PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 23, 20260 citationsOpen Access

A Taxonomy of AI Governance Approaches: Distinguishing Visibility, Alignment, and Authorization

View Full Paper
EMEdward Meyman

Key Points

  • To resolve semantic ambiguity across AI governance technologies by establishing a formal, testable taxonomy that differentiates post-hoc visibility, probabilistic alignment, and deterministic pre-execution authorization.
  • Categorized existing AI governance claims into three functional tiers: visibility (what happened), alignment (general system safety), and authorization (pre-execution policy compliance).
  • Defined the normative architecture for deterministic AI governance, specifying a non-bypassable pre-execution authorization boundary and an ALLOW, DENY, ABSTAIN enforcement triad.
  • Established a machine-checkable conformance methodology grounded in the Five Tests Standard (Stop, Ownership, Replay, Escalation, and Provenance) to evaluate vendor governance claims.
  • Demonstrated that post-hoc observability cannot substitute for ex-ante authorization due to evidentiary artifact gaps that fail to prevent unauthorized runtime actions.
  • Specified requirements for tamper-evident authorization artifacts and Minimum Evidence Packages that allow independent third parties to reconstruct governance verdicts offline.
  • Formalized the ABSTAIN verdict state to block automated execution during indeterminate policy states or authority-reserved actions until an authorized human override is emitted.

Abstract

The term “AI governance” has become semantically overloaded, applied indiscriminately to logging, guardrails, model alignment, dashboards, and policy workflows. This paper introduces a formal taxonomy that distinguishes three fundamentally different governance problems: visibility (what happened), alignment (is the system generally safe), and authorization (was this specific action permitted under policy before it executed). It maps common vendor “governance” claims to the problems they actually solve. The taxonomy defines deterministic AI governance as a pre-execution authorization layer in which identical governed state yields identical governance verdicts and the system emits authorization artifacts from which an independent third party can reconstruct the verdict offline. The current capability tier is tamper-evident; signature-grade proofs are roadmap. It specifies the normative structure of governed state, the Minimum Evidence Package (Normative), an enforcement triad (ALLOW / DENY / ABSTAIN, where ABSTAIN blocks execution pending authorized human override), and disqualifying evaluation methods, including anti-laundering checks designed to prevent trust-based or vendor-dependent imitation of governance. FERZ Governance Doctrine (v1.1): Observability explains what happened. Enforcement determines what is allowed to happen. Enforcement is realized through a non-bypassable authorization boundary that emits a proof-carrying decision prior to execution. This work is intentionally testable and disqualifying rather than aspirational. It provides enterprise buyers, regulators, auditors, and researchers with a shared vocabulary and concrete conformance criteria for evaluating AI governance claims in high-stakes, regulated deployments. The framework is architecture-agnostic and may be applied to any AI governance solution. Update (August 2026, v1.7.1): Version 1.7.1 clarifies ABSTAIN to cover both the indeterminate case, where the applicable authorization state does not resolve the action, and the authority-required case, where policy reserves the action or action class for a named human authority; in both, execution remains blocked pending authorized human override, and an unresolved ABSTAIN remains ABSTAIN rather than converting to DENY. It states the human-resolution sequence at the runtime authorization boundary: the override supplies authority-bound input, the boundary emits the verdict, and execution depends on an affirmative ALLOW verdict emitted there. It scopes the human-in-the-loop comparison to review-only arrangements, corrects the categorical descriptions of guardrails and intent classification, and replaces the statement that authorization is non-delegable with the statement that delegation does not itself authorize a proposed action. Citations are updated to the Five Tests Standard in two-DOI form (concept 10.5281/zenodo.21040295; specification v1.2.0 10.5281/zenodo.21040296), to On the Impossibility of Observability-Based Authorization v1.4.0, and to The Authorization Artifact Test v1.1. The three-problem taxonomy, the deterministic governance definition, and the conformance methodology are unchanged. This record contains the v1.7.1 kit: the full taxonomy, an Executive Summary, a Vendor Evaluation Supplement, and Evidence Package Examples, each revised to the same ABSTAIN, review-only HITL, and boundary-verdict formulations. Update (July 2026, v1.7): Version 1.7 aligns Section 4.6 with the Five Tests Standard (5TS) v1.2.0: Stop, Ownership, Replay, Escalation, and Provenance. Provenance is the established origin of the inputs grounding a verdict; it is origin, not truth. The current machine-checkable conformance bundle covers the four predecessor tests; machine-checkable Provenance conformance is deferred until input-origin binding is specified. Artifact terminology is aligned to authorization artifacts and the Doctrine block is standardized at v1.1 across editions. Update (June 2026, v1.6): Version 1.6 aligned the taxonomy package with the predecessor Four Tests Standard, the Authorization Artifact Test, and FERZ Technical Advisory TA-2026-01, which names the artifact gap: the evidentiary condition that arises when observability is relied upon to satisfy an ex-ante authorization requirement. The companion evaluation kit was updated accordingly, and the Evidence Package Examples added an agentic tool-use example in which an external data transfer is blocked before dispatch. The Five Tests Standard, which adds Provenance as a fifth normative test, supersedes the Four Tests Standard for current-standard references as of v1.7. Update (Jan 2026): Released a companion evaluation kit including an Executive Summary (board/C-suite orientation), a Vendor Evaluation Supplement with decision logic for determining when authorization-layer governance is required, and Evidence Package Examples demonstrating independently replayable ALLOW, DENY, and ABSTAIN verdicts conformant with the Minimum Evidence Package requirements.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Edward Meyman (2026) studied this question.

synapsesocial.com/papers/6a8aae007677a34114446a7bhttps://doi.org/10.5281/zenodo.22037345
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1A Taxonomy of AI Governance Approaches: Distinguishing Visibility, Alignment, and Authorization2026 · 23 citations
  2. 2The Authorization Artifact Test: Applying the Impossibility Result to Ex-Ante Authorization Requirements2026 · 12 citations
  3. 3The Authorization Threshold: When an AI Action Qualifies as Pre-Execution Authorized2026 · 7 citations
  4. 4Observability Is Not Enforcement: A Doctrinal Framework for Distinguishing Compliance Instrumentation from Runtime Authorization in AI Governance Architectures (Working Paper v2.0)2026 · 16 citations
  5. 5Deterministic Governance Is Multi‐Dimensional: Beyond Bounded Execution Gating in AI Systems2026 · 7 citations