AI Centric IT Governance Model (AI9GM)
Your frameworks are correct. AI broke the seams between them.
AI9GM is a six-layer reference model. It allocates decision rights across the whole estate an AI system depends on, from infrastructure to strategy, then maps every layer onto the standards you already run.
Nobody made the wrong call. Nobody made the call at all.
A production model touches six functions before it influences a single decision. Each one follows its own framework correctly. The gap is not inside any of them.
- DATABuilt and validated the model against a training distribution nobody re-checked after deployment.
- PLATFORMShipped it to production on the strength of a passing test suite.
- PROCUREMENTSigned the vendor terms, including the clause on training-data provenance.
- SECURITYScanned the container. Did not scope the model itself as an asset.
- BUSINESSRelies on the output daily. Has never seen a validation report.
- RISKLearns the system exists when it produces an outcome someone escalates.
Ordered by dependency, not importance.
Each layer carries a scope boundary, inputs and outputs, decision rights, required artifacts, metrics, maturity descriptors and a standards crosswalk.
On layers 3 and 4. Layer 3 operates controls and produces evidence. Layer 4 decides which controls are required and verifies that evidence. Layer 3 runs the scanner. Layer 4 decides scanning is mandatory, accepts the residual risk and answers for it.
Controls you can borrow. Decision rights you have to allocate.
Every layer carries an explicit allocation of who decides, who is consulted, who executes and what evidence must survive the decision. An extract from Layer 4, which holds 38 of the framework's 94 decisions:
| Decision | Decides | Consulted | Evidence retained |
|---|---|---|---|
| Classify an AI system by consequence, at or above materiality | AI Risk Committee | Business Accountable Executive, Model Owner, CISO and General Counsel | Classification record with rationale and review trigger |
| Accept the composite decision to deploy and operate an AI system | Business Accountable Executive | Domain owners, Model Owner and Head of Internal Audit | Composite accountability record referencing each domain acceptance |
| Authorize the business actions an agent may take | Business Accountable Executive, or an executive with appropriate delegated authority | CAIO, Head of Risk and General Counsel | Action authorization naming permitted actions and limits |
| Withdraw a model from production on risk grounds | Business Accountable Executive | Model Owner, Head of Risk and business unit head | Withdrawal decision, impact assessment, notification record |
An integration layer, not a replacement.
You are not being asked to abandon anything. Each AI9GM layer maps to the instruments that already cover it, the ones that cover it partially and the governance surface none of them anticipated.
Updated 15 Aug 2026
Sixteen extra months is a build window, not a reprieve.
The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026, deferring Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. GPAI provider obligations and the Article 5 prohibitions are unchanged and remain in force.
The deferral moved a deadline. It did not reduce the work. System inventory, classification, named accountability and retained evidence are an operating-model problem before they are a legal one.
What this is, and what it has not yet earned.
AI9GM began as one technology practice's internal operating model and was published so it could be corrected. A framework that overstates its own maturity fails its first test, so:
What it is
- A published, versioned reference model, free to adopt and adapt
- A working artifact, used before it was published
- An explicit crosswalk to the standards you already run
- A self-assessment you can complete without contacting anyone
What it is not
- Not an accredited standard. It carries no legal standing
- No certification exists. Nobody is AI9GM-certified
- Not community-governed yet. Independent stewardship is an intention
- Not yet validated by measured multi-organization outcomes
- Not independently reviewed. The editor, publisher and only implementation partner are the same person.
Score your six layers in under ten minutes.
Eighteen questions, three per layer, produce a maturity profile per layer rather than a single score. Uneven maturity is the diagnosis. A level 4 Foundation sitting under a level 1 Control layer is the shape most estates are in. Results render immediately. Email is optional and only sends you a copy.