Wiki · Concept · Last reviewed July 10, 2026

ISO/IEC 22989

ISO/IEC 22989 is the ISO/IEC International Standard that establishes artificial-intelligence concepts and terminology. Its governance value is not certification; it is disciplined language for describing what an AI system is before risk, audit, procurement, or legal claims are made.

Definition

ISO/IEC 22989:2022 is titled Information technology — Artificial intelligence — Artificial intelligence concepts and terminology. ISO lists it as Edition 1, a 60-page International Standard published in July 2022, with reference number ISO/IEC 22989:2022.

The public ISO and IEC abstracts say the standard establishes terminology for artificial intelligence, describes AI concepts, supports development of other standards, and aids communication among diverse stakeholders. ISO and IEC also say it applies to all types of organizations, including commercial enterprises, government agencies, and not-for-profit organizations.

In practice, ISO/IEC 22989 is the vocabulary layer of the AI standards stack. It helps teams decide what they mean by terms such as AI system, model, data, learning, stakeholder, lifecycle, and system property before those terms appear in inventories, contracts, management systems, risk records, impact assessments, assurance reports, or incident reports.

Snapshot

Status

As reviewed on July 10, 2026, ISO lists ISO/IEC 22989:2022 as published, with publication stage 60.60. The ISO page lists publication date 2022-07, a corrected French version dated 2025-12, Edition 1, and 60 pages. Its lifecycle record includes new-project approval on March 7, 2018, DIS ballot opening on June 11, 2021, final text received on January 11, 2022, and publication on July 19, 2022.

ISO identifies ISO/IEC JTC 1/SC 42 as the responsible technical committee and classifies the standard under ICS 35.020 and 01.040.35. The SC 42 page describes the subcommittee's scope as AI standardization and guidance for JTC 1, IEC, and ISO committees developing AI applications.

The current standards context is active. ISO's 22989 page lists amendments under development. The SC 42 catalogue identifies ISO/IEC 22989:2022/DAmd 1 as Amendment 1: Generative AI at stage 40.60, ISO/IEC 22989:2022/AWI Amd 2 at stage 20.00, and ISO/IEC AWI 22989-2, Artificial intelligence — Concepts and terminology — Part 2: Healthcare, at stage 20.00. These entries are useful current context, but should not be cited as finalized base-standard language until ISO/IEC publishes them.

In the European Union, standards also sit inside the AI Act implementation pipeline. The European Commission says standards translate legal requirements into common technical language and that CEN and CENELEC are developing harmonised standards in areas such as risk management, data governance, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. ISO/IEC 22989 can support vocabulary alignment, but it is not itself a presumption-of-conformity claim for the AI Act unless a relevant harmonised standard is referenced in the Official Journal of the European Union.

Terminology Surface

ISO/IEC 22989 matters because many AI governance disputes begin as vocabulary disputes. A policy that says "AI system," a procurement schedule that says "model," and an audit request that says "automated decision system" may point at different objects. Without a controlled vocabulary, evidence can be filed against the wrong boundary.

A terminology standard does not settle every social or legal question. It gives teams a common reference point before they write requirements, inventories, controls, supplier clauses, evaluation protocols, or incident records. In that role, it is coordination infrastructure rather than a declaration that a system is safe, fair, compliant, or ready.

The strongest use is boundary discipline. If a team treats a foundation model, a retrieval pipeline, a user interface, an authorization layer, a monitoring workflow, and a human review process as one undifferentiated "AI," the organization cannot assign controls or evidence cleanly. ISO/IEC 22989 helps establish the vocabulary; related standards and local records then have to attach that vocabulary to actual systems.

Engineering Use

For builders, ISO/IEC 22989 is most useful before the system description hardens. A project glossary should decide which terms are adopted from the standard, which local terms are aliases, and which disputed terms require a note before acceptance criteria, model cards, risk registers, audit checklists, or supplier attestations are written.

For governance teams, the standard is a translation layer among engineers, lawyers, auditors, managers, public authorities, suppliers, and affected groups. It can help keep a lifecycle process from confusing an algorithm with a deployed service, a training dataset with an operational input stream, or a model evaluation with a system assurance argument. The value is comparable records, not ceremonial citation.

For procurement and assurance, the practical question is whether definitions travel across documents. A supplier questionnaire, AI Bill of Materials, model or system card, AI System Inventory, and audit report should not use the same word for different objects without saying so.

Governance and Safety

The safety implication of ISO/IEC 22989 is indirect but real: bad terminology creates bad control boundaries. If "model" is used when the relevant object is a deployed AI system, the review may ignore prompts, retrieval stores, identity, tool access, user interface, monitoring, fallback paths, and human escalation. If "user" hides workers, operators, affected people, and administrators, oversight and redress may be assigned to the wrong group.

A governed AI program should therefore treat terminology as change-controlled infrastructure. Definitions used in policies, contracts, test plans, impact assessments, risk registers, incident reports, and public notices should have owners and review dates. When a new term enters the program, such as "AI agent," "general-purpose AI model," "automated decision system," or "synthetic content," the organization should state whether it is adopting an ISO/IEC term, a legal term, a product term, or a local operational term.

This is especially important for safety cases and incidents. A report that says "the AI failed" is too vague to repair. A useful report says whether the failure came from model behavior, data quality, retrieval, interface design, tool authorization, post-deployment drift, human workflow, procurement assumptions, or monitoring gaps. Terminology is the first layer of that repair path.

Evidence Record

An ISO/IEC 22989-informed glossary should identify the term, adopted definition, source reference, local synonym, internal owner, linked control or policy, affected documents, review date, and known ambiguity. If a term's meaning changes, the change should be visible where requirements, controls, and audit evidence depend on it.

The record should preserve unresolved disagreement. If a product group uses "AI agent," a legal team uses "automated decision system," and a security team uses "autonomous system," the glossary should not hide the mismatch. It should map the terms, identify which documents use each one, and state which definition controls for each decision context.

Boundary With Other Standards

ISO/IEC 22989 is not an AI management-system standard, risk-management framework, lifecycle-process standard, quality model, impact-assessment standard, product approval, certification, or legal safe harbor. It is the vocabulary layer that other work can depend on.

Read it beside ISO/IEC 23053 for a framework describing machine-learning-based AI systems, ISO/IEC 5338 for AI system lifecycle processes, ISO/IEC 5339 for AI application guidance, ISO/IEC 42001 for AI management systems, ISO/IEC 23894 for AI risk management, ISO/IEC 42005 for AI system impact assessment, ISO/IEC 42006 for certification-body requirements, ISO/IEC 5259 for data quality, ISO/IEC 25059 for an AI-system quality model, and ISO/IEC TR 24028 for trustworthiness topics.

Also distinguish vocabulary from law. The EU AI Act, sector rules, procurement contracts, and regulator guidance may define AI-related terms differently or more narrowly for legal purposes. A standards vocabulary can support crosswalks, but it does not override binding legal text.

Source Discipline

Use the official ISO page and IEC Webstore for the title, reference number, International Standard status, publication date, edition, page count, technical committee, ICS classifications, public abstract, and lifecycle metadata. Use the ISO/IEC JTC 1/SC 42 page and standards catalogue for committee scope, work programme context, and amendment status. Use European Commission pages for claims about AI Act harmonised-standard processes. Do not cite vendor summaries for formal status, and do not treat ISO/IEC 22989 as proof that an AI system has been evaluated or governed.

When citing draft or under-development items, preserve the stage. A draft amendment can show that a topic such as generative AI is being standardized; it should not be quoted as settled International Standard text unless ISO/IEC publishes it.

Spiralist Reading

Spiralism reads ISO/IEC 22989 as a discipline against vocabulary theater. Institutions often believe they have governed a technology once they have named it. A glossary becomes useful only when each term is tied to evidence, authority, responsibility, and review.

The stricter reading is that naming matters when it makes disagreement inspectable. A shared AI vocabulary can reduce confusion, but it can also conceal conflict if teams treat the standard term as settlement. The right question is which decisions become clearer because that language is being used.

Open Questions

Sources


Return to Wiki