The 0–9 Governance Stack
(A working sketch for a reasoning‑governance architecture)
Update September 11th 2026: Layer 9 Memory has been added.
This extends the governance stack introduced in The Architecture of Forgot
Institutions have always governed systems.
They have never governed reasoning.
AI has made that absence visible.
These notes map the layers from the physical world up to the mandate layer and show where reasoning governance should sit.
Layer 0 — The world before systems
Everything institutions try to interpret, influence or stabilise begins here: physical reality, human behaviour, markets, societies.
There is no governance here — only the reason governance exists.
Question: What is the world?
It asks what domain an institution claims to interpret, stabilise or intervene in. Without clarity here, every higher layer floats.
Layer 1 — Physical substrate
Hardware, compute, energy, thermodynamics. Systems exist as physical objects. No meaning, no intent, no reasoning. Institutions don’t control this layer; they control contracts about it.
Question: What exists physically?
This is the boundary between the institution and the material world. It defines what is actually “there” before any interpretation begins
Layer 2 — Data substrate
Raw signals. Measurements. Events. Records.
Not knowledge, not information, not thought.
Just signals.
Institutions have built heavy governance machinery here, but none of it touches meaning.
Question: What signals do we capture?
This determines what the institution chooses to notice and what it systematically ignores.
Layer 3 — Semantic Layer
Meaning, classification, ontology. Data becomes legible.
This is where signals acquire meaning through classification, ontology and context.
But this is only meaning‑management, not governance of reasoning.
Question: What do the signals mean?
This is where institutional interpretation begins and where semantic drift can undermine everything above it.
Layer 4 — Application layer
Workflows, logic, agents. Systems begin to act. Institutions respond with process governance and risk frameworks. But this governs behaviour, not thought.
Question: What can the system do?
This is the operational perimeter: the set of actions the institution allows a system to perform.
Layer 5 — Supervisory layer
Oversight, defensibility, explainability. Most AI governance sits here. It governs evidence, not intelligence. It looks backwards, not forwards.
Question: Can we observe and defend it?
This is the layer of auditability the institutional need to justify what happened, not to shape what should happen.
Layer 6 — Execution boundary
Authority, constraints, permissions. Layer 6 is the first layer where governance becomes directly coupled to institutional agency. It defines what an institution may do. But it assumes reasoning sits outside the system. That assumption no longer holds.
Question: What is it authorised to do?
Or more precisely: Who or what is actually authorised to act?
This is the layer where institutional action and system action begin to blur.
Layer 7 — Reasoning governance
The missing layer.
The layer institutions never built.
The layer AI forces into view.
This is governance of:
- what reasoning is admissible
- what reasoning is out of bounds
- which assumptions may be used
- which sources of authority may be invoked
- which contextual changes require re-evaluation
- which decisions require human/institutional judgement
- which reasoning cannot be delegated
Institutions govern data, processes, behaviour, and evidence.
They do not govern reasoning.
This is the blind spot.
Question: What reasoning is it authorised to employ?
This is the heart of reasoning governance => the cognitive perimeter of the institution.
Layer 8 — Mandate layer
Identity, purpose, legitimacy, non-delegability.
The layer that defines what the institution is and what it must never delegate.
Some reasoning is part of the mandate itself.
If an institution delegates reasoning without governing it, it delegates its mandate.
What must remain an institutional act, regardless of how capable the system becomes?
This is the real governance crisis.
Question: What must remain governed by institutional mandate?
This is the boundary between institutional identity and everything else.
Layer 9 — Memory Layer
Continuity, lineage and what an institution chooses not to forget.
Institutions do not make decisions from rules alone. They also rely on what happened before: earlier decisions, exceptions, failures, compromises and the reasons behind them.
Over time, that history becomes fragmented.
People leave, systems change and documents disappear. Decisions are often recorded without the discussion that led to them. After a few years, the rule may still exist while nobody remembers why it was introduced in the first place.
That is how institutional memory becomes institutional amnesia.
The Architecture of Forgot argued that forgetting is not simply an accident. It can be built into the way organisations work. Over time, assumptions become embedded in processes while the reasons behind them disappear. The decision remains, but its rationale is often lost.
An institution may still be able to follow its rules, while no longer understanding where those rules came from or whether the circumstances that produced them still exist.
AI makes this problem harder to ignore.
AI systems can carry enormous amounts of organisational information forward. But information is not the same as memory. A system needs to know what is authoritative, what is historical, what was an exception, what has been rejected, and why a decision was made.
Otherwise, old information remains in the system without the context that made it meaningful.
If an institution cannot remember the reasoning behind its mandate, it becomes difficult to govern the reasoning that follows from it.
What an institution remembers influences what it does next.
What it has forgotten can be just as important.
Question: What does an institution need to remember in order to remain itself?