AI Governance Has a Missing Layer

A well-known framework is getting a lot of attention right now. It breaks AI governance into six clear layers: AI Inventory, Data Foundation, Data Security and Access, Model Assurance, Human Oversight, and Compliance and Audit.

The framework provides structure: risk tiering, lineage mapping, fairness testing, drift detection, and audit trails. These are the fundamentals for safe AI deployment, yet many organisations have not caught up. The leading standard, the NIST AI Risk Management Framework, applies a similar logic: govern, map, measure, and manage the model across its lifecycle.

All six layers, and the NIST functions begin only after AI is in use. They address the model, its data, and its outputs. No one examines the origin of the model’s instruction.

The process starts with the instruction: the brief or the decision that defines what is required.

Seven-layer AI governance stack with Intent / The Brief as the top layer above AI Inventory, Data Foundation, Data Security and Access, Model Assurance, Human Oversight, and Compliance and Audit.

 


AI follows intent; it does not create it

This is the missing layer in the current frameworks. It is a material gap.

A model does not determine priorities. It does not weigh trade-offs, challenge weak objectives, or test business relevance. It executes instructions. The six layers ensure safe, fair, and auditable operation, but none assess whether the instruction itself warranted execution.

A well-governed model can operate from a poorly governed brief. Dashboards will indicate success. Audit trails will record decisions that were never examined.


The cost appears downstream, but its origin is at the outset

In marketing organisations, this issue is visible early.

A brand team briefs an agency. The agency briefs a creative team. The creative team briefs production, and production briefs suppliers. Each handoff is a chance for the original intent to get lost. In the past, this process was slow and costly, which gave people time to notice and fix mistakes.

With AI at every stage, speed increases, but ambiguity persists. Polished output can obscure underlying uncertainty. Poor instructions no longer result in isolated errors. They propagate. A vague brief once wasted a week. Now, it can produce two weeks of compliant, on-brand work directed at the wrong objective.

This problem is not new, but it is now more urgent. Even before AI, research from BetterBriefs and the IPA found that marketers estimate a third of budgets are lost to poor briefs and misdirected work. When execution was slower and more expensive, friction helped catch issues. AI accelerates execution but does not improve the brief. It removes the friction that once surfaced problems before costs were incurred.

As AI reduces execution costs, value concentrates in the quality of the input. The brief becomes the critical and most expensive component. It remains dependent on human judgement, yet is often the first area where governance lapses once the model performs well.


What it means to govern the brief

This is not an additional process. It is the same discipline applied earlier in the chain.

A brief is a decision system. It defines objectives, states assumptions, assigns accountability, and requires approval before resources are committed. It should be governed with the same rigour as any critical process:

  • Quality and completeness: Are objectives clear and specific enough to withstand challenge? Is context provided, or merely assumed?
  • Visibility of assumptions: What is being taken for granted, and who has agreed to those terms?
  • Approval must precede execution, not follow it.
  • Measurable standards: Briefs should be evaluated against defined benchmarks, not approved by instinct.

When this discipline is applied, the six layers become easier to manage. Much of what model governance seeks to address is ambiguity that should have been resolved before the model received its instructions.


A more useful question

Most AI governance focuses on a single question: Can the model be trusted?

This is not the right starting point. The model is the most controlled element. The instruction is the least governed and the most consequential, yet it is rarely examined.

A more useful question is the one the framework does not address: Can we trust the decision that drove the AI?

This is the layer above all six. It is where intent is set, cost is determined, and governance currently ends. It is also the layer iQ is building.

Governance does not start with the model. It starts with intent.