Artificial Intelligence (AI) assurance: challenges, gaps, and the path forward
Abstract
The integration of Artificial Intelligence (AI)/Machine Learning (ML) into high-impact domains such as finance and autonomous systems offers significant benefits, but also introduces complex risks and regulatory challenges. These systems exhibit properties including non-determinism, data dependence, and evolving vulnerabilities that are difficult to address through largely static assurance approaches. This paper provides a critical review of AI assurance initiatives, examining established frameworks such as the NIST AI Risk Management Framework (NIST AI RMF), global guidance including the OECD and G7 AI toolkits, practitioner-facing resources, and representative research-led approaches. Rather than treating safety, fairness, robustness, privacy, explainability and accountability as separate assurance frameworks, we treat them as assurance goals that require operationalisation through five cross-cutting commitments. They are testable claims, evidence obligations, lifecycle validity, accountability and recourse, and interoperability. Using these commitments, we compare how existing initiatives translate high-level governance objectives into auditable and maintainable assurance practices. Our analysis shows that, despite growing activity, AI assurance remains fragmented and often under-specifies deployment-facing practices needed for credible assurance in real-world settings. We highlight challenges in translating regulatory intent into operational requirements and evidence, and we emphasise the need for coherent, context-sensitive, and adaptive assurance strategies. The paper concludes with reflections on emerging directions and practical considerations for policymakers, developers, and regulators seeking to advance trustworthy AI.