EC-Council's ADG Framework Wants to End AI Governance Fragmentation
~78% of executives say they wouldn’t pass an AI governance audit in the next 90 days. ~1% believe their governance capabilities have reached maturity. Those numbers aren’t from a consulting firm trying to sell you something — they’re the backdrop against which EC-Council just dropped its most ambitious initiative yet.
What Launched
On May 29, 2026, EC-Council — the credentialing body behind the Certified Ethical Hacker (CEH) — released the Adopt. Defend. Govern. (ADG) AI Framework, a free, open operating model designed to give enterprises a single structure for governing AI across their entire deployment lifecycle. Alongside it: a free AI Readiness Self-Assessment Tool to help organizations benchmark their current posture.
The framework was built with direct input from practitioners at Citi, JPMorgan Chase, Microsoft, KPMG, Deloitte, NTT Data, GE Healthcare, GlobalLogic, Prudential, and Salesforce. This isn’t a committee document — it’s practitioners from high-stakes environments telling you what they actually needed.
What ADG Actually Is
The framework organizes around three pillars:
Adopt handles alignment between AI deployment and business objectives — workforce readiness, implementation accountability, and operational fit.
Defend focuses on securing AI systems against the threat vectors that matter most right now: prompt injection, adversarial manipulation, data poisoning, model exploitation, and AI supply chain compromise.
Govern embeds auditability and accountability into systems from initial deployment through enterprise-scale operations.
Beneath those three pillars sit 12 minimum controls, nine governance surfaces, nine deployment overlays, and three autonomy tiers. Every control maps to a major global standard — the EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM and Agentic AI, and MITRE ATLAS.
That last part is the real value proposition. Most enterprises already know ISO 42001 is the standard to hit — the problem has always been translating abstract framework requirements into auditable operational practices. ADG attempts to close that gap by providing the execution layer those standards lack.
Why the Timing Matters
Global AI spending is projected to hit $2.5 trillion in 2026. The speed of deployment has completely outpaced governance maturity, and the board-level accountability gap isn’t closing fast enough. Compliance fragmentation — organizations trying to satisfy the EU AI Act, NIST AI RMF, and ISO 42001 with three separate programs — creates overhead that most teams can’t sustain.
The ADG framework’s pitch is consolidation: one operating model, one set of controls, cross-referenced to all three major frameworks simultaneously.
Open and Extensible by Design
There’s no licensing fee. EC-Council is positioning ADG as a community-driven standard that evolves alongside AI technology — practitioners can contribute to its development. Three new certifications (Certified AI Program Manager, Certified Offensive AI Security Professional, and Certified Responsible AI Governance and Ethics Professional) align to the framework for organizations that want workforce credentials to match.
Whether ADG becomes a genuine industry standard or another shelf document depends entirely on adoption — but the practitioner pedigree, cross-framework mapping, and zero cost barrier are a credible combination.
Further Reading
- EC-Council ADG Framework Official Launch (GlobeNewswire)
- ADG Framework Site — EC-Council Global Services
- EC-Council ADG Framework Coverage — IT Brief Asia
- EC-Council ADG Framework — Foreign Policy Journal
AI Disclosure
This document is drafted by an AI skill and is provided for informational and governance support purposes only. It does not constitute legal advice or a formal compliance determination. Do not publish or rely on this notice as a substitute for review by qualified legal counsel or a licensed compliance professional with jurisdiction-specific expertise.