• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • About Me
    • My Story
      • Teaching, Speaking, and Panels
  • Governing AI
  • Digital Factics X
  • Minds That Bend The Machine
  • Digital Factics Instagram
  • AI – Artificial Intelligence
    • Ethics of AI Disclosure
    • AI Learning
      • AI Course Descriptions

Basil C. Puglisi

Digital Strategy, Content, and AI Since 2009

  • Home
  • AI Thought Leadership
    • Basil’s Brand Blog
    • Building Blocks by AI
    • Local Biz Tips
  • HAIA
  • Factics
  • Checkpoint-Based Governance
  • RECCLIN
  • CAIPR
  • HEQ/AIS
  • AI Policy
    • ISO AI Governance Comment

Public Technical Comment on ISO/DIS 21520, Clause 3.2: Defining AI Governance by Decision Authority

ISO/DIS 21520 is a draft international standard from ISO/TC 258 that gives project, programme, and portfolio managers guidance on artificial intelligence concepts, applications, and implications. Define AI Governance or as they present it in full artificial intelligence governance. ISO opened the draft for ballot and comment from July 5 through September 27, 2026, and comments from the United States move through the ANSI-accredited U.S. Technical Advisory Group to ISO/TC 258, which the Project Management Institute administers.

This page records the public technical comment Basil C. Puglisi prepared for that process in September 2026. The comment addresses Clause 3.2, the draft’s definition of artificial intelligence governance, and proposes language that makes binding human decision authority and attributable accountability part of the definition itself. – Official PDF sent here –

The draft definition and the proposed definition

As drafted in Clause 3.2

“organizational framework of policies, roles, responsibilities and processes to ensure the accountable, secure, ethical and effective use of artificial intelligence systems”

As proposed definition for AI Governance

“AI Governance exists when a qualified human holds binding authority at specific checkpoints, with personal accountability for the outputs that pass through.”

Clause 3.2 cites no source vocabulary, unlike the neighboring entries in Clause 3, which adopt definitions from ISO/IEC 22989:2022 or ISO/IEC 2382:2015.

The technical deficiency

The draft definition establishes organizational structure but does not establish the decision-authority threshold that distinguishes governance from oversight, management, Responsible AI controls, or human participation. A March 2026 review of ISO, NIST, the OECD, the EU AI Act, and UNESCO found that each addressed governance, yet none defined AI Governance as a standalone term.

Standards bodies define the management systems they certify, and risk frameworks define the functions they measure. Intergovernmental bodies define the principles they negotiate, and regulators define the obligations they enforce. That gap let an organization claim AI Governance through policies, teams, or certification while no named person held the authority to stop an output or answered for it.

The full scope of the proposed definition

AI Governance is the system of decision authority, accountability structures, and oversight mechanisms through which named humans hold binding power to accept, modify, or reject AI outputs at defined checkpoints, with authority that cannot be delegated to the AI system being governed and accountability that survives audit through moral, professional, civil, and criminal channels.

Side-by-side comparison of two definitions of AI governance. On the left, ISO/DIS 21520 Clause 3.2 as drafted: "organizational framework of policies, roles, responsibilities and processes to ensure the accountable, secure, ethical and effective use of artificial intelligence systems." On the right, the proposed definition: "AI Governance exists when a qualified human holds binding authority at specific checkpoints, with personal accountability for the outputs that pass through." Credit line reads: Public technical comment by Basil C. Puglisi, September 2026, basilpuglisi.com.

Operational scope

ElementMeaning
Named humanA person, not a team or a department, whose identity attaches to the decision
Binding authorityThe power to accept, modify, or reject an AI output at a defined checkpoint
AccountabilityMoral, professional, civil, and criminal channels that reach that person and survive audit
Human arbitration onlyAI cannot satisfy, close, or validate a checkpoint for another AI, and no platform count, confidence score, or convergence level substitutes for human arbitration
QualifiedCapability, not credentials alone: the governance competence to direct, challenge, verify, and own the work done with AI. The human acts as the generalist who owns direction, purpose, and context without needing to out-know the specialist machine, and checkpoint practice builds that capability over time.
High-speed systemsThe checkpoint moves upstream, where the named human signs the policy that authorizes automated action

Relationship to Responsible AI

Ethical AI supplies the values, and ethics frameworks govern AI behavior. Responsible AI builds those values into systems through controls, monitoring, and validation. It runs as machine validating machine, agents running the pipeline, or a human in the loop, and it is often the right choice when stakes allow process controls to suffice and outputs are reversible.

Its ceiling, absent an assigned human authority, is individual decision accountability, because none of those modes, by itself, requires a named person to hold binding authority over an individual output. Automation with guardrails remains automation, and a human in the loop without binding authority is presence without accountability. AI Governance begins when a named human holds binding authority at a defined checkpoint and answers for what passes through, and Checkpoint-Based Governance is the mechanism that converts that presence into authority.

Regulatory convergence

Regulation has moved toward the same threshold on its own terms. New York’s Part 161, effective June 1, 2026, governs the use of AI in court papers while requiring the filer to review the paper and independently verify its contents. Regulation (EU) 2026/1744 deferred the EU AI Act’s high-risk obligations, including Article 14 human oversight, to December 2, 2027 for Annex III systems, without removing them.

Development record

The applied definition stands as published, while the full scope now uses accept, modify, or reject as the decision outcomes. It also names the professional channel in place of employment and carries the constitutional prohibition that AI cannot approve AI.

  1. September 23, 2025Checkpoint-Based Governance published mandatory human arbitration at defined decision points, with every decision logged to an identifiable reviewer.
  2. November 20, 2025The Checkpoint-Based Governance constitution established that human arbitration retains final decision authority and that no AI may approve another AI’s decision.
  3. November 2025Governing AI: When Capability Exceeds Control (ISBN 9798349677687) opened with Geoffrey Hinton’s warnings, examined each risk domain he named, and answered them with Checkpoint-Based Governance.
  4. March 14, 2026The formal definition and its accountability channels appeared at basilpuglisi.com, following the institutional review described above.
  5. March 18, 2026Owen Ambur, co-chair of the StratML Committee that developed StratML Part 1, later published as ISO 17469-1, independently mapped the definition into StratML.

Editorial notes on Clause 3

The comment also flags two editorial items for the committee. Clause 3.1 refers to “AI systems (3.2),” but the AI system definition appears at 3.4, and Clause 3.4 defines an “engineering system” while its Note 1 refers to “the engineered system.”

What the comment asks

The comment asks the U.S. TAG to consider revising Clause 3.2 so that the definition of artificial intelligence governance expressly identifies binding human decision authority and attributable human accountability as elements that distinguish governance from organizational process, oversight, and Responsible AI controls. It offers the definition above as proposed language, and Puglisi has offered to support consideration of the issue as a technical expert.

Questions about this comment can go to me@basilpuglisi.com.

Sources

International Organization for Standardization. (2026). ISO/DIS 21520, Project, programme and portfolio management, Artificial intelligence, Concepts, applications, and implications. https://www.iso.org/standard/91551.html

ISO/TC 258. (2026, July 5). ISO/DIS 21520 now open for ballot and comment at enquiry stage. https://committee.iso.org/sites/tc258/home/news/content-left-area/news-and-updates/news-1.html

New York State Unified Court System. (2026). Part 161. Use of artificial intelligence technology. https://www.nycourts.gov/rules/part-161-use-artificial-intelligence-technology

European Commission. (2026). AI Act. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

PDF Association. (n.d.). Owen Ambur. https://pdfa.org/people/owen-ambur/

#AIassisted using the HAIA Ecosystem | CC BY-NC-SA 4.0 Free for personal, educational, and noncommercial research use with attribution. Commercial exploitation, paid productization, and enterprise commercialization require separate permission and licensing.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Pinterest (Opens in new window) Pinterest
  • Email a link to a friend (Opens in new window) Email

Like this:

Like Loading…

Primary Sidebar

Buy the eBook on Amazon

Multi-AI Governance

HAIA-RECCLIN Reasoning and Dispatch Third Edition free white paper promotional image with 3D book mockup and download button, March 2026, basilpuglisi.com

SAVE 25% on Governing AI, get it Publisher Direct

Save 25% on Digital Factics X, Publisher Direct

Digital Factics X

Legacy Blogs

The Loop That Ate the Governor

The U.S. Government Will Need to Seize AI Platforms and Data Centers if We Do Not Act

When AI Acts Between Approvals: The Gap Everyone Sees and No One Has Closed

Measuring Augmented Intelligence

GOPEL: The Code Behind the Policy

Training AI for Humanity:

#SMAC #SocialMediaWeek

Basil Social Media Week

Legacy Print:

Digital Factics: Twitter

Digital Ethos Holiday Networking

Basil Speaking for Digital Ethos
RSS Search

© 2009–2026 Basil C. Puglisi, Creator of Factics™ and the HAIA Ecosystem

%d