The Global Infrastructure for AI Governance

AIGN.Global | AI Governance for KRITIS & Defence
2,200+members in 50+ countries
30+ambassadors, 4 regional hubs
18+DOI-registered publications
8governance layers in AIGN OS 4.0
Invited speaker · NATO SPS ARW 2026

Documented: keynote and round table co-chair at the Advanced Research Workshop on early warning for critical infrastructure, Yerevan (September 2026) · first AIGN Education Trust Label in Asia (Seoul, September 2025) · AIGN OS 3.0 report on Zenodo (April 2026)

Sectors

Where machine authority meets critical infrastructure.

Choose your sector to see the authority question that matters most, what has to be governed, and where AIGN helps. The approach is not limited to the legal KRITIS definition: what counts is the consequence a system can have for operations, customers, supply, safety and society.

Energy & utilities

“Which optimisation decisions may AI take autonomously, and where must a technical or human boundary always take precedence?”

What to govern

  • Optimisation goals set against safety, resilience and supply requirements
  • Non-overrideable boundaries and fail-safe logic
  • Human intervention and incident evidence that stand up to audit

Frameworks in play

NIS2EU AI ActSector rules

Water & wastewater

“Which control actions may an AI-supported system trigger in supply or treatment, and who can stop it, and how fast?”

What to govern

  • An authority envelope for control actions in supply and treatment
  • Runtime limits and escalation thresholds
  • Reconstructable action evidence after an incident

Frameworks in play

NIS2EU AI ActSector rules

Transport & mobility

“What may an AI system change in scheduling, routing or traffic control without human confirmation?”

What to govern

  • A mandate and an owner for every automated change
  • A clear line between planning support and operational control
  • Re-approval when tools, data or integrations change

Frameworks in play

NIS2EU AI ActSector rules

Telecom & digital infrastructure

“Which network, access and incident-response actions may an agent take, and under whose mandate?”

What to govern

  • Agent identity, permissions and tool access
  • Separating what an agent can see from what it can change
  • Credential rotation and revocation when agents change or retire

Frameworks in play

NIS2GDPREU AI Act

Financial infrastructure & payments

“At what point does a recommendation become financial authority to act?”

What to govern

  • Transaction authority limits and human escalation
  • Runtime controls and re-approval when rights expand
  • Action evidence for supervisors and audit

Frameworks in play

DORANIS2EU AI ActGDPR

Healthcare & emergency services

“Which decisions stay reserved to humans, and can an AI-supported decision be reconstructed afterwards?”

What to govern

  • Human reserved decisions and escalation paths
  • Traceability of inputs, outputs and interventions
  • Oversight design that works under time pressure

Frameworks in play

NIS2GDPREU AI Act

Public services & administration

“Who is accountable when an AI-supported decision reaches a citizen?”

What to govern

  • Named human accountability for every delegated task
  • Fundamental-rights impact and explanation paths
  • Procurement evidence for AI suppliers

Frameworks in play

NIS2GDPREU AI Act

Space & earth observation

“Who holds authority over AI-supported sensing, tasking and early warning derived from satellite data?”

What to govern

  • Authority boundaries between analysis, alert and action
  • Trusted use of shared data across organisational and national borders
  • Evidence chains for early-warning decisions

Frameworks in play

NIS2EU AI ActData-sharing frameworks

Context: the 2026 NATO SPS workshop in Yerevan, where AIGN gave a governance keynote, covered aerial, unmanned and satellite sensing and AI-driven earth observation for early warning.

Defence & dual use

“Which decisions must remain reserved to humans, and how is delegated machine authority bounded, interrupted and evidenced?”

What to govern

  • Human reserved authority and intervention design
  • Runtime enforcement, revocation and change control
  • Evidence that holds up under independent challenge

Frameworks in play

Sector and national rulesAIGN Critical OS as reference architecture

AIGN works on governance, accountability and evidence, not on weapon systems or operations. Participation in a NATO SPS workshop does not constitute NATO endorsement of AIGN.

Illustrative governance questions, not client cases. Whether an organisation or system is legally classified as critical infrastructure depends on national law and should be checked against the current legal texts.

Organizations & Solutions

AI governance for critical systems, built to run in operations.

For operators of critical infrastructure (KRITIS), defence and dual-use organisations, regulated enterprises and the boards that oversee them. AIGN Critical OS carries authority governance into the runtime. AIGN OS 4.0 is the foundation, AIGN360 operates it, the Trust Label proves it and the Intelligence Hub keeps it current.

Where governance starts

Which AI systems in your critical processes exist, what may each of them decide or do, and can you prove it?

Capability is what a machine can do. Authority is what an organisation permits it to do.
AIGN Critical OS 1.4

As long as AI only produces information, governance can focus on model quality, data, approval and human review. Once AI receives identities, permissions, tools, APIs, communication channels or access to operational systems, the question changes: the system now holds practically effective machine authority, the ability to trigger consequences within or on behalf of an organisation. AIGN Critical OS extends AIGN OS to critical and high-consequence environments and carries authority governance into the runtime.

Scope: a governance reference architecture. It does not replace safety engineering, cybersecurity, legal review, certification or assurance. The full reference work (80+ pages) is not public; a compact executive preview is.

Nine control points, from mandate to retirement

01MandateWhich legitimate organisational assignment does the system fulfil, and which decisions or actions are explicitly part of it?
02IdentityUnder which technical and organisational identity does it act, and can actions be attributed to system, agent and mandate?
03Authority envelopeWhich data, tools, APIs, systems, channels, transactions and consequences may the AI reach?
04Human accountabilityWhich named human role approves the mandate, owns the limits, receives escalations and can change or withdraw authority?
05Runtime enforcementWhich limits, rules, thresholds and approvals act during operation, not only on paper?
06Human interventionWhen must a person take over, slow down, stop or decide, and is that technically and organisationally possible?
07EvidenceCan relevant decisions, actions, interventions, approvals and consequences be reconstructed later?
08Change controlWhich model, tool, permission, data or architecture changes alter the authority profile enough to require a new decision?
09Revocation & retirementHow are mandates, identities, credentials and permissions reliably withdrawn when an agent changes, is replaced or ends?
Enterprise AI governance vs critical AI governance

The more serious the possible consequence of a machine decision, the further governance has to reach from the document into actual system behaviour.

Enterprise AI governance
Critical AI governance
AI use case
Consequence and operational reach
Policy
Runtime enforcement
Risk classification
Authority boundary
Human oversight
Human intervention and override
Initial approval
Continuous authority control
Logging
Reconstructable action evidence
Model governance
Governance of the whole system of action
Compliance evidence
Operational defensibility
When governance becomes a critical control question eight triggers

A system does not have to be fully autonomous to hold relevant machine authority. Single permissions, automations or chained decisions can already have considerable operational effect.

  • Production system access: ERP, CRM, payment, infrastructure or communication systems.
  • Tool and API use: agents or workflows call tools, start processes or address external services on their own.
  • Transactions and communication: orders, payments, messages or approvals are prepared or triggered.
  • Critical operational processes: disruption could affect operations, customers, safety or supply.
  • Compressed human oversight: people supervise chains of machine decisions instead of checking every case.
  • Dynamic authority: new models, tools, data sources or integrations change actual permissions faster than policies.
  • Third-party dependency: foundation models, agent platforms, cloud APIs and tool connections become part of the authority chain.
  • High-consequence failure: an error can cause more than lost productivity.
From executive oversight to runtime authority

Executive layer

Materiality, risk appetite, decision rights, investment decisions, governance mandates, reporting, assurance and escalation.

Operational layer

Identities, permissions, tools, APIs, transactions, limits, overrides, human intervention, action evidence and revocation.

The gap to close: what management and boards approve must match what the system can technically do in operation.
Authority is not static re-approval triggers
TriggerModel changeA model swap or a material change in behaviour can alter the governance assumption.
TriggerAuthority changeNew APIs, tools, systems, transaction rights, data or communication paths widen operational reach.
TriggerOrganisational changeReorganisation, carve-out or acquisition must be followed in machine authority too.
TriggerRisk and incident changeIncidents, near misses, new dependencies or higher autonomy can require a new decision.

Sectors

No governance without classification. No defensibility without evidence. No trust without a system that can show why an AI system was classified, controlled and certified in a specific way.
— AIGN OS 4.0 · May 2026

AIGN OS 4.0 helps organisations classify AI systems before compliance, audit and liability questions arrive. It translates the EU AI Act, GDPR, ISO/IEC 42001, NIS2, DORA and other frameworks into operational controls, clear roles and auditable evidence, and it is delivered as modules that each produce concrete governance artefacts.

8
Governance layers
12
Evidence dimensions
8
Implementation phases
2026–28
AI Act window
The eight-layer architecture
Layer 1Organizational Interface
Roles, accountability, AI officer interfaces, RACI, board reporting and escalation ownership.
Layer 2Governance Kernel
Lifecycle logic, autonomy boundaries, governance reflexes and escalation principles.
Layer 3Classification & Regulatory Pathway
AI qualification, prohibited-use screening, Article 50, high-risk mapping, GPAI, FRIA, EU registration and responsibility mapping.
Layer 4Compliance Engine
Triggered obligations become controls, documentation, DPIA+, monitoring and operational requirements.
Layer 5Framework Modules
Global, SME, Education, Agentic AI, Data and Culture modules translate the OS into context.
Layer 6Governance Toolchain
Registers, evidence bundles, incident scripts, monitoring logs and technical documentation.
Layer 7Maturity & ASGR
Classification readiness, maturity scoring and systemic governance capability measurement.
Layer 8Trust & Certification
Trust Labels, audit scorecards, certification registry, evidence packages and external verification readiness.
Six entry modules from board briefing to operating model
Entry · BoardsExecutive Briefing
A 90–120 minute board-level session on classification, accountability, evidence and the 2026–2028 window. Includes a classification risk overview and management-ready next steps.
CoreAI System Classification Sprint
Classify 5–20 AI use cases: AI system register, prohibited-use and transparency gates, Annex I/III mapping, responsibility map and evidence bundle.
ProcurementVendor AI Governance Review
Assess AI suppliers before procurement, contract renewal or integration into critical workflows: evidence questionnaire, intended purpose, provider/deployer shift, contract risk questions.
Fundamental rightsFRIA & DPIA Integration Pack
Connect the AI Act fundamental-rights impact assessment with GDPR DPIA logic and an affected-person explanation path.
High-riskTechnical Documentation & Conformity Pack
Conformity assessment pathway, technical documentation gate, data governance evidence sheet and human oversight design record.
Operating modelAI Governance Operating Model Sprint
Role architecture, control ownership, evidence infrastructure, escalation and reporting paths, built around classification logic.

Also available as an enterprise licence for internal use, as a partner licence for implementation partners, and as preparation for Trust Label readiness.

Twelve evidence dimensions

The evidence base for boards, auditors, procurement teams, regulators and trust-label readiness.

  • Classification completeness: every material system has a documented classification path.
  • Intended purpose clarity: purpose, context, users and restrictions are documented.
  • Responsibility mapping: provider, deployer and value-chain roles are clear.
  • Provider shift risk: rebranding, modification and repurposing are assessed.
  • Evidence bundle quality: the classification rationale is reconstructable.
  • Review discipline: reclassification triggers and review cycles are active.
  • Board reporting: leadership sees the evidence required for oversight.
  • Prohibited-use clearance: Art. 5 screening is completed before high-risk logic.
  • FRIA readiness: fundamental-rights impact obligations are identified.
  • Transparency status: Article 50 disclosure duties are assessed.
  • EU database status: registration obligations are mapped and evidenced.
  • Post-market evidence: monitoring, incidents and corrective actions are recorded.
The eight-phase route discovery to defensible trust
Phase 1DiscoveryAI systems, agents, vendor systems, shadow AI, high-impact workflows.
Phase 2ScreeningProhibited AI gate and Article 50 transparency gate before high-risk assessment.
Phase 3Purpose captureIntended purpose, operational use, limitations, decision influence.
Phase 4ClassificationAnnex I, Annex III, safety component logic, GPAI dependency, filter pathways.
Phase 5ResponsibilityProvider/deployer roles, FRIA triggers, EU database registration.
Phase 6Control triggeringCompliance controls and frameworks activated by classification outcome.
Phase 7Evidence & trustClassification evidence bundle, readiness score, trust pathway.
Phase 8MonitoringDrift, incidents, model updates, vendor and regulatory change; reclassification.
Who it serves
Boards & audit committees
Which AI systems are material, how they were classified, who is accountable and what evidence exists today.
Legal, risk & compliance
AI Act classification, Article 50, FRIA, data governance and provider/deployer roles translated into operational controls.
Procurement & vendor management
Vendor AI systems assessed before purchase, integration or scaling.
AI officers & governance leads
A practical model with registers, evidence bundles, monitoring logs, incident records and reporting routines.
HR, EdTech & high-impact functions
Sensitive use cases where AI affects people, opportunity, access, performance or assessment.
SaaS, AI vendors & product teams
Product evidence, intended-purpose clarity, documentation, conformity pathway decisions and trust readiness.
Editions and further components
AIGN OS for Governments
National AI governance infrastructure: translating international rules into national standards, coordinating ministries, operationalising governance in institutions and making it visible to citizens through trust labels. Benchmarked with the ASGR Index.
Open
AIGN EOS · Education
The Education Operating System for AI decisions affecting children. Covered under Network & Education.
Go to tab
Guided Installer
The guided route to installing an AI governance operating system.
Open
Global AI Governance Reference Model
The Global AI Governance Reference Model.
Open
Runtime Economic Governance
Governing AI cost, usage and value in the token economy. Also the subject of a Zenodo paper and the book Governing Outsourced Intelligence.
Open
AI Agent Classification
An assessment for classifying AI agents.
Open
Control Center
AI governance oversight, controls and evidence management.
Open

AI governance as an operated function.

AIGN360 turns AI governance from a policy project into a continuously operated function. It controls AI use cases, responsibilities, evidence, reviews, vendors, risks and regulatory expectations across business, legal, compliance, IT, data, HR, procurement and the boardroom. It is a monthly managed service with a defined scope, not open-ended consulting.

Design
AIGN OS Design
For organisations that need a robust operating model before scaling AI use.
  • Use case and governance baseline
  • Role, responsibility and forum design
  • Policy-to-process translation
  • Evidence and documentation architecture
  • Roadmap into managed operation
Core model · Operate
AIGN360 Operate
For organisations that need governance to run continuously, not only exist on paper.
  • Recurring governance reviews
  • Control and documentation maintenance
  • Regulatory mapping and change tracking
  • Audit readiness and evidence support
  • Risk, issue and escalation management
Lead
AIGN360 Lead
For companies that need senior external AI governance leadership without building a full internal team.
  • Fractional AI governance leadership
  • C-level and board-level decision support
  • Prioritisation of critical AI risks
  • Cross-functional stakeholder steering
  • Defensibility under regulatory pressure

Engagements can start with Design and move into Operate. Scope is defined in onboarding.

The governance logic

Step 1ExposeMake AI use cases, systems, data flows, vendors, decisions and ownership visible.
Step 2ClassifyMap regulatory relevance, risk level, business criticality and control requirements.
Step 3DesignDefine roles, forums, workflows, evidence standards, oversight and escalation.
Step 4OperateRun recurring reviews, maintain documentation, monitor change, manage exceptions.
Step 5DefendEvidence why a system was approved, controlled and is still fit to operate.
Entry products focused, time-boxed starting points
AI Governance Roadmap Sprint 2026–2028
EU AI Act readiness and implementation.
Open
Risk Quantification Quick Scan
Quick scan for quantifying AI governance risk.
Open
EU AI Act Transparency Briefing 2026
Article 50 readiness and AI disclosure.
Open
Candidate Fit Assessment
Talent, skills and role readiness for AI governance roles.
Open

Descriptions follow the page titles. Scope and detail are on each page.

Who it is for
Board & C-levelLegal & complianceIT, data & securityHR & peopleProcurementRisk & auditSMEsBanking, insurance, healthcare, energy, public sector, critical infrastructure
Regulatory scope

AI governance does not happen in one regulation. AIGN360 connects it with data protection, cyber resilience, operational risk, sector regulation, vendor governance and audit expectations.

EU AI ActGDPRISO/IEC 42001NIS2DORAEU Data ActData Governance ActNIST AI RMFOECD AI PrinciplesSector rules
Governance Reality Check interactive self-assessment

Five sliders (visibility, accountability, control, evidence, resilience) indicate whether Design, Operate or Lead is the relevant entry point. It is a practical signal, not a legal assessment.

Open the check on the AIGN360 page

Make AI governance visible, evidence-based and defensible.

The AIGN Trust Label is a visible trust signal for customers, partners, boards and audit-facing processes, based on the AIGN OS reference architecture and aligned with the EU AI Act, ISO/IEC 42001, GDPR, NIS2 and DORA.

What it is not: the AIGN Trust Label is AIGN’s own private governance label. It is not a legal certification, a regulatory approval, an accreditation by an independent body, or a substitute for statutory audits.

The labels

Enterprises · Public sectorTrust Label Certified
The flagship signal. Full assessment across eight dimensions, 25+ governance criteria, regulatory mapping, public verification page, digital badge and seal, 12-month validity.
Regulated sectors · Critical infrastructureTrust Label Excellence
Extended assessment with 50+ criteria: AI risk and fundamental rights assessment, model inventory and lifecycle review, third-party governance review, board-level defensibility report, surveillance reviews.
Schools · UniversitiesEducation Trust Label
Adapted to education: AI usage and ethics framework, student protection, teacher and staff enablement, institutional oversight. See Network & Education. Go to tab
AI vendors · SaaS · PartnersVendor Trust Label
A structured review for vendors selling into enterprise procurement: AI system transparency, data and input governance, risk and control logic, human oversight, documentation, customer enablement, regulatory mapping and operational maturity. Outcome: approved, conditional or not yet ready. Annual re-validation. Buyers can commission a vendor portfolio review.
SMEsTrust Readiness
An entry tier for first governance visibility: light assessment, initial use case review, readiness badge and verification page.
What is verified eight governance dimensions
  • AI system inventory & classification: documented inventory, risk classification, scope.
  • Governance roles & accountability: RACI, governance bodies, escalation paths, reporting lines.
  • Risk & impact assessment: including fundamental rights impact where applicable.
  • Human oversight & escalation: human-in-the-loop mechanisms and override pathways.
  • Documentation & decision logs: traceable model documentation and audit-relevant logs.
  • Vendor & third-party governance: external providers, foundation models, contractual safeguards.
  • Incident, monitoring & change management: drift detection, incident response, managed change.
  • Board reporting & defensibility: reporting cadence, documented diligence, evidence packages.
Process scope, assess, validate, award, sustain
Step 1ScopeAI use cases, systems, vendors, regulatory exposure, assessment boundary.
Step 2AssessMaturity assessment against AIGN OS: documents, interviews, control mapping.
Step 3ValidateEvidence review, gap analysis, validation of controls and accountability.
Step 4AwardDecision on documented criteria, label issuance, public listing, digital seal.
Step 5SustainSurveillance reviews, regulatory updates, reassessment after 12 months.

Corporate labels: typically 8–12 weeks from scope to award. Each engagement starts with a scoping conversation and an individual proposal.

Why organisations ask for it
  • Auditors expect evidence. Policies alone are not enough; audit-facing processes need traceable controls, decision records and accountability paths.
  • Customers ask the question. “How do you govern your AI?” is becoming standard in RFPs, procurement and B2B contracts.
  • Boards need defensibility. Documented diligence protects leadership under the EU AI Act, NIS2 and sector rules.

From AI signal to governance action.

Regulation changes, vendor platforms evolve, agents enter workflows, industries differ, departments need different actions and boards need evidence. The Intelligence Hub gives each of these questions its own entry point: the Briefing explains what changed, the Index measures readiness, the Radars monitor exposure, and the Board & Audit Radar turns it into defensible oversight.

MonthlyAI Governance Briefing
What changed and what does it mean now? Monthly interpretation, priority signals, executive summary and action recommendations.
Open
ReadinessAIGN ASGR Index
How mature and ready are we? Systemic readiness and maturity view, governance gap profile and development over time.
Open
Radar · SectorIndustries Radar
How does exposure differ by industry? Banking, healthcare, insurance, public sector, manufacturing, energy, software, consulting and others.
Open
Radar · FunctionFunctional Radar
Which department must act? Legal, compliance, risk, IT, HR, finance, procurement, internal audit, marketing, sales and operations: action backlog and evidence needs.
Open
Radar · TechnologyTechnology Radar
Where does AI enter systems and workflows? Enterprise platforms, agents, Microsoft Copilot, SAP AI, chatbots and data-driven workflows.
Open
Radar · BoardBoard & Audit Radar
What must leadership be able to defend? Board briefing, audit questions, evidence expectations and defensible management decisions.
Open
The ASGR Index readiness as a measurable score

The ASGR is AIGN’s monthly benchmark of governance readiness. It looks at real governance infrastructure rather than opinions: regulation and legislation, institutional governance frameworks, certification and trust labels, and market behaviour and risk signals. Governments, enterprises and institutions can compare their readiness against a reference operating system. The underlying paper is DOI-registered (see Research & Cooperation).

The AI Governance Gap Brief monthly LinkedIn newsletter

One structural gap between how organisations deploy AI and how governance, accountability and regulation actually work, per issue. 34 issues, 3,100+ subscribers. No framework theory, no generic advice.

Latest · Issue #34: Identity Is Not Authority. Agent identity systems are maturing, but they do not answer what a machine was actually authorised by the organisation to decide, do and cause.
Research & Cooperation

Governing machine authority in high-consequence systems.

Applied research on machine authority, defensible autonomy and AI governance in critical infrastructure, early warning and other high-consequence environments: from governance principles to operational models for AI-enabled systems that can inform, decide and act. AIGN Research studies the authority, accountability and evidence structures needed to govern them, connecting AI governance, operational risk, technical control mechanisms and institutional oversight.

The research question

Under what conditions may an AI-enabled system act without real-time human confirmation, while human accountability remains clearly anchored?

Area 1
Machine authority and defensible autonomy
How the authority of an AI-enabled system is granted, bounded and controlled.
  • Operational mandates
  • Delegated authority and authority boundaries
  • Human accountability anchors
  • Evidence of authorised behaviour
Area 2
AI governance in critical infrastructure
How governance operates where AI-supported decisions may have physical, societal or systemic consequences.
  • Monitoring and early warning
  • Escalation and human intervention
  • Accountability for consequential actions
Area 3
Runtime governance and evidence
How governance requirements stay effective while systems operate.
  • Policy enforcement and monitoring
  • Intervention mechanisms
  • Logging and auditability
  • Reconstruction of consequential system actions
Area 4
Cross-border and cross-sector governance
How AI-enabled systems are governed when data, decisions and consequences cross organisational, sectoral or national boundaries.
  • Distributed accountability
  • Institutional coordination
  • Shared operational authority
From research to reference architecture AIGN Critical OS

The research feeds AIGN Critical OS, a governance reference architecture for critical systems (mandate, identity, authority envelope, human accountability, runtime enforcement, human intervention, evidence, change control, revocation). A compact executive preview is public.

Public executive preview (PDF)
Projects and collaborations

AIGN Research develops applied research projects together with academic and practice partners. Project descriptions, partners and results are published once they have been agreed with the participants.

Advanced Research Workshop, Yerevan.

Patrick Upmann presenting at the Advanced Research Workshop in Yerevan, September 2026
Patrick Upmann presenting at the Advanced Research Workshop in Yerevan, September 2026. The workshop is supported by the NATO Science for Peace and Security Programme.

14–19 September 2026, Yerevan State University, Armenia. AI-Powered Monitoring Systems, Regional Data Sharing, and Models for Early Warning in Critical Services and Infrastructure.

Keynote · 16 September · Session 2.2, Governance and trust frameworks“From innovation to implementation — building governance frameworks for AI in critical sectors”
Round table co-chair · 17 September“Toward a regional data-sharing framework for critical infrastructure”, with Prof. Ramaz Kvatadze (GRENA, Georgia)

Organised by the CenTRiS Foundation (Armenia) and the University of Calabria (Italy), with NATO SPS support under grant ARW.G9376. A documented speaking engagement; it does not constitute NATO endorsement of, or funding for, AIGN Research. View the workshop programme

Workshop scope three pillars and intended outcomes
Pillar 1AI-powered monitoringSensing, digital twins and IoT for real-time structural health and anomaly detection across energy, water and transport.
Pillar 2Regional data sharingSecure, sovereignty-respecting frameworks and privacy-enhancing technologies for trusted cross-border data exchange.
Pillar 3Early warning modelsPredictive models for multi-hazard, cascading-failure scenarios.

The programme also includes sessions on aerial, unmanned and satellite sensing and on AI-driven earth observation for early warning and resilient critical infrastructure. Intended outcomes named by the organisers: policy recommendations, a collaborative research agenda and a roadmap for a follow-on NATO SPS Multi-Year Project.

Further speaking engagements
2025TRT World Forum
Istanbul, Turkey. Invited speaker on AI governance as global infrastructure.
2025Direct Booking Summit
Mexico City, Mexico. Keynote on AI governance in the hospitality industry.
202637th EBS Symposium
EBS University, Germany. Invited to the economic symposium for business, law and leadership.
20265th Fintech Week Frankfurt
Frankfurt am Main. Speaker and panelist: “AI Governance, Risk & Regulation: From Black Box to Explainable Finance”.

Verifiable work, labelled by type.

Selected publications by Patrick Upmann, research lead of AIGN Research. Outputs are labelled by type; peer review is stated only where it has taken place.

18+
DOI-registered publications
SSRN
Zenodo · ORCID
2026
AIGN Runtime Economic Governance: Governing AI Cost, Usage and Value in the Token Economy
Zenodo · AIGN
2026
The Control–Liability Paradox in AI Governance: Where AI Liability Actually Begins
Zenodo · Report
2026
The Geopolitics of AI Governance — AI Governance as a Geopolitical Infrastructure
AIGN Global · Preprint
2026
Operationalizing Responsible AI: A Systemic AI Governance Architecture for Organizational Implementation
AIGN Global · Report
Show all publications
2026
AIGN OS 3.0 – The Operating System for Defensible AI Governance
Zenodo · Report (April 2026)
2026
AIGN EOS: Education Operating System for Trustworthy AI Decisions Affecting Children
Zenodo · Preprint
2026
AI Slop in the Enterprise: Synthetic Knowledge Amplification and the Governance of Organisational Knowledge Infrastructures
AIGN OS Research
2025
AIGN OS — AI Agents: The AI Governance Stack as a New Regulatory Infrastructure
SSRN · Working Paper
2025
AIGN OS — Trust Infrastructure: Certification, Licensing, and Market Enforcement for Responsible AI
SSRN · Working Paper
2025
AIGN — Procurement Governance Gate
Zenodo · Working Paper
2025
The AI Navigation Gap: A Cross-Domain Analysis of Why Modern Organizations Cannot Form a Unified Future Logic
Zenodo · Working Paper
2025
AIGN OS 2.0 — The Operating System for Responsible AI Governance (Architecture, Compliance & Trust Infrastructure)
Zenodo · Working Paper
2025
The ASGR Index — Establishing the First Global Benchmark for Systemic AI Governance Readiness
Zenodo · Working Paper
2025
The AIGN Declaration on Systemic AI Governance: Defining the Operating Principles for the Age of Intelligent Systems
Zenodo · Working Paper
2025
AIGN Systemic AI Governance Stress Test
SSRN · Working Paper
2025
AIGN — AI Governance Compliance Framework for SAP® S/4HANA
SSRN · Working Paper
2025
AIGN OS — The Operating System for Responsible AI Governance
SSRN · Working Paper
2025
The AIGN Academy — Institutionalizing Systemic AI Governance Education
Zenodo · Working Paper
2025
AIGN Legal — From Law to Architecture: Institutionalising Systemic Legal AI Governance
Zenodo · Working Paper

ORCID: 0009-0001-6626-8531

Books and concepts.

Book · 2026
Defensible Autonomy
From AI agent capability to accountable enterprise action. What an organisation permits a machine to do: agent mandate, authority envelope, human accountability anchor, runtime policy enforcement and action evidence chain.
On Amazon
Book · 2026
Defensible Trust
From governance principles to operational evidence: which AI system was used, what it was permitted to do, who reviewed it and what it cost.
On Amazon
Book · 2026
Governing Outsourced Intelligence
The economics of AI-enabled enterprises: token consumption, supplier concentration, operational lock-in, and Runtime Economic Governance.
On Amazon

The three books form The AI Governance Operating Series.

The authority supply chain concept

How authority is granted, transferred, constrained and evidenced across interconnected systems, organisations and jurisdictions. Introduced in The AI Governance Gap Brief, issue 32 (August 2026).

DART executive test for delegated machine authority

A proprietary executive test framework, not a regulatory standard: Delegation (what was actually transferred), Authority (what the system can reach), Runtime Control (which limits and intervention mechanisms work in operation) and Traceability (whether consequences can be reconstructed).

Research lead: Patrick Upmann
Founder of AIGN and independent AI governance advisor with more than 25 years of experience in IT governance, risk and compliance across finance, energy, automotive and retail.
About the founder
Research cooperation
AIGN Research welcomes discussions with universities, research centres, critical infrastructure operators and other organisations investigating the governance of AI-enabled systems. Scope, responsibilities, funding, intellectual property and publication rights are agreed explicitly.
Contact AIGN Research
Network & Education

A global community, and the capability to govern AI.

Practitioners, compliance professionals, technologists, educators and policymakers connected around one mission: responsible, accountable AI governance. The network is the human layer of AIGN OS, with sector peer groups such as Financial Services, Energy & Utilities, Healthcare and Public Sector. The Academy, the Fellowship and the education programmes build the capability.

The connected community for responsible AI.

Members come from business, government, academia and civil society. They contribute to benchmarks, pilots and certifications, and get access to forums, events, knowledge resources and policy insights. Applications are reviewed continuously.

2,200+
Members
50+
Countries
30+
Ambassadors
4
Regional hubs

Four regional hubs

South Korea
Education and next-generation AI governance: youth-focused frameworks and institutional readiness in schools and universities.
MENA
Policy and responsible innovation: national AI strategies, policy design and cross-border alignment.
India
Governance at scale: enterprise readiness, education institutions and sector-specific governance.
Africa
Inclusive AI, ethics and capacity building with locally relevant governance frameworks.
What members get
  • Exclusive access: private forums, events, knowledge resources and policy insights.
  • Peer recognition: a mission-driven community rather than a database.
  • Visibility and voice: opportunities to speak, publish or lead projects.
  • Global influence: contribute to trust labels, governance frameworks and standards work.
  • Collaboration: connect with experts, regulators, innovators and practitioners.
  • ASGR Index access: contribute to and benefit from the systemic readiness benchmark.
Who is welcome
AI governance leaders & policy advisorsEthics, risk & compliance officersCIOs, CDOs & responsible AI leadsUniversities, schools & institutionsStartups & enterprisesGovernment & public sector
Three ways to join
  • Apply as a member by email.
  • Become an ambassador or regional leader: share your vision for responsible AI in your country or region.
  • Stay connected on LinkedIn and in the member channels.

A curated reference for AI governance professionals.

AIGN Circle is a controlled access layer that connects organisations with governance-ready professionals and gives professionals legitimate positioning without market noise. It is a curated global reference, not a marketplace, not a consulting firm, not a recruitment platform and not an open community. Human accountability sits at the centre.

For organisations
Access to governance-ready professionals
For audit pressure, board decisions and regulatory exposure.
  • Controlled reference, not open search
  • Professionals vetted for judgment and accountability
  • Discretion on all sides
Request access
For professionals
Positioning without market noise
Be found by judgment, not by reach.
  • No self-promotion or sales pressure
  • Access to AIGN Sparring peer circles
  • Positioning within the AIGN infrastructure
Apply as professional

AIGN Sparring: peer groups with teeth

A curated, sector-specific peer circle for AI governance professionals who want structured challenge and defensible judgment before regulators, boards or auditors provide it. Not a course, not a webinar. Groups are capped at ten members, built for productive tension (diverse roles, same industry), and every application is read personally by Patrick Upmann.

Format 1Hot SeatOne member’s live governance challenge; the others challenge as regulator, auditor, board member or journalist. 60 minutes of pressure, 30 minutes of synthesis.
Format 2Red TeamOne member defends their governance strategy; the rest try to break it.
Format 3Regulation RadarEach member brings a regulatory development the others have not seen. Verdict: material or noise?
Sector groups Financial Services founding cohort

The founding cohort is in Financial Services (ten seats). Further sector groups are planned: Healthcare & Pharma, Public Sector, Tech & Software, Insurance, Manufacturing, Energy & Utilities, and Legal & Consulting.

Applying takes a direct email with your role, your sector and the governance problem you are working through. Not everyone is accepted.

The Circle logic responsibility, access, trust
  • Responsibility: real people, not frameworks or tools, stand behind governance decisions. Responsibility over frameworks, judgment over process, accountability over delegation.
  • Access: controlled and precise, without dependency or visibility pressure. Curated, contextual, discreet.
  • Trust: avoids market noise, prevents commoditisation of expertise, protects reputations on all sides.

Where governance expertise meets the roles that need it.

AIGN Talent is a specialist talent network for AI governance, data governance and regulatory experts. As consulting budgets freeze, companies internalise governance competence through permanent hires, and generic recruiters cannot evaluate this expertise. Every candidate is assessed by governance practitioners rather than keyword matching.

Step 1Register & profileCandidates submit a governance profile, employers submit the role; AIGN validates each submission.
Step 2Vetted matchMatching on regulatory scope, industry background, operating model experience and availability.
Step 3Qualified introductionBoth parties receive a structured briefing before the first conversation.

For candidates

  • AI governance and EU AI Act specialists
  • Data governance and data protection leads
  • DORA, NIS2 and GDPR implementation experts
  • Regulatory transformation and compliance leads
  • Risk, audit and assurance professionals
  • Fractional and interim governance managers

For employers

  • Financial services, insurance, healthcare
  • Automotive, energy and critical infrastructure
  • Technology companies building governance functions
  • Public sector and government bodies
  • Consulting firms building AI governance practices
  • International organisations with EU AI Act exposure

The academy for operational AI governance.

Not another AI course. The AIGN Academy is the human capability layer of AIGN OS: professionals, teams and institutions learn to understand, operate, evidence and defend AI governance under real conditions. It is 100% online, 18–40 hours depending on the level, and produces reusable governance artefacts.

IndividualsFoundation Credential
A structured introduction to AI governance and AIGN OS, with an ASGR readiness reflection and a certificate of completion.
PractitionersProfessional Certification
Applying governance in real organisations: governance artefact pack, decision and action trace logs, operating model canvas, professional credential.
AI officers · ConsultantsImplementation Professional
Advanced toolchain access, case-based artefact submission, ASGR capability profile and a partner readiness pathway.
Teams · InstitutionsCorporate Readiness
Multi-seat online access, team readiness profile, institutional artefact pack and a corporate or education trust pathway.
Learning architecture watch, apply, build, submit, score, certify, renew
1WatchStructured online units.
2ApplyPractical organisational scenarios.
3BuildTemplates and canvases become artefacts.
4SubmitSelected outputs for review or reflection.
5ScoreASGR logic creates a capability profile.
6CertifyCredentials for evidenced capability.
7RenewAnnual updates for regulatory change.
What participants leave with
  • Role & accountability map: who owns, controls, escalates and evidences governance responsibilities.
  • AI system inventory starter: a method to identify, classify and govern the AI systems the organisation depends on.
  • Decision & action trace logs: templates to reconstruct, attribute and defend AI-related decisions.
  • ASGR capability profile: strengths, active gaps and prioritised next steps.
How it differs from other training
AI literacy
Strong for awareness, insufficient for governance operation and decision evidence.
EU AI Act training
Explains legal requirements, rarely creates operating structures, decision logs or accountability frameworks.
ISO 42001 courses
Solid management-system logic, typically not built as an operating system for daily governance decisions.
AIGN AcademyOperating capability
Roles, controls, toolchain, readiness scoring, artefact packs and a trust pathway. The framework is jurisdiction-neutral; its compliance engine maps EU regulation.

The Junior AI Governance Fellowship.

A global talent programme for students and emerging professionals who want to understand, research and shape AI governance: from regulation and risk to accountability, evidence and institutional trust. It is the entry point into the AIGN ecosystem and the first step towards the Academy. Remote, English-language, part-time, research-based and selective.

8
Weeks
3–5 h
Per week
6
Research tracks
Remote
Global
Six research tracks
EU AI Act & regulatory governanceGlobal AI policy & comparative regulationEducation AI governancePublic sector AIEnterprise AI governanceAI governance in emerging markets
Journey and outputs
1ApplyCV or LinkedIn profile, short motivation, preferred focus.
2Research note testA 1–2 page note on a current development in your region or field.
3CohortEight remote weeks with guidance and research templates.
4Final outputResearch note, country snapshot, sector briefing, gap analysis or youth perspective paper.

Selected outputs may be featured as AIGN Junior Governance Notes after editorial review; publication is not automatic. Fellows who complete the programme with an accepted output receive a certificate of contribution.

Questions
  • Is it an internship? No. It is a selective remote contributor fellowship, not an employment or internship relationship.
  • Who should apply? Students (law, policy, computer science, governance, international relations, ethics, business, data), young professionals and regional observers.

Accountable AI for every classroom.

Schools, universities and EdTech platforms need child-rights sensitive, transparent and accountable AI governance. Several educational AI uses fall into the high-risk category of the EU AI Act. AIGN offers an operating system for education and a governance label for institutions.

Operating system
AIGN EOS
The Education Operating System for trustworthy AI decisions affecting children: an operational governance architecture built around the Education Decision Record. Published as a preprint (v1.0, April 2026).
Explore Education OS
Governance label
Education Trust Label
AIGN’s governance label for schools, universities and education networks. A private governance credential, not an audit or an accreditation.
Explore the label
First implementation: in September 2025, Fayston Preparatory School in Seoul, South Korea became the first institution in Asia to receive the AIGN Education Trust Label.
Why schools need it three realities in every classroom
  • No audit trail: when an AI decision disadvantages a student, most schools cannot document how it was reached, or defend it.
  • No liability basis: without auditable decision records there is no foundation to challenge or correct a flawed AI recommendation.
  • No systemic protection: without equity monitoring, algorithmic bias accumulates silently.
How EOS works input, processing, output, feedback
InputIntake & policy gateEvery AI application passes a child-rights impact assessment; institutional rules are encoded as machine-readable policy checks.
ProcessingRisk & human oversightContinuous bias and drift monitoring; teacher override with no automated high-stakes decision without a human checkpoint.
OutputDecision record & explanationAn exportable Education Decision Record per decision, plus age-appropriate explanations for child, parent, teacher and authority.
FeedbackMonitoring & remedyMaturity monitoring and an appeal and remedy service for children, parents and teachers.

As specified in the AIGN EOS preprint: a three-level maturity path (pilot-ready, operational, assurable) gated by ASGR maturity.

Who it is for
Primary & secondary schoolsUniversities & research institutionsEdTech providers & vendorsSchool districts & education networksMinistries & NGOs
Africa Kenya Pioneer Programme

Education Trust Label Africa — Kenya Pioneer Programme.

Open the programme page