The National AI Governance Playbook · Part II · Chapter 4
Two governance regimes
The four functions of AI governance fall into two regimes with different logics: one governs the model and holds across sectors, the other governs use and is rebuilt in each sector. This chapter sets out the two regimes, the interface between them, and what the split settles about how a national program is structured, funded and led.
Evidence basis: MindXO design recommendation. A MindXO architecture separating model-level and use-level governance.
By Myriam Ayada · MindXO · Version 1.1 · Updated 21 July 2026
In brief
The four functions group into two regimes, but assurance bridges them. The safety and security regime supplies common standards, evaluation and reusable technical assurance. The usage-based regime adds contextual deployment assurance and carries use-regulation with legal force. Horizontal evidence can be reused; evidence about local data, intended use, human oversight, workflow, outcomes, monitoring and incident response cannot be assumed. A Regime Interface Agreement defines what crosses, what each sector adds and who decides.
Why the functions fall into two groups
Chapter 3 separated national AI governance into four functions. Standards and evaluation create common technical reference points and evidence. Assurance then asks two questions: do the technical claims hold, and does the deployment satisfy its context? The first answer can often travel across sectors; the second changes between a bank, hospital and power grid. Use-regulation gives the contextual layer legal force.
That single difference, what each function attaches to, is what divides the four into two regimes, because it settles who can govern, with what kind of authority, and how often the work repeats. A function that attaches to the model can be built once and shared; a function that attaches to a use has to be rebuilt wherever the use occurs. The two regimes that follow are not a matter of preference or administrative taste. They are the shape the four functions take once grouped by their object.
The safety and security regime
The safety and security regime supplies common baselines, evaluation methods and reusable technical evidence about model and system properties. It supports accredited schemes and providers that sectors can draw on instead of rebuilding scarce technical capability. Its evidence is horizontal; it is not a complete judgment about a particular deployment.
Its authority is technical and evidentiary rather than legal. Standard-setting carries force by reference, when a standard is written into a contract or a rule; evaluation carries the force of evidence, which obliges no one by itself; assurance carries force through accreditation, when an accredited opinion is required before a system may be deployed. None of the three can fine or prohibit. The regime's natural home is a small number of national bodies, the standards body and the committees behind it, the evaluation capability, and the accreditation authority, treated in Part IV, and its cadence follows model releases and capability jumps rather than the review calendar of any one sector.
- Object
- A model's properties, behaviour and security, and whether a deployed system still matches its claims.
- Functions
- Standard-setting, evaluation and testing, and horizontal technical assurance.
- Force
- Technical and evidentiary; by reference, by evidence, by accreditation. No power to fine or prohibit.
- Home
- A few national bodies: the standards body, the evaluation capability, the accreditation authority.
- Cadence
- Follows model releases and capability jumps.
The regime's product is a shared reference and a flow of evidence. On its own it settles nothing about whether a given use is permitted, because it holds no legal power to permit or forbid. That is the work of the second regime, and the two are joined at the point where evidence becomes decision.
The usage-based regime
The usage-based regime governs deployment one sector at a time. It carries contextual deployment assurance and use-regulation because the same model creates different risks and duties in a bank, hospital and power grid. Sector regulators define the additional evidence, request more where needed, make the decision and enforce it.
Because it is rebuilt in each sector's terms, its central design problem is coherence. Sectoral rules drift apart without a shared national frame to hold definitions, thresholds and reporting in common, the coherence question of Chapter 6, and they arrive in an order that has to be chosen, the sequencing question of Chapter 7. What the regime cannot supply for itself is the technical basis for its judgements. A sector regulator can require that a deployed system be safe and secure; it cannot, sector by sector, define what that means or generate the evidence that it holds. It draws both from the first regime.
- Object
- A use in context: what an organisation does with a model, to whom, under which law.
- Functions
- Contextual deployment assurance and use-regulation, one sector at a time.
- Force
- Legal and binding; require, inspect, sanction, prohibit.
- Home
- The existing supervisors of each sector, on a shared national frame.
- Cadence
- Follows sector risk and the supervisory calendar.
Sheet 04 of 13: a horizontal safety and security regime supplies common baselines and reusable technical evidence. Sectoral regimes in finance, health, energy and public services add contextual assurance and use-regulation. The interface specifies reuse, contextual additions, request rights and escalation.
The interface between the regimes
The interface is the operating agreement between reusable evidence and sectoral judgment. Evaluation capability supplies technical findings; accreditation qualifies schemes and providers; assurance providers form independent opinions; sector regulators define context, decide and enforce. No one document or institution should collapse those decisions.
The one-page Regime Interface Agreement records six fields: horizontal evidence supplied; contextual evidence required; triggers and request rights; disclosure and confidentiality; escalation and incidents; ownership and review cadence. It also names the owner, effective date, next review and approving authority.
What the split settles
Once the two regimes are distinct, several decisions that look separate turn out to be the same decision, and a few that look joined come apart.
- Funding follows the regime, not the program. The horizontal regime is capital- and talent-intensive and mostly central, with its cost incurred upfront; the vertical regime runs through supervisory machinery that already exists, so its cost is mainly training and coordination. The two carry different funding logics, taken up again in Chapters 10 and 12.
- One home is possible above the line, not below it. The horizontal functions can share a single institutional home; sectoral use-regulation cannot be pulled into it without stripping the sector supervisors of powers only they can exercise. A body may host the safety and security regime; it must not absorb the usage-based one.
- Coherence is a frame, not a centre. What holds the vertical regime together is a shared national frame of definitions, thresholds and reporting, not a single regulator, so the sectors stay aligned without being merged. Chapter 6 returns to it.
- The horizontal capability comes first. Credible sectoral rules depend on a reference and evidence the sectors do not each produce, so the safety and security regime is a precondition for the usage-based one, a sequencing point developed in Chapter 7.
Common failure mode. One regulator for everything. A single AI regulator asked to run both regimes cannot hold every sector's inspection powers and knowledge, so it either under-regulates use or centralises use-regulation away from the sector supervisors. Worse, the body that produces the evidence becomes the body that acts on it, and the independence that gives evaluation its credibility, established in Chapter 3, is lost. The interface disappears precisely where it does the most work.
The two regimes give Part II its structure. Chapter 5 follows them down into the full policy and regulatory chain, from a principle at the top to a control a deployed system must pass, and locates each regime's instruments along it.
Three questions for every government
- Which functions belong to the horizontal safety and security regime, and which stay with the sector regulators?
- Where is the interface defined, and what does each side owe the other, what the horizontal capability publishes and what a sector regulator may require of it?
- What holds the sectoral rules coherent with the national frame without centralising them?
Selected public sources
- ISO/IEC 42001, AI management systems, ISO/IEC, 2023
- AI Risk Management Framework and Generative AI Profile, NIST, 2023 and 2024
- Regulation (EU) 2024/1689 (AI Act), European Union, 2024
- A pro-innovation approach to AI regulation, white paper and government response, United Kingdom, 2023 and 2024
- Introduction to AI assurance, UK Department for Science, Innovation and Technology, 2024