Making AI governance operational.
Keeping authority accountable.
AIGN.Global connects governance architecture, applied research and professional expertise to help organisations govern AI systems that inform, decide and act. With a focus on critical infrastructure, high-consequence environments and board-level accountability, we turn governance requirements into defined authority, operational controls and reconstructable evidence.
Nine sectors · one authority question
Tap a sector on the radar to preview it, tap again to open it.
Documented: keynote and round table co-chair at the NATO SPS-supported Advanced Research Workshop on early warning for critical infrastructure, Yerevan (September 2026) · first AIGN Education Trust Label in Asia (Seoul, September 2025) · AIGN OS 3.0 report on Zenodo (April 2026)
Where machine authority meets critical infrastructure.
Choose a sector to see the authority question that matters most, what has to be governed, and where AIGN helps. The approach is not limited to a single legal definition of critical infrastructure (in German usage: KRITIS): what counts is the consequence a system can have for operations, customers, supply, safety and society.
Energy & utilities
“Which optimisation decisions may AI take autonomously, and where must a technical or human boundary always take precedence?”
What to govern
- Optimisation goals set against safety, resilience and supply requirements
- Non-overrideable boundaries and fail-safe logic
- Human intervention and incident evidence that stand up to audit
Frameworks in play
Water & wastewater
“Which control actions may an AI-supported system trigger in supply or treatment, and who can stop it, and how fast?”
What to govern
- An authority envelope for control actions in supply and treatment
- Runtime limits and escalation thresholds
- Reconstructable action evidence after an incident
Frameworks in play
Transport & mobility
“What may an AI system change in scheduling, routing or traffic control without human confirmation?”
What to govern
- A mandate and an owner for every automated change
- A clear line between planning support and operational control
- Re-approval when tools, data or integrations change
Frameworks in play
Telecom & digital infrastructure
“Which network, access and incident-response actions may an agent take, and under whose mandate?”
What to govern
- Agent identity, permissions and tool access
- Separating what an agent can see from what it can change
- Credential rotation and revocation when agents change or retire
Frameworks in play
Financial infrastructure & payments
“At what point does a recommendation become financial authority to act?”
What to govern
- Transaction authority limits and human escalation
- Runtime controls and re-approval when rights expand
- Action evidence for supervisors and audit
Frameworks in play
Healthcare & emergency services
“Which decisions stay reserved to humans, and can an AI-supported decision be reconstructed afterwards?”
What to govern
- Human reserved decisions and escalation paths
- Traceability of inputs, outputs and interventions
- Oversight design that works under time pressure
Frameworks in play
Public services & administration
“Who is accountable when an AI-supported decision reaches a citizen?”
What to govern
- Named human accountability for every delegated task
- Fundamental-rights impact and explanation paths
- Procurement evidence for AI suppliers
Frameworks in play
Space & earth observation
“Who holds authority over AI-supported sensing, tasking and early warning derived from satellite data?”
What to govern
- Authority boundaries between analysis, alert and action
- Trusted use of shared data across organisational and national borders
- Evidence chains for early-warning decisions
Frameworks in play
Context: the 2026 NATO SPS workshop in Yerevan, where AIGN gave a governance keynote, covered aerial, unmanned and satellite sensing and AI-driven earth observation for early warning.
Defence & dual use
“Which decisions must remain reserved to humans, and how is delegated machine authority bounded, interrupted and evidenced?”
What to govern
- Human reserved authority and intervention design
- Runtime enforcement, revocation and change control
- Evidence that holds up under independent challenge
Frameworks in play
AIGN works on governance, accountability and evidence, not on weapon systems or operations. Participation in a NATO SPS workshop does not constitute NATO endorsement of AIGN.
The nine sectors are illustrative fields of application, not nine documented implementations, and the questions are not client cases. Which frameworks apply depends on jurisdiction, system, operator role and use context, and should be checked against the current legal texts. Whether an organisation or system is legally classified as critical infrastructure depends on national law.
AI governance for critical systems, built to run in operations.
For operators of critical infrastructure (in German usage: KRITIS), defence and dual-use organisations, regulated enterprises and the boards that oversee them. AIGN OS provides the overarching governance architecture. AIGN Critical OS extends it into critical and high-consequence environments, with particular attention to delegated machine authority and runtime controls. AIGN360 supports implementation and ongoing governance operations. The AIGN Trust Label provides an evidence-based assessment within a defined scope, while the Intelligence Hub tracks developments relevant to governance decisions.
Which AI systems in your critical processes exist, what may each of them decide or do, and can you prove it?
As long as AI only produces information, governance can focus on model quality, data, approval and human review. Once AI receives identities, permissions, tools, APIs, communication channels or access to operational systems, the question changes: the system now holds practically effective machine authority, the ability to trigger consequences within or on behalf of an organisation. AIGN OS provides the overarching governance architecture; AIGN Critical OS specialises it for critical and high-consequence environments, carrying authority governance into the runtime.
Nine control points, from mandate to retirement
Sectors
AIGN OS 4.0 helps organisations classify AI systems before compliance, audit and liability questions arrive. It translates the EU AI Act, GDPR, ISO/IEC 42001, NIS2, DORA and other frameworks into operational controls, clear roles and auditable evidence, and it is delivered as modules that each produce concrete governance artefacts.
AI governance as an operated function.
AIGN360 turns AI governance from a policy project into a continuously operated function. It is a managed service that supports governance operations: reviewing AI use cases, maintaining documentation and evidence, tracking regulatory mapping, and coordinating responsibilities across business, legal, compliance, IT, data, HR, procurement and the boardroom. It is a monthly managed service with a defined scope, not open-ended consulting.
- Use case and governance baseline
- Role, responsibility and forum design
- Policy-to-process translation
- Evidence and documentation architecture
- Roadmap into managed operation
- Recurring governance reviews
- Control and documentation maintenance
- Regulatory mapping and change tracking
- Audit readiness and evidence support
- Risk, issue and escalation management
- Fractional AI governance leadership
- C-level and board-level decision support
- Prioritisation of critical AI risks
- Cross-functional stakeholder steering
- Defensibility under regulatory pressure
Engagements can start with Design and move into Operate. Scope is defined in onboarding.
The governance logic
Make AI governance visible, evidence-based and defensible.
The AIGN Trust Label is a visible, evidence-based governance signal for customers, partners, boards and audit-facing processes, based on the AIGN OS reference architecture and aligned with the EU AI Act, ISO/IEC 42001, GDPR, NIS2 and DORA. It reflects a private assessment within a defined scope, not proof that every operational control functions as intended.
The labels
From AI signal to governance action.
Regulation changes, vendor platforms evolve, agents enter workflows, industries differ, departments need different actions and boards need evidence. The Intelligence Hub gives each of these questions its own entry point: the Briefing explains what changed, the Index measures readiness, the Radars monitor exposure, and the Board & Audit Radar turns it into defensible oversight.
Governing machine authority in high-consequence systems.
Applied research on machine authority, defensible autonomy and AI governance in critical infrastructure, early warning and other high-consequence environments: from governance principles to operational models for AI-enabled systems that can inform, decide and act. AIGN Research studies the authority, accountability and evidence structures needed to govern them, connecting AI governance, operational risk, technical control mechanisms and institutional oversight.
Under what conditions may an AI-enabled system act without real-time human confirmation, while human accountability remains clearly anchored?
- Operational mandates
- Delegated authority and authority boundaries
- Human accountability anchors
- Evidence of authorised behaviour
- Monitoring and early warning
- Escalation and human intervention
- Accountability for consequential actions
- Policy enforcement and monitoring
- Intervention mechanisms
- Logging and auditability
- Reconstruction of consequential system actions
- Distributed accountability
- Institutional coordination
- Shared operational authority
Advanced Research Workshop, Yerevan.

14–19 September 2026, Yerevan State University, Armenia. AI-Powered Monitoring Systems, Regional Data Sharing, and Models for Early Warning in Critical Services and Infrastructure.
Organised by the CenTRiS Foundation (Armenia) and the University of Calabria (Italy), with NATO SPS support under grant ARW.G9376. A documented speaking engagement; it does not constitute NATO endorsement of, or funding for, AIGN Research. View the workshop programme
Verifiable work, labelled by type.
Selected publications by Patrick Upmann, research lead of AIGN Research. Outputs are labelled by type; peer review is stated only where it has taken place.
ORCID: 0009-0001-6626-8531
Books and concepts.
The three books form The AI Governance Operating Series.
A global community, and the capability to govern AI.
Practitioners, compliance professionals, technologists, educators and policymakers connected around one mission: responsible, accountable AI governance. The network is the human layer of AIGN OS, with sector peer groups such as Financial Services, Energy & Utilities, Healthcare and Public Sector. The Academy, the Fellowship and the education programmes build the capability.
The connected community for responsible AI.
Members come from business, government, academia and civil society. They contribute to benchmarks, pilots and certifications, and get access to forums, events, knowledge resources and policy insights. Applications are reviewed continuously.
Regional programmes
A curated reference for AI governance professionals.
AIGN Circle is a controlled access layer that connects organisations with governance-ready professionals and gives professionals legitimate positioning without market noise. It is a curated global reference, not a marketplace, not a consulting firm, not a recruitment platform and not an open community. Human accountability sits at the centre.
- Controlled reference, not open search
- Professionals vetted for judgment and accountability
- Discretion on all sides
- No self-promotion or sales pressure
- Access to AIGN Sparring peer circles
- Positioning within the AIGN infrastructure
AIGN Sparring: peer groups with teeth
A curated, sector-specific peer circle for AI governance professionals who want structured challenge and defensible judgment before regulators, boards or auditors provide it. Not a course, not a webinar. Groups are capped at ten members, built for productive tension (diverse roles, same industry), and every application is read personally by Patrick Upmann.
Where governance expertise meets the roles that need it.
AIGN Talent is a specialist talent network for AI governance, data governance and regulatory experts. As consulting budgets freeze, companies internalise governance competence through permanent hires, and generic recruiters cannot evaluate this expertise. Every candidate is assessed by governance practitioners rather than keyword matching.
For candidates
- AI governance and EU AI Act specialists
- Data governance and data protection leads
- DORA, NIS2 and GDPR implementation experts
- Regulatory transformation and compliance leads
- Risk, audit and assurance professionals
- Fractional and interim governance managers
For employers
- Financial services, insurance, healthcare
- Automotive, energy and critical infrastructure
- Technology companies building governance functions
- Public sector and government bodies
- Consulting firms building AI governance practices
- International organisations with EU AI Act exposure
The academy for operational AI governance.
Not another AI course. The AIGN Academy is the human capability layer of AIGN OS: professionals, teams and institutions learn to understand, operate, evidence and defend AI governance under real conditions. It is 100% online, 18–40 hours depending on the level, and produces reusable governance artefacts.
The Junior AI Governance Fellowship.
A global talent programme for students and emerging professionals who want to understand, research and shape AI governance: from regulation and risk to accountability, evidence and institutional trust. It is the entry point into the AIGN ecosystem and the first step towards the Academy. Remote, English-language, part-time, research-based and selective.
Accountable AI for every classroom.
Schools, universities and EdTech platforms need child-rights sensitive, transparent and accountable AI governance. Several educational AI uses fall into the high-risk category of the EU AI Act. AIGN offers an operating system for education and a governance label for institutions.
Patrick Upmann
Machine Authority & Agentic AI Governance
Defensible AI Governance for boards, supervisory boards and operators of critical systems, with the goal of making Machine Authority controllable, traceable and defensible. Founder and architect of AIGN.Global and AIGN OS 4.0; author of The AI Governance Operating Series.
Who gave the machine the authority to do that, and can you prove it?
I do not replace your AI governance, risk, compliance, security or internal audit function. I provide an external challenge at the point where they meet: the authority your organisation is actually giving the machine.
Author · The AI Governance Operating Series
Quoted internationally: Infobae Mundo · The New Africa Magazine | Verifiable delivery: audit readiness, governance operating models, access & control structures, +30% efficiency in one data governance engagement (E.ON).
Three moments to call.
Ways to work together
- Scope: 1 material agent or use case
- Typically 5 business days after evidence is available
- Fixed scope, fixed fee after scoping
- Output: Machine Authority Decision Memo and executive readout
The decision to deploy remains with the organisation. The review is an external governance challenge, not a certification or approval.
Request a scoping call- 90–120 minutes, confidential
- Output: Board Question Set and 90-Day Oversight Priorities
DART: the challenge for delegated machine authority
Not an enterprise governance model and not a regulatory standard: the proprietary executive test for what an AI system has actually been given and whether that delegation remains controllable. The core tool of every advisory engagement.
When AI acts, governance becomes a leadership question.
Support for supervisory boards, audit committees, executive boards and CEOs in steering and overseeing AI effectively when technical capability turns into real decision and action authority. The focus: strategy, value, materiality, accountability, Machine Authority, operational control and reliable evidence.
Three levels of responsibility, three different questions
Six dimensions of effective executive AI governance
The AI Governance Operating Series.

“AI governance can no longer remain a policy exercise. The next era will be defined by evidence, classification, permission, runtime control and board-level assurance.”Patrick Upmann · The AI Governance Operating Series, 2026
Peer-reviewed status is stated only where it has taken place. All DOI-registered publications are listed under AIGN Research → Publications.
Where specific AI technologies, identity and IAM systems, coding agents, AI Spaces, chatbots, agentic systems, enterprise Copilots, shadow AI, algorithmic CV screening, create structural governance exposure that boards cannot see until after the incident.
Where AI governance fails inside organisations: culture, time pressure, budget decisions, procurement gaps, institutional order, human factors and structural misalignment between intent and execution.
Where specific regulatory frameworks (EU AI Act, DORA, data protection law) meet real deployment decisions, and where AI use can create new or previously invisible liability and accountability exposure.
The track record is deliberately split into two distinct evidence lines, which are not mixed together.
The operational track record documents delivered governance, risk and compliance outcomes. The Critical sector label marks the sector classification, not a formal legal critical-infrastructure designation of the specific organisation. The selection shows the six most significant engagements in critical or regulated sectors.
Core expertise & sectors
Show imprintHide imprint
Information according to §5 DDG (German Digital Services Act)
Service provider:
Commercial Register Entry
Entry in the Commercial Register · Register Court: Munich · Registration Number: HRA 97344
VAT Identification Number
VAT identification number according to §27a of the German VAT Act: DE 814736585
Content Responsible according to §18 Abs. 2 MStV
Patrick Upmann (address as above)
Liability Notice
Despite careful content control, we assume no liability for the content of external links. The respective operators are solely responsible for the content of linked pages.
Copyright & Licensing
Copyright protects the concrete expression of the content and works on this site, not the underlying ideas, methods or procedures as such. Reproduction, editing, distribution and any use beyond the limits of copyright require the written consent of the author or creator. AIGN OS, AIGN-specific terminology, proprietary models, frameworks and toolchains are the intellectual property of Patrick Upmann / AIGN; commercial use of specifically licensed materials, software and protected implementation components requires a valid AIGN licence. Where content on this site was not created by the operator, third-party copyrights are respected and marked accordingly. Upon notification of infringements, we will remove such content immediately.
Show privacy policyHide privacy policy
1. Data Controller
The controller responsible for data processing on this website is:
2. Hosting & Server Log Files
When you access this website, the hosting provider automatically collects technical access data (IP address, date and time of access, page requested, data volume transferred, browser type/version, operating system, referrer URL) in server log files. This is technically necessary to operate and secure the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional and secure website). Server log files are deleted or anonymised after 30 days at the latest, unless further retention is required for security purposes.
3. Contact by Email
If you contact us by email or via a mailto link, the data you provide (e.g. email address, message content) is processed exclusively to handle your enquiry. Legal basis: Art. 6(1)(b) or 6(1)(f) GDPR. Data is deleted once no longer required, unless statutory retention obligations apply. A mailto link only opens your local email client; no data is transmitted to us unless you send an email.
4. Cookies & Local Storage
This site does not set tracking or analytics cookies and does not use browser local storage for tracking. Any interface preference stored locally (such as a collapsed/expanded state) is technical and is not used to identify you.
5. Fonts (No External Services)
This website does not embed Google Fonts or other externally loaded font services. Typography uses locally installed system fonts and, where used, self-hosted assets. No connection to third-party font servers is made.
6. Recipients & External Links
Recipients may include hosting, email and IT service providers engaged by us, to the extent necessary to operate the website and process your enquiry; these providers process data solely on our behalf. Beyond this, we do not share personal data with third parties. This site links to third-party platforms (including LinkedIn, Amazon, aign.global, now.digital). Following such a link takes you away from this website; the respective third party’s own privacy information applies to any data processing it carries out.
7. Your Rights as a Data Subject
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the Bavarian State Office for Data Protection Supervision (BayLDA).
Last updated: September 2026. This policy may require adjustment due to technical or legal developments.