Model type by deployment option

A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column.

Model type by deployment option A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column. Chapter 15 · Governing deployment and use What each combination adds Read each cell as the one control the combination adds on top of its row and its column. Illustrative, not a claim of conformity: the controls a real deployment needs follow from its risk tier, its obligations and its failure modes. Model type Classic predictive Generative, language Generative, multimodal Proprietary (API) Open-weight Where it runs Cloud Residency check on features; input drift monitor No-training and retention terms; output guardrail Provenance marks on output; biometric-use block Pin the version; boundary evals on every change Licence gate; hash-verified weights on rented compute On-premise Own the retraining pipeline and its approval Own guardrails, patching and energy metering Own content signing; media retention rules Vendor appliance: attest version and update path You own patching: AIBOM, file scans, red team Edge Signed model; field-version telemetry; remote rollback Small model; offline guardrails; signed updates Camera and microphone notices; on-device minimisation Vendor SDK: licence limits; offline revocation Weights are extractable: licence terms and threat model How it is adapted Fine-tune Retrain is a release: re-run per-group floors Full red team; safety-erosion eval Likeness and consent checks on tuning media Vendor tuning service: data terms; your own re-eval Compute log against the GPAI one-third criterion RAG Not typical; govern feature-store lineage instead Groundedness eval; corpus permissions; poisoning checks Cross-modal injection tests on retrieved media Your corpus, their model: retention and no-training terms Every layer of evidence is yours to produce Agentic wrapper Score triggers an action: human gate on adverse outcomes Agent identity, tool mediation, kill switch Screen and voice actions behind a human gate Grant scoped tools; the vendor agent gets its own identity Own guardrails end to end; no vendor safety layer Model types run across and deployment options down: the chapter prints the same matrix turned a quarter. Hybrid hosting, prompting only and distillation have their own rows in the chapter tables, not a cell here. Source: chapter 15, Governing deployment and use: The model-type by deployment-option matrix. As of 2026-09-24 · illustrative, not a claim of conformity
Model type by deployment option The one control each combination of model type and deployment option adds on top of its row and its column, from classic predictive to open-weight models and from cloud hosting to an agentic wrapper. Find your combination and check that its control is in place before the go-live review. Drawn from chapter 15.

Text alternative

Illustrative, not a claim of conformity: the controls a real deployment needs follow from its risk tier, its obligations and its failure modes. Five model types run across (classic predictive; generative, language; generative, multimodal; proprietary API; open-weight) and six options run down in two groups: where it runs (cloud, on-premise, edge) and how it is adapted (fine-tune, RAG, agentic wrapper). Each cell is the one control the combination adds on top of its row and its column: for example, a classic predictive model behind an agentic wrapper needs a human gate on adverse outcomes, because a score now triggers an action; a generative language model with RAG needs a groundedness eval, corpus permissions and poisoning checks; an open-weight model fine-tuned in house needs a compute log against the GPAI one-third criterion. Chapter 15 prints the same matrix with model types as rows; hybrid hosting, prompting only and distillation have their own rows in its tables but no cell here. The full grid is in the data table.

Data

The control each combination adds on top of its row and its column (illustrative)
Deployment optionClassic predictiveGenerative, languageGenerative, multimodalProprietary (API)Open-weight
CloudResidency check on features; input drift monitorNo-training and retention terms; output guardrailProvenance marks on output; biometric-use blockPin the version; boundary evals on every changeLicence gate; hash-verified weights on rented compute
On-premiseOwn the retraining pipeline and its approvalOwn guardrails, patching and energy meteringOwn content signing; media retention rulesVendor appliance: attest version and update pathYou own patching: AIBOM, file scans, red team
EdgeSigned model; field-version telemetry; remote rollbackSmall model; offline guardrails; signed updatesCamera and microphone notices; on-device minimisationVendor SDK: licence limits; offline revocationWeights are extractable: licence terms and threat model
Fine-tuneRetrain is a release: re-run per-group floorsFull red team; safety-erosion evalLikeness and consent checks on tuning mediaVendor tuning service: data terms; your own re-evalCompute log against the GPAI one-third criterion
RAGNot typical; govern feature-store lineage insteadGroundedness eval; corpus permissions; poisoning checksCross-modal injection tests on retrieved mediaYour corpus, their model: retention and no-training termsEvery layer of evidence is yours to produce
Agentic wrapperScore triggers an action: human gate on adverse outcomesAgent identity, tool mediation, kill switchScreen and voice actions behind a human gateGrant scoped tools; the vendor agent gets its own identityOwn guardrails end to end; no vendor safety layer

Source: Chapter 15, The model-type by deployment-option matrix (src/data/deployment-options.ts)

Download

Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.

A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column.
The PNG, light, 1600 px wide, as it downloads (shown here as a lighter copy).

Reuse and credit

The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:

“Model type by deployment option” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/deployment-option-matrix), v0.5.0, as of 2026-09-24. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Embed with HTML

<figure>
  <img src="https://aigovernanceengineer.com/downloads/figures/deployment-option-matrix-v0.5.0-light-1600.png" alt="A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column." width="800" height="1146" loading="lazy">
  <figcaption>
    <a href="https://aigovernanceengineer.com/figures/deployment-option-matrix">Model type by deployment option</a> by Jorge García Aibar,
    aigovernanceengineer.com, v0.5.0, as of 2026-09-24.
    Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
  </figcaption>
</figure>

Embed with Markdown

![A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column.](https://aigovernanceengineer.com/downloads/figures/deployment-option-matrix-v0.5.0-light-1600.png)

*[Model type by deployment option](https://aigovernanceengineer.com/figures/deployment-option-matrix) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0, as of 2026-09-24. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*