The three questions

Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it.

The three questions Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it. The spine of the Body of Knowledge What AI is running? Layer 02 Inventory & Transparency What is it allowed to do? Layer 01 Govern-as-Code Layer 04 Runtime Controls & Observability What evidence proves it? Layer 03 Evals & Red Teaming as Evidence Layer 05 Assurance & Continuous Compliance
The three questions The three questions every AI governance function must answer from live systems, and the stack layers that answer each. If you cannot answer one of them for a system today, that is your first task. Drawn from chapter 01.

Text alternative

Three panels, one per question. What AI is running? Answered by Layer 02 Inventory & Transparency: the inventory and the agent registry, fed by a runtime data path. What is it allowed to do? Answered by Layer 01 Govern-as-Code and Layer 04 Runtime Controls & Observability: identity before autonomy, scope before action. What evidence proves it? Answered by Layer 03 Evals & Red Teaming as Evidence and Layer 05 Assurance & Continuous Compliance: evidence as a by-product of the build.

Download

Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.

Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it.
The PNG, light, 1600 px wide, as it downloads (shown here as a lighter copy).

Reuse and credit

The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:

“The three questions” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/three-questions), v0.5.0. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Embed with HTML

<figure>
  <img src="https://aigovernanceengineer.com/downloads/figures/three-questions-v0.5.0-light-1600.png" alt="Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it." width="800" height="798" loading="lazy">
  <figcaption>
    <a href="https://aigovernanceengineer.com/figures/three-questions">The three questions</a> by Jorge García Aibar,
    aigovernanceengineer.com, v0.5.0.
    Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
  </figcaption>
</figure>

Embed with Markdown

![Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it.](https://aigovernanceengineer.com/downloads/figures/three-questions-v0.5.0-light-1600.png)

*[The three questions](https://aigovernanceengineer.com/figures/three-questions) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*