P4 is the defensibility umbrella. Every other pillar reports into governance. Without P4, AI is operated; with P4, AI is operated defensibly. P4 codifies the policy architecture, control framework, risk taxonomy, and Defensibility Posture Statement that boards, regulators, auditors, and insurers reference.
Operating outputs: the Defensible AI Operating Manual, the 9-class Risk Taxonomy 2026, the AI Risk Register, the Defensibility Posture Statement, and the control crosswalks against ISO/IEC 42001, NIST AI RMF, and EU AI Act.