top of page

Global AI Governance Enters the "Implementation Era": A Map to Understand International Rules, Standards, and Choices

Author: Professor David Lee Kuo Chuen (Compiled and Edited) | July 2026

Professor David Lee Kuo Chuen is a prominent scholar and thought leader specializing in FinTech, blockchain, Web3, and digital currencies. He is a Professor at the Singapore University of Social Sciences (SUSS) and holds concurrent academic appointments, including as an Adjunct Professor and researcher at the National University of Singapore (NUS).



If you are still asking, "Which AI governance framework should we actually follow?", you are not alone.

Over the past three years, global AI governance has rushed from the "Era of Principles" into the "Era of Hard Law," and has rapidly transitioned into the "Era of Implementation and Recalibration." In July 2026, the EU's Digital Omnibus Act was just revised, the UN's first Global AI Governance Dialogue convened in Geneva, and the Vatican released its first encyclical dedicated to AI. Meanwhile, your company might still be struggling to decide: EU AI Act, NIST, ISO 42001, or OECD Principles—which one should you choose, and how do you use it?

This article is not an academic paper; it is a practical map. It helps you dismantle this complex global AI governance machine, see the gears, chains, and switches inside, and tells you exactly what your organization should do right now.


I. Global AI Governance is Actually Just a "Five-Story Building"

We can imagine the entire global AI governance landscape as a five-story building:

  1. Global Norms Layer: UNESCO's Recommendation on the Ethics of AI (adopted by 193 countries), UN Global Digital Compact — providing the foundation of legitimacy.

  2. Hard Law / Treaty Layer: EU AI Act (with fines), Council of Europe AI Framework Convention (the first binding AI treaty) — non-compliance leads to severe consequences.

  3. Soft Law and Principles Layer: OECD AI Principles (2019/2024 revisions), G7 Hiroshima Code of Conduct — no fines, but they influence legislation and procurement.

  4. Standards and Certification Layer: ISO/IEC 42001 (certifiable management system), NIST AI RMF (voluntary framework) — helping you "operationalize" governance.

  5. Organizational Practice Layer: Your internal policies, model inventories, audit logs, incident response processes — this is the true "last mile."


Key Insight: Norms flow top-down, but evidence and practice build bottom-up. Without the fifth layer, the first four are just empty talk.



II. Three Major Tools, Three Approaches

The core tools of current international AI governance can be divided into three categories based on "binding force." Enterprises often need to use all three simultaneously:

Type

Representative Tools

Binding Force

Typical Scenarios

Hard Law

EU AI Act, Council of Europe Convention

Mandatory compliance, fines up to 7% of global turnover

Products targeting the EU market

Voluntary Frameworks

NIST AI RMF, OECD Principles

Voluntary adoption, but influences procurement and legislation

Internal risk management, government bidding

Certifiable Standards

ISO/IEC 42001

Requires third-party audit after adoption

Conveying trust to clients, boards, and regulators


Real-world enterprise practice: Comply with hard law + benchmark against voluntary frameworks + obtain certifications based on market demand. It is not a "choose one of three" scenario, but a "three-in-one" integration.



III. The EU AI Act: The "Hard Bone" You Must Chew

If you or your clients are involved in the EU market, the EU AI Act is an unavoidable starting point.

  • Risk Classification: Prohibited (unacceptable risk) → High Risk → Limited Risk → Minimal Risk. Obligations increase with risk.

  • Extraterritorial Effect: As long as the output of your AI system is used in the EU, you are under its jurisdiction—regardless of where your servers are located.

  • Key Changes in 2026: The Digital Omnibus Act postponed high-risk obligations to 2027/2028, but transparency obligations (Art. 50) remain strictly enforced starting August 2, 2026, including labeling AI-generated content and informing users.


A Practical Framework: Use "Seven Diagnostic Questions" to quickly classify your AI system: Does it meet the definition of an AI system? Is it prohibited? Is it high risk? Do transparency rules apply? Is it based on a GPAI model? What is your role (provider/deployer)? Which implementation date applies?



IV. Beyond Hard Law: Two "Must-Install Systems"

  1. NIST AI RMF — The "Operations Manual" for Internal Governance

    • Published by the US NIST; non-legal, non-certifiable, but already the de facto baseline for US procurement and corporate AI governance.

    • Four Core Functions: Govern → Map → Measure → Manage, forming a continuous cycle.

    • Added the "GenAI Profile" in July 2024, specifically targeting risk categories of large models (hallucinations, bias, privacy, CBRN, etc.).

  2. ISO/IEC 42001 — The Certifiable AI Management System

    • The first international certifiable AI management standard, in the same family as ISO 27001 (security) and ISO 9001 (quality).

    • PDCA Cycle (Plan-Do-Check-Act) + Annex A containing 38 controls.

    • Certification ≠ Legal compliance, but it provides a solid "scaffolding" for EU AI Act compliance.



V. OECD and UNESCO: Why Does Soft Law Have a "Hard Impact"?

  • OECD AI Principles (Adopted 2019, Revised 2024): Defined the globally accepted concept of an "AI System," which is directly cited by the EU AI Act and the Council of Europe Convention. The OECD.AI Policy Observatory tracks 1000+ policies across 80+ jurisdictions, serving as the "foundational database" for global AI policy.

  • UNESCO Recommendation (2021): Adopted by 193 countries, centering on human dignity, and providing the "Readiness Assessment Methodology (RAM)"—many countries conduct a RAM diagnosis before drafting AI legislation.


Summary in a Sentence: The OECD gives you a "common language," while UNESCO gives you "legitimacy and tools for developing nations."



VI. Asia: Translation, Not Transplantation

Asia is not simply copying European and American frameworks; it is "translating" and "localizing" them:

  • Singapore: IMDA Model Framework (updated to include Agentic AI) + AI Verify testing tool; MAS released FEAT principles, Veritas, and BuildFin.ai SAFR (2026).

  • China: Vertical rules on algorithmic recommendations, deep synthesis, generative AI, and content labeling; Global AI Governance Initiative + WAICO proposal (Shanghai, 2025).

  • Japan: AI Promotion Act (2025), light-touch regulation.

  • South Korea: AI Framework Act (effective January 2026).

  • ASEAN: Guide on AI Governance and Ethics, aligned with the OECD, deliberately light-touch.


Key Insight: Asian companies are bound by the extraterritorial effects of the EU while needing to comply with local rules. The ability to map across different frameworks is becoming the core competency of the next generation of compliance professionals.


VII. Agentic AI: The New Frontier of Governance

As AI evolves from "answering questions" to "executing tasks," the focus of governance is undergoing a fundamental shift:

  • From Model Risk → Behavioral Risk → Authorization Risk

  • Governance responses include: Permission controls, human-in-the-loop approvals, policy encapsulation, kill switches, and audit trails.


Case Study: A bank's large-model customer service system needs to simultaneously satisfy Article 14 of the EU AI Act (human oversight), ISO 42001 lifecycle controls, and the G7 Code of Conduct—one system, multiple frameworks.


VIII. National Pathways: A Spectrum, Not a Dichotomy

Not every country is taking the "EU-style hard law" route. National choices in 2025-2026 show clear divergence:

Country

Pathway

Characteristics

Brazil

EU-style Hard Law

PL2338/2023, risk-based, aligned with the EU

UK

Sector-led

No dedicated AI law; 5 principles enforced by existing regulators

India

Light Regulation

7 "Tenets," based on the IT Act, no overarching legislation

Australia

Voluntary First

Mandatory guardrails paused; relies on existing laws + voluntary standards


Teaching Point: Most countries globally are moving toward a soft-law, interoperability-leaning path of "existing laws + voluntary standards + AI Safety Institutes," rather than a single EU-style hard law.



IX. What Should Your Organization Do Now?

If you only have five minutes, please take away these six actionable recommendations:

  1. Involved in EU Business → Immediately classify your AI systems to confirm if the EU AI Act applies, especially the transparency obligations (August 2, 2026).

  2. Need an Internal Risk Methodology → Start with the NIST AI RMF + GenAI Profile; it is free, flexible, and carries no audit burden.

  3. Clients or Regulators Demand Proof of Trust → Implement and certify ISO/IEC 42001, integrating it with ISO 27001.

  4. Drafting National Policy or Teaching → Base it on the OECD Principles + UNESCO Recommendation (RAM/EIA).

  5. Developing Frontier/Advanced Models → Commit to the G7 Hiroshima Code of Conduct + HAIP reporting, and track EU GPAI rules and Safety Institute evaluations.

  6. Want to Shape Industry Consensus → Participate in WEF/GPAI working groups and track IEEE standards—compliance is defense, shaping consensus is offense.


Conclusion: Governance is Not an Obstacle; It is the Raw Material of Trust

Global AI governance may seem complex, but its underlying logic is not hard to grasp:Hard law draws the bottom line, frameworks provide the language, standards build trust, and ethics guide the direction.

2026 is not the year "governance is completed," but the year "governance truly begins to operate." Those who view compliance merely as a cost center will feel exhausted; those who view governance as trust infrastructure will see opportunities.

Human-led, AI-empowered. The same applies to governance.


This article is based on Professor Li Guoquan's July 2026 teaching notes, "AI Governance from International Organisations," and has been reviewed and confirmed by the professor.



[Limited-Time Expert Consultation Invitation]

FOFA sincerely invites visionary entrepreneurs and investors to engage in deep, practical exchanges regarding the aforementioned trends, we will provide you with a complimentary expert planning consultation to help you tailor a specific entrepreneurial path or investment blueprint, allowing technology leverage to serve your asset appreciation.


Book your strategic dialogue NOW:

Comments


bottom of page