Afghan Language AI Governance — ISO/IEC 42001 Evidence in Pashto and Dari

A management system governs only what its evidence can see — and your AI evidence stops at English.

Ariana Nexus builds Afghan language AI governance from Washington, D.C. — ISO/IEC 42001 and NIST AI RMF programs for organizations whose AI reaches Pashto and Dari speakers, carrying evaluation evidence across 24 Afghan languages rather than English-only proxies. Advisory alongside your certifier and counsel, never in place of them.

Convened by Ariana Nexus · AI & Data Systems Practice · Washington, D.C.
What your evidence measures — and what it leaves unseen.
Measured (English)Unmeasured surfaceLatent risk
79%of unsafe prompts bypassed GPT-4's safety filters once translated into low-resource languages — versus under 1% in English.
Yong, Menghini and Bach, 2023
In this briefing
01Why English-only AI evidence fails Afghan users02The mandate register — what governs you, and when03The readiness ladder — where your program sits04Afghan patients: where AI governance meets the clinic
Built for your mandate
Healthcare compliance & privacy officers
Section 1557 language access, HTI-1 predictive-model transparency, and AI bias evaluation in Pashto and Dari — the languages Afghan patients actually speak.
General counsel & risk
EU AI Act low-resource language compliance, enforcement precedent, and a register that holds up under discovery.
Chief AI & data officers
ISO/IEC 42001 audit readiness — with the Afghan-language coverage your evaluations never measured.
Boards & audit committees
Assurance the program holds up — to the auditor and to reality.
THE PROBLEM

The certificate is real. So is the gap behind it.

AI governance programs are built to satisfy a framework — a policy set, a risk register, model cards, an audit trail. What populates them is the problem. The register lists the risks the organization already knew to look for, and the evidence behind it comes from the evaluations it already knew how to run. Both stop at English. How the same model behaves in Pashto or Dari appears nowhere in the record.

The frameworks themselves concede the limit. ISO/IEC 42001 certifies that an organization manages AI responsibly; it is the de facto governance standard, but it is not a harmonized standard under the EU AI Act and does not, on its own, make a system compliant. The NIST AI Risk Management Framework is voluntary, yet referenced across federal agencies and demanded by enterprise procurement. The obligation is real and rising — and it is satisfied by evidence, which is exactly where most programs are thin.

So a governance program can earn the certificate and still be blind. Conformance measures whether you followed the framework; coverage measures whether you can actually see your risk. They are not the same thing — and for an organization whose AI reaches Afghan users, the distance between them is all 24 Afghan languages the program never tested.

Ariana Nexus closes that distance: an audit-ready management system aligned to ISO/IEC 42001 and the NIST AI RMF, a Governance Coverage Map that makes the Afghan-language blind spots visible, and Pashto and Dari validation evidence that puts real risk in the register.

ISO/IEC 42001

the de facto AI-governance standard — and still not a coverage guarantee.

Coverage ≠ Conformance

a clean certificate proves you followed the framework, not that you can see your risk.

The Governance Coverage Map

Ariana Nexus's conformance-versus-coverage diagnostic.

DEFINITION

What is Afghan language AI governance?

Afghan language AI governance is advisory and audit-readiness work that makes an AI management system account for how a model behaves in Pashto, Dari, and the rest of the 24 Afghan languages — aligned to ISO/IEC 42001, ISO/IEC 23894, and the NIST AI Risk Management Framework, and ready for EU AI Act obligations, with validation evidence behind every control. Ariana Nexus is a Washington, D.C.–area firm providing Afghan language services and cultural intelligence — interpretation, translation, cultural training, compliance support, and AI data — across 24 Afghan languages. Ariana Nexus advises and prepares organizations for certification alongside accredited bodies and counsel; it does not issue certifications or legal opinions.

A governance program governs only what its evidence can see. Conformance proves you followed the framework; coverage proves you can see your risk — and a program fed by English-only evaluation is conformant on paper and blind to every Pashto and Dari speaker it serves. Audit-ready is not the same as risk-complete.

Conformance is not coverage.

THE OPERATING MODEL

One practice. Three coordinated capabilities.

Three institutional capabilities working as one: governance that covers the risk in Afghan languages — and passes the audit.

HIC · Human Intelligence Collective

Lived-expertise practitioners across all 24 Afghan languages; the cultural gatekeepers who keep every engagement anchored in ground truth, never extractive.

Afghan practitioners whose in-language and cultural judgment makes an Afghan language AI risk assessment real — the human evidence behind impact assessments and controls.

PROTOCOL · THE FIVE-GATE VALIDATION PROTOCOL

ADF · AI Data Factory

Governed Afghan-language data infrastructure, evaluation benchmarks, and institutional-grade training assets meeting auditable standards.

The validation and benchmark evidence — Sovereign Speech Index results, Cultural Hallucination Audit findings, red-team records — that populates the risk register, model cards, and audit trail.

PROTOCOL · THE ADF PIPELINE

CCB · Cultural Compliance Bureau

An audit-grade review regime translating cultural intelligence into compliance-ready practice — the governance layer threading through every engagement.

Governance methodology and audit-readiness review; the mapping to ISO/IEC 42001, ISO/IEC 23894, and the NIST AI RMF; independence and assurance; the CCB Sign-Off Mark on governance artifacts.

PROTOCOL · THE CCB SIGN-OFF MARK
THE PATH

How Ariana Nexus closes the gap: the Governance Coverage Map

Integrated four-phase system. Three institutional capabilities. Five validation gates. The Governance Coverage Map separates conformance from coverage and closes the gap; the Five-Gate Validation Protocol governs the evidence and artifacts that make the program audit-ready.

COVERAGE — YOUR ACTUAL RISK SURFACECONFORMANCE — WHAT THE FRAMEWORK CHECKSTHE GAP — THE LANGUAGES & CULTURESYOUR PROGRAM NEVER TESTED
COVERAGE — YOUR ACTUAL RISK SURFACE
CONFORMANCE — WHAT THE FRAMEWORK CHECKS
THE GAP — THE LANGUAGES & CULTURES YOUR PROGRAM NEVER TESTED

The Five Gates

The Five-Gate Validation Protocol — every gate cleared with evidence in the record, not assumed.

1
Linguistic Accuracy

the program accounts for linguistic-accuracy risk in Pashto, Dari, and all 24 Afghan languages, with evaluation evidence in the record, not assumed.

2
Cultural Validity

the program accounts for cultural and religious risk, with Cultural Hallucination Audit evidence incorporated; cleared by the CCB Sign-Off Mark.

3
Standards Conformance

ISO/IEC 42001 (AI management system), ISO/IEC 23894 (AI risk management), ISO 31000, and the NIST AI Risk Management Framework, mapped and documented; EU AI Act obligations addressed where applicable.

4
Population Risk

the program addresses fairness and harm risk for the Afghan communities the deployment actually reaches — not only English-language users.

5
Institutional Sign-Off

policies, risk register, impact assessments, model cards, monitoring logs, and evaluation records documented, traceable, and ready for accredited assessment.

What governs you — and when it bites.

The instruments a Chief AI Officer, a certification auditor, and a compliance lead answer to — with the status as it actually stands in June 2026, not as the headlines simplify it.

Instrument
Body
Status
Effective
EU AI Act — phased application
EU
In force
Prohibitions Feb 2025 · GPAI + governance Aug 2025
EU AI Act — high-risk obligations (Annex III)
EU
Applies Aug 2026
Operative 2 Aug 2026 · deferral to Dec 2027 proposed, not adopted
Digital Omnibus — AI Act simplification
EU
Proposed
Provisional agreement May 2026 · plenary vote expected June 2026
ISO/IEC 42001 — AI management system
ISO/IEC
In force
Certifiable · ANAB-accredited · published 2023
ISO/IEC 23894 — AI risk management
ISO/IEC
In force
Applies ISO 31000 to AI · published 2023
NIST AI RMF + Generative AI Profile
US · NIST
Voluntary
RMF 1.0 (2023) + AI-600-1 (2024) · current
ONC HTI-1 — predictive decision-support transparency
US · HHS
In force
Compliance from 1 Jan 2025 · source attributes / FAVES
Joint Commission + CHAI — Responsible Use of AI
US
Voluntary
Guidance published 17 Sep 2025 · certification pathway to follow
State AI laws — Texas TRAIGA · Colorado AI Act
US
TX live · CO delayed
TX effective 1 Jan 2026 · CO delayed to 1 Jan 2027

Status verified against primary EU, ISO, NIST, and U.S. federal and state sources, June 2026. The EU “Digital Omnibus” would defer the high-risk obligations to December 2027 — but it is not yet adopted, so 2 August 2026 remains the operative date.Ariana Nexus builds to the law in force and tracks the law in motion.

Five levels of governance maturity. Most programs stall at two.

L1
Policy on paper
An AI policy exists; governance is aspirational. No inventory, no evidence, no named owner.
L2
ConformantMost programs sit here
Mapped to a framework and audit-ready on paper. The evidence behind it stops at English; coverage is unmeasured.
L3
Evidenced
A risk register fed by real validation — model cards, evaluations, monitoring logs. The record is defensible.
L4
Covered
Evidence spans Pashto, Dari, and the other Afghan languages the deployment actually reaches. The blind spot is measured, not assumed.
L5
Audit-ready and risk-complete
Coverage-complete governance, continuously stewarded — it holds up to the auditor and to reality. This is where Ariana Nexus builds.
WHAT PARTNERSHIP LOOKS LIKE

Your governance, built to cover and to certify.

From foundations to continuous stewardship.

1/4
Foundations

Scoped, assessed, architected. The AI portfolio, the obligations, and current maturity and coverage gaps mapped.

2/4
Activation

Built to standard. The management system, risk framework, controls, and documentation designed; blind spots closed via the Coverage Map.

3/4
Operating Rhythm

The active state. The program operating; evidence flowing into the register and audit trail; the committee running.

4/4
Continuous Stewardship

Across the lifecycle. Audit and certification readiness maintained; the program monitored and continually improved.

The receivables

An audit-ready AI management system aligned to ISO/IEC 42001. Policies, controls, risk register, and documentation a certifier can assess.

An Afghan-language Governance Coverage Map. Where your program is conformant, and where it is blind — multilingual and cultural risk made visible.

ISO/IEC 23894 and NIST AI RMF multilingual risk management, operationalized. Risk identified, assessed, and managed across the lifecycle.

EU AI Act readiness, where applicable. Obligations mapped, the 42001 foundation laid, EU-specific gaps named — without overpromising that a certificate equals compliance.

Model cards, impact assessments, and risk records that carry Pashto and Dari evidence. Governance fed by validation, not assumption.

Certification and audit preparation. Readiness for accredited assessment — alongside your certifier and counsel.

Governance training and an operating cadence. The committee, the reviews, the lifecycle.

The regulation differs by border. The governance gap is the same everywhere.

ISO/IEC 42001 is international, the EU AI Act binds anyone serving the EU market, the NIST AI Risk Management Framework anchors the United States, and national AI strategies are multiplying. The obligations differ by jurisdiction; the coverage gap — governance built on English-only evidence — does not. Ariana Nexus builds audit-ready, coverage-complete AI governance worldwide.

United States
NIST AI Risk Management Framework · federal procurement · evolving U.S. state AI laws
United Kingdom
Sector-led AI assurance · ISO/IEC 42001 adoption
Germany
EU AI Act · ISO/IEC 42001
France
EU AI Act · ISO/IEC 42001
Italy
EU AI Act · ISO/IEC 42001
United Arab Emirates
National AI strategy · large Afghan diaspora
Qatar
National AI / digital-government programs · Afghan diaspora
Saudi Arabia
National AI authority frameworks · Afghan diaspora
Türkiye
Significant Afghan diaspora · AI-governance development

The framework changes at the border. The blind spot travels with the program.

Where governance meets the clinic

For healthcare, coverage is not optional.

A health system’s AI touches Afghan patients who speak Pashto and Dari — and the obligations already say so. AI governance for Afghan patients is not a separate program; governance whose evidence stops at English fails the patient and the audit at the same time.

Section 1557
Meaningful language access is a civil-rights obligation. An AI triage, intake or translation tool that quietly degrades in Pashto or Dari is a Section 1557 AI language access exposure, not just a quality gap.
ONC HTI-1
Certified health IT must expose source attributes and risk-management detail for predictive decision support. The transparency rule has been in force since January 2025.
Joint Commission + CHAI
The first U.S. accreditor framework for responsible health AI now names AI governance, bias assessment, and safety-event reporting as expectations.
The bias gap
Deploying predictive AI is not the same as evaluating it for bias on your own patients. For a health system serving Afghan families, coverage is the distance between the two.

Common questions about Afghan language AI governance

Is Dari the same as Farsi for AI evaluation?

No. Afghanistan Dari and Iranian Persian differ in vocabulary, register and idiom, and a model evaluated on Farsi data will pass tests it should fail for Dari users. Substituting one for the other is the most common way a multilingual AI evaluation looks complete and is not. Ariana Nexus treats Afghanistan Dari as its own language.

Is Hazaragi a separate language that needs its own AI testing?

Hazaragi is a dialect of Dari, not a separate language, so it is never counted among the 24 Afghan languages. It still matters for testing: a model tuned to Kabuli Dari can degrade for Hazaragi speakers. Ariana Nexus records dialect coverage — Kabuli, Herati, Badakhshani, Hazaragi — inside the Dari evidence, not alongside it.

Is “Afghani” a language? And is “Pashtun” the same as Pashto?

No to both, and the confusion shows up in datasets. Afghani is Afghanistan's currency; the people and the adjective are Afghan. Pashto is the language; Pashtun is the people who speak it. Labels like “Afghani” or “Pashtun” in a training corpus or an evaluation set usually mean nobody who speaks the language checked it.

How much does an Afghan language AI governance review cost?

Ariana Nexus scopes each engagement to the AI portfolio in question — how many systems, which obligations apply, and how much evidence already exists — so there is no list price. The first step is a coverage review that establishes where the program is conformant and where it is blind. Ariana Nexus quotes the program after that scoping.

Does Ariana Nexus issue ISO/IEC 42001 certificates?

No. Ariana Nexus prepares the management system, the risk register and the evidence for accredited assessment, and works alongside the certification body and your counsel. The certificate itself is issued by an accredited certification body, and Ariana Nexus does not provide legal opinions on EU AI Act exposure.

Does an AI system deployed only in the United States still need Pashto and Dari evidence?

Often yes. Afghan families resettled across the United States use hospital portals, benefits systems and school platforms in Pashto and Dari, and Section 1557 and Title VI obligations follow the patient, not the border. An AI system serving those users is in scope whether or not it was designed for them.

Related capabilities:

Afghan-language LLM evaluation and red-teaming

Cultural hallucination audits for AI output in Afghan languages

Who leads the AI & Data Systems Practice

Hussain Ahmad, Senior Practice Leader, AI & Data Engineering, Ariana Nexus

Hussain Ahmad

Senior Practice Leader, AI & Data Engineering

Leads the practice's model validation, red-teaming, and AI governance engagements.

Maryam Safi, Principal, Healthcare Research, Ariana Nexus

Maryam Safi

Principal, Healthcare Research

Leads the Cultural Compliance Bureau — the CCB Sign-Off Mark and the multilingual-coverage methodology.

BEFORE YOU GO

Evaluating a governance program, weighing a standard, or carrying a question this page didn't answer? Considered perspectives — and pointed challenges — are welcome.

Share a perspective →

Request an Afghan-language AI Governance Coverage Review.