Published August 30, 2026 | Version 1.0

The Five-Gate Deployment Model: A Deployment Discipline for AI Systems

Authors/Creators

  • 1. iSystematic Inc.

Description

An institution can be asked two questions about an AI system in production. The first is whether it works. The second is how it got there, and who said it could. The second question is the one a supervisor, an auditor or a board asks after something has gone wrong, and it is the one most institutions answer worst, because the machinery that put the system into production was built to move work forward rather than to record who accepted what.

This specification defines the Five-Gate Deployment Model™, a deployment discipline for AI systems. No AI system reaches production, or remains there, except by passing five gates in order: G1 Data and Design, G2 Validation, G3 Approval, G4 Deployment and G5 Operation. Each gate carries entry criteria supplied by a named framework, exit criteria, a defined rejection path, one accountable person, and a required evidence record. A gate with no rejection path is not a gate; a checkpoint that can only be passed is a formality.

Two properties distinguish the model from the machinery it sits beside. The accountable role at every gate is a single named person and must not be a committee. A committee can be consulted, can review, challenge, advise and decide, and it cannot be accountable, because accountability distributed across a body is accountability no member of that body carries alone. The question an authority asks after a failure is which person is answerable. And every gate passage record is an instance of the BOE Declaration: the entry criteria are the boundary the gate fixes, the deployment freedom granted on passage is the optimizer it frees, and the record is the evidence that the boundary held. That mapping is not presentational. It is what lets a gate record be joined with a validation record, a residency attestation and a vendor screening record during an incident reconstruction, rather than merely filed alongside them, because two controls that emit evidence in one shape compose and two that do not are adjacent.

Two paths run backwards through the model and are part of it rather than exceptions to it. Rollback reverses gate five to gate four with the evidence of the reversal preserved, because a rollback that removes the system and its records leaves the institution unable to reconstruct what the system did while it was live, which is precisely the period an authority will ask about. Loop-back reopens gate two when an incident occurs at gate five, on the reasoning that an incident is evidence about the validation as much as about the system: a patch applied without reopening validation changes the system and leaves the assessment of the system untouched, so the institution's belief about the system becomes older than the system.

The specification states plainly what would falsify the model, and states it against the hardest comparison rather than the easiest: that institutions operating five gates with a single named accountable person at each are found to deploy unfit AI systems at the same rate, and with the same severity of consequence, as institutions operating an automated delivery pipeline enforcing equivalent entry criteria with no named approver. No institution unconnected to the author has been observed operating the full sequence. No readiness instrument exists, no gate evidence templates are published, and no trademark clearance search has been completed on the name. Each of those is stated in the document rather than left to be discovered.

It is a specification, not a certification scheme, and no conformity assessment body operates against it.

Table of contents (English)

1. Introduction 2. Conceptual Model (Normative) 3. The Five Gates (Normative) 4. Reverse Paths (Normative) 5. The BOE Mapping (Normative) 6. Conformance (Normative) 7. Related Work 8. Limitations and What Has Not Been Tested 9. Versioning 10. References Appendix A. Publication Provenance

Technical info (English)

Version 1.0 of the specification. 17 pages as rendered, with every figure as vector artwork rather than a raster image. 11 numbered sections and appendices, of which 5 are normative. 3 source SVG figures accompany the record and are reusable under the same licence. 8 references, each verified against a primary source. The Markdown source of record is deposited alongside the PDF, so the text is machine-readable without extraction.

Notes (English)

No version DOI is supplied here: Zenodo mints one per version at publish time, and the concept DOI is what the document cites. The Defensible AI Framework Registry is cited at reference [3] and declared as a references relation by its reserved concept DOI. That record publishes last in the sequence of eight, because it cites the final identifier of every record it registers, so the relation resolves shortly after this one is public. Registry entry REG-06 is the canonical statement of this model's relationships to the other governance-family frameworks and governs where the two describe the same relationship. The Five-Gate Deployment Model is a trademark of the author and iSystematic Inc.; the CC BY 4.0 licence grants no rights in the mark, and no registered-mark symbol is used because no registration has issued. Section 2.6 names no proprietor of the adjacent third-party mark in the product-innovation field, because no trademark register was reachable in a way that could distinguish a genuine record from a deliberately invented control.

Files

CHANGELOG.md

Files (367.4 kB)

Name Size Download all
md5:4e5094c1a4977b7f9ec9624aff52bacd
5.5 kB Preview Download
md5:db397963c395959edd1b67d70bc6ccad
4.0 kB Download
md5:814b88a774c66203ca341324bc3514e2
8.3 kB Download
md5:95c7d08803693ab782b9ce79f1216e38
46.3 kB Preview Download
md5:48909de5a5aba14b3bef071b430676c7
277.3 kB Preview Download
md5:e69345d4fd6af920da389c2f9c076f73
7.8 kB Download
md5:022dad443225642c1ea412bf99299373
10.6 kB Download
md5:6d2f85e0f1f3adaffc0e2ee5f520b453
7.6 kB Preview Download

Additional details

Additional titles

Subtitle (English)
Deployment Model Specification, Version 1.0
Alternative title (English)
AI Deployment Gates: Production Approval and Sign-Off for AI Systems
Alternative title (English)
AI Model Deployment Approval Framework

Related works

Is documented by
Other: https://nabeelkhan.com/frameworks/five-gate (URL)
Is supplement to
Book: 978-1-0678960-1-0 (ISBN)
References
Technical note: 10.5281/zenodo.22109836 (DOI)
Report: 10.5281/zenodo.22109864 (DOI)
Technical note: 10.5281/zenodo.22170112 (DOI)

References

  • Khan, N. A. (2026). The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109836
  • Khan, N. A. (2026). A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery. Pattern Language Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109864
  • Khan, N. A. (2026). The Defensible AI Framework Registry: Canonical Names, Definitions and Relationships for the Governed Production AI Discipline. Registry Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170112
  • Khan, N. A. (2026). AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook. First Edition. iSystematic Inc. ISBN 978-1-0678960-1-0
  • International Organization for Standardization and International Electrotechnical Commission (2023). ISO/IEC 42001:2023, Information technology. Artificial intelligence. Management system. First edition, December 2023.
  • National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, 26 January 2023.
  • Office of the Superintendent of Financial Institutions, Canada (2025). Guideline E-23, Model Risk Management (2027). Published 11 September 2025, effective 1 May 2027. Scope includes artificial intelligence and machine learning models and models or data sourced from third parties.
  • Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation (2026). SR 26-2, Revised Guidance on Model Risk Management. Issued 17 April 2026. Supersedes and replaces SR 11-7 (2011) and SR 21-8 (2021).