How NIST and ISO Are Turning Voluntary AI Governance Into a Liability Defense
The risk, governance, and reward arc at the center of the standard of care. AI-generated infographic, NotebookLM.
How NIST and ISO Are Turning Voluntary AI Governance Into a Liability Defense

The risk, governance, and reward arc at the center of the standard of care. AI-generated infographic, NotebookLM.
Most companies file two of the best-known AI governance standards, the NIST AI Risk Management Framework and ISO/IEC 42001, under “nice to have.” Both are voluntary, so a busy executive can be forgiven for treating them as paperwork that competes with shipping product. That treatment is a costly mistake, and the people most likely to expose it are not regulators. They are plaintiffs’ attorneys and insurance underwriters.
What the standard of care means
The reason rests on an idea far older than artificial intelligence, the standard of care. In ordinary negligence law the test is comparative. A company is judged against what a reasonable company in its position would have done, and once a practice becomes common enough, courts and insurers begin to treat it as the benchmark for reasonable conduct. That benchmark for AI is taking shape right now, and these two standards are among the most visible forms it is taking.
The two standards, in plain terms
Two standards are shaping that benchmark, and the first is American. The NIST AI Risk Management Framework, released in 2023 by the federal agency that writes much of the technical guidance the economy quietly relies on, lays out a voluntary way to manage AI risk across four functions: govern, map, measure, and manage. NIST issues no fines. Its work tends to gain force later, when buyers, regulators, and courts reach for a shared reference and find this one already in their hands.
The second is international. ISO/IEC 42001, also published in 2023, is the world’s first management system standard for AI, and an accredited body can audit and certify against it, the same way companies certify their information security against ISO 27001. The two fit together. A company can run the NIST framework as the engine inside an ISO/IEC 42001 system, pairing substance with a certifiable structure. A certificate from an accredited body then turns an internal claim into outside evidence. “We govern our AI responsibly” is an assertion. A current certificate, backed by the records behind it, is proof within the scope it covers.
The risk: voluntary on paper, real in practice
Here is where a voluntary standard begins to carry legal and commercial weight. When an AI system causes harm, through a biased hiring screen, a discriminatory loan denial, or a fabricated and defamatory output, the question that follows is whether the company behaved reasonably. The legal theory varies, negligence for some harms and anti-discrimination law for others, and the answer often turns on whether recognized practices existed and whether the company used them. Researchers like Joy Buolamwini have spent years documenting exactly this kind of harm, the measurable bias a court can later weigh.
A plaintiff’s attorney can then ask a simple question. These practices existed, they were widely adopted, and the company ignored them, so on what basis was the conduct reasonable? A 1932 case still makes the point. In The T.J. Hooper, Judge Learned Hand held that a whole industry can lag in adopting an available precaution, and that a court, not the industry, decides what prudence required. Common practice is powerful evidence. It carries weight in a courtroom precisely because a careful peer would have followed it, and the newness of these standards is a reason to adopt early, while the floor is still being set.
Insurers see it the same way. An underwriter decides whether to cover a risk and at what price, working from recognized controls, attestations, and loss history. A company with an ISO/IEC 42001 certificate and a documented NIST-aligned program looks like a measurable, familiar risk. A company with neither looks opaque, and as AI exposures move into cyber and professional-liability policies, the absence of a recognized standard can read to an underwriter as an unpriced hazard.
The reward: the records that defend also help win
The case for governance usually stops at fear, and that leaves out the better half of the story. The same work that defends a claim also helps win business. An ISO/IEC 42001 certificate, a NIST-aligned risk register, model and data documentation, test results, approval logs, and an audit trail are the materials that satisfy an underwriter, clear a procurement questionnaire, and answer a plaintiff. They are the currency that lawyers, insurers, and enterprise buyers increasingly ask for.
There is a larger point underneath. By the available third-party data, the companies pulling ahead with AI are not the ones that emptied their payrolls. PwC’s 2025 Global AI Jobs Barometer, built from close to a billion job postings, found that productivity in the industries most exposed to AI has nearly quadrupled since 2022, that revenue per employee grew far faster there than in less exposed industries, and that jobs kept rising even in highly automatable roles. The firms capturing those gains kept people in charge of the machine’s work rather than removing them from it.
A classroom study points the same direction. In a 2025 field experiment with nearly a thousand high school mathematics students, published in the Proceedings of the National Academy of Sciences, students used either a standard chatbot or one constrained to give teacher-style hints instead of answers. Both tools lifted performance while students had them in hand. Once the tools were taken away, the students who had relied on the standard chatbot scored worse than peers who never had access, while the constrained version erased that loss. The same technology, governed two ways, either eroded the skill underneath or compounded it.
Governance is the common thread
This is why the defense and the growth are one story. The discipline that produces the records, deciding who is accountable, logging what was reviewed, and recording where a person made the call, is the discipline that keeps a workforce sharpening instead of hollowing out. The tool is available to every competitor, but the discipline to govern it is not.
Putting that discipline into practice is its own design problem. The author’s proposed approach, Checkpoint-Based Governance, would place a named human at the points where authorization or legally consequential use occurs, and would generate the records that the measure and manage work expects: who did what, where each input came from, and where a reviewer disagreed and why. The aim is to answer the one question a court or an underwriter tends to ask, whether a person held real authority over the output.
The floor keeps rising
None of this is automatic. A certificate can harden into a checkbox, and a record built carelessly can be discovered later and used against the company that made it. Claiming a standard and then ignoring it in practice can be worse than never claiming it at all, because it hands a plaintiff the argument that the company knew the risk and proceeded anyway. What counts in the end is whether the work behind the paperwork was real.
The standard of care for AI is not waiting. Every new certificate, every regulator that points to the NIST framework, and every insurer that asks for an AI governance program raises the floor a little higher. Companies that build the documented record now build it while it is still affordable. The ones that wait will still meet the standard. They will meet it for the first time in a deposition or a claim file, which is the most expensive place to learn what reasonable looks like.
This is the short version. The full article develops the argument in depth, with the detailed reasoning and the complete sources, and lives here: https://basilpuglisi.com/standard-of-care-ai-governance/
The Other AI: Audio Briefings on Augmented Intelligence and AI Governance
Spotify | Apple Podcasts | Amazon Music | YouTube Playlist
AIassisted using HAIA Ecosystem
메타데이터
- post_id
- f6578fa05c21
- slug
- how-nist-and-iso-are-turning-voluntary-ai-governance-into-a-liability-defense-f6578fa05c21
- url
- https://medium.com/@basilpuglisi/how-nist-and-iso-are-turning-voluntary-ai-governance-into-a-liability-defense-f6578fa05c21
- canonical_url
- https://medium.com/@basilpuglisi/how-nist-and-iso-are-turning-voluntary-ai-governance-into-a-liability-defense-f6578fa05c21
- author_url
- https://medium.com/@basilpuglisi
- status
- ok
- fetched_at
- 2026-08-18 06:12:11