What Is Digital Information Governance™?
Digital Information Governance™ (DIG™) is a framework for building decision systems that remain defensible when AI is in the room. It is a trademark of Matthew Bertram (USPTO Serial No. 99559923, application pending) and the operating system behind ModalPoint’s advisory practice.
DIG™ answers a single question that every regulated operator will face by the end of 2026:
“When this AI-influenced decision is challenged — by a regulator, an auditor, a plaintiff, or an AI system interpreting your company from the outside — can you prove how you got here, why it was reasonable, and who was accountable?”
If the answer is no, you do not have a governance problem. You have a defensibility problem. DIG™ exists to close that gap.
The Problem DIG™ Solves
AI is no longer a product feature. It is the substrate through which decisions are formed, validated, communicated, and — increasingly — interpreted externally by search engines, large language models, and other AI systems.
In regulated industries, two things are simultaneously true:
-
Decisions are moving faster. AI is being embedded into workflows faster than governance, oversight, or documentation can keep pace. Most organizations cannot produce a complete list of where AI is currently influencing their decisions. Shadow-IT LLM usage is near-universal.
-
Decisions are under harder scrutiny than ever before. The Texas Responsible AI Governance Act (HB 149) takes effect January 1, 2026. The EU AI Act’s high-risk obligations activate August 2, 2026. NIST has published the AI Risk Management Framework and its Generative AI Profile. ISO 42001 is now an active certification standard. Between them, there are four overlapping regulatory and standards regimes that will judge the same underlying management system in 2026.
Traditional information governance was built for documents. Digital Information Governance™ is built for decisions — the places where data, models, vendors, workflows, and human judgment converge to produce an outcome that a regulator or AI system will later re-interpret.
The Four Pillars of Digital Information Governance™

DIG™ is structured around four operational pillars. Each one answers a question the statute, standard, or AI system will eventually ask.
1. Information Provenance
“Where did the information driving this decision actually come from?”
Every AI-influenced decision rests on a chain: training data, retrieved context, vendor outputs, human inputs, cached knowledge, and model behavior. Provenance means you can reconstruct that chain on demand.
In practice, this requires:
- An AI system inventory covering every model, embedded vendor tool, and shadow-IT LLM in use
- Training data documentation for any system you built, including lineage, licensing, and opt-out compliance
- Vendor due diligence packages for every third-party AI tool in your stack
- Input capture for every decision workflow where AI output is consumed by humans
Provenance is the foundation. Every other pillar depends on it.
2. Decision Traceability
“Can I reconstruct who made this decision, when, on what basis, and with what oversight?”
Traceability is how you move from “we have AI” to “we can defend what AI did for us.” It is the pillar that establishes the rebuttable presumption of reasonable care under Texas’ TRAIGA safe harbor (Sec. 552.105), the technical documentation requirement under EU AI Act Article 11, and the audit trail controls under ISO 42001.
Traceability requires:
- Automated logging of AI system behavior across the full system lifetime (EU Art. 12)
- Decision process documentation — who approved what, under what criteria, with what override authority
- Intent statements that explain why each system exists and what outcomes it is designed to produce. We wrote about this in detail in the context of TRAIGA’s Sec. 552.056(c) intent defense and its interaction with federal civil rights law
- Version control for models, prompts, and decision rules so that past decisions remain reproducible
If your organization cannot explain a decision made six months ago, you do not have traceability. You have optimism.
3. Representation Integrity
“How are we being understood — by search engines, by AI systems, and by the people they answer — outside our own four walls?”
This is the pillar most organizations miss entirely. The same AI systems that are reshaping internal decisions are simultaneously reshaping how your company is represented externally. Search engines, large language models, customer chatbots, and AI-powered directories now aggregate public information about your business and convert it into authoritative-sounding answers.
If your public information is outdated, inconsistent, or contradictory, AI systems will generate outdated, inconsistent, or contradictory representations of you — and present them as facts. This is a new category of risk: uncontrolled external representation at scale.
Representation integrity requires:
- A canonical public entity model (website, structured data, knowledge panels, directory listings) that reflects current reality
- Schema markup aligned with actual ownership, leadership, services, and capabilities
- Content architecture that answers the questions AI systems will be asked about you
- Active monitoring of how your brand is represented by consumer-facing AI tools
You do not get to opt out of being represented. You only get to choose whether the representation is yours or the internet’s aggregate guess.
4. Audit Readiness
“If a regulator walks in tomorrow, can we produce the binder?”
Audit readiness is the integration pillar. It converts the first three — provenance, traceability, representation integrity — into shippable artifacts that invoke the safe harbors and satisfy the documentation requirements of every framework that applies to you.
Audit readiness means you can produce, on demand:
- A NIST AI RMF substantial-compliance mapping covering Govern, Map, Measure, and Manage
- An EU AI Act Annex IV technical file for any system that meets the high-risk threshold
- A Fundamental Rights Impact Assessment (FRIA) under EU Art. 27 where applicable
- A TRAIGA intent documentation packet and cure playbook for any Texas deployment
- A workforce AI literacy training log (EU Art. 4, live since February 2025)
- A serious incident reporting runbook with defined escalation paths
Audit readiness is not a certification. It is a state — a binder you maintain continuously, not a project you complete once.
How DIG™ Maps To Today’s Regulatory Landscape
DIG™ is not a replacement for TRAIGA, the EU AI Act, NIST AI RMF, or ISO 42001. It is a meta-framework that lets you answer all four from a single operational foundation.
| DIG™ Pillar | TRAIGA | EU AI Act | NIST AI RMF | ISO 42001 |
|---|---|---|---|---|
| Information Provenance | Safe harbor via “substantial compliance” (Sec. 552.105) | Art. 10 data governance + Annex IV §1 | Govern 1.2, Map 3 | A.7 (data management) |
| Decision Traceability | Intent defense (Sec. 552.056(c)) + documentation for safe harbor | Art. 11, 12 (technical docs + logging) | Manage 1 | A.6.2.6 (logs) |
| Representation Integrity | Consumer disclosure (Sec. 552.051) | Art. 50 (transparency) | Govern 3 (context) | A.6.2.4 (documentation) |
| Audit Readiness | Cure playbook (Sec. 552.104) + penalty defense | Art. 43 conformity + Art. 73 incident reporting | Measure + Manage | Clause 9 (performance evaluation) |
Bottom line: approximately 70% of the underlying artifacts required by these four frameworks are the same artifacts. DIG™ is the structure that lets you build them once and deploy them everywhere. For a deeper analysis of how TRAIGA interacts with federal civil rights law — and why every Texas deployer needs to build for the stricter federal standard even when the state standard is more permissive — see our companion analysis: TRAIGA Doesn’t Preempt Federal Civil Rights Law.
Who DIG™ Is Built For
Digital Information Governance™ was built for conviction operators — the executives in regulated industries who cannot outsource accountability, cannot wait for enforcement to define the rules, and cannot afford to discover a governance gap after the fact.
Specifically:
- Energy operators navigating the EU AI Act’s critical infrastructure provisions (Annex III, Section 2) while simultaneously facing TRAIGA exposure in Texas
- Healthcare providers subject to TRAIGA’s disclosure timing rules, Texas SB 1188’s EHR requirements, and Section 1557 of the Affordable Care Act
- Financial services firms operating across TRAIGA, the Equal Credit Opportunity Act, state insurance codes, and — for those with any EU customer base — GPAI vendor obligations
- Professional services firms whose AI-generated output is consumed by EU clients, pulling them into EU AI Act Art. 2(1)(c) scope whether or not they have an EU office
- Public-sector organizations subject to TRAIGA state-agency disclosure requirements and the coming Texas Artificial Intelligence Council’s guidance
If your organization makes decisions that carry financial, regulatory, or human consequences, and AI is now part of how those decisions get formed — you are who DIG™ was built for.
Getting Started: The Governance Readiness Assessment
Most engagements with ModalPoint begin the same way: with a five-day Governance Readiness Assessment that maps your current state against the four DIG™ pillars and produces a one-page gap report identifying the specific artifacts you need to build.
The assessment answers three questions:
- Where is AI currently present in your workflows — including systems you did not commission?
- What documentation exists to support those decisions — and what would a regulator actually find if they walked in tomorrow?
- What is your exposure if any of those decisions are audited, challenged, or questioned?
From the assessment, most organizations move into one of two structured engagements:
- “Texas Ready by September” — a 4–6 week program that delivers NIST AI RMF substantial-compliance mapping, AI inventory, intent documentation, and the TRAIGA cure playbook in time for the Texas AG complaint portal (live September 1, 2026)
- “Cross-Border Governance Binder” — an 8–12 week program that delivers all nine DIG™ artifacts, structured so a single binder satisfies TRAIGA, the EU AI Act, NIST AI RMF, and ISO 42001
Both engagements are designed to produce defensibility, not documentation theater. If your binder cannot invoke a safe harbor or answer an Annex IV question, we did not do our job.
The Short Version
Digital Information Governance™ is not a platform, a certification, or a marketing label. It is an operating discipline — four pillars (provenance, traceability, representation, audit readiness) that let regulated operators use AI at speed without sacrificing the ability to explain, defend, or stand behind the decisions it helps produce.
If you build your governance on DIG™, the statutes stop being a threat and start being a checklist.
→ Request a Governance Readiness Assessment (Calendly embed pending)
Digital Information Governance™ and DIG™ are trademarks of Matthew Bertram (USPTO Serial No. 99559923, application pending). All rights reserved.
ModalPoint is a Houston, Texas-based AI governance advisory and a division of EWR Digital. Written by Matthew Bertram, President of ModalPoint and CEO of EWR Digital.
Decision Integrity — the runtime discipline across these pillars
The four DIG® pillars above describe what governance must cover. Decision Integrity is the runtime discipline that runs across them — specifically, the discipline that captures the attestation at decision time so that Decision Traceability has something authoritative to reconstruct from, and so that Audit Readiness produces a binder that survives hostile review. Decision Integrity is the verifiable record that an AI-influenced decision was made with awareness of its governance implications, by a human with the authority to make it, at the moment it was made.
This is the technical mechanism behind ModalPoint provisional patent US 63/948,546 (Authority-Hierarchical Validation, filed December 2025). For the full operator-facing breakdown — the four artifacts (authority record, awareness statement, decision capture, tamper-evident log), the regulatory map to TRAIGA §552.105 / EU AI Act Article 12 / NIST AI RMF MANAGE / ISO 42001, and where to start — see Decision Integrity: The Attest Discipline for AI Governance in Regulated Industries on matthewbertram.com.
See our overview of AI decision governance.
AI Enforcement Signals: What the Data Shows (2026)
ModalPoint original analysis of every documented US AI enforcement action we track (2024–2026) and the 2026–2027 regulatory calendar. Analyzed by Matt Bertram, Certified AI Auditor (CAIA).
Signal 1: Every US AI enforcement action so far punishes what AI claims — not how AI decides.
Across every documented US AI enforcement action to date — the FTC’s $193,000 DoNotPay “robot lawyer” settlement, Rytr, Growth Cave, Operation AI Comply (Ascend, Empire, FBA Machine), the Texas Attorney General’s first-of-its-kind Pieces Technologies settlement, and the California and New Jersey actions against xAI over deepfakes — 100% target deceptive marketing or harmful output. None targets decision governance: how an AI-influenced decision was made, authorized, or audited. TRAIGA and the EU AI Act’s high-risk regime regulate exactly that decision layer. The enforcement that exists today is the easy kind. The enforcement that is coming is the kind no operator is ready for.
Signal 2: AI enforcement is now a state-Attorney-General game — filling the federal and Colorado vacuum.
As Colorado delayed and scaled back its AI Act (pushed to January 2027, risk framework removed) and federal rulemaking stalled, state AGs stepped into the gap: Texas (Pieces Technologies), California and New Jersey (xAI), and a 47-state coalition on deepfakes — all in the same window. Under TRAIGA, the Texas AG can issue a civil investigative demand on a single complaint. Exposure is now state-by-state and AG-driven; the map is the risk.
Signal 3: The regulatory calendar is a one-way ratchet — exposure compounds, it never resets.
- Jan 1, 2026 — TRAIGA effective (Texas): $10K–$200K per violation, up to $40K/day for continuing violations, 60-day cure, AG-exclusive.
- Aug 2, 2026 — EU AI Act general-purpose-AI enforcement begins: penalties up to €15M or 3% of global turnover.
- Jan 1, 2027 — Colorado AI Act (delayed) effective.
- Dec 2027 — EU AI Act high-risk (Annex III) obligations land.
Each date adds obligations to operators already carrying the prior ones. For a US operator with EU exposure, these stack — they do not run in parallel and reset. Waiting does not reduce the work; it compresses it.
Signal 4: One binder, not four. ~70% of obligations across the four regimes overlap.
TRAIGA, the EU AI Act, the NIST AI Risk Management Framework, and ISO 42001 share an estimated ~70% of their core obligations — risk classification, human oversight, documentation and audit trails, and accountability assignment. Built correctly, a single Digital Information Governance (DIG®) binder satisfies all four, with Texas-specific appendices for state cover, EU Annex IV appendices for cross-border exposure, and NIST-structured controls for the federal civil-rights overlay. Operators treating each regime as a separate project do four times the work.
Sources: U.S. Federal Trade Commission enforcement records; Office of the Texas Attorney General; California and New Jersey Attorneys General; the Texas Responsible AI Governance Act (HB 149); the EU AI Act; the Colorado AI Act. Analysis © 2026 ModalPoint.
Frequently Asked Questions
What is Digital Information Governance (DIG™)?
Digital Information Governance (DIG™) is a discipline for keeping AI-influenced decisions defensible and auditable, ensuring a company’s information is accurately represented, its decisions are traceable, and its AI use is provable to regulators, partners, and courts. It is a trademark of Matthew Bertram (USPTO Serial No. 99559923, application pending). The canonical public reference for the discipline is maintained at digitalinformationgovernance.com.
Who created Digital Information Governance?
Digital Information Governance was coined by Matthew Bertram, President of ModalPoint and CEO of EWR Digital, who holds the trademark (USPTO Serial No. 99559923, application pending).
How is DIG different from traditional information governance?
Traditional information governance was built to manage documents and records. Digital Information Governance is built to manage decisions, the points where data, models, vendors, workflows, and human judgment converge to produce an AI-influenced outcome that a regulator or AI system will later re-interpret.
What are the four pillars of DIG?
The four pillars are Information Provenance, Decision Traceability, Representation Integrity, and Audit Readiness. Each answers a question a statute, standard, or AI system will eventually ask about how a decision was formed and whether it can be defended.
How does DIG map to TRAIGA, the EU AI Act, NIST AI RMF, and ISO 42001?
DIG is a meta-framework rather than a replacement for any single regime. Roughly 70% of the artifacts those four frameworks require are the same artifacts, so a single DIG binder can satisfy all four, with regime-specific appendices for Texas, EU, and federal exposure. See the canonical reference at digitalinformationgovernance.com.

