Skip to content

Octave

Private Sector Global

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

The Dialogue will add real value if it recognizes the role of responsible enterprises and industry in shaping the AI environment and starts a debate on what realistic, rather than declarative, human oversight should look like alongside the contributions of states and model developers. The key outcomes should be: a focused agenda, concrete levers for implementation, and explicit recognition of enterprises as market shapers. First, the Dialogue should agree on a short list of concrete problems to tackle over the next 2-3 years, not a long catalogue of aspirations. For example: • how to make "safe, secure and trustworthy AI" work in practice across jurisdictions through minimum expectations for vendors and deployers; • how to embed human rights, transparency and accountability into real decisions on buying, integrating and operating AI systems, not just into policy documents; • how to ensure that enterprises that buy and deploy AI - including SMEs and actors in the Global South - have practical tools, model clauses and incentives to govern it responsibly and use their procurement power to raise standards in the market. Second, it should identify operational levers that turn principles into practice, especially in the relationship between enterprises and vendors. This includes patterns for AI aware procurement, minimum information and cooperation duties for vendors, model contractual clauses on incident handling and risk allocation, practical templates for internal governance (ownership models, risk registers, escalation and monitoring). These should be presented as adaptable building blocks, not one size fits all solutions. Third, it should make human oversight a practical design question, not a slogan. The Dialogue should outline shared expectations for what "human in the loop" means in realistic settings, including what information humans need, how much time they have, and what authority they hold, and emphasize that this must be co designed by AI creators and those operating systems in critical environments.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Safe, secure and trustworthy AI
  • AI capacity-building
  • Protection and promotion of human rights
  • Transparency, accountability, and human oversight

Please briefly explain your selection.

5

I selected these four priorities because, together, they define whether AI governance will work in real organizations, not just on paper. Safe, secure and trustworthy AI is the baseline for any serious deployment. In practice, incidents often come from ordinary tools integrated into critical workflows, with unclear ownership and insufficient safeguards. Focusing on safety and trustworthiness means asking how enterprises, vendors and regulators can jointly prevent avoidable failures, limit the impact when they occur and learn from them across borders. Transparency, accountability and human oversight are the mechanisms that turn principles into day to day decisions. Without clarity on who is accountable, what information is available and how humans can intervene, even strong legal frameworks risk becoming, at best, a box ticking exercise. The Dialogue should promote workable patterns for shared accountability inside organizations, usable documentation and risk registers, and escalation paths that function under time pressure. The protection and promotion of human rights must remain the anchor for all of this, especially where AI touches employment, health, finance, public services and critical infrastructure. Rights should not just appear in high-level statements; this Dialogue has the power to shape how they are built into the way AI systems are designed, trained and used. Finally, AI capacity building is essential so that these expectations are not limited to a few large actors. Governance requires skills, institutional support and realistic tools, particularly for enterprises and regulators in less resourced settings. The Dialogue can add real value by supporting the development and sharing of practical toolkits, for example, on vendor due diligence, human oversight design and proportionate controls, that different regions and sectors can adapt to their own realities.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

4

1. An under explored and heavily underestimated governance challenge is not individual AI tools, but the dense integrations between them - across systems, vendors and jurisdictions. These connections are still too often treated as a technical afterthought, even though they constitute a serious risk in their own right. When data and decisions flow through multiple AI components, legacy systems and third party services, errors can silently cascade, affecting not only businesses but people's access to services, opportunities and their fundamental rights. The Dialogue should therefore explore how safety, security, accountability and human rights safeguards need to be reinforced for these system of systems settings and how enterprises and regulators can ensure that individuals are not lost in the complexity of the stack. 2. The governance debates often focus on states and model developers, but much of the practical leverage sits with the enterprises that buy and deploy AI systems. Through their internal policies, procurement criteria, contractual safeguards, incident expectations and governance structures, they can quietly raise the bar for vendors and entire supply chains. The Dialogue should explicitly examine how to support enterprises - including in the Global South and SME ecosystems - to use this leverage responsibly, so that responsible AI spreads as a business expectation, not only as a legal minimum. This can be illustrated through concrete use cases where enterprises treat responsible practices as a source of business leverage rather than a compliance burden. 3. The "human in the loop" is frequently invoked but rarely defined in ways that match real workplaces. Effective human oversight requires a two sided dialogue between those who build AI and those who operate it in practice: operators, clinicians, engineers, customer facing teams. Humans cannot meaningfully control systems if they only receive opaque outputs, lack time to review them or bear responsibility without having influence over design. The Dialogue should therefore focus on models of shared design: how creators can expose the right information and controls and how deployers can organize processes, training and escalation so that oversight is realistic.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

Responding from my personal experience as an AI governance legal counsel at Octave (formerly Hexagon), a company providing industrial software for critical sectors such as energy, safety, oil and gas and pharma, and from earlier work as a legal advisor to private sector tech companies, NGOs and as a legislative advisor in the Polish Parliament, where I supported parliamentary work on EU technology and data‑protection legislation and its implementation in Poland, as well as a Polish lawyer now living abroad in the Middle East and currently in the Netherlands – I see a few serious governance gaps shaping this sector. First, governance debates still center on model developers and regulators, while many concrete decisions sit with enterprise buyers integrating vendor AI into complex landscapes. In practice, tools are plugged into CRMs, ticketing and industrial control systems with limited scoping, weak testing and unclear ownership, so errors quietly propagate across systems and jurisdictions. This creates significant legal and operational exposure for companies that "buy, not build" AI, especially in highly regulated, uptime critical environments. Second, existing frameworks underplay industrial risks: bias as mis-optimized processes, opaque decisions that cannot be reconstructed for audits, and training on customer data without clear contractual boundaries. In critical industry contexts, a single non explainable decision or undocumented update can block compliance, disrupt production or undermine safety cases. Third, there is a persistent gap between policy language and day to day governance: many organizations still default to "tick the box" policies rather than structured MVP testing, explicit ownership and realistic, incident driven monitoring. The opportunity is that the same regulations and standards can be used as a business lever: enterprises that demand transparency, robust documentation, clear data use terms and real human oversight from vendors are already turning responsible AI into a competitive advantage and a driver of trust with industrial and enterprise clients.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

Speaking from my experience as an AI governance legal counsel at Octave (formerly Hexagon) working on industrial AI for critical sectors, and from earlier roles advising tech companies, NGOs and the Polish Parliament on EU law, I see the AI Dialogue's value in turning fragmented practice into shared, practical guardrails. First, it can bridge the gap between high‑level principles and everyday decisions by bringing enterprise buyers, vendors, regulators and civil society into the same conversation about testing, integrations, ownership and incident handling, not just abstract ethics. This is essential where AI is bought, rapidly integrated into complex system landscapes and quietly affects access to services, opportunities and rights across borders. Second, the Dialogue can surface what already works in different regions – for example, industrial documentation practices, real‑world human oversight models, and procurement requirements that drive better vendor behavior and translate them into adaptable reference patterns that other countries and sectors can reuse. Third, by giving equal space to perspectives from highly regulated environments, SMEs and actors from the Global South, the AI Dialogue can help avoid a governance model defined only by a few jurisdictions, and instead support interoperable approaches that are realistic for organizations with very different capacities.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

Apart from creating its own processes and outputs, the AI Dialogue could focus on connecting and translating what already exists, rather than starting from scratch. Global standards such as ISO/IEC 42001 on AI management systems, the OECD AI Principles, the NIST AI Risk Management Framework, the EU AI Act and emerging sectoral standards already provide strong foundations for risk management, accountability and lifecycle governance. Its added value could be to distil these into a small set of simple, global "good practice baselines" that enterprises, SMEs and public bodies can actually apply: for example, minimum expectations for documentation, testing before deployment, human oversight, data‑use transparency and vendor governance. These baselines should highlight a short list of non‑negotiable controls rather than long checklists, with concrete illustrations from high‑performing industries and regulators worldwide. The Dialogue could also promote alignment and mutual recognition between frameworks (such as mapping ISO/IEC 42001 and the EU AI Act obligations) so that organisations do not have to navigate conflicting expectations in different markets. Finally, by producing accessible, non‑technical guidance and model questions for buyers, it can give even smaller or less resourced players something reliable to lean on when evaluating and deploying AI systems.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

To be useful, the Dialogue should feel less like a conference and more like a structured working process. Governments can contribute by sharing regulatory roadmaps, supervisory expectations and real enforcement lessons, not just high‑level statements. Industry, especially enterprise buyers and critical‑infrastructure providers, should bring concrete use cases, governance patterns and procurement practices that show how AI rules are translated into testing, integrations, contracts and monitoring. Civil society and academia can stress‑test these practices against human rights, democracy and labour impacts, and bring evidence on harms that rarely reach boardrooms. Technical experts can help distinguish what is realistically implementable from what is wishful thinking. In terms of structure, a multi‑track format makes sense: one track where governments negotiate and compare approaches; one where industry shares operational practices; one where civil society and affected communities highlight on‑the‑ground impacts; and cross‑cutting sessions where these groups co‑draft short, practical outputs together. Each cycle of the Dialogue should end with a few concrete artefacts, for example, checklists for buyers, guidance for SMEs, or model questions for regulators, rather than only general declarations.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

In my view, groups that remain underrepresented in global AI governance debates include start ups and SMEs, trade unions and workers, communities from various regions globally outside major urban centers and people directly affected by surveillance or automated decision making, such as job candidates. They can be included through reserved seats and funded participation in advisory groups and working tracks, not just one off consultations. This should cover both institutional actors (for example, SME associations, local authorities, unions, digital rights organizations) and individual experts with lived experience of AI mediated harms. Remote channels - written calls for input, structured surveys, online hearings in multiple languages - are essential so that people who cannot travel or speak in large plenaries can still influence the agenda. The Dialogue should also partner with regional networks and initiatives to host local sessions feeding into the global process, rather than expecting everyone to adapt to one format.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

To make the Dialogue dynamic and concrete, engagement formats should go beyond keynotes and static panels. Scenario labs and tabletop exercises built around realistic AI governance or AI incident scenarios, for example in industrial AI, recruitment or public services, can bring together regulators, vendors, buyers and civil society to work through decisions, trade‑offs and failure points in real time. From my own experience designing and running such workshops, for example, the "Would I buy your AI?" sessions with AI students in the Netherlands, a structured, discussion‑based simulation from the perspective of a demanding client helped participants learn how to build systems not only for efficiency, but also for safety and responsibility. Based on such hands‑on experiences, I would strongly recommend integrating similar formats into the Dialogue. Interactive "fishbowl" sessions can be used when perspectives diverge: a small inner circle discusses a concrete governance question while others observe, with open chairs so affected communities, SMEs or regulators can step in when they have something to add. This format keeps debates focused but porous and helps surface disagreements and assumptions transparently. The Dialogue could also use short "practice clinics" where organizations present a governance challenge (for example, testing vendor tools, documenting industrial AI, ensuring meaningful oversight) and receive rapid feedback from peers and regulators. To sustain engagement between meetings, online workspaces and time‑boxed drafting sprints can be used to co‑develop practical outputs such as baselines for testing, procurement questions or templates for AI incident reporting.

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

6

Effective AI governance is increasingly supported by specific tools and mechanisms, not only high-level principles. Public incident registries such as the AI Incident Database and the MIT AI Incident Tracker collect and classify real-world AI failures, giving policymakers, developers and auditors an evidence base for understanding harms, patterns and root causes instead of relying only on hypothetical risks. At EU level, the AI Act introduces mandatory serious-incident reporting and a future EU-wide database for high-risk AI systems, creating a structured way to surface problems early and learn across borders. In addition, the EU's proposed Digital Omnibus on AI requires the European Commission to publish practical guidance on key parts of the AI Act. These guidelines are meant to help organisations apply the AI Act in a realistic and proportionate way and they could also be useful for organisations outside the EU that want clear, ready-to-use governance benchmarks, even if they are not directly bound by EU law. Another promising approach is regulatory sandboxes, such as those foreseen in the AI Act, where regulators and innovators can jointly test AI systems under supervision, refine obligations and better understand practical constraints before full-scale deployment. The OECD AI Policy Observatory plays a complementary role by mapping national policies, sharing case studies and helping countries translate the OECD AI Principles into concrete, evidence-based measures. On the organizational side, AI management systems aligned with standards like ISO/IEC 42001 and the NIST AI Risk Management Framework help embed governance into inventories, risk assessments, documented controls and continuous improvement cycles, moving AI governance from abstract ethics towards everyday operational practice.