Data Mining & Security Lab - McGill University
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
Success would mean moving from general principles to actionable cooperation. Concretely: (1) agreement on a small set of shared baseline commitments (safety, human rights, transparency, and accountability) that states and stakeholders can publicly endorse; (2) practical mechanisms for cross-border incident learning, including a common template for reporting and analyzing major AI-related failures and cyber-enabled disruptions, especially in critical infrastructure; (3) credible pathways for interoperability among governance approaches, including alignment on risk management terminology, assurance concepts, and minimum documentation expectations for high-impact deployments; and (4) a workplan for capacity-building that supports regulators and operators in low- and middle-capacity settings. A strong outcome would also include an explicit focus on emerging "agentic" systems, AI that can plan and take actions through tools, because this shifts risk from model behavior to system behavior. Finally, success would be demonstrated by inclusive participation (industry, civil society, technical community, and affected groups), plus a clear timeline for follow-on work (deliverables, responsible leads, and milestones before the 2027 session).
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Interoperability of governance approaches
- Protection and promotion of human rights
- Transparency, accountability, and human oversight
Please briefly explain your selection.
4
These priorities are urgent because they are the minimum conditions for legitimate deployment at scale. "Safe, secure and trustworthy AI" must include cybersecurity and supply-chain integrity, not only model performance. "Transparency, accountability, and human oversight" are essential for attribution and remedy when harms occur, particularly where decisions are distributed across organizations, vendors, and automated components. "Protection and promotion of human rights" ensures governance is anchored in dignity, non-discrimination, due process, and effective remedy, especially where AI mediates access to essential services. "Interoperability" is necessary because fragmented rules create compliance gaps and encourage weakest-link behavior; alignment on risk tiers, documentation, and assurance expectations helps regulators and operators implement controls consistently across jurisdictions. Together, these four areas enable practical, enforceable governance, especially for high-impact contexts like critical infrastructure, public services, and security-sensitive environments.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
3
Two cross-cutting gaps deserve explicit attention. First, "agentic" and multi-agent systems: AI that can plan, coordinate with other agents, and act via tools expands the attack surface (e.g., prompt/tool injection, compromised identity and trust, privilege escalation) and complicates accountability through distributed chains of action. Governance should therefore address permissions, auditability, logging, rollback/safe-failure, and responsibility allocation across the full socio-technical system. Second, critical infrastructure and systemic risk: AI governance discussions often underweight cascading failures across interconnected sectors (energy, transport, food, communications) and the need for resilience-focused assurance. This includes operational technology realities, incident response integration, and stress-testing/"red teaming" at system level rather than model level. A related emerging issue is compute/data concentration and dependency risk (including reliance on a small number of vendors), which can create single points of failure and strategic vulnerability.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
Governance gaps in safe/secure AI, transparency/accountability, interoperability, and human rights are already affecting Canada's critical infrastructure and public-sector adoption. A key challenge is that AI governance is advancing faster than operational security and assurance practices: organizations are adopting AI-enabled tools and, increasingly, agentic workflows without consistent requirements for auditability, access control, incident reporting, or clear accountability allocation across vendors, integrators, and operators. This creates "liability ambiguity" and weakens incentives to invest in secure-by-design controls, especially where procurement focuses on functionality rather than assurance. In critical infrastructure sectors (energy, transportation, food, communications), the most significant risk is systemic: cyber-enabled disruption can cascade across interconnected services. As AI systems move from decision support toward action-taking (agents that plan and execute via tools), the attack surface expands (identity spoofing, inter-agent trust failures, prompt/tool injection, compromised orchestration). Current governance frameworks do not consistently address these system-level risks, and Canada's multi-jurisdictional regulatory environment can make responsibilities diffuse and compliance uneven. At the same time, there are major opportunities. Canada can strengthen resilience by aligning baseline assurance expectations for high-impact deployments (logging, least privilege, human override conditions, evaluation/red teaming, and safe-failure design), and by improving interoperability across governance approaches so operators face consistent requirements across provinces and sectors. Clearer accountability and documentation expectations can also increase public trust and reduce adoption friction by making responsibility traceable and remedies practicable. Capacity-building, especially for regulators and infrastructure operators, can translate high-level principles into operational governance that measurably reduces risk.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue can serve as a practical coordination layer between fragmented national and sectoral approaches. Its most valuable role would be to establish shared baselines and common operating concepts that enable cooperation without requiring uniform laws. This includes aligning definitions (risk tiers, "high-impact" systems, evaluation, assurance, incident severity), promoting minimum expectations for transparency and accountability (documentation, logging, auditability, human oversight conditions), and encouraging secure-by-design practices that incorporate cybersecurity and supply-chain integrity. The Dialogue can also create mechanisms for shared learning: a voluntary, privacy-respecting process for exchanging information about major AI-related incidents, near misses, and cyber-enabled disruptions, including common templates for root-cause analysis and lessons learned. This is especially important as "agentic" systems (AI that can plan and act through tools and coordinate with other agents) expand risk from model behavior to system behavior. The Dialogue can help normalize governance controls appropriate for agency, permissioning, action gating, identity and provenance, rollback/safe-failure, and continuous monitoring. Finally, the Dialogue can support capacity-building and inclusion by connecting regulators, operators, and civil society across regions, and by identifying priorities where targeted technical assistance and shared resources would raise global baseline safety. A successful Dialogue would not replace existing initiatives; it would connect them, reduce duplication, and accelerate convergent governance practices.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The AI Dialogue should connect with initiatives that already shape practice and standards, including the OECD AI Principles and related policy work, UNESCO's Recommendation on the Ethics of AI, and the Council of Europe's emerging AI framework. It should also engage technical and risk-management infrastructures such as the NIST AI Risk Management Framework (and international equivalents), ISO/IEC AI and cybersecurity standards work (including JTC 1/SC 42 and relevant security standards), and sector-specific safety and security regimes for critical infrastructure. The Dialogue should also coordinate with international safety and security efforts focused on evaluation, assurance, and incident response, as well as multi-stakeholder processes that engage industry, civil society, and the technical community. For cyber risk specifically, linking to established cybersecurity norms and capacity-building channels can ensure AI governance incorporates operational security and resilience rather than treating security as an afterthought. The added value of the AI Dialogue is convening across these efforts to produce interoperability and actionable guidance: mapping overlaps, identifying gaps, and translating high-level principles into implementable baseline commitments for high-impact deployments. It can also provide a neutral venue for discussing emerging issues, such as agentic and multi-agent systems, inter-agent trust and identity, and systemic/cascading risks in critical infrastructure, where current governance approaches remain uneven across jurisdictions.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Different stakeholders should contribute in ways that match their comparative advantages. Governments can articulate policy objectives, share regulatory lessons learned, and commit to baseline cooperation mechanisms (e.g., incident learning, evaluation norms). Industry can provide implementation realities, share assurance practices (documentation, monitoring, red-teaming), and support interoperable disclosure standards. Technical researchers can clarify system capabilities and failure modes (including agentic and multi-agent risks), propose evaluative methods, and stress-test assumptions. Civil society and affected communities can surface rights impacts, remedy gaps, and inclusion priorities. Standards bodies and infrastructure operators can translate principles into operational requirements and resilience practices. Format/structure recommendations: organize the Dialogue around (1) concise plenary framing sessions, (2) parallel working groups aligned to the official themes, and (3) a synthesis mechanism that produces clear outputs. Each working group should have a defined question, a rapporteur, and a short deliverable (shared definitions, baseline commitments, or a workplan). Include structured stakeholder statements (time-limited) and technical briefings to prevent abstract discussion. Finally, establish an intersessional process with milestones before 2027: virtual sessions, drafts open for comment, and a clear path to publish consensus "outcomes" and areas of disagreement.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Underrepresented perspectives include critical infrastructure operators and frontline practitioners (especially in energy, transport, health, food, and communications), public-sector procurement and compliance professionals, and communities most affected by AI-mediated public services (e.g., migrants, low-income populations, Indigenous communities). Also underrepresented are stakeholders from lower-capacity jurisdictions, including regulators in low- and middle-income countries who face high exposure but limited governance infrastructure. Cybersecurity and operational technology (OT) experts are often present indirectly, but not consistently integrated into AI governance discussions. Inclusion can be improved through targeted invitations, travel support, and structured representation (e.g., operator and affected-community panels). Use pre-dialogue consultations to gather inputs from those who cannot attend and ensure their priorities are reflected in working group agendas. Provide multilingual participation support and accessible materials. Create a pathway for practitioner evidence: short case studies on real deployment challenges, incidents, near misses, and remedies, especially in high-impact sectors. Finally, use transparent selection criteria and rotating stakeholder seats for intersessional work so participation is not limited to the usual global organizations.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
To foster meaningful engagement, combine deliberation with applied exercises. One effective format is scenario-based "tabletop" sessions focused on real governance challenges, such as a major AI incident, a cross-border cyber-enabled disruption, or a failure of an agentic system operating through tools. These exercises force stakeholders to clarify responsibilities, oversight, disclosure, and remedy pathways, and they surface interoperability gaps quickly. Other high-impact formats include structured "problem-solution" clinics (stakeholders bring a concrete governance problem; experts propose implementable options), rapid technical briefings followed by moderated policy translation, and cross-stakeholder working sprints that produce short draft outcomes (definitions, baseline commitments, or templates). Use Chatham House Rule sessions for sensitive discussions (security, procurement, vendor risk), balanced with public sessions for transparency. Finally, maintain a digital participation track with moderated Q&A, pre-submitted interventions, and a mechanism to integrate remote inputs into official summaries and working group deliverables.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
6
A practical approach is to adopt risk-management frameworks that translate principles into operational controls. For example, the NIST AI Risk Management Framework (AI RMF) provides an implementation-oriented structure (govern, map, measure, manage) that organizations can use to define accountability, document intended use, evaluate performance and risk, and maintain ongoing monitoring and incident response. Similar lifecycle approaches in cybersecurity engineering and safety-critical domains help ensure AI governance is not a one-time compliance exercise. Effective practice also includes system-level assurance mechanisms: pre-deployment evaluation/red-teaming; least-privilege access controls for AI-enabled tools; action gating for high-impact operations; and continuous logging and audit trails that support traceability and remedy. These practices become especially important as "agentic" systems (AI that plans and acts through tools and coordinates with other agents) expand risk from model outputs to chains of actions. Standards-based approaches can help operationalize governance across sectors and jurisdictions. Sectoral standards for cybersecurity engineering and risk management support consistent baselines for documentation, verification, incident handling, and supply-chain integrity, reducing "weakest-link" behavior. In procurement, concrete governance solutions include requiring model/system documentation, safety and security test evidence, and clear responsibility allocation (including incident reporting and remediation obligations) in vendor contracts. Finally, multi-stakeholder incident-learning mechanisms are a concrete solution: voluntary but structured reporting of major AI failures and near misses, common templates for root-cause analysis, and shared lessons learned, especially for deployments affecting critical infrastructure and public services.