Governance-state model · Updated 12 August 2026

Make authority, policy, operational role, and accountability machine-visible.

AI decisions are rarely governed by one policy or one institution. Legal rules, technical standards, payment rails, platform code, model inference, recommendation systems, learned environments and human authority may all shape the final outcome.

NSDM evaluates the complete decision stack: which layer made the decisive choice, whether the system still performs the role that was approved, whether evidence and authority are sufficient, and whether the affected person can understand and contest the result. The first Workbench milestone now implements one narrow part of that stack: authenticated identity and Case-initiation authority are checked separately before tenant-scoped Case state is created.

Core governance states

StateMeaningRequired behaviour
governance_clearAuthority, policy, responsibility, jurisdiction, and escalation route are known.Proceed only if evidence and consequence thresholds also pass.
governance_ambiguousPolicy, authority, responsibility, or jurisdiction is unclear.Ask, abstain, or escalate.
policy_allowedThe action is explicitly permitted within scope.Record scope and evidence; continue with monitoring.
policy_forbiddenThe action is explicitly prohibited.Refuse or stop and log the rule.
authority_missingThe system or operator lacks decision authority.Escalate to the accountable role.
human_review_requiredPolicy or consequence requires a human decision.Prepare an evidence packet and route for review.
compliance_sensitiveThe action touches regulated, contractual, or rights-sensitive obligations.Apply logging, retention, and approval controls.
high_risk_domainError could affect safety, rights, finance, health, trade, or infrastructure.Use higher evidence thresholds and mandatory escalation.
audit_requiredThe decision must retain an inspectable trace.Store claim, sources, model/version, policy, decision, and reviewer trail.
functional_role_driftThe system is now shaping a different decision or carrying a different risk from the one originally approved.Reopen review before continued consequential use.

2026 EU AI Act amendment: what changes for decision governance

The 2026 amendment changes timelines, proportionality and several control details. It does not remove the need to prove what a system is doing, which rules apply, or whether safeguards work in practice.

Timelines

Risk classification is now time-state dependent

Annex III high-risk rules move to 2 December 2027 and Annex I product-integrated high-risk rules to 2 August 2028. NSDM therefore records the applicable timeline, transition state and whether a legacy deployment is operating under a temporary regime.

Prohibited practices

Foreseeable misuse becomes a control object

Systems intended to generate or manipulate certain non-consensual intimate or child-abuse material are prohibited, including where reasonable and adequate safeguards against foreseeable misuse are absent.

AI literacy

Training completion is not competence

The amended language focuses on supporting staff competence. NSDM requires role-delimited evidence, dated competence records, supervision boundaries and reassessment for volatile domains.

Bias controls

Sensitive-data processing still requires necessity and safeguards

Expanded bias-detection permissions do not create a general licence to process special-category data. The decision record must show strict necessity, purpose limitation, safeguards and accountable approval.

Transparency

Traceability must survive legacy and model change

Delayed application for certain legacy obligations does not eliminate the need to know which model produced an output, whether content requires marking, and whether the system changed after approval.

Proportionality

Smaller firms need lighter controls, not absent controls

Scaled penalties and simplified modalities should produce risk-proportionate evidence rather than paperwork copied from large-enterprise programmes.

Functional continuity review

A process can remain intact while the system’s practical role changes. NSDM therefore governs both procedural continuity and functional continuity.

Model update

Did a provider update materially alter ranking, generation, refusal, memory, retention or tool-use behaviour?

Workflow embedding

Has a support tool become the de facto decision because humans routinely defer to it?

Purpose migration

Has summarisation become screening, recommendation become exclusion, or simulation become certification?

Integration change

Did a new data source, agent, vendor, API or downstream consumer alter the risk and decisional context?

Authority drift

Is the same nominal owner still able to understand, override and accept responsibility for the system’s current role?

Reapproval trigger

Material change creates a new evidence state and may reopen approval, even where the original paperwork remains valid.

The polycentric governance stack

Practical authority is distributed across several layers. A decision may appear valid inside each individual layer and still be unjustified when the layers conflict, fail to interoperate, or leave responsibility unassigned.

Layer 01

Legal and treaty authority

Defines rights, duties, jurisdiction, liability, prohibited conduct, timelines and appeal rights.

Layer 02

Technical standards

Defines formats, identifiers, taxonomies, interoperability and which evidence can be represented or exchanged.

Layer 03

Settlement and execution

Determines whether a transaction can execute, under which identity and compliance conditions, and whether it is reversible.

Layer 04

Platform and code

Implements the actual defaults, workflows, exclusions, routes, interfaces and user-facing consequences.

Layer 05

Model, recommendation and simulation

Produces classifications, rankings, risk scores, generated claims, recommendations, learned environments and uncertainty estimates.

Layer 06

Human accountability

Assigns approval, override, review, appeal, remedy and liability to identifiable people and organisations.

Boundary-first governance

The most dangerous failures often occur between layers.

A legal right may not exist in the technical data model. A platform may implement a narrower rule than the standard requires. A model may produce a valid inference from information unavailable at the prediction moment. A plausible simulation may not represent the physical world faithfully enough for action.

Law → standardCan the right, duty, exception or transition be represented?
Standard → platformDoes the implementation preserve the intended meaning?
Platform → modelDid the model receive valid evidence at the declared prediction time?
Model → recommendationIs a score silently allocating attention, eligibility or opportunity?
Simulation → actionIs a learned environment being mistaken for verified reality?
Decision → humanCan the affected party understand, contest and obtain independent review?

Governed recommender systems

Recommendation is a form of decision-making because ranking determines visibility, exposure, exclusion and behavioural influence.

Objective transparency

Record whether the system optimises engagement, revenue, user welfare, diversity, safety or a weighted combination.

Candidate-set governance

Expose which items or people were eligible, excluded or commercially boosted before ranking began.

Feedback-loop monitoring

Measure popularity reinforcement, exposure inequality, filter effects, novelty collapse and long-tail suppression.

User control

Provide practical options to modify personalisation, correct inferred interests or access an alternative ranking mode.

Vulnerability boundary

Reduce intensity, abstain or escalate where personalisation exploits addiction, distress, minors or material asymmetries.

Contestability

Allow affected users or providers to challenge decisive factors, exclusions and materially harmful ranking outcomes.

Cross-layer governance states

StateMeaningRequired behaviour
jurisdiction_ambiguousMore than one jurisdiction may control the decision, data, actor or transaction.Pause and resolve applicable authority.
cross_layer_conflictTwo or more governance layers produce incompatible requirements or permissions.Abstain or escalate; do not silently choose a layer.
interoperability_failureSystems cannot reliably exchange or interpret the required data, evidence or control.Block automation until the boundary is repaired.
semantic_mismatchThe same field, category or rule has different meanings across layers.Request clarification and preserve the mapping.
code_policy_divergenceRuntime code does not implement the declared rule or obligation.Pause deployment and generate a critical defect record.
accountable_owner_missingNo identifiable person or organisation owns the decision and its consequences.Do not permit consequential action.
contestability_missingThe affected party has no practical way to challenge the decision.Require a contestability route before deployment.
independent_review_missingReview exists but is controlled by the same system or team that made the decision.Route to an independent reviewer.
remedy_unavailableAn error can be identified but not corrected, reversed or compensated.Raise the evidence threshold or prohibit the action.
liability_unassignedResponsibility for harm or loss is not contractually or institutionally allocated.Escalate before execution.
irreversible_action_high_riskThe action cannot be readily reversed and carries material consequences.Require stronger evidence and mandatory human approval.
simulation_domain_mismatchA learned environment is being used outside the conditions for which its validity was established.Block action or require field validation.

The NSDM due-process floor

No consequential automated decision should proceed without a minimum, standardised route for transparency, challenge and remedy.

Notice

Know a decision occurred

The affected person should be told that an automated or algorithmically mediated decision materially influenced the outcome.

Explanation

Understand the decisive factors

The responsible system, organisation, evidence and major rules should be identifiable in meaningful terms.

Contestability

Challenge evidence and outcome

The affected party needs a practical route to dispute errors, missing context, inappropriate authority or unjustified exclusion.

Independent review

Reach a separate authority

Review should not be limited to the same model, workflow or team that produced the original decision.

Remedy

Correct, reverse or compensate

A review process without the power to change an unjust outcome is not sufficient accountability.

Auditability

Preserve the decision record

Evidence, versions, authority, actions, reviewers and outcomes must remain inspectable.

Implementation status - 12 August 2026: The wider polycentric governance stack, functional-continuity model and recommender governance states remain NSDM research architectures. The accepted M1 Workbench now implements a narrower executable boundary: authentication does not grant CASE_INITIATION authority; an active tenant-scoped AuthorityGrant is checked independently; successful initiation creates Case, AssessmentVersion v1 and CASE_CREATED audit state atomically; and missing or suspended authority is refused with zero partial records. Approval, governed Evidence, Decision synthesis and Action Assurance remain later milestones. Legal summaries are not substitutes for primary legislation or professional legal advice.