Resource
A blank cell is not a gap in the drawing.
Layer-cake diagrams let you finish a tier and climb past it. Three things never finish.
Human capability, governance and supply chain run through every layer, and all three are required at each one. That is the whole claim of the framework, and on its own it is an assertion. The matrix below makes it checkable: for each buildable layer, what each column actually requires at that layer.
Read a row to see what a layer needs on every column. Read a column to see how one concern changes shape as you climb the stack. A blank cell is where a column has quietly stopped running, which is exactly the failure the framework predicts.
Twelve cells, layer by layer
-
Runtime × Human capability
Tells drift from noise and actually overrides the model. Resists automation bias.
-
Runtime × Governance
Live oversight and incident ownership, each owned by a name.
Anchor signal: AI Oversight Override Rate
-
Runtime × Supply chain
Vendor ships a new version silently. What can you see, and what can you stop?
-
Application × Human capability
Scopes the use case honestly. Knows the limits of guardrails and the misuse patterns.
-
Application × Governance
Use-case approval and the execution boundary — enforced structurally, owned, change-controlled.
Permission is not judgment
-
Application × Supply chain
Plugins, APIs, embedded agents. Can you constrain a copilot you did not build?
-
Model assurance × Human capability
Reads an evaluation and designs a red team. Tells a real evaluation from a green dashboard.
-
Model assurance × Governance
Documented evaluation as the control, and a named go/no-go authority empowered to say no.
-
Model assurance × Supply chain
What you verify versus what you inherit. Can you even red-team a closed model?
-
Data × Human capability
Judges provenance, rights and representativeness. Knows fit-for-purpose from merely large.
-
Data × Governance
Classification, lawful-basis sign-off, rights and retention owned by a name.
-
Data × Supply chain
Are the rights to use this data for training contractually established, or assumed?
Compliance does not appear anywhere in the grid, because it is not a column. It is what the governance column produces once every cell above is owned and reported. Oversight is not a fifth layer either, for the same reason: it is the governance column, seen from the runtime end.
Walk any AI initiative through the grid and ask three things per cell
- 01
Is it present here? Not “we did that at the data phase.”
- 02
Who is the named person who owns it at this layer?
- 03
What cadence tells the board it still holds?
A cell that answers “we handled it at the bottom” is a column that stopped running above that point.
Source: A Practitioner’s Guide to AI Governance — a framework by Fredrik Lindstrom. columns are human capability, governance and supply chain; all three required. Compliance is not a column: it is what the governance column produces once every cell is owned and reported. Oversight is not a fifth layer, it is the governance column. Date discipline: EU AI Act Art 4 (AI literacy) in force 2 February 2025. Do not anchor on 2 August 2026 and never describe the Act as fully operational. Exact NIST subcategory and ISO Annex A codes live in the locked verified crosswalk. Status labels and column assignments above are this sheet’s reading of the cited source, not the source’s own framing.
Related
The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.
What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.
The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.