---
title: "What Is a Responsible AI Framework? Core Principles Explained"
url: "https://atlan.com/know/ai-readiness/responsible-ai-framework-principles/"
description: "A responsible AI framework cross-walks NIST, EU AI Act, and OECD principles, and separates responsible AI from AI governance and AI ethics in practice."
author: "Emily Winks"
author_role: "Data Governance Expert"
published: "2026-07-27"
updated: "2026-07-27T00:00:00.000Z"
---

---

A responsible AI framework is the set of principles, not an org chart or a policy binder, that defines what "trustworthy" AI actually requires: fairness, transparency, accountability, safety, explainability, and privacy. Cisco, Microsoft, McKinsey, and IBM each publish a different count. Only three bodies carry real standards-body weight: NIST's AI Risk Management Framework, the EU AI Act, and the OECD's AI Principles, and this guide cross-walks all three against each other rather than adding a fifth list.

---

[Researchers have catalogued 60 to 84 distinct, competing sets of published AI ethics and responsible-AI principles since 2018](https://ar5iv.labs.arxiv.org/html/2006.12358), which is why nearly every vendor's list reads a little different from the next. Principles only matter once something enforces them at the point a model or agent touches data.

| | |
|---|---|
| **What it is** | Principles and values guiding ethical, trustworthy AI use |
| **Key standards** | NIST AI RMF, EU AI Act (via ALTAI), OECD AI Principles |
| **Not the same as** | AI governance (implementation) or AI model governance (lifecycle controls) |
| **Adoption reality** | Fewer than 1% of companies fully operationalized (WEF & Accenture, 2025) |
| **Core principles** | Fairness, transparency, accountability, safety, explainability, privacy |
| **Best for** | Data leaders, AI governance leads, and compliance teams setting AI policy |

---

## How do NIST, the EU AI Act, and OECD define responsible AI principles?

Three bodies carry actual regulatory or standards-body weight on responsible AI: NIST, the EU AI Act (via ALTAI), and the OECD. Cisco, Microsoft, McKinsey, and IBM each simplify these same three sources into their own count rather than citing them side by side, and no single page reconciles what each standards body actually requires against the other two.

[NIST](https://www.nist.gov/trustworthy-and-responsible-ai), the U.S. National Institute of Standards and Technology, defines trustworthy AI through seven characteristics in its AI Risk Management Framework. Elham Tabassi, Associate Director for Emerging Technologies at NIST's Information Technology Laboratory, described the framework this way: "The RMF describes trustworthy AI as valid and reliable, safe, fair and unbiased, secure and resilient, accountable and transparent, explainable and interpretable, and privacy-enhanced." NIST AI RMF 1.0 released in January 2023, with a Generative AI Profile (NIST AI 600-1) finalized in July 2024.

The EU AI Act's approach to trustworthy AI builds on the EU High-Level Expert Group's Ethics Guidelines for Trustworthy AI. ALTAI, the HLEG's Assessment List for Trustworthy AI, is the practical checklist organizations use to self-assess against those same seven requirements, the backbone the Act's trustworthiness provisions draw on, not a substitute for the statute's own legal text. ALTAI groups its requirements into seven areas: human agency and oversight, technical robustness and safety, privacy and data governance, transparency, diversity/non-discrimination/fairness, societal and environmental wellbeing, and accountability.

The [OECD's AI Principles](https://oecd.ai/en/ai-principles), the first intergovernmental AI standard, were adopted in 2019 and updated in 2024, now endorsed by 47 countries and economies. They organize around five values-based principles: inclusive growth and wellbeing, human rights and democratic values (including fairness and privacy), transparency and explainability, robustness and security and safety, and accountability.

| Principle category | NIST AI RMF (7 characteristics) | EU AI Act / ALTAI | OECD AI Principles (5 values-based) |
|---|---|---|---|
| Fairness | Fair, with harmful bias managed | Diversity, non-discrimination, and fairness | Folds under human rights and democratic values |
| Transparency | Accountable and transparent | Transparency | Transparency and explainability |
| Accountability | Accountable and transparent | Human agency and oversight; accountability | Accountability |
| Safety and reliability | Valid and reliable; safe | Technical robustness and safety | Robustness, security, and safety |
| Explainability | Explainable and interpretable | Transparency (no separate explainability heading) | Transparency and explainability |
| Privacy and security | Privacy-enhanced; secure and resilient | Privacy and data governance | No standalone equivalent; implicit in human rights |

Each framework arrives at a different total because it splits or merges these same six categories differently, not because the underlying substance changes: NIST keeps "transparent" and "explainable" separate, while ALTAI and the OECD both fold explainability under transparency, one reason NIST counts seven and OECD counts five for largely overlapping ground. Two items resist a clean three-way match: NIST's standalone "secure and resilient" characteristic has no dedicated OECD principle, and OECD's explicit "human rights and democratic values" principle, bundling fairness and privacy, has no direct NIST analog. Those two gaps, not the six principles above, are where an organization aligning to only one standard is most likely to miss a real requirement rather than just use a different label for it. Grounding a [Colorado AI Act](https://atlan.com/know/ai-readiness/colorado-ai-act/) or broader [US state-level compliance program](https://atlan.com/know/ai-readiness/the-eu-ai-act-summary/) in this full cross-walk, rather than any single framework alone, catches a requirement one standard states explicitly and the others only imply.

---

## Responsible AI vs. AI governance vs. AI ethics: what's the difference?

These three terms get used almost interchangeably across vendor content, but they answer different questions: what should we value, how do we enforce it, and why does it matter philosophically in the first place.

### What is responsible AI (the principles)?

Responsible AI is the specific set of principles and values an organization commits to for building and using AI ethically. Oliver Patel, AIGP, CIPP/E, and Head of Enterprise AI Governance at AstraZeneca, frames it as "the specific principles and values which are most relevant and integral to actually achieving and advancing ethical AI." It is the "what to value" layer.

### What is AI governance (the implementation)?

AI governance is how those principles, plus applicable regulations and standards, get implemented and enforced. Patel's contrast is direct: governance is "how the principles of responsible AI, as well as AI regulations and standards, are implemented, operationalised, and adhered to in practice." That six-layer control stack, the [policy-to-risk-classification-to-audit pipeline](https://atlan.com/know/ai-readiness/ai-governance-framework/), is a separate topic this page stops at naming.

### What is AI ethics (the philosophical foundation)?

AI ethics is the underlying values question responsible AI operationalizes into concrete principles: what should AI systems be permitted to do, and to whom is that accountable. It is the least contested of the three, operating one level above both responsible AI and governance, closer to philosophy than policy.

This distinction matters in practice, not just semantically. An organization can have a beautifully written responsible AI principles document and still have no AI governance, no risk classification, no monitoring, nothing that actually enforces those principles day to day. That gap, principles documented but not enforced, is exactly what shows up in the adoption data below.

  The CIO's Guide to Context Graphs
  A primer for leaders deciding where governance and responsible AI principles sit in an AI stack that spans multiple regulatory frameworks at once.
  Get the Guide

---

## What are the 6 core principles of responsible AI?

Once the NIST, EU AI Act, and OECD frameworks above are reconciled, six recurring principles surface consistently (the framework mapping is in the cross-walk above), each grounded here in what it concretely requires.

| Principle | Plain-English definition | What it requires in practice |
|---|---|---|
| Fairness | AI systems don't produce systematically worse outcomes for protected groups | Bias testing against protected attributes pre-training, plus ongoing monitoring post-deployment |
| Transparency | People affected by an AI decision can learn a model was involved, and roughly how it decided | Disclosure that AI is in use, plus documented inputs, purpose, and limitations |
| Accountability | A named owner is responsible for an AI system's outcome, not just its build | Assigned ownership, audit trails, and an escalation path when something goes wrong |
| Safety and reliability | The system performs consistently under real-world conditions and fails safely when it doesn't | Testing across the full deployment lifecycle, plus rollback and monitoring plans |
| Explainability | The reasoning behind a specific output can be inspected, not just the system's overall behavior | Lineage from a decision back to the data and logic behind a single output |
| Privacy and security | Data used to train or run an AI system is protected from unauthorized access, and resists tampering | Access controls, encryption, and data minimization for training and runtime data |

An earlier Atlan page on [AI governance principles](https://atlan.com/know/ai-readiness/ai-governance-principles/) names nearly the same six, sourced from vendor frameworks rather than the standards bodies above; a vendor's list shifts with its roadmap, a standards body's only when NIST, the European Commission, or the OECD revises it. For fairness, see [training data bias detection methods](https://atlan.com/know/training-data-bias-detection-methods/); for accountability's traceability, [AI agent memory governance](https://atlan.com/know/ai-agent-memory-governance/), [zero-trust data governance](https://atlan.com/know/zero-trust-data-governance/), and [AI-ready data lineage](https://atlan.com/know/ai-readiness/ai-ready-data-lineage/) cover the audit-trail infrastructure, while [evaluating an AI agent beyond accuracy](https://atlan.com/know/ai-agent-evaluation-benchmarks-and-metrics/) grounds safety-and-reliability.

---

## Why does responsible AI matter for your organization right now?

Adoption lags badly behind stated commitment; the gap is measurable.

Per the [World Economic Forum and Accenture (2025)](https://www.weforum.org/publications/advancing-responsible-ai-innovation-a-playbook/), fewer than 1% of 1,500 companies surveyed have fully operationalized responsible AI, and 81% remain in the earliest stages of maturity. Per [McKinsey's State of AI Trust in 2026 report](https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era), only about 30% reach a maturity level of three or higher. Per [Deloitte's State of AI in the Enterprise 2026 report](https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html), 74% plan to adopt agentic AI, but only 21% have a mature governance model for it.

Regulated industries increasingly require a named framework as part of procurement and audit, and agentic AI widens that gap: an [AI agent acting autonomously](https://atlan.com/know/ai-agent-risks-guardrails/) needs principles enforced in real time, not documented after the fact. Both assume a framework already exists, which [AI maturity](https://atlan.com/know/l5-company-ai-maturity-framework/) and [AI readiness](https://atlan.com/know/ai-readiness/ai-ready-data/) assessments increasingly probe for before a deal closes. Naming a framework is only the first step: an [AI registry](https://atlan.com/know/what-is-ai-registry/) inventorying every model and agent in production makes accountability auditable.

---

## How Atlan approaches responsible AI principles

A policy PDF doesn't stop a biased output or an ungoverned agent; enforcement at the point an agent or model accesses data does.

The shape of that enforcement is a six-layer control stack: policy, inventory and risk classification, model cards, monitoring and drift detection, an audit trail, and remediation. [Atlan's AI governance framework guide](https://atlan.com/know/ai-readiness/ai-governance-framework/) walks through the full stack, including NIST's Govern/Map/Measure/Manage functions and the EU AI Act's enforcement calendar; [AI risk management](https://atlan.com/know/ai-readiness/ai-risk-management/), [AI model governance](https://atlan.com/know/ai-readiness/ai-model-governance/), and [AI governance platforms](https://atlan.com/know/ai-readiness/ai-governance-platforms/) cover risk-tiering, lifecycle, and tooling. For AI agents, that stack extends to agent-level guardrails: [AI security for enterprise agents](https://atlan.com/know/ai-security/), [AI agent governance](https://atlan.com/know/ai-agent-governance/), and [defending against prompt injection attacks](https://atlan.com/know/prompt-injection-attacks-ai-agents/), since an agent enforces principles in real time, not after the fact.

  Context Maturity Assessment
  See where your organization sits on the maturity curve before a regulator or customer asks first.
  Assess Your Maturity

Most responsible AI content, including Cisco's, Microsoft's, McKinsey's, and IBM's lists, stops at naming principles and leaves enforcement to the reader. Atlan closes that gap through governed context: sensitivity tags, permissions, and usage limits enforced as an agent acts, making fairness and safety runtime properties. Lineage and audit trails connect a decision to the data that produced it, and [Policy Center](https://atlan.com/know/context-engineering-ai-governance/) creates the accountability paper trail: documented bias evaluation pre-training, version history intact. General Motors' use of Atlan for lineage and visibility proves transparency and accountability; no fairness case study exists yet.

The fuller architecture lives in the broader [enterprise context layer](https://atlan.com/know/what-is-the-enterprise-context-layer/) this fits inside, [implementing an enterprise context layer for AI](https://atlan.com/know/how-to-implement-enterprise-context-layer-for-ai/), [context engineering](https://atlan.com/know/what-is-context-engineering/), and the [context graph](https://atlan.com/know/what-is-a-context-graph/) foundation all three share. For regulated data: [data privacy for AI agents](https://atlan.com/know/data-privacy-for-ai-agents/), [GDPR](https://atlan.com/know/ai-agent/gdpr-compliance-for-ai-agents/), [HIPAA compliance for AI agents](https://atlan.com/know/ai-agent/hipaa-compliance-for-ai-agents/), and [handling PII in AI pipelines](https://atlan.com/know/ai-agent/data-for-ai/how-to-handle-pii-in-ai-pipelines/) cover privacy; [connecting enterprise data sources to LLMs securely](https://atlan.com/know/ai-agent/data-for-ai/how-to-connect-enterprise-data-sources-to-llms-securely/) covers connection-layer safety.

---

## Real stories from real customers: governance at scale



      "AI initiatives require more context than ever. Atlan's metadata lakehouse is configurable, intuitive, and able to scale to hundreds of millions of assets. As we're doing this, we're making life easier for data scientists and speeding up innovation."


      — Andrew Reiskind, Chief Data Officer, Mastercard




    Watch Now




      "Context is the differentiator. Atlan gave our teams the shared vocabulary and lineage to move from reactive data management to proactive AI enablement across CME Group."


      — Kiran Panja, Managing Director, Data & Analytics, CME Group




    Watch Now


Both quotes echo this page's argument: shared vocabulary and traceable context move these principles from policy language into daily practice.

  AI Agent Context Readiness Checklist
  Check whether your data estate gives AI agents the governed context these principles require, before a regulator or customer asks.
  Assess Your Readiness

---

## Why a cross-walk beats another principles list

The vendor lists disagree less because the principles are in dispute and more because nobody had cross-walked NIST, the EU AI Act, and OECD before. That reconciliation surfaces six recurring principles more consistently than vendor labels suggest, and isolates two real gaps, NIST's standalone security characteristic and OECD's human-rights principle, most likely to be missed rather than just labeled differently. Responsible AI, AI governance, and AI ethics remain three different questions; keeping them separate makes a program auditable against a specific standard instead of a vague commitment.

The test is narrower than "do we have principles": can a requirement be traced to the standard it satisfies, and enforced where a model or agent touches data, not just documented for the next audit.

  Book a Demo

---

## Sources

1. [Trustworthy and Responsible AI, NIST](https://www.nist.gov/trustworthy-and-responsible-ai)
2. [AI Principles overview, OECD.AI](https://oecd.ai/en/ai-principles)
3. [AI Risk Management Framework (AI RMF 1.0), NIST](https://www.nist.gov/itl/ai-risk-management-framework)
4. [Advancing Responsible AI Innovation, World Economic Forum & Accenture, 2025](https://www.weforum.org/publications/advancing-responsible-ai-innovation-a-playbook/)
5. [State of AI Trust in 2026, McKinsey](https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era)
6. [AI Governance Profession Report, IAPP](https://iapp.org/resources/article/ai-governance-profession-report)
7. [Where Responsible AI Meets Reality, arXiv](https://ar5iv.labs.arxiv.org/html/2006.12358)
8. [AI Ethics vs. Responsible AI vs. AI Governance, Oliver Patel, LinkedIn](https://www.linkedin.com/posts/oliver-patel_whats-the-difference-between-ai-ethics-activity-7325778187508932609-0ABb)
9. [Responsible AI Principles and Approach, Microsoft](https://www.microsoft.com/en-us/ai/principles-and-approach)
10. [Building a Responsible AI Framework, Harvard Division of Continuing Education](https://professional.dce.harvard.edu/blog/building-a-responsible-ai-framework-5-key-principles-for-organizations/)
11. [AI Risk Management: A Discussion with NIST's Elham Tabassi, Wiley Law podcast](https://www.wiley.law/podcast-AI-Risk-Management-A-Discussion-with-NISTs-Elham-Tabassi-on-the-NIST-AI-Risk-Management-Framework)
12. [State of AI in the Enterprise, Deloitte, 2026](https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html)

---

## FAQs about responsible AI frameworks

### 1. What are the 4 pillars of responsible AI?

Most four-pillar versions collapse into fairness, transparency, accountability, and safety. Longer lists usually just split one of these in two, like separating explainability from transparency, rather than adding something new.

### 2. What are the 6 principles of responsible AI?

The number varies by framework. Cross-walking NIST, the EU AI Act, and OECD surfaces six recurring principles: fairness, transparency, accountability, safety and reliability, explainability, and privacy and security, each labeled slightly differently.

### 3. What is the difference between responsible AI and AI governance?

Responsible AI is the principles and values an organization commits to. AI governance is how those principles and regulations get implemented and enforced. Responsible AI answers what to value; governance answers how to enforce it.

### 4. What is the difference between AI ethics and responsible AI?

AI ethics is the philosophical question of what AI should and shouldn't do. Responsible AI translates that into actionable principles, like fairness and transparency, an organization can build toward and measure.

### 5. Is responsible AI the same as trustworthy AI?

Largely yes. Trustworthy AI is NIST's term for the same idea, defined in its AI Risk Management Framework as AI that is valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

### 6. Does my company need a responsible AI framework if we only use vendor AI models?

Yes. Responsible AI principles apply to how a model's output is used, not just how it was built. The EU AI Act obligates deployers as well as developers, and customers increasingly ask vendors which framework they follow.