The AI Data Governance Framework: A Five-Stage Control System for the Data Boundary in AI Systems
Description
An institution asked whether a particular item of data may be inside a particular AI system usually answers from recollection. Someone remembers which extract the training set came from, someone else remembers that the extract excluded a restricted field, and a third person remembers that the exclusion was agreed with the data owner who has since left. The answer is often correct. It is never evidence.
This specification states the control system that makes the same answer come from a record. It operates in five ordered stages. Classify determines, per data set, its sensitivity under a declared scheme, its personal-data status, and the residency clauses that reach it. Bound fixes the residency rule set, the clauses the institution may not cross, each traced to a primary instrument and dated. Prove constructs the lineage graph from an attested source through every transformation to the point of use. Gate applies the quality thresholds, the minimization check and any certification claimed. Release admits the data with a BOE Declaration attached, or does not admit it.
Two rules do the work that keeps a rule set honest over time. Every clause carries a re-verification date, and a clause relied on after that date is not a clause; the rule set's review date must not be later than the earliest re-verification date among its clauses. And an undated verification is not evidence that one occurred. A residency rule set is the kind of artifact that ages quietly into fiction, because a clause sourced once and never revisited looks exactly like a clause that is still true.
It is entry REG-03 of the Defensible AI Framework Registry, and the worked treatment of the data boundary class defined in A Pattern Language for Production LLM Platforms, which specifies and governs that class. Residency is named here as a member of that class rather than as a class of its own.
The deposit publishes residency-rule-set-schema-v1.0.json, a JSON Schema (draft 2020-12) for a residency rule set and for the selection made against it. The registry records the absence of a machine-readable classification schema as the single largest gap in this entry. Section 8 closes it, and closes the corresponding gap in the consuming framework in the same object, because a rule set expressed once and read from both ends cannot drift. Two copies would. The rule set is authored here at the Bound stage; the selection object is authored by the Cross-Border AI Architecture Patterns and references clause identifiers rather than restating clauses.
What the specification does not claim is stated plainly rather than left to inference. No institution unconnected to the author has been observed operating the five stages as specified here, and there is no implementation profile, no scored instrument and no published result: a validated file is not a populated one. The attestation cost has not been measured anywhere, and the framework's cost sits almost entirely in the per-hop attestation, so that is recorded as an unmeasured quantity rather than a manageable one. The schema has no adopters, and a schema with no adopters is a proposal. And the schema's limits are real: it cannot tell a person from a committee, resolve an identifier, check uniqueness across a document, compare a stated union against a computed one, order a date against the earliest of many, or establish that a cited instrument exists. A passing validation satisfies one of the seven requirements it supports and part of a second. A pass is not a check.
It is also not a statement of any residency or transfer rule. This specification names no jurisdiction and states no legal obligation; clauses are the institution's to source, date and re-verify. That is why its reference list carries no statute or supervisory instrument: the document advances no proposition about what any of them requires, and a specification supplying clauses would be supplying the one thing it has no standing to supply and the one thing that ages fastest. It is not a certification scheme.
Table of contents (English)
Notation 1. Introduction 2. Conceptual Model (Normative) 3. Stage One: Classify (Normative) 4. Stage Two: Bound (Normative) 5. Stage Three: Prove (Normative) 6. Stage Four: Gate (Normative) 7. Stage Five: Release (Normative) 8. The Machine-Readable Layer (Normative) 9. Conformance (Normative) 10. Related Work 11. Limitations, What Has Not Been Tested, and Falsification 12. Versioning 13. References Appendix A. Naming Crosswalk: The Seven Layers of the Source Treatment Appendix B. Publication Provenance Appendix C. Figure SpecificationsTechnical info (English)
Version 1.0 of the specification. 13 numbered sections and 3 appendices, of which 8 sections are normative. 3 source SVG figures accompany the record and are reusable under the same licence; all three are also deposited on FigShare with their own DOIs. A JSON Schema (draft 2020-12) for the residency rule set and the selection made against it ships as a separate file and is also served at its own $id with content type application/schema+json. 7 references, re-verified on 14 September 2026 with deliberate failing controls. The Markdown source of record is deposited alongside the PDF, so the text is machine-readable without extraction.Notes (English)
Files
ai-data-governance-framework-specification-v1.0.md
Files
(1.3 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:dea7dccf4426494ea2aeed4ab213355a
|
56.8 kB | Preview Download |
|
md5:7c72bf0c7fb8197ce67cfd66d036cffb
|
1.2 MB | Preview Download |
|
md5:5409d0b84fbe4b229e38baee939384c0
|
7.8 kB | Preview Download |
|
md5:d44e96dc74d8db3b8e7e415bb5c7b122
|
5.8 kB | Download |
|
md5:51da243dfaa94d6b498f0d7476f0dbcb
|
13.2 kB | Download |
|
md5:41e74a3d795b881e31357b7b802295d3
|
12.8 kB | Download |
|
md5:50b0df7a0681251dee4293047b350868
|
14.5 kB | Download |
|
md5:60a1ed249e38686bca8ea97064541884
|
9.9 kB | Preview Download |
|
md5:5ea3e75166d920ea299d67a24427e062
|
23.1 kB | Preview Download |
Additional details
Additional titles
- Subtitle (English)
- Framework Specification, Version 1.0
- Alternative title (English)
- The AI Data Governance Stack
- Alternative title (English)
- Data Residency, Lineage and Classification Controls for Regulated AI Systems
Identifiers
References
- Khan, N. A. (2026). The Defensible AI Framework Registry: Canonical Names, Definitions and Relationships for the Governed Production AI Discipline. Registry Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170112
- Khan, N. A. (2026). A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery. Pattern Language Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109864
- Khan, N. A. (2026). The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109836
- Khan, N. A. (2026). The Five-Gate Deployment Model: A Deployment Discipline for AI Systems. Deployment Model Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170122
- Khan, N. A. (2026). The Sharia AI Compliance Framework: A Dual-Authority Governance Architecture for Islamic Finance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170143
- International Organization for Standardization and International Electrotechnical Commission (2023). ISO/IEC 42001:2023, Information technology. Artificial intelligence. Management system. First edition, December 2023. Cited as the institutional-altitude management system this framework does not duplicate. Edition and date confirmed from the IEC webstore, the publisher's own page having refused an automated request.
- Khan, N. A. (2026). AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook. First Edition. iSystematic Inc. ISBN 978-1-0678960-1-0