Fairness
The system's outputs and decisions shouldn't systematically disadvantage particular groups of people, whether that bias came from the training data, the design choices, or how the system gets used.
Nearly every published AI governance framework converges on the same handful of themes, even when the exact wording differs. Here they are stated plainly, as a charter rather than a rulebook.
AI shows up in too many different situations for one specific rule to fit all of them. "Maintain human oversight" means something different for a medical diagnosis tool than it does for a marketing copy generator — the principle stays constant across both; the specific mechanism that implements it has to be designed separately for each.
That's the actual reason governance frameworks lead with broad principles instead of a fixed checklist: a checklist would either be too strict for low-stakes uses or too loose for high-stakes ones. A principle is deliberately abstract enough to apply to both, and specific enough to still mean something.
Different organizations word these differently and some add more, but this core rarely changes.
The system's outputs and decisions shouldn't systematically disadvantage particular groups of people, whether that bias came from the training data, the design choices, or how the system gets used.
People interacting with an AI system should be able to know that it's AI, and where it's practical, understand enough about why it produced a given output to reason about whether to trust it.
A person or organization remains responsible for what a system does. The system itself is never the answer to "who's accountable for this" — that question always resolves to a human or an institution.
Data used to build and run a system respects the people it came from — collected and used within what those people actually agreed to, not just whatever was technically available.
A system performs consistently under normal conditions and fails in predictable, contained ways when it doesn't — rather than failing silently or unpredictably at the moment it matters most.
Meaningful human review stays possible, especially for decisions with real consequences — oversight that's technically available but never actually exercised isn't really oversight.
"Maintain human oversight" is a principle. A specific approval gate on an irreversible action, in a specific system, is the control that implements it. Neither one works without the other.
A principle with no controls behind it is a statement of intent that never actually constrains anything a system does. A control with no principle behind it is just an arbitrary rule with no reason attached — hard to extend consistently to a new situation the rule's author never considered. The principle is the reason a specific control exists; the control is the only place the principle actually touches what a system does.
Broad statements of value that AI systems and the organizations building them are expected to uphold — fairness, transparency, accountability, privacy, safety, and human oversight are the themes that recur across most published frameworks, even though the exact wording and count vary between organizations.
No — different organizations, governments, and standards bodies have published their own versions, and the specific wording and number of principles differs between them. What's genuinely common across nearly all of them is the small set of underlying themes, not a single canonical list.
A principle states a value in the abstract, such as fairness or accountability. A control is the specific, enforceable mechanism that puts that value into practice for a given system — a permission check, an approval gate, an audit log. Principles say what matters; controls are how that gets made real.
Because AI gets used in too many different contexts for one specific rule to fit all of them. A principle like "maintain human oversight" means something different for a medical diagnosis tool than for a marketing copy generator — the principle stays constant, but the specific control that implements it has to be designed for each context.