Why Capability Growth Is Not Enough — and the AI Governance that Institutions Should Demand
Executive Summary
Artificial intelligence systems are advancing rapidly in capability. They write, analyze, coordinate, plan, and increasingly act autonomously. Many organizations interpret this technical progress as evidence of institutional readiness.
Performance gains, however, do not automatically produce legitimacy, enforceable authority, or cross-system accountability. An AI system can be competent while remaining constitutionally undefined. It can integrate into workflows while lacking verifiable refusal boundaries. It can be widely adopted while remaining publicly unauditable.
This brief proposes a seven-level governance stack for AI systems (with an optional eighth level addressing institutional destabilization). It argues that most production AI ecosystems operate at Levels 1–3. Levels 6 and 7—federal coordination and public constitutional verifiability—are effectively absent in production AI.
The key finding is not that governance is impossible. The technical and institutional building blocks already exist in cybersecurity, internet standards, and software supply-chain verification. What does not yet exist is their assembly into an AI-specific constitutional and federal framework.
Institutions adopting AI at scale should recognize this gap—and adjust their expectations accordingly.
I. The Wrong Signal: Capability Is Not Legitimacy
AI discourse increasingly equates stronger systems with safer systems. As models improve in reasoning, planning, and autonomy, they are assumed to be more mature and ready for institutional embedding.
This assumption confuses technical competence with constitutional stability.
An AI system may:
- Produce accurate outputs.
- Operate for extended autonomous periods.
- Integrate into institutional workflows.
Yet still lack:
- A stable and versioned governance identity.
- Mechanically enforced refusal conditions.
- Transparent and auditable update processes.
- Clear compatibility boundaries with other systems.
Institutions must recognize that technical maturity does not imply governance maturity.
II. The Governance Stack (Levels 1–7, Optional Level 8)
The governance stack describes increasing layers of institutional responsibility.
Level 1 — Capability Expansion
Focus: model strength and performance.
Metrics:
- Benchmarks.
- Autonomy duration.
- Tool integration.
- Generalization.
Representative organizations:
OpenAI, Anthropic, Google DeepMind, Meta AI, xAI, Mistral, Cohere.
Governance at this level is typically policy overlay. Systems are powerful but constitutionally ambiguous.
Level 2 — Human-Centered Interaction
Focus:
- User experience.
- Collaboration.
- “Human-in-the-loop” framing.
Representative ecosystems:
Human-centered AI startups, Copilot-style tools, collaboration-focused platforms.
These systems shape interaction but rarely bind behavior to enforceable governance contracts.
Level 3 — Orchestration and Agentic Execution
Focus:
- Multi-step task execution.
- Tool coordination.
- Agent frameworks.
Governance remains perimeter-based or internal to a vendor. There is little structural enforcement of constitutional identity.
Level 4 — Constitutional Runtime Identity
This is the first structural shift.
At Level 4, the system:
- Declares a governing contract.
- Binds behavior to versioned rules.
- Enforces refusal conditions mechanically.
- Fails on governance violations.
Precedent exists outside AI:
- Secure software update frameworks.
- Supply chain provenance systems.
- Policy enforcement pipelines.
In AI production environments, Level 4 remains rare.
Level 5 — Inter-System Negotiation
At this level, different AI systems must declare:
- Compatibility.
- Authority boundaries.
- Refusal translation rules.
- Governance interoperability.
In other domains, identity federations and trust negotiation frameworks allow separate institutions to coordinate securely. AI lacks an equivalent constitutional negotiation layer.
Level 6 — Federal Meta-Governance
Level 6 supports pluralism without chaos.
It requires:
- Defined amendment rules across regimes.
- Explicit fork and exit conditions.
- Compatibility declarations.
- Dispute resolution pathways.
- Safeguards against authority laundering.
No production AI ecosystem currently implements this in a comprehensive way.
Level 7 — Public Constitutional Verifiability
At Level 7, governance is not merely asserted—it is independently verifiable.
This requires:
- Public logging of governance events.
- Attestation of runtime state.
- Traceable update pathways.
- Version-bound constitutional identity.
Mature precedents exist in:
- Transparency log systems.
- Secure update frameworks.
- Remote attestation standards.
- Software provenance architectures.
These tools prove public verifiability can scale. They are not yet assembled into an AI constitutional layer.
Level 8 (Optional) — Institutional Resilience
This level addresses a broader reality:
Institutions are not stable forever.
Under geopolitical fragmentation or legitimacy crises, AI governance must operate without assuming institutional continuity.
This is less technical than institutional—but increasingly relevant.
III. Where Organizations Actually Stand
Most AI vendors operate at Levels 1–3.
Enterprise governance platforms (e.g., workflow and audit systems) may approach Level 4 within a single organization’s boundary but do not implement federal compatibility or public constitutional identity.
The strongest evidence that Levels 6–7 are feasible comes not from AI firms but from:
- Internet standards bodies.
- Software supply chain security frameworks.
- Transparency log ecosystems.
- Federated identity systems.
The technical components exist. The constitutional assembly does not.
IV. The Design Gap
The missing layer is not cryptographic; it's compositional. There is no AI-specific constitutional substrate that:
- Binds governance identity to runtime state.
- Makes refusal enforceable.
- Logs governance changes transparently.
- Enables sovereign systems to negotiate compatibility.
- Supports federal pluralism without collapse into vendor monoculture.
Until such a layer exists, “AI governance” remains largely narrative and policy-based.
V. What Institutions Should Demand
Universities, research institutions, and public agencies embedding AI systems should require:
- Declared Governance Identity
A versioned and binding constitutional reference. - Enforceable Refusal Semantics
Clear, machine-enforced boundaries. - Inter-System Compatibility Declarations
Explicit statements of authority boundaries. - Public Verifiability
Logged governance events and auditable runtime state. - Defined Amendment Pathways
Transparent upgrade and dispute processes.
Without these features, institutional AI adoption relies on vendor assurances rather than enforceable structure.
VI. Conclusion
AI ecosystems are advancing rapidly in capability and orchestration. They are not advancing at the same pace in constitutional identity, federal coordination, or public verifiability.
The building blocks for Level 6–7 governance already exist in other domains. The work now required is institutional composition: assembling these primitives into an enforceable federal substrate for AI systems.
If institutions require pluralist AI governance under destabilizing conditions, this layer will not be optional.
Member discussion: