The Defensible AI Framework Registry: Definitions and Relationships for the Governed Production AI Discipline
A body of frameworks that shares an author does not thereby share an architecture. Nine frameworks for governing artificial intelligence in regulated institutions were developed and published separately, each answering a question a supervisor or a board had asked. Read together they carried three defects that no individual framework could show: three separate names described one subject, two instruments measured the same maturity, and nothing stated why any of them belonged in the same system as the others. This registry is the instrument that fixes those defects and the authoritative record of the result. It states one architecture for the nine, assigns each framework a stable identifier and a canonical name, and publishes a normative relationship register naming which framework supplies the artifact, evidence or authority another depends on. The architecture rests on two propositions that are already published and separately citable. The MESA Framework™, a four-altitude diagnostic model for institutional AI governance, supplies the frame: governance is an alignment condition across those altitudes, so maturity is reported as a per-altitude profile rather than as a single grade. The Boundary Invariant supplies the engineering law: a boundary is a clause the optimizer may not cross, and everything else is optimization. Between them they fix the two directions in which the composed system is read. Authority flows down, from the altitude that binds to the control that executes. Evidence flows up, from the record a control writes to the profile the institution reports. Each of the nine entries carries a definition, a purpose, an altitude or boundary class, inputs, outputs, one accountable role, an evidence requirement, its relationships, its limitations, the condition that would falsify it, and its change history. Every accountable role must be occupiable by one person: a committee can be consulted, can review and can decide, but cannot be accountable, because the question an authority asks after a failure is which person is answerable. The entry schema is normative and is published in machine-readable form as registry-v2.0.json, validated against a published JSON Schema, so that a machine interface and the document cannot drift apart without one of them failing a test. Relationships are asserted once and read from both ends: the converse of an edge is derived, never authored, because a dependency written down twice is a dependency that can be written down twice differently. The registry is also the dated instrument of a consolidation. Three marks are recorded as consolidated into one framework, one instrument as superseded, one framework as renamed, and one as repositioned from peer framework to worked instance of the Boundary Invariant. Twelve asserted marks became eight marks and one deliberately unmarked framework at version 1.0. At version 2.0 the unmarked framework is renamed to CADRE™ and marked, giving nine marks, and every entry now points at a standalone deposited specification. The contribution is architectural rather than empirical. The registry describes a composition. No institution unconnected to the author has been observed operating the composed set, no framework in it carries an independent evaluation, and the specification states separately what would falsify the composition and what would falsify any framework within it. Two frameworks depend on an authority that has not acted: no Shariah Supervisory Board has reviewed the dual-authority architecture, and no trademark clearance search has been completed on the deployment model's name. Both are recorded in their entries rather than left to be discovered. It is a specification, not a certification scheme, and no conformity assessment body operates against it.
Authors
- Nabeel A. Khan (ORCID: https://orcid.org/0009-0005-5364-914X)
Institutions
- Instituto Superior Manuel Teixeira Gomes (PT)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-15
- DOI
- https://doi.org/10.5281/zenodo.22775350
- Primary Topic
- Ethics and Social Impacts of AI
- Type
- article
- Field-Weighted Citation Impact
- 0.00