AI-Governance Authoring Arc · Part 3 — a continuing series for technology executives on authoring the AI-governance standards that don’t exist yet. Earlier parts are linked at the end.
Most AI-governance advice tells you to implement the standards. The more useful move - and the larger opportunity - is to help write the ones that do not exist yet.
TL;DR
The common treatment of AI governance assumes there is a settled set of standards to implement. There is not. A few categories are mature - AI risk management, AI management systems, bank model risk. Most are emerging and non-normative - technical reports, taxonomies, and guidance with no “shall.” And several of the highest-stakes categories have no standard at all: agentic-agent governance, liability, meaningful human oversight, cross-industry safety and validation, incident reporting. The map is mostly blank. The substantive influence on what fills it is being captured now - by named authors, in citable comment letters and working-group seats. The move is two-sided: mature the standards that exist, and author the ones that do not.
The map is mostly blank
Set the AI-governance landscape side by side and the shape is striking: a few filled cells, a lot of empty ones. Risk management has NIST’s AI RMF and ISO/IEC 23894. An organization can certify a management system under ISO/IEC 42001. Banks have a model-risk regime. After that, coverage thins fast - much of what exists is a technical report or a taxonomy, not an auditable standard - and the categories that matter most for autonomous, high-consequence AI are empty.

The AI-governance landscape by maturity — three settled, four emerging guidance with no “shall,” and six with no standard at all. Each domain names its specific gap. (Illustrative, not exhaustive.)
The grid above maps the major governance domains, not the entire surface. It is illustrative, not exhaustive — a fast-moving layer of state and national rules sits outside it: Colorado’s AI Act and the wave of state measures behind it, workforce and AI-literacy mandates, and the growing treatment of AI governance as a return-on-investment lever rather than a compliance cost. Those move on their own clocks. The point of the map is not to enumerate every instrument; it is to show where an auditable, “shall”-bearing standard exists and where one still has to be written.
These gaps are not an accident of timing. Deployment is racing ahead of governance: agentic systems are shipping while the standard that would bound their authority does not exist. For instance, “meaningful human oversight” is required by law - the EU AI Act, Article 14 - with no standard yet defining what “meaningful” means; and the one cross-cutting attempt at an AI liability rule was abandoned. For most of these, no one has started.
Even the “settled” standards are moving
The mature cells are not finished either. The clearest case is bank model risk. The interagency Revised Guidance on Model Risk Management (SR 26-2), issued by the Federal Reserve, OCC, and FDIC on April 17, 2026, replaced fifteen years of guidance - SR 11-7 (2011) and SR 21-8 (2021) - that many institutions had treated as fixed. It carved generative and agentic AI explicitly out of scope, deferring them to a future request for information. The revised guidance even reframes itself as non-binding - it “does not set forth enforceable standards or prescriptive requirements” - and leaves agentic systems that orchestrate traditional models in an open governance gap. The baseline most compliance programs were built around is now superseded, and the AI part is openly unwritten. The patent side tells the same story: the USPTO’s February 2024 inventorship guidance was rescinded and reissued in November 2025 - a complete turn inside two years. Guidance that turns over that fast is not a finished object to comply with; it is a moving draft to influence. NIST, for its part, is actively extending the AI RMF - a 2025 update for generative-AI risk, a draft Cyber AI Profile, and critical-infrastructure profiles in progress - and the ISO/IEC 42001 family keeps growing, with companion standards for AI-system impact assessment (ISO/IEC 42005) and for the auditors who certify the management system (ISO/IEC 42006:2025). Treating any of these as a finished object to comply with is a mistake. The next draft is being written now.
From commentator to author
The move is from commentator to author, and the channels are more open than most executives assume. Three concrete steps:
Comment with text, not critique. For any standard or guidance open for comment, submit proposed replacement language, not a soft reaction - the record cites contributors by name. NIST accepts comments on the AI RMF at any time (AIframework@nist.gov); federal guidance runs through dated dockets on the Federal Register. A sharp LinkedIn post calling out a flaw — say, that the EU AI Act requires “meaningful human oversight” while no standard defines what “meaningful” means — can draw a thousand reactions and never enter the record. The identical argument, filed as docket text, reaches the record, draws a response, and carries your name. Only one of those is citable. Take a working-group seat - the door is wider than people think. The IEEE Standards Association uses an individual model: you can join a working group and contribute by attending meetings and joining the roster, with no membership required to participate (IEEE-SA membership matters for voting and leadership; Senior Member is a recognition grade, not a gate). Currently active and worth joining: the AI Ethics Oversight working group (P7999) and the IEEE Computer Society AI Standards Committee. For the international AI standards under ISO/IEC JTC 1/SC 42, US contributors participate through the US Technical Advisory Group, administered by INCITS. And new committees are still forming - ASTM stood up an AI-in-Manufacturing-Systems committee (F50) in 2026, an early seat for anyone who wants one. Keep a citable registry. Maintain a record of your authored contributions - named comments to standards, dockets, and frameworks, each with a full citation. Authorship that is not citable does not compound.
Isn’t this the regulator’s job?
The obvious objection is that this is the regulator’s job: wait for the final rule, comply with what gets published. That worked when the cycle ran in decades. It does not work when the model-risk baseline is replaced inside fifteen years, patent-office guidance is reissued inside two, and major AI frameworks revise on 12-to-24-month cycles - all while half the map has no standard to wait for. By the time a final rule lands, the people whose names are on the record have already shaped the field everyone else is measured against.
The AI-governance map is mostly blank, and the next drafts are being written this quarter - by named authors, in citable form. In a field this unfinished, an authoring posture beats a commentary posture every time. More in this series
The AI-Governance Authoring Arc — earlier parts:
Part 1 — AI Exclusions Are Just the Beginning: What Insurance Will Eventually Require Part 2 — Evaluation Without Seeing the Data
References
AI-governance frameworks. Nat’l Inst. of Standards & Tech., AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan. 2023), nist.gov (comments to AIframework@nist.gov); extended by the Generative AI Profile (NIST-AI-600-1, 2024) and a draft Cyber AI Profile (NIST IR 8596, 2025). Int’l Org. for Standardization & Int’l Electrotechnical Comm’n, ISO/IEC 42001:2023, AI Management System, iso.org; companion standards ISO/IEC 42005 (AI system impact assessment) and ISO/IEC 42006:2025 (requirements for AI-management-system auditors). ISO/IEC 23894:2023, Guidance on AI Risk Management, iso.org.
Standards bodies and participation. IEEE 7000-series (7000-2021, 7001-2021, 7002-2022, 7003-2024, published); active working groups: P7999 (AI Ethics Oversight) and the IEEE Computer Society AI Standards Committee; the AI-procurement standard has been published as IEEE 3119-2025. ISO/IEC JTC 1/SC 42 (Artificial Intelligence), iso.org; US participation via the INCITS AI committee (US TAG). ASTM Int’l committees F38 (Unmanned Aircraft Systems), F45 (Robotics, Automation & Autonomous Systems), and F50 (AI in Manufacturing Systems, formed 2026).
Model risk and supervisory guidance. Bd. of Governors of the Fed. Rsrv. Sys., Off. of the Comptroller of the Currency & Fed. Deposit Ins. Corp., Revised Guidance on Model Risk Management, SR 26-2 (Apr. 17, 2026), federalreserve.gov (superseding SR 11-7 (2011) and SR 21-8 (2021); generative and agentic AI carved out of scope); see also OCC Bulletin 2026-13. For a plain-language explainer, see Andy Boettcher, The Agencies Replace SR 11-7, Trepp (June 9, 2026), trepp.com.
Intellectual-property guidance. U.S. Patent & Trademark Office, Inventorship Guidance for AI-Assisted Inventions, 89 Fed. Reg. 10043 (Feb. 13, 2024) (comment period reopened to June 20, 2024), federalregister.gov; rescinded and replaced by Revised Inventorship Guidance for AI-Assisted Inventions, 90 Fed. Reg. 54636 (Nov. 28, 2025), federalregister.gov.
Mandates without a standard (the gaps). EU AI Act art. 14 (human oversight), euaiact.com. EU AI Liability Directive, withdrawn 2025, iapp.org. OECD, Towards a Common Reporting Framework for AI Incidents, oecd.ai. ANSI/UL 4600:2022, Standard for Safety for the Evaluation of Autonomous Products, oecd.ai catalogue.