The 13 AI Governance Frameworks
Comparing maturity, scope, and what differentiates them
The thirteen frameworks covered in this series share many structural elements — lifecycle governance, risk tiering, maturity models, human oversight provisions. They also share the same nominal vocabulary, which is precisely what makes them difficult to compare. Practitioners, vendors, and consultants use terms like “agentic governance,” “trust label,” and “runtime enforcement” with confidence that obscures the fact that those terms mean different things across the framework set.
The result is a landscape in which organizations selecting an AI governance approach are choosing between options whose actual differences they cannot articulate. Maturity claims are made without maturity definitions. Scope claims are made without scope boundaries. Runtime governance claims are made without distinguishing between policy enforcement at design time and continuous enforcement during live operation. The vocabulary problem is not academic — it is the reason most selection decisions are made on the basis of vendor familiarity, certification visibility, or institutional endorsement rather than on the substantive characteristics that determine fit.
This article does not solve the selection problem. It does not recommend one framework over another. What it does is lay out the eight dimensions across which the thirteen frameworks differ (the dimensions that determine what each framework will and will not help an organization do) and the patterns that emerge when the comparison is made honestly.
This is the ninth article in our ten-part series on AI governance. The previous article examined what regulators expect to see within 24 hours. This one examines the frameworks that organizations are using to organize their thinking : what each of them addresses, what each of them does not, and why the differentiation dimensions matter even before any selection conversation begins.
Framework Comparison Is Harder Than It Looks
Three structural facts make comparing AI governance frameworks harder than comparing, for example, frameworks in cybersecurity or data protection.
The frameworks are not all measuring the same thing. Some are maturity models : staged progression tools that score an organization’s current state. Some are governance frameworks : controls and processes that prescribe what an organization should do. Some are technical specifications : runtime enforcement mechanisms designed to be integrated into production systems. Some are commercial platforms — products that bundle assessment, monitoring, and certification into a single offering. Comparing a maturity model to a runtime enforcement framework to a commercial platform on a single axis produces noise rather than signal.
The frameworks were not designed to be compared. They emerged from different institutional contexts (academic research, vendor strategy, national regulator guidance, industry consortium effort, open-source community work) and they inherit the assumptions of those contexts. A framework designed by a national regulator for voluntary adoption by enterprises carries different assumptions about compliance posture than one designed by an academic research group for embedding in agent runtimes. The frameworks are not competing on the same dimensions because they were not designed to compete.
The agentic turn invalidated the comparison. Most frameworks were published before agentic AI was the dominant deployment model. The frameworks that were designed for agentic AI from the ground up (Singapore IMDA, MI9, AIGN, AISM, the Agentic Governance Framework) operate on a qualitatively different set of assumptions than the frameworks that extended existing AI governance methodology to cover agentic systems. Reading the comparison matrix requires understanding which frameworks are agentic-native and which are general AI governance that has been adapted, partially, to agentic realities.
These three facts do not make comparison impossible. They make it required that the comparison be done on the right axes; and that the axes be defined precisely before any framework is evaluated against them.
Eight Differentiating Dimensions
The thirteen frameworks can be meaningfully compared across eight dimensions. Each dimension answers a specific question that the framework selection conversation must address; even if the conversation is internal and does not result in a framework adoption.
Maturity
Maturity measures how developed the framework itself is : not how mature an organization is under it, but how established the framework is as a reference. The progression runs from Early (draft, in-progress, published without significant adoption) through Structured (formal but voluntary, with documented components) to Operational (actively deployed, with tooling and active user community) to Mature (broad adoption, formal certification path, integration into enterprise product ecosystems). Many frameworks in the AI governance space currently score Early because the agentic era is too recent for institutional adoption to have accumulated. Maturity is a useful diagnostic for how much community support, third-party validation, and ongoing investment an organization can expect when committing to a framework.
Scope
Scope measures what the framework covers. Policy-only frameworks provide documentation and governance language without specific technical controls. Technical controls frameworks specify particular controls (runtime policy engines, kill switches, audit log schemas) without prescribing the full lifecycle. Certification frameworks provide a certifiable assessment path. Full lifecycle frameworks cover design, build, test, deploy, run, and retire as a continuous sequence. Scope determines what an organization adopting the framework will still need to provide separately. A framework that covers policy but not runtime controls leaves the runtime control gap to be filled by other means.
Agentic Specificity
Agentic specificity measures how directly the framework addresses agentic AI systems. Generic frameworks apply general AI governance methodology without specific provisions for agentic properties. Explicit frameworks contain specific provisions for agents (risk tiering by autonomy level, agent classification, escalation playbooks) but were not designed for agentic AI from inception. Agentic-native frameworks were designed for agentic AI from the ground up, with control structures, risk taxonomies, and operational patterns that assume autonomous reasoning, planning, and tool use. Agentic specificity is the dimension most likely to determine whether the framework will hold up for the systems an organization is actually deploying, because the assumptions baked into pre-agentic frameworks do not always survive contact with agentic behaviors.
Regulatory Alignment
Regulatory alignment measures how the framework maps to binding legal obligations. None means no formal mapping. Mapped means the framework references or integrates with one or more regulatory frameworks; typically EU AI Act, NIST AI RMF, ISO 42001, GDPR, NIS2. Certified means the framework has a formal certification path that is recognized by a regulatory or standards body. CE marking capable means the framework is structured to support the conformity assessment process required for EU AI Act high-risk system providers. Regulatory alignment matters because frameworks that are not mapped to the binding obligations an organization faces require additional work to translate the framework controls into compliance evidence.
Runtime Governance
Runtime governance measures whether the framework operates during live system execution or only at design and deployment time. None or *Design-time only frameworks establish controls before deployment and do not provide mechanisms for live enforcement. Runtime controls frameworks include live monitoring, dynamic policy enforcement, and intervention mechanisms. Formal verification frameworks (a category that currently contains exactly one framework) provide mathematically grounded guarantees about behavioral conformance. The runtime dimension is critical because most agentic AI systems exhibit emergent behaviors that pre-deployment governance cannot fully anticipate. Frameworks that do not extend into runtime leave the governance gap that agentic systems create.
Certification
Certification measures whether the framework offers a recognized certification path. None means no certification available. Self-assessment means tools exist to score organization state but no third-party verification. Trust label means a non-ISO certification tier (AIGN, AISM). Formal certifiable means certification at the level of an ISO management system standard. Certification is a procurement and external signaling mechanism : organizations that need to demonstrate governance posture to customers, regulators, or partners frequently require something other than self-attestation.
Multi-Agent Governance
Multi-agent governance measures whether the framework addresses the specific governance challenges that arise when multiple agents operate in coordination : delegation chains, agent-to-agent messages, swarm dynamics, emergent group behavior. Most frameworks treat each agent as an independent governance target. Frameworks that explicitly address multi-agent coordination provide controls for delegation, escalation, and conflict resolution that single-agent frameworks do not. This dimension is increasingly important as agentic deployments move from single-agent to multi-agent architectures.
Open-Source Tooling
Open-source tooling measures whether the framework’s implementation or evaluation tooling is publicly available. Most frameworks are specification-only : they describe what should be done without providing the tooling to do it. A small number of frameworks ship with open-source tooling that organizations can install, audit, and extend. Open-source availability is a function of the framework’s institutional origin and matters most for organizations that need to understand the implementation details, integrate the framework into existing systems, or extend it to cover edge cases the specification does not address.
Patterns That Emerge In A Fair Comparison
The thirteen frameworks cluster in ways that are informative when the comparison is done on the eight dimensions above rather than on a single composite score.
The certification gap is structural. Only two of the thirteen frameworks (AIGN and AISM) offer formal trust labels or scored certification paths. No framework in the current set is at ISO certification level. Organizations that require certifiable governance have a small set of options to evaluate, and the absence of broader certification options is itself a fact about the maturity of the space.
The runtime governance gap is structural. Many frameworks are design-time or policy-time instruments. Only one framework (MI9) operates with formal verification properties during live execution. The gap is not accidental: runtime governance for agentic systems requires instrumentation, telemetry schemas, and intervention mechanisms that are operationally expensive to build and maintain. The frameworks that lack runtime governance are not necessarily incomplete; they are limited to the governance states that pre-deployment controls can address.
The agentic-specificity gap is closing but not closed. Of the thirteen frameworks, a clear majority (eight to nine) now include explicit provisions for agentic AI. The frameworks that are agentic-native from inception (Singapore IMDA, MI9, AISM, AIGN, the Agentic Governance Framework) represent a smaller subset. Organizations deploying agentic systems should distinguish between frameworks that include agentic provisions and frameworks that were designed for agentic AI; the assumptions underneath are different.
The institutional concentration is informative. Microsoft, GovTech Singapore, the World Economic Forum, and a small number of academic and industry groups anchor the most mature frameworks. Singapore IMDA is the only national-level framework that is explicitly agentic-native. This concentration matters because it determines which frameworks are likely to have sustained investment, formal regulatory engagement, and ongoing community development.
The “early” maturity consensus is the most important pattern. Most frameworks score Early on maturity because the agentic AI governance space is still nascent : most were published in 2025 or 2026. The frameworks that score Mature are the ones that have institutional backing and operational deployment histories that extend back further. For practitioners selecting a framework today, the maturity dimension is a measure of how much real-world validation the framework has accumulated and how much community support exists for the choices it makes.
Your Organization’s Role Matters More Than Your Framework Choice
The framework question is the wrong first question. The first question is more basic: what is your organization’s role with respect to the AI systems it has in production (provider, deployer, importer, distributor, or some combination) and what obligations does each role trigger under the EU AI Act.
The reason the role question precedes the framework question is that the obligation surface determines what the framework must address. A provider of high-risk AI systems faces Articles 9 through 17, Annex IV documentation requirements, conformity assessment, CE marking, EU database registration, and post-market monitoring obligations. A deployer of high-risk AI systems faces Article 26 obligations, six-month log retention, fundamental rights impact assessment where applicable, and serious incident reporting. A GPAI model provider faces Articles 53 through 55 obligations. A distributor or importer faces a different set of obligations again. The framework must be sized to the obligation, not the other way around.
This is why the eight dimensions above matter even before selection: each dimension is a question the framework must answer for the specific obligation surface the organization faces. An organization whose obligation surface is dominated by deployer obligations needs a framework that does well on operational maturity and runtime evidence generation. An organization whose obligation surface is dominated by provider obligations needs a framework that does well on certification, technical documentation, and conformity assessment support. The same framework can be the right answer for one role and the wrong answer for another; and many organizations hold multiple roles simultaneously.
The thirteen frameworks in this article are not competitors on a single score. They are different instruments designed for different points on the obligation surface. The selection conversation, when it occurs, is a conversation about which instrument covers which obligations; not a conversation about which framework wins.
Gaps and Open Questions in the Current Framework Set
The framework landscape carries five gaps that practitioners should be aware of when interpreting the comparison.
No dominant standard has emerged. Unlike SOC 2 for security, no equivalent certification body has become the de facto standard for AI governance. The closest candidates are AIGN and AISM, but neither has the institutional reach that SOC 2 commands in its domain.
Most frameworks are pre-regulatory or voluntary. Of the thirteen, the binding regulatory anchors are limited to the EU AI Act, NIST AI RMF, and ISO 42001; and only one is a regulation with direct legal force. The rest are specifications, guidelines, or voluntary frameworks that become relevant only when an organization maps them to a binding obligation.
Multi-agent governance is underexplored. Despite the agentic turn, only four frameworks explicitly address multi-agent dynamics. The delegation chain problem, the swarm behavior problem, and the liability allocation problem in multi-agent systems remain open implementation challenges.
Liability allocation is unsettled. When an autonomous agent takes action that causes harm, and the agent was operating within its delegated authority but the delegation chain was not properly configured, the framework does not specify who is liable. The legislative response to this question is still in development across jurisdictions.
Small organization applicability is an afterthought. Most frameworks assume enterprise-scale governance maturity. Lean teams and small organizations face the same obligation surface but rarely have the staff to implement comprehensive governance. The exception is GaaS, which explicitly targets lean teams; but the broader framework set has not internalized this constraint.
These gaps are not criticisms of the framework authors. They are properties of a field that is moving faster than the governance infrastructure can be assembled. The next article in this series examines what a real AI governance program actually requires when the framework choice has been made and the obligation surface has been mapped : the operational substrate that turns framework selection into compliance outcomes.
Download our free Framework Selection Criteria Worksheet: 8 Dimensions Evaluated.
Next: From Assessment to Action : What an AI Governance Program Requires


