BEYOND GUARD LTD
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
The first Global Dialogue will succeed if it moves beyond reaffirming principles and delivers a small number of concrete, reusable governance tools that any jurisdiction can adopt immediately. Three outcomes would signal genuine progress: First, a shared operational baseline for trustworthy AI. Governments broadly agree on values such as safety, transparency and accountability, but diverge on what these mean in practice. The Dialogue should produce a voluntary, non-binding reference that answers four questions for any AI deployment: what must be documented, what must be tested, when human oversight is required, and how decisions are logged after deployment. This does not demand legal harmonization; it creates a common language so that regulators, developers and procurers can compare expectations across borders. Second, openly licensed governance artifacts. A transparency reporting template, an incident taxonomy for cross-border learning, and a public-sector procurement checklist would have immediate practical value. These instruments cost little to produce, require no treaty, and can be iterated by the community. From our experience advising regulated institutions in banking and public administration, the single greatest barrier to responsible AI adoption is not the absence of regulation. It is the absence of usable, standardized tools that translate regulation into operational practice. Third, a capacity coordination mechanism with teeth. Many countries participate in AI governance discussions but lack the evaluation infrastructure, technical expertise and compute access to implement what is discussed. Success means the Dialogue does not simply acknowledge this gap but maps existing capacity programs, identifies where critical shortfalls remain, and commits to concrete follow-through: shared regional evaluation centres, open governance toolkits in multiple languages, and training pathways for policymakers. One additional marker of success: explicit recognition that AI governance must extend to runtime and agentic systems, where risk is dynamic and interaction-driven, not confined to model training or pre-deployment review. Outcomes should be compact, open and immediately actionable. The world does not need another declaration. It needs governance infrastructure.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- AI capacity-building
- Interoperability of governance approaches
- Transparency, accountability, and human oversight
Please briefly explain your selection.
6
These four priorities reflect the areas where we see the most urgent gap between stated governance ambitions and actual operational reality, based on direct experience securing AI systems in banking, telecommunications and public-sector environments across multiple jurisdictions. Safe, secure and trustworthy AI is our primary focus because safety cannot remain an abstract aspiration. In production environments, AI risk is not static; it is interaction-driven. A model that passes every pre-deployment evaluation can be exploited through novel prompt injection, retrieval-augmented generation manipulation, or unauthorized tool invocations within agentic workflows. Governance frameworks that stop at model-level assurance leave a structural blind spot at the runtime layer, where AI systems actually interact with users, data and critical infrastructure. Closing this gap requires continuous, real-time enforcement throughout the deployment lifecycle, not only at design or certification stages. Transparency, accountability and human oversight are inseparable from safety. Every governance decision (allow, deny, mask, escalate) must be recorded with justification, confidence level and audit context. Without verifiable evidence, governance commitments cannot be distinguished from marketing claims. Human oversight also requires practical mechanisms such as escalation paths and emergency intervention capabilities, not merely policy statements. Interoperability of governance approaches matters because organizations operating across borders face fragmented expectations. Common governance artifacts (reporting templates, incident taxonomies, procurement checklists) would enable comparability without requiring legal harmonization. This is particularly critical for regulated sectors such as finance and healthcare where cross-border AI deployments are accelerating. AI capacity-building is not secondary; it is a precondition for legitimate global governance. Many institutions we engage with, including in emerging markets, have adopted AI but lack the evaluation infrastructure, red-teaming expertise and governance tooling to manage it responsibly. Without targeted capacity support, governance frameworks become mandates that only well-resourced actors can implement, deepening rather than closing AI divides. Human rights and open innovation are woven throughout these priorities rather than treated separately.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
4
Yes. Working across banking, telecommunications and public institutions in multiple jurisdictions, I observe three cross-cutting issues that sit beneath all listed themes but are not explicitly named. The asymmetry between deployment speed and governance readiness. AI systems reach production environments far faster than institutions develop the capacity to govern them. This is not simply a regulatory lag; it reflects a structural mismatch. The organizations deploying AI at scale are rarely the same organizations responsible for oversight. In many countries, regulators are asked to evaluate systems they have never operated, using frameworks written for technologies that have already evolved. Meanwhile, adversarial techniques against AI systems evolve weekly: encoding-based evasion, multi-turn conversational manipulation, and injection payloads concealed within routine business queries. A model certified as safe on Monday can be exploited through methods that did not exist during its evaluation. Governance must therefore shift from point-in-time certification to continuous, lifecycle-based oversight that includes real-time monitoring, periodic recalibration and post-deployment accountability. Without this shift, governance becomes a retrospective exercise rather than a living discipline. Agentic AI and the redrawing of human authority boundaries. The transition from AI as an advisory tool to AI as an autonomous agent capable of invoking external services, executing transactions and chaining multi-step decisions represents more than a technical evolution. It raises fundamental questions about where human authority begins and ends. When an AI agent approves a financial transaction, escalates a customer complaint or modifies a data record, the question is no longer whether the model produced an accurate answer but whether the action was authorized, proportionate and reversible. Current governance frameworks were designed for systems that inform human decisions, not systems that replace them. The Dialogue should name agentic AI as a distinct governance frontier and initiate work on accountability structures for autonomous action. Linguistic and cultural equity in AI security. AI-based attacks increasingly exploit the uneven language coverage of safety mechanisms. Adversaries craft prompts in languages where detection models have thinner training data, effectively using linguistic diversity as an attack vector. This transforms a capacity gap into a security vulnerability. Governance discussions about inclusion and multilingualism must recognize that language equity is not only an access issue but a safety issue. Similarly, data sovereignty and on-premises deployment requirements across Turkiye, the Middle East, Africa and Asia are not obstacles to governance; they are expressions of democratic self-determination over critical digital infrastructure. Frameworks that implicitly assume cloud-delivered, English-dominant AI exclude both the communities most affected by AI risk and the deployment realities of the majority of the world.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
We operate at the intersection of three regulatory environments: the European Union, Turkiye and the Gulf. Each is advancing AI governance, but in ways that expose both significant gaps and genuine opportunities. The challenge of fragmented regulatory timelines. The EU AI Act entered into force with a staged implementation extending through August 2027, creating the most detailed compliance framework globally. Turkiye, a candidate country with deep economic ties to the EU, is simultaneously aligning with EU requirements while operating under its own data protection regime (KVKK) and sector-specific banking regulations (BDDK). Gulf states, particularly Qatar, are developing AI governance guidelines through central banks and financial regulators. For organizations operating across these jurisdictions, there is currently no mechanism to demonstrate compliance once and have it recognized elsewhere. Each regulator asks similar questions in incompatible formats. This is not a theoretical inconvenience; it is a material barrier that slows responsible adoption and diverts security resources from genuine risk reduction to duplicative paperwork. The safety gap in regulated sectors. In financial services, AI systems handle sensitive customer data, influence credit decisions and interact with critical payment infrastructure. Yet the governance tools available to banks remain largely generic. We consistently observe that security mechanisms calibrated for general-purpose use produce unacceptable false positive rates when applied to domain-specific interactions, while genuinely adversarial inputs exploit exactly these calibration blind spots. The absence of sector-specific governance baselines means every institution improvises independently, repeating the same mistakes. The opportunity. These same conditions create a compelling case for exactly what the Dialogue can provide: shared governance artifacts that are adaptable across jurisdictions without requiring legal harmonization. Turkiye and the Gulf region, sitting between the EU regulatory sphere and rapidly growing Asian and African AI markets, could serve as natural testing grounds for interoperable governance approaches. The demand exists. Institutions are not waiting for perfect regulation; they are seeking usable, comparable governance infrastructure now.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The Dialogue's most valuable role is not to produce another set of principles but to become the place where governance becomes operational across borders.Today, international AI governance suffers from a paradox. There is broad consensus on values: safety, transparency, accountability, human rights. Yet there is almost no shared infrastructure for putting these values into practice. A bank in Southeast Asia, a hospital in the Gulf and a public agency in East Africa face structurally similar AI risks but have no common language for describing them, no comparable formats for reporting incidents, and no shared benchmarks for evaluating whether their governance measures actually work. Each institution reinvents the wheel in isolation.The Dialogue can break this pattern by serving three functions that no other international body currently fills.First, a translation layer between regulatory regimes. The EU AI Act, national frameworks across the Gulf and Asia-Pacific, emerging regulations in Africa and Latin America, and sector-specific requirements like banking supervision standards all ask overlapping but differently formatted questions. The Dialogue can produce lightweight, openly licensed governance artifacts (transparency templates, incident taxonomies, procurement checklists) that allow different regimes to speak to each other without requiring legal harmonization. This is practical interoperability: not one law, but one shared vocabulary.Second, a bridge between governance ambition and governance capacity. Many countries have adopted AI strategies but lack the evaluation infrastructure, technical expertise and institutional muscle to implement them. The Dialogue should pair every governance discussion with a concrete capacity question: who can implement this, and what do they need?Third, an early warning function for emerging risks. Agentic AI, multi-language adversarial exploitation and the erosion of the boundary between human and machine decision-making are accelerating faster than any single national regulator can track. A standing international dialogue can surface these developments before they become crises rather than after.Cooperation advances not through declarations but through shared tools that reduce the cost of doing governance well.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The AI governance landscape is not empty; it is fragmented. Valuable work exists across multiple bodies, but it remains siloed, duplicative in some areas and absent in others. The Dialogue's added value lies in connecting these efforts into a coherent operational ecosystem rather than creating yet another parallel track. Frameworks and standards the Dialogue should build upon: The OECD AI Principles and their associated governance tools provide a widely accepted policy foundation. The NIST AI Risk Management Framework offers detailed operational guidance that many organizations already reference. OWASP's Top 10 for LLM Applications and its 2026 extension for Agentic Applications represent the most current practitioner-driven risk taxonomies for generative and agentic AI. MITRE ATLAS maps adversarial tactics against AI systems in a format familiar to cybersecurity teams worldwide. The EU AI Act's staged implementation is generating the most detailed compliance infrastructure globally, producing practical precedents that regulators across regions are watching closely. Regional and sector-specific mechanisms: The ISO/IEC 42001 standard for AI management systems is gaining traction as a certifiable governance baseline. Central bank AI guidelines emerging across the Gulf, Southeast Asia and Latin America demonstrate that sector-specific governance is advancing independently of horizontal legislation. The ITU's AI for Good platform and the Internet Governance Forum's Policy Network on AI have established multi-stakeholder dialogue channels that could feed directly into the Dialogue's process. The Global Partnership on AI (GPAI) and regional bodies such as the African Union's AI strategy and ASEAN's governance framework offer additional coordination surfaces. Where the Dialogue adds unique value: None of these initiatives bridge the gap between technical risk taxonomies and policy-level governance expectations. A security practitioner working with OWASP and NIST and a policymaker working with OECD principles are often addressing the same risks in mutually unintelligible languages. The Dialogue can serve as the integration layer: translating between technical, regulatory and policy communities, identifying coverage gaps, and producing openly licensed reference materials that connect existing frameworks rather than replacing them. This connecting function, not content creation from scratch, is where the Dialogue's comparative advantage lies.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
The Dialogue's credibility will depend on whether it can bridge the distance between those who write governance and those who live with its consequences.Differentiated stakeholder roles. Each group holds knowledge the others lack. Governments understand institutional constraints. The private sector, including smaller companies with hands-on deployment experience, holds operational data on what works and what fails under real conditions. In our own work securing AI systems for regulated institutions, we have found that the gap between policy intent and operational reality is often wider than either side assumes. Civil society carries the perspectives of affected communities. Academia provides methodological rigour. The Dialogue should ask each group different questions: governments what they need to implement, practitioners what breaks in the field, civil society who is being harmed.Format recommendations:Working streams organised by output, not theme. Instead of broad panels, establish small groups tasked with producing specific deliverables: a transparency template, an incident taxonomy, a capacity assessment. Output-driven structure forces concrete negotiation rather than parallel monologues.Pre-session written inputs should be published before Geneva so participants can engage with each other's positions rather than arriving cold.Regional preparatory consultations must carry genuine weight. If regional perspectives are collected but visibly absent from the final summary, participation becomes performative. Regional consultations should produce proposals the Co-Chairs are obligated to address.The Geneva session should conclude with specific next steps and a timeline, not an aspirational communique. Contributors should be able to measure whether their input was considered.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Global AI governance discussions are disproportionately shaped by a narrow set of actors: large technology companies headquartered in a handful of countries, well-funded civil society organisations in North America and Western Europe, and regulators from jurisdictions that have already enacted comprehensive legislation.Practitioners who operate AI in high-stakes environments. The people deploying and securing AI systems in hospitals, banks and public services possess direct knowledge of where governance works and where it collapses. From our field experience across financial services and public institutions in multiple regions, we see that the operational realities of AI governance are rarely represented in international discussions. These practitioners struggle with challenges that policy documents do not anticipate: domain-specific false positive patterns, adversarial techniques that evolve faster than compliance cycles, and the daily tension between security requirements and usability. The Dialogue should create channels for practitioner testimony as primary evidence, not anecdotal illustration.Communities affected by AI decisions who lack any avenue for redress. Individuals denied credit, flagged by automated systems, or excluded by eligibility algorithms are the ultimate test of governance. Most have no mechanism to participate in discussions shaping the rules that govern these systems. Inclusion requires accessible, multilingual feedback pathways that reach beyond digitally connected populations.The Global South as governance authors. Countries across Africa, Southeast Asia, Latin America and the Middle East are not simply catching up with governance designed elsewhere. Many are developing original approaches shaped by different institutional realities, data sovereignty requirements and cultural contexts. These are legitimate governance innovations, not deviations from an assumed norm. The Dialogue should treat these contributions as sources of new thinking.Linguistic communities outside the English-speaking world. When governance frameworks and safety research are produced predominantly in English, entire communities are excluded from both contribution and scrutiny. This is particularly dangerous because AI safety mechanisms tend to be weakest in languages where participation is lowest, creating a cycle where the most vulnerable populations have the least voice.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
Traditional multilateral formats, plenary speeches followed by scripted panels, are poorly suited to a governance challenge that is technically complex, fast-moving and affects vastly different stakeholders in vastly different ways.Live governance stress-testing. Instead of abstract discussions, convene sessions where a real scenario is worked through collectively. Present a concrete case: an AI agent in a financial institution executes an unauthorized action. Ask a mixed table of regulators, practitioners and civil society representatives to draft a governance response together. In our experience facilitating adversarial testing exercises for enterprise clients, these scenario-driven formats consistently reveal assumptions and blind spots that months of document review never surface.Draft-and-critique workshops. Circulate a first draft of a specific governance artifact before the Geneva session. During the session, run structured workshops where participants improve the draft collectively rather than commenting from the floor. The output is a versioned document participants can take home and test against their own institutional reality.Asymmetric dialogue tables. Most governance events seat people of similar seniority together. The Dialogue should deliberately construct tables where a data engineer from Lagos sits with a senior regulator from Brussels and a patient rights advocate from Manila. The governance gap is not between institutions. It is between lived experiences of AI. Asymmetric composition surfaces blind spots that peer-level panels never reach.Asynchronous multilingual contribution channels. Not everyone with something valuable to say can travel to Geneva in July. The Dialogue should maintain an open, moderated platform where contributions in any language are translated and made available before, during and after the session. If the Dialogue is truly global, its engagement infrastructure must reflect that ambition year-round, not only during two days in a single city.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
3
The most effective governance approaches we have encountered in our field work share a common trait: they treat AI governance not as a compliance checkbox but as a continuous operational discipline embedded in how AI systems actually run. Lifecycle-based governance rather than point-in-time certification. Organizations that govern AI effectively do not rely solely on pre-deployment review. They structure governance across four phases: design-time hardening of prompts and policies, pre-production adversarial testing through structured red teaming, runtime enforcement through centralized policy controls, and continuous evidence generation through audit logging and decision traceability. We have seen this approach dramatically reduce both security incidents and regulatory preparation burden for institutions in financial services and the public sector. The critical insight is that each phase catches what the others miss. Model-agnostic, centralized policy enforcement. Institutions that depend on the safety mechanisms of individual model providers find themselves re-doing governance work every time they switch or add a provider. The more resilient approach, and one we have observed gaining traction across multiple regions, is to enforce governance policies at the infrastructure layer independently of the underlying model. This ensures consistent security regardless of whether an organization uses cloud-hosted, open-source or on-premises models. Confidence-based decision-making over binary filtering. Rigid allow-or-block approaches generate unacceptable false positive rates in specialized domains. In banking, healthcare and legal services, we consistently see that the most effective practice is calibrated decision-making: each security assessment produces a measurable confidence score evaluated against context-specific thresholds that the organization itself defines. This preserves institutional autonomy while maintaining auditable, explainable outcomes. Sector-specific governance calibration. Generic safety models struggle with domain terminology. A query about account blocking or credit limits in a banking context is not a security threat, but generic systems frequently treat it as one. Institutions that invest in sector-adapted governance calibration achieve significantly better accuracy and operational trust. These are not theoretical recommendations. Each reflects patterns we have validated through enterprise deployments across regulated industries.