Published open · v1.0 · CC BY-ND 4.0

The Stehrling AI Governance Model

How do you know your use of AI is under control?

A plain-language operating model for companies that use AI — not companies that build it. Four planes, one gate, one loop, one signature. Published open. Running in production on our own systems.

The principle

If AI touched it, someone signs for it.

AI doesn't dilute accountability — it concentrates it. Every sanctioned use has a named owner. Every consequential output has a human who adopted it. Every year, an officer signs: the register is complete, the controls operate, exceptions are disclosed.

This is the architecture that has always worked: financial controls after SOX, cyber attestation under DFARS. The signature is what turns policy into behavior.

Within a few years, customers, insurers, and regulators will ask for a signed AI attestation the way they ask for a SOC 2 today. The companies that can produce one on request will have built this model — whether they call it that or not.

The four planes

Corporate AI risk is four nightmares. Each becomes a control plane.

One plain question, a small set of artifacts, and a named owner — per plane.

1

Permission

The governance nightmare
Who may use what AI, for what purpose, on what data?
Owner: Legal / compliance
2

Protection

The security nightmare
Where does our data go when AI touches it, and who can see it?
Owner: CISO / IT
3

Provenance

The data-integrity nightmare
Do we know what AI produced, and can we stand behind it?
Owner: The business function adopting the output
4

Price

The spend nightmare
What are we paying, across every SKU and seat, and is it working?
Owner: CFO / finance

Four planes, four questions, four owners, one signature over the top. Everything else is implementation.

The labeling rule — the label follows the signature. Internal drafts are labeled as AI-produced until a human adopts them; whoever adopts the finished work product decides what its face says, and the trace exists regardless.
The Stehrling AI Governance Model v1.0 — four planes converging at the Gate, the loop, and one signature over the top
The Stehrling AI Governance Model v1.0 on one page. © 2026 Stehrling LLC · CC BY-ND 4.0 · click to open full size.
The Gate

Four planes stay four documents until they meet in one place.

In a governed environment, every prompt passes through a single enforcement point on the way in, and every response passes through it on the way out.

Inbound · Permission + Protection

Identity and authorization checked. Payload inspected, blocked, or masked.

Outbound · Provenance + Price

Response labeled and logged — who, when, which model, what data class. Every token metered.

An organization without a gate has policies. An organization with one has controls.

Two design rules keep the gate honest and portable. Its telemetry is content-free — metadata only, never prompt or output bodies; content stays inside the governed boundary. And the gate is a specification, not a product: it assembles from the native controls of whatever environment hosts it. No new software is required to be governed.

The loop

A one-time AI policy is a decaying document. This is a verb.

The model runs as an annual cycle with quarterly pulses, because the AI landscape changes faster than any policy.

Inventory Sanction Contain Watch Attest

Find everything in use, sanctioned and shadow. Decide per tool: approve, contain, or kill. Route sensitive work inside the boundary. Watch usage, spend, and change — quarterly. Then a named officer signs. The loop is the product.

Maturity levels

Where you are, and where the question leads.

LevelNameMeaning
0ShadowAI is in use; leadership hasn't looked. Most companies today.
1AwareInventory done, policy exists, nothing enforced.
2GovernedFour planes operating, gated environment live, loop running.
3AttestedA signed attestation, producible on demand to a customer, insurer, or regulator.

Could you hand a customer your signed AI attestation tomorrow?

We run it on ourselves

This isn't theory. It's in production.

Stehrling operates its own governed AI environment on FedRAMP High-authorized infrastructure in AWS GovCloud, runs the loop on its own AI use, and executed the first signed attestation under this model on August 22, 2026. We built it for defense contractors, where the data class is CUI and the controls have to survive an assessor.

Use the model

Cite it, teach it, run it — with attribution, without modification.

The Stehrling AI Governance Model is a business operating framework for companies that use AI. NIST AI RMF, ISO/IEC 42001 and the EU AI Act are written for those who build and deploy AI systems; this model operationalizes them on the consumer side. It is published under Creative Commons BY-ND 4.0. The canonical version lives on this page.

Attribution: The Stehrling AI Governance Model, © 2026 Stehrling LLC, CC BY-ND 4.0.

Version 1.0 · August 22, 2026 · License terms

When you want it running, not just read

The model is free. The signature you can defend is the work.

Building the gated environment, running the loop, and getting you to an attestation you can hand to anyone who asks — that's what we do.

Talk to Stehrling →

An independent firm focused exclusively on CMMC compliance for defense contractors and the DIB.

Fredericksburg, VA