Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (9)

Search Parameters:
Keywords = ISO/IEC 42001

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
22 pages, 338 KB  
Perspective
Governing Agentic AI: The Human Values Alignment Framework (HVAF-A) as a Policy Tool
by Mousa Al-kfairy
Appl. Syst. Innov. 2026, 9(9), 187; https://doi.org/10.3390/asi9090187 - 3 Sep 2026
Viewed by 514
Abstract
Agentic artificial intelligence (AI) systems—software that plans, acts, and decides without step-by-step human approval—are already deployed in finance, healthcare, recruitment, and public services. They differ from earlier AI in one critical way. They do not produce outputs for a human to accept or [...] Read more.
Agentic artificial intelligence (AI) systems—software that plans, acts, and decides without step-by-step human approval—are already deployed in finance, healthcare, recruitment, and public services. They differ from earlier AI in one critical way. They do not produce outputs for a human to accept or reject. They take actions. Those actions may be irreversible. They may affect people who never used the system. Existing governance frameworks were not designed for this. Current alignment approaches—including reinforcement learning from human feedback, constitutional AI, and preference aggregation—assume that a well-aligned system satisfies what users ask for. This paper argues that the assumption fails in agentic contexts. What people ask for is not what they value. Preferences are volatile and user-centric. Values are stable, culturally grounded, and other-regarding. This paper proposes the Human Values Alignment Framework for Agentic AI (HVAF-A), grounded in Schwartz’s cross-culturally validated Basic Human Values theory. The framework connects value inputs, three alignment mechanisms (elicitation, arbitration, and propagation), and governance outcomes at individual, organizational, and societal levels. The paper positions the HVAF-A against the main international policy instruments—the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, and the OECD and UNESCO principles—and specifies an empirical program of constructs, measures, validity tests, and study designs. An illustrative case study of an agentic hiring system shows how the framework would operate. This is a purely conceptual study. No study was conducted and no instrument was administered to validate the model. A dedicated section states the framework’s boundary conditions. Empirical validation is set out as future research. Full article
(This article belongs to the Section Information Systems)
Show Figures

Figure 1

27 pages, 1709 KB  
Article
A Strategic Engineering Algorithm for Implementing Cobots (HCDXI) in Industrial Operations: Integration with Advanced Management Systems
by Alena Pauliková, Tomáš Brlej and Henrieta Hrablik Chovanová
Processes 2026, 14(17), 2780; https://doi.org/10.3390/pr14172780 - 29 Aug 2026
Viewed by 380
Abstract
The implementation of collaborative robots (cobots) in Industry 5.0 requires a synergistic connection between technical safety and integrated management systems (IMSs). This article introduces three newly defined interaction concepts that map technological evolution: HCDI, an approximation for Industry 4.0; HCDXI, designed [...] Read more.
The implementation of collaborative robots (cobots) in Industry 5.0 requires a synergistic connection between technical safety and integrated management systems (IMSs). This article introduces three newly defined interaction concepts that map technological evolution: HCDI, an approximation for Industry 4.0; HCDXI, designed for anthropocentric Industry 5.0; and aICDXI, which anticipates the emerging cognitive era of artificial intelligence. The principal contribution is an original four-phase engineering algorithm for cobot implementation linked to thirteen ISO standards, including ISO 9001, ISO 45001, ISO 14001, ISO/IEC 27001, and ISO/IEC 42001. The algorithm applies the multicriteria SCATI method for process prioritization and the probabilistic reliability performance index (RPI) based on conditional probabilities as an operational reliability acceptance gate, distinct from ISO/TS 15066 functional safety requirements. IMS synergies are visualized by the Synergy HOUSE architectural model. The methodology was validated in an optical quality-inspection cell consisting of MiR100 + UR5e + Robotiq + Smart Vision ADMIN 4.0. Evaluated via Monte Carlo simulation, the pre-operational index reached RPI = 0.9801. Deployment of the node demonstrated a 60.0% increase in productivity, a 64.5% decrease in the defect rate, a statistically significant 32.0% reduction in cognitive workload, and a 50.0% reduction in total energy consumption (ISO 50001), enabled by the transition to lights-out operation. At the same time, the energy paradox of edge cooling for AI was described. The results confirm the robustness of the algorithm for systematic and sustainable enterprise transformation. Full article
(This article belongs to the Section Manufacturing Processes and Systems)
Show Figures

Figure 1

30 pages, 712 KB  
Review
AI Risk Governance for Advancing Digital Sovereignty in Data-Driven Systems: An Integrated Multi-Layer Framework
by Segun Odion and Santosh Reddy Addula
Future Internet 2026, 18(4), 209; https://doi.org/10.3390/fi18040209 - 15 Apr 2026
Cited by 2 | Viewed by 2900
Abstract
The integration of algorithmic systems into critical digital infrastructure is no longer peripheral to governance, it is governance. As AI-mediated decisions influence credit access, clinical diagnoses, criminal risk scores, and infrastructure routing, the question of who controls these algorithms and whether that control [...] Read more.
The integration of algorithmic systems into critical digital infrastructure is no longer peripheral to governance, it is governance. As AI-mediated decisions influence credit access, clinical diagnoses, criminal risk scores, and infrastructure routing, the question of who controls these algorithms and whether that control is meaningful has become a central concern for states and institutions at every level of development. Existing frameworks, including the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act, have made real progress toward structured AI governance. However, none treats digital sovereignty as a first-order goal, nor do they provide integrated cross-layer guidance applicable across the diverse institutional landscape found worldwide. From this synthesis, we develop the Integrated AI Risk Governance Framework (IARGF): a four-layer structure covering policy and regulations, institutional oversight, technical controls, and operational execution, organized around five risk categories—technical, ethical, security, systemic, and sovereignty-related. A comparative analysis with major existing frameworks highlights the IARGF’s unique contributions, especially its explicit focus on sovereignty, adaptability across different institutional capacities, and recursive feedback mechanisms that connect all four governance layers. The framework is analyzed across three domains—healthcare AI, financial services, and critical infrastructure—to demonstrate its practical utility. Results confirm that governance effectiveness is a system property, not just a feature of individual layers; that digital sovereignty is both a governance goal and a distinct risk dimension with specific technical and institutional needs; and that context-aware, capacity-scaled governance is a design requirement, not a political compromise. The IARGF is presented as a conceptual governance model based on a systematic literature review rather than an empirically validated tool, and it remains to be tested in actual organizational settings. Its main contribution is the comprehensive theoretical integration of sovereignty, institutional capacity, and inter-layer governance dynamics, rather than proven performance advantages over existing models. Future research should aim to validate this framework through longitudinal case studies, expert panels, and retrospective failure analyses. Full article
(This article belongs to the Special Issue Security and Privacy in AI-Powered Systems)
Show Figures

Graphical abstract

24 pages, 1959 KB  
Article
LLM-Augmented Algorithmic Management: A Governance-Oriented Architecture for Explainable Organizational Decision Systems
by Nikolay Hinov and Maria Ivanova
AI 2026, 7(3), 102; https://doi.org/10.3390/ai7030102 - 10 Mar 2026
Cited by 4 | Viewed by 3077
Abstract
Algorithmic management systems increasingly coordinate work, allocate resources, and support decisions in corporate, public sector, and research environments. Yet many such systems remain opaque: they optimize and score effectively but struggle to communicate rationales that are contextual, auditable, and defensible under emerging governance [...] Read more.
Algorithmic management systems increasingly coordinate work, allocate resources, and support decisions in corporate, public sector, and research environments. Yet many such systems remain opaque: they optimize and score effectively but struggle to communicate rationales that are contextual, auditable, and defensible under emerging governance expectations. Large language models (LLMs) can help bridge this gap by translating quantitative signals into human-readable explanations and enabling interactive clarification. However, LLM integration also introduces new risks—hallucinated rationales, bias amplification, prompt-based security failures, and automation dependence—that must be governed rather than merely engineered. This article proposes a governance-oriented architecture for LLM-augmented algorithmic management. The model combines the following elements: an algorithmic decision core; an LLM-based cognitive interface for explanation and dialogue, and a verification and governance layer that enforces policy constraints, provenance, audit trails, and human-in-command oversight. The framework is developed through targeted conceptual synthesis and normative alignment with key governance instruments (e.g., the EU AI Act, GDPR, and ISO/IEC 42001). It is illustrated through cross-domain scenarios and complemented by a demonstrative synthetic-trace simulation that highlights transparency–latency trade-offs under verification controls. Using the demonstrative simulation (n = 120 decision events), the framework illustrates a mean baseline latency of 100.3 ms and a mean LLM-augmented latency of 115.8 ms (≈15.5% increase), a mean explanation validity proxy of 85.6%, and a simulated constraint-satisfaction rate of 94.2% (113/120 events), with failed cases routed to review. These values are presented as design-level indicators of operational plausibility and governance trade-offs, not empirical performance benchmarks or state-of-the-art comparisons. The paper contributes a conceptual and governance-oriented architectural blueprint for integrating generative AI into organisational decision systems without sacrificing accountability, compliance, or operational reliability. Full article
Show Figures

Figure 1

41 pages, 815 KB  
Article
XAI-Compliance-by-Design: A Modular Framework for GDPR- and AI Act-Aligned Decision Transparency in High-Risk AI Systems
by Antonio Goncalves and Anacleto Correia
J. Cybersecur. Priv. 2026, 6(2), 43; https://doi.org/10.3390/jcp6020043 - 2 Mar 2026
Cited by 4 | Viewed by 4256
Abstract
High-risk Artificial Intelligence (AI) systems deployed in cybersecurity and privacy-critical contexts must satisfy not only demanding performance targets but also stringent obligations for transparency, accountability, and human oversight under the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act). Existing [...] Read more.
High-risk Artificial Intelligence (AI) systems deployed in cybersecurity and privacy-critical contexts must satisfy not only demanding performance targets but also stringent obligations for transparency, accountability, and human oversight under the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act). Existing approaches often treat these concerns in isolation as follows: Explainable Artificial Intelligence (XAI) methods are added ad hoc to machine learning pipelines, while governance and regulatory frameworks remain largely conceptual and weakly connected to the concrete artefacts produced in practice. This article proposes XAI-Compliance-by-Design, a modular framework that integrates XAI techniques, compliance-by-design principles and trustworthy Machine Learning Operations (MLOps) practices into a unified architecture for high-risk AI systems in cybersecurity and privacy domains. The framework follows a dual-flow design that couples an upstream technical pipeline (data, model, explanation, and monitoring) with a downstream governance pipeline (policy, oversight, audit, and decision-making), orchestrated by a Compliance-by-Design Engine and a technical–regulatory correspondence matrix aligned with the GDPR, the AI Act, and ISO/IEC 42001. The framework is instantiated and evaluated through an end-to-end, Python-based proof of concept using a synthetic, intrusion detection system (IDS)-inspired anomaly detection scenario with a Random Forest (RF) classifier, Shapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME), drift indicators, and tamper-evident evidence bundles and decision dossiers. The results show that, even in a modest, toy setting, the framework systematically produces verifiable artefacts that support auditability and accountability across the model lifecycle. By linking explanation reports, drift statistics and compliance logs to concrete regulatory provisions, the approach illustrates how organisations operating high-risk AI for cybersecurity and privacy can move from model-centric optimisation to evidence-centric governance. The article discusses how the proposed framework can be generalised to real-world high-risk AI applications, contributing to the operationalisation of European digital sovereignty in AI governance. This article does not introduce a new intrusion detection algorithm; instead, it proposes an evidence-centric governance pipeline that captures decision provenance and compliance artefacts so that decisions can be audited and justified against regulatory obligations. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Graphical abstract

20 pages, 465 KB  
Article
Cross-Assessment & Verification for Evaluation (CAVe) Framework for AI Risk and Compliance Assessment Using a Cross-Compliance Index (CCI)
by Cheon-Ho Min, Dae-Geun Lee and Jin Kwak
Electronics 2026, 15(2), 307; https://doi.org/10.3390/electronics15020307 - 10 Jan 2026
Viewed by 1633
Abstract
This study addresses the challenge of evaluating artificial intelligence (AI) systems across heterogeneous regulatory frameworks. Although the NIST AI RMF, EU AI Act, and ISO/IEC 23894/42001 define important governance requirements, they do not provide a unified quantitative method. To bridge this gap, we [...] Read more.
This study addresses the challenge of evaluating artificial intelligence (AI) systems across heterogeneous regulatory frameworks. Although the NIST AI RMF, EU AI Act, and ISO/IEC 23894/42001 define important governance requirements, they do not provide a unified quantitative method. To bridge this gap, we propose the Cross-Assessment & Verification for Evaluation (CAVe) Framework, which maps shared regulatory requirements to four measurable indicators—accuracy, robustness, privacy, and fairness— and aggregates them into a Cross-Compliance Index (CCI) using normalization, thresholding, evidence penalties, and cross-framework weighting. Two validation scenarios demonstrate the applicability of the approach. The first scenario evaluates a Naïve Bayes-based spam classifier trained on the public UCI SMS Spam Collection dataset, representing a low-risk text-classification setting. The model achieved accuracy 0.9850, robustness 0.9945, fairness 0.9908, and privacy 0.9922, resulting in a CCI of 0.9741 (Pass). The second scenario examines a high-risk healthcare AI system using a CheXNet-style convolutional model evaluated on the MIMIC-CXR dataset. Diagnostic accuracy, distribution-shift robustness, group fairness (finding-specific group comparison), and privacy risk (membership-inference susceptibility) yielded 0.7680, 0.7974, 0.9070, and 0.7500 respectively. Under healthcare-oriented weighting and safety thresholds, the CCI was 0.5046 (Fail). These results show how identical evaluation principles produce different compliance outcomes depending on domain risk and regulatory priorities. Overall, CAVe provides a transparent, reproducible mechanism for aligning technical performance with regulatory expectations across diverse domains. Additional metric definitions and parameter settings are provided in the manuscript to support reproducibility, and future extensions will incorporate higher-level indicators such as transparency and human oversight. Full article
(This article belongs to the Special Issue Artificial Intelligence Safety and Security)
Show Figures

Figure 1

22 pages, 1015 KB  
Systematic Review
Gaps in AI-Compliant Complementary Governance Frameworks’ Suitability (for Low-Capacity Actors), and Structural Asymmetries (in the Compliance Ecosystem)—A Systematic Review
by William Walter Finch and Marya Butt
J. Cybersecur. Priv. 2025, 5(4), 101; https://doi.org/10.3390/jcp5040101 - 18 Nov 2025
Cited by 11 | Viewed by 6981
Abstract
This review examines AI governance centered on Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the EU Artificial Intelligence Act), alongside comparable instruments (ISO/IEC 42001, NIST AI RMF, OECD [...] Read more.
This review examines AI governance centered on Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the EU Artificial Intelligence Act), alongside comparable instruments (ISO/IEC 42001, NIST AI RMF, OECD Principles, ALTAI). Using a hybrid systematic–scoping method, it maps obligations across actor roles and risk tiers, with particular attention to low-capacity actors, especially SMEs and public authorities. Across the surveyed literature, persistent gaps emerge in enforceability, proportionality, and auditability, compounded by frictions between the AI Act and GDPR and fragmented accountability along the value chain. Rather than introducing a formal model, this paper develops a conceptual lens—compliance asymmetry—to interrogate the structural frictions between regulatory ambition and institutional capacity. This framing enables the identification of normative and operational gaps that must be addressed in future model design. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

14 pages, 465 KB  
Article
Assessment of the Benefits of the ISO/IEC 42001 AI Management System: Insights from Selected Brazilian Logistics Experts: An Empirical Study
by Alanna Oeiras da Costa Mazzinghy, Raurielly Maria dos Santos e Silva, Reimison Moreira Fernandes, Edney Dias Batista, Ailson Renan Santos Picanço, Nathália Jucá Monteiro, Daniel Meireles de Amorim, Brenda de Farias Oliveira Cardoso, Jonhatan Magno Norte da Silva and Vitor William Batista Martins
Standards 2025, 5(2), 10; https://doi.org/10.3390/standards5020010 - 21 Mar 2025
Cited by 4 | Viewed by 6203
Abstract
(1) Background: This study aimed to analyze and rank the benefits of adopting Artificial Intelligence (AI) in the logistics area, considering the opinions of professionals working in the Brazilian logistics sector through the implementation of ISO/IEC 42001. (2) Methods: The procedures adopted included [...] Read more.
(1) Background: This study aimed to analyze and rank the benefits of adopting Artificial Intelligence (AI) in the logistics area, considering the opinions of professionals working in the Brazilian logistics sector through the implementation of ISO/IEC 42001. (2) Methods: The procedures adopted included a literature review to identify the benefits of the use and the application of a survey aimed at professionals in the logistics sector. The analysis used the TOPSIS method to identify and rank the most decisive benefits. (3) Results: Of the 15 benefits mapped in the literature, the professionals attributed the greatest importance to customer satisfaction, operational efficiency, incentives for innovation, and improving the company’s image and competitive advantage. The results indicate that adopting ISO/IEC 42001 not only promotes process optimization and cost reduction, but also encourages innovation and strengthens competitiveness in the market. (4) Conclusions: The implementation of this standard is vital for companies in the logistics sector, especially in a Brazilian context of major infrastructural and regulatory challenges. The findings highlight the need for a strategic approach to the adoption of AI, emphasizing the importance of efficient logistics management and ethical practices in the application of this technology. Full article
Show Figures

Figure 1

21 pages, 3922 KB  
Article
Maximising Synergy: The Benefits of a Joint Implementation of Knowledge Management and Artificial Intelligence System Standards
by Natalia Khazieva, Alena Pauliková and Henrieta Hrablik Chovanová
Mach. Learn. Knowl. Extr. 2024, 6(4), 2282-2302; https://doi.org/10.3390/make6040112 - 8 Oct 2024
Cited by 12 | Viewed by 5511
Abstract
Implementing management systems in organisations of all types and sizes often raises the following question: “What benefits will this bring?” Initial resistance and criticism are common as potential challenges are identified during the implementation process. To address this, it is essential to highlight [...] Read more.
Implementing management systems in organisations of all types and sizes often raises the following question: “What benefits will this bring?” Initial resistance and criticism are common as potential challenges are identified during the implementation process. To address this, it is essential to highlight the advantages of these systems and engage stakeholders in supporting management efforts. While the planning, implementation, use, maintenance, auditing, and improvement of management systems are generally voluntary, certification is frequently driven by external factors, particularly customer demands. Employees also stand to gain significantly, with knowledge and information serving as valuable resources, especially for leveraging artificial intelligence. This article explores the management’s readiness to adopt and fully utilise two management systems based on international standards: the ISO 30401 Knowledge management system (KMS) and the ISO/IEC 42001 Artificial intelligence management system (AIMS). Through interviews, we assess the challenges and solutions associated with implementing these systems, whether planned or partially adopted. The findings illustrate the synergistic benefits of integrating the KMS and AIMS, demonstrating how their combined use can enhance Integrated Management Systems (IMSs). Such integration supports comprehensive planning, operation, and performance evaluation of processes and services while also promoting continuous improvement. Full article
(This article belongs to the Section Data)
Show Figures

Figure 1

Back to TopTop