Pith. sign in

REVIEW 4 major objections 4 minor 18 references

Toward Effective AI Governance: A Review of Principles

T0 review · 4 major / 4 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Nine secondary studies show AI governance literature converges on the EU AI Act and NIST RMF but offers few actionable implementation mechanisms.

desk verdict A well-intentioned but under-supported tertiary review: the abstract and body disagree on the top principles, and no frequency data backs either ranking. read the letter →

arxiv 2505.23417 v1 pith:65HPFWYB submitted 2025-05-29 cs.SE cs.AI

classification cs.SEcs.AI
keywords AIgovernanceResponsibletertiaryreviewrapidtransparencyaccountabilityEUActNISTRMF
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper is a rapid tertiary review: a synthesis of existing reviews rather than a new primary study. The authors ask what the secondary literature on AI governance emphasizes and synthesize nine secondary studies published between 2020 and 2024, drawn from two major computing-oriented digital libraries. Their central finding is that the literature converges on high-level frameworks—most often the EU AI Act and the NIST RMF—and on a small set of principles, with transparency and accountability most prominent, but that few studies give concrete, organization-level governance mechanisms or stakeholder engagement strategies. If the finding holds, it gives practitioners and researchers a consolidated map of what the field regards as important and a clear statement of where the evidence stops: principle-level agreement, not implementation guidance.

What carries the argument

The carrying mechanism is the rapid tertiary review design: a search of two computing-oriented digital libraries with a fixed query, manual screening of 55 candidate records down to nine secondary studies, structured data extraction, and thematic synthesis following the steps of extract, code, translate into themes, and build higher-order themes. The classification grid is a set of six governance pillars—fairness, transparency, privacy and security, sustainability, accountability, and explainability—used to code the reviewed studies. The main evidence carriers are the included studies themselves, especially the Responsible AI Pattern Catalogue, the Responsible AI Metrics Catalogue, a privacy-and-security-aware framework, and an explainability roadmap. This machinery matters because the reported rankings of frameworks and principles are produced by what those nine studies happen to cite and emphasize.

What would settle it

Re-running the same search with dual screening and a third digital library would falsify the central claims if it returns a different dominant framework or principle set—if, say, human oversight or fairness outranks transparency, or if detailed implementation mechanisms turn out to be common in the wider literature.

Watch

Extended reading notes

Core claim

On the paper's own terms, the discovery is a gap analysis of the AI governance review literature. After screening 55 candidate records down to nine secondary studies, the authors report that the most frequently cited governance frameworks are the EU AI Act and the NIST RMF, alongside a range of other instruments such as AI Verify, the EU's capAI project, the EU Trustworthy AI Assessment List, and the NSW AI Assurance Framework. The most emphasized principles are transparency and accountability, followed by fairness, privacy, explainability, and safety; accountability is often decomposed into responsibility, auditability, and redressability. Stakeholders tend to be categorized at industry, organizational, and team levels, but the authors conclude that concrete guidance is scarce: only a subset of the reviewed studies describe audit procedures, ethics committees, documentation protocols, or similar mechanisms, and even less attention is paid to empirical validation or the inclusion of underrepresented groups.

Load-bearing premise

The load-bearing premise is that nine studies located in two computing-oriented digital libraries by a single screener—including some that were not peer-reviewed—fairly represent what the AI governance literature emphasizes; if that sample is biased, the rankings change.

Editorial extensions

If this is right

  • Organizations designing AI governance can expect consensus on what matters—transparency, accountability, fairness—but little tested guidance on how to implement it; the paper collects the few concrete mechanisms that appear, such as ethics committees, algorithmic audits, standardized reporting, maturity models, and certification.
  • Researchers mapping AI governance can treat the computing-oriented literature as converging on the EU AI Act and NIST RMF, so new studies should either build on these anchors or justify diverging from them.
  • Stakeholder strategy in the current literature is largely a three-level categorization (industry, organization, team) plus calls for inclusive engagement, not an operational procedure.
  • The review's conclusion implies that the most useful next studies are empirical evaluations of governance practices and methodologically consistent re-reviews, rather than additional surveys of principles.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A broader search that included policy, law, and human-computer-interaction databases would probably surface more implementation-oriented governance mechanisms, meaning the reported operational gap may partly reflect the computing-only corpus rather than the whole field of AI governance.
  • Because at least one of the nine selected studies is a preprint rather than a peer-reviewed publication, the synthesis actually draws on non-peer-reviewed sources; if that is true, the peer-reviewed framing in the abstract is doing less work than claimed.
  • A conflict-oriented reading of the same nine studies, looking for tensions between transparency and privacy or between accountability and efficiency, might find that the principles form not a shared foundation but a set of unresolved trade-offs.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. This paper presents a rapid tertiary review of nine secondary studies on AI governance, retrieved from IEEE Xplore and ACM Digital Library, with the aim of mapping frameworks, principles, organizational mechanisms, and stakeholder roles. It reports that the EU AI Act and NIST RMF are the most cited frameworks, that transparency and accountability are the most common principles, and that few reviews detail actionable governance mechanisms. It concludes with implications for industry, society, and research, and it acknowledges the streamlined and limited nature of the review.

Significance. A rigorous synthesis of secondary literature on AI governance would be valuable to both researchers and practitioners, and the paper's four-question structure is sensible. The paper is transparent about its rapid-review constraints, provides its search string and an open data link, and explicitly acknowledges limitations such as the two-database scope and single-author screening. However, as submitted, the headline rankings are not supported by reproducible counts, the selection process includes non-peer-reviewed preprints despite a stated peer-review criterion, and the evidence table contains broken references. The contribution would be useful after these issues are corrected and the reported findings are made internally consistent and verifiable.

major comments (4)
  1. [Abstract and §III (RQ2)] The abstract and the introduction's bullet list state that transparency and accountability are the most common principles, but §III RQ2 states that 'Across all studies, transparency and privacy are the most frequently cited principles, followed by fairness, accountability, explainability...' No frequency counts are reported anywhere, and the only citations given for the RQ2 claim are [16] and [17], which do not support the abstract's phrasing. This internal contradiction makes the headline result unverifiable; the authors should report per-study counts and align the abstract, introduction, and results.
  2. [§II.C–D and §III.A] The inclusion criteria require that articles be peer-reviewed, and §III.A asserts that 'All selected articles were published between 2020 and 2024 in peer-reviewed venues.' However, refs [11], [16], and [17] are arXiv preprints (with [11] marked 'forthcoming' at the time), and Table I includes them. This violates the stated criterion and changes the composition of the reviewed sample. Either the criterion must be relaxed with a clear justification, or the preprints must be replaced or reclassified, and all reported rankings must be re-derived from the corrected sample.
  3. [§III (RQ1)] The claim that the EU AI Act and NIST RMF are 'the most cited frameworks' is not supported by any quantitative extraction. RQ1 provides only qualitative examples and points to individual studies; no table or count shows how often each framework appears across the nine included studies. The phrase 'most cited' is therefore an assertion rather than a reported finding, and it needs to be backed by a frequency count or a clear coding table.
  4. [Table I and References] The evidence table has broken reference numbering: reference [10] is assigned to both 'Towards a Privacy and Security-Aware Framework...' and 'IT Governance in the Artificial Intelligence Age...', and the row 'Responsible AI Systems: Who are the Stakeholders?' is keyed to [2], which in the reference list is Raji et al. 'Closing the AI accountability gap' (2020), not the Deshpande and Sharp study. This prevents readers from mapping the included studies to the reported synthesis, and the table and reference list must be corrected.
minor comments (4)
  1. [§II] In §II, the sentence beginning 'However, the growing number of such reviews, we believe it is time...' is grammatically incomplete, and the word 'belive' should be 'believe'.
  2. [Table I] Table I contains a typographical error: 'Metrics Catalogue:cA Collection' should read 'Metrics Catalogue: A Collection'.
  3. [References] Reference [6] has a truncated author field ('B. , G. Pinto, and S. Soares') and should be completed.
  4. [§VI Conclusion] The conclusion claims that the literature shows convergence on 'algorithmic auditing' as a best practice, but the results section does not report any included study specifically recommending algorithmic auditing; this claim should either be supported with extracted evidence or removed.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the review's findings are aggregations of external secondary studies, not derived from the authors' own prior claims.

full rationale

This rapid tertiary review summarizes nine external secondary studies from IEEE and ACM. Its central claims—which frameworks and principles are most cited, which mechanisms are described, and which stakeholders are represented—are presented as thematic syntheses of that external literature, not as consequences of prior results by the same authors. The self-citations to rapid-review methodology (refs 5–7) support only the procedural choice of a streamlined review, and do not feed into the substantive findings about AI governance. No fitted parameter is renamed as a prediction, and no definition is constructed in terms of the claimed outcome. The paper is therefore self-contained against its evidence base. The internal inconsistency between the abstract's 'transparency and accountability are the most common principles' and the body's RQ2 statement that 'transparency and privacy are the most frequently cited principles' is a reporting/correctness issue, not a circularity issue, because neither claim is produced by circular reasoning from the paper's own inputs. Accordingly, the circularity score is 0.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The review depends on assumptions about database coverage, the peer-review status of included studies, the reliability of single-author screening, and the suitability of the coding scheme. The peer-review assumption is demonstrably violated, and the coverage assumptions are acknowledged in the threats to validity section.

assumptions (4)
  • domain assumption The IEEE Xplore and ACM Digital Library are sufficient to capture the relevant AI governance secondary literature.
    Search limited to these two libraries (Section II-B), which may miss legal, policy, and HCI perspectives (acknowledged in Section V).
  • ad hoc to paper The nine selected studies are peer-reviewed secondary studies.
    Inclusion criteria require peer-reviewed (Section II-C), but references [11], [16], and [17] are arXiv preprints, and [8] is an arXiv preprint, violating this criterion.
  • domain assumption Single-author screening and extraction without inter-rater reliability is sufficient for accurate synthesis.
    Only the first author performed screening (Section II), increasing risk of selection bias.
  • domain assumption The six RAI governance pillars (fairness, transparency, privacy/security, sustainability, accountability, explainability) form an appropriate coding scheme.
    Classification based on pillars from prior work (Section II-E), but not validated for this corpus.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Toward Effective AI Governance: A Review of Principles." pith.science (2026). https://pith.science/paper/65HPFWYB

@misc{pith2026250523417,
  author       = {Pith},
  title        = {Pith review of: Toward Effective AI Governance: A Review of Principles},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/65HPFWYB}},
  note         = {Machine review of arXiv:2505.23417}
}
read the original abstract

Artificial Intelligence (AI) governance is the practice of establishing frameworks, policies, and procedures to ensure the responsible, ethical, and safe development and deployment of AI systems. Although AI governance is a core pillar of Responsible AI, current literature still lacks synthesis across such governance frameworks and practices. Objective: To identify which frameworks, principles, mechanisms, and stakeholder roles are emphasized in secondary literature on AI governance. Method: We conducted a rapid tertiary review of nine peer-reviewed secondary studies from IEEE and ACM (20202024), using structured inclusion criteria and thematic semantic synthesis. Results: The most cited frameworks include the EU AI Act and NIST RMF; transparency and accountability are the most common principles. Few reviews detail actionable governance mechanisms or stakeholder strategies. Conclusion: The review consolidates key directions in AI governance and highlights gaps in empirical validation and inclusivity. Findings inform both academic inquiry and practical adoption in organizations.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

18 extracted references · 16 canonical work pages

  1. [10]

    It gov- ernance in the artificial intelligence age: Trends and practices,

    K. ¯Abeln¯ıca, A. Rom ¯anovs, G. Petrovskis, and A. Vindecs, “It gov- ernance in the artificial intelligence age: Trends and practices,” in 2024 IEEE 65th International Scientific Conference on Information Technology and Management Science of Riga Technical University (ITMS). IEEE, 2024, pp. 1–6

  2. [13]

    Responsible ai systems: Who are the stakeholders?

    A. Deshpande and H. Sharp, “Responsible ai systems: Who are the stakeholders?” in Proceedings of the 2022 AAAI/ACM Conference on Artificial Intelligence, Ethics, and Society , 2022

  3. [16]

    Responsible AI Pattern Catalogue: A Collection of Best Practices for AI Governance and Engineering

    Q. Lu, L. Zhu, X. Xu, J. Whittle, D. Zowghi, and A. Jacquet, “Responsi- ble ai pattern catalogue: A collection of best practices for ai governance and engineering,” arXiv preprint arXiv:2209.04963 , 2023, accessed via arXiv on September 29, 2023

  4. [17]

    Towards a Responsible AI Metrics Catalogue: A Collection of Metrics for AI Accountability

    B. Xia, Q. Lu, L. Zhu, S. U. Lee, Y . Liu, and Z. Xing, “Towards a responsible ai metrics catalogue: A collection of metrics for ai accountability,” arXiv preprint arXiv:2311.13158 , 2024

  5. [11]

    Typology of Risks of Generative Text-to-Image Models

    C. Bird, E. L. Ungless, and A. Kasirzadeh, “Typology of risks of generative text-to-image models,” in Proceedings of the 2023 AAAI/ACM Conference on AI, Ethics, and Society (AIES 2023) , 2023, forthcoming. [Online]. Available: http://arxiv.org/abs/2307.05543v1

  6. [2]

    Closing the ai accountability gap: Defining an end-to-end framework for internal algorithmic auditing,

    I. D. Raji, A. Smart, R. White, M. Mitchell, T. Gebru, B. Hutchinson, J. Smith, and P. Barnes, “Closing the ai accountability gap: Defining an end-to-end framework for internal algorithmic auditing,” in Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency . ACM, 2020, pp. 33–44

  7. [1]

    Ai4people—an ethical framework for a good ai society: Opportunities, risks, principles, and recommendations,

    L. Floridi, J. Cowls, M. Beltrametti, R. Chatila, P. Dignum, C. Luetge, R. Andorno, V . Botti, P. F. de Hert, B. Stahl, P. Sattari, M. D. Dubber, and T. V . Wiegand, “Ai4people—an ethical framework for a good ai society: Opportunities, risks, principles, and recommendations,” Minds and Machines, vol. 28, no. 4, pp. 689–707, 2018

  8. [3]

    Ai index report 2023,

    Stanford Institute for Human-Centered Artificial Intelligence (HAI), “Ai index report 2023,” 2023, accessed: 2024-05-16. [Online]. Available: https://aiindex.stanford.edu/wp-content/uploads/ 2023/04/HAI AI-Index-Report-2023 CHAPTER 1-1.pdf

Show all 18 references
  1. [4]

    Oil & water? diffusion of ai within and across scientific fields,

    N. Kolt, M. Dell, M. Feldman, and S. Mullainathan, “Oil & water? diffusion of ai within and across scientific fields,” https://arxiv.org/abs/ 2405.15828, 2024, accessed: 2024-05-16

  2. [5]

    Cartaxo, G

    B. Cartaxo, G. Pinto, and S. Soares, Rapid Reviews in Software Engineering. Cham: Springer International Publishing, 2020, pp. 357–

  3. [6]

    The role of rapid reviews in supporting decision-making in software engineering practice,

    B. , G. Pinto, and S. Soares, “The role of rapid reviews in supporting decision-making in software engineering practice,” in Proceedings of the 22nd International Conference on Evaluation and Assessment in Software Engineering 2018 , ser. EASE ’18. New York, NY , USA: Associat...

  4. [7]

    Rapid reviews in software en- gineering,

    B. Cartaxo, G. Pinto, and S. Soares, “Rapid reviews in software en- gineering,” Contemporary Empirical Methods in Software Engineering , pp. 357–384, 2020

  5. [8]

    Responsible artificial intelligence (rai) in u.s. federal government : Principles, policies, and practices,

    A. Rawal, K. Johnson, C. Mitchell, M. Walton, and D. Nwankwo, “Responsible artificial intelligence (rai) in u.s. federal government : Principles, policies, and practices,” 2025. [Online]. Available: https://arxiv.org/abs/2502.03470

  6. [9]

    Recommended steps for thematic synthesis in software engineering,

    D. S. Cruzes and T. Dyba, “Recommended steps for thematic synthesis in software engineering,” in 2011 International Symposium on Empirical Software Engineering and Measurement . IEEE, 2011, pp. 275–284

  7. [12]

    Towards a privacy and security-aware framework for ethical ai: Guiding the development and assessment of ai systems,

    D. Korobenko, A. Nikiforova, and R. Sharma, “Towards a privacy and security-aware framework for ethical ai: Guiding the development and assessment of ai systems,” in Proceedings of the 25th Annual International Conference on Digital Government Research (DGO 2024), 2024

  8. [14]

    A roadmap of explainable artificial intelligence: Explain to whom, when, what and how?

    Z. Wang, C. Huang, and X. Yao, “A roadmap of explainable artificial intelligence: Explain to whom, when, what and how?” ACM Transac- tions on Autonomous and Adaptive Systems , vol. 19, no. 4, p. Article 20, 2024

  9. [15]

    A systematic literature review on ai-based recommendation systems and their ethical considerations,

    E. Masciari, A. Umair, and M. H. Ullah, “A systematic literature review on ai-based recommendation systems and their ethical considerations,” IEEE Access, 2024

  10. [384]

    Available: https://doi.org/10.1007/978-3-030-32489-6 13

    [Online]. Available: https://doi.org/10.1007/978-3-030-32489-6 13

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.