The Human-Ai Institute
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
A successful first Global Dialogue should produce four concrete outcomes. First, a Co-Chairs' summary that names the operational gap as the central challenge: the distance between principle-level commitments (in UNESCO 2021, the OECD AI Principles, A/RES/79/325) and the organisational decisions that determine whether those principles are honoured in practice. Restating principles at the international level is no longer the binding constraint; equipping Regulators and the Regulated to act on them consistently is. Second, explicit recognition that governance must operate at multiple levels simultaneously. International instruments addressed to Regulators, such as the UNECE WP.6 Overarching Common Regulatory Arrangement (CRA) on products with embedded AI (ECE/TRADE/486, 2024), need organisational counterparts addressed to the Regulated, bound together by a common rights-based ethical filter. The Dialogue should encourage integrated multi-level governance stacks rather than promoting any single instrument in isolation. Third, a clear preference for interoperability through mapping rather than top-down harmonisation. The Dialogue can usefully invite Member States and stakeholders to publish formal cross-walks between national requirements and major international references, so convergence is achieved bottom-up and remains compatible with jurisdictions of differing institutional capacity. Fourth, a workplan that moves from pre-deployment conformity assessment toward continuous, indicator-based oversight, particularly for general-purpose and frontier systems. Static conformity is insufficient when AI systems evolve through updates and learning after release. Underpinning all four, success looks like a Dialogue that treats AI conduct risk and human conduct risk symmetrically, recognising that AI systems and their human principals create risks that cannot be supervised in isolation. If the Geneva and New York sessions deliver these outcomes, the Dialogue will have laid durable foundations rather than producing another set of high-level statements.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Interoperability of governance approaches
- Protection and promotion of human rights
- Safe, secure and trustworthy AI
Please briefly explain your selection.
2
The primary clusters selected, namely Cluster 3 (Safe, secure and trustworthy AI: responsible and interoperable approaches) and Cluster 4 (Respecting, protecting and promoting human rights: transparency, accountability and human oversight), are selected because they together capture the operational core of AI governance. Cluster 3 frames the question of how regulatory cooperation can produce trustworthy outcomes without imposing a single regulatory model on jurisdictions of widely differing capacity. Cluster 4 frames the question of how rights commitments translate from principle into testable organisational decisions. The Enterprise-Wide AI Risk Management Framework (EW-AiRM) is directly relevant to both. Its design is mapping-native (consistent with ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF, the EU AI Act, DORA, the GPAI Code of Practice and the UNECE CRA), lifecycle-anchored, and freely adoptable. This addresses Cluster 3's interoperability priority. Its embedded ethical filter, HAiPECR, addresses Cluster 4 by translating UNESCO 2021's ten core principles into seven testable governance dimensions covering human oversight, accountability, inclusion, privacy and safety, ethics, conduct and resilience. The secondary clusters, Cluster 1 (AI opportunities and implications) and Cluster 2 (Bridging AI divides), are highly relevant but addressed through the same instruments. EW-AiRM's Strategic layer requires a necessity assessment before deployment, which speaks directly to Cluster 1's framing of opportunity and implication as interconnected. The open and standards-bridging design of EW-AiRM and HAiPECR makes them suitable for capacity-building partnerships under the Global Digital Compact, addressing Cluster 2 without locking developing jurisdictions into any single regulatory bloc. Selecting Clusters 3 and 4 as primary therefore reflects where the operational gap is widest, while the secondary selections recognise that opportunity-realisation and bridging divides are best advanced through the same governance instruments rather than through separate workstreams.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
1
First, the operational gap. The listed themes capture the substantive policy aims but not the persistent gap between principle-level commitments and the organisational decisions that determine whether those principles are honoured. This is itself a governance topic and should be named as such. Second, the symmetry between Regulators and the Regulated. International instruments addressed to governments (such as the UNECE CRA on products with embedded AI) require operational counterparts addressed to non-government enterprises. Without that pairing, policy declarations cannot, by themselves, change organisational behaviour. Third, AI conduct risk and human conduct risk treated symmetrically. AI systems and the human principals who design, deploy and supervise them create risks that cannot be supervised in isolation. Most current frameworks implicitly assume the human side is governed by existing professional, fiduciary or fitness-and-propriety rules, but AI-specific human-conduct expectations remain underdeveloped. The UN Universal Conduct Risk Paradigm (UCRP) offers one starting point. Fourth, AI Black Swans and emergent multi-agent failure. Failure modes generated by interactions between AI systems, rather than within a single system, fall outside most existing risk taxonomies. As agentic and multi-agent deployments expand, governance frameworks need explicit categories for interaction-generated and cascade failures. Fifth, neurotechnology and AI convergence. UNESCO's 2024 Recommendation on the Ethics of Neurotechnology marks a domain where AI governance, data protection and bodily integrity intersect. The Dialogue should ensure neural-data applications are not treated as a niche concern but as a foreseeable extension of trustworthy-AI requirements. These issues are addressable within the existing four-cluster structure, but only if the Co-Chairs' summary names them explicitly. Treating them as cross-cutting, rather than allocating them to a single cluster, reflects the fact that each cuts across opportunity, divides, trustworthiness and rights simultaneously.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
From a UK and European vantage point, and across the financial services and regulated-industry sectors in which the Human-AI Institute works, three challenges and three opportunities stand out. Challenges. First, regulatory multiplication. Regulated firms now face the EU AI Act, NIS2, DORA, ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF, the GPAI Code of Practice and sector-specific supervisory expectations, often with overlapping but non-identical requirements. Without mapping-native frameworks, organisations duplicate compliance work and small and medium-sized enterprises are disproportionately burdened. Second, the pace problem. AI capabilities and deployment patterns are evolving faster than supervisory capacity in most jurisdictions, including well-resourced ones. Pre-deployment conformity assessment alone is insufficient when systems update, learn and integrate after release. Third, the operational gap. Boards and senior management are committing to AI principles without yet having tested governance operating models through which to honour those commitments at the level of specific decisions, controls and indicators. Opportunities. First, the UNECE WP.6 Overarching CRA on products with embedded AI (ECE/TRADE/486, 2024) provides a credible international anchor that national authorities can adopt voluntarily, with Hungary as the first signatory and the Declaration open to all UN Member States. Second, frameworks such as EW-AiRM offer the regulated population a single, lifecycle-based operating model consistent with the major international references, reducing duplication across jurisdictions. Third, ethical filters such as HAiPECR (UNESCO-aligned, OECD-listed) translate the ten core principles of the UNESCO 2021 Recommendation into testable governance requirements, giving organisations and supervisors a shared language for human oversight, accountability, inclusion, privacy and safety, ethics, conduct and resilience. International cooperation under the Dialogue can reinforce these opportunities by encouraging integrated multi-level governance stacks rather than promoting any single instrument.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue is well-placed to play four distinct roles, each reinforcing the others. First, as a convenor of multi-level governance. The Dialogue should explicitly recognise that durable AI governance operates simultaneously at international, organisational and ethical levels, and that instruments at each level need counterparts at the others. The pairing of an instrument for the Regulators (such as the UNECE WP.6 Overarching CRA) with one for the Regulated (such as the Enterprise-Wide AI Risk Management Framework), bound by a common ethical filter (such as HAiPECR), illustrates how this can be done. Second, as a facilitator of interoperability through mapping. Rather than seeking a single global regulatory model, which is neither achievable nor desirable, the Dialogue can encourage Member States and stakeholders to publish formal cross-walks between national requirements and major international references including UNESCO 2021, the OECD AI Principles, ISO/IEC 42001, the NIST AI RMF and the UNECE CRA. This delivers convergence without imposing uniformity. Third, as a bridge across the AI divides. The Dialogue's reach extends beyond traditional standard-setting fora and can ensure that capacity-building partnerships under the Global Digital Compact draw on open, freely available frameworks suitable for jurisdictions with significant institutional and technical capacity deficits, rather than locking developing countries into any single regulatory bloc. Fourth, as a forum for the unfinished business. The Dialogue can name and progress topics that fall between existing initiatives, including AI conduct risk symmetry, multi-agent and cascade failure modes, neurotechnology-AI convergence, and the operational gap between principle and practice. Played together, these four roles allow the Dialogue to produce decisions that are both legitimate (because multi-stakeholder) and operational (because grounded in existing instruments rather than starting from scratch).
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
Existing initiatives the Dialogue should build upon include, at the international policy level, the UNECE WP.6 Overarching Common Regulatory Arrangement (CRA) on products with embedded AI and its Declaration (ECE/TRADE/486, 2024), UNESCO's 2021 Recommendation on the Ethics of Artificial Intelligence and 2024 Recommendation on the Ethics of Neurotechnology, the OECD AI Principles and the OECD AI Policy Observatory's Catalogue of Tools and Metrics for Trustworthy AI, the Global Digital Compact, and General Assembly resolution A/RES/79/325. At the standards and risk-management level: ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk management), the NIST AI Risk Management Framework, the GPAI Code of Practice, the WHO Ethics and Governance of AI for Health guidance, the EU AI Act, NIS2 and DORA, and the MIT FutureTech AI Risk Repository (more than 1,000 catalogued risks under CC BY 4.0). At the organisational and ethical-filter level: open frameworks listed on the OECD AI Policy Observatory, including the Enterprise-Wide AI Risk Management Framework (EW-AiRM) and HAiPECR. Within the UN system, the UN University Artificial Intelligence Network (UNU AI) and its founding members, including the Human-AI Institute (www.human-ai.institute) , can usefully serve as a delivery network for capacity-building. The added value the Dialogue can bring is fourfold. First, formal endorsement of integrated multi-level governance stacks rather than competition between individual instruments. Second, a mandate to develop cross-walks between the references above. Third, a bridge to jurisdictions currently outside the major standard-setting fora, particularly Base of the Pyramid markets. Fourth, sustained attention to the unfinished topics including AI conduct risk symmetry, multi-agent failure modes and the principle-to-practice gap. In short, the Dialogue's value is in coherence and reach, not in producing further new instruments.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Different stakeholders bring distinct and complementary contributions. Member States and national authorities (the Regulators) can share regulatory experience, signal adoption of voluntary instruments such as the UNECE Overarching CRA, and publish cross-walks against major international references. Industry and civil-society organisations (the Regulated, broadly defined) can contribute field-tested operating models, risk taxonomies, and lessons learned from deploying AI under existing regulation. Academia and research institutes can provide independent evidence, including through resources such as the MIT FutureTech AI Risk Repository (more than 1,000 catalogued risks; CC BY 4.0). International organisations and standard-setting bodies can ensure interoperability with existing instruments. Affected communities and civil society can ensure the framing remains grounded in lived experience. Recommendations for format and structure. First, organise around the multi-level governance stack rather than around the four thematic clusters in isolation. Each cluster is best examined at international, organisational and ethical levels in turn. Second, alternate plenary sessions with structured working groups dedicated to specific cross-walks, for example between UNESCO 2021, the OECD AI Principles, ISO/IEC 42001, the NIST AI RMF and the UNECE CRA. Working-group output should feed into the Co-Chairs' summary in concrete form. Third, ensure each Dialogue session includes one block specifically dedicated to the operational gap between principle and practice, drawing on practitioner case studies from both well-resourced and capacity-constrained jurisdictions. Fourth, provide low-barrier asynchronous channels alongside the in-person sessions, so that stakeholders unable to travel to Geneva or New York, including Base of the Pyramid voices, can contribute meaningfully. Fifth, publish all submissions in a searchable repository to enable cumulative work across sessions, rather than each session starting from scratch.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Several voices remain systematically underrepresented in global AI-governance discussions. Base of the Pyramid markets and lower-income jurisdictions. Most international AI-governance instruments originate in OECD or G20 contexts. Jurisdictions with significant institutional and technical capacity deficits are typically consulted late and invited to adopt instruments designed elsewhere. The forthcoming UN policy paper, provisionally titled ["Sovereign AI in Base of the Pyramid Markets"] (Mamun and Faride, [2026]), to which the author is providing analytical support and framework contribution, examines how this asymmetry can be redressed. Smaller and medium-sized regulated entities. Most operational risk-management discussion centres on large platforms or major financial institutions. The bulk of AI deployment occurs in smaller organisations that lack proprietary risk-tooling capacity, and their governance challenges deserve dedicated attention. Workers, end-users and communities affected by AI deployment. Their voices are often mediated through civil-society organisations, but direct testimony, particularly on inclusion (HAiPECR's i-dimension) and human oversight, is limited. Children and young people, whose AI-mediated environments raise distinct rights questions under the UN Convention on the Rights of the Child General Comment No. 25 (2021) but who rarely participate directly. Indigenous and minority-language communities, whose data, languages and cultural contexts are underrepresented in foundation-model training data and whose governance preferences are rarely solicited. Inclusion measures should include: structured Base of the Pyramid representation in every working group; dedicated capacity-building and travel support; asynchronous and multi-language submission channels; specific outreach to small and medium-sized regulated entities through national chambers of commerce and sector bodies; engagement with youth-oriented and child-rights organisations; and partnerships with indigenous-knowledge networks. The UN University Artificial Intelligence Network (UNU AI) and its founding members can serve as one delivery channel. Inclusion is, in HAiPECR terms, an embedded prerequisite, not a participation step.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
Six formats would together produce more meaningful and dynamic engagement than plenary panels alone. First, structured cross-walking workshops. Small mixed-stakeholder groups working line-by-line to map national requirements against major international references (UNESCO 2021, OECD AI Principles, ISO/IEC 42001, the NIST AI RMF, the UNECE CRA on products with embedded AI), producing publishable cross-walks as a tangible output. This converts abstract interoperability discussion into concrete artefacts. Second, case-clinic sessions. Practitioner-led examinations of specific AI deployment cases (regulated and unregulated, well-resourced and capacity-constrained) tested against the seven HAiPECR dimensions and the seven MIT FutureTech AI Risk Repository domains. Output: shared anonymised reference cases. Third, regulator-and-Regulated dialogues. Structured sessions pairing national authorities with the regulated population they oversee, focused specifically on the operational gap between principle and practice. The UNECE WP.6 model offers one precedent. Fourth, asynchronous working-group sprints between sessions. Time-bounded online collaboration on specific deliverables (cross-walks, indicator sets, capacity-building toolkits), so the Geneva and New York sessions consolidate work rather than starting from scratch. Fifth, scenario and simulation exercises. Multi-stakeholder tabletop exercises on AI Black Swan and multi-agent emergence scenarios, making cascade and interaction-generated failure modes tangible to policymakers, supervisors and the regulated alike. Sixth, youth and community panels. Direct, structured contributions from groups currently mediated through intermediaries, including young people under General Comment No. 25 (2021), workers, indigenous-knowledge holders and Base of the Pyramid representatives. Cutting across all six: low-barrier participation channels (multi-language, asynchronous, virtual-attendance options) and a searchable public repository of all submissions and outputs, so the Dialogue accumulates institutional memory rather than depending on each Co-Chairs' summary alone.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
5
The following examples, drawn from the author's own work and from the wider international landscape, illustrate effective AI-governance approaches that the Dialogue may wish to reference. At the international policy level. The UNECE WP.6 Overarching Common Regulatory Arrangement (CRA) on products and services with embedded AI and its accompanying Declaration (ECE/TRADE/486, 2024), under the author's project leadership, promotes voluntary convergence of national product regulations across five tasks, including regulatory objectives, risk assessment, reference to international standards, conformity assessment and market surveillance. Hungary became the first signatory; the Declaration remains open to UN Member States. At the organisational governance level. The Enterprise-Wide AI Risk Management Framework (EW-AiRM) is the natural evolution, at the organisational level, of the UNECE CRA. It is addressed to non-government enterprises (the Regulated/Regulatees), is mapping-native across ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF, the EU AI Act, DORA, the GPAI Code of Practice and UNESCO 2021, lifecycle-anchored across Strategic, Operational and Resilience layers, and instrumented through Key X Indicators (KXIs). Further details: www.EnterpriseWideAiRisk.Management and www.EWAIRM.Tools. At the cross-cutting ethical-filter level. HAiPECR translates UNESCO 2021's ten core principles into seven testable governance dimensions, covering Human oversight, Accountability, inclusion, Privacy and safety, Ethics, Conduct and Resilience. It is publicly available on the OECD AI Policy Observatory's Catalogue of Tools and Metrics for Trustworthy AI (https://oecd.ai/en/catalogue/tools/haipecr). Underpinning resources. The MIT FutureTech AI Risk Repository (more than 1,000 catalogued risks across seven domains and twenty-four sub-domains; CC BY 4.0) provides an evidence-based taxonomy organisations can map their portfolios against. These three instruments, treated as a stack, illustrate the multi-level governance approach this submission recommends.