The Carrier Stability Problem
AI Governance Between Risk Genesis and Governability • VECTOR • Issue 01
Reality Anchor
The EU AI Act begins with a seemingly technical question: What qualifies as an AI system?
The question appears purely definitional. In reality, it determines whether risks can be classified, obligations assigned, and conformity assessed. Only once this entity has been defined can governance operate on it.
A bank seeking to deploy AI in credit approval faces a different question: Who is authorized to approve a loan? The challenge is not merely to assess risks. The decisive issue is where authorization is anchored and who is permitted to make a decision.
A hospital deploying diagnostic AI systems faces yet another challenge: Who bears responsibility when AI influences treatment? Here, roles, responsibilities, and organizational accountability move to the forefront. A decision must be made about where responsibility is anchored.
An organization introducing new AI systems faces a different task: Which systems should be admitted into the organization at all? The central question concerns the admission decision as much as the subsequent risk.
A security team, by contrast, is often concerned primarily neither with models nor with procurement processes. The decisive question is: Can the organization detect, coordinate, and respond to threats? Here, the focus shifts away from the individual system toward the organization’s capacity to respond.
These situations originate from different domains and address different risks. Each places a different object at the center of attention.
The differences are substantial. AI systems, organizations, authorizations, admission decisions, and organizational capabilities differ fundamentally from one another. Nevertheless, they all qualify as objects of governance.
Reconstruction
The most immediate explanation is that different risks give rise to different governance units.
This explanation captures part of reality. It does not, however, explain why precisely these reference points are selected. The same risks could often be reconstructed through different reference points. Credit risks can be reconstructed through models, organizations, or approval rights. Clinical risks can be examined through systems, hospitals, or medical personnel. Security risks can be analyzed through individual systems, processes, or organizational capabilities.
The risk perspective alone therefore does not explain why certain reference points repeatedly move to the forefront.
Their significance derives from the governance functions they enable. An AI system can be classified. An approval right can be granted or revoked. An organization can assume responsibility. An admission decision can be approved or denied. A security capacity can be developed, assessed, and mobilized.
Despite their differences, the functions performed through them exhibit a striking similarity. Governance classifies, authorizes, admits, verifies, assigns responsibility, and coordinates.
Attention therefore shifts from the units themselves to the functions performed through them. Their commonality lies in enabling particular governance functions.
Risks can be described, assessed, and analyzed. Governance, however, cannot operate directly on risks themselves. It operates on objects to which responsibilities can be assigned, authorizations granted, or requirements imposed.
Governance therefore does not address risks directly. It addresses them through carriers.
Carrier Selection
Once governance functions become the focus, another question arises:
Why are certain carriers selected repeatedly?
Many other reference points are equally relevant: contexts of use, chains of action, delegations, and interactions among multiple systems. Yet they are less frequently chosen as primary governance reference points. Why?
Because relevance alone is not sufficient. Governance must be able to operate on a unit. That unit must remain identifiable, be capable of delimitation, carry responsibility, and serve as the object of decisions.
Relevance alone does not make an object governance-capable.
Against this background, the repeated selection of particular carriers can be understood as a search for carriers on which governance functions can be performed.
From Selection to Stability
The repeated selection of particular carriers points to an underlying logic of selection. Governance appears to prefer certain carriers because they possess characteristics that make governance operational.
These carriers can be delineated. They can be documented and verified. They can be linked to rights, obligations, and responsibilities. Above all, they remain identifiable over a sufficiently long period of time.
Against this background, the repeated selection of particular carriers can be understood as a search for carriers that are sufficiently stable for governance.
The Carrier Stability Problem
The crucial point, however, lies elsewhere.
Governance frequently operates on carriers other than those on which risks arise.
This difference is not new. Governance has always had to address risks through governance-capable carriers. Under AI conditions, however, risk genesis increasingly shifts into relational, distributed, and dynamic constellations, while governance must continuously adapt its carriers to these changes.
Many relevant risks now emerge in contexts of use, delegations, chains of action, and interactions among multiple components - in other words, in relationships.
These relationships lack many of the characteristics that governance requires of stable carriers. They are often difficult to delineate, change over time, generate ambiguous responsibilities, and can only be documented or institutionally embedded to a limited extent.
Governance responds by constructing new carriers - for example, monitoring pipelines, runtime controls, or evidence systems. In doing so, relational risks are translated into objects of governance.
This adaptation does not eliminate the underlying tension. With each new generation of governance carriers, the constellations in which risks arise continue to evolve. Governance therefore continuously adapts its carriers to an evolving risk genesis.
The Carrier Stability Problem therefore does not describe a one-time distance between risk genesis and governance carriers. It describes an ongoing process of adaptation in which governance continuously adjusts its operational carriers to changing forms of risk genesis.
The stability of the problem therefore lies not in immutable governance carriers, but in the recurring necessity to create new governance carriers under changing conditions.
The Reappearance of the Tension
The Carrier Stability Tension is not confined to individual governance regimes. It reappears across different decision contexts.
An organization procuring new AI systems frequently operates at the level of the admission decision. Many risks, however, only become visible during subsequent deployment. Governance intervenes where it can operate - not necessarily where risks arise.
A hospital faces a similar challenge. Diagnostic systems influence decisions, treatment trajectories, and responsibilities. The risks arise neither exclusively within the model nor exclusively within the organization. Nevertheless, governance must determine where responsibility, accountability, and control are anchored.
The examples differ substantially. The underlying tension remains the same. Governance operates on carriers capable of supporting its functions. Risk genesis frequently occurs elsewhere.
Consequence
The Carrier Stability Problem does not create a one-time trade-off. It creates a continuous pressure for adaptation.
Governance must continuously adapt its carriers to new forms of risk genesis. New governance carriers can reduce existing tensions while simultaneously changing the operational reference points, responsibilities, and control structures on which governance subsequently operates.
The central challenge lies in continuously organizing governance functions under conditions of ongoing change while preserving stability, traceability, and institutional embedding.
Implications for the Governance Discourse
The Carrier Stability Tension explains a striking characteristic of many AI governance debates.
Positions that appear to contradict one another often address different governance problems. They differ not only in their perspective on risk, but also in their choice of the carrier on which governance should operate.
As a result, conflicts frequently appear to be disagreements about risk. The reconstruction suggests, however, that they often begin one level earlier: with the question of which governance function is at stake and which carrier can reliably support that function.
Core Insight
The central tension is that the characteristics of effective governance carriers do not necessarily coincide with the characteristics of actual risk genesis.
Governance prefers carriers that are stable, clearly delineated, attributable, and verifiable. Many AI-related risks, by contrast, arise in distributed, relational, and context-dependent constellations.
Current governance conflicts often appear to be conflicts about risk. The reconstruction suggests, however, that they frequently begin one level earlier: with the question of the carrier on which governance should operate in the first place.
Governance does not primarily search for the places where risks arise. It searches for carriers on which it can operate.
Under AI conditions, the relationship between risk genesis and governance carriers becomes a continuous process of adaptation.
Evidence Note
Recent governance papers exhibit a consistent operational convergence.
Across runtime governance, monitoring, safety, reporting, and institutional capacity, governance is consistently attached to specific operational governance carriers rather than to risk itself. These include failure surfaces, admission boundaries, runtime controls, monitoring pipelines, identities, evidence systems, and institutional capacities.
This convergence appears across documents from Microsoft, IMDA, DeepMind, OpenAI, Anthropic, OECD, RAND/Oxford, and GovAI despite their different objectives, governance traditions, and problem settings.
The vector developed here does not derive its argument from these documents. Instead, it reconstructs a general governance mechanism and subsequently observes that the current governance literature increasingly organizes operational governance around comparable carriers.
The governance paper stack therefore does not prove the Carrier Stability Problem. It provides independent evidence that contemporary AI governance is increasingly operationalized through identifiable governance carriers rather than through abstract risk categories alone.

