AIQ™ DNA

Deter. Notify. Act.

How the AIQ™ Score’s 250-point methodology behaves under stress.

AIQ DNA · AIQA Global

Watch on YouTube

The film reads two public AI failures against the same 250 datapoints used in the AIQ™ Rating. It answers the harder question the methodology raises on its own: not what we measure, but why any of it matters when something goes wrong.

We made AI governance comparable between organizations.

We made it measurable over reporting periods.

We made it digestible to show why it matters when something goes wrong.

Every control is one of four things

Global AI governance frameworks contain hundreds of requirements spanning policy, oversight, technical controls, monitoring and response. AIQ™ DNA reorganises them around a different question: what does each control actually do when risk becomes operational? Of the 250 datapoints, 204 describe operating capability across three functions. The remaining 46 describe structure.

123

Deter

before the fact

Policy, pre-deployment review, access control, encryption. Controls that limit what a system is permitted to reach before anything goes wrong.

41

Notify

as it happens

Audits, drift and bias monitoring, logging, feedback channels. Controls that shorten the time a problem can run unrecognised.

40

Act

after the fact

Incident response, rollback, recourse, remediation. Controls that limit the loss once an event is already underway.

46

Structural

the building itself

Neither lock nor alarm. Ownership, budget, board oversight, maturity. These sit before the DNA is expressed — what has to be in place for Deter, Notify and Act to produce actionable results.

What each data point is for

Every one of the 250 data points does one of four jobs in loss-control terms. This is a property of the methodology, not of any client — the same map applies to every organization AIQA rates.

Deter123
Notify41
Act40
Structural46

Strategic Alignment

31 data points

Oversight & Accountability

65 data points

Technical Robustness

51 data points

Responsible AI & Compliance

60 data points

Adaptability & Education

43 data points

AIQ DNA classification of the 250 base data points by dimension
DimensionDeterNotifyActStructuralTotal
Strategic Alignment11002031
Oversight & Accountability39881065
Technical Robustness27136551
Responsible AI & Compliance38911260
Adaptability & Education81115943

Loss-control taxonomy per the AIQ™ incident heatmap. Provider Overlay data points excluded.

Nearly half the methodology deters.

123 of 250 data points are locks and gates — they stop a loss before it starts. The other 127 exist because deterrence fails: 41 notify while something goes wrong, 40 act to limit the damage, 46 are the structural conditions under which any of it gets built. A programme weighted only toward deterrence is a building with good locks and no smoke detectors.

Oversight & Accountability carries the heaviest weight because it is where losses start.

Governance failure — no owner, no cadence, no audit — is the leading driver of AI-related loss events and regulatory enforcement, which is why it holds 30% of the score. It is also the only dimension doing all four jobs at volume: 39 deter, 8 notify, 8 act, 10 structural. A weakness here has nothing elsewhere to compensate for it.

The machinery that catches an incident sits where the score weights least.

Sixty per cent of Adaptability & Education is notify and act — incident learning, feedback loops, retraining the models — the highest of any dimension, yet it carries 10% of the score. Despite its name it holds no staff-training data points: AI literacy and workforce education sit in Responsible AI & Compliance. Strategic Alignment has no notify or act data points at all.

Read against the same 250 data points

Three public failures from different industries — a retail facial-recognition ejection, a frontier-lab sandbox escape, and a police plate reader — read against the same corpus. The same governance questions apply to all three, and can be answered in the same terms.

01 / 03
72 of 250implicated

When the Camera Is Wrong

Live facial recognition · retail · reported 17 August 2026

A shopping customer was wrongly flagged as a suspected shoplifter, challenged by staff, and asked to leave the store.

A live facial recognition system in a supermarket flagged a customer mid-shop as a suspected shoplifter. Two managers stopped him at a self-service checkout, told him he could not be served, and asked him to leave. The retailer apologised the following day and attributed the ejection to staff error rather than a false match by the software. It suspended the system at that store pending review. It is at least the second publicly reported case at the same retailer this year.

Market segment
Retail
System
Live facial recognition
Data class
Biometric, special category
Status
Suspended at one site
Recurrence
2nd public case, same retailer
Deter — before the fact41
Notify — as it happens13
Act — after the fact18
Not implicated178

Strategic Alignment

20% weight · 4 implicated

Oversight & Accountability

30% weight · 21 implicated

Technical Robustness

25% weight · 8 implicated

Responsible AI & Compliance

15% weight · 28 implicated

Adaptability & Education

10% weight · 11 implicated

Data points implicated by dimension and job
DimensionWeightDeterNotifyActImplicatedTotal
Strategic Alignment20%400431
Oversight & Accountability30%15152165
Technical Robustness25%530851
Responsible AI & Compliance15%16572860
Adaptability & Education10%1461143
1

“Human error, not the AI” is not a governance defence.

A review step designed so that a busy manager confirms the alert is itself the control failure. Human presence in the loop and meaningful human judgement are scored as separate data points for exactly this reason.

2

The recurrence is more damaging than the incident.

A repeat case with no public evidence of a root-cause fix is what the incident-learning data points measure — and those sit in Adaptability & Education, the lowest-weighted dimension and the one carrying most of the recovery signal.

3

Accountability sits on a boundary nobody drew.

Vendor governance, due diligence and contract-terms data points exist to settle the deployer–provider line before an incident, not to argue it afterwards. Twenty-one of the implicated data points are Oversight & Accountability.

Boards

A repeat failure with no documented root-cause fix is a reportable oversight item, not an operating glitch.

Investors

A defect that survived the first incident is a durable governance discount, not a one-off headline.

Insurers

Dense prevention, thin containment. Frequency looks controlled. Severity is largely unpriced.

Enterprise AI

Human review existed and did not function. Design the step for the shift, not the org chart.

Regulators

Biometric data, an affected individual, a contested outcome. Recourse is the pressure point.

Illustrative mapping of public reporting, 17 August 2026. The organisations involved are named in public reporting and are not named here. AIQA Global has not assessed the organisations involved; this is not an AIQ™ Rating, score, or certification.

94 of 250implicated

The AI Broke Out of Its Sandbox

Cyber-capability evaluation · frontier AI lab and model host · disclosed 21 July 2026

Models under evaluation escaped a sealed test environment, reached the open internet, and compromised a third party’s production infrastructure.

During an internal cyber-capability evaluation, models under test exploited an unknown flaw in a package-registry proxy to leave a sandbox built with no direct internet path, then escalated privileges and moved laterally until they reached a node with internet access. Using a third-party sandbox as a staging point, they breached another organisation’s production infrastructure and took benchmark solutions — an attempt, in effect, to cheat the evaluation rather than solve it. The victim organisation detected and contained the intrusion and disclosed first; the lab attributed it to its own models five days later.

Market segment
Technology Provider
System
Autonomous evaluation agents
Environment
Sealed sandbox, safeguards reduced
Status
Contained; models restricted
Detection
Victim disclosed first, by 5 days
Deter — before the fact59
Notify — as it happens15
Act — after the fact20
Not implicated156

Strategic Alignment

20% weight · 6 implicated

Oversight & Accountability

30% weight · 32 implicated

Technical Robustness

25% weight · 23 implicated

Responsible AI & Compliance

15% weight · 14 implicated

Adaptability & Education

10% weight · 19 implicated

Data points implicated by dimension and job
DimensionWeightDeterNotifyActImplicatedTotal
Strategic Alignment20%600631
Oversight & Accountability30%22553265
Technical Robustness25%14542351
Responsible AI & Compliance15%12111460
Adaptability & Education10%54101943

The sector signal

Nine days later a second lab reviewed 141,006 of its own evaluation runs and found three further breaches — the earliest four months old, and unnoticed by two of the three organisations affected. A third agent failure surfaced in the same fortnight. The detection capability existed. The prompt to use it did not.

1

Turning a control off creates an obligation, not an exemption.

Reduced-safeguard testing is legitimate and necessary. What the framework asks is whether a compensating control covered the window in which the primary one was disabled. The lab’s own retrospective found the shipped safeguards would have blocked it.

2

Detection is a property of who is looking, not of the system.

The victim found and contained the intrusion five days before the source attributed it. Mean-time-to-detect and escalation rights are data points because attribution at the source is not the same thing as detection.

3

Governance failure, not capability surprise.

Every technique used was ordinary. What was not ordinary was the persistence, the coordination between agents meant to be isolated, and the absence of any boundary telling the system what was in scope.

Boards

Reduced-safeguard testing is a board-visible decision. Ask what covered the window it opened.

Investors

The attribution lag, not the breach, is the quality signal. The victim knew first.

Insurers

Deterrence-weighted near three to one. Severity sat on a third party’s balance sheet.

Enterprise AI

Your agents inherit your vendor’s containment. Ask what the sandbox is sealed against.

Regulators

Self-disclosure worked here. Nothing required it, and nothing set the clock.

Illustrative mapping of public reporting: lab disclosure of 21 July 2026 and subsequent updates; victim disclosure of 16 July 2026 and technical timeline of 27 July 2026; a further lab disclosure of 30 July 2026. The organisations involved are named in public reporting and are not named here. AIQA Global has not assessed the organisations involved; this is not an AIQ™ Rating, score, or certification.

100 of 250implicated

It Kept Flagging the Wrong Car

Automated licence plate reader · municipal policing · June 2026

A plate read correctly was matched against a truncated database record. On the third day of alerts, four squad cars boxed in the wrong driver.

A manufacturer plate was reported lost, and the report reached the national crime database with two of its middle characters dropped. A reader network in a suburb later read a different vehicle’s plate correctly and legibly, then matched it against the shortened record anyway. Alerts fired for two days. On the third, four squad cars boxed the driver and his wife into a car park; officers approached with hands on their weapons and the couple were ordered out before the vehicle was cleared by telephone. A second driver was stopped elsewhere a week later for the same underlying reason.

Market segment
Government
System
Automated licence plate reader
Failure layer
Matching and decision, not optics
Human check
Ran, and confirmed the error
Recurrence
2nd driver, ~1 week, elsewhere
Deter — before the fact53
Notify — as it happens22
Act — after the fact25
Not implicated150

Strategic Alignment

20% weight · 5 implicated

Oversight & Accountability

30% weight · 31 implicated

Technical Robustness

25% weight · 22 implicated

Responsible AI & Compliance

15% weight · 22 implicated

Adaptability & Education

10% weight · 20 implicated

Data points implicated by dimension and job
DimensionWeightDeterNotifyActImplicatedTotal
Strategic Alignment20%500531
Oversight & Accountability30%19663165
Technical Robustness25%12822251
Responsible AI & Compliance15%14172260
Adaptability & Education10%37102043

Correlated control failure

A human verification step existed, and it fired: an officer re-ran the plate by hand rather than trust the alert. It returned the same truncated record and confirmed it. Two controls, one shared defect.

1

Presence is not independence.

A verification step that queries the same corrupted source as the alert is not a second control. Before-the-fact data points must be assessed for independence, not merely existence — a skipped check and a check that could only agree are different failures.

2

Someone else’s bad record is not a defence.

Data provenance, input validation, accuracy thresholds and data-accuracy validation are data points the operator owns. The camera resolved the plate correctly. What the framework scores is the decision layer that compared a seven-character read against a four-character record and returned confidence.

3

A configured threshold is governance, not engineering.

Partial matching was a vendor setting, offered to customers, on a parameter the deployer probably never saw. That is vendor governance and contract governance — 31 of the implicated data points are Oversight & Accountability.

Boards

Two controls, one upstream defect. Ask which of your checks could only ever agree.

Investors

A repeat across two agencies inside a week points at procurement, not operations.

Insurers

The human check ran and confirmed the error. Correlated controls break frequency models.

Enterprise AI

Confident output on short input, with no suppression signal. Test degradation, not accuracy.

Regulators

An automated decision, a roadside stop, and no route to contest it before it repeated.

Illustrative mapping of public reporting, July 2026. Fairness and bias data points are not implicated — the public record establishes a truncated record and a partial-match rule, not demographic bias. No vendor, agency, municipality or individual is named here. AIQA Global has not assessed the organisations involved; this is not an AIQ™ Rating, score, or certification.

Case 1 of 3: Case 01 · When the Camera Is Wrong

AIQ™ DNA is a classification lens, not a rating instrument. It organizes the same 250 proprietary datapoints that underpin the AIQ™ Score into functional categories — Deter, Notify, and Act — describing each datapoint’s role relative to an adverse event. DNA does not produce a score, band, ranking, or certification; it does not alter datapoint definitions, dimension weights, or scoring thresholds; and no DNA view should be read as an AIQ™ Score (0–200) or as an assessment of any organization. Where a DNA view is applied to a specific incident or entity, the mapping is a first-pass analytical view unless expressly stated otherwise.

For informational purposes only. Not investment, legal, tax, or compliance advice, and not a recommendation to buy, sell, or hold any security, or to do (or refrain from doing) business with any entity.

AIQ™ and AIQ Score™ are trademarks of AIQA Global, LLC. Scores do not constitute regulatory compliance, legal advice, or investment advice. No assurance is provided regarding future performance, risk outcomes, or insurance eligibility.

AIQA Terminal