The governance stack
Six layers of AI governance
Most orgs fund the last one first
The layers are real. The order they get built in usually is not. Dependencies run top-down — budgets run bottom-up. That inversion is the most common failure pattern in enterprise AI governance.
- Layers
- Six
- Build first
- Inventory
- Build last
- Compliance
- Failures concentrate
- Top & bottom
Each layer assumes the one above it exists
↓ dependency·funding ↑The layer almost no one funds — and the one everything else depends on. Tools spread through SaaS features faster than any registry tracks them.
Compliance is not an input. It is an output. An audit trail only proves something if the layers above it produced something worth recording. Built first, it is a binder with nothing behind it.
Run one test this week
Ask for a complete inventory of every AI system operating in the company right now.
If no one can produce it, that is your real governance gap — everything below it is resting on a layer that does not exist yet.