-
Notifications
You must be signed in to change notification settings - Fork 0
2026 05 06 ai capability reference architecture security supply chain update
Integrating 2026-05 security and supply chain findings into the enterprise Artificial Intelligence capability reference architecture
How should the enterprise Artificial Intelligence (AI) ecosystem capability reference architecture (as expressed in 2026-04-22-enterprise-ai-capability-model and the 2026-05-05-enterprise-ai-capability-stack Knowledge synthesis) be revised and extended to incorporate findings from the 2026-05 research cycle on: Software Bill of Materials (SBOM) and Artificial Intelligence Bill of Materials (AIBOM) conceptual gaps and schema design; AI supply chain risk and runtime composition integrity; the enterprise AI security threat model covering prompt injection, Retrieval-Augmented Generation (RAG)-based attacks and model supply chain compromise; automated governance assurance and change-control verification; and AI evaluation frameworks?
In scope:
- Gap analysis: which capability domains in the existing reference architecture are absent or underspecified relative to the 2026-05 completed items
- SBOM/AIBOM integration: how AI Bill of Materials concepts (provenance graph, runtime divergence, identity and attribution, schema standards alignment) fit into the architecture as first-class supply-chain capabilities
- Supply chain risk layer: where in the layered architecture supply-chain integrity controls belong, how they interact with the model registry, artifact promotion pipelines, and runtime observation
- Security threat model integration: mapping the security capabilities (prompt injection defense, RAG poisoning controls, model supply chain compromise mitigations, data exfiltration guards) to specific architectural layers and control surfaces
- Governance assurance integration: how automated change-control verification and governance gating fit into the delivery pipeline and control-plane components
- Evaluation capability integration: how AI skill evaluation and meta-analysis standards inform the observability and quality-gate layers of the architecture
- Revised architectural diagram (component list and layering) and updated capability ownership recommendations
Out of scope:
- Implementation guidance for specific vendor products
- Original research into supply chain standards (rely on already-completed items)
- Cost modelling or tooling selection for individual capability domains
Constraints:
- Must build on and extend (not replace) the existing reference architecture in
2026-04-22-enterprise-ai-capability-modeland the2026-05-05-enterprise-ai-capability-stackKnowledge item - All claims must cite the completed 2026-05 items or their primary sources; no new primary research required
- Output must be a revised Knowledge item (or versioned amendment to the existing
enterprise-ai-capability-stacksynthesis), and it must not duplicate content already in source items
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] The current enterprise Artificial Intelligence (AI) reference architecture is expressed as a five-layer stack, data and knowledge, model and inference, orchestration, delivery and platform engineering, and operating model, with a shared control core around policy, identity, observability, and evaluation.
- [fact; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html] The completed 2026-05 research cycle adds new evidence on Artificial Intelligence Bill of Materials (AIBOM) design, runtime divergence, identity delegation, supply-chain integrity, layered security controls, automated governance assurance, and evaluation discipline.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html] Without an update, the reference architecture understates the control surfaces now required for model provenance, retrieval integrity, delegated authority, runtime evidence, and release-time governance.
-
Gap mapping: Read the existing reference architecture (
2026-04-22-enterprise-ai-capability-model,2026-05-05-enterprise-ai-capability-stack) and the newly completed items. For each completed item, list: (a) which capability domain it informs, (b) which architectural layer it belongs to, and (c) whether a gap currently exists in the architecture. -
SBOM/AIBOM capability integration: Using
2026-05-06-aibom-sbom-conceptual-gaps-theory,2026-05-06-aibom-schema-design-standards-alignment,2026-05-06-aibom-identity-delegation-trust-theory, and2026-05-06-aibom-runtime-generation-divergence-theory, determine the minimum AIBOM capability set (provenance graph generation, schema-conformant output, runtime-divergence detection, identity and attribution tracking) that must appear as explicit architectural components. -
Supply chain risk layer: Using
2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chainand2026-02-28-ai-control-testing-and-assurance, establish where supply-chain integrity controls (model registry signing, artifact lineage, trojan weight detection, supply-chain audit) belong in the architecture and how they interact with the delivery pipeline layer. -
Security capability integration: Map the security capabilities from
2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain(prompt injection defense, RAG poisoning controls, exfiltration guards, runtime monitoring) to specific architectural layers, filling gaps against the existing control-surface architecture in2026-04-26-ai-lowcode-governance-enforcement-architecture. -
Governance assurance integration: Using
2026-04-22-ai-governance-assurance-change-control-verificationand2026-04-30-explainable-ai-xai-regulation-governance, determine how automated change-control verification, explainability requirements, and regulatory evidence generation fit into the control-plane and delivery-pipeline components. -
Evaluation capability integration: Using
2026-05-02-meta-analysis-standards-and-ai-skill-evaluation, identify which evaluation and quality-gate capabilities are absent from the architecture and where they should be inserted (model evaluation gates, quality benchmarks, systematic review processes for AI outputs). -
Synthesis: Produce an updated architectural component list (layers, components, ownership), a revised layered diagram, and delta findings showing what has changed from the prior version. Record as a versioned amendment to
2026-05-05-enterprise-ai-capability-stackor as a new Knowledge item (decide based on the scope of change).
- Mitchell (2026) Enterprise AI capability model for use-case maturity decisions - five-layer baseline architecture and foundational capability domains
- Mitchell (2026) Enterprise capability stack for sustainable multi-provider Artificial Intelligence - current synthesis baseline to be extended
- Mitchell (2026) Why does Software Bill of Materials fail as a complete inventory model for agentic AI workloads, and what new conceptual abstractions are required? - provenance-graph argument for AIBOM
- Mitchell (2026) What is the minimal viable schema for an Artificial Intelligence bill of materials, and how should it align with CycloneDX and SPDX? - declared AIBOM schema and standards alignment
- Mitchell (2026) How should identity, delegation chains, and permission scopes be formally modelled in an AIBOM schema? - delegation and permission-manifest requirements
- Mitchell (2026) How can a runtime-observed AIBOM be generated, and how much does it diverge from the declared design-time AIBOM? - runtime evidence and divergence taxonomy
- Mitchell (2026) What security capabilities are required in an enterprise Artificial Intelligence system to address prompt injection, Retrieval-Augmented Generation attacks, model supply chain compromise, and data exfiltration? - layered security capability set
- Mitchell (2026) Automated governance assurance and change control verification patterns for AI-assisted delivery - automated governance and evidence pipeline
- Mitchell (2026) Meta-analysis standards and Artificial Intelligence skill evaluation - evaluation and review-quality discipline
- Mitchell (2026) Explainable Artificial Intelligence (XAI) regulation and governance - explainability as governance evidence
- Mitchell (2026) AI agent control-plane architecture in the enterprise - centralized policy and distributed enforcement
- Mitchell (2026) AI and low-code governance enforcement architecture - control-surface placement across layers
- Mitchell (2026) AI agent identity and access management in the enterprise - machine identity and delegation controls
- Mitchell (2026) Permission-safe Retrieval-Augmented Generation enterprise information architecture - authoritative retrieval permissions and provenance
- National Institute of Standards and Technology AI Risk Management Framework Core - lifecycle governance and traceability outcomes
- Google Cloud What is Retrieval-Augmented Generation? - authoritative definition of Retrieval-Augmented Generation
- CycloneDX Introduction to AI/ML-BOM - standards coverage for models, datasets, and configurations
- Open Worldwide Application Security Project AIBOM - AI bill-of-materials transparency and auditability goals
(Full output from running the research skill, retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)
- Question: how should the existing enterprise Artificial Intelligence capability reference architecture be revised so that supply-chain provenance, layered security, governance assurance, and evaluation become explicit enterprise capabilities?
- Scope: extend the existing architecture rather than replace it; map the new evidence to layers, components, ownership, and review gates; avoid vendor-specific implementation guidance.
- Constraints: rely on completed repository items and the primary sources they already surfaced; keep output as architecture synthesis rather than fresh empirical research.
- Output: knowledge, specifically a revised layered architecture, component delta, and ownership model that can inform a later Knowledge-item update.
- Prior completed items reviewed before investigation: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html ; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md ; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html ; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html ; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html ; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html ; https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html ; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html ; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html ; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html ; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html ; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html ; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html ; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html ; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html
- Root question: what architectural changes are required so the enterprise reference architecture reflects the 2026-05 evidence set rather than only the April baseline?
-
A. Baseline and delta
- A1. Which capabilities are already present in the baseline five-layer model?
- A2. Which control surfaces from the newer items are absent or under-specified in that baseline?
-
B. AIBOM and supply-chain capability
- B1. Which declared AIBOM components must exist before release?
- B2. Which runtime-observed AIBOM components must exist after deployment?
- B3. Where do identity, delegation, and runtime-divergence controls belong?
-
C. Security capability placement
- C1. Which security controls belong in data and knowledge rather than in model runtime?
- C2. Which controls belong in orchestration and delivery rather than in the gateway alone?
- C3. Which controls must remain cross-layer?
-
D. Governance assurance and explainability
- D1. Which evidence and change-control capabilities must be part of the architecture?
- D2. How should explainability be represented, as model technique, process artifact, or both?
-
E. Evaluation capability
- E1. Which evaluation gates are now required before release?
- E2. Which evaluation and monitoring capabilities remain required during runtime?
-
F. Ownership and synthesis
- F1. Which components should remain centrally owned?
- F2. Which components can remain domain-local on top of shared rails?
- F3. Should the update preserve the five-layer stack, or replace it with a different shape?
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html] The baseline enterprise capability model organizes enterprise Artificial Intelligence into five layers, data and knowledge, model and inference, orchestration, delivery and platform engineering, and operating model.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] The capability-stack synthesis already argues for a shared control core around policy, identity, observability, vendor approval, and evaluation, with low-code and pro-code variation above that core rather than below it.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html] The baseline is structurally reusable, but it under-specifies model provenance, retrieval integrity, delegated authority, signed promotion, runtime divergence detection, and evidence-generation loops.
- [fact; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The conceptual-gaps item concludes that traditional Software Bill of Materials remains useful for software dependencies, but a complete Artificial Intelligence Bill of Materials needs a provenance-oriented graph that also captures prompts, retrieval surfaces, memory, authority, and realized execution paths.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/] The schema item shows that CycloneDX and Open Worldwide Application Security Project AIBOM work already cover models, datasets, and configuration metadata better than classic SBOM, but still require explicit extensions for prompts, tool manifests, memory schemas, and execution-context bindings.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html] The identity item concludes that auditable multi-agent operation requires typed identity inventory, explicit delegation chains, permission manifests, trust-boundary metadata, and attribution requirements rather than flat component lists.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html] The runtime-divergence item concludes that observed runs differ across retrieval set, memory state, caller authority, orchestration path, external state, and active guardrails, so declared and observed architecture artifacts must both exist.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html] The security-threat item identifies model supply-chain compromise, unsafe artifact loading, and registry provenance weakness as distinct risk classes beyond prompt misuse.
- [inference; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html] The architecture therefore needs three explicit supply-chain capabilities: declared AIBOM generation before release, signed registry and artifact lineage during promotion, and runtime-observed AIBOM plus divergence detection after deployment.
- [fact; source: https://cloud.google.com/use-cases/retrieval-augmented-generation; https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html] The security-threat model treats prompt injection, Retrieval-Augmented Generation (RAG) poisoning and leakage, model supply-chain compromise, and data exfiltration as interacting but distinct attack classes.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] The governance-enforcement architecture assigns different control responsibilities to gateways, data systems, orchestration runtimes, model runtimes, and applications because no single layer can close every bypass path.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html] The permission-safe RAG item concludes that retrieval permissions and source-of-truth authorization must remain authoritative in the data and knowledge layer rather than being copied into orchestration metadata.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html] The control-plane item concludes that enterprise governance needs centralized policy administration and translation with distributed enforcement adapters rather than one universal gateway or one universal vendor plane.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] The identity item shows that machine identity, delegation, and attribution are first-order enterprise controls rather than local runtime settings.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html] The revised architecture should place retrieval integrity, classification, and permission truth in data and knowledge; semantic safety and model-facing guardrails in model and inference; tool and connector constraints in orchestration; and artifact promotion, attestation, and policy gating in delivery and platform engineering.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The governance-assurance item concludes that near-machine-speed governance requires provenance evidence, policy-decision evidence, risk-tiered enforcement, and explicit exception routing rather than only manual Change Advisory Board review.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html] The explainability item concludes that regulated explainability is mainly a governance capability built from logging, documentation, audience-specific explanation artifacts, oversight, and challenge, not a mandate to adopt one Explainable Artificial Intelligence technique.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html] The control-testing item concludes that automated evidence is acceptable only when validation, documentation, and explicit human accountability remain visible.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html] Governance, explainability, and assurance should therefore be modeled as one shared evidence plane that binds policy decisions, release evidence, runtime evidence, evaluation results, incident records, and audience-specific explanation artifacts.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html] The evaluation item concludes that high-quality Artificial Intelligence output needs explicit evidence maps, structured review criteria, and stronger upstream evaluation artifacts than ad hoc judgement alone.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] The capability-stack synthesis already identifies evaluation as part of the shared enterprise control core rather than a team-local optional practice.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html] The capability model places evaluation and measurement in the foundational layer because reuse is unsafe when benchmarks, thresholds, and monitoring do not already exist.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html] The architecture should treat evaluation as a formal gate at both promotion time and runtime, with benchmark harnesses, adversarial tests, confidence thresholds, and post-deployment drift signals feeding the same evidence plane.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html] The baseline synthesis favors a shared enterprise core with differentiated experiences above it rather than provider-specific governance silos.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html] The best-supported update preserves the five-layer stack but adds two explicit cross-cutting planes, supply-chain and provenance, plus policy, evaluation, and evidence, because those capabilities now span every layer rather than fitting cleanly inside one of them.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] The existing architecture already provides a usable layered frame and a shared-core principle.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html] The new AIBOM items collectively require explicit design-time provenance, delegation semantics, and runtime-divergence handling.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] The security evidence supports layered control placement rather than a one-layer fix.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html] Governance assurance, evaluation, and explainability all depend on reusable evidence-generation capabilities.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html] Because declared-versus-observed divergence and review-time evidence both span every layer, they are better represented as cross-cutting planes than as one more vertical layer.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] Central ownership should cover policy, identity semantics, provenance schema, evaluation standards, and evidence retention, while domain teams should own local knowledge, workflows, and risk-calibrated operating thresholds on top of those rails.
- [assumption; source: https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html] Enterprises can adopt a minimum viable declared AIBOM before one universal cross-vendor standard exists, because current standards coverage is partial but already sufficient to anchor models, datasets, configurations, and extensions.
- [assumption; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html] High-risk systems can expose enough runtime traces and policy logs to support declared-versus-observed comparison, even if some commercial tool surfaces still require adapters.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html] Tension: the baseline favors a stable five-layer model, while the new evidence introduces capabilities that span every layer. Resolution: preserve the five layers, but add explicit cross-cutting planes for provenance and evidence rather than replacing the stack.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/] Tension: AIBOM standards are incomplete, yet the architecture now needs AIBOM as a first-class capability. Resolution: require a minimum viable internal schema now and treat standards convergence as an external dependency, not a reason to omit the capability.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html] Tension: explainability can look like a model-science concern, while assurance evidence looks like a governance concern. Resolution: model explainability artifacts as part of the shared evidence plane, with model techniques contributing supporting artifacts rather than replacing governance records.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md] Tension: evaluation already exists in the shared core, but the new cycle sharpens its role. Resolution: keep evaluation in the shared core and make its build-time and runtime gates explicit in the revised architecture.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html] Technical lens: the most consequential architectural shift is from static inventory toward linked declared and observed control objects, because runtime composition, delegation, and retrieval behavior materially affect security and audit.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html] Regulatory lens: lifecycle governance, traceability, and audience-specific evidence requirements reinforce the need for a persistent evidence plane instead of one-time release approval.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html] Economic lens: shared provenance, evaluation, and policy services are reusable enterprise rails, so centralizing them reduces duplicated governance effort more than centralizing domain-specific workflow logic would.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html] Behavioural lens: the evidence set keeps converging on the same organizational bottleneck, verification capacity, so evaluation and evidence-generation are not secondary observability concerns but primary scale constraints.
(This section seeds the Findings below.)
Executive summary:
- The existing five-layer enterprise Artificial Intelligence reference architecture remains usable only if it is extended with explicit supply-chain provenance, runtime-governance, and evaluation services that operate across every layer. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html]
- The most important revision is to treat declared Artificial Intelligence Bill of Materials (AIBOM) generation, delegated-identity capture, signed model and artifact lineage, and declared-versus-observed runtime divergence as first-class architectural components rather than as optional logging detail. [inference; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
- Security control placement should remain layered, with authoritative retrieval and permission controls in data and knowledge, semantic safety in model and inference, tool and connector constraints in orchestration, and signed promotion plus policy gates in delivery and platform engineering. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html]
- Governance, explainability, and evaluation should be unified as a shared evidence plane that decides what may ship, what may run, and what records must exist for audit, incident response, and regulatory review. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html]
Key findings:
- What changes the baseline most is not the five-layer frame itself, but the need to make provenance, runtime evidence, and evaluation explicit architectural components instead of leaving them implicit inside the shared core. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html)
- A release process without declared Artificial Intelligence Bill of Materials (AIBOM) generation, model and artifact signing, registry lineage, delegated-identity manifests, and runtime-divergence detection cannot reliably explain both what an enterprise AI system was approved to do and what it later executed across heterogeneous runtime stacks. ([inference]; medium confidence; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html)
- No reviewed source supports a gateway-only answer, because retrieval permission truth belongs in the data layer, semantic guardrails belong in the model layer, tool and connector constraints belong in orchestration, and signed promotion plus policy verification belong in delivery. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
- Enterprise agent architectures need identity controls that describe multi-hop human, workload, and tool relationships, because delegation chains, permission manifests, and trust boundaries determine which actions are attributable and valid. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
- Governance that stops at release time is too narrow, because provenance, policy-decision logs, exception routing, explainability artifacts, and human sign-off all need to persist beyond one deployment event to support later review and incident handling. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html)
- Evaluation has to sit on both sides of release, because benchmark harnesses, adversarial checks, confidence thresholds, and drift signals determine whether higher-autonomy systems remain governable after deployment rather than only whether they looked acceptable in design review. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html)
- The cleanest way to absorb the new evidence is to preserve the five vertical layers while adding two explicit cross-cutting planes, one for supply-chain and provenance and one for policy, evaluation, and evidence. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html)
- On ownership, the evidence favors central stewardship of policy, identity semantics, provenance schema, security baselines, evaluation standards, and evidence retention, while domain teams continue to own local knowledge, workflow design, and risk-calibrated operating thresholds. ([inference]; medium confidence; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
Evidence map:
Assumptions:
- Assumption: enterprises can implement a minimum viable declared AIBOM before external standards converge on one canonical schema. Justification: current CycloneDX and OWASP AIBOM coverage is partial but already sufficient to anchor models, datasets, configuration, and typed extensions. [assumption; source: https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html]
- Assumption: high-risk enterprise systems can expose enough runtime events and policy logs to compare approved architecture against observed execution. Justification: the reviewed runtime-divergence and governance-assurance evidence assumes adapter work, but still supports runtime comparison as a practical design target. [assumption; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
Analysis:
- An additive design fits the evidence better than a replacement model, because the original five layers still sort responsibilities sensibly while the newer findings mostly introduce shared services and stronger layer boundaries. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md]
- A single control-plane interpretation is weaker, because the security and retrieval items show that permission truth, semantic safety, tool control, and promotion integrity are strongest in different places. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html]
- Taken together, those constraints support a revised architecture that reads as five layers plus two cross-cutting planes. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
- Operating model and governance remains the top layer, because ownership model, risk-tier intake, exception review, audience-specific explainability artifacts, and human accountability define what lower layers are allowed to do. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html]
- Delivery and platform engineering is where signed promotion pipelines, model and dataset registries, declared AIBOM generation, evaluation harnesses, and policy translation belong, because this layer controls approved artifacts before release. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
- Orchestration and execution should own workflow runtimes, tool allowlists, connector policy, delegation-chain capture, rate and recursion controls, and action approval checkpoints, because this layer shapes executed behavior rather than only stored assets. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html]
- Model and inference should hold approved model endpoints, inference configuration control, semantic guardrails, and provider-facing safety policies, because this layer sees prompt and response semantics directly. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html]
- Data and knowledge should remain the home of authoritative source systems, permission-safe retrieval, retrieval-snapshot metadata, provenance, and classification, because knowledge truth and access truth should not be reconstructed downstream from partial copies. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html]
- A cross-cutting supply-chain and provenance plane should span all five layers, because declared AIBOM, signing, lineage, identity manifests, runtime-observed AIBOM, and divergence detection together create the approved-versus-observed record. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
- A cross-cutting policy, evaluation, and evidence plane should also span all five layers, because policy decisions, benchmark outcomes, exception records, explainability artifacts, incident logs, and drift signals together create the governance review loop. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html]
- The delta from the previous version is therefore precise rather than total: add explicit provenance services, explicit identity-delegation services, explicit evaluation gates, and a formal evidence loop, but keep the original layered architecture as the organizing frame. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
Risks, gaps, uncertainties:
- No reviewed source provides one mature cross-vendor runtime AIBOM standard that already normalizes prompts, retrieval state, delegated authority, and runtime divergence in one production-ready schema. [inference; source: https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html]
- The evidence is stronger on architecture and control placement than on cross-vendor operational benchmarks for the cost and reliability of continuous runtime provenance capture. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
- Explainability expectations for multi-agent workflows remain more mature at the governance-objective level than at the concrete technical-control level, so explanation artifacts should supplement, not replace, provenance and policy evidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html]
- Vendor administration coverage is still uneven, so some tool-specific controls will remain adapter-heavy even if the architectural pattern is stable. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html]
Open questions:
- What minimum shared schema should represent exception approvals, evaluation waivers, and residual-risk decisions across build, release, and runtime governance?
- What minimum runtime snapshot is sufficient for declared-versus-observed comparison without collecting more prompt, memory, or retrieval content than the enterprise can safely retain?
- Which third-party copilot and software-as-a-service control surfaces now expose enough administration coverage to participate fully in a centralized provenance and evidence plane?
- Coverage check: completed for baseline architecture, AIBOM, layered security, governance assurance, explainability, evaluation, ownership, and architectural delta.
- Cross-item sweep repeated before Findings: identity, access control, information architecture, deployment pipeline, and governance-surface items reviewed and cited where they materially changed the synthesis.
- Acronym expansion audit completed: AI, SBOM, AIBOM, RAG, and XAI are expanded on first use in the document.
- Findings and synthesis parity: complete.
- Overall confidence: medium, because the architecture is strongly supported directionally by convergent repository work, but runtime AIBOM and cross-vendor evidence-plane practice remain less standardized than the layered-security and governance-placement conclusions.
The five-layer enterprise Artificial Intelligence reference architecture should be retained, but only as the structural base for a broader design that exposes provenance, runtime evidence, and evaluation as explicit enterprise capabilities instead of leaving them implicit in the shared core. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html]
In practice, that means the architecture now needs named services for declared Artificial Intelligence Bill of Materials (AIBOM) creation, delegated-identity capture, signed artifact lineage, and runtime comparison between approved design and observed execution. [inference; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
The security evidence still argues against collapsing these controls into one gateway, because retrieval permissions, semantic safeguards, orchestration constraints, and promotion checks are strongest in different layers. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html]
Governance, explainability, and evaluation therefore work best as one shared evidence system that records policy decisions, release gates, runtime signals, and review artifacts for later challenge or audit. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html]
- The main architectural delta is the move from an implied shared core to explicit enterprise services for provenance capture, runtime evidence, and evaluation, while the five-layer backbone remains intact. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html)
- Release governance is materially incomplete unless it records declared Artificial Intelligence Bill of Materials (AIBOM) data, artifact signing, registry lineage, delegated authority, and runtime divergence, because those records are what connect approved design to later execution. ([inference]; medium confidence; source: https://owaspaibom.org/; https://cyclonedx.org/capabilities/mlbom/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html)
- The reviewed security evidence favors layer-specific enforcement, with retrieval authorization anchored in data systems, semantic safeguards near model execution, orchestration controls around tools, and promotion checks in delivery pipelines. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
- Enterprise agent architectures need identity controls that describe multi-hop human, workload, and tool relationships, because delegation chains, permission manifests, and trust boundaries determine which actions are attributable and valid. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
- Governance evidence has to survive past deployment, because provenance records, policy decisions, exceptions, explainability artifacts, and human approvals all remain relevant when incidents, audits, or regulatory questions arrive later. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html)
- Evaluation belongs at promotion time and during live operation, because benchmarks, adversarial tests, thresholds, and drift signals are part of the same control loop rather than separate design-time and runtime disciplines. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html)
- The least disruptive architecture update is to keep the five vertical layers and add two cross-cutting planes, one for supply-chain provenance and one for policy, evaluation, and evidence. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html)
- Ownership should stay centralized for policy semantics, provenance schema, security baselines, evaluation standards, and retained evidence, while domain teams keep responsibility for local knowledge, workflow composition, and risk-tuned operating thresholds. ([inference]; medium confidence; source: https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html)
- Assumption: enterprises can stand up a minimum viable declared AIBOM before external standards converge on one canonical schema. Justification: CycloneDX and Open Worldwide Application Security Project AIBOM already define enough structure for models, datasets, configuration, and typed extensions to support an internal starting point. [assumption; source: https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html]
- Assumption: high-risk enterprise systems can emit enough runtime events and policy logs to support meaningful approved-versus-observed comparison. Justification: the runtime-divergence and governance-assurance items both assume some adapter work, but they still treat runtime comparison as operationally achievable rather than speculative. [assumption; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
The evidence points toward an additive change, not an architectural reset, because the original stack still separates responsibilities coherently and the new research mostly adds shared services plus stronger boundaries. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md]
The strongest alternative would be to collapse most of the new controls into one central control plane, but that would hide where critical trust decisions are actually made. Retrieval authorization belongs with authoritative data, semantic safety belongs near inference, orchestration constraints belong with workflow execution, and signing plus promotion checks belong with delivery systems. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html]
That distribution of trust decisions is why the best synthesis is still a layered model, but now with two cross-cutting planes that make provenance and governance evidence visible everywhere instead of assumed nowhere. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
Within that structure, the operating-model layer still defines risk intake, ownership, exception review, audience-specific explanation duties, and human accountability for downstream automation. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html]
Delivery and platform engineering now has a clearer remit: approved registries, signing, declared AIBOM generation, evaluation harnesses, and policy translation belong here because this is the last layer that can consistently gate artifacts before release. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
Orchestration and execution should own runtime workflow policy, tool allowlists, delegation capture, recursion controls, and action checkpoints, since those controls govern what the system actually does rather than what it merely stores. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html]
Model and inference remains the correct place for approved endpoints, inference configuration, semantic guardrails, and provider-facing safety policy because that is where prompt and response semantics are visible in real time. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-02-ai-security-threat-model-prompt-injection-rag-supply-chain.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html]
Data and knowledge should keep authoritative source systems, permission-safe retrieval, provenance, classification, and retrieval-snapshot metadata, because access truth and knowledge truth become unreliable when recreated downstream from partial copies. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html]
Across all five layers, one cross-cutting plane should maintain declared and observed supply-chain records, while a second cross-cutting plane should maintain policy decisions, evaluations, explanations, incident records, and other governance evidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-identity-delegation-trust-theory.html; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-05-02-meta-analysis-standards-and-ai-skill-evaluation.html; https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html]
The practical consequence is a precise extension of the prior model rather than a replacement of it: keep the original organizing frame, but add explicit provenance services, explicit delegation-aware identity services, explicit evaluation gates, and one formal evidence loop. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
- Cross-vendor runtime AIBOM standardization is still immature, so enterprises should expect internal schema work before they get a broadly interoperable production-ready format for prompts, retrieval state, delegated authority, and runtime divergence. [inference; source: https://cyclonedx.org/capabilities/mlbom/; https://owaspaibom.org/; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-schema-design-standards-alignment.html]
- The evidence base is stronger on where controls belong than on the comparative cost and operational reliability of continuous runtime provenance capture across toolchains. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html]
- Explainability guidance is more mature at the governance-objective level than at the exact technical-control level for multi-agent workflows, so explanation artifacts should be treated as complements to provenance and policy records, not substitutes. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-30-explainable-ai-xai-regulation-governance.html; https://davidamitchell.github.io/Research/research/2026-02-28-ai-control-testing-and-assurance.html]
- Administration coverage still varies across vendors and software-as-a-service surfaces, which means some parts of the target architecture will remain adapter-heavy even if the overall pattern is stable. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html]
- What minimum shared schema should represent exception approvals, evaluation waivers, and residual-risk decisions across build, release, and runtime governance?
- What minimum runtime snapshot is sufficient for declared-versus-observed comparison without collecting more prompt, memory, or retrieval content than the enterprise can safely retain?
- Which third-party copilot and software-as-a-service control surfaces now expose enough administration coverage to participate fully in a centralized provenance and evidence plane?
- Type: knowledge
- Description: Revised enterprise Artificial Intelligence capability reference architecture that preserves the five-layer baseline while adding explicit supply-chain and provenance services, policy and evidence services, and new ownership guidance for security, governance, and evaluation. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://github.com/davidamitchell/Research/blob/main/Knowledge/2026-05-05-enterprise-ai-capability-stack.md; https://davidamitchell.github.io/Research/research/2026-05-06-aibom-runtime-generation-divergence-theory.html]
- Links:
- https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html
- https://davidamitchell.github.io/Research/research/2026-05-06-aibom-sbom-conceptual-gaps-theory.html
- https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson