What this is.
Position in the architecture · None. MESA defines the altitudes and occupies none of them
Specification · Deposited. 10.5281/zenodo.22109836, CC BY 4.0.
The single grade.
Governance maturity reported as one number is not a summary. It is a concealment mechanism. An institution with a strong regulatory posture and a substrate that cannot enforce it scores respectably, and the score is the reason nobody looks at the substrate. MESA reports a profile across four altitudes instead, so the question stops being how mature the institution is and becomes which altitude is failing.
The enforcement constraint.
The sharp edge of the framework is a single claim: a policy operates at the maturity of the substrate that has to enforce it, not at the maturity of the policy. An institution may write an excellent standard and operate it at the maturity of the logging, lineage and access control underneath. The constraint is what makes the profile diagnostic rather than descriptive, because it says which altitude sets the ceiling.
On the name.
MESA stands for Maturity, Evidence, Substrate, Alignment. That is the only canonical expansion, established in the version 1.1 specification and recorded in the Defensible AI Framework Registry. The earlier expansion, Middle East Strategic Alignment, is RETIRED and is correct only when citing the earlier work; the framework is not regional and its scope was never geographic. Maturity reports. Evidence tests. Substrate bounds. Alignment is the proposition. Read in reverse, that is the order of derivation: the proposition first, then what it rests on, then what proves it, then what is published. The four letters are not the four altitudes, and conflating them is the error the retirement was meant to end.
What is published, and what is not.
The four altitudes and the five maturity levels are published here and in the book. The free Readiness Self-Assessment scores against them in twelve questions, three per layer, and returns a per-layer profile immediately without gating the result. The fifty-question instrument and its five-level rubrics are published too: specified in the book and callable over MCP without a key. What is not published is the severity model and the evidence grading applied on top of them. Self-assessment tells you roughly where you stand; an examination produces an evidence-traced record.
Which institutions, and on whose authority.
MESA is institution-shaped rather than sector-shaped. It asks how mature an institution’s AI governance is across four altitudes, and the altitudes are the same in a bank, a hospital and a ministry. What changes by sector is which authority occupies the Regulatory Floor.
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
- 2026-08-30 · entry v1.0 — First registry entry
- 2026-08-30 · entry v1.0 — Records the retirement of the expansion Middle East Strategic Alignment at specification version 1.1, and the absorption of the Governance Maturity Model
Limitations recorded in the registry
- That the four-altitude decomposition matches the way institutions actually fail. Recorded as untested in the framework specification.
- The clause-level mappings to ISO/IEC 42001 and the NIST AI Risk Management Framework are the author's readings. Neither issuing body has reviewed or endorsed them.
- No scoring dataset has been published, so no baseline exists against which a result can be positioned.
- No institution unconnected to the author has published a MESA assessment.
What would show this to be wrong. MESA is falsified if institutions that score high at the Regulatory Floor, the Strategic Compass and Operational Machinery while scoring low at the Technical Substrate are found to experience AI governance failures at the same rate as institutions scoring high at all four. That finding would refute the enforcement constraint, which is the mechanism the four-altitude decomposition exists to express, and a framework whose central mechanism does not hold does not survive by being useful.
What this does not claim.
The contribution is architectural rather than empirical. No institution unconnected to the author has been observed operating the framework, and it carries no independent evaluation.
It is a diagnostic instrument, not a certification scheme. Scoring well against it establishes nothing about compliance with any statute or supervisory expectation.
Citation.
Cite this work. MESA Framework, version 1.1. 10.5281/zenodo.22109836. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
In the practice.
- Governed production AI, the discipline this framework belongs to
- Defensible AI, the family and the register
- AI Governance and Compliance Frameworks for the Middle East, the source treatment
- Model risk, the service this framework is applied through
- AI governance in the wiring, on where governance actually lives