# Stanford CodeX AILCCP: 37 Principles Wired to Controls, Standards, and Risks

Times of AI Desk · 2026-04-05 · Policy

[https://timesof.ai/2026/04/stanford-codex-ai-life-cycle-core-principles-governance](https://timesof.ai/2026/04/stanford-codex-ai-life-cycle-core-principles-governance)

> Eran Kahana’s Stanford CodeX post ships AILCCP — a knowledge graph of 37 principles, 48 controls, 43 standards, 10 life-cycle phases, 18 risks, 500+ links, plus Explorer at ailccp.replit.app. The trade: make ‘trustworthy’ operational and auditable across instruments that don’t interoperate (ISO 42001, NIST AI RMF, IEEE, EU AI Act).

AI governance fails less from missing slogans than from **missing maps**. AILCCP’s frame: stitch OECD/UNESCO/G7-style principles to controls, ISO/IEEE/NIST standards, life-cycle owners, and rated risks so “ethical” stops being undefined wallpaper.

**Eran Kahana** on the **Stanford CodeX** blog (April 5) detailed the **AI Life Cycle Core Principles (AILCCP)** framework: a navigable knowledge graph with **37** principles, **48** controls, **43** international standards, **10** life-cycle phases (scoping → decommissioning), **18** risks, and **500+** explicit cross-references — plus ownership, metrics, and evidence artifacts. Interactive **AILCCP Explorer**: ailccp.replit.app.

## Graph contents (author counts)

| Layer | Count / notes |
|-------|----------------|
| **Principles** | 37 — defs, objectives, questions, controls, evidence, stakeholders; 15 categories / 10 pillars |
| **Controls** | 48 — 187 control↔principle links |
| **Standards** | 43 IEEE/ISO/IEC/NIST — 215 standard↔principle links (29 principles) |
| **Life cycle** | 10 phases — owners (Product, Legal, ML Eng…), artifacts, metrics; 84 phase↔principle links |
| **Risks** | 18 — 7 Very High / 8 High / 3 Medium; 23 risk↔standard links; “enabling risks” (e.g. transparency gaps) |

Problem diagnosis: ISO/IEC 42001, NIST AI RMF, IEEE, EU AI Act **don’t interoperate** cleanly — orgs reconcile without principle→control→phase→risk maps.

## Claims vs checks

Component counts and link totals are from the **April 5 CodeX publication**. Usefulness depends on org adoption — not proven by the blog post. Explorer is a Replit app; treat as author tooling, not a standards body adoption.

## Limits

- Academic/practitioner framework — not law.
- Crosswalks can over-simplify jurisdictional conflicts.
- Maintenance burden as standards revise.

## Sources

- [Eran Kahana, Stanford CodeX: “Turning AI Governance Into Operational Infrastructure”](https://law.stanford.edu/2026/04/05/turning-ai-governance-into-operational-infrastructure) (April 5, 2026).
- [AILCCP Explorer](https://ailccp.replit.app/).
- Framework details from the April 5 publication (counts and cross-reference totals).
