AI Governance Library

Harmonizing AI Guidance: Distilling Voluntary Standards and Best Practices into a Unified Framework

This issue brief consolidates recommendations from AI, cybersecurity, privacy and risk-management guidance into a single framework. It presents 258 harmonized recommendations across 34 topics and five categories, with AI Scores showing the contribution of AI-specific sources.
Cover of Harmonizing AI Guidance: Distilling Voluntary Standards and Best Practices into a Unified Framework

⚡ Quick Summary

Published by the Center for Security and Emerging Technology, this report consolidates voluntary guidance on governing, managing and protecting technology, including AI systems. It responds to the difficulty organisations face in reconciling a large and dispersed set of AI, cybersecurity, privacy and risk-management recommendations. Its stated first-stage purpose is to harmonize guidance; later CSET work is intended to operationalize and tailor it to particular deployment scenarios.

The authors analyse 7,741 recommendations from 52 guidance documents, including 29 AI-specific reports and 23 reports on cybersecurity, privacy and risk management. They reduce these to 258 recommendations organised into 34 topics and five categories: Governance, Safety, Security, Privacy, and Detection & Response. Each recommendation has an AI Score indicating the normalized percentage of underlying source recommendations originating in AI-specific reports. The report also sets out a mixed quantitative and qualitative harmonization method, validates the resulting set against the original recommendation space, and identifies areas where existing AI guidance concentrates or remains limited.

🧩 What’s Covered

The brief progresses from the problem of fragmented guidance to its synthesis method, framework, and findings.

  • Background and implementation barriers: Explains how safety, security and trustworthiness guidance has developed through different communities, then identifies information overload, disparate sources, inaccessible language, limited implementation detail and one-size-fits-all guidance as obstacles for organisations.
  • Research phases and source selection: Positions harmonization as the first of three planned phases—harmonize, operationalize and tailor. It defines inclusion criteria for prescriptive, extractable and prominent English-language guidance relating to AI, risk management, cybersecurity or privacy.
  • Harmonization method: Describes extracting recommendations, standardising terminology and voice, producing 3,072-value vector embeddings with OpenAI's text-embedding-3-large model, and using agglomerative clustering to identify 34 topics. Qualitative coding and thematic analysis then produce between five and ten themes per topic.
  • Results and validation: Reports that the 258 recommendations cover five higher-level categories. It uses embedded recommendation-space visualisations to discuss accuracy, representativeness and completeness, and says comparable coverage would require seven source reports containing 946 recommendations.
  • Governance and Safety framework: Sets out recommendations on leadership, integrated risk management, supply chains, workforce, inventories and audit. Safety topics address responsible business conduct, stakeholder engagement, societal effects, impact assessment, fairness, synthetic content, TEVV, traceability, transparency, human oversight and model safeguards.
  • Security, Privacy, and Detection & Response framework: Covers secure design, vulnerability management, identity, access and network controls, information and endpoint security, data and PII handling, logging, monitoring, incident response, continuity and recovery. Recommendations include model security against adversarial, poisoning, inversion, membership-inference and extraction attacks.
  • Insights, gaps and supporting material: Assesses the concentration of existing AI guidance in safety, expanded risks, new vulnerabilities, transparency, testing and synthetic content. It identifies relative gaps concerning workforce preparation, AI incident reporting, confidential information in AI interactions and agentic AI, and appends source documents, a standardisation example and clustering summaries.

💡 Why it matters?

The framework gives governance, assurance and technical teams one structure for connecting AI practices with existing cybersecurity, privacy and enterprise risk-management work. It treats AI management as an organisational activity spanning leadership, procurement, development, model safeguards, data handling, monitoring and recovery rather than as a standalone technical task.

The AI Scores also help users distinguish recommendations developed mainly from AI-specific guidance from those rooted chiefly in established technology controls. The report directs practitioners to adapt recommendations to their own needs rather than use them as a checklist, while its traceability approach and supplementary crosswalk are intended to help users locate relevant underlying guidance.

❓ What’s Missing

The report explicitly excludes regulation and legislation, so following its voluntary framework does not establish compliance with applicable legal requirements. Its source corpus is broad but not exhaustive, especially for non-AI guidance. Harmonizing thousands of recommendations into a smaller set necessarily removes information and some source-level specificity. The recommendations remain high-level and broadly applicable: the authors state that granular implementation actions, techniques and tools will be addressed in a future operationalizing phase, while scenario-specific adaptation is reserved for a later tailoring phase. The report refers users to supplemental crosswalk materials for links between harmonized recommendations and underlying sources, but that crosswalk is not contained in this document.

👥 Best For

AI governance leads, risk managers, security and privacy teams, and internal audit functions seeking a common structure for managing AI alongside existing technology controls. It is also suited to policymakers assessing the voluntary practices organisations may be asked to implement and the operational implications of potential requirements.

📄 Source Details

Harmonizing AI Guidance: Distilling Voluntary Standards and Best Practices into a Unified Framework is an English-language issue brief published by the Center for Security and Emerging Technology in September 2025. It is authored by Kyle Crichton, Abhiram Reddy, Jessica Ji, Ali Crawford, Mia Hoffmann, Colin Shea-Blymyer and John Bansemer. The supplied complete PDF is 79 pages and gives the document identifier doi: 10.51593/20240041.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.