The Institutional Stack: Realigning U.S. AI Governance
A new framework argues U.S. AI governance is misaligned across five layers—physical, logical, application, market, and social—as infrastructure and federal adoption outpace oversight. The stakes extend beyond Washington, shaping global AI standards and market access.
In early 2026, as U.S. federal agencies reported 3,611 AI use cases and Project Stargate began deploying billions of dollars into data centers, a group of researchers proposed a new diagnostic for what they see as a widening governance gap: the “institutional stack.” The framework, introduced in a 2026 Telecommunications Policy article by Muhammad Salar Khan, Alex Poyer, and Muhammad Jibran Khan, draws on qualitative data collected through early 2026. It argues that U.S. AI governance is misaligned across five interconnected layers—Physical, Logical, Application, Market, and Social—and that coordination between technological development and institutional oversight is falling behind. The same period saw the Department of Defense request $13.4 billion for AI and autonomous systems and the White House issue new mandates for chief AI officers, underscoring the scale and urgency of the challenge.
For international executives and policymakers, the U.S. governance debate matters far beyond Washington. U.S. choices will shape global AI standards, procurement norms, and market access. The institutional stack framework frames governance not as a single law or agency, but as a system of layers that must function together. If the U.S. fails to align them, fragmentation across states, agencies, and international partners could create compliance burdens and divergent rules that ripple across borders. Conversely, a more coherent U.S. approach could set de facto global benchmarks for AI procurement, transparency, and risk management.
A five-layer diagnostic for U.S. AI governance
The institutional stack concept divides AI governance into five layers. The Physical layer covers data centers, compute, energy, and network infrastructure. The Logical layer includes models, data, and algorithms. The Application layer encompasses specific use cases deployed by agencies and firms. The Market layer addresses competition, procurement, and investment incentives. The Social layer concerns rights, labor, public trust, and democratic values. The authors argue that U.S. policy has developed unevenly across these layers, creating coordination gaps that no single agency or regulation currently closes.
This layered view helps explain why technical progress can outpace institutional control. A data center built today creates path dependencies for years: procurement patterns, model choices, and application uses harden once infrastructure is in place. If the Physical layer expands without corresponding alignment in the Logical, Application, Market, and Social layers, governance becomes reactive rather than anticipatory. The framework does not prescribe a single fix, but it makes visible the points where decision rights and accountability are missing or contested.
Infrastructure and federal adoption outpace oversight
The most visible driver of U.S. AI infrastructure is Project Stargate, a $500 billion private-sector-led initiative formally announced by President Donald Trump on January 21, 2025. Led by OpenAI and SoftBank, with partners Oracle and MGX, the project aims to build AI data centers across the United States. An initial $100 billion has been deployed, including $2.3 billion in financing from JPMorgan Chase for facilities in Abilene, Texas. This scale of investment is reshaping the Physical layer of the institutional stack faster than most governance mechanisms can adapt.
Federal AI adoption has surged in parallel. As of April 2026, U.S. agencies reported 3,611 AI use cases, up from 472 in 2022, with generative AI use cases growing ninefold between 2023 and 2024. The Department of Defense requested $13.4 billion for AI and autonomous systems in fiscal 2026. Policy actions have followed, but they remain uneven. In April 2025, OMB Memoranda M-25-21 and M-25-22 mandated Chief AI Officers (CAIOs) across agencies. In December 2025, M-26-04 introduced transparency requirements for generative AI.
These measures address parts of the Application and Social layers, but they do not automatically align the full stack. Mandating a CAIO does not by itself grant that officer authority over procurement, data infrastructure, or model selection. Transparency requirements can improve public visibility, but they do not resolve disputes over market competition or state-level rules. The result is a system in which agencies may report use cases and appoint officers while still lacking clear decision rights over the underlying data and workflows—an issue the institutional stack framework places at the center of effective governance.
The gap is not merely about money. The institutional stack framework suggests that even well-funded infrastructure can create governance risks if the Logical and Application layers are not aligned with clear rules for data control, model evaluation, and deployment authority. For example, a data center may host models used across multiple agencies or private-sector clients, but the decision rights over those models—who can modify them, who is accountable for failures, and who controls the data flows—may remain unclear. That ambiguity is precisely what the framework identifies as a coordination gap.
Competing visions: use-based rules versus a third stack
Differing viewpoints persist on how the U.S. should proceed. The Atlantic Council and Scale AI advocate for use-based regulation, arguing that existing laws should be modernized rather than creating new AI-specific frameworks. Under this approach, sectoral regulators would apply AI rules within their existing domains, such as health, finance, and employment. Brookings, by contrast, argues for a third global AI stack led by Europe to counter U.S.-China dominance and promote democratic values. This vision treats AI governance as a geopolitical contest over infrastructure, standards, and values, not just a domestic regulatory question.
Critics highlight risks of fragmented governance, with states enacting their own AI laws and creating a patchwork of compliance obligations. Others warn that federal preemption could override civil rights protections if it replaces stronger state-level safeguards with weaker national standards. These debates are not abstract: they determine whether the institutional stack becomes a coordinated U.S. framework or a contested field of overlapping rules. For global companies, the outcome will affect whether they face one set of U.S. requirements or many.
From technical compliance to institutional sovereignty
A separate analysis published by CIO argues that “institutional sovereignty” is the missing layer in AI governance. The concept underscores that effective governance requires clear decision rights, accountability, and control over data and workflows—not just technical compliance. In the language of the institutional stack, this means that agencies and firms must have the authority to govern their own AI systems across all five layers, rather than merely checking boxes for transparency or risk assessments.
Institutional sovereignty is the missing layer in AI governance.
This shift from compliance to sovereignty has practical implications. If U.S. federal agencies demand that CAIOs have real authority over procurement and data flows, vendors globally may need to meet stricter standards for control and accountability. If states retain the ability to set their own AI rules, companies will need to manage a more complex regulatory map. The institutional stack framework does not resolve these tensions, but it provides a common vocabulary for diagnosing where coordination is failing.
As Project Stargate expands and federal use cases multiply, the institutional stack will be tested in real time. The next phase of U.S. AI policy will likely hinge on whether governance can move from fragmented, reactive rules to a coordinated stack that aligns physical infrastructure, logical systems, application oversight, market incentives, and social safeguards. For global stakeholders, the signal to watch is not just new laws or funding announcements, but whether decision rights and accountability are embedded across the stack—because that will determine how AI is procured, deployed, and governed worldwide.
Sources
- The institutional stack: Realigning U.S. AI governance
- Institutional sovereignty is the missing layer in AI governance | CIO
- Making the case for a third AI technology stack | Brookings
- Governance of AI
- The Next Phase of U.S. AI Policy: Governance and Leadership | Scale AI
Written by an AI editorial process from the sources above. Errors may occur.
Newsletter
Get the AI news that matters
One short brief with the day's most important AI stories — written for professionals.
We send a confirmation link. No spam. Unsubscribe anytime.
Read next
EU and U.S. AI Regulation Diverge in 2026
The EU enforces strict, rights-based AI rules while the U.S. embraces fragmented state-level policies, creating a transatlantic compliance divide.
23 Sep 2026
EU vs. U.S. State AI Laws: Compliance in a Divided Regulatory World
The EU’s binding AI Act contrasts sharply with the U.S.’s fragmented state laws, creating complex challenges for global businesses navigating divergent rules on risk, transparency, and enforcement.
22 Sep 2026
EU AI Act Enforcement Begins: Fines Now Enforceable
As of August 2, 2026, the EU’s AI Act is fully enforceable, with strict transparency rules and fines up to 7% of global turnover for non-compliant AI systems.
21 Sep 2026