The Knowledge Layer: A Reference Architecture for Delegated AI Action in Regulated Institutions

AI capability is no longer the constraint on enterprise deployment. Admissibility is. The sense is operational and not evidentiary: whether, before the act, an institution may rely on a given basis for the action it is about to take, and answer for it afterwards. Where the consequence of an action is low and a human stays accountable, the existing governance apparatus is sufficient, and AI is shipping there today. Where the consequence is material, the action is delegated, and it is not human-paced, the deployment gate refuses what model evaluation passed. The institution cannot show, at the moment of action, what the system relied on, with what standing, under whose authority, against which consequence class, with what contradiction state. This paper specifies a reference architecture for the layer that produces that account — the Knowledge Layer. The argument is that institutions already operate a mature apparatus for governing probabilistic actors — they govern humans — and that AI agents are a new class of player inside that same apparatus, differing in one respect that changes the engineering: they act at machine speed, so the moment-of-action gate must run at machine speed too. The layer sits between data governance and the dissolving application layer. It treats the claim — a single governed assertion carrying provenance, evidential warrant, scope, temporal validity, contradiction status, and named authority — as the atomic unit. It computes, for each claim, two governed axes of standing — evidential warrant, across five independently degrading dimensions, and authority, kept separate from the evidence score so that a well-corroborated claim from a low-authority source is not scored down for its source. It gates each consequential action against a consequence class the institution declares externally, and it records a replayable manifest of the basis the action rested on. The paper is explicit about the kind of contribution it makes. The components the layer is built from — provenance tracking, event logs, confidence scoring, bitemporal data, policy gating — are individually well established, and the paper cites them as such. The contribution is not a new primitive and is not an evaluated system. It is the work of naming this layer, defining it as one architecture rather than as features scattered across data platforms and application code, deriving the requirements it must satisfy, and specifying the mechanisms precisely enough to be built against and argued with. The paper states the architecture (three primitives, four concurrent jobs), the fifteen requirements and where each is enforced, the signed action manifest and what its replay does and does not establish, and the model-risk treatment of the layer itself. Section 13 is explicit about what a reference architecture does not establish — there is no implementation and no evaluation here — and about the open problems that remain. Version 3 (September 2026) corrects the treatment of the US agencies' revised model-risk guidance (SR 26-2), which excludes generative and agentic AI from its scope; defines and disclaims admissibility at first use; adds Section 4.1 on what the retrieval-evaluation literature measures about the gate's conditions; and carries a citation-verification pass dated 5 September 2026.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-17
DOI
https://doi.org/10.5281/zenodo.22813826
Primary Topic
Scientific Computing and Data Management
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The Knowledge Layer: A Reference Architecture for Delegated AI Action in Regulated Institutions

Arnaud Gelas, Witold Reichhart
Zenodo (CERN European Organization for Nuclear Research)
Scientific Computing and Data Management
article

The Knowledge Layer: A Reference Architecture for Delegated AI Action in Regulated Institutions

Arnaud Gelas, Witold Reichhart
article en

Abstract

AI capability is no longer the constraint on enterprise deployment. Admissibility is. The sense is operational and not evidentiary: whether, before the act, an institution may rely on a given basis for the action it is about to take, and answer for it afterwards. Where the consequence of an action is low and a human stays accountable, the existing governance apparatus is sufficient, and AI is shipping there today. Where the consequence is material, the action is delegated, and it is not human-paced, the deployment gate refuses what model evaluation passed. The institution cannot show, at the moment of action, what the system relied on, with what standing, under whose authority, against which consequence class, with what contradiction state. This paper specifies a reference architecture for the layer that produces that account — the Knowledge Layer. The argument is that institutions already operate a mature apparatus for governing probabilistic actors — they govern humans — and that AI agents are a new class of player inside that same apparatus, differing in one respect that changes the engineering: they act at machine speed, so the moment-of-action gate must run at machine speed too. The layer sits between data governance and the dissolving application layer. It treats the claim — a single governed assertion carrying provenance, evidential warrant, scope, temporal validity, contradiction status, and named authority — as the atomic unit. It computes, for each claim, two governed axes of standing — evidential warrant, across five independently degrading dimensions, and authority, kept separate from the evidence score so that a well-corroborated claim from a low-authority source is not scored down for its source. It gates each consequential action against a consequence class the institution declares externally, and it records a replayable manifest of the basis the action rested on. The paper is explicit about the kind of contribution it makes. The components the layer is built from — provenance tracking, event logs, confidence scoring, bitemporal data, policy gating — are individually well established, and the paper cites them as such. The contribution is not a new primitive and is not an evaluated system. It is the work of naming this layer, defining it as one architecture rather than as features scattered across data platforms and application code, deriving the requirements it must satisfy, and specifying the mechanisms precisely enough to be built against and argued with. The paper states the architecture (three primitives, four concurrent jobs), the fifteen requirements and where each is enforced, the signed action manifest and what its replay does and does not establish, and the model-risk treatment of the layer itself. Section 13 is explicit about what a reference architecture does not establish — there is no implementation and no evaluation here — and about the open problems that remain. Version 3 (September 2026) corrects the treatment of the US agencies' revised model-risk guidance (SR 26-2), which excludes generative and agentic AI from its scope; defines and disclaims admissibility at first use; adds Section 4.1 on what the retrieval-evaluation literature measures about the gate's conditions; and carries a citation-verification pass dated 5 September 2026.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 3%
Scientific Computing and Data Management
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.