ISO - AI Concepts and Terminology

ISO/IEC 22989:2022 - Information technology — Artificial intelligence — Concepts and terminology

ISO

RAI-XS-GO-I2ITAXX-2022

ISO/IEC 22989:2022

Effective: July 19, 2022
In Force(In Force)
StandardGovernance and OversightTransparency and DisclosureRisk Management
Export PDF

The primary international standard for AI terminology and concepts, establishing a common language for global AI governance and development.

Overview

ISO/IEC 22989:2022 serves as the foundational linguistic and conceptual infrastructure for the global artificial intelligence ecosystem. Developed by the joint technical committee ISO/IEC JTC 1/SC 42, this standard was created to resolve the significant fragmentation in AI terminology that characterized the early 2020s. By establishing a common vocabulary, the standard enables diverse stakeholders—including researchers, developers, regulators, and end-users—to communicate with precision across different jurisdictions and industrial sectors. It provides the essential definitions that underpin subsequent governance standards, such as ISO/IEC 42001 (Management Systems) and ISO/IEC 23894 (Risk Management), ensuring that technical requirements and regulatory obligations are built upon a consistent conceptual base. The standard is designed to be technology-neutral, meaning it focuses on the fundamental characteristics of AI rather than specific programming languages or hardware architectures, making it resilient to the rapid pace of technological change.

The significance of ISO/IEC 22989 lies in its role as a 'horizontal' standard, meaning its definitions and conceptual models are designed to be applicable across all domains, from healthcare and finance to autonomous transportation and manufacturing. In the context of international AI governance, it acts as a Rosetta Stone that harmonizes the technical understanding of AI with legal and ethical frameworks. By providing clear distinctions between terms like 'machine learning,' 'deep learning,' and 'artificial intelligence,' the standard assists policymakers in defining the scope of regulations, such as the EU AI Act, which often relies on ISO-aligned definitions to ensure legal certainty and international interoperability. This harmonization is critical for reducing trade barriers and ensuring that safety assessments conducted in one region are understandable and valid in another.

Definitions

The standard provides over 100 formal definitions that are critical for technical and legal compliance. At its core is the definition of an 'AI system,' described as an engineered system that generates outputs such as content, forecasts, recommendations, or decisions for a given set of human-defined objectives. This definition is pivotal because it distinguishes AI from traditional software by emphasizing the role of data-driven inferences and the system's ability to influence physical or virtual environments. Furthermore, the standard defines 'machine learning' as a process where computational techniques enable a system to improve its performance through experience, effectively codifying the distinction between rule-based systems and learning-based systems. It also introduces the concept of 'autonomy' in the context of AI, defining it as the degree to which a system can perform its intended functions without human intervention, which is a key metric for safety and liability assessments.

Beyond basic technical terms, ISO/IEC 22989 defines qualitative properties that are essential for 'trustworthy AI.' These include transparency (the property that information about an AI system is available), explainability (the ability to present the mechanics of an AI system in human-understandable terms), and robustness (the ability of a system to maintain its performance level under various conditions). By standardizing these terms, the document provides a technical basis for 'Trustworthiness'—a key pillar of global AI governance. It also introduces critical data-related terms such as 'training data,' 'validation data,' and 'test data,' which are essential for the technical auditing and conformity assessment processes required by emerging regulatory frameworks. Other vital definitions include 'bias,' which is defined as a systematic error in an AI system that results in unfairness, and 'reliability,' which refers to the ability of a system to perform its required functions under stated conditions for a specified period.

Governance and Institutional Framework

The development and maintenance of ISO/IEC 22989 are managed by ISO/IEC JTC 1/SC 42, the first international standards committee to address the entire AI ecosystem. This committee operates as a 'system integration entity,' collaborating with other technical committees within ISO and the International Electrotechnical Commission (IEC) to ensure that AI standards are integrated into broader information technology and management frameworks. The governance of the standard follows the established ISO/IEC consensus-based process, which involves national standards bodies from over 30 'P-member' (participating) countries, including ANSI (USA), BSI (UK), AFNOR (France), and JISC (Japan). This ensures that the terminology reflects a global consensus rather than the perspective of a single region or industry. The committee also maintains a 'Strategic Advisory Group' to identify emerging trends and ensure the standard remains relevant to industry needs.

The institutional framework of SC 42 is divided into several working groups, with Working Group 1 (WG 1) specifically tasked with foundational standards like concepts and terminology. This group ensures that the standard remains a 'living document' through systematic reviews and amendments. The governance structure also includes liaison relationships with international organizations such as the OECD, UNESCO, and the European Commission. These liaisons ensure that the technical definitions provided in ISO/IEC 22989 are aligned with high-level policy principles, such as the OECD Principles on AI, thereby bridging the gap between technical standardization and global policy-making. This collaborative approach ensures that the standard is not developed in a vacuum but is informed by the latest developments in ethics, law, and social science, reflecting a holistic view of AI's impact on society.

Key Provisions

One of the most significant provisions of ISO/IEC 22989 is the establishment of a standardized 'AI System Lifecycle.' This model divides the existence of an AI system into distinct stages: inception, design and development, verification and validation, deployment, operation and monitoring, and finally, retirement. By defining these stages, the standard provides a framework for organizations to implement governance controls at every phase of a system's life. For instance, it specifies that 'verification' is the process of confirming that a system meets its specified requirements, while 'validation' is the confirmation that the system achieves its intended use in a real-world environment. This distinction is vital for safety-critical applications where failure to validate could lead to significant harm. The lifecycle model also emphasizes the importance of 'continuous monitoring' to detect performance degradation or unexpected behaviors after a system has been deployed.

The standard also outlines a functional overview of AI systems, describing the relationships between data, models, and algorithms. It provides conceptual models for different types of learning, including supervised, unsupervised, and reinforcement learning, and explains how these techniques interact with data processing and knowledge representation. Another key provision is the categorization of 'AI stakeholder roles,' which identifies the responsibilities of AI providers, producers, customers, partners, and subjects. This role-based framework is essential for establishing accountability and liability, as it clarifies which entity is responsible for specific activities, such as data curation, model training, or system monitoring, within a complex AI supply chain. By defining these roles, the standard helps organizations draft clearer contracts and service-level agreements, ensuring that all parties understand their obligations regarding safety and compliance.

Scope and Application

The scope of ISO/IEC 22989 is intentionally broad, covering the fundamental concepts required for the development, deployment, and use of AI systems across all sectors. It is designed to be used by any organization, regardless of size or industry, that is involved in the AI lifecycle. Because it is a foundational standard, its primary application is to serve as a reference for other, more specific standards. For example, a company implementing an AI Management System (AIMS) under ISO/IEC 42001 would use ISO/IEC 22989 to define the scope of their system and to ensure that their internal policies use terminology that is recognized by external auditors and regulators. The standard is also applicable to third-party assessors and certification bodies who need a rigorous set of definitions to evaluate an organization's compliance with AI governance requirements.

Geographically, the standard has global application through the ISO/IEC network. In Europe, it has been adopted as EN ISO/IEC 22989:2023 by CEN-CENELEC, making it a recognized European standard that supports the implementation of the EU AI Act. In the United States, it is adopted as INCITS/ISO/IEC 22989:2022. This widespread adoption means that a developer in Asia can use the same conceptual framework as a regulator in Europe, facilitating international trade and reducing the compliance burden for multinational corporations. The standard is also used in academic research and by professional organizations to provide a rigorous basis for AI education and certification programs. By providing a common language, it enables the creation of global benchmarks for AI performance and safety, which are essential for the maturation of the AI industry.

Implementation Framework

Implementation of ISO/IEC 22989 typically occurs as the first step in an organization's AI governance journey. Organizations are encouraged to map their existing internal vocabularies and process descriptions to the standard's definitions and lifecycle model. This 'mapping exercise' identifies gaps in the organization's understanding of its AI assets and ensures that all departments—from legal and compliance to data science and engineering—are using the same language. For example, an organization might use the standard's definition of 'bias' to develop its internal fairness metrics, ensuring that its technical testing is aligned with internationally recognized definitions of algorithmic prejudice. This internal alignment is crucial for building a culture of responsibility and for ensuring that technical risks are effectively communicated to senior management.

The standard also supports the implementation of risk management frameworks. By providing a clear structure for the AI lifecycle, it allows organizations to conduct 'Impact Assessments' at the inception and design stages, as recommended by the standard. It provides the vocabulary needed to describe specific risks, such as 'adversarial examples' or 'model drift,' which are unique to AI systems. Furthermore, the standard's emphasis on documentation and transparency properties provides a blueprint for creating the 'technical documentation' required for conformity assessments. In essence, implementing ISO/IEC 22989 transforms AI governance from an abstract ethical exercise into a structured, auditable management process. Organizations that successfully implement the standard can demonstrate to regulators, customers, and the public that they are following international best practices for AI safety and transparency.

Monitoring and Evaluation

Monitoring and evaluation under ISO/IEC 22989 are conducted at both the organizational and the institutional levels. At the organizational level, the standard provides the terminology for 'monitoring' (the continuous checking of a system's performance) and 'evaluation' (the systematic determination of a system's quality or value). Organizations use these concepts to build dashboards and reporting mechanisms that track whether an AI system is operating within its intended parameters. This is particularly important for detecting 'concept drift,' where the statistical properties of the target variable change over time, rendering the AI model less accurate. The standard also encourages the use of 'feedback loops' where the results of monitoring are used to update the system's design or training data, ensuring continuous improvement.

At the institutional level, ISO/IEC JTC 1/SC 42 monitors the relevance of the standard through a 'systematic review' process, which typically occurs every five years. However, given the rapid pace of AI development, the committee can initiate amendments or revisions more frequently. For instance, in 2024, work began on 'Amendment 1: Generative AI' to incorporate terms like 'foundation model,' 'prompt engineering,' and 'hallucination' into the standard. This ensures that the standard remains relevant as new technologies emerge. Evaluation of the standard's effectiveness is also gathered through feedback from national member bodies and through the analysis of its adoption in regulatory frameworks worldwide. This iterative process ensures that the standard evolves alongside the technology it seeks to define, maintaining its position as the global authority on AI terminology.

Relationship to Other Instruments

ISO/IEC 22989 is the 'normative reference' for the entire ISO/IEC 42xxx series of AI standards. Its most critical relationship is with ISO/IEC 42001:2023, the international standard for AI Management Systems. While 42001 provides the 'requirements' for what an organization must do to govern AI, 22989 provides the 'definitions' of the terms used in those requirements. Without 22989, the requirements in 42001 would be subject to varying interpretations, undermining the consistency of the management system. It also has a close relationship with ISO/IEC 23053, which provides a framework for AI systems using machine learning, and ISO/IEC 23894, which focuses on AI risk management. Together, these standards form a comprehensive toolkit for organizations to manage the technical, legal, and ethical aspects of AI.

Beyond the ISO ecosystem, the standard is designed to be compatible with other international instruments. It aligns closely with the OECD's definition of an AI system, which was updated in 2023 to be more technically precise and harmonized with ISO terminology. It also supports the NIST AI Risk Management Framework (RMF) by providing a technical lexicon that complements NIST's focus on socio-technical risks. In the context of the EU AI Act, ISO/IEC 22989 is expected to be part of the 'harmonized standards' package that provides a 'presumption of conformity' for high-risk AI systems, effectively linking voluntary technical standards with mandatory legal requirements. This alignment ensures that organizations can use a single set of technical definitions to meet multiple regulatory and voluntary obligations, significantly reducing the complexity of global AI compliance.

International Alignment

The standard represents a high degree of international alignment, reflecting contributions from a diverse range of global stakeholders. During its development, significant effort was made to ensure that the terminology did not conflict with existing legal definitions in major jurisdictions like the US, EU, and China. This alignment is crucial for 'mutual recognition' agreements, where different countries agree to recognize each other's conformity assessments. By using a shared terminology, countries can more easily compare their regulatory requirements and ensure that AI systems developed in one country meet the safety and ethical standards of another. This is particularly important for the growth of the global AI market, as it prevents the fragmentation of the industry into regional silos with incompatible technical requirements.

Furthermore, ISO/IEC 22989 aligns with the work of other international bodies such as the ITU (International Telecommunication Union) and the IEEE (Institute of Electrical and Electronics Engineers). While the IEEE often focuses on the ethical design of autonomous systems (e.g., the P7000 series), ISO/IEC 22989 provides the high-level conceptual bridge that allows these detailed technical standards to be understood within a broader organizational and regulatory context. This 'system of standards' approach ensures that the global AI governance landscape is not a collection of isolated silos, but a coherent framework that supports innovation while protecting fundamental rights and safety. The standard's role in international alignment is also supported by its translation into multiple languages, ensuring that its concepts are accessible to a truly global audience.

Implementation Timeline

MilestoneDateStatus
Project Approval (New Work Item Proposal)2018-04-20Completed
Draft International Standard (DIS) Inquiry2021-10-15Completed
Official Publication of ISO/IEC 22989:20222022-07-19In Force
Adoption as European Standard (EN ISO/IEC 22989:2023)2023-06-26Completed
Launch of Amendment 1 (Generative AI)2024-05-15Under Development
Projected Publication of Amendment 12025-12-30Planned

Adoption and Endorsement

EntityDateStatus
ISO/IEC JTC 1/SC 422022-07-19Adopted
CEN-CENELEC (European Union)2023-06-26Endorsed
ANSI (United States)2023-01-01Adopted
BSI (United Kingdom)2022-07-31Adopted
AFNOR (France)2022-08-15Adopted
DIN (Germany)2022-09-01Adopted

Sources and References

SourceType
ISO/IEC 22989:2022 - Information technology — Artificial intelligence — Concepts and terminologyInternational Organization
ISO/IEC 22989:2022 - IEC WebstoreInternational Organization
Artificial intelligence concepts and terminology (ISO/IEC 22989:2022) - ÚNMS SRRegulatory Agency
Information technology - Artificial intelligence - Artificial intelligence concepts and terminology (ISO/IEC 22989:2022) SS-EN ISO/IEC 22989:2023 - Swedish Institute for Standards, SISRegulatory Agency
Foundational building blocks for AI systems - IEC e-techInternational Organization
Plain English

ISO/IEC 22989:2022 provides the essential common language and concepts for anyone developing, deploying, or regulating artificial intelligence systems worldwide.

This international standard applies to any organization, regardless of size or industry, involved in the lifecycle of AI systems, from initial design to operation and retirement. It's designed for researchers, developers, product managers, and regulators alike, aiming to resolve the confusion caused by fragmented AI terminology. Its core purpose is to standardize over 100 key definitions, ensuring everyone uses the same terms for concepts like "AI system," "machine learning," "bias," "transparency," and "explainability." This consistency is vital for building trustworthy AI and for clear communication across different sectors and countries. The standard also outlines a universal "AI System Lifecycle" – from inception to retirement – providing a framework for managing AI projects. It further clarifies "AI stakeholder roles," helping define responsibilities within complex AI supply chains.

The standard officially took effect on July 19, 2022, and has since been adopted by major regions like the European Union (as EN ISO/IEC 22989:2023) and the United States. While ISO standards don't carry direct legal penalties, their widespread adoption means they form the technical bedrock for mandatory regulations, such as the EU AI Act. Compliance with these definitions can offer a "presumption of conformity" with legal requirements, reducing compliance burdens and trade barriers. A key practical takeaway is that this standard is a "living document." Given the rapid evolution of AI, the committee regularly reviews and updates it, with an amendment for Generative AI already underway. This means organizations must stay current with revisions to ensure their internal terminology and governance frameworks remain aligned with the latest international consensus.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under ISO - AI Concepts and Terminology. Not legal advice — verify against the official text before relying on it.

  1. #1ImportantImplementation Framework

    Applies to: Organizations involved in the AI lifecycle.

    Organizations are encouraged to map their existing internal vocabularies and process descriptions to the standard's definitions and lifecycle model.
  2. #2ImportantImplementation Framework

    Applies to: Organizations involved in the AI lifecycle.

    ensures that all departments—from legal and compliance to data science and engineering—are using the same language.
  3. #3ImportantKey ProvisionsBefore deploying an AI system

    Applies to: Organizations developing or deploying AI systems.

    By defining these stages, the standard provides a framework for organizations to implement governance controls at every phase of a system's life.
  4. #4ImportantDefinitions

    Applies to: Organizations developing or assessing AI systems.

    By standardizing these terms, the document provides a technical basis for 'Trustworthiness'—a key pillar of global AI governance.
  5. #5ImportantImplementation Framework

    Applies to: Organizations developing or deploying AI systems.

    an organization might use the standard's definition of 'bias' to develop its internal fairness metrics
  6. #6ImportantImplementation Framework

    Applies to: Organizations involved in the AI lifecycle.

    The standard also supports the implementation of risk management frameworks. ... It provides the vocabulary needed to describe specific risks...
  7. #7ImportantImplementation FrameworkBefore seeking conformity assessment

    Applies to: Organizations seeking conformity assessment for AI systems.

    the standard's emphasis on documentation and transparency properties provides a blueprint for creating the 'technical documentation' required for conformity assessments.
  8. #8ImportantMonitoring and EvaluationBefore deploying an AI system

    Applies to: Organizations operating AI systems.

    Organizations use these concepts to build dashboards and reporting mechanisms that track whether an AI system is operating within its intended parameters.
  9. #9ImportantKey ProvisionsBefore entering into AI-related contracts

    Applies to: Organizations involved in AI supply chains.

    By defining these roles, the standard helps organizations draft clearer contracts and service-level agreements, ensuring that all parties understand their obligations...
  10. #10RecommendedMonitoring and Evaluation

    Applies to: Organizations operating AI systems.

    The standard also encourages the use of 'feedback loops' where the results of monitoring are used to update the system's design or training data...

© Regulations.AI — created on 07-Jan-2026 using Gemini 3 Flash Preview