The Five-Gate Deployment Model: A Deployment Discipline for AI Systems
Description
An institution can be asked two questions about an AI system in production. The first is whether it works. The second is how it got there, and who said it could. The second question is the one a supervisor, an auditor or a board asks after something has gone wrong, and it is the one most institutions answer worst, because the machinery that put the system into production was built to move work forward rather than to record who accepted what.
This specification defines the Five-Gate Deployment Model™, a deployment discipline for AI systems. No AI system reaches production, or remains there, except by passing five gates in order: G1 Data and Design, G2 Validation, G3 Approval, G4 Deployment and G5 Operation. Each gate carries entry criteria supplied by a named framework, exit criteria, a defined rejection path, one accountable person, and a required evidence record. A gate with no rejection path is not a gate; a checkpoint that can only be passed is a formality.
Two properties distinguish the model from the machinery it sits beside. The accountable role at every gate is a single named person and must not be a committee. A committee can be consulted, can review, challenge, advise and decide, and it cannot be accountable, because accountability distributed across a body is accountability no member of that body carries alone. The question an authority asks after a failure is which person is answerable. And every gate passage record is an instance of the BOE Declaration: the entry criteria are the boundary the gate fixes, the deployment freedom granted on passage is the optimizer it frees, and the record is the evidence that the boundary held. That mapping is not presentational. It is what lets a gate record be joined with a validation record, a residency attestation and a vendor screening record during an incident reconstruction, rather than merely filed alongside them, because two controls that emit evidence in one shape compose and two that do not are adjacent.
Two paths run backwards through the model and are part of it rather than exceptions to it. Rollback reverses gate five to gate four with the evidence of the reversal preserved, because a rollback that removes the system and its records leaves the institution unable to reconstruct what the system did while it was live, which is precisely the period an authority will ask about. Loop-back reopens gate two when an incident occurs at gate five, on the reasoning that an incident is evidence about the validation as much as about the system: a patch applied without reopening validation changes the system and leaves the assessment of the system untouched, so the institution's belief about the system becomes older than the system.
The specification states plainly what would falsify the model, and states it against the hardest comparison rather than the easiest: that institutions operating five gates with a single named accountable person at each are found to deploy unfit AI systems at the same rate, and with the same severity of consequence, as institutions operating an automated delivery pipeline enforcing equivalent entry criteria with no named approver. No institution unconnected to the author has been observed operating the full sequence. No readiness instrument exists, no gate evidence templates are published, and no trademark clearance search has been completed on the name. Each of those is stated in the document rather than left to be discovered.
It is a specification, not a certification scheme, and no conformity assessment body operates against it.
Table of contents (English)
1. Introduction 2. Conceptual Model (Normative) 3. The Five Gates (Normative) 4. Reverse Paths (Normative) 5. The BOE Mapping (Normative) 6. Conformance (Normative) 7. Related Work 8. Limitations and What Has Not Been Tested 9. Versioning 10. References Appendix A. Publication ProvenanceTechnical info (English)
Version 1.0 of the specification. 17 pages as rendered, with every figure as vector artwork rather than a raster image. 11 numbered sections and appendices, of which 5 are normative. 3 source SVG figures accompany the record and are reusable under the same licence. 8 references, each verified against a primary source. The Markdown source of record is deposited alongside the PDF, so the text is machine-readable without extraction.Notes (English)
Files
CHANGELOG.md
Files
(367.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:4e5094c1a4977b7f9ec9624aff52bacd
|
5.5 kB | Preview Download |
|
md5:db397963c395959edd1b67d70bc6ccad
|
4.0 kB | Download |
|
md5:814b88a774c66203ca341324bc3514e2
|
8.3 kB | Download |
|
md5:95c7d08803693ab782b9ce79f1216e38
|
46.3 kB | Preview Download |
|
md5:48909de5a5aba14b3bef071b430676c7
|
277.3 kB | Preview Download |
|
md5:e69345d4fd6af920da389c2f9c076f73
|
7.8 kB | Download |
|
md5:022dad443225642c1ea412bf99299373
|
10.6 kB | Download |
|
md5:6d2f85e0f1f3adaffc0e2ee5f520b453
|
7.6 kB | Preview Download |
Additional details
Additional titles
- Subtitle (English)
- Deployment Model Specification, Version 1.0
- Alternative title (English)
- AI Deployment Gates: Production Approval and Sign-Off for AI Systems
- Alternative title (English)
- AI Model Deployment Approval Framework
Identifiers
Related works
- Is documented by
- Other: https://nabeelkhan.com/frameworks/five-gate (URL)
- Is supplement to
- Book: 978-1-0678960-1-0 (ISBN)
- References
- Technical note: 10.5281/zenodo.22109836 (DOI)
- Report: 10.5281/zenodo.22109864 (DOI)
- Technical note: 10.5281/zenodo.22170112 (DOI)
References
- Khan, N. A. (2026). The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109836
- Khan, N. A. (2026). A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery. Pattern Language Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109864
- Khan, N. A. (2026). The Defensible AI Framework Registry: Canonical Names, Definitions and Relationships for the Governed Production AI Discipline. Registry Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170112
- Khan, N. A. (2026). AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook. First Edition. iSystematic Inc. ISBN 978-1-0678960-1-0
- International Organization for Standardization and International Electrotechnical Commission (2023). ISO/IEC 42001:2023, Information technology. Artificial intelligence. Management system. First edition, December 2023.
- National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, 26 January 2023.
- Office of the Superintendent of Financial Institutions, Canada (2025). Guideline E-23, Model Risk Management (2027). Published 11 September 2025, effective 1 May 2027. Scope includes artificial intelligence and machine learning models and models or data sourced from third parties.
- Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation (2026). SR 26-2, Revised Guidance on Model Risk Management. Issued 17 April 2026. Supersedes and replaces SR 11-7 (2011) and SR 21-8 (2021).