Traditional governance tracks individual objects — but what happens when the thing that fails isn't an object at all? It's a shared condition that several objects quietly depend on. A hosted model drifts, and six decisions get flagged. The seventh — the one that actually mattered — was never tracked.
What it does for you: Common-Exposure Governance treats shared conditions (model providers, data processors, legal bases) as first-class versioned entities. When a condition drifts, the system separates the response into two tiers: Tier 1 (Confirmed) — subjects who explicitly declared dependency are immediately suspended. Tier 2 (Residual) — subjects with possible but unproven exposure are flagged for review, not suspended. This prevents over-suspension while maintaining governance integrity.
Try it: Click "Register Condition" to create a versioned condition node, then "Declare Drift" to see the two-tier response separate confirmed dependencies from residual exposure in real-time.
This implementation was shaped by collaborative discourse with Stephen Gettel and Ravi Shankar NRK, whose insights on condition versioning, the confirmed/residual separation, and the distinction between shared exposure and shared failure directly informed the architecture.
What risk does this eliminate?
Who benefits:
AI Governance Leads · Chief Information Security Officers · Data Protection Officers · Enterprise Architects · AI Consultants advising on GDPR/DSPT compliance
Compliance frameworks addressed:
GDPR Article 22 (explainability of automated decisions) · NHS DSPT (data security governance) · ISO 27001 (information security controls) · SOC 2 Type II (system monitoring) · EU AI Act (high-risk AI oversight)
Follow this story step-by-step using the interactive demo below. Each step maps to a button you can click.
Presenter tip: Walk a governance board through this in under 2 minutes. Start with "Register Condition", end with "Re-Attest". The timeline and audit panels update live — no slides needed.
A governed condition with version history. Version only increments on drift — never on re-attestation.
Subjects with edges to the condition. Green = active, Red = suspended (confirmed), Amber = flagged (residual).
Decisions made during drift carry governance annotations. Confirmed set is hard-blocked (no decisions admitted). Residual set decisions are annotated as unproven_exposure. Escaped decisions carry escaped_boundary.