FL Fredrik Lindstrom

AI Governance

Columns Not Layers

Seventy percent of an AI program is people. Most governance diagrams give them one box.


Columns, not layers — the practitioner's guide to AI governance that holds, and how to read the ones that don't.

By Fredrik Lindstrom · ~12 minute read · August 2026

Start with a number that isn’t mine. Boston Consulting Group’s own breakdown of an AI program: ten percent algorithm, twenty percent technology and data, seventy percent people and process. The model is the smallest piece of the work.

Now pull up an AI governance diagram and find the people in it. One tile, usually near the bottom, labeled “oversight” or “human in the loop.” The largest part of the program gets the smallest square on the page.

That is the mistake this article discusses. Human capability and governance are not layers in a stack. They are columns that run through every layer. Most published frameworks draw them as horizontal tiers or single nodes. The diagram doesn’t cause the failure. It’s the tell that it’s coming, a picture that faithfully renders a staffing decision: the human thought of as an approval step, not staffed; governance owned at the end, not throughout.

The three columns — human capability, governance, supply chain — running the full height of the four layers. A column is load-bearing on every floor.

This is not another governance stack, framework, or standard. The field has more than enough of those. It is a lens for reading the ones that already exist — a four-question test you can run on any diagram someone puts in front of you, to see what actually matters.

None of this is a knock on the standards. NIST AI RMF already calls its GOVERN function “a cross-cutting function that is infused throughout AI risk management” — the one function meant to run through all the others. The EU AI Act runs obligations along the whole value chain. ISO 42001 builds a management system meant to sit across the organization, not inside one department. The people who wrote these saw the same problem.

So the point isn’t to crown one of them. Three standards carry the weight here: NIST AI RMF, the EU AI Act, ISO 42001. Each holds part of the answer. None holds all of it. The columns pull the three into one structure you can actually run: every column with a named owner, a board cadence, and a signal you can put a number on. The standards say what good governance looks like. They stop short of staffing it. That gap, between what a standard names and what an organization builds, is what the Column Test catches.

The standards will keep moving. The EU has just amended the Act, deferring its high-risk deadlines to 2027. NIST revises its profiles. ISO updates its annexes. So this is a living document. When the regulation changes, the columns hold and you update what sits inside them.

Two failures, and a third column the diagrams skip

Open LinkedIn or X on any given week and another AI governance framework scrolls past. There are hundreds, maybe even thousands, of them by now, on LinkedIn, on X, on every Substack and consulting blog with a diagram tool. Strip them down and they arrive in four shapes. A layer cake stacked from data up to oversight. An agent-native flow with authority rings and policy gates. A radial hub-and-spoke with governance domains as spokes. A runtime model that governs machine authority at the point of action.

Different authors. Different metaphors. Two failures every one of them shares.

The first is universal. Every shape draws the human as a control: an oversight box, an approval step, an escalation node. Each one assumes a competent person standing at it. Read the language at the human node. “Meaningful human review.” “Human approval required.” “A human has to be able to say no.” Every one of those phrases quietly assumes a person who can tell when the model is wrong. Not one of the frameworks builds that person. They specify the gate and skip the staffing.

The second failure mistakes the output for the property. Every shape draws governance as a place: a compliance tier at the bottom of the stack, or a final gate before deployment. Something you arrive at, satisfy, and move past. That placement tells the reader they can build everything else first and bolt governance on at the end. Governance is not a place in the architecture. It is a property the whole architecture has to express.

There is a third column, and here the diagrams split — but the regimes do not. Supply chain is third-party model, vendor, and component provenance. The obligations exist everywhere: the EU AI Act assigns duties along the value chain and to general-purpose model providers, NIST treats third-party risk as its own requirement, ISO names it too. If you build on a foundation model you did not train, its provenance is your governance problem. What the pictures do is dissolve it. The layer cake leaves it out, most flows fold it into “data” or “application,” and only the hub-and-spoke carries it as a first-class node. Where the picture hides the supply chain, no one owns it. That is the failure, and it sizes to your exposure: a page and a named owner for a single-vendor API shop, a standing function for a multi-vendor or agentic chain.

Hundreds of posts, dozens of authors, the same four shapes, the same two omissions and the same unresolved third. That makes it a property of the field, not a critique of a diagram.

The hardest case is not a diagram at all. ISO 42001 is the standard boards certify against, and unlike the diagrams it is cross-cutting by construction — a management system that runs across the organization, with no compliance tier to knock down. It passes the governance test the four shapes fail. And it still files the human as documented competence: Clause 7.2 competence, Clause 7.3 awareness, evidence retained for the auditor. There is no named owner of the capability column, and no live signal that tells the board whether the competent-on-paper reviewer catches a failure. An organization can hold the certificate and leave the column empty. The most rigorous instrument in the field does governance right and still assumes the human it never staffs.

The people are a column, not a box

The human in these frameworks is a control. It should be a capability.

A control is a checkbox. Someone holds override authority, someone signs the approval, someone sits in the loop. A capability is the thing that makes the control work: that person can actually read the failure. Override authority held by someone who cannot tell when the model is wrong is a checkbox, not a safeguard.

The data now says the capability is what separates the winners. McKinsey’s 2025 survey put numbers on it. Only 39 percent of organizations report any enterprise-level impact on earnings from AI. The ones that do share a trait, and it is not the model. Sixty-five percent of the high performers have defined human-in-the-loop validation built into their workflows. Among everyone else, 23 percent do. This is survey data, so read it as association rather than proof. But the gap is wide, and it is a gap about people, not algorithms.

McKinsey counted the practice. BCG counted the room. In a survey published in July 2026, they asked 152 chief executives at companies with revenue of at least $500 million which functions they include in AI governance. Eighty-two percent named technology. Thirty percent named HR. In the same survey, 55 percent named people redesign as a barrier to getting value from AI, and 14 percent had clearly defined the P&L impact of all their AI initiatives.

It is a small sample, and it is chief executives describing their own organizations. It is also the only number I have found that counts who is in the room. A majority named the people problem. Fewer than a third have the people function present where it would be solved. The diagrams give people one tile. The org charts give them one seat in three.

A data scientist who does not understand how the model will consume the data, or how it moves through the wider AI ecosystem, cannot deliver data the rest of the stack can trust. A board member who cannot read a model evaluation cannot exercise oversight. Capability is not a stage you reach after model assurance. It is present at every layer, or the layer fails.

Even the regulator blinked on this. In February 2025, Article 4 of the EU AI Act put an AI-literacy duty on every organization, the one cross-cutting capability the diagrams skip. In 2026 the Digital Omnibus softened it under pressure. The duty to ensure a sufficient level of literacy became a duty to take measures to support it, with even that obligation drifting off deployers and onto the Commission and member states. The law specified the gate, then walked back the staffing. That is the failure mode this article is about, now written into the statute.

I have watched this exact movie before. For two decades, security frameworks treated people as a control to manage instead of a capability to build, right up until people became the primary attack surface. Phishing was never solved with a better firewall. It dropped when organizations started building human capability instead of assuming it. AI governance is walking into the same wall, one decade later.

There is one more shape to name, and it is not a column. The L has two arms, and they do different work. Baseline AI literacy is the horizontal one: it sits under the layers as the ground the whole program stands on, the floor everyone shares whatever seat they occupy. Role-specific AI skills are the vertical one: they run up the side as the edge every layer leans against. Together they wrap the build and the columns both. Every place a person meets the system is an intersection the L has to feed: reading a model output, preparing a training set, signing an approval, questioning a vendor. And no two of those intersections ask for the same thing. Each stacks its own competence on top of the shared floor, specific and different at every point: the skill that prepares a clean training set is not the skill that reads a model evaluation, and neither is basic literacy on its own. Draw literacy as one more tier and you have already lost it. It is not a floor you finish. It is the floor and the frame.

The L — baseline AI literacy as the ground the program stands on, role-specific AI skills as the edge beside every layer.

Governance is the column. Compliance is the by-product.

Governance is not the bottom layer, and compliance is not a workstream you bolt on at the end. Build the operation and the governance correctly and compliance falls out on its own. Data rights respected. Decision rights owned. Evaluations documented. Oversight staffed with people who can read a failure.

Security learned this the hard way. Run the control for real and its compliance artifact becomes a record of something that happened, not a fiction you stage. By-product doesn’t mean free — evidence retention and access reviews are themselves controls you have to run. Chase the audit instead of the posture and you get a binder full of controls that pass inspection and stop nothing. AI governance works the same way. A framework that draws compliance as a discrete tier has already mismodeled it, and the organizations that build to the checklist will still fail the audit they thought they had passed.

There is a newer way to get this wrong. Automate the compliance activity itself. Run the checks continuously inside the workflow and the receipt prints itself, finished before anyone thinks to ask for it. Every word of by-product is satisfied and nothing is governed. A check running inside the workflow is not independent of it, and when it is wrong it is wrong silently. So the condition is this: the evidence has to be re-performable by someone other than the system that produced it, and a failed check has to reach a name that can stop the line. An audit nobody re-performs, produced by the system it audits, is not a receipt.

For high-risk systems the dependency runs the other direction too. Regulatory classification reaches up and dictates what model assurance has to prove, what the runtime layer has to document, what the data layer has to retain. Governance does not sit under the stack. It runs through it, top to bottom, and compliance is the residue it leaves behind.

The number that says whether the column is staffed

Of the last ten thousand AI drafts your review team approved, how many did they change?

Most organizations cannot answer that, and the ones who can are often unhappy with the answer. It is the AI Oversight Override Rate: the share of AI outputs a human reviewer changes or rejects before the output ships. It answers the only oversight question that matters. When you put a human in the loop, is that human changing anything?

This is the number that separates the picture from the reality. A framework can specify a human at every gate and still describe an organization where nobody has ever disagreed with a model. A sign-off can be performed in two seconds. An override cannot be faked into existence.

It measures human oversight, which is narrower than it sounds. Where review has been handed to another agent, the figure measures agreement between two systems, and that tells a board nothing. Move the measurement rather than abandon it. The human still owns the policy envelope: the thresholds, and the exceptions granted and revoked. Measure the overrides there. Govern the envelope, not the packets.

Read it as a triggered diagnostic, never as a target. Any reading outside its expected range, high or low, tells the owner to sample the overrides and find out whether the model is right or nobody is looking. A rate near zero, left uninvestigated, is the designed detector of a powerless owner — a column with a name against it and no authority anyone has exercised. Security already learned this one. A SOC analyst whose escalation rate is zero is not evidence of a quiet network; it usually means the alerts stopped getting read.

Two cautions, because this is where metrics rot. Any interpretation bands you see for this number (mine included) are heuristics, not benchmarks. No validated thresholds exist for it, and presenting one as certified would be the same overclaim this whole article is complaining about.

And the number needs a substrate. An override rate computed from your own logs, about your own reviewers, reported by you, is the same self-issued evidence a vendor hands you in an assurance pack and expects you to take on trust. The condition from the by-product section applies to your own metrics too: someone other than the system that produced the record has to be able to re-perform it. For an override that means the decision it changed surfaces somewhere with no stake in the number, in an output that shipped differently or a release that moved.

A column with a name against it and a number nobody can corroborate is not staffed. It is decorated.

The Column Test

Put the pieces together first. The layers are the build: data, model assurance, application, runtime, stacked in the order you actually construct them. The columns are what holds the layers together: human capability and governance, plus supply chain wherever you deploy on what you did not make, each one running the full height. The L is the floor and the near edge, baseline literacy sitting under everything and beside everything. Draw all three at once and compliance stops being a box you bolt on the end. Layers plus columns plus the L, built to hold, is what produces the compliance in the first place. That is the model. What follows is how you check a framework against it in under a minute.

The whole model — four layers you build, three columns that run through all of them, on the L of baseline literacy.

Here is the practical artifact. Four questions. Run them on any AI governance framework someone shows you.

One. Find the human. Is it a gate, or a capability the framework builds? If it is a single node, the framework assumes a competent person it never staffs. Ask who builds that competence, and when.

Two. Find governance. Is it a property running through every layer, or a compliance tier at the bottom and a gate at the end? If it is terminal, the framework is chasing compliance instead of building governance, and it will fail an audit it thought it had passed.

Three. Find the supply chain. Is third-party model and vendor provenance first-class with a named owner — or dissolved into “data” and “application” where no one owns it? The obligations exist in every regime; the failure is a picture that hides them so a board cannot assign them. Ask who owns it, on what cadence, and sized to what exposure.

Four. Ask the done-ness question. Are the cross-cutting concerns drawn as finishable tiers you complete and move past, or as properties that run through every layer and never close out? If capability and governance appear as schedulable, finishable layers, the framework mismodels them — you stand these functions up on a date and they never ship as done, like security awareness. The people assuring the model already need the literacy; for a high-risk system, the regulatory classification shapes the data layer before the model is ever trained.

A layer can be built in sequence. A column cannot. That is the whole argument.

The seductive thing about the layer cake is that you can schedule it: secure the data, then assure the model, then add oversight at the end. That is exactly the permission a board does not need — permission to defer the two things it can least afford to defer. The capability gap and the governance gap behave like every other kind of debt. They do not go away. They get more expensive.

One last thing. Calling out what the diagrams miss is easy, and this article has done plenty of it. Naming a gap is not the same as showing what good looks like, and what good looks like is what boards need now. So I built it.

A Practitioner’s Guide to AI Governance

Alongside this article I am releasing a practitioner toolkit. Ten instruments, each answering one question a board has to answer anyway.

The Practitioner Playbook — the order you roll the rest of this out in, and at each step the failure that shows up first and the move that avoids it. Every organisation hits the same bumps in roughly the same sequence. This is the map of them.

The Column Test — the four questions above, as a worked instrument. Run it on whatever framework is on your table and see which columns are specified but unstaffed.

The Columns × Layers Competence Matrix — twelve intersections, four layers by three columns. Each one names the specific skill that seat needs and what breaks without it. This is the substrate the rest of the toolkit reads from.

The Column Ownership Map — one named person, one reporting cadence, and one number per column. Plus the question most ownership records skip: name one decision that owner actually made last quarter.

The AI and Agent Inventory — every system and agent you run, its owner, its vendor, its model version, and what it is allowed to touch. Worksheet and spreadsheet. The rule that travels with it: no un-inventoried system in production.

The Decision-Rights Register — which decisions an agent may make alone, which need a human, and what evidence moves a decision up a tier or pulls it back down. Autonomy is not a level you graduate to. It is a right you grant per decision and revoke on evidence.

The AI-Literacy Syllabus — the competence spec per seat, written so HR can hire and train against it. The floor everyone shares, then the specific skill each intersection stacks on top of it.

The Governance Operating Model — the cadence, the two bodies that convene it, and the governance-before-scale rule that stops a deployment shipping ahead of the column meant to hold it.

The board metric cards — four numbers, each a triggered diagnostic rather than a target. The AI Oversight Override Rate is the anchor. When you put a human in the loop, is that human changing anything?

The verified crosswalk — all twelve intersections mapped to the EU AI Act, NIST AI RMF, and ISO 42001, with the article numbers and subcategories checked against the primary sources. This is where compliance shows up as the by-product instead of the workstream.

You can find it at fredriklindstrom.info/toolkit. Fill these in before the incident and you answer the regulator’s first question in one sentence. Fill them in after and you spend the inquiry reconstructing who was supposed to be watching.