Governance statements
A published statement of how an organisation works with AI, in two layers: the positions it holds, and how those positions are held. Nothing in it is calculated. No band is ever assigned to an organisation and a governance statement never produces a grade.
01.
What the object is
Two layers, in one document. A statement that published one and not the other would be half an object, and it is the second half that is usually missing.
Layer one
The positions
What the organisation deems acceptable, each expressed in a model the framework already publishes.
Ceilings per medium
Transparency Model
The maximum acceptable band, per medium, each with its reason
What AI may depict
Content Integrity Model
One rule across the visual media: permitted, not permitted, and why the line falls there
Consent
Content Integrity Model
What is required before AI manipulation of an identifiable person
Disclosure
Transparency Model
The minimum disclosure on AI-generated work
Review requirement
A governance rule
Whether work is reviewed before publication, and by whom
Ethics review trigger
Ethics Consideration Tool
When the tool is run before work begins
Expected of suppliers
Transparency Model
Whether vendors must disclose on delivery
Environmental posture
Environmental Impact Model
Whether a limit is set, including the case where none is
Layer two
How the positions are held
Who decides, what is fixed, how it changes, what happens at a breach, and what is admitted as undecided. Nothing here is expressed in a model, because none of it is a measurement.
Decision authority
Named, with input distinguished from approval
Fixed and operational
Every position marked as one or the other when it is written
Version log
Every change dated, with what changed and why, including corrections of the organisation's own errors
Exceptions
Who approves work outside a stated position, and where the exception is recorded
What has not been decided
Each open item with its route, and the rule that anyone reaching one asks first
Review
A cadence and a date rather than an intention
What the statement does not cover
Carried inside the statement, so a reader holding the artefact alone sees the boundary
02.
What a ceiling is
Every ceiling carries a reason
A reason is required, and a statement whose reasons are missing is not published. One or two sentences: long enough to say what was decided and on what grounds, short enough that nine read as a set rather than an appendix.
It is never behind a disclosure, never in a tooltip and never after the table. The reason sits on the row it explains, because a ceiling alone reads as a number and invites a reader to mistake a permission for a practice. The reasoning is the only thing on the page that shows a decision was taken rather than a default accepted.
A ceiling is a limit, not a description of practice
A ceiling states the most AI involvement an organisation deems acceptable for a kind of work. It does not say how much that organisation uses, and most work sits below its ceiling.
The framework's own site scored Considerable against a ceiling of Extensive. That gap is the normal case rather than an embarrassment, and reading a ceiling as a practice is the misreading the reasons exist to prevent.
A ceiling carries two values
Typical and maximum. What an organisation ordinarily does, and the most it permits. Each is labelled on its own line, because a row reading "typically Limited, up to Moderate" assumes the reader already knows what a ceiling is, and the reason both values are stated is that a maximum on its own was being read as a description of practice.
The maximum is the position. The typical is a description. Only the maximum is ever breached: work above what an organisation usually does is work that used more AI than usual, which is not a breach of anything.
Both sit on one rail. Filled to the typical, outlined from there to the maximum, and the run of outlined slots is the distance between what an organisation does and what it permits. A statement whose typical sits at its maximum is an organisation working at its own limit, and one with four outlined slots has left itself room it does not use. Neither is legible from two band names.
A stated typical says it was stated. Once the member application can count an organisation's own disclosures, an observed one says how many it was counted from, and the evidence sits in the same row as the permission. Nothing else about the row changes, because the difference between the two is where the value came from.
A ceiling may name its own exceptions
In the organisation's own words, one or two sentences, sitting with the ceiling they qualify and in the same place as the reason. "Illustrated treatments applied to our own photography are permitted and labelled as illustration."
An exception is a stated qualification rather than a category. The framework does not offer a list of exception types to pick from: those are unbounded, every organisation wants different ones, and a framework cannot ratify what it cannot maintain.
So an exception is checked by a reader rather than by a machine, which is true of the reasons too. It qualifies the position and it never changes a verdict.
A breach is never a lower score
Work above a ceiling, or outside a depiction condition, breaches the organisation's own position. The band stands as calculated, the code is unchanged and the points are unchanged, because a policy cannot retrospectively change a fact about a deliverable.
A breach resolves in one of two ways: the work changes, or the position changes in a new version of the statement. Contract section 3 settles it, and it is what keeps a ceiling from becoming a second scale.
03.
What a governance statement is not
Named, so that their absence reads as a line rather than an omission.
- Approved and prohibited tool lists, which date within weeks.
- Data classification, and what may be pasted where.
- Roles, permissions and access.
- Training plans.
- Contract clauses.
These are real governance questions and they are advisory work rather than framework material. This object covers the things the framework measures, and the value of publishing the pattern openly comes from the pattern being stable.
04.
The pattern is open. Checking it is what membership is.
Anyone can read this object, copy the structure and write a statement in a document. The framework publishes the instrument and always has.
What membership provides is what makes a statement operate: ceilings checked against every disclosure the organisation issues, a breach register with something generating breaches, the exception route as a recorded workflow, versioning with a real log, and the supplier expectation enforced when a supplier issues a disclosure.
A ceiling nobody checks is a wish. That is the honest difference between a document and governance.
Advisory is help deciding what the positions should be. Nine defensible ceilings is genuinely hard, and an organisation attempting it alone produces either nine defaults or a blank page.