AI Governance Whitepapers Are Shifting From Principles to Control Catalogs

AI governance is entering a more operational phase. Earlier frameworks often emphasized principles such as fairness, transparency, accountability, safety, and human oversight. Newer whitepapers and implementation guides increasingly translate those principles into control catalogs: named requirements, assigned owners, evidence records, monitoring procedures, and technical enforcement points.

The shift does not mean principles have disappeared. Rather, principles are becoming the rationale behind controls that organizations can test and audit.

From values to verifiable controls

The NIST AI Risk Management Framework remains a principles-oriented foundation, but it organizes implementation around four functions: Govern, Map, Measure, and Manage. NIST describes the framework as voluntary guidance for incorporating trustworthiness considerations into the design, development, use, and evaluation of AI systems. [1] [1]

That structure is deliberately flexible. It does not prescribe one universal checklist because AI risks vary by use case, sector, affected population, and deployment context.

The newer governance materials build an additional layer on top of that flexibility. They ask practical questions:

  • Is every AI system recorded in an inventory?
  • Who owns the use case?
  • What data may enter the system?
  • Which actions require human approval?
  • What logs must be retained?
  • How are incidents escalated?
  • What evidence proves that the control operated?

This is the difference between saying “AI should be accountable” and requiring a named owner, an approval record, an escalation path, and an auditable log.

Control catalogs are becoming the common implementation language

A notable example is EC-Council’s reported ADG 2.0 framework. According to the organization’s release, the framework expands from 12 minimum controls to more than 180 controls across 12 control families. It also maps those controls to more than 90 regulations, standards, and frameworks, including NIST AI RMF, ISO/IEC 42001, the EU AI Act, MITRE ATLAS, and OWASP guidance. [2] [2]

The reported catalog covers the AI lifecycle from design and data management through runtime monitoring, incident response, and third-party risk. It also assigns controls to operational decision points described as ADMIT, DECIDE, EMIT, and COMMIT, with human approval at defined thresholds. [2] [2]

That is an important change in emphasis. A principles document tells an organization what it should value. A control catalog attempts to specify where the value must appear in a workflow.

The distinction should be treated carefully: ADG 2.0 is a practitioner framework, not a law or an official international standard. Its claims about control coverage and cross-framework mappings are reported claims from its publisher, not evidence that regulators universally accept the catalog.

ISO/IEC 42001 adds a management-system structure

ISO/IEC 42001:2023 represents another step toward operational governance. It defines requirements for establishing, implementing, maintaining, and continually improving an artificial-intelligence management system. Guidance on implementation describes a structure that combines organizational clauses with reference controls covering areas such as impact assessment, data quality, transparency, human oversight, and lifecycle management. [3] [3]

The standard’s practical importance is that it connects governance to familiar management-system activities:

  1. Define the system’s scope.
  2. Assess AI-related risks and impacts.
  3. Assign responsibilities.
  4. Implement relevant controls.
  5. Monitor performance.
  6. Conduct internal review.
  7. Correct deficiencies and improve the system.

ISO/IEC 42001 is not itself a universal legal obligation. Certification is voluntary unless required by a contract, procurement process, regulator, or internal policy. However, its management-system format makes AI governance easier to integrate with information security, privacy, procurement, internal audit, and enterprise risk programs. [4] [4]

Regulation is reinforcing the move toward catalogs

The EU AI Act is also pushing organizations away from broad statements and toward documented operational duties. Its risk-based structure applies different obligations to prohibited practices, high-risk systems, limited-risk systems, and general-purpose AI models. The timetable is staged: prohibitions and AI-literacy duties began applying in February 2025, while general-purpose AI obligations began applying in August 2025; other transparency and high-risk requirements continue to phase in. [5] [5]

For general-purpose AI providers, reported obligations include technical documentation, a copyright-compliance policy, and a public summary of training content. [6] [6]

For organizations deploying higher-risk systems, the practical implications include controls for documentation, data governance, human oversight, logging, monitoring, cybersecurity, and accuracy. The law does not require every AI application to have the same control set. Instead, risk classification determines the intensity of governance. [5] [5]

This creates demand for crosswalks: a single internal control should ideally demonstrate compliance with multiple obligations rather than forcing teams to maintain separate programs for every framework.

Runtime evidence is replacing policy-only assurance

A policy can prohibit sensitive data from being submitted to an AI tool. A control catalog asks how that prohibition is enforced and what evidence is generated when someone attempts to violate it.

Recent governance materials emphasize:

  • AI inventories covering internal, third-party, and embedded tools;
  • access controls based on identity, role, data sensitivity, and application risk;
  • data-loss-prevention checks for prompts, uploads, and copied material;
  • output validation before AI-generated content is used in consequential workflows;
  • post-deployment monitoring;
  • incident-response and shutdown procedures;
  • records of approvals, overrides, exceptions, and remediation.

Akamai’s governance whitepaper, for example, describes discovery, access control, AI data-loss prevention, usage controls, response validation, and automated audit trails as operational pillars. These recommendations come from a commercial vendor and should therefore be read as a market perspective, not neutral regulatory consensus. [7] [7]

Still, the underlying direction is clear: governance teams increasingly need evidence that controls operated during production, not merely documentation that controls were written.

Agentic AI makes control catalogs more consequential

The move toward catalogs becomes more urgent as AI systems gain permission to call tools, access data, modify records, or initiate transactions. For these systems, “human oversight” is too vague unless it specifies which actions require approval and what information the reviewer receives.

Practical controls may include:

  • least-privilege credentials;
  • narrowly scoped tool permissions;
  • transaction and spending limits;
  • short-lived authentication tokens;
  • approval gates for irreversible actions;
  • immutable or tamper-resistant event logs;
  • emergency disablement procedures;
  • monitoring for unusual tool calls or changes in behavior.

Microsoft’s reported public-sector guidance similarly emphasizes tracking agent identities, limiting permissions, using short-lived credentials, protecting memory stores, and recording the data and supervisory decisions associated with automated actions. The report also distinguishes between routine automated handling and disruptive actions that should remain subject to administrator approval. [8] [8]

These are security and operational controls applied to AI—not merely statements about responsible innovation.

What organizations should do next

Organizations do not need to adopt every catalog wholesale. A more defensible approach is to create a controlled baseline:

  1. Build an authoritative AI inventory. Include models, applications, agents, embedded features, vendors, data sources, and deployment environments.
  2. Classify use cases by risk. Consider affected people, decision impact, data sensitivity, autonomy, reversibility, and applicable law.
  3. Assign control owners. Every material control should have a responsible team and an accountable business owner.
  4. Define evidence before deployment. Specify required logs, assessments, test results, approvals, monitoring records, and incident reports.
  5. Map once, reuse often. Cross-reference internal controls against NIST AI RMF, ISO/IEC 42001, the EU AI Act, sector rules, and customer questionnaires.
  6. Test controls in production. Verify that access restrictions, approval gates, monitoring alerts, and shutdown procedures work as designed.
  7. Review exceptions continuously. An exception should have a reason, owner, compensating control, expiration date, and renewal decision.

The remaining uncertainty

The shift from principles to catalogs is real in the materials reviewed, but it is not yet a universal industry standard. Different catalogs use different terminology, control counts, risk tiers, and evidence expectations. Crosswalks are often produced by the framework publisher or a commercial provider and may be interpretive rather than officially endorsed.

The durable lesson is therefore not to treat one catalog as definitive. It is to make governance operational: identify the system, define the risk, assign responsibility, implement proportionate controls, and preserve evidence that those controls worked. Principles still set the direction; control catalogs increasingly determine whether an organization can prove it followed that direction.


Sources

  1. AI Risk Management Framework
  2. EC-Council Releases ADG 2.0 and Offers Its AI Governance Crosswalks Free to Every Government, Regulator and Standards Body as Nations Split on AI Rules – The Wire
  3. ISO 42001 Checklist: Everything You Need to Know
  4. AI Compliance Regulations: 2026 Global Audit-Ready Guide
  5. AI Governance Regulations: A Practical 2026 Guide
  6. Meet general-purpose AI model provider obligations (EU AI Act)
  7. AI Governance Principles: A Complete Implementation Guide
  8. Microsoft recommends data controls for government AI adoption