Privacy License
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
Success requires moving from principles to enforceable infrastructure. Three concrete outcomes would mark this dialogue as transformative: First, agreement on a universal machine-readable rights standard for AI training data — a technical protocol that AI systems can automatically detect and comply with, similar to how robots.txt functions but with legal enforceability built in. Without this, every national regulation becomes siloed and unenforceable at the speed AI operates. Second, recognition that creator compensation and AI development are not opposing forces but interdependent ones. AI systems trained on uncompensated, low-quality data produce worse outputs. A governance framework that protects creator rights simultaneously improves AI quality. The dialogue should establish this as foundational principle. Third, a commitment to interoperable compliance infrastructure across jurisdictions. The EU AI Act, emerging US frameworks, India's DPDPA, and others cannot function as isolated islands. Success means agreeing on shared technical implementation standards that allow one compliance action to satisfy multiple regulatory regimes simultaneously.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Social, economic, ethical, cultural, linguistic and technical implications of AI
- Protection and promotion of human rights
- Interoperability of governance approaches
- Safe, secure and trustworthy AI
Please briefly explain your selection.
3
These four priorities represent the implementation gap in current AI governance. Safe and trustworthy AI cannot exist without protecting the human creators whose work trains these systems. The social and economic implications of uncompensated data extraction are already visible - journalism revenue collapsing, creative industries contracting, $2B+ in active litigation with no systemic resolution. Interoperability of governance approaches is urgent because AI operates globally while regulations remain national. And human rights protection must explicitly include intellectual property rights and economic rights of creators in the AI era. Privacy License is building the technical infrastructure that makes all four priorities actionable rather than aspirational.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
4
The most urgent cross-cutting issue is the absence of post-crawl data governance infrastructure - the missing technical layer between AI regulation and AI compliance. Current governance frameworks assume AI companies can know what they trained on and can selectively comply with creator rights. In practice, no such infrastructure exists. Robots.txt, the thirty year old protocol governing web crawling, was designed as a gentleman's agreement with no legal enforceability. AI companies routinely index content despite explicit blocks - a provable, quantifiable violation with no systematic remedy. The result is a compliance gap that no amount of policy language closes without technical implementation standards. The EU AI Act Article 53 mandates machine-readable rights compliance but points to no implementation standard. The UN dialogue should urgently address this by convening technical and legal bodies to establish a universal post-crawl data governance protocol - one that is machine-readable, legally enforceable, and interoperable across jurisdictions. This issue cuts across every theme: it is a human rights issue for creators, a safety issue for AI systems trained on contested data, an economic issue for the content industries AI depends on, and a governance interoperability issue for regulators worldwide. The internet built trust through protocols. HTTPS secured transactions. DNS resolved addresses. The AI era needs its equivalent - a universal rights protocol that both creators and AI systems can rely on.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
The most significant governance gap affecting the AI sector globally is the absence of enforceable technical infrastructure for data rights — the missing layer between AI regulation and AI compliance. The challenge: Regulations like the EU AI Act, India's DPDPA, and emerging US frameworks establish clear principles: AI systems must respect creator rights, training data must be documented, and machine-readable rights signals must be honored. But no universal technical standard exists to implement these principles at the speed and scale AI operates. The result is a governance gap that is measurable and growing. Publishers explicitly block AI crawlers in robots.txt yet their content continues appearing in AI training datasets and search indexes. A single publisher loses an estimated $1M+ annually in uncompensated licensing value. Multiplied across millions of creators globally this represents a structural collapse of the content economy that AI itself depends on. Active litigation — now exceeding $2B globally — is filling this gap through courts rather than standards bodies. This is the least efficient possible outcome for every stakeholder: creators face years of expensive litigation, AI companies face mounting legal uncertainty, and regulators have no implementation standard to point to. The opportunity: The same moment that created this crisis contains its solution. The EU AI Act's Article 53 mandate for machine-readable rights compliance creates regulatory demand for exactly the infrastructure that doesn't yet exist. Organizations building this infrastructure today are positioned to become the technical standard the entire industry converges on. Privacy License is building this infrastructure — a machine-readable, legally enforceable post-crawl data governance protocol already adopted organically across 64 countries. The governance gap is real. The technical solution exists. What's needed is international coordination to establish it as the universal standard before litigation becomes the default governance mechanism.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue's most urgent contribution would be establishing a universal machine-readable data rights protocol as the technical standard for AI governance compliance globally — and partnering with existing infrastructure that has already proven adoption at scale. AI Privacy License (aiprivacylicense.com) represents exactly this kind of infrastructure. Built as the legal successor to robots.txt, it is the world's first machine-readable, legally enforceable post-crawl data governance protocol — already adopted organically by 1,900 creators across 64 countries without any marketing spend. The EU AI Act office has already recognized it as a promising implementation solution for Article 53(1)(c) compliance. The AI Dialogue can play three specific roles: First, formally recognize and standardize emerging technical protocols like AI Privacy License that have demonstrated real-world adoption. Bottom-up organic adoption across 64 countries is the strongest signal that a protocol works. The Dialogue should identify and accelerate these rather than building from scratch. Second, create a multilateral mandate for machine-readable rights compliance that gives protocols like AI Privacy License the international legal backing needed for universal adoption — similar to how international bodies gave HTTPS and DNS their authority. Third, establish a creator rights implementation working group that brings together AI companies, publishers, creators, and technical standards bodies to converge on a single interoperable standard — preventing fragmentation where every jurisdiction invents its own incompatible solution.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The AI Dialogue should build upon and formally connect with AI Privacy License as a proven technical implementation layer for the governance principles already established by existing frameworks. Specifically, the Dialogue should recognize AI Privacy License as the technical bridge between existing initiatives that currently lack implementation infrastructure: The EU AI Act's Article 53 mandates machine-readable rights compliance but specifies no implementation standard. AI Privacy License directly fulfills this mandate and has been recognized by the EU AI Act office as a promising solution. The Dialogue should formalize this connection, extending the protocol's recognition globally. WIPO's ongoing work on AI and intellectual property establishes the legal principles governing creator rights in AI training. AI Privacy License translates these principles into enforceable technical infrastructure — the implementation layer WIPO frameworks currently lack. Partnering here would create the first end-to-end system from legal principle to technical enforcement. UNESCO's Recommendation on AI Ethics, adopted by 193 member states, established creator rights as a global principle. AI Privacy License converts that principle into a protocol any creator in any of those 193 countries can deploy today for free. The Dialogue should build on UNESCO's political foundation by mandating technical implementation through protocols with demonstrated global adoption. The W3C's web standards governance model provides the right technical process. AI Privacy License should be brought into a formal W3C or IETF standardization process with the Dialogue providing the political mandate for urgency. The added value the Dialogue uniquely brings is converting AI Privacy License's organic bottom-up adoption into top-down international mandate — creating the universal trust layer the internet needs for the AI era.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
The AI Dialogue's structure should move beyond panel discussions toward implementation working groups where stakeholders contribute tangible technical and legal deliverables. Concretely, the Dialogue should establish a Data Rights Protocol Working Group that brings together: AI companies contributing their technical requirements for machine-readable rights detection — what format, what signals, what crawling pipeline integration looks like in practice. Without AI company participation, any protocol remains theoretical. Creators and publishers contributing real-world rights requirements — what compensation models, attribution standards, and opt-out mechanisms actually protect their interests. AI Privacy License's 1,900 creators across 64 countries represent exactly this constituency and should be formally represented. Standards bodies — W3C, IETF, ISO — contributing the technical governance process to formalize emerging protocols like AI Privacy License into internationally recognized standards. Regulators contributing the legal mandate — mapping EU AI Act Article 53, WIPO frameworks, and national laws to specific technical requirements the protocol must satisfy. The format should produce a deliverable: a ratified technical specification for machine-readable AI data rights, not another principles document. AI Privacy License's existing open-source implementation provides the starting point rather than building from scratch.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
The most critically underrepresented voices are the creators whose work trains AI systems — journalists, authors, photographers, musicians, independent publishers — and the communities in the Global South whose cultural output is extracted without compensation or attribution. Current AI governance conversations are dominated by AI companies, large technology regulators, and academic institutions. Missing are: Independent creators who lack legal resources to enforce existing rights. AI Privacy License addresses this directly by giving any creator — regardless of resources — a free, machine-readable, legally enforceable rights protocol they can deploy in minutes. The Dialogue should formally include creator communities already organizing around these tools as representative voices. Global South content creators whose linguistic and cultural output disproportionately enriches AI training datasets while those communities receive the least benefit. AI systems trained on Swahili literature, Bengali journalism, or Tamil music generate value that flows entirely to AI companies headquartered elsewhere. The Dialogue should establish a specific working group for Global South creator rights with AI Privacy License as the technical tool enabling participation. Privacy engineers and technical implementers who understand what is actually feasible to build. Policy without technical feasibility produces unenforceable mandates. The IAPP Privacy Engineering community — of which Privacy License's founder is an advisory board member — represents this constituency and should have formal standing in the Dialogue.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
The most effective format innovation would be live technical demonstrations rather than position papers — showing governance solutions working in real time rather than describing them abstractly. Concretely the Dialogue should include: A Protocol Demonstration Track where technical teams show working implementations of AI governance infrastructure. AI Privacy License could demonstrate in real time how a creator deploys machine-readable rights, how an AI crawler detects and honors those rights, and how violations are detected and quantified — the complete governance loop in under five minutes. Seeing working infrastructure changes conversations faster than any policy document. A Creator Rights Lab where journalists, authors, and independent publishers from diverse countries generate AI Privacy Licenses live during the Dialogue — demonstrating that governance tools can be accessible to any creator globally regardless of legal resources or technical sophistication. Real adoption happening in the room is more compelling than adoption statistics on a slide. A Cross-Jurisdiction Compliance Simulation where regulators from EU, US, India, and African Union map a single content rights scenario through each jurisdiction's framework — identifying where AI Privacy License's protocol simultaneously satisfies multiple regulatory requirements and where gaps remain. This produces actionable harmonization recommendations rather than abstract interoperability principles. The underlying innovation across all three formats is the same: replace statements about what AI governance should achieve with live demonstrations of what it already does. The infrastructure exists. The Dialogue should show it working.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
2
The most effective AI governance approaches share a common characteristic: they translate principles into enforceable technical infrastructure that operates at the speed and scale of AI itself. Three examples demonstrate this concretely. AI Privacy License - Machine-Readable Data Rights Protocol AI Privacy License (aiprivacylicense.com) is the world's first machine-readable, legally enforceable post-crawl data governance protocol - built as the technical successor to robots.txt with legal enforceability built in. It allows any creator or organization to generate a machine-readable rights declaration that AI crawlers can automatically detect, interpret, and honor - converting regulatory principles into executable technical signals. What makes this approach effective is demonstrated adoption without mandates. With zero marketing spend, 1,900 creators across 64 countries organically generated 10,000+ AI Privacy Licenses - proving that governance infrastructure works when it is accessible, free, and technically interoperable. The EU AI Act office has recognized it as a promising implementation solution for Article 53(1)(c) compliance requirements. The open-source AI Privacy License Detector SDK allows AI companies to integrate rights detection directly into their crawling and training pipelines - making compliance the path of least resistance rather than an obstacle. The EU AI Act Article 53 Framework The EU AI Act's mandate for machine-readable rights compliance represents the most advanced regulatory approach to AI training data governance. Its effectiveness lies in creating legal demand for technical infrastructure - establishing that AI companies must honor machine-readable rights signals or face significant penalties. AI Privacy License is the implementation layer this mandate points toward. The robots.txt Governance Model Thirty years of robots.txt adoption demonstrates that lightweight, universally accessible technical protocols achieve broader compliance than complex legal frameworks. The lesson for AI governance is clear: the most effective policies produce simple technical standards that any stakeholder can implement immediately. AI Privacy License applies this proven model with the legal enforceability robots.txt always lacked - combining protocol simplicity with regulatory teeth for the AI era.