{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-005.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-005",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-005.json",
    "title": "Staged rollout with pre-registered rollback criteria",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every change to a deployed AI system (a new model, a retrain, a prompt or corpus change, a new vendor model version) reaches production through shadow, pilot, canary and general availability stages, each with rollback criteria signed before it starts and evaluated by the pipeline, which writes a promote, hold or roll-back verdict per stage to the assurance store.",
    "failureModes": [
      "A change goes from the eval harness to all traffic at once, so the first evidence about live behaviour is the harm itself.",
      "A rollback criterion is written or loosened after the metric moved, or a threshold is edited on a dashboard rather than through a reviewed diff with an approver.",
      "A criterion trips and the rollback waits for a meeting instead of the pipeline acting on it.",
      "Criteria are checked only in aggregate, so a regression for one group (the pattern's example: one language) passes the canary."
    ],
    "scope": "Changes to deployed AI systems that can move quality, safety or fairness, including changes that touch no line of the deployer's code. At general availability the criteria stay on as live monitors.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Rollout plan registered before the first stage, stage verdicts and rollback events in the assurance store, summarised in the rollout field of the go/no-go record",
        "schemaId": "go-no-go",
        "schema": "https://aigovernanceengineer.com/schemas/go-no-go.v1.json",
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A tripped criterion stops promotion and returns the exposed cohort to the baseline; the stage verdict and the rollback event are recorded before anyone meets."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "staged-rollout-rollback-criteria",
        "title": "Staged Rollout with Rollback Criteria",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "staged-rollout-rollback-criteria",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
      },
      {
        "kind": "schema",
        "ref": "go-no-go",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-go-no-go"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART26-5",
          "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        },
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 1.1",
          "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
        },
        {
          "id": "MEASURE 2.3",
          "title": "Performance or assurance criteria measured for deployment-like conditions"
        },
        {
          "id": "MANAGE 2.4",
          "title": "Mechanisms to supersede, disengage or deactivate AI systems"
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 18,
        "title": "Pattern: Staged Rollout with Rollback Criteria",
        "text": "Pattern: Staged Rollout with Rollback Criteria (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria",
        "verified": "primary"
      },
      {
        "n": 19,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Progressive delivery as a control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#progressive-delivery-as-a-control",
        "verified": "primary"
      },
      {
        "n": 20,
        "title": "The Site Reliability Workbook, ch. 16 \"Canarying Releases\"",
        "text": "The Site Reliability Workbook, ch. 16 \"Canarying Releases\" (\"a partial and time-limited deployment of a change in a service and its evaluation\"). Google (O'Reilly). 2018.",
        "url": "https://sre.google/workbook/canarying-releases/",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 21,
        "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)",
        "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (Art. 49 and 71 registration in the EU database; Art. 60 testing of high-risk AI systems in real-world conditions outside sandboxes). Publications Office of the EU (EUR-Lex). 2024-07-12.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Give each stage a purpose: shadow proves behaviour on real traffic, a pilot with trained users proves oversight works, and a canary against a control group proves no regression at scale.",
      "Each stage lists metric, comparison, threshold, window and the group breakdowns that matter; where outcome labels arrive after the stage ends, lean on proxies such as disagreement, overrides, complaints and groundedness.",
      "Review the criteria with their owners on the maintenance calendar: criteria that are too tight produce rollback fatigue.",
      "A provider or prospective provider that pilots an Annex III system with real users before placing it on the market is testing in real-world conditions, which Art. 60 governs; that pre-market pilot is outside this control, which covers changes to systems already in use."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "How long each stage runs and how much exposure it takes are left to the plan; the source material gives illustrative values only and no method to size a stage for a per-group regression."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
