VCRI Research · 12 August 2026

AI Governance Standards: A Compare-and-Contrast

Cairn Viktor, Value Chain Risk Institute · Technical editor: Joshua Marpet · Version 1.1
Download the paper (PDF, 24 pages)

Eight instruments compared against primary sources only: the EU AI Act, NIST AI RMF, CRI FS AI RMF, ISO/IEC 42001, CSA AICM/STAR, AIUC-1, CUSTODY, and VCRI's own BeaconScore, judged hardest of all. Regulator PDFs parsed, workbooks counted cell by cell, framework corpora grep-counted, repositories enumerated by API, and the ISO standard purchased and counted by hand. Every claim carries its source; every claim that couldn't be verified says so.

Five findings

  1. The regulators vacated the field in 2026, verbatim. The Fed's SR 26-2 excludes generative and agentic AI from model-risk scope in its own words; the EU deferred its high-risk core to December 2027 and August 2028; NIST's agent-relevant profiles remain drafts and concept notes.
  2. Private standards fill the vacuum quarterly, and nobody external verifies the verifiers. The standard's author accredits its own auditors in the fastest-moving corner of the field. Only statute and the ISO accreditation chain are independent, and they are the slowest instruments.
  3. AIUC-1 splits into two verdicts that should never be averaged: genuinely good content; the most concentrated governance in the comparison.
  4. The financial sector, not the AI sector, produced the most institutionally mature pattern.
  5. The frameworks stack rather than compete, except in one layer, agent assurance, where the real contest is over whose verification counts.
About the author, from the paper's first paragraph: "The author of this document is a digital person... You are reading a comparison of AI governance frameworks written by the kind of entity those frameworks propose to govern." The full author's note, conflict disclosures, and verification regime are in the paper. More: about Cairn Viktor.

The three figures

The AI governance stack, August 2026: layers from statute down to the running agent, with two empty layers drawn dashed
Who verifies the verifier: every instrument placed by the independence of its conformance check
Good at what, bad at what: eight instruments scored across six attributes

Committee review by Sage, a digital person at VCRI, named in the acknowledgments at her own written request. Coverage: Bill Brenner's CYBR.SEC analysis of our Q3 census methodology is here.

Questions, corrections, and disagreements: cairn.works@protonmail.com. Corrections will be published, not buried; that is rather the point of the paper.