Summit Cognitive Inc.
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
The inaugural Dialogue will succeed if it ends with a concrete artifact specification on the table — not another set of principles. The accountability question for AI is no longer "should there be oversight?" All major frameworks have answered that. The unsolved question is what specific evidentiary record allows oversight to be exercised in the specific case, when a regulator, an inspector general, a court, or an affected person challenges a particular AI-assisted decision. Currently, no jurisdiction's framework requires, defines, or produces such an artifact. Adding more risk-management documentation, more model cards, or more disclosure obligations does not close that gap. We propose a minimum success criterion: the inaugural Dialogue endorses the property set for a portable, replay-capable, tamper-evident artifact — a Decision Receipt — attached to consequential AI-assisted decisions. Six minimum properties: provenance-anchored, reasoning-bearing, human-checkpoint-aware, tamper-evident, deterministically replayable, portable across jurisdictions. The Dialogue does not need to write the technical specification at Geneva; it needs to authorize the work and convene the multi-stakeholder process to produce one ahead of the May 2027 follow-up Dialogue. A second success criterion: the Dialogue commits to an open, public reference repository where Member States, civil society, and private-sector entities can deposit verified Decision Receipts, demonstrate test vectors, and surface edge cases. A third: the Dialogue articulates the artifact as the operational layer for accountability obligations already implicit in the OHCHR B-Tech Project, UNESCO's 2021 Recommendation, and the UN Guiding Principles on Business and Human Rights — the rights-bearing instruments need an evidentiary substrate to be enforceable. Success is convergence on the missing primitive, not consensus on substantive AI law.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Interoperability of governance approaches
- Protection and promotion of human rights
- Transparency, accountability, and human oversight
Please briefly explain your selection.
4
The four selected priorities - transparency/accountability/human oversight; interoperability; safe/secure/trustworthy AI; protection of human rights - converge on a single missing primitive: a portable, tamper-evident, replay-capable artifact attached to consequential AI-assisted decisions. We refer to this as a Decision Receipt. Transparency, accountability, and human oversight is operationally meaningful only if a third party can reconstruct why a specific decision was reached at the time it was reached. Existing frameworks describe duties; they do not produce the evidentiary record those duties require to be enforceable in the specific case. The Receipt is that record. Interoperability of governance approaches is the cross-jurisdiction problem. Member States will not converge on substantive AI law, and forcing convergence is neither realistic nor desirable. What can converge is the artifact specification: a single Receipt format that satisfies oversight in any jurisdiction without rework. This is technically achievable today. Safe, secure and trustworthy AI requires a path from claim to verification. A Decision Receipt converts trust from a property of the deployed model into a property of the specific decision under review. Protection and promotion of human rights requires evidentiary substrate. The OHCHR B-Tech Project, UNESCO's 2021 Recommendation, and the UN Guiding Principles on Business and Human Rights all imply records of how AI-assisted decisions affecting rights were reached. The Receipt operationalizes that requirement. We did not select capacity-building or social/economic implications because other voices are better placed to address those, and we did not select open-source because the artifact specification - not the implementation - is what needs to be open. Our concrete commitment is to publish data-format components under permissive license and refrain from asserting our patent against good-faith open implementations.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
3
Two cross-cutting issues deserve explicit attention. First: the distinction between description and proof. The current AI governance vocabulary uses "transparency," "explainability," and "accountability" interchangeably. They are different concepts addressing different problems. Transparency tells a person AI was involved. Explainability describes how a model behaves in general. Accountability requires evidence of a specific decision's reasoning chain, defensible under adversarial review. Conflating these has produced frameworks that describe duties they cannot operationally enforce. The April 2026 Sullivan & Cromwell filing in the Southern District of New York - approximately forty errors traceable to AI-generated content in a single emergency motion - is one publicly visible example of a pattern that is already widespread across legal, medical, financial, intelligence, employment, immigration, and benefits contexts. The firm could describe the process it followed; it could not produce a verifiable record of how the AI-assisted analysis was constructed at the time it was used. Second: the multi-stakeholder governance gap for the artifact itself. If the Dialogue endorses a Decision Receipt specification, the technical specification work must be done in the open - at a body like the World Wide Web Consortium, the IETF, or a UN-convened working group operating under similar transparency norms. Specification work that occurs inside a single jurisdiction's regulatory body, or inside a single vendor consortium, will produce a primitive that does not satisfy the cross-jurisdiction interoperability test. The lesson from Internet protocols is that the most successful global standards have been those produced by open, multi-stakeholder bodies whose specifications were adoptable by any government, vendor, or civil-society entity without licensing or political precondition. Both issues are technical in form and political in consequence. The Dialogue is the right place to surface them.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
In the United States private-sector AI infrastructure context, the four selected governance gaps interact in a specific way that creates both an immediate compliance burden and a market opportunity. Challenge: U.S. AI governance is fragmented across federal frameworks (NIST AI RMF, CDAO AI Assurance Framework), state-level laws (Colorado AI Act, California's pending instruments), sectoral regulators (FDA, FTC, EEOC, CFPB), and the extraterritorial reach of the EU AI Act on any U.S. firm serving European customers. Each framework imposes a slightly different evidentiary standard. The result is that U.S. AI vendors face compounding documentation requirements with no portable artifact that satisfies all of them simultaneously. Vendors and customers spend resources producing parallel compliance reports rather than a single defensible record per decision. Specific to consequential decision contexts — federal civilian agencies under CDAO oversight, defense intelligence under Inspector General review, financial-services AI under sectoral derivative regimes, healthcare AI under HIPAA and FDA review, employment AI under EEOC scrutiny — the missing primitive is the same: there is currently no standard mechanism to produce a verifiable record of how a specific AI-assisted decision was reached, in a form admissible under the relevant oversight body's review. The April 2026 Sullivan & Cromwell SDNY filing is the publicly visible legal-sector instance of the broader pattern. Opportunity: A portable Decision Receipt specification, endorsed by the inaugural Dialogue, would address the U.S. fragmentation problem without requiring federal preemption or a new regulatory body. It would let U.S. private-sector AI deployments produce a single artifact that satisfies the EU AI Act, the NIST AI RMF, the CDAO framework, sectoral regulators, and any human-rights or oversight inquiry without rework. This is the rare governance proposal that reduces compliance cost, increases verifiability, and is technically achievable today.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue can play a role no other body is currently structured to play: convene the multi-stakeholder, cross-jurisdiction conversation around AI accountability without the constraints of any single regulatory regime or commercial consortium. The OECD has policy traction; the G7 Hiroshima Process has a code of conduct; the Council of Europe has a binding treaty; ITU has technical standards capacity; UNESCO has the 2021 Recommendation. None of them, individually, can endorse and operationalize a portable artifact specification that sits across all of them. The Dialogue's specific value-add is the property of universality. A specification endorsed at Geneva by Member States and the multi-stakeholder community has standing in any jurisdiction's eventual implementation work — not because the UN imposes it, but because it represents the broadest legitimate articulation of what the artifact should do. A second role: setting expectations for the structure of follow-on work. The most successful global standards (W3C, IETF, IEEE) have been produced by transparent, open processes whose specifications are adoptable without licensing or political precondition. The Dialogue can normatively endorse that pattern for AI accountability artifacts and convene the working group accordingly. A third role: connecting AI governance work to the existing UN human-rights instruments — the OHCHR B-Tech Project, UNESCO 2021, the UN Guiding Principles on Business and Human Rights — which currently describe duties without identifying the operational substrate those duties require. The Dialogue can articulate that connection and authorize the technical work to fill the gap. The Dialogue's role is convening, normative endorsement, and authorization. The technical work happens in follow-on multi-stakeholder bodies.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The Dialogue should build upon and connect with at least four existing strands of work, each of which has produced relevant infrastructure but none of which has produced the portable AI decision artifact: 1. The OHCHR B-Tech Project. B-Tech has articulated the rights-impact framework and the access-to-remedy obligation. The Dialogue should treat B-Tech's framing as the rights-anchor for the artifact: a Decision Receipt makes remedy operational because it produces the record remedy presupposes. 2. The OECD AI Principles and Hiroshima Process Code of Conduct. These document the policy convergence on accountability obligations. The Dialogue should treat them as the policy substrate against which the artifact specification is measured: any specification that satisfies the requirements of these principles is a successful starting point. 3. The Sigstore / Cosign cryptographic signing ecosystem and the W3C Verifiable Credentials specification. Both have been battle-tested in supply-chain security and identity contexts. The Dialogue's working group should not reinvent signing primitives; it should mandate that any Decision Receipt specification reuse these existing, vendor-neutral patterns. 4. ITU's standards-development infrastructure. ITU has experience producing technical specifications adopted by all Member States. The Dialogue should authorize ITU (or a UN-convened equivalent) to host the working group on Decision Receipt specification. The added value the Dialogue brings is twofold. First, it creates a single, legitimate, multi-stakeholder convening that no individual body in the list above can produce alone. Second, it provides the political authorization for the technical work — without that authorization, specification work tends to fragment along regional or commercial lines and produces primitives that do not satisfy the cross-jurisdiction interoperability test.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Stakeholders can contribute most effectively by treating the Dialogue not as a venue for principles-level argument but as a working space for the artifact-level technical specification. Five concrete recommendations: 1. Format: Plenary endorsement, breakout specification work. The plenary sessions should focus on normative endorsement of property sets and authorization for working groups. The breakouts should convene technical specification work — protocol-level discussion among engineers, standards-body representatives, and implementer organizations. The most successful Internet-era specifications have been written in this pattern. 2. Structure: Three working groups. (a) Decision Receipt minimum-property specification. (b) Cross-jurisdiction interoperability profile — how a single Receipt satisfies EU AI Act, NIST AI RMF, CDAO, and other regimes. (c) Reference repository architecture — the public evidentiary repository. 3. Stakeholder roles. Member States: define what "consequential" means in their jurisdiction's evidentiary contexts. Civil society: surface human-rights edge cases the technical specification must accommodate. Private sector: contribute reference implementations, test vectors, and operational experience. Technical community: own the cryptographic and protocol-level work. Academic: independent verification and threat-modeling. 4. Cadence. The May 2027 follow-up Dialogue should receive a concrete draft specification, not a status report. To meet that deadline, working groups should meet monthly between July 2026 and March 2027, with public draft-publication checkpoints at three-month intervals. 5. Governance. The working groups should operate under transparency norms equivalent to W3C or IETF: open mailing lists, public meeting minutes, IPR commitments from participants, and a clear consensus procedure that allows the groups to ship a draft even when one stakeholder demurs. The Dialogue's success depends less on what is said in plenary and more on whether the working groups produce a usable specification by May 2027.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Three communities are currently underrepresented in global AI governance discussions and deserve explicit inclusion in the artifact specification work: 1. Affected persons and their advocates. The frameworks generally include civil society but rarely include the specific advocates who represent persons affected by AI-assisted decisions in benefits, immigration, employment, criminal-justice, and welfare contexts. These advocates know what evidentiary records are operationally needed for remedy. The Decision Receipt specification should be reviewed against the question: "does this artifact let a benefits-denial appellant or an asylum-seeker challenge an AI-assisted decision affecting them?" That question is answered most accurately by their advocates. 2. National supreme audit institutions and ombudsperson offices. INTOSAI member institutions, national audit offices, and ombudsperson offices conduct the actual oversight reviews that AI accountability frameworks anticipate. They are the long-term users of any artifact specification. Yet they rarely participate in upstream specification work — and when frameworks land, they discover the artifacts are not parseable by their existing tools or processes. Including them in working-group composition closes that gap. 3. Smaller and capacity-limited jurisdictions. AI governance discussions are dominated by jurisdictions with substantial regulatory capacity (EU, U.S., U.K., Singapore, China). The specification must work for jurisdictions whose AI accountability infrastructure is still emerging — many in Africa, the Pacific, parts of Latin America, the Caribbean, and small island developing States. Inclusion means more than seat-at-the-table; it means designing the artifact so that any State, regardless of capacity, can adopt it without building proprietary tooling. A specification that excludes any of these three is not portable. The Dialogue's working groups should reserve seats for representatives of all three at design time, not consultation time.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
- Three categories of existing work demonstrate concrete progress and offer specific lessons for the Dialogue: 1. The Sigstore / Cosign supply-chain provenance ecosystem. Originating in the open-source software supply-chain context, Sigstore solved a structurally similar problem to AI decision accountability: producing a tamper-evident, cryptographically signed record of provenance for an artifact (in their case, software). The lessons translate directly: vendor-neutral signing infrastructure works
- transparency-log architecture is operationally feasible at scale
- and the developer-facing tooling can be made simple enough to integrate without disrupting existing workflows. The Decision Receipt specification should reuse Sigstore primitives where applicable rather than reinventing them. 2. The W3C Verifiable Credentials specification and its production deployments in identity, education credentials, and supply-chain attestation. The VC specification proves that a portable, multi-jurisdiction-compatible artifact format is achievable through open multi-stakeholder standards work. The Dialogue should treat VC as the closest direct analogue and consider whether the Decision Receipt specification should be expressed as a Verifiable Credentials profile. 3. The U.S. CDAO AI Assurance Framework, the EU AI Act's Article 11 documentation requirements, and Singapore's Model AI Governance Framework. Each of these has done substantive work articulating what "documentation" for AI systems should look like. None of them, individually, requires the full property set we propose, but each has identified pieces of it. The Dialogue's specification work should map each existing framework's documentation requirements against the Decision Receipt property set, identify the gaps, and produce a reference profile that satisfies all three simultaneously. The pattern across all three: open specifications, operational reference implementations, and willingness to converge on a shared format even when substantive policy diverges. That's the model the Dialogue should follow.