An operating manual for institutions that buy, deploy, and run AI systems
Version 1.0, 1 October 2026. doi:10.5281/zenodo.22986774
AI governance is being written for the organisations that build AI. It will be lived by the organisations that deploy it. Nearly all published guidance addresses the developers of models, with their evaluation teams and compliance departments. Almost none of it addresses the institution that buys a system, installs it, and runs it inside decisions about care, money, benefits, education, or essential services. That institution typically has a procurement office, an IT team at capacity, a vendor’s sales deck, and a deadline. The gap is visible in the instruments themselves: most of the EU AI Act’s obligations attach to providers of systems. This framework fills that gap: an operational manual for adopting and running AI responsibly, written for the deployer’s seat.
Five operating rules, each turned into checklists, clauses, and signatures: accountability names a person; evidence comes before trust; oversight carries real authority; watching continues after go-live; and you can always leave.
It restates no principles and competes with no standard. It maps visibly onto the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, the OECD AI Principles, and the UNESCO Recommendation on the Ethics of AI, so work done under it is evidence of movement towards recognised standards, and where any law applies, the law prevails. It states what it cannot do and names the few points where an institution must buy specialist help.
A technology or operations lead inside an institution adopting AI: a public hospital, a ministry, a municipal utility, a regional bank, a tax authority, a school system, a mid-sized enterprise. It assumes no AI expertise, no compliance department, and no budget for consultants. It covers systems you buy and run, both predictive (systems that score, rank, classify, or forecast) and generative (systems that produce text, images, or code). Systems authorised to act on their own (agentic systems) are covered through Module 2’s autonomy rules, which treat an adverse action taken without prior human review as a matter for escalation.
This is Version 1.0. Every file, including the editable artifacts, is free to download from ystech.io/ai-governance without registration. Revised versions are published there with a version history that records what changed and why. The publisher decides revisions. Earlier versions remain available, so each institution decides when to move to a new version; the system register (Artifact 7.11) records the version it adopted.
Each artifact repeats its own instructions, carries its own licence line, and works without its parent module.
Write to Anuuj Chauhan, Co-Founder and CEO of Yellow Sapphire Technologies, at [email protected] when an artifact fails in practice, a checklist is missing a question, a passage does not survive translation, you find an error, or you have an improvement to suggest. The authors will read every message. Institutions adopting the framework can use the same address to arrange a conversation with the authors about implementation, at no charge. A contribution that leads to a material change in a checklist, clause, or definition is acknowledged in a later version, with the contributor’s consent.
Community translations are welcome under the licence and will be linked from the framework page. A translation is official only when the publisher has commissioned and checked it, and every translation states the version it was made from.
Written and published by Yellow Sapphire Technologies Inc. as the delivery of a commitment registered through the Partnerships Hub of the United Nations Global Dialogue on AI Governance; it was not endorsed, approved, or authored by the United Nations. Published free of charge under CC BY 4.0: any institution may use, adapt, translate, and localise it, with attribution.
This framework is guidance and it is not legal advice. Full disclaimers in the back matter.