ISO/IEC 22989
ISO/IEC 22989 is the ISO/IEC International Standard that establishes artificial-intelligence concepts and terminology. Its governance value is not certification; it is disciplined language for describing what an AI system is before risk, audit, procurement, or legal claims are made.
Definition
ISO/IEC 22989:2022 is titled Information technology — Artificial intelligence — Artificial intelligence concepts and terminology. ISO lists it as Edition 1, a 60-page International Standard published in July 2022, with reference number ISO/IEC 22989:2022.
The public ISO and IEC abstracts say the standard establishes terminology for artificial intelligence, describes AI concepts, supports development of other standards, and aids communication among diverse stakeholders. ISO and IEC also say it applies to all types of organizations, including commercial enterprises, government agencies, and not-for-profit organizations.
In practice, ISO/IEC 22989 is the vocabulary layer of the AI standards stack. It helps teams decide what they mean by terms such as AI system, model, data, learning, stakeholder, lifecycle, and system property before those terms appear in inventories, contracts, management systems, risk records, impact assessments, assurance reports, or incident reports.
Snapshot
- Status: ISO/IEC 22989:2022 is a published International Standard, Edition 1, with publication stage 60.60.
- Responsible committee: ISO/IEC JTC 1/SC 42, the joint artificial-intelligence standards committee.
- Scope: terminology and concepts for artificial intelligence, usable across sectors and organization types.
- Governance role: a shared vocabulary for standards development, AI system inventories, procurement files, risk registers, model and system cards, audit trails, and policy crosswalks.
- Boundary: not a management-system standard, risk-management guide, impact-assessment guide, certification scheme, product approval, or legal safe harbor.
- Current follow-on work: SC 42 lists a generative-AI amendment, a second amendment, and a healthcare terminology part under development; those are not yet the published base text.
Status
As reviewed on July 10, 2026, ISO lists ISO/IEC 22989:2022 as published, with publication stage 60.60. The ISO page lists publication date 2022-07, a corrected French version dated 2025-12, Edition 1, and 60 pages. Its lifecycle record includes new-project approval on March 7, 2018, DIS ballot opening on June 11, 2021, final text received on January 11, 2022, and publication on July 19, 2022.
ISO identifies ISO/IEC JTC 1/SC 42 as the responsible technical committee and classifies the standard under ICS 35.020 and 01.040.35. The SC 42 page describes the subcommittee's scope as AI standardization and guidance for JTC 1, IEC, and ISO committees developing AI applications.
The current standards context is active. ISO's 22989 page lists amendments under development. The SC 42 catalogue identifies ISO/IEC 22989:2022/DAmd 1 as Amendment 1: Generative AI at stage 40.60, ISO/IEC 22989:2022/AWI Amd 2 at stage 20.00, and ISO/IEC AWI 22989-2, Artificial intelligence — Concepts and terminology — Part 2: Healthcare, at stage 20.00. These entries are useful current context, but should not be cited as finalized base-standard language until ISO/IEC publishes them.
In the European Union, standards also sit inside the AI Act implementation pipeline. The European Commission says standards translate legal requirements into common technical language and that CEN and CENELEC are developing harmonised standards in areas such as risk management, data governance, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. ISO/IEC 22989 can support vocabulary alignment, but it is not itself a presumption-of-conformity claim for the AI Act unless a relevant harmonised standard is referenced in the Official Journal of the European Union.
Terminology Surface
ISO/IEC 22989 matters because many AI governance disputes begin as vocabulary disputes. A policy that says "AI system," a procurement schedule that says "model," and an audit request that says "automated decision system" may point at different objects. Without a controlled vocabulary, evidence can be filed against the wrong boundary.
A terminology standard does not settle every social or legal question. It gives teams a common reference point before they write requirements, inventories, controls, supplier clauses, evaluation protocols, or incident records. In that role, it is coordination infrastructure rather than a declaration that a system is safe, fair, compliant, or ready.
The strongest use is boundary discipline. If a team treats a foundation model, a retrieval pipeline, a user interface, an authorization layer, a monitoring workflow, and a human review process as one undifferentiated "AI," the organization cannot assign controls or evidence cleanly. ISO/IEC 22989 helps establish the vocabulary; related standards and local records then have to attach that vocabulary to actual systems.
Engineering Use
For builders, ISO/IEC 22989 is most useful before the system description hardens. A project glossary should decide which terms are adopted from the standard, which local terms are aliases, and which disputed terms require a note before acceptance criteria, model cards, risk registers, audit checklists, or supplier attestations are written.
For governance teams, the standard is a translation layer among engineers, lawyers, auditors, managers, public authorities, suppliers, and affected groups. It can help keep a lifecycle process from confusing an algorithm with a deployed service, a training dataset with an operational input stream, or a model evaluation with a system assurance argument. The value is comparable records, not ceremonial citation.
For procurement and assurance, the practical question is whether definitions travel across documents. A supplier questionnaire, AI Bill of Materials, model or system card, AI System Inventory, and audit report should not use the same word for different objects without saying so.
Governance and Safety
The safety implication of ISO/IEC 22989 is indirect but real: bad terminology creates bad control boundaries. If "model" is used when the relevant object is a deployed AI system, the review may ignore prompts, retrieval stores, identity, tool access, user interface, monitoring, fallback paths, and human escalation. If "user" hides workers, operators, affected people, and administrators, oversight and redress may be assigned to the wrong group.
A governed AI program should therefore treat terminology as change-controlled infrastructure. Definitions used in policies, contracts, test plans, impact assessments, risk registers, incident reports, and public notices should have owners and review dates. When a new term enters the program, such as "AI agent," "general-purpose AI model," "automated decision system," or "synthetic content," the organization should state whether it is adopting an ISO/IEC term, a legal term, a product term, or a local operational term.
This is especially important for safety cases and incidents. A report that says "the AI failed" is too vague to repair. A useful report says whether the failure came from model behavior, data quality, retrieval, interface design, tool authorization, post-deployment drift, human workflow, procurement assumptions, or monitoring gaps. Terminology is the first layer of that repair path.
Evidence Record
An ISO/IEC 22989-informed glossary should identify the term, adopted definition, source reference, local synonym, internal owner, linked control or policy, affected documents, review date, and known ambiguity. If a term's meaning changes, the change should be visible where requirements, controls, and audit evidence depend on it.
- Term record: term, definition, ISO/IEC reference where applicable, local aliases, and whether the term is normative, advisory, or explanatory inside the organization.
- Scope record: which systems, products, data flows, contracts, policies, and reports use the term.
- Owner record: business owner, technical owner, legal or compliance reviewer, and change approver.
- Evidence links: affected inventory fields, procurement clauses, risk controls, impact-assessment questions, model or system card sections, audit evidence, and incident categories.
- Conflict record: local meanings that differ from ISO/IEC, legal definitions, supplier wording, or sector-specific terms.
- Review trigger: new standard, new law, product architecture change, incident, supplier change, or material update to the AI system boundary.
The record should preserve unresolved disagreement. If a product group uses "AI agent," a legal team uses "automated decision system," and a security team uses "autonomous system," the glossary should not hide the mismatch. It should map the terms, identify which documents use each one, and state which definition controls for each decision context.
Boundary With Other Standards
ISO/IEC 22989 is not an AI management-system standard, risk-management framework, lifecycle-process standard, quality model, impact-assessment standard, product approval, certification, or legal safe harbor. It is the vocabulary layer that other work can depend on.
Read it beside ISO/IEC 23053 for a framework describing machine-learning-based AI systems, ISO/IEC 5338 for AI system lifecycle processes, ISO/IEC 5339 for AI application guidance, ISO/IEC 42001 for AI management systems, ISO/IEC 23894 for AI risk management, ISO/IEC 42005 for AI system impact assessment, ISO/IEC 42006 for certification-body requirements, ISO/IEC 5259 for data quality, ISO/IEC 25059 for an AI-system quality model, and ISO/IEC TR 24028 for trustworthiness topics.
Also distinguish vocabulary from law. The EU AI Act, sector rules, procurement contracts, and regulator guidance may define AI-related terms differently or more narrowly for legal purposes. A standards vocabulary can support crosswalks, but it does not override binding legal text.
Source Discipline
Use the official ISO page and IEC Webstore for the title, reference number, International Standard status, publication date, edition, page count, technical committee, ICS classifications, public abstract, and lifecycle metadata. Use the ISO/IEC JTC 1/SC 42 page and standards catalogue for committee scope, work programme context, and amendment status. Use European Commission pages for claims about AI Act harmonised-standard processes. Do not cite vendor summaries for formal status, and do not treat ISO/IEC 22989 as proof that an AI system has been evaluated or governed.
When citing draft or under-development items, preserve the stage. A draft amendment can show that a topic such as generative AI is being standardized; it should not be quoted as settled International Standard text unless ISO/IEC publishes it.
Spiralist Reading
Spiralism reads ISO/IEC 22989 as a discipline against vocabulary theater. Institutions often believe they have governed a technology once they have named it. A glossary becomes useful only when each term is tied to evidence, authority, responsibility, and review.
The stricter reading is that naming matters when it makes disagreement inspectable. A shared AI vocabulary can reduce confusion, but it can also conceal conflict if teams treat the standard term as settlement. The right question is which decisions become clearer because that language is being used.
Open Questions
- Which AI terms should be controlled in public model inventories, procurement files, and incident reports?
- How should organizations handle local definitions that conflict with a standards vocabulary?
- Which terminology changes should trigger review of policies, controls, contracts, and audit evidence?
- How should legal definitions, ISO/IEC definitions, vendor definitions, and internal engineering terms be crosswalked without hiding disagreement?
Related Pages
- AI Governance
- AI System Inventory
- AI Bill of Materials
- Model Cards and System Cards
- AI Procurement
- AI Change Management
- AI Incident Reporting
- AI Evaluations
- AI Audits and Assurance
- ISO/IEC 23053
- ISO/IEC 5338
- ISO/IEC 5339
- ISO/IEC 42001
- ISO/IEC 42005
- ISO/IEC 42006
- ISO/IEC 23894
- ISO/IEC 5259
- ISO/IEC 25059
- ISO/IEC TR 24028
- ISO/IEC TR 24027
- ISO/IEC TR 24368
- EU AI Act
- NIST AI Risk Management Framework
Sources
- ISO, ISO/IEC 22989:2022 standard page, title, status, abstract, lifecycle, publication stage, corrected-version note, committee, ICS codes, and page count, reviewed July 10, 2026.
- ISO, ISO/IEC JTC 1/SC 42 committee page, artificial-intelligence committee scope and structure, reviewed July 10, 2026.
- ISO, Standards by ISO/IEC JTC 1/SC 42, published and under-development AI standards catalogue, reviewed July 10, 2026.
- IEC Webstore, ISO/IEC 22989:2022, publication metadata and public abstract, reviewed July 10, 2026.
- European Commission, Standardisation of the AI Act, standards and harmonised-standard context, reviewed July 10, 2026.
- European Commission, Understanding the standardisation of the AI Act, harmonised standards, presumption of conformity, and international-standard alignment, reviewed July 10, 2026.