AI Business TransformationBusiness Ops
Our ApproachInsightsStart a Conversation
AI Governance

Where Rules Become Protection: The Enforcement Layer and the Governance That Never Ends

By Shawn Plaster, Founder & CEO, Plaster Group

Article 3 of 3 — Plaster Group’s AI Governance Methodology

CIOCISOCAIOEnforcementContinuous Governance
·12 min read

Where the Rules Start Working by Themselves

This series has walked a five-level governance methodology built for the way AI is actually arriving. It comes along two legitimate tracks, a healthy decentralized wave of productivity tools and a deliberate centralized track that runs from bought point solutions to redesigned core workflows, and one discipline has to hold both. The first article made the case and introduced the five levels, each behind a gate. The second walked the deciding half. Leadership makes the five decisions only it can make, a chartered governance board writes the rulebook as architecture, and the design-time work ends with a contract between the business and IT, one register of every classified step, confirmed buildable. This final article walks the half that runs at machine speed. It covers the enforcement layer that turns those decisions into protections that work automatically, the annual loop that keeps everything honest, and the on-ramp for organizations already mid-journey, which is to say nearly everyone.

One worry deserves naming at the outset, since many executives bring it to this half of the methodology and the answer is reassuring. The deciding half sounded like leadership work. This half sounds like a heavy technology build that will slow everyone down. In practice it is the opposite. The enforcement layer is what removes governance from everyone’s daily attention. Once the rules are built into the systems themselves, people stop carrying them in their heads. Approvals stop depending on somebody remembering to ask. Compliance stops being a matter of vigilance. The work gets safer and lighter at the same time, and that is the entire point.

Level 4: The Enforcement Layer

Level 4 is where IT puts up the guardrails and the rules become protections that work automatically. Everything decided upstream arrives here in one register, and the CIO-side teams build it into the systems themselves, so compliance stops depending on memory. Rules that live in documents get argued with. Rules that live in systems simply operate. Six builds carry the weight.

  1. Built by ITchartered systems, run in productionRelease Gate
  2. Boughtpoint solutions with AI already insideProcurement Gate
  3. HomegrownAI productivity tools on every deskAdoption Channel

One governed estate · one rulebook, from Levels 1 to 3Rails built and run by IT

  • Identity
  • Guardrails
  • Monitoring
  • Audit trail
Three sources of AI enter through three named gates into one governed estate under one rulebook, with identity, guardrails, monitoring and an audit trail running underneath.Figure 3.1 · The Governed Estate · Plaster Group’s AI Governance Methodology · © 2026 Plaster Group

Before the builds, the level settles who runs them. Enforcement is a permanent job rather than a project phase, and things that everyone runs, no one runs. A small governance function stands up inside IT. It is a handful of people, not a department, with a named day-to-day owner who keeps the inventory current, runs the weekly operating rhythm, operates the exception process, and produces the evidence the audits will later read. The level also asks honestly whose existing jobs change. When enforcement goes live, platform engineers, data engineers, and identity teams each inherit a governance duty they have not held before. The gaps between those duties and today’s skills are found and closed before go-live, so nobody is handed a responsibility they were never prepared for.

Every actor gets an identity, including the AI. People and AI agents alike operate under their own credentials, scoped to the task at hand and expiring when the task ends, with every agent bound to a named human owner. This answers the two questions that matter most when something surprising happens. Who did that, and who can stop it? Revoking an identity is the stop mechanism, designed and tested before it is ever needed rather than discovered during a live incident. The failure this prevents is documented well enough to have a name in the security community’s standard threat list. It is called excessive agency, a system granted more functionality, permissions, or autonomy than its task ever needed.1

The count never stops. An inventory covers every model, system, and embedded AI feature in vendor software, with an intake process that keeps it current and a registry recording what each agent may do and who owns it. Coverage becomes a number the board can ask for and get. That sounds modest and is quietly transformative. The question of what AI the organization is running finally has an answer that stays true.

Guardrails and release gates enforce the rules at machine speed. Actions beyond a system’s permitted autonomy are refused at the moment they are attempted, and nothing unclassified can reach production. The release gate checks every system against the register before it launches. The hard lines leadership wrote at Level 1 are enforced here, word for word, closing a loop this series opened in the second article. Leaders write more carefully when they know their sentence will become software, and this is where it does. The approval workflow that feeds the gate is instrumented from its first week, with cycle time measured and published. Speed is how a young governance program earns the right to be strict. When teams can see that classified systems move quickly, the gate reads as a service rather than an obstacle.

Every decision leaves a trail. Audit trails record what happened with the acting identity attached, so any decision can be reconstructed in minutes, whether for an auditor, a regulator, or the organization’s own peace of mind. European law already sets this expectation for high-risk systems, which must allow automatic recording of events over their lifetime.2 Documentation and record retention follow each system’s actual legal obligations, no more and no less. Proportionality is a feature, not a shortcut. Evidence is organized as it is produced and mapped to the safeguards it demonstrates. When an auditor asks, the answer is a lookup rather than an archaeology project, and the time it takes to produce evidence is itself measured and improved.

Behavior is measured, since AI systems can change without changing code. Every system’s normal behavior is recorded before it goes live, so that drift, the slow shift of behavior away from that baseline, sets off an alert instead of accumulating quietly. People check samples of real outputs against reality on a schedule scaled to each system’s tier. One dashboard reports coverage, approval speed, and alerts into a weekly operating rhythm. None of this second-guesses the teams that built the systems. It gives them instruments, the way a finance function gives the business reconciliation rather than suspicion. One discipline keeps the instruments honest. Every threshold descends from the system’s risk tier, decided by the business at Level 2, never from a solution’s default settings. What counts as acceptable is always the organization’s own judgment rather than a vendor.

Bought AI walks through the same door. Vendor systems enter through the same classification checkpoint as anything built in-house, with contract terms that secure audit rights and incident notification, and a monitoring rhythm that catches the AI features vendors add in routine updates. The call-center voice agent from this series' first article never needed an enterprise redesign program, and it never gets a private rulebook either. It classifies at intake, its handoff to human agents gets an oversight specification, and its vendor terms come through this gate. This is what makes the estate one estate. Built, bought, and homegrown AI all sit behind one set of protections, and the organization’s governance is never only as strong as its least-examined purchase.

And if something misbehaves anyway, the response is rehearsed. An AI incident is usually not an outage. The system is up, running, and doing something it should not, which is why response gets its own playbooks rather than borrowed ones. Runbooks cover each category, including the tested procedure for stopping a system fast, and the whole chain is exercised in a rehearsal before go-live, with every finding fixed. Through all of this, remarkably little changes for the people doing the work. Teams keep building, the checks run quietly in the background, and breaking the rules stops being a risk anyone has to manage. The systems simply do not allow it.

Level 5: The Governance That Stays Honest

Governance left alone decays, and it decays through ordinary organizational physics rather than anyone’s failure. Controls drift toward ceremony. Paperwork stands still while regulation moves. Metrics watched long enough start being managed instead of informing. Level 5 is the annual operating loop that prevents all three, and it is deliberately permanent.

Never doneonly current or late
Quarterly auditfour a year, evidence in hand
Annual re-ratificationthe board of directors re-signs on the year’s evidence
Revalidationmodels re-tested when the evidence demandstriggers jump the queue: drift, an incident, or a new law
Monthly sensingtwelve digests a year
Four stations run clockwise through the governance year, from the quarterly audit to annual re-ratification, revalidation and monthly sensing, on a loop that is never done, only current or late.Figure 3.2 · The Annual Loop · Every level gates, including the one that never ends. · Plaster Group’s AI Governance Methodology · © 2026 Plaster Group

A quarterly audit tests behavior, not binders. The governance board asks four questions and requires evidence for each. What work changed? What got caught? What got fixed? Which forum decided something that mattered? A program that can answer those with specifics is alive. A program that cannot has started to become a ceremony, and this audit catches the drift within a quarter of onset, while it is still a course correction rather than a rebuild.

A standing watch keeps the rules current. Regulation and standards keep moving, so a named owner tracks them on a monthly rhythm, distills the changes to a single page, and routes every one into the registers that govern daily work. This year alone moved the European timeline and rewrote an American state law before it ever took effect. That is exactly why the first article argued that governance should stand on the organization’s own foundations. The watch is how it stays true anyway. Whatever moves, the registers move with it.

Deployed systems are revalidated when the evidence calls for it. A drift alert, a material change, or a new use triggers a review that re-asks three plain questions at the depth the system’s tier demands. Does the design still make sense for the job it holds? Is its behavior still tracked against expectations? Did its outputs prove right against reality? The standards this methodology is built on prescribe exactly this pattern, reassessment at planned intervals or when significant changes arise, assessed before the change ships.3 A yearly backstop guarantees no system goes unexamined regardless of triggers. Approval is a photograph, and systems keep moving after the shutter. Revalidation is how trust stays earned rather than remembered.

Once a year, the organization re-signs. The board of directors re-ratifies the policy against the year’s actual record, in a one-page summary of what changed and what the evidence taught. The measures themselves are audited too, including the uncomfortable question every mature program learns to ask out loud. Which of our metrics have we started gaming? The mechanism is familiar enough that Harvard Business Review gave it a name, surrogation, the strategy quietly replaced by the number meant to track it. Asking the question annually is the cheapest integrity mechanism a program can own.4

Two closing disciplines keep the program truthful and compounding. The first is a register of what the organization still owes itself. Every known gap, waiver, and interim fix goes on it, each with an owner, an aging clock, and a retirement path, reviewed monthly and expected to trend down or escalate, never to merely grow. Temporary things become permanent through amnesia, and the register is the anti-amnesia device. The second is reuse. The controls, playbooks, and gate designs that worked are codified into named, versioned patterns, so the second domain’s governance costs a fraction of the first. The first domain through the program is always the most expensive governance the organization will ever build. The patterns are how that investment pays forward.

The year then closes at an annual gate, where the cycle’s evidence re-authorizes the next one. The four audit records, the twelve monthly digests, the revalidations, and the re-signed policy are that evidence. Every level of this methodology passes through a gate, including the level that never ends, which is why it describes its own continuous work honestly. It is never done, only current or late.

Entering Mid-Flight: The Honest On-Ramp

Now the passage this series promised in its first article, written for the situation most readers are actually in. Very few organizations get to build governance in the order the levels describe, for the simple reason that very few organizations are starting. AI is already deployed, teams are already building, and governance exists in pieces. Nothing about that is failure. It is what responsible adoption looked like while everyone was learning. A governance program that pretended otherwise, demanding a restart at Level 1 while real systems run in production, would be useless to the majority of real organizations. This methodology treats mid-flight entry as a first-class path, not an exception to apologize for.

The entry works like this. When an organization arrives ready to build the enforcement layer and the upstream decisions do not all exist, the team building enforcement does not invent the missing decisions. The first article gave the reason. A rule invented by the people it constrains is not governance. Instead, the program builds thin, interim versions of only the decisions enforcement genuinely cannot run without. Those cover how systems are classified and how much autonomy each class may have, who is accountable, and what is simply not allowed. We call this the Minimum Viable Decision Layer. It is the smallest set of upstream decisions the guardrails need, built quickly, and sanctioned in writing by an executive with the authority to own them, never self-authored by IT. The entire value of a rule lies in who stands behind it when it is tested.

Two disciplines keep the on-ramp honest. Every interim artifact carries a sunset date on its face and an upgrade path to the full build, tracked on a register that is reviewed monthly until the interim version is retired. Temporary decisions cannot quietly become permanent ones. And the entry begins with a candid audit of what already exists. The most common finding is not absence but near-miss. A policy was written but never ratified. A classification was started but never calibrated. That finding is good news, not bad. It means much of the work is salvage and completion rather than construction. The standards themselves assume this phased reality. They expect leadership to own the risk posture the organization actually has today, not the one it would have after an imaginary restart.5

One boundary on the on-ramp is worth stating plainly, and it protects the organization as much as the program. The interim decisions must be sanctioned by an executive willing to put their name on them. Where no executive will, the honest move is to pause rather than proceed. Guardrails built on rules nobody owns will not hold under pressure, and learning that during an incident costs far more than learning it during a conversation. In practice the pause is rare. Executives who see the interim set, small, clearly scoped, and dated to expire, almost always sign. It asks for ownership of exactly what they already believed someone should own.

Adopt Boldly. Rest Easy.

Step back from the three articles and a single picture remains. Leadership makes the decisions only it can make, and signs them. A chartered board turns them into workable rules, and the people already using AI meet those rules as an invitation. The people who own the work apply the rules where work is designed, and hand IT a register it can build from. IT builds the rules into the systems themselves, so the protections work automatically across everything built, bought, and homegrown. And once a year, everyone looks at the evidence and signs again. Each level feeds the next, each level is gated, and nothing downstream ever has to invent a decision that belongs upstream.

The two tracks where this series began offer the best final test of the methodology, judged by what daily life looks like on each. On the decentralized track, an employee has capable sanctioned tools, knows the few data boundaries that genuinely matter, and builds personal solutions with the organization’s blessing rather than in its blind spots. The most motivated adopters in the building are now its best-governed. On the centralized track, the picture holds at both ends of the spectrum. A function that bought a point solution runs it with a named owner, a clear tier, and vendor terms settled before signature. A redesign team at the far end works inside boundaries it learned before design began, gets approvals in days, and ships into an enforcement layer that catches what everyone would rather catch early. Neither track experiences governance as an office it must visit. Both experience it as the reason they can move fast without looking over their shoulders.

What that buys an organization is not caution. It is confidence of the earned kind, grounded in named authority, working protections, and evidence renewed every year. The organizations that govern this way do not adopt AI more slowly than their peers. They adopt it faster. Every yes is a safe yes, and nobody is quietly wondering what would happen if a regulator, a customer, or a journalist looked closely. That is what we most want for the organizations we serve, and it is the note this series should end on. Five proven levels, one clear path. Adopt AI boldly and safely, for the people you serve. Adopt boldly. Rest easy.

This series addresses “what” to do, not “how” to do it. If you are a business executive and would like help thinking through the “how,” please feel comfortable reaching out.

Sources

  1. 1.OWASP, “Top 10 for LLM Applications” (2025), LLM06: Excessive Agency (excessive functionality, permissions, or autonomy). https://owasp.org/www-project-top-10-for-large-language-model-applications/
  2. 2.EU AI Act (Regulation (EU) 2024/1689), Article 12. High-risk AI systems must technically allow automatic recording of events over their lifetime. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  3. 3.ISO/IEC 42001:2023, Clauses 8.2 and 8.4 (assessments at planned intervals or when significant changes arise); ISO/IEC 42005:2025, Clause 5.4 (reassessment triggers, assessed before the change is deployed). https://www.iso.org/standard/81230.html
  4. 4.Michael Harris and Bill Tayler, “Don’t Let Metrics Undermine Your Business,” Harvard Business Review, September-October 2019. Surrogation: the strategy replaced by the number meant to track it. https://hbr.org/2019/09/dont-let-metrics-undermine-your-business
  5. 5.ISO/IEC 42001:2023, Clause 5 (top-management ownership of the organization’s current risk posture); NIST AI Risk Management Framework, GOVERN 2.3 and MANAGE 4.1 (executive responsibility for AI risk decisions as they are; post-deployment monitoring with mechanisms to supersede or deactivate). https://www.nist.gov/itl/ai-risk-management-framework

Frequently Asked Questions

Can we start AI governance when AI is already deployed?

Yes, and this methodology treats mid-flight entry as a first-class path rather than an exception to apologize for. Very few organizations are starting from zero. AI is already deployed, teams are already building, and governance exists in pieces, which is what responsible adoption looked like while everyone was learning. When the upstream decisions do not all exist, the team building enforcement does not invent them. It builds thin, interim versions of only the decisions the guardrails cannot run without, which the methodology calls the Minimum Viable Decision Layer, each sanctioned in writing by an executive and carrying a sunset date. The entry begins with a candid audit whose most common finding is near-miss rather than absence, so much of the work is salvage rather than construction.

Why does an AI agent need its own identity?

Because identity answers the two questions that matter most when something surprising happens. Who did that, and who can stop it? People and AI agents alike operate under their own credentials, scoped to the task at hand and expiring when the task ends, with every agent bound to a named human owner. Revoking an identity is the stop mechanism, designed and tested before it is ever needed rather than discovered during a live incident. The failure this prevents is documented well enough to have a name. OWASP calls it excessive agency, a system granted more functionality, permissions, or autonomy than its task ever needed.

Is AI we buy from a vendor governed differently from AI we build?

No. Vendor systems enter through the same classification checkpoint as anything built in-house, with contract terms that secure audit rights and incident notification, and a monitoring rhythm that catches the AI features vendors add in routine updates. A bought point solution never needed an enterprise redesign, and it never gets a private rulebook either. It classifies at intake, its handoff to human staff gets an oversight specification, and its vendor terms come through the same gate. That is what makes the estate one estate, so the organization's governance is never only as strong as its least-examined purchase.

How do you know whether AI governance is still working a year later?

Through a quarterly audit that tests behavior rather than binders. The governance board asks four questions and requires evidence for each. What work changed? What got caught? What got fixed? Which forum decided something that mattered? A governance program that can answer those with specifics is alive. One that cannot has started to become ceremony, and the audit catches that drift within a quarter of onset, while it is still a course correction rather than a rebuild. The year then closes at an annual gate, where four audit records, twelve monthly digests, the revalidations, and the re-signed policy re-authorize the next cycle.

Shawn Plaster, Founder & CEO of Plaster Group

About the author

Shawn Plaster

Founder & CEO, Plaster Group

Shawn is the author of Plaster Group's five-level AI Governance Methodology and its 3-article Insights series, and leads the firm's enterprise AI transformation work.

Previous: Article 2: The Business Decides

© 2026 Plaster Group, LLC. All rights reserved. This article may not be reproduced, distributed, or transmitted in any form without prior written permission from Plaster Group. Brief excerpts may be quoted for review or commentary purposes with attribution to the author and a link to the original article.

Ready to move forward?

Let's discuss how your organization can build with AI — securely, strategically, and starting from where you are today.

Start a Conversation