Whereas Policy defines what rules should be applied under particular conditions, Authority serves to connect those Policies to their legitimate basis. In I2EA, the “Policy Repository” provides the mechanism for storing and managing these diverse Policies.

In real-world governance, an AI system or other system is rarely subject to only one type of Policy. Multiple domains may apply simultaneously, including Privacy Policies concerning personal data, minors, medical information, and confidential information; Safety Policies concerning violence, illegal content, human review, and emergency escalation; and Copyright Policies concerning attribution, AI training, and redistribution.

Organizations may also maintain their own rules, such as Internal Use Only, Trade Secret, Retention Policy, and Access Control. Different Policies may apply across jurisdictions such as Japan, the EU, and the United States, while additional rules may arise from specific organizations, industries, or contractual relationships.

The Policy Repository provides the infrastructure for storing, managing, and updating these Policies in machine-readable form. Rather than serving merely as a list of rules, it retains information about the Authority from which each Policy originates, where it applies, when it becomes effective, and which Version is in force, thereby maintaining the Policies in a form that AI systems and other systems can reference.

Authority in this context does not refer to a single central institution. States, regulatory authorities, local governments, industry bodies, professional institutions, companies and other organizations, and contracting parties may all constitute Authorities that establish Policies within their respective scopes of authority.

Accordingly, the purpose of the Policy Repository is not to unify rules around the world under a single set of values. Rather, it is to manage Policies established by different Authorities in machine-readable form while preserving their respective scopes of application and underlying bases.

Policies also change over time. Amendments to laws and regulations, revisions to internal organizational rules, and changes to contractual terms may alter the applicable Policy. Rather than simply overwriting previous Policies, it is therefore important to preserve the ability to determine which Policy was in force at a particular point in time.

By distinguishing Authority from the Policy Repository, I2EA can represent not only that a rule exists, but also who has the authority to establish that rule and the scope within which it is valid. This provides the foundation for applying legitimate Policies to subsequent Decisions.