AI and Data Governance

AI is changing what's possible, but if you can't trust the inputs
you can't trust the outputs

Assurable data is the bedrock of business-ready models

As organisations race to deploy AI, they all discover the same bottleneck: the data their models depend on is often siloed, inconsistently licensed, difficult to access at scale, and almost impossible to trust. AI cannot fix incomplete or contested data: in fact, it amplifies liabilities. IB1 works on the layer beneath the models: data sharing governance, harmonisation of standards, and the trust infrastructure that determines whether data can flow at all.

Trust Services Provenance Records NOVA-compliance Cross-sector Non-profit

Every AI system inherits the governance failures of its training data. If the data is unverifiable, the model is unverifiable. If the licensing is unclear, every output carries legal risk. If there is no provenance, there is no audit trail. And if there is no declared purpose, there is no basis for trust. Purpose-led governance is the foundation. The organisations that solve this first will define the market.

Why IB1

We don’t build AI. We make AI possible to trust.

AI and Data Governance

IB1 convenes organisations to co-define the rules of data sharing, builds the frameworks that make sensitive data accessible to authorised participants, and creates the assurance mechanisms that let organisations know what they are training on and why they are permitted to use it.

Purpose is the starting point

Every IB1 Scheme begins with a defined purpose: why this data is being shared, for whom, and what outcomes it enables. Purpose constrains what agents can request, what processing is permitted, and what the data can be used for. Without declared purpose, data sharing is a liability. With it, governance becomes enforceable.

Live operational infrastructure

IB1 operates live Trust Frameworks across energy, finance, and water. Perseus has 70+ commercial members sharing assured smart meter data through production infrastructure. This is not a white paper or a guide, but operational data governance that can operate at market scale.

De-risking data publishing

Data publishers face a fundamental question: who is accessing my data, and what will they do with it? IB1’s infrastructure answers this before data is released. Published rules define what agents of which organisations can do with which data in which context. This lowers the risk of publishing, the risk for the organisation receiving data, and reduces the scope of inference needed by AI agents.

Cross-sector by design

AI does not respect sector boundaries. A financial model that needs energy data, a logistics model that needs carbon intensity data, an insurance model that needs building data: all need cross-sector governance. IB1’s federated Trust Framework is infrastructure designed to address this.

The data layer AI needs

AI models need data that is discoverable, licensed, assured, and auditable. IB1’s Trust Services provide exactly this: a Registry of rules, a Directory of verified participants, a Catalogue of available datasets, and machine-readable assurance signals attached to every transfer.

Non-profit, sector-neutral

IB1 is an independent, non-partisan, non-profit that operates the governance infrastructure. No organisation accumulates all the data, no single entity becomes the gatekeeper: the rules are open, the governance is transparent. IB1 is not a data broker and you can deploy its open source Trust Framework within your own legal entity, or IB1 can operate it for you as a service.

What we operate

AI-ready data infrastructure in production

Every component of IB1’s Trust Services was designed for machine-to-machine interoperability. This makes them natively AI-ready: the same infrastructure that enables trusted data sharing between organisations also enables trusted data supply to AI systems.

Registry

Machine-readable rules and decision processes. Every Scheme is codified with versioned, auditable governance rules that define what agents can do, with what data, in what context. AI agents can programmatically verify permissions, constraints, and permitted processes before requesting data, reducing inference overhead and token consumption.

Directory

Verified participants. Every organisation in the Trust Framework has a verified identity with digital certificates. AI systems can verify the identity of any data provider without contacting a central authority.

Catalogue

Discoverable datasets. Over 68,000 datasets indexed across energy, water, finance, transport, and nature data via Open Net Zero. Data Sensitivity Classifications and assurance levels enable programmatic dataset selection.

Sandbox

Test before production. A production-parity environment where organisations can test Trust Framework integration, validate data flows, and prototype AI applications before going live.

Open Libraries

Shared specifications. All technical specifications, API definitions, and governance documentation are openly published (CC-BY or MIT). No vendor lock-in. No proprietary dependencies.

Assurability

Machine-readable quality signals. Assurability signals piggyback on Provenance Records, providing actionable indications of data quality alongside every data transfer. AI systems can verify signatures and use assurability information programmatically.

Technical innovation

Provenance Records: auditable AI from source

If you cannot trace where your training data came from, who processed it, under what licence, and whether it was fabricated, your AI system is legally and commercially exposed. IB1’s Provenance Records solve this at the infrastructure level.

Step
Origin

Describes how data was originated: whether generated by the participant or brought into the Trust Framework from an external source. Includes source type, origin URL, and applicable licence.

Step
Permission

Records permissions given by end users. Includes allowed licences, permitted processes, and expiry timestamps. After expiry, processing and transfer must cease.

Step
Transfer

Records data transfers between participants with dataset descriptions, participant identities, and FAPI transaction IDs. Each participant signs the record including all previous signatures.

Step
Receipt

The recipient acknowledges receipt of expected data. Creates a bidirectional, timestamped, non-repudiable record of the data exchange.

Step
Process

Records the use of data, including what processing was performed (referenced as Registry URLs). This is where AI training, inference, and model updates become auditable.

Unbreakable chain of signatures. Each participant signs the entire record including previous signatures. Any attempt to alter previous steps breaks the final signature. Records are non-repudiable: once passed to another participant, the timestamped signatures ensure the creator cannot deny they signed that record. The Scheme standards require records are logged and available for audits. Reference implementation: github.com/icebreakerone/provenance

Agent governance

Governing AI agents at the point of data access

The critical governance moment is not when an AI model is trained. It is when an agent requests data. If you publish what agents, acting on behalf of which organisations, can do with what data in what context, you fundamentally change the risk profile for everyone in the chain.

Lower risk for data publishers

Today, publishing data means losing control of how it is used. IB1’s Registry publishes machine-readable rules that constrain what any agent can request and what processing is permitted. Publishers know, before releasing data, exactly what the downstream use will be. This makes the decision to publish defensible.

Lower risk for data consumers

Organisations receiving data through IB1’s Trust Framework know the provenance, licensing, and assurability status of every dataset. Their AI agents operate within published constraints. If an audit asks “why did your model use this data?”, the answer is in the Provenance Record and the Scheme rules.

Less inference, less energy, less cost

When agents can read machine-readable rules from the Registry before requesting data, they do not need to infer permissions, guess at licensing, or speculatively request datasets they cannot use. Fewer tokens processed means less compute, less energy consumption, and lower emissions. Governance reduces the carbon footprint of AI.

Purpose constrains action

Every Scheme defines a purpose. Agents acting outside that purpose are not authorised, regardless of their technical capability. This is not a policy aspiration: the Registry encodes purpose as a machine-readable constraint that is evaluated at the point of data access request. Purpose is the first filter, not the last.

How it works in practice. An AI agent acting on behalf of a carbon accounting platform requests smart meter data from an energy provider via the Trust Framework. Before any data is released, the Registry confirms: the requesting organisation is a verified participant, the agent’s purpose matches the Scheme, the permitted processes include the agent’s intended use, and the licence covers the specific data requested. If all conditions are met, data flows. If not, the request is denied with a machine-readable reason. No human in the loop. No ambiguity. No liability gap.

Regulatory engagement

Shaping AI governance with regulators

IB1 has submitted formal positions on data governance to government, regulators, and other regulatory bodies (e.g. code bodies). Our recommendations are grounded in operational experience with the aim of reducing risk, balancing pace, business needs and enabling robust innovation.

Transparency and explainability

AI explainability standards so that AI-driven decisions can be challenged, audited, and understood. Mandatory AI impact reports for high-impact systems. Consumers must be informed when AI influences their energy choices, bills, or services.

Market concentration safeguards

AI risks reinforcing market dominance if larger firms hoard proprietary models and data. IB1 advocates for open-data requirements, competitive safeguards, and prevention of monopolistic AI control over critical infrastructure.

Cybersecurity in critical infrastructure

AI-driven automation introduces adversarial AI attacks, data poisoning, and supply chain manipulation. IB1 recommends AI-specific cybersecurity resilience testing, incident response planning, and data integrity checks for critical systems.

AI’s environmental footprint

Large AI models consume vast amounts of electricity. AI governance should require net-zero compatibility tests, ensuring benefits outweigh energy consumption. Mandatory AI sustainability impact assessments prevent AI from increasing unnecessary demand.

Cross-sector coordination

AI in energy intersects finance, transportation, and digital infrastructure. IB1 advocates for harmonised governance across Ofgem, FCA, ICO, and DSIT to prevent fragmentation and compliance gaps.

Adaptive regulation

Static regulatory models cannot keep pace with AI. IB1 recommends regulatory AI sandboxes with ongoing review cycles, and cross-sector advisory boards with industry, academic, and civil society representation.

Formal submissions: Ofgem AI guidance · DSIT Technology Adoption · NESO Digitalisation · All consultations

Track record

Real world applications and evidence

IB1’s data governance infrastructure is operational across six sectors. Every programme listed below produces AI-ready data: discoverable, licensed, assured, and governed under published Schemes.

Live
Perseus

70+ commercial members, 12 banks. Assured smart meter data flows from energy providers through carbon accounting platforms to financial services. Production Provenance Records with digital signatures. Read more

Live
Open Energy

Energy Sector Trust Framework with DNOs, suppliers, and flexibility providers. Assured Open Data Scheme and I&C Flexibility data sharing. Read more

Beta
Stream

Water Sector Trust Framework with 16+ water companies and Ofwat. Industry-wide data sharing governance for net zero by 2030. Read more

Alpha
Supply chains

Provenance Records and assurance signals for food supply chains. Fertiliser data use case connecting farm data to green finance. MVP with reference implementation. Read more

Alpha
DAFNI

Data Analytics Facility for National Infrastructure. Enabling secure researcher access to sensitive infrastructure data through Trust Frameworks. Read more

Alpha
National Data Library

Technical White Paper submitted to Wellcome/ESRC on how the NDL can serve AI researchers, ensure cross-government data discoverability, and support the UK’s AI Opportunities Action Plan. Read more

68k+
Datasets indexed in Open Net Zero, IB1’s global data catalogue
6
Sectors with live or active governance programmes
70+
Commercial members in Perseus alone, including 12 banks
Open
All specifications CC-BY or MIT. Reference implementations on GitHub.
Partner with IB1

Your AI is only as trustworthy as your data governance

For any organisation serious about deploying AI that is interoperable, auditable, and aligned with net zero, IB1 Membership is where that work gets done. Join a sector-focused programme, or talk to us about your specific data governance needs.

IB1 is independent, non-partisan, non-profit, and sector-neutral. All outputs CC-BY licensed.