GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"

iso iec 22989 generative ai amendment

ISO/IEC 22989 Generative AI Amendment: What US Organizations Need to Know

The vocabulary of artificial intelligence has never been more contested. As large language models, diffusion systems, and multimodal architectures become embedded in enterprise workflows, regulators and standards bodies are racing to establish shared definitions that hold up under legal, technical, and operational scrutiny. ISO/IEC 22989’s generative AI amendment is one of the most consequential responses to that challenge and US organizations that treat it as a background document do so at their peril.

Published under Joint Technical Committee 1, Subcommittee 42 (ISO/IEC JTC 1/SC 42), the amendment extends the existing AI concepts and terminology framework to formally address generative AI systems. For US compliance professionals, AI governance leads, and technology counsel, understanding precisely what changed and what the changes demand is the starting point for any credible governance posture.

What Is ISO/IEC 22989 and Why It Matters

ISO/IEC 22989:2022 established the foundational vocabulary for artificial intelligence: a reference document that defines terms like “AI system,” “machine learning,” “training data,” and dozens of related concepts in ways that are internationally recognized and referenced by downstream standards.

The problem is that 2022 predates the mainstream deployment of large language models. ChatGPT launched in November 2022, the same month the standard was published. Within 18 months, generative AI had moved from research curiosity to enterprise infrastructure and the terminology infrastructure hadn’t caught up.

The generative AI amendment closes that gap. It introduces formal definitions for concepts that practitioners were using inconsistently across jurisdictions, contract documents, risk assessments, and regulatory filings. A “foundation model” means one thing in a research paper, something subtly different in an EU AI Act recital, and something else again in a vendor SLA. The amendment standardizes that language at the international level.

For US organizations, the amendment matters for three concrete reasons: alignment with the NIST AI Risk Management Framework, increasing citation by sector-specific regulators, and the need for terminology that works across both US and EU AI governance frameworks.

Key Definitions Introduced by the Generative AI Amendment

The amendment does not merely append a glossary. It restructures how the standard treats AI system categories and introduces relationship mapping between new concepts. The most operationally significant additions are:

GENERATIVE AI SYSTEM An AI system capable of producing content (text, images, audio, code, or other outputs) that was not directly present in its training data, based on patterns and relationships learned during training. This definition is deliberately technology-neutral it covers large language models, diffusion models, variational autoencoders, and architectures not yet in mainstream deployment.
FOUNDATION MODEL A large-scale AI model trained on broad data that can be adapted for a wide range of downstream tasks. The amendment distinguishes foundation models from purpose-built models by their generality and adaptation potential. Critically, the definition includes fine-tuned derivatives a foundation model does not lose its classification just because it has been adapted for a specific domain.
PROMPT & PROMPT ENGINEERING These terms receive formal treatment for the first time in an ISO AI standard. A prompt is defined as an input provided to a generative AI system to elicit a specific output; prompt engineering is the practice of designing and refining prompts to influence system behavior. For US organizations deploying AI in regulated contexts, having these definitions in a recognized standard strengthens the case for treating prompt engineering as a documented, auditable process.
HALLUCINATION The generation of outputs that are factually incorrect, fabricated, or inconsistent with verifiable information, presented with apparent confidence. This definition matters enormously for risk disclosure: organizations that fail to document hallucination risks in AI system descriptions can no longer claim the concept lacks a recognized definition.
MULTIMODAL AI SYSTEM A system that processes or generates content across multiple modalities (text, image, audio, video) within a single model architecture distinguishing it from pipelines that chain separate unimodal models. This distinction has direct implications for risk assessment scope.
AI-GENERATED CONTENT (AIGC) Content produced by a generative AI system, regardless of whether it has been subsequently edited by a human. The “regardless” clause is significant: AIGC does not become human-generated content simply because a person reviewed or modified it.

How the Amendment Changes Risk Assessment Requirements

The definitional work is not academic. Once terms like “hallucination” and “foundation model” carry ISO-recognized meanings, they create anchors for risk assessment frameworks, audit checklists, and contractual representations.

Under the NIST AI RMF’s GOVERN function, organizations are expected to identify and document AI risks at the system level. The amendment’s definitions create a more precise taxonomy for that documentation. A risk register that previously noted “model accuracy limitations” can now reference “hallucination risk” using internationally recognized terminology improving both internal audit quality and external communication with regulators.

The foundation model definition has particular implications for supply chain risk. Many US organizations deploying generative AI are not training foundation models themselves they are accessing them through APIs (OpenAI, Anthropic, Google, Cohere) or deploying fine-tuned versions. Under 22989’s framework, the foundation model and the fine-tuned derivative are separate entities with separate risk profiles.

Risk AreaPre-Amendment TerminologyPost-Amendment Standard TermGovernance Implication
Output accuracy“Model limitations,” “accuracy issues”HallucinationMust be documented and disclosed in risk registers
Model procurement“Base model,” “pre-trained model”Foundation modelRequires separate risk assessment from fine-tuned derivative
Content attribution“AI output,” “generated text”AI-generated content (AIGC)Human review does not change content classification
Input management“Query,” “instruction,” “input”PromptPrompt engineering becomes an auditable, documented process
System scope“AI tool,” “AI platform”Generative AI systemTriggers specific governance requirements under 42001

The Amendment’s Relationship to ISO/IEC 42001

ISO/IEC 42001:2023 the AI management system standard is the framework most US organizations are currently implementing or evaluating. Understanding how 22989’s amendment connects to 42001 is essential for anyone building an integrated AI governance program.

42001 explicitly references 22989 as its terminological foundation. Every defined term used in 42001 traces back to 22989. The generative AI amendment therefore updates the vocabulary layer that 42001 sits on top of. In practical terms:

  1. Review AI system descriptions against 22989’s updated definitions. A system previously classified as a “decision support tool” may require reclassification as a “generative AI system” depending on its architecture.
  2. Update internal audit criteria to verify that AI system registers use terminology consistent with the amended 22989, not idiosyncratic internal definitions.
  3. Confirm certifying body alignment third-party certification bodies are expected to update their 42001 audit criteria to reflect the amendment. Organizations seeking or renewing certification should verify their certifying body’s position.

GAICC’s ISO/IEC 42001 Lead Implementer training program has already integrated 22989’s updated terminology into its curriculum, ensuring that certified practitioners can apply current definitions across both standards.

What US Compliance Teams Must Do Now

Knowing the amendment exists is different from acting on it. US organizations should treat the following as a structured response plan.

Conduct a terminology audit. Review AI governance documents: AI system registers, risk assessments, board-level AI policies, vendor contracts for terminology inconsistent with 22989 or that uses lay terms where standardized definitions now exist. Hallucination disclosures are a priority area.

Update AI system classification. If your organization uses a system that generates text, images, code, or other content including systems accessed via API verify that classification reflects the amendment’s generative AI system definition. API-accessed foundation models are a common gap.

Revisit vendor contracts. AI vendor agreements that predate the amendment may use inconsistent terminology. For agreements covering foundation model access, fine-tuning services, or AI-generated content, consider updating contract language to reference ISO/IEC 22989 definitions.

Align training programs. Staff responsible for AI governance, procurement, legal review, and risk management need terminology fluency not deep technical training, but enough to prevent costly miscommunication in cross-functional conversations about AI risk.

Track regulatory adoption. The FTC, SEC, and sector-specific regulators have shown increasing willingness to reference international standards in AI-related guidance. Monitor whether regulatory publications begin citing 22989 definitions.

The Broader Standardization Landscape in 2026

ISO/IEC 22989’s generative AI amendment does not exist in isolation. JTC 1/SC 42 is simultaneously developing and revising multiple AI standards that interact with 22989:

ISO/IEC 23894 (AI risk management guidance) is being revised to incorporate generative AI-specific risk scenarios including prompt injection attacks, training data memorization, and the particular challenges of evaluating foundation model outputs.

ISO/IEC 42006 (requirements for AI certification bodies) will reference 22989 definitions when specifying what AI systems certification programs must assess directly affecting how GAICC and other certification bodies design their programs.

The IEEE is developing complementary standards on AI transparency and explainability that deliberately align with ISO/IEC terminology, reducing the risk of conflicting vocabulary across standards bodies. For US organizations, 22989 is the hub around which AI standards interoperability is being built.

Common Misconceptions About the Amendment

Several patterns of misunderstanding are already circulating among US practitioners.

“This only applies to AI developers.” The amendment’s definitions apply to any organization that deploys, manages, or is accountable for AI systems including organizations accessing foundation models via API. Deployers carry governance obligations requiring the same terminological precision as developers.

“Our existing risk framework already covers this.” Frameworks like SOC 2, ISO 27001, and legacy IT risk standards address control environments but do not provide AI-specific definitions. A SOC 2 audit will not validate whether an organization’s hallucination risk disclosure meets the 22989 standard.

“The amendment is not yet enforceable in the US.” Enforceability is the wrong frame. The amendment creates a recognized standard against which practices can be measured by internal auditors, external certifiers, regulatory examiners, and plaintiffs’ attorneys. “Not yet mandatory” and “irrelevant” are not the same thing.

“We don’t use generative AI.” Organizations should verify this claim carefully. Generative AI components appear in customer service platforms, document processing tools, code development environments, marketing automation, and HR screening systems. API-mediated access is still access.

Frequently Asked Questions

What is ISO/IEC 22989 and what does the generative AI amendment change?

ISO/IEC 22989 is the international standard establishing AI concepts and terminology. The generative AI amendment extends it to formally define terms including generative AI system, foundation model, hallucination, prompt, and AI-generated content. For US organizations, these definitions create a recognized vocabulary baseline for governance, contracts, and regulatory communication.

Does the amendment apply to organizations accessing generative AI through APIs?

Yes. The amendment’s definitions apply based on how a system functions and what it produces, not based on whether the organization trained the underlying model. Companies accessing foundation models through OpenAI, Anthropic, Google, or similar providers are deploying generative AI systems as defined by the standard and carry corresponding governance obligations.

How does the amendment relate to the NIST AI Risk Management Framework?

The NIST AI RMF is a voluntary US framework for managing AI risks; it does not define AI terminology at the level of detail that 22989 does. The two are complementary: NIST AI RMF provides the governance structure, and 22989 provides the vocabulary. Organizations using the RMF benefit from aligning their AI system descriptions and risk documentation with 22989 definitions.

What is the formal definition of “hallucination” under the amendment?

The amendment defines AI hallucination as the generation of outputs that are factually incorrect, fabricated, or inconsistent with verifiable information, presented with apparent confidence. This definition applies regardless of the cause and regardless of whether a human reviews the output before use.

Does the amendment affect ISO/IEC 42001 certification programs?

It does, because 42001 uses 22989 as its terminological foundation. Organizations implementing 42001 should review AI system classifications and governance documentation for consistency with the updated definitions. Certification bodies are expected to align their audit criteria accordingly.

What is the difference between a “foundation model” and a “fine-tuned model”?

The amendment defines a foundation model as a large-scale model trained on broad data and adaptable to many tasks. A fine-tuned model is a derivative adapted for a specific domain or task. Under 22989’s framework, both require separate governance documentation the fine-tuned model does not replace the foundation model in the risk register.

How should legal teams use 22989 definitions in AI vendor contracts?

Legal teams should use 22989 as a reference framework when defining AI-specific terms in vendor agreements, particularly for provisions covering accuracy obligations, disclosure requirements, and liability allocation related to AI-generated content. Using standardized definitions reduces interpretive disputes and creates clearer accountability chains.

When does the amendment come into effect for US organizations?

ISO amendments take effect upon publication and are immediately relevant as the current version of the standard. There is no grace period in the traditional regulatory sense. Practical adoption timelines depend on whether sector-specific regulators formally reference the amendment and how quickly certification programs update their criteria.

Build Your AI Governance Credentials GAICC’s ISO/IEC 42001 Lead Implementer certification trains practitioners to apply 22989’s updated terminology across governance, risk assessment, and management system implementation.

Conclusion

ISO/IEC 22989’s generative AI amendment gives the AI governance field something it has needed since large language models moved from research labs to production systems: a shared, internationally recognized vocabulary that gives compliance professionals, legal teams, and regulators a common language.

The immediate work for US organizations is concrete. Audit your AI system terminology. Classify foundation model access accurately. Update vendor contracts where definitions have become ambiguous. The organizations that treat this as a mere vocabulary update will find themselves revisiting their documentation far more expensively when sector regulators begin citing 22989 directly and that shift is already underway.

The GAICC ISO/IEC 42001 Lead Implementer certification program incorporates 22989’s updated terminology and trains practitioners to apply it across AI governance, risk assessment, and management system implementation. If your organization is building the governance infrastructure to match the pace of generative AI deployment, certification is the most efficient path to doing it right.

Share it :
About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

Start Your ISO/IEC 42001 Lead Implementer Training Today

4.8 / 5.0 Rating

Recent Post