Skip to content

Legend Biotech

Private Sector Western Europe and Other States

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

Success here shouldn't be measured by how sweeping the final declaration sounds. It should be measured by whether anyone can actually use it on Monday morning. Three things would make this Dialogue worth the trip to Geneva. - The first is a working definition of human oversight that means something. "Human in the loop" is in every framework I've read. It means something different in every organization I've spoken to. In some places, it means a human approved the model six months ago. In others, it means someone gets an email after the AI acts. Neither is oversight in any meaningful sense. The Dialogue should settle on a definition that distinguishes pre-action approval from post-action review, and be specific about which high-risk AI applications require which. - The second is a shift from approval as a finish line to governance as an ongoing obligation. Right now, most organizations treat vendor AI assessment as a one-time gate. Pass the questionnaire, get approved, move on. But the model that passed your assessment in January may not be the model running in July. Vendors update models, swap sub-processors, and change data handling policies, often quietly. A meaningful outcome would be an international consensus that AI governance doesn't end at deployment. It starts there. - The third is a seat at the table for practitioners in the regulated industry. Pharmaceutical companies, hospitals, and financial institutions - these organizations are deploying AI in environments where a wrong output isn't just embarrassing, it's a regulatory event. They're largely absent from international governance conversations. The frameworks being written in their absence will eventually govern them. That's a problem worth fixing in Geneva.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Safe, secure and trustworthy AI
  • Transparency, accountability, and human oversight
  • Interoperability of governance approaches
  • Social, economic, ethical, cultural, linguistic and technical implications of AI

Please briefly explain your selection.

6

These aren't abstract priorities for me. I run an AI governance program at a publicly traded pharmaceutical company. The gaps I'm selecting around are ones I hit every week. Safe, secure, and trustworthy AI is the starting point. In pharma, an AI system that misbehaves isn't a support ticket; it can affect patient safety or trigger a regulatory investigation. You can't patch your way out of that after the fact. It has to be built in. Transparency, accountability, and human oversight are where the real work is unfinished. I've read a lot of frameworks. Every one of them mentions human oversight. Almost none of them say what it means when an AI agent is taking autonomous actions in a live production system. Who's accountable? Did any human actually have a chance to stop it, or just a chance to read about it afterward? Those are different things, and we don't have agreed-upon answers yet. Interoperability of governance approaches is a practical problem my team lives with. We're simultaneously managing FDA requirements, GxP validation, the EU AI Act, and NIST. They don't speak the same language. The effort spent reconciling them doesn't make our AI safer; it just makes compliance more expensive and more confusing. Social, economic, ethical, and technical implications are the category that covers what actually happens when governance fails. Not in theory. In the hiring algorithm that screens out qualified candidates. In the fraud detection system that flags the wrong accounts. In the clinical tool that's confidently wrong. These aren't edge cases. International action on these four areas would change how AI governance actually works inside organizations. The others matter too, but these are where the gaps are widest right now.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

2

Two things are missing from the current list, and both are already causing problems. The first is what happens after a vendor gets approved. In my experience, and from conversations with peers across regulated industries, AI approval gets treated as a finish line. The questionnaire is answered, the vendor clears the process, and oversight stops. But the model that passed your assessment in January may not be the model running in July. Vendors retrain, swap infrastructure, update data practices, quietly add autonomous capabilities. No international framework I've seen creates clear obligations for what comes next: ongoing monitoring, mandatory change notifications, reassessment on a defined cycle, and confirmed data deletion at offboarding. That's where risk builds up. Quietly, over months, after everyone has moved on. The second is agentic AI: systems that don't surface recommendations but act on them directly. This isn't a future concern. It's being sold and deployed in enterprise environments right now, including in pharma and financial services. The governance questions it raises don't fit existing frameworks well. What can an agent do without human approval? What oversight applies when multiple agents act in sequence, and no single person reviewed the outcome? What happens when an autonomous action touches a regulated record or a production system? These aren't hypotheticals. They're procurement conversations happening this quarter. Both gaps point to the same problem. The international governance conversation is describing AI as it existed a few years ago. Post-deployment drift and autonomous action without clear accountability are the risks accumulating right now. They deserve their own space in the thematic structure, not a footnote under something else.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

I'll speak to the sector, pharmaceutical, and life sciences, because that's where I work and where these gaps are most visible to me. The core problem is pace. AI is moving into pharma faster than the governance infrastructure can follow. Right now, vendors are selling agentic systems that autonomously remediate vulnerabilities, generate infrastructure code, and execute workflows, inside environments where any undocumented change to a validated system is a regulatory problem. The frameworks being used to assess these tools were designed for AI that advises. Not AI that acts. That's not a theoretical gap. It's a live procurement conversation happening this quarter in organizations like mine. The second problem is framework fragmentation. A pharma company operating across the US and EU is simultaneously managing FDA requirements, GxP validation standards, 21 CFR Part 11, and the EU AI Act. They don't share definitions, risk tiers, or evidence requirements. Every inconsistency becomes reconciliation work, legal reviews, duplicated assessments, and parallel documentation, which consumes governance capacity without making anything safer. The third is what happens after a vendor gets approved. Most pharma organizations, once they've cleared a vendor through their assessment process, have no structured way to monitor what the AI does next. Whether it drifts. Whether the vendor changes something without notice. In an industry where audit trail completeness is a hard regulatory requirement, running blind after onboarding is not a sustainable position. Fixing it requires infrastructure and vendor cooperation that most of the sector hasn't built. The opportunity is that pharma already has the instincts for this. Validation culture, change control, documented decisions, audit trails, that's not a bad starting point for AI governance. It just needs to be extended. Frameworks that work with existing quality systems rather than alongside them would move faster and stick better.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

The most useful thing the AI Dialogue can do is something no single government or standards body can pull off alone: get the people writing governance frameworks into genuine conversation with the people implementing them. Those two groups are largely operating in parallel right now. Policymakers build frameworks based on how AI is supposed to work. Practitioners in regulated industries deal with how it actually works, vendors that change models without notice, agentic systems acting autonomously in environments nobody designed for that, and regulatory requirements that don't map onto each other. Most frameworks don't anticipate this. That gap is where governance breaks down, quietly, after everyone has moved on. Three things would make the Dialogue concretely useful. Making practitioner input permanent rather than periodic. A comment window at the end of a drafting process isn't the same as building deployment experience into how frameworks are developed from the start. The ones that hold up are tested against reality before they're finalized. Pushing toward shared definitions on the basics. Human oversight. High-risk AI. Meaningful accountability. Every major framework uses these terms. They don't mean the same thing across jurisdictions. The Dialogue has the convening authority to broker convergence on language without requiring full harmonization. That would reduce more real-world friction than most new frameworks would. Building an early warning function. When a new AI capability starts appearing in enterprise deployments, agentic systems, autonomous decision chains, and multi-model pipelines, there's currently no international forum where practitioners and policymakers can flag the governance gaps before they calcify. That forum doesn't exist. The Dialogue could be it. The goal shouldn't be another framework. It should be a standing mechanism for honest conversation between the people governing AI on paper and the people governing it in production.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

The groundwork is already there. The question is whether the Dialogue connects with it or builds alongside it. NIST's AI Risk Management Framework is the most widely used practical reference for organizations building internal AI governance programs, at least in the US. Regulated industries have been quietly adapting it for a couple of years now. Building on that vocabulary rather than introducing competing terminology would save practitioners real time and reduce the reconciliation burden that's already significant. The EU AI Act is the most serious attempt yet at binding, risk-tiered AI regulation. The implementation infrastructure being built around it, particularly for medical devices and critical infrastructure, is worth engaging with directly, not designing around. It's the closest thing to a working model of what binding governance actually requires in practice. The OECD AI Principles and the Global Partnership on AI have done the multilateral foundation work. No need to repeat it. The Dialogue should pick up from there. At the sector level, the FDA's evolving guidance on AI in drug development and the EMA's parallel work in Europe are doing something important: translating abstract governance principles into requirements a regulated industry can actually follow. That work deserves more than a peripheral mention in international discussions. It's evidence that sector-specific governance can be done, and done rigorously. What the Dialogue has that none of these initiatives do is reach. NIST is American. The EU AI Act is European. The OECD works within its membership. The UN talks to everyone. That's not a small thing. The opportunity is to use that convening authority to connect these parallel tracks, technical, regulatory, and sectoral, rather than launching another one that practitioners will eventually have to reconcile with the rest.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

The Dialogue will be shaped by who's actually in the room. And the default lineup, governments, large tech companies, academics, leaves out the organizations running AI in high-stakes environments every day. Different stakeholders bring different things. Governments have regulatory authority. Tech companies know what the models can and can't do. Academics bring research depth. But practitioners inside pharmaceutical companies, hospitals, financial institutions, and critical infrastructure operators bring something none of the others have: experience of what governance looks like when it has to hold up under regulatory scrutiny, with real consequences when it doesn't. That perspective is closest to where AI risk actually shows up. It deserves a formal seat, not an occasional consultation slot. On format, the smallest sessions will do the most work. Large plenaries produce careful consensus language. Mixed working groups of fifteen people, practitioners alongside policymakers alongside technical experts, produce honest conversations about where the gaps actually are. Geneva should weigh the schedule toward those. There also needs to be a way to stay connected between convenings. This submission process is a start. A standing practitioner advisory group meeting in the gap between Geneva and New York would be better. The AI landscape in 2027 will look different from today. A Dialogue that only updates itself every eighteen months will fall behind. And the Dialogue should be honest about who isn't there. Which sectors. Which regions. Which organization sizes? Naming the absences publicly creates at least some accountability for closing them before the next round. A process that only includes stakeholders with the resources and connections to participate will produce governance that works for them. The organizations most exposed to AI risk are often not those organizations.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

Three groups keep getting left out. Their absence shows up directly in what the frameworks get wrong. Regulated industry practitioners are the most obvious gap. The people deploying AI inside pharmaceutical companies, hospitals, financial institutions, and critical infrastructure operators are rarely in the room when international frameworks get written. This matters in a specific way: regulated industries face AI governance consequences that generic frameworks don't anticipate. An AI system behaving unexpectedly in a pharma environment isn't a reputational problem; it can be a regulatory violation with legal consequences. The frameworks being written without these practitioners will still govern them. Submission processes like this one are useful. Permanent sector-specific working groups with real practitioner seats would be more useful. Small and mid-sized organizations are the second gap. International AI governance is shaped by large tech companies and large governments. But most AI deployment happens inside organizations without dedicated AI ethics teams, without legal departments tracking multiple regulatory frameworks, without anyone whose job it is to engage with international policy processes. Their version of AI governance, under-resourced, framework-overloaded, dependent on vendor assurances, is almost absent from the conversations producing the rules they'll eventually have to follow. Getting them included requires deliberately lowering the barriers: simpler participation mechanisms, regional representation structures, guidance that doesn't assume specialist staff. The third is frontline workers. Nurses, pharmacists, financial advisors, infrastructure operators, and people whose professional judgment AI is increasingly being asked to augment or replace. They have direct visibility into where AI fails in practice, where human oversight is meaningful versus performative, and where automation creates risks that neither developers nor policymakers saw coming. That knowledge is governance-relevant. It should be treated as input, not collected as feedback after the decisions are made. These groups won't find their way in without deliberate design. That's the design problem worth solving.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

The formats that work are the ones that make prepared answers harder to give. The most useful change would be replacing formal address sessions with structured problem-solving workshops. Instead of stakeholders presenting positions to a room, put practitioners, policymakers, and technical experts in small groups around a specific problem. How do you define meaningful human oversight for an agentic system? What should mandatory vendor notification of a model change actually require? Give them ninety minutes and a facilitator. What comes out of that will be more useful than most keynotes. Red team sessions should be on the formal agenda. A practitioner presents a real AI governance failure, anonymized if needed, and a mixed group works through what existing frameworks would and wouldn't have caught. It grounds abstract discussion in something that actually happened and surfaces gaps that position papers don't find. Most policy dialogues avoid this format because it's uncomfortable. That discomfort is the point. Live scenario testing is consistently underused. Put a specific agentic AI deployment in front of different stakeholder groups, an autonomous system modifying infrastructure in a regulated environment without prior human approval, and ask how their current frameworks handle it. Where they agree, a useful signal. Where they diverge or go quiet, that's the work. Between formal sessions, structured peer exchange would surface things that individual submissions miss. A pharma governance lead, a financial services risk officer, and an infrastructure operator talking for an hour will find shared problems faster than any synthesis document. They'll also find out quickly where their assumptions about each other's industries are wrong. Less time on principles. More time on cases. That's the format shift that would make Geneva worth the trip.

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

4

I'll speak to what I've seen work rather than what reads well in a policy document. The most effective practice in my own organization is treating AI vendor assessment as a continuous obligation. When a vendor indicates they use AI, it triggers a structured assessment covering model transparency, data governance, bias testing, human oversight controls, explainability, incident response, and regulatory compliance. That goes to a cross-functional governance committee. Approval comes with conditions, named owners, and deadlines. The logic is straightforward: the vendor who passed your assessment in January may not be running the same model in July. Approval has to be maintained, not just issued. NIST's AI Risk Management Framework is the most practically useful reference I've found for building an internal AI governance program. Its four functions, Govern, Map, Measure, and Manage, translate into actual organizational processes rather than sitting at the level of principles. Organizations looking for a starting point that doesn't require building from scratch should start here. The EU AI Act gets the basic architecture right. Governance requirements that scale with potential for harm, rather than applying uniformly to everything, reflect how risk management actually works inside regulated organizations. The implementation detail needs refinement, especially where it overlaps with existing sector frameworks. But the tiered structure is worth extending internationally rather than designing around. The most underrated tool at the operational level is the audit trail. Organizations that can produce complete, tamper-proof logs of AI inputs, outputs, and decisions on demand are in a genuinely different position from those relying on vendor questionnaires and annual attestations. Most organizations haven't built that capability. It's where the gap between declared governance and actual governance is widest. Effective AI governance is built. Not announced.