Blog · AI · AI Policy · AI Strategy · Governance

Six Layers of AI Governance: A Framework for Getting It Right

Rob May · 25 September 2026
A six-layer approach to AI governance as discussed in many of my AI talks this year.
A six-layer approach to AI governance as discussed in many of my AI talks this year.

Most conversations about AI governance end up in one of two places. Either they get so abstract they're useless in practice, or they get so focused on risk that they slow everything down that's actually working. Neither serves your organisation well.

The framework I've been using with clients, and sharing on stage at events this year, tries to cut through that. Six layers. Three phases. Each with a clear job to do.

Here's how I think about it.

Adopt: Build responsibly

The first two layers are about getting AI into your organisation in a way that doesn't create problems you'll spend the next three years unpicking.

Layer 1: AI Inventory. Before you govern what you have, you need to know what you have. Most organisations don't. Shadow AI, department-level ChatGPT subscriptions, tools embedded in SaaS platforms, models baked into your ERP. Start with a proper inventory: what AI systems are running, who owns them, how they're classified by risk, and whether anyone actually has visibility over how they're being used. This isn't bureaucracy. It's basic hygiene.

Layer 2: Responsible Deployment. Knowing what you have is step one. Deploying it sensibly is step two. This means choosing use cases deliberately rather than opportunistically, making considered choices about architecture and model selection, putting change control in place, and integrating AI into your DevSecOps pipeline if that's relevant to your organisation. The intention here is simple: turn good intent into safe, scalable use, not just a series of experiments that never join up.

Defend: Test and protect

Layers three and four are where most organisations have the biggest gaps, because they assume that using a reputable AI tool means they're safe. They're not.

Layer 3: AI Security and Access. Every AI system you introduce is a potential new attack surface. Identity and access management applies to AI just as much as to any other system. Context and data protection matter enormously, particularly when staff are feeding customer data, financial data, or sensitive internal documents into consumer-grade tools. Tool and MCP controls, access controls, data integrity. These aren't optional extras. They're the foundation of a defensible AI posture.

Layer 4: Testing and Monitoring. AI systems behave differently over time. Models drift. The outputs you got six months ago may not be the outputs you get today. Pre-production evaluation, red teaming, runtime monitoring, drift detection, and having a proper incident response plan in place: these are the mechanisms that keep you ahead of problems rather than scrambling to explain them after the fact.

Govern: Authorise and oversee

The final two layers are about accountability, and they're the ones that tend to be weakest in fast-moving organisations.

Layer 5: Human Oversight. AI is not a decisionmaker. It's a tool that informs decision-making. That distinction matters, and it needs to be embedded in how you operate. Decision review processes, clear escalation paths, defined override authority, output validation, accountability mapping. The question "who is responsible when the AI gets it wrong?" should have a clear answer in your organisation before something goes wrong, not after.

Layer 6: Compliance and Audit. Policy and decision rights documented. Regulatory alignment maintained, not just at point of deployment but on an ongoing basis as regulation evolves. Audit evidence collected. Incident reporting in place. Audit trails and logs available. This is how you demonstrate trust to regulators, clients, and partners, and it's also how you protect yourself when questions are asked.

What this means in practice

I'm not sharing this framework to suggest you need to implement all six layers at once. Most organisations I work with are somewhere between layers one and three, with gaps across the board.

The point is to have a map. Governance without a structure is just policy documents nobody reads. Governance with a structure gives you a way to assess where you are, identify the gaps, and make deliberate choices about where to focus.

If you're working with ramsac, your account team can help you think through where you sit across these layers. The frontier and data security teams are particularly well placed to work through layers three, four and five in detail. This is exactly the kind of conversation worth having before an incident forces it.

If you want to talk through your AI governance position, or you'd like a copy of the framework to use internally, get in touch via thoughtprovoked.co.uk or reach out to ramsac directly at ramsac.com.

The question isn't whether AI governance is necessary. It's whether yours is fit for purpose.


Frequently asked questions

What are the six layers of AI governance?

The framework includes six layers across three phases. Phase one, Adopt, includes AI Inventory and Responsible Deployment. Phase two, Defend, covers AI Security and Access alongside Testing and Monitoring. Phase three, Govern, focuses on Human Oversight and Compliance and Audit. Together, these layers give organisations a clear map to manage AI safely.

Why is an AI inventory essential for organisations?

Before governing AI, an organisation must know what systems exist. An AI inventory tracks running tools, department subscriptions, shadow AI, embedded SaaS features, and ERP models. It identifies who owns each tool, how risk is classified, and who has visibility, creating basic operational hygiene to avoid long term problems.

How does human oversight fit into AI governance?

Human oversight ensures AI remains a tool to inform decisions rather than act as a final decisionmaker. Layer five requires clear decision reviews, escalation paths, override authority, and accountability mapping. This ensures your organisation clearly defines who is responsible when an AI system makes a mistake before any issues actually happen.

Why do organisations need ongoing testing and monitoring for AI?

Reputable AI tools are not automatically safe, as AI models behave differently over time and experience drift. Layer four addresses this through pre-production evaluation, red teaming, runtime monitoring, and drift detection. Having a proper incident response plan in place keeps organisations ahead of issues rather than scrambling after problems occur.

Must an organisation implement all six governance layers immediately?

No, organisations do not need to implement all six layers at once. Most businesses currently sit between layers one and three, with gaps throughout. The framework serves as a map to evaluate current standing, identify vulnerabilities, and make deliberate choices about where to focus efforts rather than relying on unread policy documents.

Never miss an article

Get new articles by email

Whenever I publish something new on AI, cybersecurity and cyber resilience, I'll send you a link. No newsletters, no selling, and one click to stop at any time.

Your address is used only to send you new articles. See the privacy notice.