Skip to content
Fabrizio Degni edited this page Aug 25, 2026 · 2 revisions

PALO Framework Wiki

Principled AI Lifecycle Orchestration

Current public baselines: PALO Web 3.1.0 (23 August 2026) and the independently versioned PALO-AI 2.7.0 developer preview (25 August 2026).

PALO is an open-source framework and toolkit for operational AI governance. It helps organizations translate principles, laws, standards, and risk signals into lifecycle decisions, controls, evidence, KPIs/KRIs, review gates, and accountable outcomes.

PALO is a governance support framework. It is not a certification body, does not provide legal advice, and does not replace organization-owned identity, security, risk, legal, audit, or assurance functions.

Choose the right PALO route

Your objective Start here What it provides
Govern the complete AI lifecycle PALO Framework Lifecycle governance, risk classification, assessment, controls, evidence, metrics, monitoring, and decommissioning
Govern delegated and agentic systems PALO-AM Agent identity, authority, autonomy, action-space, human oversight, agentic risk, and evidence methodology
Enforce and verify agent actions PALO-AI Developer-preview contracts and runtime patterns for policy enforcement, approvals, one-time capabilities, receipts, and outcome verification

The three routes are complementary: PALO is the umbrella framework, PALO-AM is its specialist agentic governance modality, and PALO-AI is a technical developer-preview implementation of selected agentic controls.

Governance lifecycle

PALO supports governance from initial purpose through retirement:

  1. Ideation and ethical screening — clarify purpose, affected people, expected value, and unacceptable uses.
  2. Assessment and planning — classify risk, assess fundamental-rights impacts, map stakeholders, and define controls.
  3. Responsible development and validation — test data, models, workflows, security, human oversight, and evidence requirements.
  4. Deployment and monitoring — approve release gates, monitor performance and risk, manage incidents, and preserve evidence.
  5. Continuous improvement and decommissioning — review changes, reassess context, retire safely, and retain accountable records.

Start here

Agentic assurance and Microsoft AGT

PALO-AI separates permission from outcome assurance. A policy engine may allow an action, while PALO independently verifies whether the approved effect actually occurred.

The PALO-maintained Microsoft Agent Governance Toolkit interoperability proposal uses Microsoft AGT ACS as an optional, replaceable pre_tool_call decision provider. PALO retains the immutable Action Claim, digest-bound approval, one-time capability, trusted execution receipt, authoritative post-state verification, Case File, and incident-hold workflow.

The adapter is a community interoperability proposal maintained by PALO. It is not maintained, certified, sponsored, or endorsed by Microsoft.

Project status

  • The static PALO website and governance tools are the supported public experience.
  • PALO 3.1 provides the current governance control-plane and semantic baseline. PALO-AI is versioned independently.
  • PALO-AI v2.7, the reference runtime, Governance Hub, MCP transports, approval flows, data-assurance contracts, and connector examples are developer previews for isolated evaluation.
  • PALO-AI v2.7 adds Action Claim 1.4, payload-minimized external context evidence, purpose-bound Data Fitness Decisions, signed Data Disclosure Contracts and Receipts, AI system and agent registry records, tenant-bound MCP operations, and continuous invalidation.
  • The capability inventory contains 40 tracked capabilities: 5 implemented, 28 prototype, 7 specified, and 0 production-ready.
  • Preview components must not be treated as production authorization services or unavoidable security boundaries.
  • Production use requires organization-owned identity, access control, key custody, tenant isolation, monitoring, resilience, retention, legal review, and independent security assurance.

Community

PALO is MIT-licensed and welcomes evidence-based contributions, documentation improvements, translations, integrations, and critical review.