The fourth disclosure object

Governance statements

A published statement of how an organisation works with AI, in two layers: the positions it holds, and how those positions are held. Nothing in it is calculated. No band is ever assigned to an organisation and a governance statement never produces a grade.

01.

What the object is

Two layers, in one document. A statement that published one and not the other would be half an object, and it is the second half that is usually missing.

Layer one

The positions

What the organisation deems acceptable, each expressed in a model the framework already publishes.

Ceilings per medium

Transparency Model

The maximum acceptable band, per medium, each with its reason

What AI may depict

Content Integrity Model

One rule across the visual media: permitted, not permitted, and why the line falls there

Consent

Content Integrity Model

What is required before AI manipulation of an identifiable person

Disclosure

Transparency Model

The minimum disclosure on AI-generated work

Review requirement

A governance rule

Whether work is reviewed before publication, and by whom

Ethics review trigger

Ethics Consideration Tool

When the tool is run before work begins

Expected of suppliers

Transparency Model

Whether vendors must disclose on delivery

Environmental posture

Environmental Impact Model

Whether a limit is set, including the case where none is

Layer two

How the positions are held

Who decides, what is fixed, how it changes, what happens at a breach, and what is admitted as undecided. Nothing here is expressed in a model, because none of it is a measurement.

Decision authority

Named, with input distinguished from approval

Fixed and operational

Every position marked as one or the other when it is written

Version log

Every change dated, with what changed and why, including corrections of the organisation's own errors

Exceptions

Who approves work outside a stated position, and where the exception is recorded

What has not been decided

Each open item with its route, and the rule that anyone reaching one asks first

Review

A cadence and a date rather than an intention

What the statement does not cover

Carried inside the statement, so a reader holding the artefact alone sees the boundary

02.

What a ceiling is

Every ceiling carries a reason

A reason is required, and a statement whose reasons are missing is not published. One or two sentences: long enough to say what was decided and on what grounds, short enough that nine read as a set rather than an appendix.

It is never behind a disclosure, never in a tooltip and never after the table. The reason sits on the row it explains, because a ceiling alone reads as a number and invites a reader to mistake a permission for a practice. The reasoning is the only thing on the page that shows a decision was taken rather than a default accepted.

A ceiling is a limit, not a description of practice

A ceiling states the most AI involvement an organisation deems acceptable for a kind of work. It does not say how much that organisation uses, and most work sits below its ceiling.

The framework's own site scored Considerable against a ceiling of Extensive. That gap is the normal case rather than an embarrassment, and reading a ceiling as a practice is the misreading the reasons exist to prevent.

A ceiling carries two values

Typical and maximum. What an organisation ordinarily does, and the most it permits. Each is labelled on its own line, because a row reading "typically Limited, up to Moderate" assumes the reader already knows what a ceiling is, and the reason both values are stated is that a maximum on its own was being read as a description of practice.

The maximum is the position. The typical is a description. Only the maximum is ever breached: work above what an organisation usually does is work that used more AI than usual, which is not a breach of anything.

Both sit on one rail. Filled to the typical, outlined from there to the maximum, and the run of outlined slots is the distance between what an organisation does and what it permits. A statement whose typical sits at its maximum is an organisation working at its own limit, and one with four outlined slots has left itself room it does not use. Neither is legible from two band names.

A stated typical says it was stated. Once the member application can count an organisation's own disclosures, an observed one says how many it was counted from, and the evidence sits in the same row as the permission. Nothing else about the row changes, because the difference between the two is where the value came from.

A ceiling may name its own exceptions

In the organisation's own words, one or two sentences, sitting with the ceiling they qualify and in the same place as the reason. "Illustrated treatments applied to our own photography are permitted and labelled as illustration."

An exception is a stated qualification rather than a category. The framework does not offer a list of exception types to pick from: those are unbounded, every organisation wants different ones, and a framework cannot ratify what it cannot maintain.

So an exception is checked by a reader rather than by a machine, which is true of the reasons too. It qualifies the position and it never changes a verdict.

A breach is never a lower score

Work above a ceiling, or outside a depiction condition, breaches the organisation's own position. The band stands as calculated, the code is unchanged and the points are unchanged, because a policy cannot retrospectively change a fact about a deliverable.

A breach resolves in one of two ways: the work changes, or the position changes in a new version of the statement. Contract section 3 settles it, and it is what keeps a ceiling from becoming a second scale.

03.

What a governance statement is not

Named, so that their absence reads as a line rather than an omission.

  • Approved and prohibited tool lists, which date within weeks.
  • Data classification, and what may be pasted where.
  • Roles, permissions and access.
  • Training plans.
  • Contract clauses.

These are real governance questions and they are advisory work rather than framework material. This object covers the things the framework measures, and the value of publishing the pattern openly comes from the pattern being stable.

04.

The pattern is open. Checking it is what membership is.

Anyone can read this object, copy the structure and write a statement in a document. The framework publishes the instrument and always has.

What membership provides is what makes a statement operate: ceilings checked against every disclosure the organisation issues, a breach register with something generating breaches, the exception route as a recorded workflow, versioning with a real log, and the supplier expectation enforced when a supplier issues a disclosure.

A ceiling nobody checks is a wish. That is the honest difference between a document and governance.

Advisory is help deciding what the positions should be. Nine defensible ceilings is genuinely hard, and an organisation attempting it alone produces either nine defaults or a blank page.