Skip to content
CoherenceResearch
ArticlesARTICLE

The Layer Governance Frameworks Don’t Reach

AuthorJason Carroll
Published2026-04-12
Reading6 min

Every serious conversation about AI governance eventually hits the same question: what are you actually governing?

Most frameworks answer with risk models, behavioral controls, output monitoring, and organizational process requirements. They specify how decisions get made, who reviews what, which thresholds trigger escalation. These are meaningful answers. But they all share an assumption that never gets checked: that the structural foundations of the system being governed are sound.

SC-AS doesn’t assume that. It addresses it directly. And that places it in a different layer: the structural layer that governance frameworks rest on.

The layer governance frameworks don’t reach

NIST AI RMF, ISO 42001, EU AI Act. These operate at the policy layer. They specify processes, roles, controls, documentation requirements. They’re valuable. They’re also downstream of a question that never gets asked:

Are the structural configurations this system can reach admissible in the first place?

Not “what might go wrong.” That’s the probabilistic risk framing, and it requires enumerating failure modes you may not be able to enumerate. Not “what policies govern this system.” That’s assuming the governance instruments are attached to something structurally coherent.

The prior question is structural: what conditions must a configuration satisfy to be admissible at all, independent of what the system encounters, independent of what failure modes we’ve anticipated?

That’s the question SC-AS answers. And it answers it formally.

Why the structural layer is prior

This isn’t a philosophical preference about the order of operations. It’s a structural fact about what governance instruments can and cannot do.

Governance frameworks operate on observable properties of a system: its outputs, its behaviors, its documentation, its organizational structure. These are real and important. But they’re all downstream of the system’s structural configuration — the set of states it can occupy, the transitions between those states, and the identity conditions that determine whether it remains the same system across those transitions.

When a governance framework specifies that a system must not produce certain outputs, it’s placing a constraint on the observable surface. The structural question is different: can the system reach configurations from which those outputs are structurally forced, regardless of intent? If the answer is yes, then the policy constraint is a control on a symptom. It may slow the failure. It doesn’t address the structural condition that makes the failure reachable.

The structural layer is prior because it determines the possibility space within which policy operates. A governance framework that doesn’t characterize the structural possibility space of the system it’s governing is, in a precise sense, ungrouped. It’s making commitments about a system it hasn’t described.

SC-AS formalizes what it means to describe that structural possibility space. Specifically, it formalizes the conditions under which a configuration is admissible — where admissibility is not a policy judgment, but a structural property derived from the axioms.

What “formal” actually means here

SC-AS is an axiomatic system. It starts from primitive definitions — identity, interaction, change — and derives admissibility conditions from those primitives through explicit necessity proofs. Every term traces to the primitives. Every condition carries its derivation chain. Nothing enters the specification that isn’t structurally forced by what came before it.

This is not how governance frameworks are built. Governance frameworks are built from expert consensus, regulatory precedent, risk management practice, organizational experience. That’s the right way to build governance frameworks. It’s the wrong way to build a structural foundation.

A configuration either satisfies the SC-AS admissibility conditions or it doesn’t. That verdict doesn’t depend on organizational context, risk appetite, or expert judgment. It’s a structural fact about the configuration.

This is what “independently verifiable” means in practice. Not that a third party audit firm signs off on the process — anyone willing to trace the derivation chain can check the claim. The specification defines its own conformance criteria internally. You don’t need to trust the people who wrote it to determine whether a given configuration satisfies it.

The failure mode of confusing the two layers

Here’s what happens when you apply governance frameworks without a structural foundation: you govern the outputs of a system whose internal coherence has never been formally verified. You build controls around behaviors that emerge from a structure you haven’t characterized. You enforce policies on something you don’t have a structural description of.

This works until it doesn’t. At scale, under distribution shift, under adversarial pressure, under the kind of deployment conditions that no policy document anticipated — incoherent structural foundations fail. In ways the governance framework wasn’t designed to catch. Because it was operating at the policy layer, not the structural layer.

The more subtle version of this failure is drift. A system that was structurally sound at deployment can reach structurally inadmissible configurations through a sequence of individually permissible transitions. Each step passes the governance check. The trajectory doesn’t. If you have no formal characterization of the structural possibility space, you have no way to detect when the trajectory has crossed into inadmissible territory — only when it produces an output that triggers a policy threshold. By that point, the structural condition that produced the output is already established.

SC-AS addresses this at the design level, not the observation level. The admissibility conditions apply to configurations, not outputs. The gate is structural, not behavioral. This is why the specification has to be axiomatic — because the admissibility of a configuration has to be determinable from its structural properties, not inferred from its behavior over time.

SC-AS is the layer below governance frameworks: the one that makes “this system is structurally coherent” a verifiable claim rather than an assumption.

What SC-AS actually does

It specifies three verifiable structural conditions that any coherent configuration must satisfy:

  • Identity that persists — what must remain invariant for a system to remain itself across time, scale, and perturbation. This is the condition that prevents a system from drifting into being a structurally different system while appearing to be the same one.
  • Interaction that stays bounded — the adjacency and composition relationships that carry coherence across system boundaries. Unbounded interaction is the structural mechanism of coherence failure under scale and composition.
  • Change that stays admissible — the redistribution of structural content along pathways that preserve integrity. Not all change is inadmissible — only change that destroys structural content or crosses the identity boundary without a declared transition.

These conditions are formally derived from primitive definitions. They apply to any system where structure matters — AI architectures, organizations, governance structures, formal theories. The domain changes. The structural conditions don’t.

The specification is crushingly rigorous. It is intentionally not accessible to casual reading. Every term carries a necessity proof, a minimality proof, and an explicit admissibility interface. The Five Rigors — Austerity, Minimal Necessity, Coherence, Conservation, Fidelity — are independent formal audit dimensions that every derived specification must pass before publication. These aren’t quality gates bolted onto a finished product. They’re the discipline that determines what enters the specification in the first place.

This is not hype prevention. It’s structural necessity. A foundation that bends under examination isn’t a foundation.

How the two layers work together

Governance frameworks address the policy layer: who decides what, how risk is managed, what documentation is required, what organizational controls apply. SC-AS addresses the structural layer below: what configurations are admissible to exist at all.

A well-governed AI system on an incoherent structural foundation is precisely governed failure. A structurally coherent system without governance is a coherent system that still needs policy, accountability, and human oversight.

The layers are complementary. Neither replaces the other. But the structural layer has to exist and has to be formally verified before governance at the policy layer can be meaningful. Governance without structural characterization is policy applied to a black box. It may constrain the observable surface. It cannot characterize what the system is capable of reaching.

The work of making structural coherence formally describable and independently verifiable is what SC-AS is for. It gives governance somewhere structurally sound to stand.


SC-AS v1.0 is available now — open, CC BY-ND 4.0, DOI-archived on Zenodo. Read the specification →

Cite this articleCarroll, J. (2026). The Layer Governance Frameworks Don’t Reach. Coherence Research. coherenceresearch.com/articles/the-layer-governance-frameworks-dont-reach
Published 2026-04-12History