Open-source engineering for governable, verifiable, resilient, and accountable AI.
Transforming AI chaos into aligned order.
Global AI Governance turns AI uncertainty into evidence, controls, human decisions, and repeatable governance outcomes.
Choose one public path. Each route names the capability and maturity that exist today.
Open the live local-first governance browser. The hosted browser reflects current main. The controlling tagged reference is v2.3.0 - Assurance & Accountability Profiles.
AI system inventory
→ normalization and schema validation
→ preliminary risk tier
→ policy-driven findings
→ machine-readable governance outputs
→ AI Governance Decision Pack
→ human review and decision
- Open the live browser and select Run sample.
- Review normalization, findings, machine outputs, and the Decision Pack.
- Load one authorized CSV when appropriate; approval, restrictions, risk acceptance, rollback, and shutdown remain human-owned.
For a reproducible tagged reference path, use the released v2.3.0 five-minute workflow.
v2.3.0 preserves the bounded sovereignty assessment and adds optional Auditable AI, Quantum-AI synthetic assurance, and CISO accountability profiles. These profiles produce non-authorizing evidence and decision support; they do not establish provider attestation, certification, compliance, production authorization, quantum advantage, or operating authority.
Use only the versioned public contracts that fit your boundary:
- Toolkit v2.3.0 automation for inventory checks, policy findings, reports, and a human Decision Pack.
- Agentic AI Governance v0.1.0-alpha.2 schemas for experimental authority, passport, evidence, validation, expiry, and revocation artifacts.
- Portfolio repository contracts for reference-only handoffs that do not transfer approval, truth, certification, or operational authority.
Published tags remain controlling. Merged or local development work is not a released interface until its own release gate passes.
Start with one bounded, evidence-producing pilot: one authorized inventory, one accountable human owner, one Decision Pack, and one documented decision boundary. Use the flagship's public contribution process to propose a reproducible use case, fixture, documentation improvement, or integration adapter.
Partnership does not imply endorsement, certification, production authorization, compliance, or acceptance of submitted claims. Do not include confidential, personal, regulated, or otherwise protected information in public contributions.
Understand repository maturity → Maturity Model
| Lifecycle role | Repository | Current maturity | Finished outcome |
|---|---|---|---|
| GOVERN + MEASURE | Global AI Governance Toolkit | v2.3.0 · working public reference toolkit | Reproducible Decision Pack, bounded sovereignty assessment, and optional assurance/accountability profiles |
| AUTHORIZE | Agentic AI Governance | v0.1.0-alpha.2 · experimental public alpha | Machine-readable authority, evidence, passport, validation, expiry, and revocation artifacts |
| DESIGN ENFORCEMENT | Governed Systems Administration | Pre-alpha · preimplementation · independent semantic review required · no execution capability | Proposed human-governed administration request, review, validation, and evidence contracts |
| OBSERVE + VERIFY + CLOSE | Verified Vulnerability Governance | v0.1.3 · verified-closure pre-release | Evidence-linked vulnerability ownership, remediation, retesting, and closure |
| CONTAIN + RECOVER | AI Cyber Resilience Framework | v0.1.1 · public defensive reference | Boundary assessment, evidence cards, and architecture-hardening backlog |
| DECIDE + LEARN | Peace OS: Crisis Room | v0.3.0-rc2 · published public browser review candidate · stable, human-validation, Godot, and Windows gates open | Fictional crisis-verification simulation and after-action review |
| FOUNDATION | AI Governance Foundations | v1.1 · foundational governance model and template set | Inventory, ownership, risk, control, monitoring, and reporting foundations |
Published release identities remain controlling. Merged development work is tracked separately so development state does not silently become a release claim.
- Agentic AI Governance: the bounded OPA Enforcement Bridge and synthetic Agent Incident Readiness lifecycle reference implementations are merged and unreleased with current-main status
DEFINED / VERIFIED. The lifecycle demonstrates authorized, policy-denied, revoked, rollback-rejected, and distinct new-passport reauthorized states while preserving terminal revocation of the original passport. It performs no external enforcement. The published release remainsv0.1.0-alpha.2. - Verified Vulnerability Governance: the bounded synthetic crypto-migration closure reference is merged and unreleased. It uses the existing governed-remediation contract and does not evidence real migration, deployment, or independent retesting. The published pre-release identity remains
v0.1.3. - AI Cyber Resilience Framework:
v0.2.0 Continuous Assurance Thread, including the optional synthetic crypto-agility reference, is merged and unreleased. The published release remainsv0.1.1. - Peace OS: Crisis Room:
Post-RC2 Portfolio Operating Disposition Referenceis merged and unreleased. The published browser review candidate remainsv0.3.0-rc2, and its documented stable-release holds remain open.
These development handoffs are reference-only. They do not silently become release claims, production authorization, certification, operational truth, or permission to act.
See docs/PROGRAM_CLOSEOUT.md for the bounded M0-M9 closeout and deferred release/maturity gates.
The final internal reference thread demonstrates bounded interoperability across the portfolio without transferring authority or truth between repositories.
- Governed Vulnerability Remediation integrated reference
- NIST AI RMF 1.0 bounded portfolio mapping
- Final internal update scope and evidence boundary
The thread is synthetic and reference-only. It does not prove real remediation, independent retesting, operational assurance, compliance, certification, or permission to act.
Govern
→ Authorize
→ Enforce
→ Observe
→ Verify
→ Contain
→ Recover
→ Measure
→ Learn
The repositories are complementary. They do not all implement every lifecycle stage, and they do not share one maturity level.
- No inventory, no governance.
- No owner, no deployment.
- No evidence, no claim.
- No verification, no closure.
- No shutdown path, no frontier release.
- No sovereignty, no strategic AI.
- AI may assist. Humans retain authority.
This portfolio includes a working public reference toolkit, an experimental alpha specification, verified-closure and public-browser-review prereleases, a pre-alpha design, a defensive reference framework, and foundational governance templates.
Repository checks establish bounded technical consistency for the included artifacts. They do not establish operational safety, factual truth of submitted declarations, legal compliance, certification, production authorization, institutional approval, or fitness for every environment.
Start narrow. Govern one system. Produce one decision-ready outcome. Capture proof. Repeat.
Repository content is provided under the Apache License 2.0 unless a linked repository states its own license.