FL Fredrik Lindstrom

The Framework · Free to read

Columns Not Layers

The things that actually fail in an AI program — human oversight, regulatory alignment, supply-chain dependency — don’t sit at one layer. They run through all of them. Draw them as layers and someone owns them at the data stage and no one owns them after. Draw them as columns, each with one named person, and they hold.


The two shapes

Most governance pictures draw AI as a stack of layers — data at the bottom, a model, an application, monitoring on top. That shape is right about what you build. Layers are sequenceable: you finish the data work, then the model work, then ship. A team can own a layer because a layer has a start and an end.

But three things don’t behave like layers. Human capability, governance, and supply chain each run through every layer and never close out. Hand one to a stage and it falls through the gap the moment you climb past that stage. Hand it to “everyone” and no one holds it. They are columns, not layers — and a column holds only when it has one named owner, a board cadence, and a single number that shows it is live.

The best standards already say governance cuts across — NIST’s AI RMF calls its GOVERN function cross-cutting. So that idea is not the contribution. The contribution is two moves the standards don’t make: it extends the same cross-cutting treatment to human capability and supply chain, which the standards still park at a node or a clause; and it operationalizes what cross-cutting actually requires — one named owner, a cadence, an anchor signal. The gap between saying cross-cutting and drawing a box is what the whole framework is built to catch.

What you build

The layers

Buildable, sequenceable, bottom to top. Oversight is not a fifth layer — it is the governance column, live.

  1. Data Provenance, rights, quality, representativeness. What can lawfully and fitly train or ground a model.
  2. Model assurance Evaluation as the control, disciplined versioning, a named go/no-go authority empowered to say no.
  3. Application The execution boundary — what the system is permitted to do, enforced structurally, owned, change-controlled.
  4. Runtime / monitoring Live oversight, drift detection, incident ownership, and the override that actually fires when the model is wrong.

What holds

The columns

Each column becomes a control the moment it has one named owner (a person, not a function), a board cadence, and an anchor signal. A function name in the owner slot means the column is unassigned.

Human capability

Owner
One person accountable for AI-literacy coverage of build / approve / use roles
Cadence
Semi-annual coverage report
The one number
% of decision-role staff meeting the literacy bar

Governance

Owner
One accountable person per AI system in production (regulatory alignment is a sub-obligation here)
Cadence
Quarterly to the relevant committee; exception-triggered ad hoc
The one number
AI Oversight Override Rate

Supply chain

Owner
One person accountable for third-party model and vendor provenance
Cadence
On new vendor or integration, plus periodic review
The one number
Components mapped vs. assessed

The floor and the frame

The L — baseline AI literacy

Beneath and beside the whole model sits one condition it all depends on: a baseline of AI literacy across the organization (EU AI Act Article 4, in force since February 2, 2025; NIST files the same duty under GOVERN as workforce competence). Drawn, it makes an L — a vertical arm beside the layers and a horizontal arm under them.

It is not a bottom tier you finish and climb past. It is the one cross-cutting concern that is also the precondition for the layers existing at all — the people at every layer need it at once. Without it, all three columns fail quietly: a governance owner who cannot read a failure, a reviewer who cannot judge an evaluation, a vendor assessor who cannot read a model card.

The whole model

Columns × Layers

For each layer, what each column actually requires there. Read a row to see what a layer needs on every column. A blank cell is where a column has quietly stopped running — which is exactly the failure the framework predicts.

Layer Human capability Governance Supply chain
Runtime / monitoring Reads monitoring output, tells drift from noise, overrides the model when it is wrong instead of rubber-stamping. Live oversight and incident ownership, each owned by a name. Anchor: the AI Oversight Override Rate. Logs are evidence, not control. Third-party model updates you do not control, vendor incident notification, dependency drift. What can you actually see and stop?
Application Scopes the use case honestly; understands the limits of guardrails and the misuse patterns of what is shipped. Use-case approval, a pre-deployment impact assessment, and the execution boundary — enforced structurally, owned, change-controlled. Embedded components, plugins, APIs, agents. Who owns the risk of what you integrated, and can you constrain a copilot you did not build?
Model assurance Can read an evaluation and design a red-team — tells a real evaluation from a green dashboard. Documented evaluation as the control, disciplined versioning, a named go/no-go authority empowered to say no. Foundation and third-party models: what you can verify vs. what you inherit. Model cards, not vendor assurances taken on faith.
Data Judges provenance, rights, quality — knows lawfully-sourced and fit-for-purpose from merely large. Data classification, lawful-basis sign-off, rights and retention owned by a name. The obligation map starts here. Provenance of external and licensed datasets. Are the rights to use this data for AI contractually established, or assumed?

Rows are shown top-of-stack first for reading; build order runs the other way — data up to runtime.


Compliance is the by-product

Compliance is not a column, and it is not a tier you bolt on at the end. It is what the governance column produces when every cell above is owned and reported. Do the work — name the owners, run the cadence, wire the signals — and the evidence a regulator wants falls out as a by-product. Build for the audit instead, and you get a binder that passes the review and a program that doesn’t hold. Governance done right makes compliance a receipt. The reverse never works.

The practical artifact

The Column Test

Run these four questions on any AI governance framework you’re shown — or on your own.

  1. 1 Find the human. Is it a gate — a box, a node, an approval step — or a capability the framework builds? A single node assumes a competent human it never staffs.
  2. 2 Find governance. Is it a property that runs through every layer, or a compliance tier at the bottom and an oversight box at the top? If it is terminal, it is chasing compliance instead of building governance.
  3. 3 Find the supply chain. Is third-party model, vendor, and component provenance first-class with a named owner — or dissolved into “data” and “application” where no one owns it?
  4. 4 Ask the done-ness question. Are the cross-cutting concerns drawn as finishable tiers you complete and move past, or as properties that run through every layer and never close out?

Three yeses on the wrong side, and the framework on the table looks like governance without being it.