AI‑OGF — Front Matter

Document Identifier: AIOGF‑00‑Front‑Matter
Framework Version: 0.9 (Draft)
Document Version: 1.6
Author: Randy Manthey
Last Updated: March 2026
Status: Working Draft
© 2025–2026 Randy Manthey. All Rights Reserved.

Table of Contents


Linked Supplements

4.x — Principles

5.x — Dependency Mapping

6.x — Autonomy & Identity Controls

7.x — Continuity and Safety Controls

8.x — AI Workflow Layer Limits (AI‑WLL)

9.x — AI Aware Continuity Planning

10.x — AI Isolation and Air Gaps

11.x — AI Monitoring and Drift Detection

12.x — Human Oversight and Intervention


1. Foreword

To be completed after the framework is finalized.
This section introduces the AI‑OGF, its origin, and its purpose in modern AI‑enabled environments.


2. Introduction

The AI Operational Governance Framework (AI‑OGF) provides a structured, standards‑aligned approach for governing AI systems across autonomy, identity, dependency mapping, workflow safety, and operational continuity.

AI‑OGF is organized into major control families (4.x–12.x), supported by supplemental documents that provide detailed implementation guidance.


2.1 Document Conventions

The AI‑OGF uses a hierarchical numbering system aligned with ISO and NIST standards.
“Must,” “shall,” and “required” indicate mandatory requirements.
“Should” indicates recommended practices.
Supplemental documents expand on specific controls and are referenced by section number.


2.2 Intended Audience

This framework is designed for:

  • CISOs
  • CTOs
  • AI platform owners
  • Engineering leaders
  • Risk & compliance teams
  • Operational technology leaders
  • AI governance and safety officers

2.3 Normative and Informative References

Normative references are required for compliance.
Informative references provide additional context.
(References will be added as the framework matures.)


2.4 Framework Structure

AI‑OGF is organized into the following major sections:

  • 4.x Principles
  • 5.x Dependency Mapping
  • 6.x Autonomy & Identity Controls
  • 7.x Continuity & Safety Controls
  • 8.x AI Workflow Layer Limits (AI‑WLL)
  • 9.x AI‑Aware Continuity Planning
  • 10.x AI Isolation & Air‑Gaps
  • 11.x AI Monitoring & Drift Detection
  • 12.x Human Oversight & Intervention
  • Glossary
  • Index

2.5 AI Deployment Models (Informative)

AI systems are deployed through a variety of architectural patterns, each with distinct operational characteristics, dependency structures, and governance implications. Understanding these deployment models is essential for applying the AI Operational Governance Framework (AI‑OGF) consistently across diverse environments.

The following eight deployment models represent the most common patterns observed in enterprise, cloud, agentic, and embedded AI systems. These models are descriptive rather than prescriptive and are provided to establish a shared reference for interpreting the principles and supplements that follow.


2.5.1 Local / Standalone AI

Definition:
AI that runs entirely on a local device or isolated server, without external network dependencies.

Examples:

  • Desktop LLM applications
  • Local inference engines (e.g., Ollama, LM Studio)
  • Air‑gapped robotics
  • Edge‑isolated inference nodes

Governance relevance:

  • Strong isolation and minimal external dependencies
  • Reduced exposure to external drift
  • Local identity and permission boundaries
  • Emphasis on fail‑safe defaults and safe‑mode behavior

2.5.2 Cloud API / Gateway AI

Definition:
AI accessed through API calls to a cloud provider or gateway service.

Examples:

  • OpenAI API
  • Azure OpenAI Service
  • Anthropic Claude API
  • AWS Bedrock

Governance relevance:

  • External dependency chains must be mapped
  • Identity‑bound authority and API key governance
  • Workflow depth and recursion limits
  • Monitoring for external model updates and drift

2.5.3 SaaS‑Embedded AI

Definition:
AI capabilities embedded within SaaS platforms where the underlying model is not directly visible or controllable.

Examples:

  • Microsoft 365 Copilot
  • Salesforce Einstein
  • ServiceNow AI
  • Zendesk AI

Governance relevance:

  • Governance focuses on usage, not model internals
  • Requires compensating controls for opaque systems
  • Identity and permission scoping is critical
  • Monitoring for unexpected behavior or drift

2.5.4 WebUI / Hosted Application AI

Definition:
AI accessed through a browser‑based interface rather than an API or programmatic agent.

Examples:

  • ChatGPT web
  • Claude web
  • Gemini web
  • Perplexity web

Governance relevance:

  • Human‑in‑the‑loop by default
  • Limited autonomy and workflow depth
  • Requires human override and checkpoint controls
  • Browser identity and session governance

2.5.5 Agentic / Orchestration Layer AI

Definition:
AI systems capable of calling tools, APIs, or other AIs, often operating as autonomous or semi‑autonomous agents.

Examples:

  • MCP (Model Context Protocol) agents
  • LangChain agents
  • AutoGen
  • CrewAI
  • Function‑calling LLMs

Governance relevance:

  • Highest autonomy and recursion risk
  • Requires Workflow Layer Limits (AI‑WLL)
  • Requires Constrained Autonomy Envelope (CAE)
  • Cross‑AI dependency mapping
  • Identity‑bound authority and escalation rules

2.5.6 Hybrid / Distributed AI

Definition:
AI that spans multiple environments or layers, combining local, cloud, SaaS, or agentic components.

Examples:

  • Local agent + cloud API
  • Edge inference + cloud refinement
  • On‑prem LLM + SaaS orchestration
  • Multi‑AI pipelines

Governance relevance:

  • Complex dependency chains
  • Multiple identity and permission domains
  • Cross‑AI interaction limits
  • Multi‑layer continuity and fallback planning

2.5.7 Embedded / Device‑Integrated AI

Definition:
AI integrated into hardware, robotics, IoT devices, industrial equipment, or autonomous systems.

Examples:

  • Autonomous drones
  • Industrial robotics
  • Smart appliances
  • Automotive AI systems

Governance relevance:

  • Physical‑world safety implications
  • Isolation and air‑gap requirements
  • Fail‑safe defaults and safe‑mode behavior
  • Strict continuity and override controls

2.5.8 Batch / Offline AI

Definition:
AI used in scheduled pipelines, ETL flows, or offline inference processes where outputs are generated asynchronously.

Examples:

  • Batch scoring pipelines
  • ETL‑embedded AI transformations
  • Offline model evaluation
  • Scheduled inference jobs

Governance relevance:

  • Transparency of inputs and outputs
  • Dependency mapping for upstream/downstream systems
  • Drift detection across batches
  • Monitoring for silent failures or degraded performance

Note:
A single AI system may fit more than one deployment model. These categories are intended to support consistent interpretation of AI‑OGF principles and supplements across varied architectures.


3. Purpose and Scope

3.1 Purpose

The purpose of the AI‑OGF is to ensure AI systems operate safely, predictably, and under human authority by defining autonomy boundaries, dependency structures, workflow limits, continuity requirements, and operational safeguards.

A core objective of the AI‑OGF is to ensure clear accountability for all AI‑initiated actions. The framework establishes the expectation that organizations—not AI systems, not engineers, and not vendors—retain responsibility for outcomes resulting from AI behavior. AI‑OGF provides the structure necessary for organizations to understand, assign, and maintain accountability across the full lifecycle of AI‑driven operations.

The AI‑OGF also aims to build organizational awareness of continuity considerations as AI becomes increasingly integrated into business processes. As AI systems replace or augment human roles, new dependencies and potential points of failure emerge. The framework highlights these risks and provides guidance to ensure continuity planning evolves alongside AI adoption, preventing operational blind spots and ensuring resilience in AI‑dependent environments.

3.2 Scope

The AI‑OGF applies to all AI systems that interact with infrastructure, humans, or other AI systems.
It is designed as an operational governance framework focused on autonomy boundaries, dependency structures, workflow safety, and continuity.

AI‑OGF is not intended to be prescriptive, nor does it replace existing AI governance or risk frameworks such as the NIST AI RMF, ISO/IEC 42001, or other organizational, regulatory, or industry‑specific standards.

Instead, AI‑OGF is designed to complement and integrate with these frameworks by providing operational, implementation‑level guidance for environments where AI interacts with infrastructure, identity systems, and automated workflows.

3.2.1 In Scope

  • Autonomy levels and boundaries
  • Identity‑bound authority
  • Dependency mapping
  • Workflow safety
  • Continuity and fallback
  • Drift detection and monitoring
  • Isolation and air‑gap strategies
  • Human oversight and intervention

3.2.2 Out of Scope

  • Ethical AI and fairness
  • HR or personnel policy
  • Legal compliance specifics
  • Data governance and privacy frameworks
  • Model training ethics or bias mitigation
  • Organizational culture or change management
  • Full‑stack AI risk management (covered by frameworks such as NIST AI RMF)

Glossary

(To be developed)


Index

(To be developed)

This document is part of the AI Operational Governance Framework (AI-OGF) and is protected under the AI‑OGF Limited Use License.
Official source: https://rmanthey-mantheyco.github.io/ai-ogf/


This site uses Just the Docs, a documentation theme for Jekyll.