released May 2026
Open Framework · Practitioner-led · Vendor-neutral

An AI governance framework for everyone who touches the stack.

Twelve controls, mapped today to NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Extended tomorrow as new national and sector regulations come online.
Digital · 12 controls · Live crosswalks
12
Minimum controls
· Evidenced
09
Governance surfaces
· Input → output
04
Harm classes
· Covered end-to-end
03
Pillars
· Adopt · Defend · Govern
Get involved

Assess your organization's AI readiness.

Question 1 of 12 · illustrative

Do you maintain a complete, current inventory of every AI system running in production?

Open the full assessment →
Tier 3 / 5 Managed
Defend
58
Adopt
64
Govern
72

Most organizations land at Tier 2. Illustrative reading from 1 of 12 controls, the full assessment scores all twelve and returns a 30/60/90-day roadmap.

Your board-ready roadmap, in about 5 minutes.

Build Your 90-Day Roadmap →
Skill check · ~20 min Test your AI-governance skills ~20 minutes. A few personalized questions. Your EC-Council badge and a certification path, drawn live as an interactive knowledge map. ADG Verified in Adopt badge ADG Verified in Defend badge ADG Verified in Govern badge

~20 minutes to an EC-Council badge and your path.

Earn Your EC-Council Badge →
Crosswalks · ADG aligns with
Six published frameworks · One operational floor
Section 11.2
Control Crosswalk: NIST AI RMF & ISO/IEC 42001
NIST AI RMF function
ISO/IEC 42001 Annex A group
Adopt
Defend
Govern
Click a Minimum Control to highlight its mapped NIST functions and ISO Annex A groups.
§ 02 · The framework

Three pillars.
One operating model.

This AI governance framework runs on three pillars. ADOPT builds and operates. DEFEND breaks and protects. GOVERN authorizes and oversees. An AI Governance Council mediates tension between the three and escalates when needed.
01
Adopt
Build · Operate
Deliver business value, safely.
Use-case selection, capability planning, architecture and deployment. The disciplines that get AI into production without cutting corners.
01
Use cases & value framing
02
Architecture & model selection
03
Deployment & DevSecOps
04
Operating model & capability
02
Defend
Break · Protect
Identify harm before it ships.
Threat modelling, red-teaming, runtime guardrails, detection and response. Maps cleanly to OWASP LLM Top 10 and MITRE ATLAS.
01
Threat modelling & red-team
02
Model & data integrity
03
Runtime guardrails
04
Detection & incident response
03
Govern
Authorize · Oversee
Justify AI use at the board.
Policy, decision rights, regulatory alignment, audit-grade evidence. The governance layer your CAIO, legal and risk officers can sign on.
01
Policy & decision rights
02
Regulatory alignment
03
Assurance & audit
04
Board-level evidence
Mediation layer
AI Governance Council
A standing body of product, security, legal and risk leaders. Resolves tension between ADOPT velocity and DEFEND caution; escalates material decisions to GOVERN.
§ 03 · Coverage

Every place an AI
can fail. ADG covered.

Nine governance surfaces trace the runtime from first prompt to audit log. Five sit in the request pipeline. Four cross-cut every surface.
Request pipeline · 05 surfaces
Input → Output
01
Prompt
Injection · jailbreak · system-prompt leakage
02
Context
RAG · retrieval poisoning · over-broad memory
03
Model
Provenance · weights · evaluation · drift
04
Tools
Function calls · agent actions · blast radius
05
Orchestration
Plans · loops · multi-agent emergence
Cross-cutting bands · 04 surfaces
Slice every layer above
Identity
Who is asking · who is acting · whose data
Safety layer
Pre/post filters · content policy · refusal
Telemetry
Logs · traces · evidence for audit
Learning loop
Feedback · evals · retraining · drift
Harm classes · 04 outcomes the framework prevents
End-to-end coverage
H · 01
Confidentiality loss
Prompt leakage, model exfiltration, training-data extraction, RAG over-disclosure.
H · 02
Integrity failure
Hallucination at scale, decision manipulation, agent-action drift, tool misuse.
H · 03
Availability impact
Resource exhaustion, cost-amplification attacks, cascading agent loops.
H · 04
Accountability gap
No evidence trail, unclear decision rights, regulatory non-conformance.
§ 04 · Built for

An AI governance framework for everyone
who touches the stack.

From the first lecture to the board pack. ADG is written so a student can read it end-to-end and a CISO can adopt it tomorrow.
A · Learner
Free · Self-paced
Students & new practitioners
Start with the basics: what an AI control actually looks like, why prompt injection isn't hypothetical, and how ADG maps to a real system. No prior security background required.
The framework, in plain English
Annotated reference architectures
Self-assessment lab
Take the skill check →
B · Practitioner
Implementer · SMB · SMC
AI & security engineers
Twelve evidence-backed controls you can ship this quarter. Reference architectures, threat models, runtime guardrail patterns and detection rules, all open, all crosswalked to OWASP and ATLAS.
Implementation playbooks
Detection rules & guardrails
Crosswalk to OWASP & ATLAS
Take the skill check →
C · Executive
Board · CISO · CAIO
Implement Ethical, Responsible and Explainable AI across the organization.
Audit-grade evidence the board will accept. ADG maps your AI estate to NIST AI RMF, ISO/IEC 42001 and the EU AI Act in one artefact, so attestation is a translation, not a programme.
Board-ready evidence model
EU AI Act conformance pathway
Maturity assessment template
Benchmark your organization's AI readiness →
§ 05 · AI Advisory Board

Practitioner-led.
Vendor-neutral. By design.

An advisory board of CISOs, CAIOs, AI engineers and academic leaders from Microsoft, Salesforce, KPMG, BASF, BNP Paribas, Reliance Jio and more Stewards this AI governance framework openly, through EC-Council Global Services.
AI Advisory Board
38 Practitioners · 20+ global organizations
Jay Bavisi, Chairman & CEO at EC-Council Group
Jay Bavisi
Chairman & CEO
EC-Council Group
Karthik S., Practice Head, SecureAI and Framework Architect
Karthik S.
Practice Head, SecureAI · Framework Architect & Lead Author
EC-Council
Mayank Tandon, Global Outreach & Partner Experience
Mayank Tandon
Global Outreach & Partner Experience
EC-Council
Kathy Baxter, VP / Principal Architect, Responsible AI at Salesforce
Kathy Baxter
VP / Principal Architect, Responsible AI
Salesforce
Adam Spearing, VP of AI GTM EMEA at ServiceNow
Adam Spearing
VP of AI GTM EMEA
ServiceNow
Anita Lacea, Head of AI Transformation at Microsoft
Anita Lacea
Head of AI Transformation
Microsoft
Dr. Sayed Peerzade, EVP Cloud, AI & Government at Jio
Dr. Sayed Peerzade
EVP · Cloud, AI & Government Initiatives
Jio
Edoardo Tealdi, Executive Head of AI Transformation at NTT DATA
Edoardo Tealdi
Executive Head of AI Transformation
NTT DATA
Lily Rachmawati, Director, Head of Applied AI at BNP Paribas
Lily Rachmawati
Director, Head of Applied AI
BNP Paribas
Naveen Upadhyay, VP AI/ML Product Management at JPMorgan Chase
Naveen Upadhyay
VP, AI/ML Product Management
JPMorgan Chase
Raji Bhimireddy, VP Cloud, AI & Architecture at Prudential
Raji Bhimireddy
VP Cloud, AI, Architecture, FinOps
Prudential
Sanjoy K. Saha, Head of AI Portfolio & Governance at GE Healthcare
Sanjoy K. Saha
Head of AI Portfolio & Governance
GE Healthcare
ShanShan Pa, Global Head of AI & Data Governance at GlobalLogic
ShanShan Pa
Global Head of AI & Data Governance
GlobalLogic
Lewis W. Adams, VP Enterprise AI Transformation at Citi
Lewis W. Adams
VP, Enterprise AI Transformation
Citi
Malik Hussain, AI Enablement Lead at BASF
Malik Hussain
AI Enablement Lead, Data & AI Academy
BASF
Oscar Jarabo, Global Head of AI Product & Strategy at TKE
Oscar Jarabo
Global Head of AI Product & Strategy
TKE
Pavan Kristipati, Head of AI Engineering at Huntington Bank
Pavan Kristipati
Head of AI Engineering & Transformation
Huntington Bank
Sophia Katrenko, VP of AI/ML at EcoVadis
Sophia Katrenko
VP of AI/ML
EcoVadis
Sruthi Pakanati, Head of AI & Data Transformation at Deloitte Australia
Sruthi Pakanati
Head of AI & Data Transformation
Deloitte Australia
Sudarson Roy Pratihar, Founder at A2IQ
Sudarson Roy Pratihar
Founder & Principal
A2IQ
Yashwinder Chhikara, SVP AI, Analytics & Product at iSON Xperiences
Yashwinder Chhikara
SVP · AI, Analytics & Product
iSON Xperiences
Mark Ritcey, VP AI & Automation Delivery
Mark Ritcey
VP, AI & Automation Delivery
Latent Bridge
Dinesh Bhogle, Head of AI/ML Platform at Black & Veatch
Dinesh Bhogle
Head of AI/ML Platform
Black & Veatch
Anish Mitra, Director at KPMG
Anish Mitra
Director
KPMG
Andrei Son, Head of AI Transformation
Andrei Son
Head of AI Transformation
AUMOVIO
Raghunandan Mishra, AI & Data Engineering Leader
Raghunandan Mishra
AI & Data Engineering Leader
,
+ more advisors from Microsoft, Citi, JPMorgan, Prudential, BASF and others
In their words From the 38-member AI Advisory Board

What enterprise AI leaders say about ADG.

Enterprise AI has outpaced governance, and most frameworks still operate at the level of principles, not decisions. ADG changes that. It defines who builds, who validates, and who ultimately decides.
Madhur Mayank Sharma
VP, AI Product Engineering & Global Head of AI Services · SAP
The ADG Framework offers enterprises a credible, practical, and forward-looking blueprint for responsible AI adoption. I am confident it will serve as a global benchmark.
Naveen Upadhyay
VP, AI/ML Product Management · JPMorgan Chase
The ADG Framework is the operating model that enterprise AI has been missing. It turns abstract standards into auditable practices and resolves the real tension between delivery speed and safety.
Lewis V. Adams
VP, Enterprise AI & Capital Productivity Transformation · Citi
AI governance fails when it is built by theorists for theorists. ADG was built by practitioners who deploy AI in production every day, and that difference is everything.
Pavan Kristipati
Head of AI Engineering & Transformation · Huntington Bank
The future of enterprise AI will be determined by how responsibly it is governed, not merely how quickly it is deployed. ADG provides a timely, much-needed foundation to scale AI with confidence, control, and trust.
Dr. Sayed Peerzade
EVP, Cloud, AI & Government Initiatives · Jio Platforms
The industry does not lack AI frameworks; it lacks operational clarity. ADG helps organizations move from high-level principles to actionable, trackable AI risk management.
ShanShan Pa
Global Head of AI & Data Governance · GlobalLogic
§ 06 · FAQs

FAQ - AI Governance

Find answers to the most common questions.

Many people mistakenly think of an AI governance framework as the rulebook nobody reads until something breaks. In reality, it's the policies, controls, and accountability chains that decide how an organization actually builds, ships, and keeps watch over its AI systems - who signs off before a model goes live, what has to be checked before and after that happens, and how any of it gets proven to a regulator or the board when they come asking. Given the rapid pace of change in the world of AI, a viable AI governance framework needs to be a flexible, living document focused on robust implementation, not on checking the box on some corporate compliance form.

ADG stands for Adopt, Defend, Govern — a free and open AI governance framework developed by EC-Council, in collaboration with a distinguished advisory board of AI leaders from around the world. Most AI governance frameworks quietly stop at policy. ADG doesn't: it bolts on a dedicated Defend pillar for the technical side of AI security, so governance and security end up working off the same evidence instead of running as two programs that never quite talk to each other.

Not quite, though people mix them up constantly. AI governance is the policy side that determines who is allowed to approve a use case and how it is audited. AI security is the technical side: defending against threats specific to AI, such as prompt injection or someone quietly extracting your model. ADG doesn't make you pick one. Govern sets the policy, Defend enforces it, and together they operate as a single operating model rather than two teams working past each other.

All twelve of ADG's minimum controls align with NIST AI RMF, ISO/IEC 42001, and the EU AI Act, and new national or sector regulations will be incorporated as they emerge. The point is, you're not maintaining three separate compliance programs. Audit and compliance teams work off one control set instead of chasing every standard on its own.

Three different kinds of people at once. 1. Students and new practitioners who are still working out what AI governance looks like, once you get past the theory. 2. Security and AI leaders – the people actually responsible for implementing responsible AI. 3. Executives like CISOs, CIOs, and board members who drive corporate-level strategy and risk management and need audit-grade documentation and evidence.

Take the ADG AI Readiness Assessment — it benchmarks your organization against ADG's twelve controls and hands you a 30/60/90-day roadmap to work from.

EC-Council Global Services runs the point on it, backed by a 38-member AI Advisory Board — CISOs, CIOs, and AI engineering leads from organizations such as Microsoft, Salesforce, JPMorgan Chase, and Citi. Everything is versioned publicly (currently v1.0), and community feedback genuinely shapes what comes next.

Yes, genuinely free and not "free trial" free. ADG is an open AI governance framework: the twelve controls, the regulatory crosswalks, the whitepaper, the self-assessment tools — all of it is free to access and implement. EC-Council stewards it through its AI Advisory Board rather than selling it as a licensed product.

§ 06 · Adopt the framework

Read it. Implement it.
Help shape v2.

This AI governance Framework is open. The crosswalks are free. The advisory board is taking pull requests. Make AI worth trusting, at your scale.