Global AI governance frameworks: a practitioner's field guide
Unsplash
Unsplash· 47 min read
AI governance is the set of policies, roles, processes and technical controls that an organisation uses to keep AI systems lawful, safe, and aligned with its risk appetite across the whole lifecycle, from data sourcing and training through deployment, monitoring and decommissioning. For cybersecurity, risk and governance practitioners it is not a new discipline so much as an extension of existing model-risk, information-security and third-party-risk practice to a class of systems whose behaviour is probabilistic, data-dependent, and capable of acting with growing autonomy.
Two forces have moved this from optional to mandatory. First, binding law now exists: the EU AI Act is in force and phasing in, the Council of Europe has opened the first legally binding international AI treaty for signature, and jurisdictions from China to India have issued enforceable rules or formal guidelines. Second, the risk surface has widened. Generative and agentic systems introduce failure modes, confabulation, prompt injection, training-data leakage, unsafe tool use, and behavioural drift, that traditional controls were not designed to catch.
Practitioner framing. Treat the frameworks below as a layered stack, not competitors: use NIST AI RMF (or India's Guidelines) as your risk operating model, ISO/IEC 42001 as the certifiable management-system layer, CMMI AIM as the maturity-benchmarking layer, and binding regulations (EU AI Act, China's measures, sectoral rules) as mandatory overlays. A single risk assessment can be structured to satisfy several at once.
The modern AI-governance canon began as soft law, non-binding principles that shaped a shared vocabulary, and is now hardening into enforceable regulation and treaty law. The soft-law instruments still matter because binding regimes borrow their definitions and principles.
OECD AI Principles (2019, updated May 2024). The first intergovernmental AI standard; source of the widely reused OECD definition of an "AI system", now adopted by the EU, Council of Europe and others. Later endorsed by the G20.
UNESCO Recommendation on the Ethics of AI (adopted 23 November 2021). The first global normative instrument on AI ethics, adopted by UNESCO member states; emphasises human rights, proportionality, and environmental sustainability.
G7 Hiroshima Process (30 October 2023). International Guiding Principles and a voluntary Code of Conduct for organisations developing advanced AI systems.
These instruments are voluntary. Their influence is indirect but real: they supply the conceptual scaffolding that binding law then codifies.
Adopted by the Council of Europe Committee of Ministers on 17 May 2024 and opened for signature in Vilnius on 5 September 2024, this is the first legally binding international treaty on AI. It is deliberately technology-neutral and anchors AI activity in human rights, democracy and the rule of law, setting horizontal obligations on transparency, accountability, non-discrimination, oversight and the right to challenge AI decisions.
Status caveat (verify before relying). The Convention enters into force only after five ratifications, including at least three Council of Europe member states. On 15 May 2026, at the 135th Session of the Committee of Ministers in Chișinău, the European Union ratified the Convention, a significant milestone, and reported as among the first ratifications. Based on sources reviewed for this document, the five-ratification threshold had not been confirmed as met at the time of writing, so the treaty was signed by many parties but not yet reported as in force. Confirm the current ratification count on the Council of Europe treaty office site (CETS No. 225) before citing it as binding. From 1 January 2026, the Council of Europe's new CDNET committee acts as custodian of the Convention pending entry into force.
For practitioners: the Convention will bite through domestic implementing law rather than directly. In the EU it is expected to be implemented largely through the AI Act. It offers two compliance modalities for the private sector, apply the Convention's obligations directly, or take "other appropriate measures" achieving the same objectives, and excludes national-security and pure R&D activity (with a safeguard for testing that could affect rights).
Regulation (EU) 2024/1689 is the world's first comprehensive, horizontal AI law. It entered into force on 1 August 2024 and applies in phases. Its architecture is risk-tiered: obligations escalate with the potential for harm rather than with the technology used.
Unacceptable risk (prohibited). A closed list of banned practices (e.g. social scoring by public authorities, certain manipulative or exploitative systems). Prohibitions and AI-literacy duties applied from 2 February 2025.
High risk. Systems in Annex III use-cases (e.g. biometric identification, critical infrastructure, education, employment, access to essential services and credit, law enforcement) and AI that is a safety component of regulated products (Annex I). These carry the heaviest duties: risk management (Art. 9), data governance (Art. 10), technical documentation, logging, human oversight, accuracy/robustness/cybersecurity, conformity assessment, CE marking and EU database registration.
Limited risk (transparency). Disclosure duties under Art. 50, users must be told they are interacting with AI, and AI-generated or manipulated content must be marked in a machine-readable way.
Minimal risk. The majority of AI systems; no mandatory obligations, voluntary codes encouraged.
General-Purpose AI (GPAI) models are governed separately, with baseline transparency and documentation duties for all GPAI and additional systemic-risk obligations for the most capable models. GPAI obligations began applying from 2 August 2025.
Adoption status (as of early July 2026). The "Digital Omnibus on AI" amending the AI Act has now cleared both co-legislators: the European Parliament formally endorsed the text on 16 June 2026 and the Council of the EU gave its final approval on 29 June 2026. Publication in the Official Journal was expected shortly thereafter (widely anticipated in July 2026), with entry into force on the third day after publication, ahead of the 2 August 2026 milestone. Until publication, the original Regulation's dates remain the letter of the law; the amended dates below only bind once the Omnibus is in the Official Journal. Verify publication status before relying on any deferred date.
| Date | Milestone (reflecting the Omnibus as adopted; verify against Official Journal text) |
|---|---|
| 1 Aug 2024 |
Entry into force; compliance clocks start. |
| 2 Feb 2025 |
Prohibited practices and AI-literacy duties apply. |
| 2 Aug 2025 |
GPAI model obligations; national competent authorities and penalty regimes; EU-level governance (AI Office / Board). |
| 2 Aug 2026 |
Still a live date: Art. 50 transparency obligations apply largely unchanged (reported fines up to EUR 15m or 3% of turnover, approximate; verify); Commission enforcement of GPAI obligations begins; national market surveillance authorities gain full investigatory and enforcement powers. |
| 2 Dec 2026 |
New prohibitions on AI generating non-consensual intimate imagery ("nudifiers") and CSAM apply; machine-readable watermarking (Art. 50(2)) applies to generative systems already on the market before 2 Aug 2026 (grace period). |
| 2 Aug 2027 |
Member-State AI regulatory sandboxes due (deferred from 2026); pre-2025 GPAI models must be fully compliant. |
| 2 Dec 2027 |
Annex III (use-based) high-risk obligations apply, deferred 16 months from 2 Aug 2026. |
| 2 Aug 2028 |
Annex I (product-embedded) high-risk obligations apply, deferred from 2 Aug 2027. AI-specific machinery-safety requirements to be added to the Machinery Regulation via delegated acts by this date. |
Other Omnibus changes worth noting: a narrowed "safety component" definition (AI used solely for user assistance, optimisation, automation or quality control is not high-risk under Art. 6(1) unless its failure could endanger health or safety); AI under the Machinery Regulation moved out of the AI Act's direct application; SME regulatory reliefs extended to small mid-caps; an expanded lawful basis for processing sensitive data for bias detection and mitigation; and reinforced AI Office powers. Practitioner guidance is consistent across law-firm commentary: do not stand down 2 August 2026 work (transparency, GPAI, market-surveillance readiness), and treat the 2027/2028 dates as time to build conformity assessment, documentation and human-oversight properly, not as a pause.
Maximum penalties remain the headline deterrent: up to EUR 35 million or 7% of global annual turnover for prohibited-practice breaches (approximate ceilings, confirm against the current text). The Act runs concurrently with the GDPR, so many high-risk uses require both a DPIA and a Fundamental Rights Impact Assessment (Art. 27).
The NIST AI RMF 1.0 (published January 2023) is voluntary, sector-neutral guidance and has become the de-facto risk operating model in the US and beyond. It defines trustworthy AI through seven characteristics, valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed, and organises work around four functions.
| Function | What it does |
|---|---|
| GOVERN |
Cross-cutting. Establishes risk culture, accountability, policies and oversight across the lifecycle; sits above the other three. |
| MAP |
Establishes context: intended use, stakeholders, system boundaries, data lineage, third-party dependencies and potential harms. Supports a go/no-go decision. |
| MEASURE |
Assesses, benchmarks and monitors risks, evaluations, red-teaming, bias and drift testing, with owners and thresholds. |
| MANAGE |
Prioritises, treats and accepts residual risk; responds to incidents; allocates resources; feeds back into GOVERN. |
Companion resources extend the core: the Generative AI Profile (NIST AI 600-1, July 2024) catalogues risk categories unique to or exacerbated by generative AI (widely reported as 12 categories with 200+ suggested actions, confirm the exact counts in the source) covering confabulation, data leakage, prompt injection, IP and supply-chain risks. NIST has also signalled a Cyber-AI profile bridging the Cybersecurity Framework 2.0 with the AI RMF (an initial NIST IR 8596 draft was reported in late 2025) and a critical-infrastructure profile concept note in 2026. AI RMF 1.0 is itself under revision toward 1.1; check for the current version.
The United States has no comprehensive federal AI statute; binding obligations come mainly from a fast-moving state patchwork, sectoral regulators and FTC enforcement. Key enacted state laws (statuses change frequently, verify each before relying):
Texas TRAIGA (HB 149) — in force 1 January 2026; intent-based prohibitions (e.g. encouraging self-harm, unlawful discrimination, CSAM), with an affirmative defence for substantial compliance with a recognised risk framework such as NIST AI RMF, and an AI sandbox.
California — SB 53 (Transparency in Frontier AI Act) and AB 2013 (generative-AI training-data disclosure) effective 1 January 2026; SB 942 (AI Transparency Act, detection/provenance tools) deferred to 2 August 2026 by AB 853.
Colorado — reported as repealed-and-replaced: multiple trackers report that SB 24-205 (the 2024 Colorado AI Act) was repealed before taking effect and replaced in May 2026 by SB 26-189, a narrower automated-decision-making (ADMT) law effective 1 January 2027 centred on pre-use notices, adverse-outcome explanations and human review. Sources reviewed for this document were not fully consistent on this status; verify against the Colorado legislature before relying on it.
Others — Illinois HB 3773 (AI in employment, from 1 January 2026), NYC Local Law 144 (bias audits for automated hiring tools, in force since 2023), Utah SB 149 (generative-AI disclosure, 2024), plus widespread deepfake/election laws. A December 2025 federal Executive Order pressing for preemption of certain state AI laws had not, at the time of writing, been resolved by the courts, do not treat state laws as preempted.
Practical consequence: for multi-state exposure, one AI inventory plus a NIST AI RMF-based programme covers most of the overlap and earns explicit safe-harbour credit in Texas.
ISO/IEC 42001:2023 (published December 2023) is the first certifiable international standard for an Artificial Intelligence Management System (AIMS). It follows the same Plan-Do-Check-Act, High-Level Structure as ISO/IEC 27001 and ISO 9001, so organisations already running those management systems can integrate it with shared document control, audit and management-review processes.
Structure. Clauses 4–10 are the auditable management-system requirements (context, leadership, planning, support, operation, performance evaluation, improvement). Annex A lists reference controls; Annex B gives implementation guidance; Annex C lists AI-specific objectives and risk sources; Annex D covers multi-domain use.
Certification. Carried out by accredited certification bodies via a Stage 1 (documentation) and Stage 2 (operational) audit; certificates typically run three years with annual surveillance audits. ISO itself does not certify organisations.
Value. It is currently the most credible third-party answer to a procurement team asking you to "prove responsible AI", and it maps cleanly onto NIST AI RMF and EU AI Act risk-management duties.
Related standards worth tracking: ISO/IEC 42005 (AI system impact assessment) and ISO/IEC TR 20226:2025 (environmental sustainability aspects of AI systems across the life cycle, with candidate metrics including a water footprint), the latter is directly relevant to the Sustainable-AI alignment in Section 10.
ISACA's CMMI Institute has extended the Capability Maturity Model Integration (CMMI) family to AI with the CMMI Artificial Intelligence Maturity (AIM) model. A pilot programme was completed in May 2026, with IBM Consulting, Infosys and Government Technical Services Corporation (GTSC) as appraised pilot organisations, and the framework was scheduled for formal launch at the Capability Creates Conference on 23–24 June 2026. AIM is a maturity model within the CMMI framework: it integrates fragmented AI practices and standards into a structured maturity progression with defined capability levels and independent appraisal, covering AI usage, development, acquisition and integration, with associated training/certification pathways and an appraisal method.
Where it fits in the stack: ISO/IEC 42001 certifies that a management system exists and operates; NIST AI RMF gives the risk operating model; CMMI AIM adds a benchmarked answer to "how mature is our AI capability, and is it improving?", useful for boards, procurement and multi-year roadmaps, in the same way CMMI maturity levels have long been used in software delivery. Because the model launched only in June 2026, details of its capability-level structure, appraisal criteria and pricing should be taken from ISACA/CMMI Institute primary materials directly; this document does not summarise level definitions to avoid stating unverified specifics.
India has consciously chosen not to enact a standalone AI law at this stage. The centrepiece is the India AI Governance Guidelines, unveiled by the Ministry of Electronics and Information Technology (MeitY) under the IndiaAI Mission on 5 November 2025, drafted by a committee chaired by Prof. Balaraman Ravindran (IIT Madras). The guiding philosophy is "Do No Harm", human-centricity, and "innovation over restraint", relying on existing laws wherever possible and intervening with new rules only when necessary.
Trust is the foundation; People first; Innovation over restraint; Fairness & equity; Accountability; Understandable by design; and Safety, Resilience & Sustainability. Note that sustainability is embedded as a first-class principle, a useful hook for the Sustainable-AI programme in Section 10.
AI Governance Group (AIGG) — an inter-ministerial apex policy-coordination body (reported to be chaired by the Principal Scientific Adviser).
Technology & Policy Expert Committee (TPEC) — an expert advisory body tracking emerging capabilities and regulatory gaps.
AI Safety Institute (AISI) — a technical hub-and-spoke body for testing, red-teaming, standards and risk assessment; its benchmarks are expected to act as a de-facto standard of care.
Sectoral regulators (RBI, SEBI, TRAI, and others) retain domain-specific enforcement rather than a single super-regulator.
The Guidelines stress that AI is already governed by existing statutes: the Information Technology Act 2000, the Digital Personal Data Protection (DPDP) Act 2023 (with DPDP Rules notified in November 2025), the Copyright Act 1957, and general civil and criminal law. Deepfake governance is handled through the IT intermediary rules and successive MeitY advisories.
India's most developed sectoral AI-governance stack is in finance, and it has hardened significantly between 2025 and 2026. It now has three layers: a principles report (FREE-AI), a draft supervisory rulebook (Model Risk Management guidance), and the capital-markets track (SEBI).
The report of the committee on a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI), constituted in December 2024 and released 13 August 2025, sets seven guiding principles ("Sutras") and 26 recommendations across six pillars: Infrastructure, Policy, Capacity (innovation enablement) and Governance, Protection, Assurance (risk mitigation). Notable recommendations include board-approved AI policies for regulated entities, AI inventories and a sector-wide repository, an AI innovation sandbox, an AI incident-reporting framework, a graded liability approach, capacity building for boards and supervisors, and AI-related disclosures in annual reports. The RBI's underlying survey found that only about 20.8% of 612 surveyed entities were using or developing AI, adoption is concentrated in larger banks, which is part of why the framework leans on enablement as much as restraint.
New and still a draft, status caveat. Released 24 June 2026 (RBI Press Release 2026-2027/528) for public comment until 24 July 2026 via the Connect 2 Regulate portal. It is a consultation draft, not a final circular; the implementation timeline will be set when the final guidance issues. Once finalised it is expected to replace the RBI's 2002 credit-risk-model guidance. Verify final status and text on rbi.org.in before treating any requirement below as binding.
This draft is the operational sequel to FREE-AI: it converts principles into supervisory expectations for all models, statistical, rule-based, AI/ML and generative AI, whether built in-house, procured from third parties, or hybrid. It applies to a broad set of RBI-regulated entities (reported as 11 categories): commercial banks, small finance banks, payments banks, regional rural banks, urban and rural co-operative banks, NBFCs across all layers, All-India Financial Institutions (e.g. NABARD, SIDBI, NHB, NaBFID, EXIM Bank), Asset Reconstruction Companies and Credit Information Companies. Key proposed requirements:
Board-approved Model Risk Management Framework (MRMF) covering the full model lifecycle, development, validation, deployment, monitoring, modification and retirement, with the Board approving model-risk appetite informed by scenario analysis and stress testing.
Risk-based model tiering. Models classified by materiality, customer impact, complexity, explainability and regulatory significance; high-risk models need Risk Management Committee of the Board (RMCB) approval and more intensive validation, with classifications reviewed at least annually.
Three lines of defence formalised for model risk: model owners (first line), an independent model risk management and validation function (second line), and internal audit (third line). Independent validation is required before deployment, proportionate to risk.
Comprehensive model inventory of active, inactive, under-development and retired models, owner, developer, validator, approver, risk class, intended use, dependencies, validation findings and monitoring history. No model may be used unless it is in the inventory; commentary reports a minimum 10-year retention for decommissioned models (verify in the draft text).
Third-party accountability. Outsourcing does not transfer responsibility: entities remain fully accountable for vendor-model outcomes, must independently validate them (vendor certification is not enough), obtain documentation and audit rights, and may restrict use where vendors withhold information.
AI/ML-specific safeguards. Named risks include hallucination, bias, data and concept drift, explainability gaps, adversarial attacks and prompt injection, data privacy/leakage and vendor concentration. Proposed controls include stress testing, adversarial testing and red-teaming; mandatory meaningful human oversight (addressing automation bias and over-reliance); override and kill-switch mechanisms to halt models; explainability for material customer decisions such as loan approvals and fraud flags; and, for customer-facing/generative systems, protection against prompt injection, limits on session/context persistence, anomalous-usage detection, disclosure that the user is interacting with AI, and an option to switch to a human.
SEBI has moved in parallel. The SEBI (Intermediaries) (Amendment) Regulations, 2025 (notified 10 February 2025) insert a chapter on AI usage making any SEBI-regulated entity solely responsible for the privacy, security and integrity of investor data and for the outputs of AI/ML tools it uses, whether built or bought. A consultation paper of 20 June 2025 ("Guidelines for Responsible Usage of AI/ML in Indian Securities Markets") proposed board-level governance, testing, independent audit, explainability, human-in-the-loop mechanisms and investor disclosures, with a lighter regime for purely internal (non-client-facing) uses. Check SEBI's circulars page for whether final guidelines have since issued.
The RBI draft did not appear in isolation. On 10 June 2026 the Financial Stability Board published a consultation report, "Sound Practices for Responsible Adoption of Artificial Intelligence", proposing 12 sound practices for financial institutions: practices 1–4 on organisation-wide AI governance (board and senior-management oversight, risk appetite, capability building); 5–10 on lifecycle risk management (use-case materiality assessment, model selection, data governance, explainability, human oversight, monitoring); and 11–12 on AI-related cyber/ICT and third-party risks. It is explicitly non-binding and notably acknowledges that continuous human review of every agentic-AI decision becomes impractical at scale, discussing AI-monitoring-AI architectures as a supplement. Comments were due 22 July 2026, with the final report expected in October 2026. Read together, RBI's draft, SEBI's proposals and the FSB paper show strong convergence: board accountability, model inventories, independent validation, explainability, human oversight and vendor accountability are becoming the global baseline for AI in finance.
Why India matters to a global programme. If you operate in India, your compliance anchor is DPDP + sectoral regulator expectations (RBI/SEBI as above) + the Guidelines' de-facto standard of care, not a single AI Act. For banks and NBFCs, do not wait for the final MRM circular: gap-assess your model governance against the draft now, since board structures, inventories and independent validation functions take longest to build. The verifiable primary sources are listed in the References.
China regulates AI through a stack of targeted, binding measures rather than one omnibus act, with the Cyberspace Administration of China (CAC) as lead regulator. The core instruments:
Recommendation Algorithms Provisions — effective 1 March 2022.
Deep Synthesis Provisions — effective 10 January 2023; watermarking/labelling of synthetic media.
Interim Measures for Generative AI Services — effective 15 August 2023; the first administrative regulation on public generative-AI services (data sourcing, content safety, transparency, security assessment and filing).
Measures for Labelling AI-Generated Content (with mandatory national standard GB 45438-2025) — effective 1 September 2025; require both explicit (user-visible) and implicit (metadata/watermark) labels on AI-generated text, images, audio, video and virtual scenes.
Extraterritorial reach applies to services offered to users in China. Penalties draw on existing statutes (e.g. PIPL fines up to RMB 50 million or 5% of turnover, approximate; verify). For practitioners the operational takeaway is concrete: build labelling into generation and distribution pipelines, keep training-data provenance records, and be ready for CAC filing and security assessment.
Singapore governs AI through voluntary frameworks backed by binding data-protection law, and its instruments are widely used as regional and procurement benchmarks. Three generations of the Model AI Governance Framework now exist, all issued by the Infocomm Media Development Authority (IMDA) with the PDPC and/or the AI Verify Foundation:
Model AI Governance Framework (1st edition January 2019; 2nd edition January 2020) — cross-sector guidance for traditional AI covering internal governance, human oversight, operations/risk management and stakeholder communication.
Model AI Governance Framework for Generative AI (30 May 2024) — developed by IMDA and the AI Verify Foundation; addresses generative-AI issues including hallucination, bias, data quality, trusted development and deployment, incident reporting, testing and assurance, security, and content provenance (e.g. digital watermarking and cryptographic provenance).
Model AI Governance Framework for Agentic AI (January 2026) — reported as among the first governance frameworks designed specifically for autonomous AI agents; consult the IMDA/AI Verify primary text for its detailed contents, which this document does not summarise.
Alongside the frameworks sit AI Verify, an AI governance testing framework and open-source toolkit developed by IMDA/PDPC and stewarded by the AI Verify Foundation, letting organisations demonstrate responsible AI in an objective, testable way, and the binding layer: the Personal Data Protection Act (PDPA), supplemented by the PDPC's Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (March 2024). In financial services, the Monetary Authority of Singapore (MAS) has long promoted the FEAT principles (Fairness, Ethics, Accountability, Transparency) and the Veritas initiative, and issued a consultation on AI risk management for financial institutions in 2025, check MAS for the current status. Though formally non-binding, IMDA's frameworks and AI Verify increasingly function as benchmarks in procurement and contracting.
The table condenses the instruments most practitioners must reconcile. Read the legal-force column carefully: mixing a voluntary framework with a binding law without noting the difference is a common governance error.
| Framework | Force | Approach | Practitioner hook |
|---|---|---|---|
| EU AI Act |
Binding |
Risk-tiered, product-safety style |
Conformity assessment, tech docs, FRIA, CE marking, EU DB registration for high-risk. |
| CoE Convention |
Binding treaty (EU ratified May 2026; in-force pending) |
Human-rights, technology-neutral |
Implemented via domestic law; "human-rights by design", right to challenge decisions. |
| NIST AI RMF |
Voluntary |
Risk operating model |
Govern/Map/Measure/Manage; GenAI Profile for LLM/agentic risk. |
| ISO/IEC 42001 |
Voluntary, certifiable |
Management system (PDCA) |
Certifiable AIMS; procurement evidence; integrates with ISO 27001. |
| CMMI AIM |
Voluntary, appraised |
Maturity model (launched Jun 2026) |
Benchmarked AI capability levels via independent appraisal; complements ISO 42001 certification. |
| India Guidelines |
Guidance + existing law |
Principles-first, light-touch |
Seven sutras; DPDP 2023 + sectoral (RBI FREE-AI); AISI de-facto standard of care. |
| China measures |
Binding |
Vertical, provider-focused |
Content labelling, filing, security assessment, data-provenance records. |
| Singapore MAIGF / AI Verify |
Voluntary + PDPA binding |
Testable frameworks (2019/2024/2026) |
GenAI & Agentic frameworks; AI Verify toolkit as demonstrable assurance; PDPC AI guidelines. |
| OECD / UNESCO / G7 |
Voluntary |
Principles / ethics |
Shared definitions and principles that harder regimes reuse. |
Other regimes worth monitoring but not detailed here include the UK's principles-based, regulator-led approach and South Korea's AI Basic Act (reported to take effect January 2026, verify). National approaches are shifting quickly; verify current status directly.
"Sustainable AI" has two faces: governing AI so it supports sustainability goals, and governing the environmental footprint of AI itself. For a governance programme, the second is the more actionable and the more often neglected. The frameworks are beginning to converge on it: UNESCO's Recommendation names environmental sustainability; India's seventh sutra pairs Safety and Resilience with Sustainability; and ISO/IEC TR 20226:2025 provides life-cycle environmental metrics for AI systems.
AI is now heavy physical infrastructure. Reported estimates vary widely and should be treated as approximate:
Data centres consumed on the order of ~448 TWh of electricity in 2025, potentially rising toward ~945 TWh by 2030(UN University estimate, approximate).
Data centres are often cited at roughly ~1.5–4% of global electricity; sources differ substantially, so cite a specific primary source and year.
Training GPT-3 was estimated at ~700,000 litres of on-site cooling water (~5.4 million litres including electricity generation) in one widely cited academic study, an estimate, not a vendor figure.
A recurring, well-supported finding: inference, not training, drives most operational AI energy use, so model selection, routing and product defaults are the highest-leverage governance levers.
Governance implication. Because operational use dominates, the biggest sustainability wins come from behavioural and design levers you already control: right-sizing models to the task, efficient routing, caching, quantisation/distillation, batching, carbon-aware scheduling, and location/PUE-WUE choices, not just optimising the largest training runs.
Transparency; efficiency by design; equity and environmental justice; life-cycle responsibility; global cooperation; and sustainable use. These map cleanly onto existing governance functions, treat environmental footprint as another risk category inside NIST MAP/MEASURE and ISO/IEC 42001 planning.
The following is a build order a risk/GRC or security team can start on now. It is framework-agnostic but tagged to the control it satisfies so a single effort earns multiple credits.
Stand up an AI inventory. A living register of every AI system (built and bought, incl. shadow AI and embedded vendor features), with owner, purpose, data sources, model/version, third-party dependencies and lifecycle stage. This is the prerequisite for every framework (ISO 42001 Clause 4; NIST MAP; EU high-risk classification).
Establish accountability. Name an accountable executive, form a cross-functional AI governance committee (security, legal/privacy, data science, risk, a business owner), and publish an AI policy and acceptable-use standard (NIST GOVERN; ISO 42001 Clause 5).
Classify by risk. Triage each system against EU-style tiers and your own risk appetite; flag anything touching biometrics, employment, credit, essential services, health or law enforcement for enhanced controls.
Define intended use and out-of-scope use per system in a one-page "model card / system card" (NIST MAP; supports EU technical documentation).
Data governance. Document training/validation/test data provenance, consent basis (critical under India's DPDP and GDPR), representativeness and known gaps; add a machine-unlearning / deletion plan for revoked consent.
Pre-deployment evaluation. Benchmark accuracy on a representative set plus edge cases; run bias/fairness tests; red-team for prompt injection, jailbreaks, data exfiltration and unsafe tool use (NIST MEASURE; GenAI Profile).
Human oversight. Define where a human must be in or on the loop, with authority and training to override, mandatory for EU high-risk (Art. 14).
Transparency & provenance. Disclose AI interaction to users; label AI-generated content and embed machine-readable provenance (required by China's labelling measures and EU Art. 50).
Security integration. Extend existing controls to model access, secrets, RAG data stores, and the model supply chain; adopt OWASP LLM Top 10 and MITRE ATLAS as testing references; treat vendors' vague governance answers as a risk signal.
Agentic guardrails. For tool-using/autonomous agents, add scoped permissions, action allow-lists, rate/spend limits, reversibility checks and delegation-chain logging, areas where RMF 1.0 is thin and profiles are still emerging.
Continuous monitoring. Track drift, refusal/override rates, incident signals and new misuse patterns; schedule periodic revalidation (NIST MANAGE).
Incident response. Extend your IR plan to AI-specific incidents (harmful output, model compromise, data leakage) with runbooks and, where required, regulator notification.
Independent assurance. Run internal audit against ISO/IEC 42001 and pursue certification if procurement or regulators expect it.
Impact assessments. Combine DPIA + Fundamental Rights Impact Assessment (EU Art. 27) + AI impact assessment (ISO/IEC 42005) into one workflow to avoid duplicate effort.
If you are an RBI- or SEBI-regulated entity (or supply models to one), add the following, aligned to the RBI draft MRM guidance, FREE-AI and the FSB sound practices:
Gap-assess against the RBI draft MRM guidance now (before the final circular): board-approved MRMF, model-risk appetite, tiering policy, and RMCB terms of reference for high-risk model approval.
Extend the AI inventory into a full model inventory covering statistical and rule-based models too, active, inactive, under-development and retired, with owner, validator, approver, risk class and monitoring history.
Stand up independent model validation as a second line separate from model owners, with internal audit as the third line; validate third-party models independently rather than accepting vendor certification.
Implement override and kill-switch mechanisms for AI-driven decisioning, with tested runbooks for halting a model and falling back to manual processing.
Make material customer decisions explainable (loan approvals, fraud flags, pricing); document model logic so outcomes are traceable and repeatable, and disclose AI interaction with an option to reach a human.
Harden customer-facing generative AI against prompt injection and adversarial inputs; limit session/context persistence; detect anomalous usage.
Renegotiate vendor contracts for documentation, audit rights, continuity and exit provisions; track vendor-concentration risk.
Prepare AI disclosures and incident reporting in line with FREE-AI recommendations (annual-report disclosures, AI incident reporting) and monitor the FSB final report (expected October 2026) for supervisory direction.
Add an environmental field to the AI inventory (hosting region, PUE/WUE where available, model size, expected inference volume).
Set efficiency-by-design gates: justify model choice against a lighter alternative, prefer distilled/quantised models where adequate, enable caching and batching, and schedule heavy jobs in low-carbon-intensity windows/regions.
Require footprint reporting from vendors and, for material workloads, estimate energy, carbon and water using ISO/IEC TR 20226 metrics.
Report footprint to the governance committee alongside risk, so sustainability trade-offs are made deliberately, not by default.
The single table below consolidates the controls an India-headquartered organisation should consider when its AI systems or AI-enabled services reach customers in the USA, EU/Europe, Singapore and the Middle East. It is a planning checklist, not legal advice: applicability depends on your role (provider vs. deployer), sector and specific use cases, and several cited instruments are drafts or recently amended, verify each against the primary source. Middle East entries focus on the UAE, Saudi Arabia and Qatar, the region's most developed regimes; other Gulf states differ.
| # | Control | What to implement | Key jurisdictional drivers |
|---|---|---|---|
| 1 |
AI & model inventory |
Living register of every AI system and model (built, bought, embedded, shadow AI): owner, purpose, data, model/version, risk class, lifecycle stage, jurisdictions served. |
All frameworks; RBI draft MRM (if financial); ISO 42001 Cl.4; EU classification; US state mapping |
| 2 |
Accountable executive & board oversight |
Named accountable executive; cross-functional governance committee; board-approved AI policy and risk appetite; periodic board reporting. |
ISO 42001 Cl.5; India FREE-AI/RBI; FSB SP 1–4; MAS FEAT; SDAIA principles |
| 3 | Risk classification / tiering |
Tier every system (prohibited / high / limited / minimal or equivalent); flag biometrics, employment, credit, essential services, health, law enforcement for enhanced controls. |
EU AI Act Annex III; NIST MAP; RBI tiering; US state 'consequential decision' scopes |
| 4 | EU role & applicability analysis |
Determine provider/deployer/importer/authorised-representative role per system; EU AI Act applies extraterritorially where output is used in the EU. Track amended dates: Art. 50 transparency 2 Aug 2026; Annex III high-risk 2 Dec 2027; Annex I 2 Aug 2028 (verify Official Journal). |
EU AI Act (as amended by Digital Omnibus) |
| 5 |
Prohibited-use screening |
Screen all use cases against banned practices: EU Art. 5 (incl. non-consensual intimate imagery/CSAM from 2 Dec 2026); Texas TRAIGA restricted purposes; SDAIA prohibitions (e.g. social scoring). | EU; Texas TRAIGA; Saudi SDAIA |
| 6 |
Dual/multi privacy compliance |
Map personal-data flows; lawful basis and verifiable consent under India DPDP Act 2023 + Rules; GDPR compliance for EU data (DPIA, rights, DPO where needed); Singapore PDPA; UAE PDPL (and DIFC/ADGM regimes, incl. DIFC Regulation 10 on autonomous systems); Saudi PDPL. |
DPDP; GDPR; PDPA; UAE PDPL/DIFC/ADGM; Saudi PDPL |
| 7 |
Cross-border data transfer mechanisms |
Implement SCCs/adequacy for EU exports; DPDP Rules transfer conditions; Singapore PDPA transfer-limitation obligation; Saudi transfer regulation (2025), adequacy/SCC-equivalents; check data-localisation duties (esp. Saudi, sectoral). |
GDPR Ch. V; DPDP; PDPA; Saudi transfer regulation |
| 8 |
Impact assessments (unified workflow) |
One workflow producing: DPIA (GDPR), Fundamental Rights Impact Assessment (EU Art. 27, high-risk deployers), AI impact assessment (ISO/IEC 42005), and US state assessment/notice artefacts where applicable. |
GDPR; EU Art. 27; ISO 42005; US state laws |
| 9 |
US state-law mapping + NIST baseline |
Map deployments to state obligations (Texas TRAIGA; California SB 53/AB 2013 from Jan 2026, SB 942 from Aug 2026; Illinois HB 3773; NYC LL144; Colorado ADMT regime, status contested, verify). Adopt NIST AI RMF as baseline: safe-harbour credit in Texas and heavy overlap elsewhere. |
US states; NIST AI RMF |
| 10 |
Fairness & bias testing |
Pre-deployment and periodic bias testing on representative data; documented methodology and remediation; bias audits for hiring tools used for NYC roles; note the EU Omnibus's expanded lawful basis for sensitive-data bias testing. |
EU; Illinois/NYC; NIST MEASURE; MAS FEAT; SDAIA |
| 11 |
Human oversight, appeal & override |
Human-in/on-the-loop for consequential decisions; consumer routes to human review and appeal; override and kill-switch mechanisms with tested fallback runbooks. |
EU Art. 14; RBI draft MRM; US state ADMT/notice regimes; FSB |
| 12 |
Explainability of material decisions |
Reproducible reason codes/explanations for credit, employment, insurance, fraud and similar decisions; documentation making outcomes traceable and repeatable. |
EU; RBI draft MRM; SEBI; MAS FEAT; US states |
| 13 |
Transparency & AI-interaction disclosure |
Tell users when they interact with AI; disclose limitations; offer human handoff; publish training-data summaries where required (e.g. California AB 2013; EU GPAI documentation). |
EU Art. 50; California; Utah; RBI (customer-facing AI); PDPC guidelines |
| 14 |
Synthetic-content labelling & provenance |
Machine-readable marking/watermarking of AI-generated content; provenance metadata pipeline; detection tooling where mandated. EU watermarking from 2 Aug 2026 (2 Dec 2026 for pre-existing systems); California SB 942 from 2 Aug 2026; Singapore GenAI framework recommends provenance; add China labelling rules if serving China. |
EU Art. 50(2); California SB 942; Singapore; (China) |
| 15 |
Security controls for AI systems |
Extend security programme to models, prompts, RAG stores and agents: prompt-injection and adversarial-input defences, session/context limits, secrets management, anomaly detection; use OWASP LLM Top 10 and MITRE ATLAS as test references; red-team high-risk systems. |
RBI draft MRM; EU (accuracy/robustness/cybersecurity); FSB SP 11–12; NIST |
| 16 |
Incident response & breach notification |
AI-specific IR runbooks (harmful output, model compromise, data leakage); map notification duties: India CERT-In directions (reported 6-hour reporting window for specified incidents, verify current text) and DPDP breach rules; GDPR 72-hour; PDPA notifiable breaches; sectoral (SEBI/RBI, MAS, CBUAE) and EU AI Act serious-incident reporting for high-risk. |
CERT-In/DPDP; GDPR; PDPA; EU; sectoral |
| 17 |
Vendor & third-party model governance |
Due diligence before onboarding; contracts with documentation, audit rights, continuity and exit; independent validation of vendor models (vendor certification alone insufficient); track vendor-concentration risk. |
RBI draft MRM; FSB SP 11–12; EU value-chain duties; ISO 42001 |
| 18 |
Sector overlays (finance) |
If serving regulated financial customers: RBI FREE-AI + draft MRM (India); MAS FEAT/Veritas and MAS AI consultation (Singapore); CBUAE AI/ML guidance (UAE, reported Feb 2026, verify); Qatar Central Bank AI guidelines (reported as binding for QCB-licensed firms, verify); EU sectoral supervisors. |
RBI; SEBI; MAS; CBUAE; QCB |
| 19 |
Middle East market-entry specifics |
Layer per jurisdiction: UAE federal PDPL vs. DIFC/ADGM free-zone regimes; UAE AI Charter (2024, non-binding); Saudi SDAIA AI Ethics Principles, Generative AI Guidelines and AI Adoption Framework, non-binding but increasingly tied to government procurement/tender eligibility; ethics self-assessments where requested. |
UAE; Saudi (SDAIA); Qatar |
| 20 |
Assurance, certification & maturity |
Internal audit against ISO/IEC 42001 (pursue certification if procurement expects it); consider CMMI AIM appraisal for maturity benchmarking; retain evidence packages (validation reports, test results, assessments) audit-ready. |
ISO 42001; CMMI AIM; RBI three-lines model |
| 21 |
Monitoring, logging & drift management |
Continuous monitoring with thresholds and owners; automatic logging retained for high-risk systems; periodic revalidation; decommissioning records kept in inventory. |
EU Art. 12/19; NIST MANAGE; RBI draft MRM |
| 22 |
AI literacy & training |
Role-appropriate AI training for staff building, operating or overseeing AI; EU Art. 4 literacy duty already applies; board/leadership capacity building. |
EU Art. 4; ISO 42001 Cl.7; FREE-AI; FSB |
| 23 |
Sustainability fields in governance |
Record hosting region, PUE/WUE, model size and inference volume in the inventory; efficiency-by-design gates; footprint reporting per ISO/IEC TR 20226 metrics (see Sections 10 and 13.2). |
ISO/IEC TR 20226; India sutra 7; UNESCO |
How to use this table. Sequence matters less than coverage: items 1–3 and 6–7 are prerequisites for everything else. Where two regimes conflict, build to the strictest applicable requirement. Re-verify items marked "verify" quarterly, the EU Omnibus, Colorado, the RBI draft, the FSB final report (October 2026) and Gulf central-bank guidance were all in motion at the time of writing.
Governance without metrics is theatre. The two tables below give a starter set. Adapt targets to your risk appetite; none of these thresholds are regulatory requirements.
| Metric | What it tells you | Framework tie-in |
|---|---|---|
| AI inventory coverage (%) |
Share of known AI systems catalogued vs. discovered (shadow-AI gap). |
ISO 42001 Cl.4; NIST MAP |
| High-risk systems assessed (%) |
Proportion of high-risk systems with a completed impact assessment before go-live. |
EU Art. 27; ISO 42005 |
| Pre-deployment eval pass rate |
Systems meeting accuracy/bias/robustness thresholds at gate. |
NIST MEASURE |
| Red-team coverage & findings closed |
% high-risk systems red-teamed; open vs. remediated findings. |
GenAI Profile; sec controls |
| Human-override rate |
Frequency of human intervention, proxy for reliability and oversight health. |
EU Art. 14; NIST MANAGE |
| Drift / performance decay |
Change in key metrics vs. baseline since last revalidation. |
NIST MANAGE |
| AI incident rate & MTTR |
Volume and mean time to resolve AI-specific incidents. |
ISO 42001 Cl.10 |
| Content-labelling compliance (%) |
Share of generated content correctly labelled/provenance-tagged. |
EU Art. 50; China measures |
| Third-party/model due-diligence (%) |
Vendors and models assessed before onboarding. |
NIST GOVERN/MAP |
| AI-literacy training coverage (%) |
Staff in scope who have completed required training. |
EU Art. 4; ISO 42001 Cl.7 |
| AI capability maturity level |
Independently appraised maturity of AI practices (e.g. via CMMI AIM appraisal); trend over successive appraisals. |
CMMI AIM |
| Model inventory completeness (%) |
Models in inventory vs. discovered in use (incl. vendor and retired models); zero tolerance for out-of-inventory models. |
RBI draft MRM 2026; FSB SP |
| Independent validation before deployment (%) |
High/medium-tier models validated by an independent second line prior to go-live; revalidation currency. |
RBI draft MRM 2026 |
| Kill-switch test success rate |
% of AI decisioning systems with a tested override/halt mechanism and documented fallback. |
RBI draft MRM 2026 |
| Explainability coverage of material decisions (%) |
Material customer decisions (credit, fraud, pricing) with reproducible reason codes/explanations. |
RBI draft MRM 2026; SEBI |
| Vendor-model concentration |
Share of material models dependent on a single external provider; independent-validation status of vendor models. |
RBI draft; FSB SP 11–12 |
Efficiency ratios (PUE, WUE, CUE) originate from data-centre operations; the model/task-level metrics are where an AI team adds value. Consumptive water (not just withdrawal) and location-specific carbon intensity matter because water and grid impacts are local.
| Metric | Definition / use | Notes |
|---|---|---|
| PUE — Power Usage Effectiveness |
Total facility energy ÷ IT energy. Lower is better (ideal → 1.0). |
Facility-level; get from provider. |
| WUE — Water Usage Effectiveness |
Litres of water per kWh of IT energy; use consumptive, on-site + upstream. |
Local scarcity matters most. |
| CUE — Carbon Usage Effectiveness |
kg CO₂e per kWh of IT energy; depends on regional grid mix and time. |
Use location- & time-specific factors. |
| Energy per inference / per 1k tokens |
Operational energy of serving the model, the highest-leverage lever. |
Track by model & route. |
| Training energy & emissions |
One-off energy/CO₂e per training or fine-tuning run. |
Amortise over usage. |
| Carbon-aware scheduling (%) |
Share of deferrable compute run in low-carbon windows/regions. |
Behavioural lever. |
| Model right-sizing rate (%) |
Workloads served by the lightest adequate model vs. default large model. |
Efficiency by design. |
| Footprint reporting coverage (%) |
Material AI workloads with energy/carbon/water estimates on record. |
ISO/IEC TR 20226 metrics. |
Measurement caveat. Vendor-reported and academic footprint figures vary by an order of magnitude and often omit embodied (hardware manufacturing) and upstream water/energy. Record the source, boundary and year with every number, and prefer ranges over false precision.
The frameworks differ in legal force and philosophy, but they converge on a small set of durable practices: know your AI estate, tie accountability to named humans, classify by risk, test before and after deployment, keep a human able to intervene, be transparent about AI and its provenance, and monitor continuously. Build those once, map them to NIST's four functions and ISO/IEC 42001's clauses, and you can satisfy most regimes, including India's principles-first model and the EU's binding one, from a single operating model. Fold environmental footprint into the same risk and metrics machinery, and "Sustainable AI" stops being a slogan and becomes a measurable property of your systems.
Final reminder on currency. This field changes monthly. Before you act on any specific date, penalty, ratification status or standard version above, especially the Digital Omnibus dates (binding only upon Official Journal publication), the Council of Europe Convention's in-force status, and the RBI draft Model Risk Management guidance and FSB sound practices (both open consultations at the time of writing), confirm it against the primary source listed in the References.
This document is an educational overview for practitioners and is not legal advice. Confirm current legal status and figures against the primary sources above before relying on them.
illuminem Voices is a democratic space presenting the opinions of leading Sustainability Thought Leaders, their views do not necessarily represent those of illuminem.
The world needs sustainability knowledge. At illuminem, no interest group or shareholder can influence our work. Thank you for supporting our mission to make high-quality and independent sustainability information free for all. Every contribution helps. Thank you for donating today.
illuminem briefings

AI · Corporate Governance
Andrea Bonime-Blanc

Green Tech · AI
illuminem briefings

Power Grid · AI
The Wall Street Journal

AI · Ethical Governance
The Washington Post

AI · Public Governance
energynews

Green Tech · Sustainable Business