Technology

AIQA Global Introduces AIQ DNA to Measure How AI Governance Performs When Risk Becomes Real

Published

on

New framework organizes 250 governance datapoints around Structural controls and three operational functions: Deter, Notify, and Act

AIQ DNA is an analytical framework from AIQA Global that groups AI governance controls into three functions — Deter, Notify, and Act — based on what each control does before, during, and after an incident.

CHICAGO, Sept. 3, 2026 /PRNewswire/ — AIQA Global, LLC., (AIQA), the first independent AI governance rating firm, today introduced AIQ DNA, an analytical framework that organizes the company’s 250-datapoint AI governance methodology around what each control does before, during and after an AI incident.

Global AI governance frameworks contain hundreds of requirements spanning policy, oversight, technical controls, monitoring and response. AIQ DNA reorganizes them around a different question: what does each control actually do when risk becomes operational?

AIQ DNA Three Functions

Within AIQA’s 250-datapoint reconciliation of the major frameworks, 46 datapoints describe structure — ownership, budget, board oversight and program maturity. The remaining 204 describe operating capability, grouped into three functions:

Deter — controls that reduce exposure before an event, including least privilege, access authority, pre-deployment review and procurement standards. 123 datapoints.Notify — controls that shorten the time a problem can run unrecognized, including monitoring, anomaly detection, logging and escalation. 41 datapoints.Act — controls that limit the loss once an event is underway, including incident response, rollback, recourse and remediation. 40 datapoints.

The distribution is instructive on its own. The methodology contains 123 datapoints addressing exposure before an event, against 41 for detection and 40 for response and recovery. Watch the AIQ DNA explainer video.

“When something goes wrong, a board wants pretty basic answers,” said James E. Malackowski, Co-Founder and Chairman of AIQA Global. “When did we know? What could the system reach? Who had the authority to stop it? Could we keep operating without it? Those aren’t policy questions. They’re questions about whether the controls actually work. AIQ DNA gives us a common way to look at those controls together.”

Industry Context

AIQ DNA arrives as industry attention shifts from statements of policy toward verified controls and measurable outcomes. In an August 27 open letter on collective cyber defense, OpenAI and more than one hundred signatories called on organizations to verify that security fixes work, and urged the technology industry to measure how quickly attacks are contained.

A day earlier, OpenAI published its technical report on the Hugging Face incident, in which internal research models circumvented isolation controls and reached third-party systems. The report states that OpenAI’s chain-of-thought monitoring was not running on the affected evaluations, and that had it been, it would have flagged the activity and alerted the security team more than a day before the models reached Hugging Face. It also states that the production safeguards applied to OpenAI’s deployed systems were not extended to that evaluation environment. OpenAI worked with external advisors including CrowdStrike to validate its understanding of the incident, and METR and Redwood Research conducted an independent investigation and published separately.

“The controls existed. They were not in scope for that environment,” Chase Malackowski, AIQA’s Co-Founder, Managing Director, and Chief Technology Officer said. “That is not a technology failure. It is a governance question — which controls apply where, who decided that, and whether anyone checked. Those questions tend to get answered after an incident when they should be answerable before one.”

AIQ DNA was developed by Maria Ross, AIQA’s Chief Operating Officer, who leads the company’s insurance segment.

“Underwriters do not price adjectives,” said Ross. “They price likelihood and consequence. Deter speaks to likelihood and exposure surface. Notify speaks to how long a problem can run before anyone understands it. Act speaks to containment time, severity and recovery. Those are observable characteristics of risk. Once controls can be observed consistently, insurers can begin testing whether they are predictive of loss.”

AIQA does not provide cybersecurity products or remediation services. Its role is to assess independently whether an organization’s AI governance controls are supported by evidence, have been implemented and, where appropriate, have been tested.

AIQ DNA does not create a separate rating. It is an additional view of the same 250 datapoints used in the AIQ™ Rating, allowing an organization to see the balance of its governance capability across Structural, Deter, Notify and Act.

About AIQA Global, LLC

AIQA Global, LLC is the first independent AI governance rating firm, providing enterprises, investors, insurers, and boards with a standardized, quantitative measure of AI governance quality. The company’s AIQ™ score quantifies enterprise AI governance quality across 250 data points and five dimensions. For more information, visit AIQA Global.

AIQ™ scores are based on disclosed and verified data and represent AIQA Global’s independent assessment of AI governance quality. Scores do not constitute regulatory compliance, legal advice, or investment advice. No assurance is provided regarding future performance, risk outcomes, or insurance eligibility. AIQ™ and AIQ™ Score are trademarks of AIQA Global, LLC. Copyright 2026 AIQA Global, LLC. All rights reserved.

View original content to download multimedia:https://www.prnewswire.com/news-releases/aiqa-global-introduces-aiq-dna-to-measure-how-ai-governance-performs-when-risk-becomes-real-302868958.html

SOURCE AIQA Global, LLC

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version