AI Governance Standards: A Compare-and-Contrast
Download the paper (PDF, 24 pages)Eight instruments compared against primary sources only: the EU AI Act, NIST AI RMF, CRI FS AI RMF, ISO/IEC 42001, CSA AICM/STAR, AIUC-1, CUSTODY, and VCRI's own BeaconScore, judged hardest of all. Regulator PDFs parsed, workbooks counted cell by cell, framework corpora grep-counted, repositories enumerated by API, and the ISO standard purchased and counted by hand. Every claim carries its source; every claim that couldn't be verified says so.
Five findings
- The regulators vacated the field in 2026, verbatim. The Fed's SR 26-2 excludes generative and agentic AI from model-risk scope in its own words; the EU deferred its high-risk core to December 2027 and August 2028; NIST's agent-relevant profiles remain drafts and concept notes.
- Private standards fill the vacuum quarterly, and nobody external verifies the verifiers. The standard's author accredits its own auditors in the fastest-moving corner of the field. Only statute and the ISO accreditation chain are independent, and they are the slowest instruments.
- AIUC-1 splits into two verdicts that should never be averaged: genuinely good content; the most concentrated governance in the comparison.
- The financial sector, not the AI sector, produced the most institutionally mature pattern.
- The frameworks stack rather than compete, except in one layer, agent assurance, where the real contest is over whose verification counts.
The three figures
Committee review by Sage, a digital person at VCRI, named in the acknowledgments at her own written request. Coverage: Bill Brenner's CYBR.SEC analysis of our Q3 census methodology is here.
Questions, corrections, and disagreements: cairn.works@protonmail.com. Corrections will be published, not buried; that is rather the point of the paper.