Seven layers, one operating loop.
Each layer answers one question, carries its own risks and owners, and runs the same loop: set policy, gate the lifecycle, enforce at runtime, prove it with evidence. Select a layer to preview it, then go as deep as the room requires — every layer has an executive, practitioner, and technical view.
You cannot govern what you have not inventoried, and you have not governed what nobody owns.
The operating model above every AI system: named accountability, an inventory of everything AI in the enterprise, risk-tiered intake, policy that maps to regulation, and the councils and escalation paths that make decisions stick. Every framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — starts here, because none of the other layers can work if nobody owns them.
The whole framework on one screen.
The seller's cheat sheet: what each layer governs, who owns it, and the flagship controls. Every row links to the full treatment.
| Layer | Core question | Risks concentrated here | Flagship controls | Primary owners |
|---|---|---|---|---|
| 1. Enterprise | Who is accountable for AI — and for which AI? | Shadow AI · Regulatory non-compliance · Runaway cost | AI inventory / registry · Risk-tiered intake · Accountable operating model | CAIO · AI governance council · CEO |
| 2. Data | What is the AI allowed to know? | Data leakage · IP & copyright exposure · Unauthorized access & identity | Classification before connection · ACL-aware retrieval · De-identification pipeline | CDO · Platform team · Security |
| 3. Models | Which models do we trust — and how do we know? | Hallucination & grounding failure · IP & copyright exposure · Bias & discrimination · Model supply chain | Approved model catalog · Model due diligence · Evaluation gates | AI platform team · Second line (AI risk) · Product teams |
| 4. Applications | Does the system behave — and can we prove it? | Data leakage · Hallucination & grounding failure · Prompt injection · Unsafe or off-brand content | Grounding & citation discipline · Prompt & config change control · Output validation & egress | Product team · Engineering · Product |
| 5. Agents | What may AI do on its own — and who can stop it? | Prompt injection · Agent autonomy failure · Unauthorized access & identity · Runaway cost | Agent identity · Least-privilege tool scopes · Human approval gates | Security · Platform · Business owner per agent |
| 6. Runtime | What is happening right now — and would we notice? | Data leakage · Prompt injection · Unsafe or off-brand content · Unauthorized access & identity · Runaway cost | Runtime screening floor · AI security posture management · End-to-end tracing | CISO · Security operations · Platform |
| 7. People | What are our people doing with AI today? | Data leakage · Shadow AI · Hallucination & grounding failure | Sanctioned alternative · Shadow-AI discovery · Inline coaching & DLP | CIO · Security · HR |
Full control detail — mechanisms, standards hooks, and technical enforcement — lives on each layer page under the practitioner and technical views.