Somebody in the organization has to be able to say, on the record, whether AI is governed — not monitored, not blocked, governed. That word carries a specific meaning, and the distance between due care and due diligence is where most programs quietly sit.
Here is a sentence we hear, in some variation, from well-tooled security teams: “Between our AI security posture management and our data loss prevention rules, AI governance is handled.” Both named tools may be excellent. The sentence is still a category error, and the error has a predictable ending: strong tooling, and nothing defensible to hand over when the board, the auditor, or the underwriter asks how AI is governed. It is worth pulling the three layers apart, because each one answers a different question.
Layer one: observability answers “what is happening?”
AI security posture management (AI-SPM), CASB dashboards, network monitoring — the observability layer surfaces activity. It tells you a deployed agent has a misconfiguration, that traffic reached a model provider’s endpoint, that a data flow looks anomalous. This is genuinely necessary: you cannot govern a surface you cannot see, and the Discover stage of any honest program depends on observation. But telemetry has a short half-life and no clause anchor. A dashboard is a live view; it is not a dated record of a decision. We ran this experiment on ourselves — deployed a runtime guardrail in observe mode and published what it produced — and the receipts were exactly what the category predicts: findings without context, evidence without an owner, observability without governance.
Layer two: enforcement answers “what can’t happen?”
Data loss prevention, secure service edge policies, blocking rules — the enforcement layer stops specific flows. Also necessary, within its scope. But notice what a block actually is: a technical action, not a documented position. If your DLP blocks uploads to one AI endpoint and silently permits ninety others, what is your policy? Nobody decided; the rule set just grew. Enforcement without a governing document is arbitrary in the precise sense that matters legally — it does not evidence a considered, documented exercise of due care, and it cannot answer the question an auditor actually asks, which is not “what do you block?” but “who decided what, on what basis, and where is that written?”
Layer three: governance answers “prove what you decided.”
The governance layer produces the documented account: an observed AI inventory, a regulation-anchored acceptable-use policy that names who may use what and under which controls, a risk assessment with owners, a board record, and verification an outsider can check. This is the layer EU AI Act Article 17, ISO/IEC 42001, and the NIST AI RMF Govern function are written about — documented policies, procedures, and records, not feeds and not rules. And it is the layer that gives the other two their meaning: the enforcement rules become the implementation of a stated policy instead of an accident of configuration, and the telemetry becomes evidence that the policy operates instead of a stream nobody owns.
The three layers are complements, not competitors. A serious 2026 program runs observability, enforcement scaled to its risk, and a governance layer above both. The failure mode is buying the first two and believing you have the third — because the first two ship dashboards, and dashboards feel like coverage right up until someone asks for the document.
Observability tells you what happened. Enforcement decides what can’t. Governance proves what you decided.
The observe-mode guardrail trial referenced above is written up, with receipts and the vendor disclosure, in our August perspective. The five-stage method the governance layer implements lives on the AI Governance Playbook page.