AI Vocabulary Standard
The one-paragraph answer
ISO/IEC 22989 is the international vocabulary standard for artificial intelligence. It does not tell you what to do. It tells you what to call things. Every other AI standard from ISO/IEC, including ISO/IEC 42001, references ISO/IEC 22989 to define its terms. Alignment happens implicitly: if you use ISO/IEC 42001, you are using ISO/IEC 22989.
Ask ten people in your organization what "AI system" means. You will get ten answers. Some will mean a large language model. Some will mean a machine-learning pipeline. Some will mean the app they use every day. Some will mean anything a vendor labeled "AI." The confusion is not academic. It shows up in policies that cover things nobody meant to include, in incident reports that miss things everyone meant to include, and in audit findings that argue for months about scope.
ISO/IEC 22989 ends that argument. It defines the terms that every other AI standard uses. AI system, AI actor, machine learning, deep learning, agent, stakeholder, risk, transparency. Adopting the vocabulary means every artifact, every policy, and every audit line uses the same words to mean the same things. The pain of scope confusion is what this standard was built to remove.
ISO/IEC 22989 is an international standard published by the joint technical committee of ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission). The full title is "Information technology, Artificial intelligence, Artificial intelligence concepts and terminology." It was published in July 2022, ahead of ISO/IEC 42001, because the community needed a shared vocabulary before the operating standard could be written.
This is not a certification target. Nobody gets audited against ISO/IEC 22989. It is a reference. When ISO/IEC 42001 uses the term "AI actor," the normative reference at the front of the standard says "as defined in ISO/IEC 22989." When ISO/IEC 23894 (risk management) talks about "AI system life cycle stages," it points at ISO/IEC 22989 for the definitions. This makes ISO/IEC 22989 the shared dictionary for the entire AI standards family.
The standard defines terms across several categories.
What an AI system is. What machine learning is (a subset of AI). What deep learning is (a subset of machine learning). What an autonomous system is. What generative AI is. What an agent is. What a foundation model is. Precise definitions that let policies and contracts refer to specific technology categories without ambiguity.
The stages an AI system passes through: inception, design and development, verification and validation, deployment, operation and monitoring, continuous validation, re-evaluation, and retirement. Governance obligations attach to specific stages, so the life cycle vocabulary matters for audit trails.
Who does what in an AI ecosystem. AI provider, AI producer, AI customer, AI subject, AI partner, AI evaluator. The definitions matter because obligations differ by role. A "deployer" in the EU AI Act corresponds to specific ISO/IEC 22989 actor categories.
Definitions of the properties that make AI trustworthy: transparency, explainability, controllability, reliability, robustness, resilience, security, privacy, fairness, safety, accountability. These are also used by NIST AI RMF (with slightly different names but similar meanings).
You do not adopt ISO/IEC 22989 directly. You adopt it by proxy when you align to ISO/IEC 42001, NIST AI RMF, or any credible governance framework that references it. But the value of adopting it consciously is disambiguation.
When your policies say "AI system," a reader knows which definition applies. When your contracts say "AI actor," a court has an accepted definition to interpret. When your risk register references "AI life cycle stages," an auditor knows what you mean. Without ISO/IEC 22989, every document becomes an argument about terminology. With it, arguments about scope end and the substantive work begins.
For SRJ engagements, ISO/IEC 22989 is the vocabulary layer underneath every artifact. The Accountability Matrix identifies roles using ISO/IEC 22989 AI actor definitions. The AI Usage Policy uses ISO/IEC 22989 to distinguish AI systems from adjacent technologies. The dossiers describe AI systems using the standard's life cycle stages. The book crosswalk in Appendix L of Volume III maps every artifact to the exact ISO/IEC 22989 terms it depends on.
The academic literature on ISO 22989 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about ISO 22989 arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, ISO 22989 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No. It is a terminology standard, not a management-system standard. Certification is available for management-system standards (like ISO/IEC 42001, ISO 9001, ISO 27001), not for vocabulary references.
Alignment to ISO/IEC 42001 automatically incorporates ISO/IEC 22989 definitions. But knowing the vocabulary consciously (rather than by accident) helps in negotiations, audits, and cross-framework mapping.
They overlap heavily and were coordinated during drafting. NIST AI RMF uses similar categories with slightly different terminology. ISO/IEC 22989 is more comprehensive on life cycle stages; NIST is more comprehensive on trustworthiness characteristics.
Vocabulary from ISO/IEC 22989 is used throughout Volume III, The AI Risk & Governance Review™, especially in chapters describing the AI system life cycle, the AI Governance Framework Crosswalk™ (Appendix L), and the Accountability Matrix chapter. The book adopts ISO/IEC 22989 definitions verbatim wherever the standard specifies one.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning ISO 22989 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including ISO/IEC 22989, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →