Skip to content
03The governance stack

Seven layers, one operating loop.

Each layer answers one question, carries its own risks and owners, and runs the same loop: set policy, gate the lifecycle, enforce at runtime, prove it with evidence. Select a layer to preview it, then go as deep as the room requires — every layer has an executive, practitioner, and technical view.

1Enterprise

You cannot govern what you have not inventoried, and you have not governed what nobody owns.

The operating model above every AI system: named accountability, an inventory of everything AI in the enterprise, risk-tiered intake, policy that maps to regulation, and the councils and escalation paths that make decisions stick. Every framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — starts here, because none of the other layers can work if nobody owns them.

Risks concentrated here
Shadow AIRegulatory non-complianceRunaway cost
The control map

The whole framework on one screen.

The seller's cheat sheet: what each layer governs, who owns it, and the flagship controls. Every row links to the full treatment.

LayerCore questionRisks concentrated hereFlagship controlsPrimary owners
1. EnterpriseWho is accountable for AI — and for which AI?Shadow AI · Regulatory non-compliance · Runaway costAI inventory / registry · Risk-tiered intake · Accountable operating modelCAIO · AI governance council · CEO
2. DataWhat is the AI allowed to know?Data leakage · IP & copyright exposure · Unauthorized access & identityClassification before connection · ACL-aware retrieval · De-identification pipelineCDO · Platform team · Security
3. ModelsWhich models do we trust — and how do we know?Hallucination & grounding failure · IP & copyright exposure · Bias & discrimination · Model supply chainApproved model catalog · Model due diligence · Evaluation gatesAI platform team · Second line (AI risk) · Product teams
4. ApplicationsDoes the system behave — and can we prove it?Data leakage · Hallucination & grounding failure · Prompt injection · Unsafe or off-brand contentGrounding & citation discipline · Prompt & config change control · Output validation & egressProduct team · Engineering · Product
5. AgentsWhat may AI do on its own — and who can stop it?Prompt injection · Agent autonomy failure · Unauthorized access & identity · Runaway costAgent identity · Least-privilege tool scopes · Human approval gatesSecurity · Platform · Business owner per agent
6. RuntimeWhat is happening right now — and would we notice?Data leakage · Prompt injection · Unsafe or off-brand content · Unauthorized access & identity · Runaway costRuntime screening floor · AI security posture management · End-to-end tracingCISO · Security operations · Platform
7. PeopleWhat are our people doing with AI today?Data leakage · Shadow AI · Hallucination & grounding failureSanctioned alternative · Shadow-AI discovery · Inline coaching & DLPCIO · Security · HR

Full control detail — mechanisms, standards hooks, and technical enforcement — lives on each layer page under the practitioner and technical views.