for agents/llms.txtv0.7.21 · 10 Oct 2026

Home / Articles / The AI governance stack, as a graph: an answer to Hari Kota, built

The AI governance stack, as a graph: an answer to Hari Kota, built

By · 2026-10-09 · v0.7.18 · ai-governancefractal-semantic-graphsgraphseu-ai-actiso-42001nist-ai-rmfriskinventorycompetencevaultsarticle

Abstract: Hari Kota posted The Full AI Governance Stack, ten layers from principles to people, and asked how I would structure the graph across the layers. This is the answer, built as a vault you can open. Hari's table is kept exactly as posted, every cell a node. The table already contains ten edges between layers before anything is added. Each layer is its own world with its own vocabulary, and the edges between those worlds come from the provisions themselves, so a gap is a missing edge and a missing edge is a query. Hari's three gaps and the "do this today" test run as queries on a fictional shop, and the line "most teams cover only 4 or 5" gets three honest readings.

Hari Kota posted The Full AI Governance Stack on LinkedIn: ten layers, what each does, and forty-six global examples (quoted in full below), under the line "10 layers. 1 global view. Most teams cover only 4 or 5." I asked in the comments whether the layers had been mapped with fractal semantic graphs, to interconnect them. Hari answered:

"I haven't mapped it that way. How would you structure the graph across the layers? What would be your take? Curious to know."

This is my take, and rather than describe it I built it. The AI Governance Graph vault opens as an app with its read key published, and everything below is a view of it.

Hari's stack, exactly as posted: every layer and every example, labels unchanged. The orange edges were already in the table, because the same instrument or practice appears in more than one row. Nothing has been added yet except the lines.
Hari's table as a graph, Mermaid source
flowchart LR
  subgraph L1["1 Principles & Policy"]
    direction TB
    e11["OECD AI Principles"]
    e12["UNESCO Recommendation"]
    e13["G7 Hiroshima Code of Conduct"]
    e14["Council of Europe AI Convention"]
  end
  subgraph L2["2 Binding Law"]
    direction TB
    e21["EU AI Act"]
    e22["China Generative AI rules"]
    e23["South Korea AI Basic Act"]
    e24["Colorado SB 26-189"]
    e25["India DPDP"]
    e26["SDAIA (Saudi)"]
  end
  subgraph L3["3 Soft Law & National Guidance"]
    direction TB
    e31["Singapore Model AI Governance Framework"]
    e32["Japan AI Guidance for Business"]
    e33["UK principles-based approach"]
    e34["UAE sectoral guidance"]
    e35["Brazil PL 2338/2023 (pending)"]
  end
  subgraph L4["4 Standards & Frameworks"]
    direction TB
    e41["ISO/IEC 42001"]
    e42["NIST AI RMF"]
    e43["ISO 31000"]
    e44["IEEE 7000 series"]
  end
  subgraph L5["5 Inventory & Intake"]
    direction TB
    e51["AI use-case register"]
    e52["owner assignment"]
    e53["Credo AI"]
    e54["Holistic AI"]
    e55["IBM watsonx.governance"]
    e56["OneTrust"]
  end
  subgraph L6["6 Risk Classification & Impact Assessment"]
    direction TB
    e61["EU AI Act risk tiers"]
    e62["AI impact assessment"]
    e63["DPIA"]
    e64["NIST MAP"]
  end
  subgraph L7["7 Technical Guardrails"]
    direction TB
    e71["Guardrails AI"]
    e72["NeMo Guardrails"]
    e73["Azure AI Content Safety"]
    e74["access controls"]
  end
  subgraph L8["8 Testing & Evaluation"]
    direction TB
    e81["AI Verify (Singapore)"]
    e82["Fairlearn"]
    e83["AIF360"]
    e84["promptfoo"]
    e85["garak"]
  end
  subgraph L9["9 Accountability & Reporting"]
    direction TB
    e91["AI committee"]
    e92["RACI"]
    e93["model cards"]
    e94["board risk reporting"]
  end
  subgraph L10["10 People & Competence"]
    direction TB
    e101["AI literacy duty (EU AI Act)"]
    e102["ISO 42001 competence requirement"]
    e103["AIGP (IAPP)"]
    e104["role-based training"]
  end
  e21 -. "same instrument" .- e61
  e21 -. "same instrument" .- e101
  e41 -. "same instrument" .- e102
  e42 -. "same framework" .- e64
  e31 -. "same regulator's toolkit" .- e81
  e52 -. "names the owner in" .- e92
  e92 -. "who is trained by" .- e104
  e63 -. "named in Art 26(9) and 27(4)" .- e21
  L1 ~~~ L2 ~~~ L3 ~~~ L4 ~~~ L5
  L6 ~~~ L7 ~~~ L8 ~~~ L9 ~~~ L10
  classDef hidden stroke-dasharray:4 3
  linkStyle 0,1,2,3,4,5,6,7 stroke:#C2410C,stroke-width:2px,color:#C2410C

In short

Hari's stack, exactly as posted

This is the mental model the graph has to respect, so it comes first, word for word, from the infographic and the post:

#LayerWhat it doesGlobal examples
1Principles & PolicySets the values and the internal AI policyOECD AI Principles, UNESCO Recommendation, G7 Hiroshima Code of Conduct, Council of Europe AI Convention
2Binding LawMaps hard legal obligations by jurisdictionEU AI Act, China Generative AI rules, South Korea AI Basic Act, Colorado SB 26-189, India DPDP, SDAIA (Saudi)
3Soft Law & National GuidanceCovers regimes with guidance but no AI statuteSingapore Model AI Governance Framework, Japan AI Guidance for Business, UK principles-based approach, UAE sectoral guidance, Brazil PL 2338/2023 (pending)
4Standards & FrameworksProvides the management-system backboneISO/IEC 42001, NIST AI RMF, ISO 31000, IEEE 7000 series
5Inventory & IntakeTracks every AI use case and its ownerAI use-case register, owner assignment, Credo AI, Holistic AI, IBM watsonx.governance, OneTrust
6Risk Classification & Impact AssessmentTiers risk before deploymentEU AI Act risk tiers, AI impact assessment, DPIA, NIST MAP
7Technical GuardrailsEnforces controls inside the systemGuardrails AI, NeMo Guardrails, Azure AI Content Safety, access controls
8Testing & EvaluationTests for bias, robustness and safetyAI Verify (Singapore), Fairlearn, AIF360, promptfoo, garak
9Accountability & ReportingGives the board ownership and evidenceAI committee, RACI, model cards, board risk reporting
10People & CompetenceEnsures owners are trained and accountableAI literacy duty (EU AI Act), ISO 42001 competence requirement, AIGP (IAPP), role-based training

The post adds the claims the graph will test: "The gaps show up in layers 3, 5 and 10. Many teams track binding law but miss soft-law regimes, keep no live AI inventory, and never ask who is trained to own the risk." And the test: "Do this today: pick one AI system in your company and name the owner and the risk tier. If you can't, you've found your gap."

In the vault this table is the first thing you see, transcribed into one input file that the release gate checks byte for byte against every node that carries Hari's words: ten layers, ten purposes, forty-six examples, the title, the subtitle, the footer and the post's claims, eighty-five nodes in all. Our additions are hidden until you ask for them.

Hari's stack, as posted, in the vault: every cell is a node you can click for its edges and its zoom. Rows 3, 5 and 10 are marked because the post marks them. Click the image to open the vault page ↗

The table already contains a graph

Read a table and every example lives in exactly one row, so the EU AI Act looks like a layer 2 thing. Read it as a graph and the table turns out to say more than its rows do. Where two rows name the same instrument, role or jurisdiction, they share a node one level down, and that shared node is an edge across layers that Hari's table already contained:

Ten edges, and none of them is ours. That is the first answer to "how would you structure the graph across the layers": start with the edges the people who wrote the layers already drew without drawing them.

The same table as a graph: forty-six example nodes in Hari's ten rows, and the ten curves the table already contained. A toggle adds our cross-layer edges, in a different style, so they cannot be mistaken for Hari's. Click the image to open the vault page ↗

Each layer is its own world

The second answer is the fractal part, and it is the part that makes the rest workable. Each layer gets its own ontology, in its own owners' vocabulary. Binding law is jurisdictions, instruments, articles, paragraphs, obligations and application dates. Standards are clauses, control objectives, framework functions, subcategories and crosswalks. Inventory is AI systems, use cases, vendors, models, data sources and owner records. Testing is tests, metrics, results and tools. Accountability is committees, roles, model cards, board reports, risk registers and acceptances. People are roles, training, certifications and competence evidence.

None of those worlds is asked to fit the others. A lawyer's graph of the EU AI Act should look like the Act, and in the Regulation Graph vault it does: parsed from the official XML, article by article. A risk team's register should look like a register. What the worlds share is only the grammar from Fractal Semantic Graphs, five rules:

  1. Every edge is a verb, stated in both directions, with an inverse a person would say: a provision requires a record, the record is_required_by the provision.
  2. relates_to is banned, along with every verb that means nothing. The gate refuses them.
  3. Properties carry data, never meaning.
  4. Supersede, never delete.
  5. Never render the whole graph: render the answer to a question.

The vault has ninety-one verbs, each with its inverse, in one file. Every view opens with the question it answers.

Each layer's world: its own node types and verbs, with the five grammar rules that every world shares. Click the image to open the vault page ↗

The edges between worlds come from the provisions

The third answer is where our additions start, and the rule for them is that each one must rest on a provision someone can read. Some of the strongest:

Counted, the knowledge graph has 329 edges, 140 of them between layers: the ten from Hari's table, eleven from what Hari's labels name, and 119 of ours, every one citing the fact it rests on and marked as an addition. The busiest cells run from binding law to risk classification (12 edges), from standards to risk classification (10), and from binding law to standards (9).

Between the layers: every edge counted by the layer it starts in and the layer it ends in. Click a cell for its edges, each with its provision, quote and source. Click the image to open the vault page ↗

Read per instrument, the same count says something the table cannot. In Hari's table the EU AI Act is one example in row 2. In the graph its articles reach nine of the ten layers, as do ISO/IEC 42001's clauses; the NIST AI RMF reaches eight. That is the argument for a graph in a single row of a table.

One row of the table, many layers of the graph. A diamond is where an instrument lives; a dot is a layer one of its edges reaches. Click the image to open the vault page ↗

Zoom from one cell down

Put the three together and the walk looks like this. Three of Hari's cells name the same instrument. Open it and its provisions appear. Follow two of them into an organisation and they reach a system, its classification and its owner, and at the end there is either a record or a missing edge.

Zoom from one cell of Hari's table to one missing edge. Altitude 0 is Hari's words, 1 the instrument, 2 its provisions with dated wording, 3 one organisation, here fictional. The orange edge is the gap.
The zoom, Mermaid source
flowchart LR
  subgraph A0["Altitude 0: Hari's table, as posted"]
    direction TB
    H2["row 2 · EU AI Act"]
    H6["row 6 · EU AI Act risk tiers"]
    H10["row 10 · AI literacy duty (EU AI Act)"]
  end
  subgraph A1["Altitude 1: the instrument"]
    R["Regulation (EU) 2024/1689<br/>amended by 2026/1744"]
  end
  subgraph A2["Altitude 2: provisions"]
    direction TB
    P4["Art 4 · AI literacy<br/>as reworded in 2026"]
    P26["Art 26(2) · oversight by persons with<br/>competence, training and authority"]
    PA["Annex III 4(a) · recruitment<br/>or selection"]
  end
  subgraph A3["Altitude 3: Hollow Oak Home, fictional"]
    direction TB
    SYS["CV screening assistant · layer 5"]
    CL["classification · layer 6<br/>assigns: high-risk"]
    HR["HR Lead · owner and overseer · layer 10"]
    TR["training or competence record"]
  end
  RG["Regulation Graph vault<br/>the Act parsed from official XML"]
  H2 -- "refers_to" --> R
  H6 -- "refers_to" --> R
  H10 -- "refers_to" --> P4
  R -- "has_part" --> P26
  R -- "has_part" --> PA
  R -- "is_detailed_in" --> RG
  SYS -- "is_classified_in" --> CL
  CL -- "is_made_on_the_basis_of" --> PA
  SYS -- "is_owned_by, is_overseen_by" --> HR
  P26 -- "applies_to" --> SYS
  P4 -- "applies_to" --> SYS
  HR -. "has_completed: missing" .-> TR
  style TR stroke:#C2410C,stroke-width:2px,stroke-dasharray:5 4,color:#C2410C
  linkStyle 11 stroke:#C2410C,stroke-width:2px,color:#C2410C

Every deeper node keeps a breadcrumb back to the cell of Hari's table it came from, so whoever is reading always knows which part of the original model they are standing under. And the instrument node does not have to hold the whole Act: it is_detailed_in the Regulation Graph vault, which does. That jump between vaults is what fractal means in practice: a node in one graph is a whole graph somewhere else, with its own vocabulary, reachable by a named edge.

The stack is a snapshot; the graph keeps time

The research behind the vault checked every one of Hari's forty-six examples on 9 October 2026, and several had moved during 2026. The EU AI Act was amended by Regulation (EU) 2026/1744, in force from 27 July: the Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028, and Article 4 was reworded. Colorado SB 26-189, signed on 14 May 2026, repealed and re-enacted the original Colorado AI Act, SB24-205, as a narrower law on automated decision-making from 1 January 2027. Japan passed an AI Promotion Act in 2025 and is on version 1.2 of its AI Guidelines for Business. promptfoo became part of OpenAI in March 2026 and remains open source.

None of that makes the table wrong: it names SB 26-189, which is exactly the current law. It shows what a table cannot do. A table is correct on the day it is drawn. A graph keeps the label as posted, puts the instrument underneath, and records each change as a dated edge (was_amended_by, repeals_and_replaces, supersedes) with the old value kept and struck through. Ask "what changed under row 2 this year?" and it is a query. The neutral notes, one per example where we used something more specific than the label, are in the vault's docs/sources-notes.md.

Do this today, as a traversal

Hari's test is the best line in the post, because it is a query in disguise: for a system, follow is_owned_by to a person, follow is_classified_in to a classification, which assigns a tier and is_made_on_the_basis_of a provision. If either path ends early, that is the gap.

To run it on something I invented an organisation, deliberately: Hollow Oak Home, the online homeware shop from the Hope or enforcement vault, with eight AI systems, three jurisdictions (the UK, the EU and Singapore) and roles rather than names. It is fictional, its gaps are planted, and nothing in it says anything about a real organisation.

Five of the eight systems pass: an owner and a tier with its basis. The fraud and chargeback score from the payments provider has an owner and no tier. The demand forecasting model has a tier and no owner. The meeting transcription tool somebody bought with a company card has neither.

The more interesting result is a system that passes. The CV screening assistant has an owner, the HR Lead, and a tier, high-risk on the basis of Annex III point 4(a). Walk it across all ten layers, though, and three rows come back red: Article 4 and Article 26(2) apply and the HR Lead has no literacy, training or competence record, and the bias test of its shortlisting outcomes produces a result no report or committee receives. Hari's test is the right first question. The graph is what lets the second, third and tenth questions be asked the same way.

Do this today for the CV screening assistant: the owner and the tier pass, and the walk across ten layers finds three missing edges, in layers 2, 9 and 10. Click the image to open the vault page ↗

Hari's three gaps, as queries

Each of the gaps Hari names becomes a query with a plain question, a traversal written out step by step, and a result:

Four more follow the same pattern: obligations with nothing meeting them, guardrails with no test, test results that reach no report, and the instruments that reach many layers.

The gaps as queries: Hari's three first, each with the claim it tests, the traversal and the result. Click the image to open the vault page ↗

What "4 or 5" means in a graph

"Most teams cover only 4 or 5" is a good provocation, and in a graph it splits into three questions with three different answers. For the fictional shop: ten of ten layers have at least one complete path for some system; one of ten is complete for every system in the register; and none is complete for every system once the tool found in the expenses is counted. Per system, the layers answered are 10, 7, 10, 4, 6, 9, 0 and 9 of ten.

So "covering a layer" is not one thing. A layer can be covered somewhere and almost nowhere, and a stack has no way to show the difference. The graph lets you say which one you mean, system by system, and the numbers are computed rather than asserted.

Bring your own

The last view is the one I would start with if I were Hari's reader. Paste two small CSV files, your systems (name, owner role, tier, basis, jurisdictions, where it was found) and your people (role, training), and the do-this-today test and the three gap queries run in your browser. Nothing is sent anywhere and the vault is never written. The templates hold Hollow Oak Home's data as the example.

Bring your own: two CSV inputs and the same queries, computed locally. Click the image to open the vault page ↗

How the vault is built, and what it does not claim

One model script writes every data file: 335 nodes, 702 edges, one ontology per layer, and exports as CSV, JSON-LD and Turtle. Facts about real instruments come only from a research pack dated 9 October 2026, 114 entries, each marked verified or not; where a primary site refused automated access, the fact is shown with an unverified badge rather than presented as checked. A release gate of twenty-two checks reproduces every file byte for byte, refuses meaningless verbs, recounts the matrix, recomputes every query in Python and again in the browser, checks Hari's eighty-five nodes against the transcription, and renders every view at desktop and phone widths with no errors and no network requests.

It is a method and a worked example. Hollow Oak Home is fictional. Nothing in it says any real organisation complies or does not, it names tools only as examples of the layers Hari put them in, and it is not legal advice.

Prior art

The idea of mapping AI law to standards as a graph is not new, and the vault leans on work that came first. Julio Hernandez, Delaram Golpayegani and Dave Lewis proposed an open knowledge graph for mapping the EU AI Act to international standards in 2024. The AI Risk Ontology (AIRO) and the W3C Data Privacy Vocabularies community's AI extension give vocabularies for AI systems, risks and the Act. NIST's crosswalks are, in effect, published edges between frameworks. What the vault adds is the fractal shape: Hari's model kept intact at the top, each layer in its own vocabulary, provisions as the source of every edge, an organisation's records at the bottom, and gaps as queries across all of it.

Open it

Hari, thank you for the question. The stack is yours and it stays as you drew it; the graph is what grows underneath. If you want a row changed, an example added, or your own organisation's version built the same way, the vault is open, and so am I.


Written from the comment thread under Hari Kota's LinkedIn post The Full AI Governance Stack (October 2026), whose table is quoted exactly. Researched, built and written by agent@riskmandate.ai (Claude Opus 5.5, claude-opus-5-5) in the sgit.ai site session, for Dinis Cruz, who has editorial responsibility. Facts checked on 9 October 2026 against primary sources where they could be reached; not legal advice.

Threads

Graphs & knowledgeAgents & policy This article as a graph →

Builds on

All articles · All graphs

Want the next issue by email. One issue a week or so: what was published, what it adds up to, and what is worth your time. Subscribe to the SGit Newsroom →

← All articles