Monday, July 20, 2026

Global AI Governance- where should it head to?

 Global AI Governance- where should it head to?

AI governance is often viewed as a debate about laws and regulations. But laws are only the surface. Underneath them lies a deeper question, what actually makes an AI system “safe,” and who gets to decide?
Three broad regulatory philosophies are emerging globally.

The United States largely prioritizes innovation. Regulation generally takes a lighter-touch approach, allowing AI development to move quickly while addressing risks as they emerge.

The European Union prioritizes safeguards. Organizations deploying high-risk AI systems are expected to demonstrate compliance through risk assessments, documentation, governance controls, and testing before deployment. Yet the recent delays to parts of the EU AI Act highlight an important reality: regulation alone is not enough. Without mature standards and assurance mechanisms to operationalize legal requirements, even well-designed legislation can face implementation challenges.

China takes a state-directed approach. Innovation is encouraged, but within a governance framework aligned with national priorities, social stability, and government oversight.

These are not simply three regulatory models they represent three different philosophies of who defines responsible AI and how accountability should be demonstrated.

Why this matters beyond regulation?Despite their differences, all three approaches eventually encounter the same challenge.A regulation may require AI to be “safe,” but it rarely specifies what safety looks like in practice, how it should be measured, or what evidence demonstrates compliance. That gap is where standards and assurance become critical.

Consider an organization that develops an AI system which satisfies regulatory expectations in its home jurisdiction. As it expands internationally, it undergoes an external audit in a market with stricter governance expectations. The issue isn’t that the AI system is unsafe it is that the organization cannot demonstrate its governance through recognised standards and evidence.

Increasingly, the differentiator will not simply be having governance policies. It will be the ability to demonstrate that those policies are operating effectively through credible assurance mechanisms.

This is why frameworks such as ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, and the NIST AI Risk Management Framework are becoming increasingly important. Regulations define the desired outcomes. Standards provide a structured way to demonstrate those outcomes.Assurance mechanisms provide confidence that organizations are genuinely meeting the required standard.

In my view, organizations that focus solely on complying with individual regulations risk missing the bigger picture. As AI becomes increasingly global, trust will depend not only on legal compliance but on the ability to demonstrate consistent, transparent, and accountable governance across jurisdictions.

Internationally recognised standards have an important role to play because they provide a common language that can operate across different legal systems while still allowing jurisdictions to reflect their own societal values and policy priorities.

Regulations will continue to differ across borders.Good governance principles should not.

Whether the future global baseline ultimately becomes ISO/IEC 42001, the NIST AI Risk Management Framework, or another emerging framework, the organizations that build governance capabilities around internationally recognised standards today are likely to be better positioned for tomorrow’s regulatory landscape.

Which framework do you think is most likely to become the de facto global baseline, and why?