AI Governance Study

Why AI needs its own governance, and how to describe a system: the OECD's five dimensions

AI has specific traits that make ordinary IT governance insufficient. Doing something about them starts with describing a system in a standard way that a vendor, a regulator and a review board all share. This topic covers both: the traits, and the standard

Domain I · Understand what AI is and why it needs governance · about 6 min

Why this matters for the exam

AI has specific traits that make ordinary IT governance insufficient. Doing something about them starts with describing a system in a standard way that a vendor, a regulator and a review board all share. This topic covers both: the traits, and the standard description framework.

What you need to know

The topics so far explained what AI is, how it learns, and what kinds of models exist. This one turns to governance: why AI needs rules of its own, and the standard tool for describing the system you are about to govern.

Seven traits that make AI need its own governance

Software has been governed for decades. What makes AI different is a specific set of traits, and the Body of Knowledge lists seven:

TraitWhy it drives governance
ComplexityAI's intricate nature makes it hard for regulators to write comprehensive rules, creating gaps. As systems get more complex, attributing responsibility for a given decision gets harder too.
OpacityLack of transparency in decision-making undermines public trust and requires frameworks that prioritize explainability. Opaque algorithms can perpetuate bias that is hard to audit.
AutonomyHighly autonomous systems may operate without human oversight, raising the risk that a system's objectives drift from human values (misalignment).
Speed and scaleDeployment can outpace regulatory response, and AI's effects can cross borders faster than any single jurisdiction can govern.
Potential for harm or misuseCapabilities can be exploited maliciously, so governance has to assess risk before harms happen, not only after.
Data dependencyReliance on large datasets raises privacy concerns, and poor-quality or biased data produces flawed outputs. That demands real standards for data collection, curation and validation.
Probabilistic vs. deterministic outputsProbabilistic systems complicate decision-making and interpretation, and may need more stringent risk assessment than deterministic systems, because the same input will not always produce the same output.

The last trait connects back to the classic-versus-generative axis from the previous topic: probabilistic output is normal for generative models, and it is one reason they need closer watching.

Governing starts with describing: the OECD's five dimensions

Discussing a system's risks requires a description of the system that everyone at the table shares. The OECD publishes the standard framework for this: it classifies any AI system along five dimensions.

DimensionWhat it covers
1. People and planetThe individuals and groups the system might affect: human rights, the environment, society. Privacy considerations sit here.
2. Economic contextThe sector the system operates in (finance, health care, education), its business function and model, how necessary it is to operations, how and where it is deployed, its scale, and its technological maturity (a newer system has had less real-world testing).
3. Data and inputWhat data the system was built on, plus any expert input (human knowledge codified into rules). Covers how the data was collected, by machine or by human, and its structure and format.
4. AI modelThe technical type of model, and how it was built and is used.
5. Tasks and outputThe tasks the system performs, its outputs, and the actions those outputs trigger, including how task and action combinations are evaluated.

In plain terms, the five dimensions ask: who is affected, why the system exists economically, what fed it, how it works, and what happens with its output. Dimensions 3 and 4 are the data and the model from the first topic; the framework wraps them in the human and economic context around the system. Impact assessments in Domain III are built on the same questions, so learning the framework now saves work later.

The framework applied to an example

Take a hospital system that reads medical scans and flags likely tumors for a radiologist to review. Along the five dimensions:

DimensionThe scan-reader, classified
People and planetPatients and clinicians are affected; health and privacy are at stake.
Economic contextHealth care sector; supports diagnosis; deployed inside hospitals.
Data and inputHistorical scans labeled by radiologists; the data was collected and prepared by humans.
AI modelA deep learning classifier.
Tasks and outputFlags suspicious scans; each flag triggers a human review.

On the capability scale from the previous topic, the scan-reader is narrow AI: it reads scans, and nothing else.

Three placements in that example are easy to get wrong. Privacy belongs to People and planet, because it is about who is affected. How the training data was collected belongs to Data and input. And the sector a system serves always sits under Economic context.

Next up: the principles that answer these demands, from the 1980 fair-information practices to today's responsible-AI frameworks.

Remember

  • The seven traits that make AI need its own governance: complexity, opacity, autonomy, speed and scale, potential for harm or misuse, data dependency, and probabilistic vs. deterministic outputs. The list is worth knowing exactly.
  • The OECD's five dimensions: People and planet, Economic context, Data and input, AI model, Tasks and output. These names are worth knowing exactly too.
  • In plain terms the framework asks: who is affected, why the system exists economically, what fed it, how it works, and what happens with its output.
  • Privacy sits under People and planet. How data was collected sits under Data and input. The sector a system serves sits under Economic context.

Practise this topic

Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.

Start studying free

Previous: Comparing AI models: four axes, expert systems, and capability levels
Next: Principles of responsible AI: FIPs, OECD AI Principles, ethics by design, and trustworthy AI
Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.