AI governance gets real when a control produces evidence. EC-Council's ADG 2.0 expands to 180+ controls
EC-Council's new framework specifies the evidence each AI control must produce during operation, and sets human review points by autonomy tier. Useful, if nobody mistakes a crosswalk for compliance.
Listen to this article · 6 min
AI-generated narration of the full article.

Most AI governance documents say the right things: maintain human oversight, monitor for bias, keep an inventory. Few say what proves any of it happened. EC-Council’s founder Jay Bavisi put it bluntly when the company released ADG 2.0 on October 1: “Most AI governance today is a policy document nobody tests.”
The framework is one of many. What makes it worth a look is how it is built.
What ADG 2.0 contains
ADG stands for Adopt, Defend, Govern. Version 2.0 replaces the original 12 minimum controls with more than 180 controls in 12 families, crosswalked to more than 90 regulations, standards and frameworks, including the NIST AI RMF, ISO/IEC 42001, the EU AI Act, MITRE ATT&CK and ATLAS, and the OWASP Top 10 lists for LLM applications and for agentic systems.
Two design choices stand out:
- Each control specifies the evidence it requires, so the evidence is collected while the system runs, not reconstructed when an auditor arrives.
- Human review is tied to autonomy tiers. The framework uses three tiers (Assistive, Conditional, Autonomous) and defines review thresholds at four operational points it calls ADMIT, DECIDE, EMIT and COMMIT.
The framework and a self-assessment tool are free, without registration. EC-Council is also offering its crosswalks at no cost to governments, regulators and standards bodies.
Policy, control, evidence
The useful idea is a ladder every governance program can apply, whichever framework it follows:
- Policy statement
- Technical control
- Evidence produced in operation
- Independent check of the evidence
What we intendWhat the system enforces
Take “human oversight for high-impact decisions.” As policy, it is a sentence. As a control, it is an approval step that the workflow cannot skip. As evidence, it is a record of who approved, what they saw, how long they took and how often they overrode the agent. Only the last one survives an audit, and only the last one tells you whether oversight is real. That is the gap we described in our analysis of IBM’s study on human oversight: a review step that nobody can challenge is not a control.
The evidence a production agent should generate
For any agent with real permissions, the question for each control is the same: what artifact proves this happened? A practical minimum:
- Owner and sponsor of the agent, with dates of assignment.
- Model and version, and the version of its instructions.
- Identity the agent runs under, and the permissions granted.
- Retrieved context for each decision, at least as references.
- Tools invoked, with parameters and results.
- Approvals requested and given, by whom.
- Actions taken in other systems.
- Evaluation results for the version in production, and the date they were run.
- Exceptions and overrides, with reasons.
Most of this is telemetry engineering, not policy writing. It overlaps with what observability tools capture, as in our analysis of agent observability beyond uptime, but the purpose differs: observability asks whether the system works; evidence asks whether the system did what governance said it would. Design the schema with compliance in the room, before go-live. Retrofitting evidence is how audits become archaeology.
ADG’s autonomy tiers also echo the approach in our framework for earning agent autonomy one action at a time: review requirements should depend on what the agent is allowed to do, and evidence is what moves an action class up a tier.
What a crosswalk is not
A mapping from a control to the EU AI Act or ISO/IEC 42001 tells you which requirement the control relates to. It does not mean that implementing the control satisfies the requirement. Regulations have scope conditions, documentation duties and conformity procedures that a control list cannot discharge. Use crosswalks to find gaps and avoid duplicate work across frameworks; use counsel and auditors to decide what compliance means.
For U.S. companies, the practical frame is usually the NIST AI RMF for internal programs and SOC 2 or ISO/IEC 42001 when customers ask for assurance. A crosswalk that lets one evidence set serve all three is worth more than a new framework adopted on its own.
What to do now
- Pick your top five AI controls and write, next to each, the artifact that proves it operated.
- Check whether that artifact is produced automatically today. If not, that is your engineering backlog.
- Define an evidence schema for agents using the list above, and have compliance sign off on it.
- Tie review requirements to autonomy tiers, and log approvals and overrides as evidence.
- Use crosswalks to reduce duplicate work, not as proof of compliance.
- Run the self-assessment if you want an outside checklist, and treat its output as a gap list.
The bottom line
ADG 2.0 will not be the last framework, and frameworks are not the point. The point is the shift it represents: AI governance is becoming evidence engineering. The companies that design what their agents must record, before those agents go live, will find every framework easier to satisfy.