Artificial intelligence is moving from an emerging technology into a general-purpose capability embedded across business, government and society. As organisations increasingly use AI to make recommendations, generate content, analyse information, automate processes and take actions on behalf of people, governments are moving beyond voluntary discussions about AI ethics and beginning to establish formal systems of governance. The result is not one global AI law, but a rapidly developing landscape of laws, regulations, standards, guidelines and assurance frameworks.
For organisations, this distinction matters. AI governance is no longer simply a question of whether a company complies with the European Union’s AI Act. Organisations operating internationally may simultaneously encounter European risk-based regulation, American sectoral and state-level requirements, China’s rules on algorithms and synthetic content, Singapore’s practical governance frameworks, Japan’s principles-based approach, Korea’s new foundational AI legislation and Australia’s emerging guardrails. At the international level, frameworks from the OECD, UNESCO, the Council of Europe and standards organisations are creating a common vocabulary around issues such as human oversight, transparency, safety, accountability, privacy, fairness and risk management.
The practical consequence is that organisations should not build AI governance around one regulation alone. A better approach is to establish an internal AI governance system that captures the common requirements appearing across leading jurisdictions and then maps additional country- or sector-specific obligations onto that foundation. In other words, regulation should become one input into an organisation’s AI operating model rather than the entire operating model.
What is AI governance?
AI governance is the system through which an organisation directs, controls, monitors and accounts for its use of artificial intelligence. It covers much more than legal compliance. A mature governance system determines which AI applications an organisation is willing to use, which uses require additional controls, who is accountable for AI-related decisions, what information must be documented, how AI systems are tested, how humans supervise AI outputs, how incidents are reported and how affected individuals can challenge or appeal important outcomes.
This is important because the risk associated with AI does not come solely from the underlying model. The same model can be relatively harmless in one context and highly consequential in another. An AI assistant used to summarise internal meeting notes is fundamentally different from an AI system used to assess job applicants, approve loans, recommend medical treatment or control critical infrastructure. AI governance therefore increasingly focuses on the combination of the technology, its purpose, its deployment environment, the people affected and the consequences of failure.
This principle appears across the leading international frameworks. The OECD AI Principles, updated in 2024, promote trustworthy and innovative AI that respects human rights and democratic values, while emphasising transparency, safety, robustness, accountability and the ability for people to challenge outcomes. The emerging international consensus is therefore not that every AI system should be regulated in the same way. Instead, governance should generally be proportionate to the potential impact of the system.
The EU AI Act: the world’s most comprehensive horizontal AI law
The European Union’s AI Act is the most significant example of this approach. It establishes a horizontal legal framework that applies across sectors and classifies AI according to the risks associated with particular applications. It is designed around four broad categories: prohibited practices, high-risk AI, AI systems subject to specific transparency obligations, and systems presenting minimal or no risk.
The central idea is straightforward: the greater the potential harm to people, safety or fundamental rights, the greater the governance obligations. Most low-risk applications do not face extensive regulatory requirements. Higher-risk applications can require risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity and ongoing monitoring.
The EU framework is particularly significant because it regulates the AI value chain rather than treating AI as merely a software feature. Obligations can fall on providers developing AI systems or general-purpose AI models, as well as organisations deploying AI. The Act also establishes specific obligations for general-purpose AI models, including technical documentation, copyright policies and public summaries of training content. The most capable models with systemic risk face additional requirements around evaluation, risk mitigation, incident reporting and cybersecurity.

The EU has also moved beyond the original legislation into implementation. The AI Act entered into force in August 2024, while prohibited practices and AI literacy requirements began applying in February 2025 and GPAI obligations began applying in August 2025. As of August 2026, transparency obligations are also applying. Following the 2026 AI Omnibus, the main high-risk obligations have been given additional transition time: high-risk systems in areas such as employment, education, biometrics and critical infrastructure are scheduled for December 2027, while AI embedded in regulated products such as medical devices, toys and machinery has a transition to August 2028. This makes the EU model particularly important for global companies. Even organisations that are not headquartered in Europe may encounter the Act when their products, services or AI systems enter the EU market or are used within its jurisdiction.
The EU model is more than compliance
One of the most important lessons from the EU approach is that AI governance needs to be established before deployment rather than after something goes wrong. Risk classification should occur when an AI use case is proposed, followed by appropriate assessment, controls, documentation and monitoring.
For organisations, this suggests that an AI inventory should become a core governance asset. Every significant AI system should have an identified owner, intended purpose, model or provider, data sources, users, affected stakeholders, risk classification, applicable regulations, controls, testing evidence and monitoring arrangements. This is also why the EU’s governance model is relevant outside Europe. Even where a particular organisation is not legally subject to the AI Act, the underlying operating practices provide a useful baseline for managing consequential AI.
The United States: innovation-first, standards-driven and increasingly fragmented
The United States presents a fundamentally different regulatory model. Rather than establishing a single comprehensive federal AI law comparable to the EU AI Act, the US has historically relied on existing sectoral regulation, executive action, technical standards and state-level legislation.
The National Institute of Standards and Technology’s AI Risk Management Framework remains one of the most influential practical frameworks in the world. It provides a voluntary structure for managing AI risks across the lifecycle, with the Generative AI Profile extending the framework to risks specific to generative AI. NIST describes the framework as a resource for incorporating trustworthiness considerations into the design, development, use and evaluation of AI systems.
The current US federal direction is increasingly focused on maintaining American AI leadership and reducing regulatory fragmentation. A December 2025 executive order called for a minimally burdensome national AI policy framework and challenged what the administration considers excessive or conflicting state AI regulation. The administration subsequently issued legislative recommendations for a national framework.
The result is a very different governance philosophy from Europe. The US approach places greater emphasis on innovation, competitiveness, national security and voluntary risk-management standards, while individual states and existing federal regulators continue to play important roles. For businesses, this means that “US AI compliance” cannot simply be treated as a single checklist. Organisations must consider applicable federal requirements, state laws, sectoral regulation, contractual obligations and voluntary standards such as NIST AI RMF.
China: AI governance as both safety regulation and industrial policy
China has developed another distinctive model. Rather than waiting for a single comprehensive AI statute, China has progressively introduced rules covering specific aspects of the AI ecosystem, including algorithmic recommendation systems, deep synthesis, generative AI and AI-generated content. This approach combines technology governance with broader objectives around cybersecurity, information management, social stability and industrial development. China’s regulatory system therefore places significant emphasis on the providers of AI-enabled internet services and on the management of generated and distributed information.
A particularly important development is China’s AI-generated synthetic-content labelling regime. The 2025 rules require applicable providers to use both visible and hidden identification mechanisms for AI-generated or synthetic text, images, audio, video and virtual scenes. Metadata and other technical mechanisms are used to support traceability, while platforms distributing content also have responsibilities for identifying and labelling synthetic material.
The Chinese model therefore demonstrates an important dimension of AI governance that is sometimes underemphasised in Western discussions: governance is not only about preventing discrimination or protecting individual rights. It can also encompass information integrity, content provenance, platform responsibility, national security and control over the digital information environment.
Singapore: governance designed to be operational
Singapore represents perhaps the clearest example of a country attempting to bridge the gap between regulation and practical implementation. Rather than relying exclusively on legislation, Singapore has developed a combination of governance frameworks, testing methodologies, assurance tools and sectoral initiatives.

Singapore introduced its Model AI Governance Framework in 2019 and updated it in 2020. The framework focuses on practical organisational measures including internal governance structures, clear responsibilities, explainability, transparency, fairness, human-centricity and risk management. Singapore subsequently developed AI Verify, a testing framework and software toolkit designed to help organisations assess AI systems against governance principles such as transparency, explainability, reproducibility, safety, security, robustness, fairness, data governance, accountability and human agency.
Singapore has now moved into another important stage of AI governance: agentic AI. In 2026, the Infocomm Media Development Authority introduced and updated a Model AI Governance Framework for Agentic AI. The framework addresses a new problem created by AI systems that can plan, execute tasks and interact with external systems with varying degrees of autonomy. It emphasises bounding agent powers, establishing meaningful human checkpoints, implementing technical controls throughout the lifecycle and ensuring end-user responsibility and transparency.
This is significant because the governance problem changes as AI becomes more autonomous. Traditional AI governance often asks whether a model’s output is accurate and fair. Agentic AI governance must additionally ask what the system is authorised to do, what systems it can access, what actions require approval, how its actions can be reversed and who remains accountable when the AI acts autonomously.
Japan: principles, guidance and responsible implementation
Japan has generally favoured a more flexible approach than the EU. Rather than immediately imposing a broad, prescriptive AI law, Japan has developed guidance intended to encourage responsible AI development and deployment while preserving room for innovation. Japan’s AI Guidelines for Business consolidate earlier AI research, utilisation and governance guidance. The framework is designed to help AI developers, providers and users implement responsible AI practices while adapting to rapid technological change. Japan continued updating these guidelines, with version 1.2 released in March 2026.
The Japanese approach is useful for organisations because it illustrates another regulatory philosophy: governance does not always have to begin with detailed statutory requirements. Principles, organisational responsibilities, risk assessment and practical guidance can provide a flexible foundation that evolves alongside technology. For multinational organisations, Japan’s model reinforces the value of maintaining a governance framework capable of absorbing new requirements rather than rebuilding the entire compliance structure whenever a jurisdiction introduces new guidance.
Korea: moving toward a comprehensive national AI framework
South Korea is taking a more formal legislative route. Its AI Basic Act, passed in December 2024 and taking effect in January 2026, establishes a foundational legal framework for AI development and trustworthy AI while simultaneously supporting national AI competitiveness. The Korean government described the legislation as an attempt to establish a foundational law appropriate to Korea’s economic and social circumstances while building trustworthy AI infrastructure.
Korea is therefore interesting because it sits between the EU and more flexible Asian governance models. It recognises the need for a national legal foundation while maintaining a strong emphasis on AI development, industrial competitiveness and national capability. The broader lesson is that AI governance is increasingly becoming part of national industrial strategy. Governments are not simply deciding how to constrain AI. They are simultaneously deciding how to build AI capability, support domestic companies, attract investment, develop infrastructure and establish trust.
Australia: practical guardrails and organisational accountability
Australia provides another useful model. Its government developed a Voluntary AI Safety Standard consisting of ten guardrails covering accountability, risk management, data governance, testing, human oversight, transparency, contestability and other governance measures. The standard applies across the AI supply chain and is explicitly designed to help organisations manage AI risks throughout the lifecycle. Australia had previously consulted on mandatory guardrails for high-risk AI, but the government has since stated that it will not proceed with those previous proposals at this time, with feedback informing development of its National AI Plan. The voluntary framework nevertheless provides a useful picture of what practical AI governance looks like when translated into organisational controls. One particularly valuable principle in the Australian approach is that accountability cannot simply be outsourced to the AI provider. Organisations deploying third-party AI still need to understand the system’s risks, data provenance, security, performance and appropriate controls. [Voluntary AI Safety Standard Australia]
The Council of Europe: AI governance as a human-rights framework
Beyond individual countries, the Council of Europe has created an important international layer. Its Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the first international legally binding treaty specifically addressing AI in this field. The Convention takes a lifecycle approach and requires AI activities to remain consistent with human rights, democracy and the rule of law. It incorporates risk and impact assessments, prevention and mitigation measures, transparency, accountability, equality, privacy, reliability and safe innovation. It also allows for bans or moratoria on certain applications where appropriate. This is significant because it frames AI governance differently from purely technology-oriented regulation. The fundamental question is not simply whether an AI system works, but whether the way it is designed and used is compatible with the rights and institutions of society.
From different regulations to a common global AI governance model
Despite their substantial differences, the world’s leading AI governance regimes are beginning to converge around a surprisingly consistent set of concepts. The terminology varies, and the legal obligations differ, but organisations repeatedly encounter the same underlying questions. Who is accountable for the AI system? What is the intended purpose? What could go wrong? Who could be harmed? What data does the system rely on? How was it tested? How accurate and robust is it? Can humans intervene? Are users aware that AI is involved? Can affected people challenge important outcomes? Are incidents detected and reported? Can the organisation demonstrate what happened after the fact?
These common questions provide the foundation for a globally useful AI governance framework.
The first layer should be accountability. Every material AI system should have an identifiable business owner and clearly defined responsibilities across development, procurement, deployment, monitoring and incident response. Accountability should remain with people and organisations rather than being attributed to the AI system itself.
The second layer should be purpose and risk classification. Organisations should document what each AI system is intended to do and assess the consequences of failure, misuse or unexpected behaviour. Risk should be determined by the combination of technology and use case rather than by the model alone.
The third layer should be data governance and provenance. Organisations need to understand what data an AI system uses, where it came from, what rights apply to it, how it is protected and whether it is sufficiently accurate and representative for the intended purpose.
The fourth layer should be testing and assurance. AI systems should be evaluated before deployment and monitored afterwards. Testing should cover not only technical performance but also security, robustness, bias, reliability, misuse, adversarial behaviour and the specific harms identified during risk assessment.
The fifth layer should be human oversight and control. Human involvement should not be reduced to a nominal approval step. For consequential systems, people need sufficient authority, competence, information and time to intervene. As AI becomes more autonomous, governance must increasingly define what the system may do without approval and which actions require human authorisation.
The sixth layer should be transparency and provenance. People should know when they are interacting with AI when that information matters. Organisations should also be able to identify AI-generated or manipulated content where appropriate. This is becoming particularly important as synthetic media becomes increasingly difficult to distinguish from human-created material.
The seventh layer should be contestability and redress. Where AI can materially affect a person, organisations should provide mechanisms for questioning, reviewing and correcting outcomes. A governance system that can detect an error but provides no mechanism for correcting the consequences is incomplete.
The eighth layer should be security and resilience. AI introduces new attack surfaces, including prompt injection, model manipulation, data poisoning, model extraction and attacks against connected tools and agents. Security therefore needs to be considered throughout the AI lifecycle rather than treated as an infrastructure issue alone.
The ninth layer should be continuous monitoring and incident management. AI governance cannot be a one-time approval exercise. Models, data, users, environments and use cases change. Organisations therefore need mechanisms for detecting unexpected behaviour, recording incidents, escalating significant events and reassessing risk when systems materially change.
Finally, organisations need AI literacy and organisational capability. Governance cannot work if employees do not understand what AI systems can and cannot reliably do. The EU explicitly incorporates AI literacy into its regulatory framework, while Singapore, Australia and other jurisdictions similarly emphasise organisational capability and training.
A global AI governance architecture
These principles can be organised into a practical governance architecture. At the foundation is the AI inventory: a continuously maintained record of the AI systems an organisation develops, purchases, deploys or materially relies upon. Above this sits AI risk classification, which determines the level of governance required for each system. The next layer is lifecycle governance, covering procurement or development, data, testing, approval, deployment, monitoring, change management and retirement. Alongside this should sit organisational governance, defining the roles of boards, executives, AI owners, technical teams, legal and compliance functions, risk management, cybersecurity and affected stakeholders.
A separate but connected layer should address assurance. This includes testing, validation, documentation, audits, impact assessments and evidence that controls actually work. Finally, the organisation needs an incident and remediation system capable of detecting problems, escalating them and ensuring that lessons are incorporated back into the governance process. This architecture is more resilient than building separate compliance programmes for every jurisdiction. The organisation establishes one global baseline and then maps regulatory requirements onto it.
Regulation should be treated as a minimum, not the objective
One of the most important mistakes organisations can make is treating AI governance as a legal checklist. Compliance answers the question: What does the law require us to do? Governance asks a larger question: What should we permit AI to do, under what conditions, with whose authority and with what consequences if it fails? The distinction becomes increasingly important as AI systems become more capable. A system may technically comply with a regulation while still being poorly governed. For example, an organisation might disclose that an AI system is being used but fail to provide meaningful human oversight. It might document a model but fail to monitor how employees actually use it. It might conduct an initial risk assessment but never revisit it after connecting the AI to new data or tools. Effective AI governance therefore needs to operate as a management system rather than a compliance document.
The emergence of AI assurance
The next stage of AI governance is likely to move from policy into assurance. Organisations will increasingly need evidence that their AI systems actually satisfy the requirements established by their policies, contracts and applicable regulations. This is where frameworks such as NIST AI RMF, Singapore’s AI Verify and emerging international standards become particularly valuable. They translate broad principles into testable practices.
The long-term direction is therefore likely to resemble other mature areas of corporate governance. Financial systems are subject to controls and audits. Cybersecurity systems are subject to testing and monitoring. Privacy programmes maintain inventories, assessments and incident processes. AI will increasingly become another organisational control domain, with its own inventory, risk assessments, testing, documentation, monitoring and assurance mechanisms.
The next challenge: agentic AI
Generative AI has already changed the governance problem by making AI accessible to almost every employee. Agentic AI changes it again. A conventional generative AI system primarily produces an output in response to a prompt. An agent can potentially interpret an objective, formulate a plan, call tools, access databases, communicate with external parties and execute actions. The risk therefore shifts from what the AI says to what the AI is empowered to do. This is why Singapore’s 2026 framework for agentic AI is particularly significant. It explicitly addresses bounding agent powers, human checkpoints, technical controls and responsibility across the agent lifecycle.
Future AI governance frameworks will therefore need to distinguish between informational AI, decision-support AI, decision-making AI and autonomous action-taking AI. The more control an AI system has over external systems, money, data, physical infrastructure or consequential decisions, the stronger the required controls should become.
What organisations should do now
An organisation beginning its AI governance programme should not start by attempting to interpret every AI regulation in every country. It should first establish an enterprise-wide AI inventory and determine where AI is being developed, purchased, embedded, deployed and used informally by employees. Each significant AI use case should then be assigned an accountable owner and documented according to its purpose, users, affected stakeholders, data, underlying models or providers, level of autonomy and potential consequences. The organisation should assess the system against a common risk framework and then map the relevant legal and regulatory requirements onto that assessment.
The resulting governance process should determine what controls are required before deployment. Low-risk productivity tools may require basic approval, data protection and usage rules. More consequential systems may require formal testing, impact assessments, human oversight, security evaluation, contractual controls, monitoring and documented approval. Systems that cross defined organisational or legal red lines should not be deployed at all.
The organisation should also establish a mechanism for continuous reassessment. A system should not remain classified as “approved” indefinitely. Changes to models, data, integrations, users, autonomy or intended purpose should trigger reassessment. Most importantly, organisations should build governance into procurement. A company buying an AI service is still responsible for understanding the risks created by deploying it. Contracts should therefore address data use, security, model changes, incident notification, service levels, audit rights, transparency, intellectual property and responsibilities between the provider and deployer.
A global baseline for responsible AI
The global AI regulatory environment may remain fragmented for years. The EU is unlikely to abandon its risk-based legal model, the US is pursuing a more innovation-oriented national framework while state regulation continues to evolve, China is developing a tightly managed technology and information governance system, and countries such as Singapore, Japan, Korea and Australia are experimenting with different combinations of law, standards, guidance and assurance. Yet fragmentation does not mean there is no common direction.
Across these systems, a broad governance consensus is emerging around accountability, risk management, human oversight, transparency, data governance, safety, security, fairness, contestability, documentation and continuous monitoring. The OECD AI Principles provide one of the clearest international expressions of this convergence, while the Council of Europe has begun translating similar concepts into an international legal framework.
For organisations, the strategic response should therefore not be to build a collection of disconnected “EU compliance”, “China compliance”, “Singapore compliance” and “US compliance” programmes. The better approach is to establish a global AI governance operating system built around common principles and controls, with jurisdiction-specific requirements layered on top. The objective of AI governance is ultimately not to prevent organisations from using AI. It is to create the organisational capability to use increasingly powerful AI systems deliberately, safely and accountably.
The most mature organisations will therefore treat AI governance in the same way they treat cybersecurity, financial controls, data governance and enterprise risk: not as a barrier to innovation, but as the infrastructure that allows innovation to scale with confidence.

