National Institute of Standards and Technology — Center for AI Standards and Innovation. What tit governs — and what it leaves to your institution
By Dr. Freddie Seba © 2026 Freddie Seba. All rights reserved.
Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI
Governance as Leadership
The organizations that govern AI intentionally will lead. The ones that don’t will follow the consequences.
This series is not about compliance. It is about leadership. Every framework examined here surfaces the same question: not whether your institution is following the rules — but whether your leaders are governing the most consequential technological transformation of our time. Ungoverned: Applied Frameworks Under the Lens exists for leaders who understand the difference.
Previously: Anthropic, OpenAI, and Google Gemini. This week: NIST-CAISI. Coming next: EU AI Act, China, Singapore, South Korea, Canada.
Constructive analysis — three questions, every installment, without exception.
Why this series — and why these frameworks
This series does not examine every AI governance framework. It examines the frameworks that together reveal the full shape of the governance challenge — and the full scope of what institutional leadership must build in response.
The selection logic is deliberate. It begins with the AI labs — Anthropic, OpenAI, Google — because that is where most institutions first encountered the governance gap: in the terms of service of tools already embedded in their workflows. It moves to U.S. federal bodies — NIST-CAISI — because understanding the voluntary, underfunded, and pending-authorization nature of federal AI standards is essential context for every institution that assumed federal governance was someone else’s responsibility.
It then moves outward — to the EU AI Act, China, Singapore, South Korea, and beyond — because AI governance is not a Western conversation, and leaders who govern only within the frameworks they already know will be ungoverned by the ones they do not. It will explore Canada — not because Canada has a framework, but because it does not, and the governance vacuum left by failed legislation is itself a governance lesson every institution needs to examine. It will explore the Gulf states — UAE, Saudi Arabia, Qatar — because some of the world’s most aggressive AI investment is happening in jurisdictions whose governance frameworks Western institutions have barely begun to examine.
The frameworks explored in this series are not the only ones that matter. They are the ones that, examined together, reveal the pattern. The framework governs the platform, the standard, the model, or the market. Only the institution governs the consequences. That pattern is what this series is for.
This is a living series. Frameworks are added as the global AI governance landscape evolves — and it is evolving faster than any publication schedule can fully anticipate.
Series roadmap — a living intellectual agenda
This roadmap reflects the series as currently envisioned. New frameworks will be added as countries, standards bodies, and sector organizations publish governance guidance. The sequence may evolve. The three questions never will.
Tier 1 — AI Labs
The governance gap begins here — in the terms of service, privacy policies, and platform decisions of the tools already embedded in institutional workflows.
- Anthropic — United States
- OpenAI — United States
- Google Gemini — United States
Tier 2 — Government & Standards Bodies
Federal and national frameworks that shape institutional expectations — and the gaps those frameworks deliberately or structurally leave ungoverned.
4. U.S. NIST-CAISI — United States
5. Canada AI Governance — North America
6. UK AI Governance — United Kingdom
Tier 3 — Binding Regulatory Frameworks
The binding laws and regulations that define legal compliance floors — and the institutional governance required to meet them.
Tier 4 — International Standards & Multilateral Bodies
The frameworks that aspire to global consensus — and the institutional gaps that consensus cannot close.
Tier 5 — Sector & Vertical Frameworks
Where global frameworks meet institutional reality — in education, financial services, and emerging economies.
Tier 6 — Series Synthesis
What the frameworks — examined together — leave ungoverned. And what leadership must build in the space they leave behind.
New frameworks added as the global AI governance landscape evolves.
Question One — What was the framework designed to govern?
NIST-CAISI — the National Institute of Standards and Technology’s Center for AI Standards and Innovation — was established in June 2025 when the Trump administration restructured the former U.S. AI Safety Institute within NIST. NIST is the U.S. federal agency responsible for setting measurement standards and promoting innovation across science, technology, and industry. CAISI’s mandate is to serve as the U.S. government’s primary point of contact with industry for testing and collaborative research to harness and secure commercial AI systems.
Since its establishment, CAISI’s work has expanded significantly across four areas.
In model evaluation, CAISI has completed more than 40 evaluations of AI systems — including the first public U.S. government evaluation of DeepSeek V4 Pro in April 2026, which found its capabilities lag the frontier by approximately 8 months, using non-public benchmarks that produced materially different results than DeepSeek’s own self-reported evaluations.
In agentic AI governance, CAISI launched the AI Agent Standards Initiative on February 17, 2026 — the first U.S. government program explicitly dedicated to interoperability and security standards for agentic AI systems — meaning AI systems capable of autonomous planning, reasoning, and action. The initiative is organized around three pillars: industry-led standards development and U.S. leadership in international standards bodies; community-led open-source protocol development; and fundamental research in AI agent security and identity.
In federal procurement, CAISI signed a Memorandum of Understanding — a formal cooperative agreement — with the General Services Administration (GSA), the federal agency responsible for government procurement, to support USAi’s AI evaluation needs, a secure generative AI platform enabling federal agencies to adopt AI at scale.
In consortium governance, NIST renamed the former AI Safety Institute Consortium as the NIST AI Consortium in May 2026, expanding its focus to AI innovation and adoption with six task groups concentrating on AI measurement science and evaluation.
It governs AI evaluation and standards at the federal level. Seriously. At scale. With expanding scope and growing technical sophistication.
Question Two — The Governance Gap: what falls outside the frame, and where leadership begins?
Institutional deployment accountability.
CAISI’s framework is the most technically substantive U.S. government effort to define what secure AI deployment looks like. Its model evaluations are rigorous. Its agentic AI standards initiative is operationally grounded. Its federal procurement partnership is of practical significance. What it cannot do — and was not designed to do — is govern your institution’s deployment decisions, build your change management process, or maintain your continuity plan if its guidance is revised or superseded. That work belongs to the institution. That is where leadership begins.
Three structural facts, alongside CAISI’s substantive record, that every institutional leader should understand.
Its authority remains entirely voluntary — bipartisan legislation, meaning legislation with support from both major U.S. political parties, to formalize CAISI in statute has been introduced in both chambers of Congress and is pending. Its red-team research — meaning adversarial testing designed to find weaknesses — found that novel attack strategies against AI agents achieved an 81% success rate compared to 11% against baseline defenses. That finding was published in January 2025. The standards-based response is still being drafted. The institutions deploying those agents are not waiting.
Consider the questions CAISI cannot answer for your institution. Who in your organization monitors CAISI guidance updates in real time — not annually? When CAISI’s standards evolve, who determines whether your institution’s deployed AI systems still meet the thresholds established at the time of deployment? When CAISI evaluates a model your institution relies on and finds performance gaps — as it did with DeepSeek V4 Pro — who owns the institutional response? Who has the authority to suspend or modify your institution’s use of that model pending review?
CAISI defines what evaluated AI looks like. Leadership governance defines what happens after deployment.
Question Three — What does governance as leadership look like before deployment?
This is where AI Minimum Viable Governance (AI-MVG) begins. Not after a standards revision forces the question — before deployment, when the institution still has the leverage to govern with intention. This is not a compliance checklist. It is a leadership architecture.
Vendor dependency mapping — know what breaks if the standard your vendor references is revised, expanded, or superseded.
Decision ownership — name who is accountable for each AI-assisted institutional decision, including decisions made by agentic systems
Policy monitoring — track CAISI guidance updates, AI Consortium developments, and agentic AI standards in real time.
Change management triggers — define what level of standards revision, model evaluation finding, or federal guidance change requires institutional review
Contingency planning — document what happens if CAISI guidance is defunded, superseded, or contradicted by sector-specific regulation.
Agentic AI inventory — document every AI agent deployed or under consideration, including third-party agents, against CAISI’s emerging agentic standards
Executive accountability — assign a named leader responsible for AI governance outcomes, not just AI adoption metrics
This week’s 12 Ps lens: Predictability
Federal standards are not federal stability. CAISI’s guidance is voluntary. Its statutory authorization is pending. Its funding is precarious. And its scope — from model evaluation to agentic AI standards to federal procurement — is expanding faster than the legal and institutional frameworks that would make its guidance binding. Predictability — the ninth P — means knowing in advance what your institution will do when the standard shifts, rather than discovering the gap afterward. Leadership governance means building that predictability into your institution before the standard changes — not scrambling to respond after it does.
Purpose: CAISI’s mandate is federal evaluation and standards development. Your institution must align its AI purpose statements against CAISI’s evolving standards on an ongoing basis, not just at deployment.
People: CAISI engages industry, federal agencies, and international partners. Your institution must name the internal person responsible for monitoring and responding to CAISI guidance — not just the category.
Processes: CAISI develops voluntary processes for AI evaluation and standards. Your institution must build the internal processes to adopt, monitor, and respond to those standards before they become relevant to your deployed systems.
Policy: CAISI’s guidance is voluntary. Your institution’s internal policy must establish its own compliance floor, rather than waiting for federal mandates that may not arrive.
Privacy: CAISI’s evaluation scope does not include institutional data governance. Your institution must map AI data flows against applicable privacy frameworks independently of CAISI guidance.
Performance: CAISI produces performance benchmarks and model evaluations. Your institution must define internal performance thresholds and monitor against them — CAISI’s evaluations are a reference, not a substitute for institutional monitoring.
Procurement: CAISI’s MOU with GSA shapes federal procurement. Non-federal institutions must build their own procurement governance frameworks that draw on CAISI guidance without assuming it is sufficient.
Partnerships: CAISI’s partnerships cover major AI labs and federal agencies. Your institution’s third-party AI risk must be mapped independently — CAISI’s agreements do not extend to your institutional relationships.
Predictability: This is the governance gap. Standards can be revised, defunded, or superseded without notice. Your institution must build a continuity plan that does not depend on CAISI guidance remaining stable. That continuity plan is a leadership decision — not a compliance exercise.
Protection: CAISI’s security research covers cybersecurity, biosecurity, and chemical weapons risks. Your institution must implement its own protection measures — CAISI’s research informs but does not govern your institutional security posture.
Proof: CAISI publishes model evaluations and research. Your institution must build its own audit trail demonstrating that its AI deployment decisions were made with reference to current standards and sound institutional judgment.
Precedent: CAISI does not assign accountability for outcomes within your institution. Who owns the decision — and the consequences — when an AI system your institution deployed based on CAISI’s evaluation produces an unexpected outcome? Answering that question before deployment is what governance-as-leadership looks like.
CAISI governs what evaluated AI looks like at the federal level. Institutional leadership governance governs the consequences of AI deployment within your organization. One defines the standard. The other builds the capability to meet it — and to respond when the standard changes. That is the foundation of AI Minimum Viable Governance.
For executive briefings, board workshops, and keynote presentations → freddieseba.com
About the Author
Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator, Silicon Valley founder, and global executive — EdD, USF · MBA, Yale · MA, Stanford.
This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI to organizations shaping AI governance globally — including AI labs, governments, standards bodies, and international actors across the United States, Europe, Asia-Pacific, the Gulf, Latin America, and beyond. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
© 2026 Freddie Seba. All rights reserved.
References
National Institute of Standards and Technology. (2026). Center for AI Standards and Innovation (CAISI). https://www.nist.gov/caisi
National Institute of Standards and Technology. (February 17, 2026). Announcing the AI Agent Standards Initiative for interoperable and secure innovation. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure
National Institute of Standards and Technology. (March 18, 2026). CAISI signs MOU with GSA to boost AI evaluation science in federal procurement through USAi. https://www.nist.gov/news-events/news/2026/03/caisi-signs-mou-gsa-boost-ai-evaluation-science-federal-procurement-through
National Institute of Standards and Technology. (May 1, 2026). CAISI evaluation of DeepSeek V4 Pro. https://www.nist.gov/news-events/news/2026/05/caisi-evaluation-deepseek-v4-pro
National Institute of Standards and Technology. (2026, May). NIST expands AI Consortium’s scope, calls for new members. https://www.nist.gov/news-events/news/2026/05/nist-expands-ai-consortiums-scope-calls-new-members
Cloud Security Alliance. (March 30, 2026). Federal agentic AI security: NIST’s emerging standards initiative. https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-ai-agent-standards-federal-framework/
Federation of American Scientists. (2026, April). A national center for advanced AI reliability and security. https://fas.org
Cybersecurity Dive. (May 21, 2026). NIST will test three major tech firms’ frontier AI models for cybersecurity risks. https://www.cybersecuritydive.com/news/nist-ai-model-testing-caisi-google-microsoft/819452/
Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
#AIGovernance #ResponsibleAI #AIMVG #AILeadership #Ungoverned #NIST #FederalAI #BoardGovernance #AIPolicy #AIRisk #CIO #Canada #UK #Japan #UAE #SouthKorea #Singapore #China #EUAIAct #SaudiArabia #Qatar #HongKong #Brazil #India

Leave a Reply