• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • About Me
    • My Story
      • Teaching, Speaking, and Panels
  • Governing AI
  • Digital Factics X
  • Minds That Bend The Machine
  • Digital Factics Instagram
  • AI – Artificial Intelligence
    • Ethics of AI Disclosure
    • AI Learning
      • AI Course Descriptions

Basil C. Puglisi

Digital Strategy, Content, and AI Since 2009

  • Home
  • AI Thought Leadership
    • Basil’s Brand Blog
    • Building Blocks by AI
    • Local Biz Tips
  • HAIA
    • SMART
  • Factics
  • Checkpoint-Based Governance
  • RECCLIN
  • CAIPR
  • HEQ/AIS
  • AI Policy
    • ISO AI Governance Comment

Humans Are Optional When Defining AI Governance for ISO, According to the U.S. Technical Advisory Group

September 22, 2026 by Basil Puglisi Leave a Comment

On September 21, 2026, the U.S. Technical Advisory Group to ISO/TC 258 answered my public comment on the draft international standard for AI in project management. It accepted two of my corrections and rejected the one that mattered, writing that human control is desirable but not always required for AI governance to exist.

I’ve read that sentence many times now, and it still lands the same way. It states in plain words the position I have argued against since my first Checkpoint-Based Governance paper, and it arrived during the same week that the public made clear it wants the opposite.

ISO_commenting_DIS_21520_AI_Governance_PuglisiDownload

Why This Lands Now

The rejection came at the end of a month when fear of AI moved from the margins into the center of American life. Dario Amodei published a pacing essay on September 12, Sam Altman and Elon Musk agreed within hours, and Demis Hassabis endorsed the direction. Two days later, the President answered by placing AI catastrophe fears among the claims he labels hoaxes. A POLITICO Poll fielded by Public First from September 13 to 15 found that 63 percent of American adults see at least a moderate risk that advanced AI could destroy humanity. Majorities across parties, genders, and age groups hold that view. The same poll found 48 percent favor pausing development against 31 percent who want to keep building, and about half believe the insiders issuing warnings mean what they say.

I wrote about that month in The AI HOAX Distraction. Six positions surfaced in nine days, and every one of them aligned with the speaker’s balance sheet. My argument there was that the slowdown calls are not evidence that governance is working, because the same mechanism that produced ship anyway in 2023 produces slow down in 2026 once the calculus moves. The prescription I offered was narrower than pacing the frontier. Slow the autonomy rather than the capability, which means no AI system holds authority to act without a named human accountable at the decision point and a record of what it did.

The moral voices of this year have been asking for the same thing in different words. Pope Leo XIV’s first encyclical, Magnifica Humanitas, dated May 15, 2026 and formally presented later that month, placed human dignity at the center of how technology should be judged. The Vatican’s own summary of the letter says AI “cannot and should not assume a role of responsibility” over human intelligence. When he presented it, the Pope said that decisions about technology must never be separated from conscience and responsibility.

The public wants someone to answer. The moral authorities want responsibility to stay with people. The standards process that will shape how organizations define AI governance inside their projects has now said that no human needs to hold control at all.

The Draft and Its Definition

ISO/DIS 21520 is the draft standard on artificial intelligence in project, programme, and portfolio management, developed under ISO/TC 258. ISO describes it as guidance for any organization, whether public, private, or charitable, on the concepts, benefits, risks, and governance of AI used in that work. Clause 3 carries the terms the rest of the document builds on. Clause 3.2 then defines artificial intelligence governance this way:

organizational framework of policies, roles, responsibilities and processes to ensure the accountable, secure, ethical and effective use of artificial intelligence systems

The definition names accountability as a goal and assigns it to no one. It lists roles without saying that any role holds the authority to stop an output. It also cites no source vocabulary, while its neighbors in Clause 3 adopt their definitions from ISO/IEC 22989:2022 or ISO/IEC 2382:2015.

The Filing

I filed through the U.S. TAG to ISO/TC 258, which PMI administers, on September 15, 2026. The U.S. TAG Administrator replied that the internal deadline for U.S. comments had closed July 15 and that the U.S. position had gone in on September 13. The comment went to TAG members ahead of their plenary regardless, and the response came back six days after I filed.

My filing carried a three-row comment form, a supporting memo, and a public record at basilpuglisi.com, so anyone can read what I submitted and when. Two rows were editorial corrections I found during a line-by-line reading of Clause 3. The third was the technical comment on Clause 3.2.

The Proposal

My technical comment argued that Clause 3.2 establishes organizational structure but not the decision-authority threshold that separates governance from oversight, management, Responsible AI controls, or simple human participation. Regulation has already moved toward that threshold on its own terms. New York’s Part 161, effective June 1, 2026, governs the use of AI in court papers while requiring the filer to review the paper and independently verify its contents. Regulation (EU) 2026/1744 deferred the EU AI Act’s high-risk obligations, including Article 14 human oversight, to December 2, 2027 for Annex III systems, without removing them.

I asked the TAG to revise Clause 3.2 so the definition expressly identifies binding human decision authority and attributable human accountability as the elements that distinguish governance. I offered two versions of the definition.

The applied definition: AI Governance exists when a qualified human holds binding authority at specific checkpoints, with personal accountability for the outputs that pass through.

The full-scope definition: AI Governance is the system of decision authority, accountability structures, and oversight mechanisms through which named humans hold binding power to accept, modify, or reject AI outputs at defined checkpoints, with authority that cannot be delegated to the AI system being governed and accountability that survives audit through moral, professional, civil, and criminal channels.

Side by side panels comparing the ISO DIS 21520 Clause 3.2 AI governance definition with the rejected human authority version

Two Accepted

The TAG accepted both of my editorial rows as written. Clause 3.1 referred to “AI systems (3.2)” although the AI system definition sits at 3.4, so the cross reference moves to 3.4. Clause 3.4 defined an “engineering system” while its own Note 1 said “the engineered system,” and the source it adopts, ISO/IEC 22989:2022, 3.1.4, uses “engineered” in both places.

Both corrections now go to ANSI for addition to the U.S. comments. They’re small fixes, but they show the TAG read my comment closely and agreed wherever the draft was plainly wrong.

One Rejected

On Clause 3.2, the TAG wrote that it was not possible to accept the change, and it gave four reasons. It read my proposal as saying AI governance exists only when a qualified or named human holds binding authority. It then stated its own position: “While such human control is desirable, that control is not always required for AI governance to exist.”

The remaining reasons concern drafting. ISO definitions stay high level and concise so they apply broadly and globally, and users can add operational detail themselves. The TAG also noted that my proposed definition could be read as containing requirements, which ISO does not permit in definitions.

That last point has a real basis, and I accept it as a drafting rule. The ISO/IEC Directives, Part 2, state that a definition shall not take the form of, or contain, a requirement, while the same Directives allow terminological entries to carry requirements in their notes to entry. The rule governs where binding authority can sit in the text, but it does not decide whether governance requires a governor. The TAG answered that second question on its own, and it answered no.

Where the Line Falls

My definition starts from a single distinction. Governance requires a governor, and where decisions carry human consequences, that governor must be a person who holds the authority and answers for how it gets used.

Read plainly, the TAG holds that AI governance can exist without a human in oversight or accountability. Calling human control desirable makes it optional, and once control is optional, accountability has no owner. The TAG rejected my proposal as a whole, so the attributable human accountability it named falls with the binding authority.

Clause 3.2 still promises the accountable use of AI. Accountability means someone answers for the result, yet a policy cannot answer and a process cannot answer. A role on an organizational chart answers only when the person in it holds the power to accept, modify, or reject the output. Without that power, the framework describes how AI is managed rather than who governs it.

The strongest objection to my position comes from engineering, where a governor is often a machine. A flyball governor holds a steam engine to a set speed with no human touching it, and a critic could say automated controls govern AI the same way. The mechanical governor enforces a limit that a person chose, though, and when the engine fails, nobody asks the governor to explain itself. That’s control, and governance begins where a named person answers for what passed through.

The universality argument deserves the same scrutiny. A definition becomes easy to apply everywhere when it asks nothing of anyone. Every organization with a policy binder and an org chart can meet Clause 3.2 as drafted, including one where no person holds the authority to stop a consequential AI-supported decision.

Why This Fails More Than a Technical Test

If the only problem were drafting, a note to entry would fix it. The deeper failure is that the definition answers a moral question the public is asking out loud, and it answers it the wrong way.

People who tell pollsters they fear AI are not asking for a better policy binder. They’re asking who stops it when it goes wrong, who answers when it harms someone, and whether any person still holds the switch. A definition that treats human control as optional tells them the honest answer is nobody, and that the arrangement still counts as governance.

The four channels in my definition exist because each one needs a person to reach. Moral accountability needs a conscience, professional accountability needs someone whose standing is on the line, and civil and criminal accountability need a party a court can name. A framework of policies and processes can be audited, revised, or retired, but it cannot feel the weight of a decision, lose a license, or stand before a judge.

This is also where the TAG’s position meets two arguments I have been developing in parallel. The AI HOAX Distraction asks how to tell a genuine safety claim from an economic incentive, and The AI Risk Economy asks what happens when AI risk cannot be attributed, priced, transferred, or proven. Both reach the same missing record: who held authority when the system acted, what that person knew, and what that person decided. Carriers issued AI exclusions to preserve capital, and they could not do anything more precise because nobody can prove how an AI system was governed at the moment it acted. Insurance cannot price what governance cannot prove. A definition that allows governance with no human at the decision point makes that proof impossible by design, since there is no named person whose judgment the record can show.

It also invites the failure I warned about in that piece, the liability sponge. That’s a person stationed near an AI decision who lacks the time, authority, information, or standing to actually decide. The system acts at machine speed and the person approves, so the blame lands on the individual while the loss lands on the organization. A standard that calls human control merely desirable leaves room for exactly that arrangement, with the human present on paper and absent in authority.

The AI HOAX piece closed its critique of the frontier labs with a line that now applies to the standard: governance begins where revocability ends. An independent review panel had found the leading labs weakening or voiding their pause pledges, some of them contingent on what competitors do. A commitment that can be withdrawn at will is a bid rather than a constraint. Human control that is desirable but not required is the same kind of commitment, written into a definition instead of a scaling policy.

The TAG’s position describes Responsible AI in its clearest form, and Responsible AI is machine checking machine. An AI agent is a machine, AI reviewing AI is a machine, and a human in the loop who only watches is machine on machine with a person standing nearby. That person rarely acts and in most cases barely observes, so nothing in the arrangement puts a named person on the hook for an individual output. Magnifica Humanitas names the danger in moral terms when it warns against handing moral responsibility to automated systems, and the draft definition allows exactly that handoff while still calling the result governance.

Every side of this year’s argument needs the same missing piece. If the market is the check, it needs evidence to price, and if liability is the check, it needs a record to steer by. If the warnings are sincere, sincerity needs something outside the speaker to verify it, and if they’re self-interested, the same record is what exposes them. Even the hoax claim needs those records, because a motive claim can’t be tested against nothing, and none of them exist without a named human who held the authority and owns the outcome.

The Record Going Forward

The U.S. position now moves forward without my proposed change to Clause 3.2, carrying the two editorial corrections and none of the substance. The enquiry ballot opened on July 6 for twelve weeks and has not closed, so the international text is not settled and the U.S. comments are one input among many. The full record, including my memo, the comment form, and the TAG’s disposition, stays public at basilpuglisi.com so readers can weigh both positions in the words each side used.

The question also travels upstream. Clause 3 already adopts neighboring definitions from ISO/IEC 22989, the AI vocabulary standard, and an amendment to that standard opened for committee consultation on August 28, 2026. Wherever AI governance gets defined next, the same test applies. When an AI output fails, a definition either names who answers or leaves the answer to no one, and the public has already said which one it expects.

Sources

Dicastery for Promoting Integral Human Development. (2026). Magnifica humanitas [Summary of the encyclical letter]. https://www.humandevelopment.va/en/magnifica-humanitas.html

International Organization for Standardization. (n.d.). ISO/DIS 21520: Project, programme and portfolio management, Artificial intelligence, Concepts, applications, and implications. https://www.iso.org/standard/91551.html

International Organization for Standardization & International Electrotechnical Commission. (2021). ISO/IEC Directives, Part 2: Principles and rules for the structure and drafting of ISO and IEC documents (9th ed.), Clause 16.

Leo XIV. (2026a, May 15). Magnifica humanitas: On safeguarding the human person in the time of artificial intelligence [Encyclical letter]. Vatican. https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html

Leo XIV. (2026b, May 25). Presentation and promulgation of the encyclical letter Magnifica humanitas [Address]. Vatican. https://www.vatican.va/content/leo-xiv/en/speeches/2026/may/documents/20260525-presentazione-enciclica.html

New York State Unified Court System. (2026). Part 161. Use of artificial intelligence technology. https://www.nycourts.gov/rules/part-161-use-artificial-intelligence-technology

POLITICO. (2026, September). Poll: Americans say there’s a serious risk of AI destroying humanity [The POLITICO Poll, conducted by Public First, September 13 to 15, 2026]. https://www.newsbreak.com/politico-560779/4889139951265-poll-americans-say-there-s-a-serious-risk-of-ai-destroying-humanity

Puglisi, B. C. (2026, March 14). AI Governance has no formal definition. Here is one. https://basilpuglisi.com/ai-governance-has-no-formal-definition-here-is-one/

  • International Organization for Standardization. (2021). ISO 37000:2021 Governance of organizations.
  • International Organization for Standardization. (2023). ISO/IEC 42001:2023 AI management systems.
  • National Institute of Standards and Technology. (2023). AI Risk Management Framework (AI RMF 1.0).
  • OECD. (2019). Recommendation of the Council on Artificial Intelligence.
  • UNESCO. (2021). Recommendation on the ethics of artificial intelligence.

Puglisi, B. C. (2026, September). AI Governance: The definition, its scope, and the record behind it [Public technical comment on ISO/DIS 21520, Clause 3.2]. https://basilpuglisi.com/iso-21520-ai-governance-comment/

  • New York State Unified Court System. (2026). Part 161. Use of artificial intelligence technology.
  • Regulation (EU) 2026/1744.
  • International Organization for Standardization. (n.d.). ISO/DIS 21520, Clause 3.

Puglisi, B. C. (2026, September 17). The AI HOAX distraction: Safety, money, and why you can’t tell which is driving. https://basilpuglisi.com/ai-hoax/

  • Amodei, D. (2026, September 12). We must pace the frontier.
  • Future of Life Institute. (2026, July). AI Safety Index: Summer 2026 edition.
  • W.R. Berkley Corporation. Form PC 51380 00 (06-24), Artificial Intelligence Exclusion (Absolute); Verisk ISO Form CG 40 47 01 26.
  • Directive (EU) 2024/2853, Revised Product Liability Directive.

Puglisi, B. C. (2026). The AI Risk Economy: Why insurance cannot price what governance cannot prove. basilpuglisi.com

Puglisi, B. C. (n.d.). Checkpoint-Based Governance (CBG). https://basilpuglisi.com/cbg/

Regulation (EU) 2026/1744 of the European Parliament and of the Council.

U.S. Technical Advisory Group to ISO/TC 258. (2026, September 21). Disposition of comments on ISO/DIS 21520 submitted by B. C. Puglisi [Comment form]. Project Management Institute.

Frequently Asked Questions

What does ISO/DIS 21520 Clause 3.2 define as AI governance?

Clause 3.2 defines artificial intelligence governance as an organizational framework of policies, roles, responsibilities and processes meant to ensure the accountable, secure, ethical and effective use of AI systems. The definition names accountability as a goal, yet it assigns that accountability to no particular person or role.

Why did the U.S. TAG reject the proposed change to Clause 3.2?

The TAG gave four reasons. It read the proposal as limiting governance to cases where a named human holds binding authority, stated that human control is desirable rather than always required, held that ISO definitions stay high level for global use, and noted that definitions cannot contain requirements.

Which comments on ISO/DIS 21520 were accepted?

Two editorial corrections were accepted as written. Clause 3.1 pointed to the AI system definition at 3.2 when it sits at 3.4, and Clause 3.4 said engineering system while its own note and the source standard say engineered system. Both corrections go to ANSI for the U.S. comments.

Can AI governance exist without human oversight or accountability?

The TAG’s position allows it, because a framework of policies and processes can exist with no person holding authority to stop an output. The opposing position holds that accountability requires someone who answers, so a definition without a governor describes management rather than governance.

What is the difference between Responsible AI and AI governance?

Responsible AI is machine checking machine. An agent is a machine, AI reviewing AI is a machine, and a watching human is machine on machine with a person nearby. AI governance, by contrast, puts a named person with binding authority on the hook for an individual output.

Do ISO rules allow human authority inside a definition?

The ISO/IEC Directives, Part 2, state that a definition shall not take the form of or contain a requirement. The same Directives allow a terminological entry to carry requirements in its notes to entry, so the drafting rule governs placement rather than whether governance needs a governor.

What do Americans think about the risks of advanced AI?

The POLITICO Poll, conducted by Public First from September 13 to 15, 2026, found that about two in three adults see at least a moderate risk that advanced AI could destroy humanity, with majorities across parties, genders and age groups. Roughly half believe the industry warnings are sincere.

#AIassisted using the HAIA Ecosystem | CC BY-NC-SA 4.0 Free for personal, educational, and noncommercial research use with attribution. Commercial exploitation, paid productization, and enterprise commercialization require separate permission and licensing.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Pinterest (Opens in new window) Pinterest
  • Email a link to a friend (Opens in new window) Email

Like this:

Like Loading…

Filed Under: AI Artificial Intelligence, AI Governance, AI Policy Regulation, AI Thought Leadership, Policy & Research, Thought Leadership Tagged With: AI accountability, AI Governance, AI Governance Definition, AI Policy, AI Regulation, AI Standards, Checkpoint-Based Governance, human oversight, ISO 21520, ISO TC 258, public trust in AI, Responsible AI

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Buy the eBook on Amazon

Multi-AI Governance

HAIA-RECCLIN Reasoning and Dispatch Third Edition free white paper promotional image with 3D book mockup and download button, March 2026, basilpuglisi.com

SAVE 25% on Governing AI, get it Publisher Direct

Save 25% on Digital Factics X, Publisher Direct

Digital Factics X

Legacy Blogs

HAIA: Human Artificial Intelligence Assistant

Checkpoint-Based Governance (CBG): A Constitutional Framework for Human-AI Collaboration

GOPEL v1.5: The Non-Cognitive Governance Layer That Automates Without Thinking

Cross AI Platform Review beyond the RECCLIN Dispatch

Why GOPEL Now Has Post-Quantum Cryptography and Confidential Processing

What 34 Reports Actually Told Us About AI: The Truth Behind the Hype, the Proof, and the Path Forward

#SMAC #SocialMediaWeek

Basil Social Media Week

Legacy Print:

Digital Factics: Twitter

© 2009–2026 Basil C. Puglisi, Creator of Factics™ and the HAIA Ecosystem

%d