FL Fredrik Lindstrom


Layer-cake diagrams let you finish a tier and climb past it. Three things never finish.

Human capability, governance and supply chain run through every layer, and all three are required at each one. That is the whole claim of the framework, and on its own it is an assertion. The matrix below makes it checkable: for each buildable layer, what each column actually requires at that layer.

Read a row to see what a layer needs on every column. Read a column to see how one concern changes shape as you climb the stack. A blank cell is where a column has quietly stopped running, which is exactly the failure the framework predicts.

A four-by-three matrix. Rows are the buildable layers: runtime and monitoring, application, model assurance, data. Columns are human capability, governance and supply chain. Each of the twelve cells states what that column requires at that layer.
Download the matrix PDF, text selectable, prints for board packs. No email required.

Twelve cells, layer by layer

  1. Runtime × Human capability

    Tells drift from noise and actually overrides the model. Resists automation bias.

  2. Runtime × Governance

    Live oversight and incident ownership, each owned by a name.

    Anchor signal: AI Oversight Override Rate

  3. Runtime × Supply chain

    Vendor ships a new version silently. What can you see, and what can you stop?

  4. Application × Human capability

    Scopes the use case honestly. Knows the limits of guardrails and the misuse patterns.

  5. Application × Governance

    Use-case approval and the execution boundary — enforced structurally, owned, change-controlled.

    Permission is not judgment

  6. Application × Supply chain

    Plugins, APIs, embedded agents. Can you constrain a copilot you did not build?

  7. Model assurance × Human capability

    Reads an evaluation and designs a red team. Tells a real evaluation from a green dashboard.

  8. Model assurance × Governance

    Documented evaluation as the control, and a named go/no-go authority empowered to say no.

  9. Model assurance × Supply chain

    What you verify versus what you inherit. Can you even red-team a closed model?

  10. Data × Human capability

    Judges provenance, rights and representativeness. Knows fit-for-purpose from merely large.

  11. Data × Governance

    Classification, lawful-basis sign-off, rights and retention owned by a name.

  12. Data × Supply chain

    Are the rights to use this data for training contractually established, or assumed?

Compliance does not appear anywhere in the grid, because it is not a column. It is what the governance column produces once every cell above is owned and reported. Oversight is not a fifth layer either, for the same reason: it is the governance column, seen from the runtime end.


Walk any AI initiative through the grid and ask three things per cell

  1. 01

    Is it present here? Not “we did that at the data phase.”

  2. 02

    Who is the named person who owns it at this layer?

  3. 03

    What cadence tells the board it still holds?

A cell that answers “we handled it at the bottom” is a column that stopped running above that point.

Source: A Practitioner’s Guide to AI Governance — a framework by Fredrik Lindstrom. columns are human capability, governance and supply chain; all three required. Compliance is not a column: it is what the governance column produces once every cell is owned and reported. Oversight is not a fifth layer, it is the governance column. Date discipline: EU AI Act Art 4 (AI literacy) in force 2 February 2025. Do not anchor on 2 August 2026 and never describe the Act as fully operational. Exact NIST subcategory and ISO Annex A codes live in the locked verified crosswalk. Status labels and column assignments above are this sheet’s reading of the cited source, not the source’s own framing.


Related

The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.

What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.