Enterprise AI Leadership Forum

Enterprise AI, grounded in practice

EntAIL Forum

A collaborative forum for the practical realities of building, buying, deploying and governing enterprise AI.

EntAIL brings together provider, deployer, governance, risk, technology and regulated-industry perspectives to develop practical, interoperable approaches to enterprise AI transparency and accountability.

Current EntAIL working initiative
AI
AI PassportAn extensible framework for enterprise AI identity, transparency, authority and downstream assurance.
Working demo availableExplore the provider, deployer, agent and material-change scenarios.

EntAIL focuses on the implementation gap between policy and operating reality: what enterprises need to know, declare, verify and update when AI crosses organizational boundaries.

About the Forum

EntAIL brings together industry professionals with deep expertise in AI and practical experience applying it across the enterprise.

The Forum is organized around practical enterprise use cases. It examines the information providers can supply, the assurances deployers need, the responsibilities that change across the AI supply chain, and the standards that can be reused rather than reinvented.

Convene

Bring both sides of the market together.

Providers, deployers, governance teams, risk leaders and technologists often see different parts of the same problem. EntAIL uses those differences to clarify what must be shared and who is responsible for it.

Translate

Turn broad requirements into usable operating models.

The Forum works from concrete scenarios, including third-party AI services, regulated uses, agents, model substitutions, permissions changes and downstream notification.

Connect

Build on existing standards and assurance mechanisms.

EntAIL seeks common terminology and interoperable structures that can reference provenance, identity, authorization, security, evaluation and compliance evidence without replacing the systems that produce it.

Forum focus areas

Enterprise AI leadership requires more than model selection.

EntAIL concentrates on the cross-organizational questions that become difficult once AI systems are purchased, integrated, operated and changed over time.

Governance and accountability

Who declares, operates and owns the risk?

Clarify provider, supplier, integrator, deployer, evaluator and accountable-owner roles so declarations remain attributable at every layer.

Supply chain and interoperability

What is under the hood?

Make material models, services, tools, dependencies, execution environments and upstream records visible in a structured, machine-readable way.

Assurance and boundaries

What is it intended to do—and not do?

Connect intended use, unsupported and prohibited uses, validation, known limitations, failure modes, controls and evidence state.

Agents and operational change

What may it access or act upon?

Address identity, delegated authority, tools, data permissions, human approval, revocation, monitoring and material changes that can alter risk without changing the product name.

Current EntAIL working initiative

AI Passport

The AI Passport is an extensible framework for communicating what an enterprise AI model, service, system, agent or deployment is; who stands behind each declaration; what it depends on; what it is intended and not intended to do; and what has materially changed.

Mandatory starting pointA common cover and technical envelope make each record identifiable, comparable and attributable.
Extensible Passport pagesPurpose, dependencies, validation, risk, data, deployment, oversight, agent authority and change history add the appropriate depth.
Composable supply-chain recordModel, service, system, agent and deployment Passports can reference one another without erasing who made each claim.
Change-awareMaterial substitutions, permission expansions and other changes can trigger review and downstream notification.

AI Passport framework

A small mandatory starting point. Extensible depth when it is needed.

The cover is the entry point, not the entire record. Each layer remains attributable, version-specific and machine-readable so downstream organizations can make and maintain their own deployment decisions.

01

Mandatory cover

Five seed business fields plus a technical envelope make every record identifiable and comparable.

02

Standard pages

Purpose, dependencies, validation, risk, data, deployment and authority use defined page schemas.

03

Composable roll-up

Model, service, system, agent and deployment Passports reference one another without erasing who made each claim.

04

Change-aware

Material model, supplier, data, control or authority changes can trigger review and downstream notification.

Enterprise AI Passport · illustrative

Talent Intelligence Service

Provider Passport · supplier-declared

01 · NameTalent Intelligence Service
02 · Author / developerAI Engineering Team
03 · SupplierSoftware provider
04 · VersionService 4.8.2
05 · Execution operator & environmentSupplier-operated cloud · customer-selected U.S./EU processing region

The working group is reviewing which additional facts are so fundamental that they belong on every cover rather than on a specialized page. Subject type, declarer, schema version, timestamps, upstream references, state and integrity data remain mandatory in the technical envelope.

Initial Passport page catalog

P
Purpose & Use BoundariesFunction, users, context, intended, conditional, unsupported and prohibited uses.
C
Components & DependenciesModels, tools, providers, versions and upstream Passport references.
V
ValidationTesting criteria, datasets, applicable version, results, limits and evidence state.
R
Risk & ComplianceControls, obligations, threats, mitigations and residual risk.
D
DataSources, categories, permissions, access boundaries, retention and deletion.
DP
DeploymentOperator, runtime environment, region, integrations and configuration.
H
Human OversightReview, escalation, intervention, appeals and accountable ownership.
A
Agent Identity & AuthorityPrincipal, tools, actions, data scope, approval, revocation and logging.
CH
Change HistoryVersions, substitutions, permission changes, currentness and notification.
O
Operations & MonitoringTelemetry, drift, incidents, alerts, rollback and service ownership.

Provider and deployer perspectives

The same organization can occupy several roles.

A company may publish software to customers, deploy that software internally, develop its own models and integrate upstream services. The Passport preserves the role and accountability associated with each declaration.

Software provider

What are we supplying?

The provider identifies the service, its dependencies, its intended and restricted uses, the evidence available and the changes customers need to know about.

  • References exact upstream model and service versions
  • Adds end-to-end system validation and operating boundaries
  • Notifies customers of material dependency changes
Enterprise deployer

How are we using it?

The deployer adds the specific business process, users, data, controls, oversight, jurisdiction and accountable owner associated with its own use.

  • Declares its actual deployment and intended context
  • Adds local validation, controls and human decision points
  • Reviews upstream changes against its use and obligations
ModelCreator, version, provenance, capabilities and limitations.
Service / APICommercially supplied AI capability and operating terms.
SystemModels, retrieval, controls, interfaces and workflows.
AgentIdentity, available tools, actions and authority model.
DeploymentEnterprise configuration, purpose, data and accountability.
Runtime attestationTime-limited principal, permissions, session and integrity reference.

Agent profile

Agents add authority to transparency.

A model produces outputs. An agent may select tools, retrieve data and take actions on behalf of a person or organization. The Agent Identity & Authority Page makes that delegated authority visible without replacing the underlying authorization system.

Acting principalWho or what the agent represents
Permitted toolsSystems and services it may invoke
Allowed actionsRead, draft, write, approve or execute
Data scopeRecords, tenants and categories it may access
Human approvalWhere intervention is mandatory
Revocation & loggingHow authority ends and actions are audited

AI Passport interactive working concept

See what is inside the service—and know when something underneath it changes.

The v0.3 enterprise demo can be presented as a manually advanced, spotlight-guided walkthrough or explored freely. It shows provider and deployer views, Passport pages, a supply-chain roll-up, model substitution and an agent permission expansion.

EntAIL approach to standards

Reference existing mechanisms. Do not replace them.

The AI Passport is intended to connect and present information from provenance, identity, authorization, security, model-card, system-card and assurance mechanisms. It is not a competing content-provenance standard, a universal quality score or a certification that a system is safe or compliant.

C2PA or other provenance evidence can be referenced where applicable.
Authorization policies remain enforceable in the systems designed to enforce them.
Declaration, evidence, verification and currentness remain separate trust states.

Perspectives represented

Experience from across the enterprise AI ecosystem.

EntAIL discussions and reviews have included people whose current or prior professional experience spans AI and cloud platforms, enterprise software, financial services, healthcare, identity, security and regulated industries.

AWS
Bank of America
DTI Group
Fiddler AI
H2O.ai
HID
Humana
Intel / Intel Labs
Kastle Systems
LinkedIn
Microsoft
Oracle Cloud
Quantum Secure
SCCG
ServiceNow
SoFi Technologies
Wells Fargo
Zodia Custody
Affiliation notice: Organization names identify current or prior professional affiliations represented through individual participation and feedback. Listing does not mean that an organization is a member of EntAIL, or that it has sponsored, approved, adopted or endorsed EntAIL or the AI Passport.

Current AI Passport decision agenda

What remains open for v0.3 review.

Complete the coverConfirm the five seed fields and nominate the remaining universal fields.
Assign required pagesDecide which pages are mandatory for each subject and participant role.
Define trust statesSeparate declaration, evidence, verification and currentness with controlled values.
Set change triggersDefine which substitutions, configuration changes and authority changes require notification.
Select a pilotTest model substitution, agent permission expansion or both in an authoring workflow.

EntAIL working initiative

Explore the AI Passport concept.

Use the manual presentation mode to advance one focused concept at a time, or leave presentation mode and explore the interactive enterprise demo freely. All company and system data shown inside the demo are illustrative.