# Apparens > Apparens is an AI governance practice founded by Jeroen Janssen (Deventer, the Netherlands). We help boards, CTOs, CISOs, DPOs, enterprise architects, procurement, legal and risk leaders make AI governance decisions they can defend. Our method is Strategic Red Teaming — adversarial strategic testing of the logic, regulatory classification and structural dependencies behind major AI decisions, before they become irreversible. Our product is the AI Control Index, a personal AI governance decision-support app. Vendor-neutral, evidence-first, no hype. ## About Apparens treats AI governance as a moment of decision, not a library of documents. For any consequential AI decision we structure five questions: what must be decided now, what can go wrong, who must own it, which controls are needed, and what evidence makes the decision defensible. The throughline is decision defensibility — being able to explain and defend a decision to a board, auditor, regulator, vendor, or legal team. Founded by Jeroen Janssen, author of *Executive Accountability in the Age of AI* (2026) and *Iedereen Obeya*. Before founding Apparens he ran large regulated IT delivery himself — he led the IT department for the Dutch Tax Authority's Toeslagen (benefits) division through the years after the childcare-benefits scandal (growing it to ~220 engineers) and today advises the Tax Authority on AI governance, risk and compliance. We apply evidence over opinion, visual clarity, and shared accountability to AI governance, strategic red teaming, and runtime governance. We serve organisations across Europe that must operationalise the EU AI Act, ISO/IEC 42001, and the NIST AI RMF — and prove it. ## The idea: executive accountability for AI Organisations are judged not by the decisions they make, but by whether those decisions remain defensible when reality, regulators and auditors eventually test them. The enemy is false confidence: the green dashboard, the passed audit, the signed DPIA, the successful pilot — none of which prove the decision was good. The work divides into four disciplines: decision quality (how the decision is reached), decision control (how it is executed and controlled in production), decision legitimacy (why anyone should trust it) and decision learning (how the organisation gets better at deciding). - [Executive Accountability for AI](https://apparens.nl/executive-accountability): the idea and the four disciplines, in English - [Bestuurlijke verantwoordelijkheid voor AI](https://apparens.nl/bestuurlijke-verantwoordelijkheid): the Dutch edition, with a public-sector section (parliamentary accountability, the Dutch Court of Audit, the toeslagenaffaire as an accountability crisis) ## AI Control Index (product) - [AI Control Index](https://apparens.nl/ai-control-index): A personal AI governance decision-support app. It structures AI governance decisions — maturity assessment across seven control layers (L0–L7) and five shields (S1–S5), an advisory team that pressure-tests your position, evidence tracking, and defensible governance outputs. "A team, not a library." - [Pricing](https://apparens.nl/pricing): A free demo (a complete fictional workspace, no login) and a Pro plan (EUR 39/month, regular price EUR 59; your own workspace and the full advisory team). - [Demo](https://apparens.nl/app/ai-control-index?demo): Explore the complete Green Canopy Ventures governance workspace with no login required. - [Trust Center](https://apparens.nl/trust): Subprocessors, data handling, assurance status, and known limitations — every claim code-verified. ## Weekly Decision Intelligence (free brief) - [Weekly brief](https://apparens.nl/brief): A free weekly email + web edition on what moved in AI governance — EU regulation, enforcement, security, and the running cost of AI — distilled from dozens of primary sources (regulators, standards bodies, AI labs) and composed by the Apparens team. Brutally honest and independent; every item shows its source provenance (verified at, or straight from, a primary source). - [Brief archive](https://apparens.nl/brief/archive): Every past edition of the Weekly Decision Intelligence brief. - [RSS feed](https://apparens.nl/feed.xml): machine-readable feed of every published edition. ## Method: Strategic Red Teaming - [Strategic Red Teaming](https://apparens.nl/strategic-red-teaming): The discipline of systematically attacking your own AI strategy to expose hidden weaknesses — at the strategic layer (decisions, assumptions, governance, economics), not the technical layer. This is adversarial strategic testing, distinct from cybersecurity red teaming and penetration testing. Dutch edition: [Strategische Red Teaming](https://apparens.nl/strategische-red-teaming). - [How it works](https://apparens.nl/how-it-works): The method and the traceable evidence chain behind every score and finding — no claim without a verifiable source. Dutch edition: [Hoe het werkt](https://apparens.nl/hoe-het-werkt). - [Adversarial Strategic Testing](https://apparens.nl/adversarial-strategic-testing): testing an organisation's strategy from a hostile perspective, before reality does. Dutch edition: [Adversarieel strategisch toetsen](https://apparens.nl/adversarieel-strategisch-toetsen). - [Runtime Governance](https://apparens.nl/runtime-governance): governing AI systems while they operate in production — boundary rules, circuit breakers, default-deny, drift and post-market monitoring. Dutch edition: [Runtime governance (NL)](https://apparens.nl/runtime-governance-nl). - [Decision Defensibility](https://apparens.nl/decision-defensibility): the property of a decision that lets you explain and defend it afterwards. Dutch edition: [Verdedigbare beslissingen](https://apparens.nl/verdedigbare-beslissingen). - [AI Governance Decision Support](https://apparens.nl/ai-governance-decision-support): structure the decision, not a library. Dutch edition: [AI-governance beslissingsondersteuning](https://apparens.nl/ai-governance-beslissingsondersteuning). - [EU AI Act readiness](https://apparens.nl/eu-ai-act-readiness): classify the systems, map the obligations, surface the evidence gaps, record the owners. Dutch edition: [EU AI Act-gereedheid](https://apparens.nl/eu-ai-act-gereedheid). - [AI Vendor & Procurement Review](https://apparens.nl/ai-vendor-review): challenge the vendor's claim before you sign. Dutch edition: [AI-leveranciersbeoordeling](https://apparens.nl/ai-leveranciersbeoordeling). - [Board & Audit Reporting](https://apparens.nl/board-audit-reporting): brief a position you can defend. Dutch edition: [Bestuurs- en auditrapportage](https://apparens.nl/bestuurs-en-auditrapportage). ## Executive Accountability in the Age of AI (book) - [Executive Accountability in the Age of AI](https://apparens.nl/book): *Governance is not what you claim. It's what you can prove.* by Jeroen Janssen (2026, ISBN 9798252058993; also in Dutch as *Bestuurlijke verantwoordelijkheid in het tijdperk van AI*). A practical framework for executives to document, defend and prove their AI decisions, built on real public cases (Robodebt, Air Canada, Knight Capital) rather than hypotheticals. Covers seven control layers, five organisational shields, and eight governance artifacts (ART-01–ART-08). Maps to ISO/IEC 42001, the EU AI Act, and the NIST AI RMF. Out now on Amazon in e-book and hardcover. E-book: [English](https://www.amazon.com/dp/B0H94XKCWQ) · [Nederlands](https://www.amazon.nl/dp/B0H943GD4H). Hardcover: [English](https://www.amazon.com/dp/B0H94SLHYW) · [Nederlands](https://www.amazon.nl/dp/B0H94SY3WD). ## AI Governance Glossary (54 canonical terms) The canonical glossary for AI governance terminology, mapped to the AI Enterprise Control Index framework. Each term carries a definition, why it matters, how it is used in AI governance, related controls and frameworks, and DefinedTerm structured data. - [Glossary Index](https://apparens.nl/ai-control-index-glossary): all 54 terms, searchable - [Agent](https://apparens.nl/glossary/agent): AI component that perceives, reasons, and acts autonomously - [AI Actor Classification](https://apparens.nl/glossary/ai-actor-classification): EU AI Act operator roles — provider, deployer, distributor, importer - [AI SBOM](https://apparens.nl/glossary/ai-sbom): machine-readable inventory of all AI system components - [AI System Inventory](https://apparens.nl/glossary/ai-system-inventory): centralised register of all deployed AI systems - [Application](https://apparens.nl/glossary/application): an AI-enabled application within the control model - [Autonomy Level](https://apparens.nl/glossary/autonomy-level): classification of agent independence (A1–A4) - [Blast Radius](https://apparens.nl/glossary/blast-radius): scope of impact when a component or vendor fails - [Boundary Rule](https://apparens.nl/glossary/boundary-rule): a rule defining the permitted limits of an AI system's behaviour - [Circuit Breaker](https://apparens.nl/glossary/circuit-breaker): automatic disable on failure conditions - [Classification Ceiling](https://apparens.nl/glossary/classification-ceiling): maximum data sensitivity an AI system may process - [Component](https://apparens.nl/glossary/component): a discrete element of an AI system in the control model - [Contestability](https://apparens.nl/glossary/contestability): the right to challenge AI decisions and obtain remedy - [Control](https://apparens.nl/glossary/control): a measure that modifies risk — preventive, detective, or corrective - [CSRD](https://apparens.nl/glossary/csrd): Corporate Sustainability Reporting Directive (EU) - [Data Lineage](https://apparens.nl/glossary/data-lineage): the traceable origin and transformations of data - [Default-Deny](https://apparens.nl/glossary/default-deny): all permissions denied unless explicitly granted - [DPIA](https://apparens.nl/glossary/dpia): Data Protection Impact Assessment under GDPR Art. 35 - [EU AI Act](https://apparens.nl/glossary/eu-ai-act): Regulation (EU) 2024/1689 — risk-based AI legislation - [Evidence](https://apparens.nl/glossary/evidence): documented proof a control is in place and effective - [Evidence Factory](https://apparens.nl/glossary/evidence-factory): a centralised repository for audit-ready governance evidence - [Exfiltration](https://apparens.nl/glossary/exfiltration): unauthorised extraction of data from AI systems - [Fine-Tuning](https://apparens.nl/glossary/fine-tuning): further training a model on domain-specific data - [Forensic Exposure](https://apparens.nl/glossary/forensic-exposure): the mapped dependencies and failure modes that create governance exposure - [Foundation Model / GPAI](https://apparens.nl/glossary/foundation-model): a model trained on broad data at scale; general-purpose AI - [FRIA](https://apparens.nl/glossary/fria): Fundamental Rights Impact Assessment under EU AI Act Art. 27 - [Gate](https://apparens.nl/glossary/gate): a mandatory pass/fail checkpoint before progression - [GDPR](https://apparens.nl/glossary/gdpr): General Data Protection Regulation (EU) 2016/679 - [GPAI Code of Practice](https://apparens.nl/glossary/gpai-code-of-practice): EU code of practice for general-purpose AI models - [GRC](https://apparens.nl/glossary/grc): Governance, Risk & Compliance — Shield S1 - [Hallucination](https://apparens.nl/glossary/hallucination): fluent, plausible, but fabricated model output - [HITL](https://apparens.nl/glossary/hitl): Human-in-the-Loop — human review at defined decision points - [Human Oversight Pattern](https://apparens.nl/glossary/human-oversight-pattern): the specific model of human oversight applied to an AI system - [i-DEPOT](https://apparens.nl/glossary/i-depot): a BOIP evidence-of-creation filing (the framework's IP record) - [ISO/IEC 42001](https://apparens.nl/glossary/iso-iec-42001): the AI management system standard - [Layer](https://apparens.nl/glossary/layer): a horizontal control layer (L0–L7) - [LLM](https://apparens.nl/glossary/llm): Large Language Model - [Mandatory Artifact (ART)](https://apparens.nl/glossary/mandatory-artifact): required governance documents ART-01 through ART-08 - [Maturity Level](https://apparens.nl/glossary/maturity-level): implementation progression per control (1 Ad Hoc – 4 Optimised) - [Model](https://apparens.nl/glossary/model): a trained artifact performing inference - [Model Drift](https://apparens.nl/glossary/model-drift): performance degradation as input data diverges from training data - [Multi-Agent Orchestration](https://apparens.nl/glossary/multi-agent-orchestration): controls over agent-to-agent communication and delegation - [NIST AI RMF](https://apparens.nl/glossary/nist-ai-rmf): the NIST AI Risk Management Framework - [Orchestrator](https://apparens.nl/glossary/orchestrator): the component coordinating multiple agents and tools - [OWASP Agentic Top 10](https://apparens.nl/glossary/owasp-agentic-top-10): the top security risks for agentic AI systems - [OWASP LLM Top 10](https://apparens.nl/glossary/owasp-llm-top-10): the top security risks for LLM applications - [Plane](https://apparens.nl/glossary/plane): a cross-cutting control plane in the AI Control Index model - [Post-Market Monitoring](https://apparens.nl/glossary/post-market-monitoring): ongoing monitoring of a deployed AI system under the EU AI Act - [Posture](https://apparens.nl/glossary/posture): an organisation's overall AI governance stance - [Prompt Injection](https://apparens.nl/glossary/prompt-injection): an adversarial attack embedding malicious instructions in input - [RAG](https://apparens.nl/glossary/rag): Retrieval-Augmented Generation — grounding model output in documents - [Risk Appetite](https://apparens.nl/glossary/risk-appetite): a board-level declaration of acceptable AI risk with calibrated thresholds - [Severity](https://apparens.nl/glossary/severity): a 1–5 impact classification if a control fails - [Shield](https://apparens.nl/glossary/shield): a vertical, cross-cutting control section spanning all layers (S1–S5) - [System](https://apparens.nl/glossary/system): a deployed AI system in the control model ## Essays & publications - [From Battlefield to Boardroom](https://apparens.nl/essay-red-teaming): strategic red teaming as an epistemic governance instrument (Feb 2026, SSRN abstract 6860020; arXiv edition arXiv:2607.01913, July 2026) - [A Supervisory-Evidence Ontology for Agentic AI under EU Law](https://apparens.nl/essay-mcs): a candidate Minimum Conceptual Set (23 slots) and a temporal extension (OWL-Time + SHACL) for supervisor-ingestible accountability evidence under GDPR, the AI Act and NIS2 (April 2026, v0.5.1, DOI 10.5281/zenodo.19758441, CC BY 4.0) - [From Record to Finding](https://apparens.nl/essay-record-to-finding): an evidentiary-adequacy criterion for runtime oversight of agentic AI under the EU AI Act — why tamper-proof logs cannot establish legal findings of fact (June 2026, DOI 10.5281/zenodo.21025237, CC BY 4.0; on arXiv as "From Runtime Records to Legal Findings: An Evidentiary-Adequacy Criterion for Agentic AI Oversight", arXiv:2607.00941) - [The Implementation Gap](https://apparens.nl/essay-implementation-gap): the AI Enterprise Control Index as an operational governance instrument for agentic AI systems (March 2026) - [Iedereen Obeya](https://apparens.nl/obeya): a book on transparent strategic decision-making by Jeroen Janssen ## Framework Library - [Framework Library](https://apparens.nl/framework-library): 173 searchable strategic frameworks across 13 domains, curated into an adversarial red-teaming lifecycle. ## Blog - [Blog index](https://apparens.nl/blog): research and essays on adversarial AI governance - [When AI Eats the Control Group](https://apparens.nl/blog-control-group): the METR randomised trial, why one productivity number cannot travel between people and work systems, and who is authorised to draw the denominator’s border - [How Will We Ever Work Alongside the Machine?](https://apparens.nl/blog-alongside-the-machine): six conditions one episode has to satisfy, three and a half of them machine-checkable from the record, and the two nobody is building a field for - [Agentic AI Changes the Operating Model](https://apparens.nl/blog-runtime-governance): MAS's SAFR and Kyvvu's Building Secure Agents at Scale converge — govern the agent's execution path at runtime and produce evidence that can answer the question - [The Hacker Has an Address](https://apparens.nl/blog-hacker-address): where Harari's civilisational-hack thesis breaks — syntax versus runtime, arbitrage versus takeover, the signature as the wall - [Why Every AI Strategy Needs a Red Team](https://apparens.nl/blog-why): the case for adversarial governance - [Scaling Strategic Red Teaming](https://apparens.nl/blog-scaling): from boutique practice to organisational capability - [The AI Auditor's Dilemma](https://apparens.nl/blog-auditor): when the examiner has no evidence - [Strategic Decisions Under Uncertainty](https://apparens.nl/blog-decisions): what boards actually need to know - [The Contract That Was Never Adversarial](https://apparens.nl/blog-contract): why procurement is a governance failure point ## Key concepts (Apparens IP) Executive Accountability · Bestuurlijke verantwoordelijkheid · Strategic Red Teaming · Adversarial Strategic Testing · Runtime Governance · AI Control Index · Decision Defensibility · False Confidence · Governance as Decision Support · Evidence-Based AI Governance · Control Evidence · Defensible Position · Governance Drift · Decision Readiness · Human-Centric AI Governance · AI Governance Decision Support ## Standards we operationalise EU AI Act (Regulation (EU) 2024/1689) · ISO/IEC 42001 · NIST AI RMF · ISO/IEC 23894 · GDPR · NIS2 · CSRD · OWASP LLM Top 10 · OWASP Agentic Top 10 · Three Lines Model ## Contact - Website: [apparens.nl](https://apparens.nl) - Founder: Jeroen Janssen — [LinkedIn](https://linkedin.com/in/jeroen-janssen-mba-7686b01/) - Location: Deventer, the Netherlands · Service area: Europe - Positioning: AI governance decision support, not generic AI consultancy or a standard GRC tool. Vendor-neutral, evidence-first.