A concept map of the AI governance domain, written as an Ecore model in ai-governance-concepts.xcore and published as a generated documentation site: one page and one context diagram per concept, so the vocabulary can be walked rather than read.

577 concepts across sixteen neighborhoods: the technology being governed, its lifecycle, the actors, the normative landscape, risk, harm, trustworthiness, bias, data and privacy, security, documentation, evaluation, human oversight, impact assessment, the organizational program, and ethics.

This is a demonstration and study project. It is not a tower floor and it is not meant to be instantiated.

What this is, and what it is not

The field has a vocabulary problem. “Provider” and “deployer” carry specific legal weight, “bias” means one thing to a statistician and another to a lawyer, and “human oversight” covers everything from a kill switch to a checkbox. Most of the available material is either a linear course, which cannot show that a concept sits in six different neighborhoods at once, or a glossary, which flattens every relationship into alphabetical order.

A typed model does neither. Every concept has a position: what it specializes, what specializes it, what it relates to, and which neighborhood it belongs to. A context diagram around any single class is the set of concepts you need in order to understand that one, and it is computed, not curated. That is the whole demonstration.

Three things follow from treating this as a concept map rather than a metamodel:

  • Classes are concepts, not types to instantiate. Nothing here is meant to be constructed at runtime. A class earns its place by being worth a paragraph.
  • Taxonomies are class hierarchies, not enumerations. An enum literal gets a bullet on a shared page. A class gets its own page, its own diagram, and its own elaborated description. Since drill-down is the entire point, the subclass encoding wins. The model has one enumeration, Level, for an ordinal scale where the literals genuinely carry no meaning beyond their order.
  • There is no root container. contains appears only where the relation is part-whole in the domain, such as a framework and its requirements. A concept graph has no root, and inventing one to make the file serializable would put a modeling artifact in the middle of a description of the world.

If the model is later wanted as something to instantiate, adding a root is a one-commit change. Starting with one would have distorted every decision above it.

Relationship to the model tower

This project sits beside the Nasdanika model tower, not in it.

The tower already has an AI Governance model, branching off the threat floor, and that is the model that does the work: AI systems as assets, controls, risks, evidence, oversight, incidents, all composing with the floors below. It is deliberately small, because a working model should be.

This one is deliberately large, because a map of a domain should be. The two answer different questions. The tower model answers “what is the state of control X on system Y, and where is the evidence”. This one answers “what is a notified body, and why does the answer matter to me”. Confusing the two would make both worse, which is why the name is different and the namespace URI points at the demos site rather than at models.nasdanika.org.

There is exactly one point of contact with the tower: the abstract Concept class extends NxCore NamedElement. That is enough to demonstrate composition, since every concept inherits identity, documentation as structure, and provenance markers, without pulling in floors this model only describes. One import, one line, easy to remove, and it makes the point that a model takes its position in the tower rather than redefining what a lower floor already provides.

The neighborhoods

# Neighborhood Entry point What it answers
1 Technology TechnologyConcept, AISystem, AIModel What is the thing, and is it even AI for the purposes of the rule
2 Lifecycle AILifecycle, LifecycleStage When does each duty attach, and who is present
3 Actors Stakeholder, ValueChainRole Who owes what to whom
4 Normative landscape NormativeInstrument, NormativeStatement, Jurisdiction What says you must, and where does it bite
5 Risk Risk, Control, RiskTreatment What might go wrong, and what reduces it
6 Harm Harm Who gets hurt, and how badly
7 Trustworthiness TrustworthinessCharacteristic What properties should the system have
8 Bias and fairness Bias, FairnessMetric Where does unfairness enter, and how is it measured
9 Data, privacy, IP DataGovernanceConcept, DataSubjectRight What may be used, on what basis, whose is it
10 Security AISecurityThreat, SecurityControl How is it attacked, and what defends it
11 Documentation GovernanceArtifact, ExplainabilityMethod What does governance actually produce
12 Evaluation Evaluation, Metric, Drift, Incident How do we know it works, and that it still does
13 Human oversight HumanOversight, MeaningfulHumanControl What makes a human in the loop more than a signature
14 Impact assessment ImpactAssessment Who could this hurt, asked before it ships
15 Program AIGovernanceProgram, Triage How does an organization operate all of this
16 Ethics EthicalPrinciple, ResponsibleAI What do we consult when the law is silent

The neighborhoods are a reading order, not a partition. The interesting concepts belong to several at once, and the context diagrams are where that shows: AutomationBias is a cognitive bias, and it is also the reason HumanInTheLoop controls need their own effectiveness testing, and it is also what makes Overreliance an organizational rather than an individual failure. Three neighborhoods, one concept, one diagram that says so.

A few opinions the model encodes

A map with no point of view is a glossary. Some choices here are arguments:

  • Harm is modeled separately from risk. A risk register full of risks to the company, with no entry for harm to the people the system acts on, is the most common failure in the field. Separating Harm from Risk makes the omission visible instead of structural.
  • Instruments, statements, and jurisdictions are three things. Nearly every practical compliance confusion comes from treating a document, an obligation, and a territory as one object. They vary independently, and a crosswalk is only possible if they are modeled apart.
  • Roles, not organizations, carry obligations. One company is a provider for what it builds and a deployer for what it buys, and owes different duties in each capacity on the same afternoon.
  • MeaningfulHumanControl is a separate concept from HumanOversight. The qualifier does the work. Oversight without competence, time, information, authority, and the absence of a penalty for dissenting is a signature, not a control. RubberStamping is in the model for the same reason.
  • FairnessImpossibility is a class. Several reasonable fairness definitions cannot hold at once except in degenerate cases. That is a proof, not a gap in current methods, and it means choosing a fairness definition is a normative act that cannot be delegated to the data science team.
  • ShadowAI and EmbeddedAI are first-class. Most ungoverned AI in an organization arrives either switched on by a vendor inside something already bought, or brought in by employees. A program that only governs what it commissioned governs a minority of what it runs.

How this was built, and how it gets finished

Two passes, which is also the demonstration.

Pass one: the model. Concepts, hierarchy, relations, and a short comment on each, written so that the comment says the non-obvious thing rather than restating the name. class Prohibition extends NormativeStatement needs no gloss; what it needs is “the bright line, and therefore the cheapest statement to check and the most expensive to cross”.

Pass two: the generator produces a readme.md per model element from the model, and each one gets elaborated into a full page: definition, why it matters, how it connects to its neighbors, where practitioners get it wrong. The model stays the source of structure; the prose hangs off it. Nothing in the elaboration can contradict the graph, because the graph is what generated the page it sits on.

This is the draw-first, execute-later pattern applied to writing: get the structure right in a model, then generate the artifact, rather than writing 577 pages and hoping they stay consistent with each other.

Licensing

Two licenses, because there are two kinds of thing here.

  • The model and any generated code are under the Eclipse Public License 2.0, matching the rest of the Nasdanika ecosystem. Consistency matters more than optimality here: anyone already using a Nasdanika model has resolved this question once.
  • The prose, meaning this file, the per-element pages, and the generated site, is under CC BY 4.0. Attribution only, deliberately. A non-commercial clause would block exactly the use this is for, which is somebody reading it to do their job, and a no-derivatives clause would block somebody forking the concept map for their own domain, which is the most useful thing that could happen to it.

On sources

The concepts here are derived from publicly available primary material, and the licensing of that material is not uniform:

  • Legislative texts are the safest ground. EU legislation is published on EUR-Lex and reusable under the Commission’s reuse decision, with attribution and without distortion of the original meaning. National statutes are generally outside copyright.
  • Government publications such as the NIST AI Risk Management Framework are, as works of the US government, not subject to domestic copyright. Function and category names can be used directly.
  • Intergovernmental principle sets such as the OECD AI Principles are published under their own reuse terms, which generally permit reproduction with attribution. Check the specific terms before quoting at length.
  • ISO and IEC standards are purchased copyright works. They may be cited by number and title, which is a factual reference, and their definitions may not be reproduced. This model uses terms that also appear in those standards in their ordinary professional sense and reproduces no definitional text. That distinction is worth keeping deliberately, not accidentally.
  • Certification bodies of knowledge and the training material built on them are licensed content. A body of knowledge outline is a compilation, and the selection and arrangement can attract protection even where the individual facts do not. The way to stay clear of this is not to paraphrase carefully; it is to derive the structure from the primary sources instead, which is what the sixteen neighborhoods here do.

On names and marks

Certification program names, the organizations that run them, and their acronyms are trademarks. This project does not use them, does not organize itself around any one program’s syllabus, and does not describe itself as exam preparation. It is a model of AI governance concepts, which is a thing that exists independently of anyone’s certification.

That is a positioning choice as much as a legal one. Tying a general-purpose concept map to a specific credential would date it, narrow its audience, and invite a conversation nobody needs to have.