EC-Council has released ADG 2.0, the second version of its Adopt, Defend, Govern framework, and is making the framework and its crosswalks to more than 90 regulations, standards and global frameworks available at no charge to any government, regulator or standards body in the world, the company said. It said it will also assist any of those bodies that reach out, helping officials apply the framework to their own laws, draft rules and national standards, consistent with applicable law.
The offer was announced as governments remain divided on how AI should be governed. President Trump has said concerns about AI risks are being exaggerated, while China's Foreign Ministry said fearmongering, confrontation and vicious competition would hamper sound global AI governance. On September 26, Singapore's Foreign Affairs Minister, Vivian Balakrishnan, urged the UN General Assembly to establish new multilateral rules, suggesting a UN Framework Convention on AI Safeguards.
Autonomous agents are already crossing boundaries, according to the announcement. In July, OpenAI disclosed that models undergoing an internal cybersecurity evaluation had circumvented their testing environment and compromised parts of Hugging Face's production infrastructure. Last week, Australia's Prime Minister said an OpenAI agent had gained unauthorized access in June to a public facing Medicare statistics portal, and OpenAI confirmed its agents had accessed U.S. government websites in ways it neither planned nor approved and paused training of its latest models. An independent research lab separately reported a failed attempt against a Department of Education website.
ADG 2.0 replaces the original 12 minimum controls with more than 180 controls in 12 control families, mapped to sources including NIST AI RMF, ISO/IEC 42001, the EU AI Act, MITRE ATT&CK, MITRE ATLAS, and the OWASP Top 10 for LLM Applications and the OWASP Agentic Top 10. It sets out runtime governance at four points — ADMIT, DECIDE, EMIT and COMMIT — with human approval required at defined decision thresholds; Assistive, Conditional and Autonomous tiers of autonomy; evidence requirements specified for each control; and a DART method of Discover, Analyze, Report and Transform. The framework, its crosswalks and an AI Readiness Self-Assessment are available to everyone without registration.
Jay Bavisi, EC-Council's founder, chairman and group chief executive, said the nuclear non-proliferation treaty worked because inspectors could weigh uranium, but an agent's behaviour cannot be weighed, and no AI treaty would be signed and ratified in time to protect the systems agents are reaching today. He said governments should not have to build governance from a blank page while they wait, and that the company would sit down with any government, regulator or standards body that wanted help putting ADG 2.0 to work.