As artificial intelligence systems transition from advisory tools to delegated and agentic decision-makers, a structural governance gap emerges: existing frameworks define controls and accountability, but do not formally model the layers at which decisions acquire legal, organizational, and economic standing. ISO/IEC 42001 establishes a management system for AI, yet its orientation remains primarily horizontal, focusing on process and risk rather than the vertical topology of authority. This paper introduces Decision Layer Analysis (DLA) as a control-plane extension to ISO/IEC 42001. DLA defines a vertical authority architecture spanning capability, delegation, authorization, constraint, identity, and sovereignty, and identifies the binding points at which AI-mediated outputs transition into institutional actions. It formalizes a new governance risk class—Authority Drift—in which delegated systems acquire de facto standing faster than escalation, refusal, and revocation mechanisms are structurally enforced. By mapping DLA to the High-Level Structure and Annex A controls of ISO/IEC 42001, the paper provides audit-grade primitives for authority binding, structural refusal, and jurisdictional traceability. The framework shifts AI governance from a focus on technical behavior and procedural oversight to enforceable standing and decision legitimacy, enabling boards, regulators, and conformity assessment bodies to evaluate not only whether systems are safe, but whether they are authorized to decide.
MacFarland (Wed,) studied this question.