Cyntrisec, Inc.
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
The first Global Dialogue would be successful if it produces a practical shared understanding of what evidence should exist after consequential AI use, not only high-level principles. Governments and stakeholders already agree that AI should be safe, transparent, accountable and human-supervised. The harder question is how those commitments can be checked later. A useful outcome would be a technology-neutral recommendation that high-impact AI deployments preserve durable evidence records for material AI-assisted decisions. Such records should show which AI system or model version was used, under which policy or control state, with what data reference, what human review or override occurred, and what independent verification result exists. This would help regulators, affected people, auditors and organizations reconstruct important AI-supported decisions without relying only on vendor self-attestation or informal logs. The Dialogue should also encourage interoperability across governance regimes so that evidence generated for one framework can be reused across others. This would reduce compliance burden, help smaller organizations participate responsibly, and make accountability more concrete.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Interoperability of governance approaches
- Protection and promotion of human rights
- Transparency, accountability, and human oversight
Please briefly explain your selection.
2
These priorities are connected. Safe and trustworthy AI cannot be evaluated only through policies or general assurances; it requires evidence that specific AI systems operated under expected controls. Transparency, accountability and human oversight also require records showing what happened in a particular workflow, including model identity, policy version, data reference, human review and override status. Interoperability is urgent because AI governance frameworks are emerging across jurisdictions. If each jurisdiction requires different evidence formats, organizations will face unnecessary burden and smaller companies will struggle to comply. Shared, technology-neutral evidence expectations would allow organizations to demonstrate responsible AI operation across multiple regimes. Human rights are also central. Individuals and communities affected by high-impact AI systems need meaningful accountability. That is difficult when organizations cannot reconstruct which AI system influenced a decision or what controls were active at the time.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
2
A cross-cutting issue is the gap between AI governance policy and AI execution evidence. Many organizations can document that they have AI policies, model inventories, vendor questionnaires and review procedures. Fewer can later prove what happened in a specific AI-assisted decision. The Dialogue should consider runtime evidence as a governance primitive. For high-impact AI, organizations should be encouraged to preserve privacy-protective, independently reviewable evidence records that include model identity, policy/control version, timestamp, data references or digests, output references, human-review status and verification result. This issue cuts across safety, interoperability, transparency, human oversight and rights protection. Without execution evidence, governance can become performative: organizations may appear compliant while regulators and affected people lack the records needed to evaluate actual AI behavior. With interoperable evidence expectations, AI governance can become more auditable, portable and practically enforceable.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
In regulated sectors, the main governance gap is that organizations are being asked to show responsible AI use, but the evidence available after deployment is often weak. Policies, model inventories, risk assessments and vendor questionnaires are important, but they usually do not prove what happened in a specific AI-assisted workflow. This creates challenges for audit readiness, incident review, human oversight and accountability. For small companies and technical providers, fragmented governance expectations are also a significant burden. Different jurisdictions and sectors are developing different AI governance requirements, but they often do not define a common evidence layer. This makes it harder for smaller organizations to demonstrate trustworthy operation across markets, even when they are trying to build responsibly. The opportunity is to make AI governance more practical and interoperable. If high-impact AI systems preserve privacy-protective runtime evidence records, regulators and affected people can better understand how AI was used without requiring disclosure of proprietary model internals or sensitive personal data. Such records can support safety review, human-rights accountability, vendor oversight and cross-border governance compatibility. For the technical community and private sector, this is also an opportunity to build trustworthy AI infrastructure that works across jurisdictions: evidence records that identify the model, control state, data reference, human-review status and verification result for material AI-assisted decisions. This would make governance less dependent on self-attestation and more grounded in reviewable facts.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue can help international cooperation by turning broad AI governance principles into shared practical expectations. Many jurisdictions are developing AI rules, standards and guidance, but organizations that deploy AI across borders need clearer alignment on what evidence is expected after consequential AI use. The Dialogue should not try to replace existing standards bodies or national regulators. Its value is convening governments, technical experts, civil society and the private sector around common governance primitives that can work across regimes. One such primitive is durable evidence for high-impact AI decisions: records showing model identity, policy/control state, data reference, human-review status and verification result. The Dialogue can also help ensure that governance does not become accessible only to large companies with large compliance teams. If evidence expectations are technology-neutral and interoperable, smaller companies and developing markets can adopt responsible practices without duplicating different compliance systems for every jurisdiction. A successful role for the Dialogue would be to identify areas where international cooperation is most needed: interoperable evidence records, accountable human oversight, incident review, vendor accountability, privacy-preserving auditability and capacity-building for regulators and smaller organizations.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The AI Dialogue should build on existing governance and technical initiatives rather than duplicate them. Relevant foundations include the NIST AI Risk Management Framework, ISO/IEC AI management and risk standards, OECD AI Principles, UNESCO recommendations on AI ethics, the EU AI Act, the Council of Europe AI Convention, privacy and data protection frameworks, and sector-specific regulatory work in finance, health care and critical infrastructure. It should also connect with technical standards and assurance communities working on transparency, provenance, auditability, cybersecurity, identity, confidential computing, digital signatures, software supply-chain attestations and secure logging. These communities can help translate governance expectations into implementable evidence patterns. The added value of the AI Dialogue is universality and inclusion. Many existing initiatives are regional, sectoral or technically specialized. The Dialogue can connect them into a shared language that is useful for governments, affected communities, regulators, technical implementers and smaller organizations. A concrete contribution would be to recommend interoperable, technology-neutral evidence expectations for high-impact AI systems. This would not require one global compliance regime, but it would help different regimes ask compatible questions: what AI system ran, under what controls, with what data reference, what human oversight, and what reviewable evidence remains.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Different stakeholders should contribute in complementary ways. Governments and regulators can identify legal obligations, public-interest priorities and implementation constraints. Civil society and affected communities can identify harms, remedies and accountability needs that may not be visible from technical or commercial perspectives. Academia and the Scientific Panel can provide evidence-based assessments. The technical community can explain what governance expectations are implementable, verifiable and interoperable. The private sector can contribute deployment lessons, incident patterns and operational evidence needs. The Dialogue should avoid relying only on high-level speeches. A useful structure would combine plenary sessions with small facilitated thematic working groups, written submissions, regional inputs and hybrid participation. Each thematic cluster should produce a short output: areas of convergence, unresolved disagreements, practical recommendations and issues requiring follow-up before the 2027 Dialogue. For meaningful participation, the Dialogue should publish guiding questions in advance, provide multilingual summaries, support remote participation, and preserve a public record of submissions and outcomes. It should also include practical case-study sessions where stakeholders examine concrete AI-use scenarios and ask what evidence, oversight and remedies should exist after deployment. The format should include technical assurance demonstrations, but not vendor sales demos. Demonstrations should focus on governance questions: how to preserve evidence, verify claims, protect privacy, support human oversight, and enable review by regulators or affected people.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Underrepresented voices include people directly affected by high-impact AI decisions, especially in public services, employment, health care, education, migration, finance and law enforcement. Communities in Least Developed Countries, Landlocked Developing Countries and Small Island Developing States also need stronger participation, as do Indigenous communities, linguistic minorities, disability communities, worker organizations and civil-society groups focused on rights and access to remedies. Several implementation perspectives are also underrepresented. AI governance discussions often include policymakers and large technology companies, but less often include small and medium-sized enterprises, startups, open-source maintainers, technical auditors, security researchers, local governments, procurement officers, compliance teams and frontline professionals who must make governance work in practice. These groups can be included through travel support, remote participation, regional consultations, multilingual materials, targeted invitations, stipends or other support for civil-society participation, and structured calls for case studies. The Dialogue should also distinguish presence from influence: underrepresented groups should be able to see how their input affected the co-chair summary and follow-up agenda. For technical and small-organization participation, the Dialogue should create low-burden formats for submitting practical evidence: short implementation notes, incident-review lessons, governance-pattern proposals and open-source examples. This would make participation possible for groups that cannot prepare formal policy papers or send large delegations.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
The Dialogue could use scenario-based engagement formats rather than only panels. For example, participants could work through concrete AI-use cases such as health triage, hiring, credit decisions, public-benefit allocation, education assessment, law-enforcement support or agentic business workflows. For each scenario, stakeholders would identify the required safeguards, evidence records, human oversight points, appeal mechanisms and cross-border governance questions. Another useful format would be "governance evidence clinics." In these sessions, technical experts, civil society, regulators and private-sector participants examine what evidence should remain after a high-impact AI decision. The goal would not be to endorse a product, but to define practical expectations: model identity, data reference, policy/control state, human-review status, incident record, audit trail and verification result. The Dialogue could also use structured debates, live polling, regional breakout groups, asynchronous online commenting, short lightning talks and rapporteur-led synthesis sessions. Each session should produce a visible output, such as a checklist, glossary, map of unresolved issues, or list of capacity-building needs. To include more voices, engagement should continue before and after the Geneva meeting. A public online repository of submissions, summaries and proposed governance patterns would allow stakeholders who cannot attend in person to contribute. Follow-up sessions after the first Dialogue could test whether proposed recommendations are understandable and implementable by smaller organizations, regulators with limited resources and affected communities.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
6
Useful approaches combine governance policy, technical testing, operational evidence and accountability mechanisms. The NIST AI Risk Management Framework is a good example of a flexible structure because it separates governance into practical functions such as governing, mapping, measuring and managing AI risks. ISO/IEC 42001 is also useful because it treats AI governance as a management system that organizations must maintain and improve, not as a one-time checklist. The OECD AI Principles and UNESCO recommendations provide important human-centric and rights-oriented foundations that can be adapted across jurisdictions. Singapore's AI Verify is a useful implementation example because it connects governance principles with testing, process checks and report generation. Similar approaches should be encouraged: model and system cards, impact assessments, red-team results, incident reports, human-oversight records, vendor-risk documentation and post-deployment monitoring. However, many current practices remain too document-centered. A stronger approach is to connect governance documentation with runtime evidence from actual AI use. For high-impact AI systems, organizations should preserve privacy-protective evidence records showing model identity, policy/control version, data reference, output reference, human-review status and verification result. This would make existing practices more auditable and interoperable. Regulatory sandboxes, assurance sandboxes and sector-specific pilots can help test these approaches in practice. They should include not only model-performance evaluation but also evidence-retention, incident-review and auditability requirements.