Skip to the content.

Governance

The AI IR Overlay is open, vendor-neutral, and Apache 2.0 licensed. This document defines how decisions get made today and how governance will change as the project matures.

Project status

This is a pre-1.0 project with governance maturation in progress. Current scale:

The framework’s roadmap to v1.0.0 is documented in CHANGELOG.md [Unreleased] and CONTENT_MAP.md.

Current governance (v0.x)

Roles

Decision-making

Release cadence

Cadence Type Approver
Per content drop (v0.x) MINOR (0.x.0) Lead Maintainer
As warranted PATCH (0.x.y) Lead Maintainer

Amendments to this document

During v0.x: Lead Maintainer decides after a 14-day public comment window.

Future governance (v1.0.0 and beyond)

The following structures will be convened only if the project reaches v1.0.0 with sustained external community engagement. None of these structures exist today.

Planned: Steering Committee (target: 5 seats)

Planned: Working Group Leads

Planned: Decision-making at v1.0.0 and beyond

Planned: Release cadence at v1.0.0 and beyond

Cadence Type Approver
Quarterly MINOR (1.x.0) Lead Maintainer
As warranted PATCH (1.x.y) Working Group Lead
Roughly annual MAJOR (x.0.0) Steering Committee

Major versions would only be justified by external-ecosystem shifts. Examples: a future NIST AI Agent Interoperability Profile, an EU AI Act Article 26 update, an OWASP Agentic Top 10 revision.

Planned: Certification program

The AI IR Overlay Certified™ mark exists as a defensive registration to reserve the framework’s brand. The certification program itself does not yet exist. When the program is built (target: with v1.0.0), it will be documented in a separate charter at certification/charter.md and will cover:

Until then, the mark is reserved for the maintainer’s future use; no third party is currently authorized to claim certification under it.

Planned: Amendments at v1.0.0 and beyond

From v1.0 onward: Steering Committee two-thirds vote after a 30-day public comment window.

Trademark

Code of Conduct

This project adopts the Contributor Covenant v2.1. See CODE_OF_CONDUCT.md.

Security disclosures

For vulnerabilities, follow the private reporting path in SECURITY.md.