Hello,
Organizations deploying high-risk AI systems increasingly have the paperwork: model cards, risk registers, signed governance policies. Safety incidents still trace back to human decision points — engineers who override red flags to hit a deadline, deployers who assign oversight to staff without the authority to act. The gap isn’t documentation. It’s behavioral infrastructure.
NIST’s AI Risk Management Framework treats its GOVERN function as cross-cutting rather than a checklist. Subcategories like GV-1.2 (accountability structures) and GV-4.1 (risk tolerance) expect named individuals and tested escalation paths, not policies sitting in a shared drive.
ISO/IEC 42001:2023 goes further — it’s certifiable. Clause 5.1 requires leadership to show resource commitment, not just sign a policy. Clause 6.1.4 requires an AI system impact assessment completed during development, not bolted on before an audit.
The EU AI Act adds legal teeth: Article 9’s continuous risk management, Article 14’s human oversight design, Article 26(2)’s requirement that deployers assign oversight to competent, trained, authorized people. The timeline has moved, though. The Digital Omnibus entered into force on July 27, 2026, pushing standalone high-risk obligations (Annex III) to December 2, 2027, and embedded high-risk systems (Annex I) to August 2, 2028. Penalties of up to €15 million or 3% of global turnover apply once those obligations bite.
That extra runway matters for one reason: current audits check whether a document exists, not whether anyone acted on it. An accountability framework only satisfies Article 17(1)(m) if the named individual actually exercises authority when speed and safety conflict. Organizations that use the delay to build measurable behavioral indicators — override rates, post-mortem completion time, safety suggestion volume — will walk into 2027 audits with evidence. Everyone else will be assembling a paper trail after the fact.
Full framework and recommended indicators: https://aigovernancedesk.com/ai-safety-culture-framework/
