Chirag Dani · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22707377
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Organisations deploying artificial intelligence face a practical governance question that existing standards, principles and regulations do not answer directly: given a specific AI system, how much governance is enough? Overgoverning low-consequence systems creates bureaucratic drag and stalls beneficial adoption; undergoverning high-consequence systems creates operational, regulatory and societal risk. This paper introduces CALIBRE, a factorbased governance-intensity framework for AI systems. The framework distils recurring risk dimensions from the AI risk literature into five interpretable factors (Autonomy, Consequence, Irreversibility, Data Sensitivity, and Affected-Population Scale), each scored on a 0 to 4 ordinal scale and combined through explicit weights into a Governance Intensity Index (GII) on a 0 to 100 scale. Four intensity bands (Low, Moderate, High, Critical) route the assessed system to a proportionate set of ten core CALIBRE controls, each pre-mapped to the NIST AI Risk Management Framework, ISO/IEC 42001, and the European Union AI Act. A consistencyfloor mechanism prevents systematic under-rating on characteristic combinations known to warrant elevated governance regardless of arithmetic score. Because the scoring model is strictly linear, per-factor contributions to the GII match Shapley values, giving CALIBRE exact, factor-decomposable explanations without post-hoc approximation. To address AI architectures whose governance-relevant characteristics are not captured by the five-factor core (agentic, physical-actuator, cryptographic-critical, distributed-ledger, and biometric systems), the paper introduces an Architecture-Sensitive Amplification mechanism that conditionally activates targeted sub-scores whose only permitted effect is a band uplift. The framework is positioned as a design-science artefact whose propositions are open to empirical validation; the paper defines a Delphi expert-panel study protocol as the immediate next validation step. The paper’s principal theoretical contribution is a layered separation of governance intensity, risk characteristics, and governance controls into three distinct architectural layers, and the demonstration that a small, stable core plus conditional amplification provides coverage across ten representative AI architectural classes without expanding the core assessment.
No comments yet — start the discussion below.