The Authority is a small, senior, cross-functional body with clear decision rights. It owns the standards, runs the reviews, and is the only route to an exception. It operates as the AI-specialist complement to the Group Industrialization Design Authority (IDA), applying Group and Business Line policy to AI product work — see Foundations.
Standing members hold the bar and the cadence. A rotating bench of practitioners brings deep expertise to individual reviews so the core stays lean.
Ian Davies. Accountable for the Authority. Owns the cadence, breaks ties, and holds the final decision on delivery escalations.
One senior owner per pillar — Responsible AI, Architecture, Product & UX, Delivery. Each maintains their standards and leads reviews in their domain.
Independent authority on ethics, safety, and regulation. Holds a standing veto on Responsible AI grounds that the Lead cannot override.
Runs intake, scheduling, and the decision record. Keeps the standards library and waiver register current.
Not members, but decision-holders the Authority coordinates with: the CISO owns cybersecurity approval and exceptions; the DPO owns data protection sign-off.
A rotating pool of senior engineers, data scientists, and designers who staff reviews. Rotation spreads the standard and avoids single points of failure.
Etienne Grass. Mandates the Authority, unblocks resourcing, and represents it to the wider practice and to the IDA.
A member of the Authority, connecting it to the AI Asset Product Owner community and the asset creation process. See Asset Lifecycle.
Clear ownership prevents both bottlenecks and quiet gaps. Every decision has one accountable role.
| Decision | Accountable | Notes |
|---|---|---|
| Asset technology approval | AI Design Authority | The technology lens at Step 4 of the asset process |
| Risk class of a product | Reviewer, confirmed by pillar lead | Set at Gate 0; re-classified on material change |
| Gate Pass / Hold decision | Assigned reviewer | Escalates to Lead if contested |
| Responsible AI sign-off | Responsible AI lead | Independent; not overridable by the Lead |
| Cybersecurity approval & exceptions | CISO | Group Exception Management process; Authority coordinates |
| Data protection sign-off | DPO | Required for sensitive or live personal data |
| Granting a waiver / exception | Pillar lead + Authority Lead | Cyber exceptions to CISO; RAI exceptions to the RAI lead |
| Investment docking (>€1M) | Group Investment Committee (GIC) | Per ASLM; aligns Group IT, Cyber, Legal, Portfolio |
| Adding or changing a standard | Authority, by consensus | Lead decides if consensus is not reached |
| Delivery escalation | Lead | Final within the Authority; sponsor beyond |
Open drop-in plus scheduled gate reviews. The working heartbeat of the Authority.
Standing members meet to decide waivers, contested gates, and standards changes.
The full library is reviewed against new regulation, tooling, and lessons from live products.
The sponsor reviews the Authority's mandate, membership, and measured impact.
The library is version-controlled and dated, and structured as an AI management system aligned to ISO/IEC 42001. Anyone can propose a change; the Authority ratifies it. A standard that no longer earns its place is retired, not left to rot.
Any practitioner raises a gap or a change, with the problem and evidence behind it.
The relevant pillar lead drafts or refines the standard and tests it against real builds.
The Authority agrees the wording and level, versions it, and communicates the change with a lead time.
Standards overtaken by regulation or practice are deprecated and archived, with the reason recorded.
Sometimes a mandatory standard genuinely cannot be met in time. An exception makes that a conscious, owned, time-boxed decision — never a silent gap. Cybersecurity exceptions follow the Group Exception Management process and require CISO sign-off.
State the standard, why it cannot be met, a risk assessment, and the compensating controls and mitigation plan.
The pillar lead and Authority Lead decide — the Responsible AI lead for safety or ethics, the CISO for cybersecurity exceptions. Granted, refused, or narrowed.
Every exception carries a named owner and an expiry date. It closes when the standard is met, or it is reviewed again.
All live exceptions sit on a visible register the Authority reviews at each session. Nothing expires unnoticed.
What cannot be waived. Legal and regulatory obligations, prohibited use cases, and core Responsible AI protections are not waivable. If you cannot meet these, the product does not ship in that form.
It is a recorded, senior decision to accept a known risk for a defined time. Teams that lean on waivers to skip standards will find the bar comes back at the next gate.
We track gate pass rates, waiver volume and age, and time-to-decision — and publish them. The Authority is accountable for being fast and fair, not just strict.
Both start at the same intake. Bring the problem and the evidence — we will take it from there.