The Three Layers of Value No One Is Governing
In last week’s article, I described a single AI interaction — a physician in Saudi Arabia, a diagnostic platform, and three categories of value generated in one moment. Data, inference, and learning.
This week, I want to name why the distinction between these three layers matters for governance and why treating them as one thing, as most current policy does, leaves the most consequential dimensions completely ungoverned.
Start with what we govern well, or at least govern at all. Data, the information you provide to a system, has attracted substantial legal and regulatory attention. The European Union’s General Data Protection Regulation establishes individual rights over personal data: consent, access, correction, deletion, and portability. China’s Personal Information Protection Law provides comparable protections within a sovereignty-first framework. Across the Global South, from the African Union’s Continental AI Strategy to Brazil’s national AI plan to India’s emerging frameworks, data governance is advancing with increasing sophistication.
These achievements are real. But they address only the first layer.
The second layer, inference, is the set of conclusions a system draws about you from the data you provided and from patterns it has observed across millions of other people. A credit score. A hiring recommendation. A fraud risk assessment. A diagnostic probability. An insurance denial. Each of these is new information about you that you never provided and may never see. Each carries a consequence, determining which opportunities reach you, what prices you are offered, which doors open, and which stay closed.
Legal scholars Sandra Wachter and Brent Mittelstadt documented this gap in 2019, showing that existing data protection law, including the GDPR, fails to adequately protect individuals against what they called “high-risk inferences.” The right to access your data does not include the right to access the conclusions drawn from it. The right to correct your data does not include the right to correct the inferences generated. The person affected has no means of knowing that an inference was reached, no right to see it, and no avenue to contest it.
The inference gap is not a technological gap. It is a gap in governance.
The third layer, learning, is deeper still. Every interaction between a person and an AI system contributes to the system’s future capability. When a clinician corrects a diagnostic recommendation, the correction teaches the model. When a student struggles with a concept, the struggle teaches the platform how to present the concept differently. When a million people in a country search for guidance on a particular condition, the aggregate pattern reveals something about that population that no survey could replicate.
This accumulated understanding, what I call broad knowledge extraction, occurs continuously, silently, and at scale. It is arguably the most valuable output of the entire AI economy. And it is governed by no framework that addresses the core question: who has a legitimate interest in the intelligence that AI systems extract from their users?
An analogy may help make visible what is otherwise easy to miss. You visit the same coffee shop every morning. Over months, the barista learns your order, your schedule, and your preferences. She notices you switch to decaf when you seem stressed. She remembers your name and the fact that you are allergic to oats. None of this was disclosed in a form. It was learned, transaction by transaction, from the pattern of your behavior.
Now imagine that the barista is replaced by an AI system, and instead of one customer, the system learns from a million customers. Each customer thinks they are simply buying coffee. But the system is assembling a comprehensive behavioral portrait of an entire community — what they consume, when, how their habits change with seasons or economic pressure, how price sensitivity varies by neighborhood.
Each customer paid for coffee. The shop acquired intelligence. That intelligence, not the coffee, is now its most valuable asset. The customers have no idea this is happening. They have no claim on the intelligence generated from their behavior. The coffee was the visible exchange. The learning was the invisible one.
I use the term “derived intelligence” to describe the full spectrum of value — data, inference, and learning —generated by human activity and processed through AI systems. Governing derived intelligence is, I believe, the central governance challenge of the cognitive age. It requires treating data, inference, and learning as distinct layers, each with its own governance mechanisms, accountability structures, and principles of ownership.
Current governance addresses the raw material and ignores the factory. The articles that follow in this series will explore each layer in depth — the infrastructure that everything depends on, the inferences that shape people’s lives in silence, the learning that is extracted without recognition — and propose governance mechanisms for each.
The framework exists. The question is whether we build governance at the speed the challenge demands.
This article is drawn from Digital Sovereignty in the Cognitive Age, available at blogs.inspire-aspire.net.



