Where are we at the moment with AI governance

Workspace actions
Then Answer

Current State of AI Governance

- Fragmented global landscape: No single binding international treaty. Governance is a mix of national laws, regional frameworks, voluntary industry standards, and multistakeholder initiatives. (See OECD AI Principles; EU AI Act draft.) - Leading regional efforts: - European Union: EU AI Act (risk-based regulatory regime) moving toward implementation — the most comprehensive statutory framework. (European Commission) - United States: Sectoral/agency approach (FTC, NIST guidance, targeted bills in Congress) — emphasis on innovation + enforcement of existing consumer/procurement laws. - China: Rapid regulatory development with standards, security reviews, and state-centered governance for AI deployment and data use. - Soft law and standards: Organizations (ISO, IEEE, OECD, Partnership on AI) and technical bodies (NIST, OpenAI policies) produce guidelines, risk assessments, and standards adopted by industry and governments. - Corporate governance & procurement: Large tech firms implement internal safety teams, red-teaming, model cards, and deployment controls; governments increasingly require risk assessments in procurement/use. - Focus areas and tensions: - Safety and alignment: Research on robustness, interpretability, and long-term risks is growing, but regulation lags technical progress. - Accountability and liability: Debates over who is responsible for harms (developers, deployers, users). - Civil rights and discrimination: Regulations and litigation address bias, surveillance, and due process. - Security and dual-use: Export controls, classification of capable models, and monitoring of misuse (e.g., cybercrime, biological risks). - Economic and labor impacts: Policy discussions on redistribution, retraining, and competition. - Emerging moves: - International coordination: G7, OECD, UN, and multilateral forums discussing norms; proposals for model testing, transparency, and sharing of safety work. - Regulatory sandboxes and certification: Pilot programs to test rules before broad enforcement. - Capacity gaps: Many countries lack expertise/resources to regulate effectively; calls for technical assistance and globally interoperable standards. Bottom line: Progress is substantive but uneven — substantial policy building blocks exist (EU Act, standards, agency guidance), but global coordination, enforcement mechanisms, and technical integration of safety into governance remain works in progress. Key upcoming milestones will be EU implementation, U.S. legislative moves, and international agreements on model testing, export controls, and responsible disclosure. Selected sources: OECD AI Principles; EU AI Act (European Commission); NIST AI Risk Management Framework; Partnership on AI; recent G7/OECD statements.
Then Node

International Coordination on AI Governance — Current State

International coordination is currently active but fragmented. Major forums — the G7, OECD, the United Nations (including UNESCO and the UN Secretary‑General’s initiatives), and other multilateral venues — are convening governments, industry and civil society to negotiate shared high‑level norms, principles and governance approaches. Key features of this coordination include: - Norm‑setting and principles: Bodies like the OECD and UNESCO have issued nonbinding frameworks (e.g., OECD AI Principles, UNESCO Recommendation on the Ethics of AI) that many countries reference when shaping national policy. The G7 and the EU have similarly articulated principles stressing safety, human rights, and accountability. - Proposals for testing and evaluation: There is growing consensus on establishing standardized safety testing and red‑teaming protocols for advanced models. Governments and expert groups are drafting approaches for independent model evaluation, risk classification, and pre‑deployment assessment, though no single global testing regime has been adopted. - Transparency and information‑sharing: International proposals emphasize transparency about model capabilities, training data provenance, and deployed use cases. Efforts range from voluntary disclosure frameworks and model cards to calls for legally mandated reporting for high‑risk systems. - Coordination on safety research: States and multilateral bodies promote sharing of safety research and best practices, including cooperative funding, shared benchmarks, and mechanisms to exchange incident/near‑miss information — but practical mechanisms for secure, trustful sharing are still under development. - Gaps and challenges: Coordination is uneven (developed countries lead; many low‑ and middle‑income countries are underrepresented), enforcement is limited because most outputs are nonbinding, and technical disagreements persist about thresholds for regulation, export controls, and how to reconcile openness with security. In short, international actors are building normative and technical scaffolding — testing regimes, transparency expectations, and safety‑sharing proposals — but have not yet converged on a comprehensive, enforceable global governance architecture. For more detail, see OECD AI Policy Observatory, UNESCO Recommendation on the Ethics of AI (2021), and recent G7 and UN statements on AI.
Then Related Ideas

Why this snapshot of AI governance was chosen — and where to read further

Explanation for the selection - Representative coverage: The summary captures the major, distinct elements shaping AI governance today — regional laws (EU, U.S., China), soft law and standards bodies, corporate practices, and key policy tensions (safety, accountability, rights, security, economic impacts). That mix reflects how governance is actually emerging: not from a single source but from overlapping legal, technical, and voluntary regimes. - Policy relevance: It highlights the frameworks most likely to affect deployment and design choices in the near term (EU AI Act, U.S. agency guidance, China’s state-led measures), which is crucial for actors trying to comply or influence outcomes. - Actionable levers: By noting concrete mechanisms (regulatory sandboxes, certification, export controls, procurement rules), the summary points to where policymakers and firms can intervene or pilot solutions. - Realistic assessment: The snapshot emphasizes fragmentation, capacity gaps, and uneven enforcement — important qualifiers for anyone claiming governance is “solved.” Suggested ideas and authors to explore - Regulatory design and comparative approaches - Helen Toner (Center for Security and Emerging Technology) — analyses on policy levers and governance pathways. - Karen Yeung — work on algorithmic regulation and risk-based frameworks. - Standards, testing, and technical governance - NIST (AI Risk Management Framework) — practical, technical touchstone for risk assessment. - David Kaye / Nicholas Eberstadt (various authors in standards and testing debates) — for discussion of model testing and capabilities evaluation. - Corporate governance, safety teams, and industry norms - Joanna Bryson — AI ethics and governance, including accountability debates. - Timnit Gebru, Margaret Mitchell — critiques of corporate practice and calls for research governance. - International coordination and geopolitics - Els Torreele / Allan Dafoe — on global coordination and institution-building for powerful technologies. - Henry Farrell / Abraham Newman — for geopolitical perspectives on technology standards and influence. - Rights, bias, and public-interest approaches - Ruha Benjamin — social justice lens on tech and governance. - Cathy O’Neil — critical perspectives on algorithmic harms and accountability. - Security, dual-use, and export controls - Miles Brundage (Future of Humanity Institute) — on misuse risks, export controls, and governance options. - The WHO/CSET/BIOSAFETY authors on bio-related dual-use concerns tied to generative models. Key reports and documents to consult - OECD AI Principles and related OECD guidance - European Commission: EU AI Act (proposal and legislative texts) - NIST: AI Risk Management Framework - Partnership on AI publications and model governance guidance - Recent G7/OECD/UN statements on AI safety and coordination If you’d like, I can: - Prepare a one-page annotated reading list tailored to a policymaker, technologist, or civil-society advocate. - Suggest concrete policy options (e.g., model certification, mandatory impact assessments) mapped to actors who could implement them.
Then Node

Concrete AI Governance Options and Who Should Implement Them

Below are concise, actionable policy options paired with the actors best placed to implement each. Options are practical, interoperable across jurisdictions, and scalable to different capabilities. 1. Model classification and capability-based certification - What: Require independent testing and tiered certification based on model capabilities (e.g., compute, emergent behaviors, ability to generate disinformation or perform code/biological design). - Who: National regulators (tech/competition/security agencies) set rules; accredited third‑party labs perform testing; standards bodies (ISO, OECD, IEC) define technical criteria. - Rationale: Focuses regulatory attention where risk is highest and creates interoperable attestations for cross‑border use/export. 2. Mandatory pre‑deployment impact assessments (AIIA) - What: Obligate developers and deployers of high‑risk systems to conduct and publish standardized impact assessments covering safety, privacy, discrimination, security, and societal harms. - Who: Legislatures/regulatory agencies mandate format and scope; firms conduct assessments; independent auditors verify completeness for high‑risk classes. - Rationale: Encourages risk identification early, informs procurement and public oversight, and creates accountability trails. 3. Incident reporting and near‑miss sharing - What: Require timely reporting of safety incidents, misuse, and near misses to a secure national or international repository, with tiers for confidentiality vs public disclosure. - Who: National regulators require reporting; an international body (OECD or a UN technical forum) hosts cross‑border aggregation and anonymized sharing; industry participates via sectoral coalitions. - Rationale: Builds collective learning, early warning about emergent risks, and evidence for regulation; balances transparency with IP/security needs. 4. Regulatory sandboxes and conditional authorizations - What: Create controlled environments where novel AI systems can be tested under regulatory supervision with informed users and monitoring. - Who: National agencies (financial, health, transport) run sandboxes; regional blocs coordinate mutual recognition of lessons and approvals. - Rationale: Lowers barriers to innovation while enabling regulators to observe real‑world impacts and refine rules. 5. Model provenance, documentation and “model cards” mandates - What: Standardize and require metadata disclosures (training data provenance, capability statements, known limitations, safety evaluations) for models above a risk threshold. - Who: Standards bodies define schemas; national regulators mandate disclosures for market access; procurement rules require them for public contracts. - Rationale: Improves transparency for users, auditors, and downstream deployers; aids accountability and risk management. 6. Export controls and usage restrictions for high‑capability models - What: Restrict cross‑border transfer of models, weights, or specialized tooling that enable dual‑use harms; apply licensing and end‑use controls. - Who: National governments coordinate multilaterally (Wassenaar-like processes, G7, OECD) for harmonized controls; customs/security agencies enforce. - Rationale: Mitigates proliferation of capabilities that can be misused for cyberattacks, biological design, or large‑scale disinformation. 7. Mandatory red‑teaming and adversarial testing for high‑risk models - What: Require internal and external red‑teaming, with documented remediation before broad deployment. - Who: Firms perform tests; accredited independent red‑teams and standard test suites (via NIST/ISO) validate results; regulators set minimum requirements for high‑risk classes. - Rationale: Reduces unexpected failure modes and uncovers misuse vectors prior to release. 8. Liability frameworks and clarity on accountability - What: Define civil and administrative liability rules for harms caused by AI (differentiating manufacturers, deployers, and operators), and safe‑harbor paths for good‑faith compliance. - Who: Legislatures enact laws; courts refine standards through adjudication; regulators provide guidance and enforcement. - Rationale: Aligns incentives for safer design and careful deployment without stifling innovation. 9. Public procurement standards and certification requirements - What: Require certified safety, transparency, and impact assessments for AI used in government services. - Who: Governments set procurement rules; procurement agencies enforce; vendors comply to sell to public sector. - Rationale: Uses government buying power to raise baseline safety and set market norms. 10. Capacity building and technical assistance for lower‑resource countries - What: Fund and coordinate technical help (training, labs, policy toolkits) so more countries can assess and regulate AI responsibly. - Who: Multilateral development banks, OECD, UN agencies, regional organizations deliver programs; high‑income states fund and mentor. - Rationale: Reduces governance gaps, promotes interoperable standards, and prevents regulatory arbitrage. Implementation notes (short) - Layered approach: Combine voluntary standards for lower‑risk systems with mandatory rules and audits for high‑risk or high‑capability AI. - MutualTitle: Concrete AI Governance Options — What to Do and Who Should Act Below recognition: are practical Encourage international policy options, brief descriptions, and the actors best mutual recognition placed to implement each of certifications one. 1. Mandatory pre and test‑deployment impact assessments - results to What: Require developers/deploy reduce duplicationers to assess risks (safety, privacy, and friction fairness, security) before public release, with documentation. - and mitigation plans. - Who: National Privacy/security regulators (privacy/data balance: protection authorities, sectoral regulators), procurement Design reporting agencies for government use and sharing; companies must conduct and certify systems that assessments. - Why: Ident protect IPifies harms early and creates accountability and sensitive trail. 2. data while Risk‑based model enabling oversight certification and labeling - What. -: Independent certification for high‑ Iterationrisk models (safety tests: Use, red‑te sandboxesaming results), plus standardized labels/model cards and phased describing capabilities, limitations, and training data rollouts provenance. - Who so rules: National standards bodies and certifying agencies can adapt (or delegated third alongside rapid‑party conformity assessment bodies); technical change international standards bodies (ISO, OECD). Selected for harmonized criteria; industry references consortia to operationalize- OECD tests. - Why: Provides verifiable AI Principles assurance to regulators, purchasers, & AI and the public; supports cross Policy Observatory‑border interoperability. 3. Mandatory incident reporting and - shared near‑miss databases - What EU AI: Obligate organizations to report Act ( breaches, misuse, or seriousproposal) model failures to authorities and contribute- N anonymized near‑miss dataIST AI to secure Risk Management, shared repositories. - Who Framework : Regulators (- UNESCOcybersecurity agencies, sectoral overse Recommendation oners) the Ethics of AI to collect If you want reports; multilateral platforms (, IOECD, UN) or trusted intermedi can convertaries to host shared databases; industry required this into to submit. - Why: a one Enables collective learning, faster mitigation‑page, and evidence for policy brief policymaking. 4. Export tailored to controls and model capability classification a specific- What: Class actor (ify models by capability and restrict export ornational regulator access to high‑capability, tech models and associated tooling that pose firm, security risks. - Who: or international National governments (trade and security agencies) body). coordinating via multilateral fora (Wassenaar Arrangement, G7/OECD) to align thresholds. - Why: Limits proliferation of dual‑use capabilities while allowing legitimate research and commerce. 5. Regulatory sandboxes and conditional approvals - What: Time‑limited, supervised testing environments where companies can pilot systems under regulatory oversight and data protection safeguards. - Who: Regulators and innovation agencies to host sandboxes; standards bodies to set evaluation criteria. - Why: Balances innovation with risk control and informs rulemaking with real‑world evidence. 6. Mandatory transparency for government use and procurement rules - What: Governments must disclose AI use in public services, conduct public impact assessments, and adopt procurement rules requiring vendor safety attestations. - Who: National and local governments, public procurement offices, audit institutions. - Why: Protects civil rights, promotes accountability, and incentivizes safer products. 7. Liability rules and consumer redress mechanisms - What: Clarify legal responsibility for harms from AI (strict liability for certain harms, duty of care standards), and ensure accessible remedies for affected individuals. - Who: Legislatures to enact liability frameworks; courts to interpret; regulators to implement enforcement mechanisms. - Why: Creates stronger incentives for safe design and deployment. 8. Funding and coordination for global safety research and capacity building - What: Public funding for foundational safety research, grants for low‑ and middle‑income countries to build regulatory capacity, and mechanisms for secure sharing of safety knowledge. - Who: National governments, multilateral institutions (World Bank, OECD, UN), philanthropic funders, and research consortia. - Why: Reduces global disparities and supports informed governance. 9. Standards for data governance and access controls - What: Rules for data provenance, consent, and secure data‑sharing infrastructures for model training and evaluation. - Who: Data protection authorities, standards bodies (ISO, IEEE), and national legislatures. - Why: Protects privacy and improves auditability. 10. Ethical review boards and corporate safety governance - What: Require large AI developers to maintain independent safety boards, red‑teaming teams, and internal compliance processes with whistleblower protections. - Who: Companies (especially those operating advanced models), guided by industry codes and regulator minimum requirements. - Why: Strengthens internal checks and aligns corporate incentives with public safety. Implementation notes (short) - Mix of instruments: Use a layered approach—mandatory rules for high‑risk cases, standards/certification for technical assurance, and voluntary best practices for lower‑risk innovation. - Multilevel coordination: National laws needed for enforcement; international alignment (standards, export controls, data sharing) reduces fragmentation. - Phased rollout: Start with high‑risk sectors/models, pilot sandboxes/certification, then scale as methods mature. Key sources and precedents: EU AI Act (risk‑based rules, conformity assessment), NIST AI Risk Management Framework (assessment guidance), OECD AI Principles (nonbinding standards), export‑control frameworks (for dual‑use tech).

Continue this thread

This path ends here for now.

If you want to keep exploring this line of thought, open the editor and add the next question or answer from this endpoint.

Continue this thread in the editor on desktop.

Other paths you could read

Earlier, at Why this snapshot of AI governance was chosen — and where to read further, the conversation split. If this is not the thread you want, you can switch to one of the other paths below.

Node

Why this selection fairly represents the current state of AI governance

Read this path
Node

Why these governance efforts matter for policy and practice

Read this path
Node

Why “Actionable levers” matters — a brief explanation

Read this path
Node

Why a Realistic Assessment Matters

Read this path
Node

Regulatory Design and Comparative Approaches — A Short Explanation

Read this path
Node

Standards, Testing, and Technical Governance — A Short Explanation

Read this path
Node

Corporate Governance, Safety Teams, and Industry Norms — Why They Matter

Read this path
Node

International Coordination and Geopolitics — Why It Matters

Read this path
Node

Rights, Bias, and Public‑Interest Approaches in AI Governance

Read this path
Node

Security, Dual‑Use, and Export Controls — Short Explanation

Read this path
Node

Why Helen Toner (CSET) was selected — contribution summary

Read this path
Node

Karen Yeung — Algorithmic Regulation and Risk‑Based Frameworks

Read this path
Node

Why the NIST AI Risk Management Framework Is a Practical Technical Touchstone

Read this path
Node

Why cite David Kaye and Nicholas Eberstadt on model testing and capabilities evaluation

Read this path
Node

Joanna Bryson — AI ethics and governance, including accountability debates

Read this path
Node

Critiques by Timnit Gebru and Margaret Mitchell — Corporate Practice and Research Governance

Read this path
Node

Why Els Torreele and Allan Dafoe on Global Coordination and Institution‑Building

Read this path
Node

Why Read Henry Farrell and Abraham Newman on Geopolitics of Tech Standards

Read this path
Node

Ruha Benjamin — A Social Justice Lens on Tech and Governance

Read this path
Node

Cathy O’Neil — Critical Perspectives on Algorithmic Harms and Accountability

Read this path
Node

Miles Brundage — misuse risks, export controls, and governance options

Read this path
Node

Why the WHO/CSET/Biosafety authors’ work on bio-related dual‑use risks from generative models was selected

Read this path
Node

OECD AI Principles and Related OECD Guidance — Short Explanation

Read this path
Node

European Commission — EU AI Act (proposal and legislative texts)

Read this path
Node

NIST — AI Risk Management Framework (AI RMF) — Brief Explanation

Read this path
Node

Partnership on AI — publications and model governance guidance

Read this path
Node

Recent G7 / OECD / UN Statements on AI Safety and Coordination — Short Explanation

Read this path
Node

International Coordination on AI Governance — Annotated One‑Page Reading List

Read this path

Highlights

0 saved passages and connected ideas

No highlights yet

Select text to save it here.