OECD Recommendation on Artificial Intelligence (2024 Update)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Definitions and Scope
Apply the updated OECD definition of AI system per the OECD Recommendation on Artificial Intelligence as amended 3 May 2024. The updated definition aligns with the EU AI Act and converging international consensus and defines an AI system as a machine-based system that for explicit or implicit objectives infers from the input it receives how to generate outputs such as predictions content recommendations or decisions that can influence physical or virtual environments. AI systems vary in their levels of autonomy and adaptiveness after deployment. The 2024 Update materially expanded scope to address foundation models + generative AI + agentic AI capabilities. Apply scope considerations covering (a) general-purpose AI models and systems including foundation models and generative AI + with consideration for downstream deployer responsibilities, (b) AI systems lifecycle covering plan and desi
- updated AI system definition adopted per 2024 OECD/EU convergence
- AI actor role matrix per 2024 OECD taxonomy
- AI lifecycle coverage documentation
- framework interoperability mapping
- pre-2024 definition still used producing regulatory drift
- AI actor roles ambiguous across foundation model + downstream deployer
- lifecycle coverage gaps in pre-training or decommissioning
Deployer Responsibilities and Agentic AI
Operate deployer responsibilities + agentic AI considerations + engagement with rights holders per OECD 2024 Update. Deployer responsibilities and contextual adaptation must (a) adapt AI systems received from providers to deployment context including domain + jurisdiction + population + use case + with documented adaptation choices and responsibilities, (b) implement provider-deployer cooperation on safety + performance + incident response + improvement + (c) maintain deployer-level monitoring + evaluation + improvement complementing provider-level governance, (d) provide users with context-appropriate disclosures + training + support. Agentic AI considerations must (a) implement governance for AI systems with extended autonomy + action-taking capability + tool use + including AI agents that can perform multi-step tasks + access external systems + make consequential decisions, (b) constr
- deployer-level adaptation + monitoring + complementing provider governance
- agentic AI scope + authority + circuit breakers + human override
- rights holder engagement + impact assessment + contestation + redress
- deployer treats provider compliance as sufficient without deployer adaptation
- agentic AI deployed without scope limits or circuit breakers
- rights holders not identified or engaged
Frontier Model Risk
Manage frontier model risk + capability disclosure + independent evaluation per OECD 2024 Update + emerging international AI safety governance. Frontier model risk and capability disclosure must (a) identify frontier models based on compute + capability + use case + potential catastrophic risk profile + aligned with emerging frontier model definitions (UK AI Safety Institute + US Executive Order on AI Safety + EU AI Act Article 51 general-purpose AI with systemic risk + similar), (b) assess and disclose capabilities + limitations + risks + including dual-use + autonomy + cyber + bio + chem + nuclear risk + persuasion + manipulation + economic disruption + (c) implement risk management proportionate to risk profile including dangerous capability evaluation + responsible disclosure + scaling policies + (d) participate in voluntary frontier model commitments (Frontier Model Forum + Hiroshim
- frontier model identification + capability assessment + risk disclosure
- responsible scaling policy + dangerous capability evaluation
- independent evaluation participation (AISI + third-party + red team)
- alignment with international frontier commitments
- frontier model not identified despite meeting capability/compute thresholds
- no responsible scaling policy
- evaluation conducted internally without independent assurance
GenAI Transparency and Provenance
Adhere to OECD 2024 Update transparency requirements for generative AI + content provenance + authenticity. Generative AI transparency for outputs must (a) clearly disclose to users when they are interacting with AI-generated content + AI-personalised content + or AI-augmented content per applicable jurisdiction requirement (EU AI Act Article 50 + similar), (b) maintain disclosure proportionate to the risk + context + and potential for harm of mistaking AI-generated content for human-generated content + (c) implement labelling + watermarking + or other technical measures for AI-generated synthetic media including deepfakes + voice cloning + image manipulation per emerging standards (C2PA Coalition for Content Provenance and Authenticity + W3C standards + similar). Content provenance and authenticity must (a) implement cryptographically verifiable provenance metadata including content ori
- GenAI output disclosure mechanisms aligned to EU AI Act Article 50
- content provenance metadata per C2PA or equivalent
- watermarking + labelling per content type and risk
- downstream verification support
- GenAI outputs not labelled producing regulatory exposure
- provenance metadata stripped by intermediaries
- no content authentication infrastructure
Incident Reporting and Information Integrity
Operate AI incident reporting + information safety + misinformation + manipulation mitigation per OECD 2024 Update. AI incident reporting and information sharing must (a) participate in OECD AI Incidents Monitor (AIM) and related international AI incident reporting frameworks where applicable, (b) report incidents per applicable regulation (EU AI Act Article 73 serious incident reporting + sectoral + voluntary commitments) + national and international monitoring initiatives, (c) coordinate incident response with other affected AI actors + regulators + civil society + (d) maintain incident learning loop feeding back to risk management + design + deployment. Information safety and integrity must (a) protect against AI-enabled disinformation + propaganda + targeted manipulation + including via generative AI, (b) maintain platform-level + content-level + and ecosystem-level information safet
- AI incident reporting per applicable regulation + voluntary monitoring (OECD AIM + Hiroshima)
- information safety measures + platform coordination
- misinformation + manipulation mitigation per applicable regulation (DSA + AI Act + similar)
- AI incidents under-reported
- no pre-emptive election or crisis response capability
- no coordination with platforms or fact-checkers
Interoperability and Cross-Border
Operate interoperability with international AI frameworks + public reporting + cross-border governance per OECD 2024 Update. Interoperability with other AI frameworks must (a) align AI governance across multiple international and national frameworks (EU AI Act + UK AI regulation + US Executive Order + Canada AIDA + Japan AI guidelines + China AI rules + Singapore AI guidance + Australia AI ethics + sectoral US guidance + NIST AI RMF + ISO/IEC 42001 + ISO/IEC 23894 + UNESCO Recommendation on AI Ethics), (b) maintain framework crosswalk to avoid duplicative effort + identify framework conflicts + manage residual ambiguity, (c) participate in international standard-setting (ISO + IEC + ITU + IEEE) + voluntary commitment processes (Hiroshima + Bletchley + Seoul + Paris AI Action Summit + Frontier Model Forum). Public reporting on AI governance must (a) maintain transparency reporting on AI g
- AI regulatory inventory across applicable jurisdictions + crosswalk
- public reporting on AI governance + outcomes + harms
- cross-border AI governance + extraterritoriality alignment + incident coordination
- regulatory inventory incomplete missing China + India + emerging frameworks
- public reporting absent or generic
- no extraterritoriality assessment for EU AI Act + similar
Security, IP, Environment
Adhere to OECD 2024 Update security + model and data protection + IP + environmental sustainability. Security including model and data protection must (a) protect AI models against extraction + theft + tampering + with model signing + cryptographic protection + access control + (b) protect training and inference data against unauthorised access + tampering + extraction + including model inference attacks + (c) implement security per emerging AI security frameworks (NIST AI 100-3 + ISO/IEC TS 27091 + MITRE ATLAS + OWASP LLM Top 10 + similar), (d) coordinate AI security with broader cybersecurity governance. Intellectual property and training data must (a) respect IP rights in training data including copyright + trademark + database rights + sui generis protections + (b) maintain training data provenance + licensing + opt-out + with reproducible data trails, (c) navigate emerging case law
- AI security per NIST AI 100-3 + MITRE ATLAS + OWASP LLM Top 10
- IP rights respected in training data + provenance + licensing + opt-out
- AI environmental impact assessment + disclosure + efficiency measures
- AI security treated as separate from broader cybersecurity
- training data IP rights not verified
- environmental impact not measured or disclosed
Workplace AI, Children, Vulnerable Populations
Adhere to OECD 2024 Update workplace AI + worker voice + children + vulnerable populations protections. Workplace AI and worker voice must (a) implement workplace AI deployment with worker consultation + collective bargaining engagement + transparency + (b) protect workers from AI-enabled surveillance overreach + algorithmic management harms + discrimination + (c) support workforce transition through reskilling + redeployment + just transition measures aligned with OECD MNE Guidelines Chapter V + ILO standards, (d) maintain mechanisms for worker contestation of AI decisions affecting employment + working conditions + (e) consult worker representatives in AI procurement + deployment + policy decisions. Children protection must (a) implement age-appropriate AI design + deployment + with consideration for cognitive + emotional + developmental needs + (b) protect against AI-enabled exploitat
- worker consultation in workplace AI deployment + collective bargaining engagement
- children protection per COPPA + UK Children Code + EU + sectoral requirements
- vulnerable populations impact assessment + engagement + redress
- workplace AI deployed without worker consultation
- children AI services without age verification or parental consent
- vulnerable populations not engaged in impact assessment
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the OECD Recommendation on Artificial Intelligence (2024 Update) framework page.