EU Security and AI Lab
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
On behalf of EU Security and AI Lab, where our mission is to safeguard the security of the European Union, we wish to communicate the following: AI security is no longer only a technical issue—it is a global governance challenge. AI is already being deployed in transportation, surveillance, critical infrastructure, and military systems. However, there is still limited transparency on how these models are trained, how bias is managed, and how they will respond if control is taken over by an adversary. Existing security frameworks often do not fully address AI-specific risks, and responsibility and accountability remain unclear. In practice, security approaches must be tailored to each system—there is no unified solution, despite recent efforts to develop compliance frameworks. Too often, security is addressed only after harm occurs, such as identity misuse, system take-over through techniques like spoofing, or disruption of control through methods such as jamming. At the same time, AI is being rapidly deployed—including in banking and autonomous systems—without sufficiently secure architectures. The EU Security and AI Lab urges the global community to treat AI security as a core pillar of global AI governance. Not an option. Because in a connected world, security is only as strong as its weakest point. Thank you.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Social, economic, ethical, cultural, linguistic and technical implications of AI
- Transparency, accountability, and human oversight
Please briefly explain your selection.
The three selected areas have direct impact on human rights.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
We believe that "AI controlled by an adversary" should be a standalone topic to address, as taking control of AI-driven systems is not a science. It's yet another routine illegal technique, however with an enormous impact.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
Here are the most urgent examples: AI-enhanced drones and other weapons are being employed in current conflicts, while control take-over methods are still not even possible to prevent in more simple devices such as satellites and airplanes. European banking and critical infrastructure sectors (such as energy) are widely adopting AI agents that have access to private and governmental data, while we often see that the data is not sufficiently secured. However, the fast cost-saving coming from AI-automation is too often the primary interest of those entities and security audits are not yet able to reflect this situation. This may allow adversarial entities to identify critical points of the EU infrastructure and enable harm. Children and other vulnerable groups are exposed to surveillance of actors that practice child abuse through numerous AI-enhanced digital platforms, while security is left behind and underdeveloped.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
From a security perspective, the AI Dialogue should focus on establishing interoperable security standards and clear accountability for AI systems. Today, vulnerabilities in AI-based systems can have cross-border impact, but governance remains fragmented. The Dialogue can help bridge this gap by promoting shared security principles, encouraging security-by-design, and supporting global capacity to manage AI risks.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The AI Dialogue should build on existing international efforts, such as the OECD AI Principles, the G7 Hiroshima AI Process, and technical frameworks developed by NIST and ISO/IEC. It should also connect with regulatory approaches such as the EU AI Act. These initiatives already provide valuable principles, standards, and risk frameworks. However, they remain fragmented and are not always interoperable in practice. The added value of the AI Dialogue would be to connect these efforts—aligning them into a more coherent global approach, especially in areas like security, accountability, and transparency. It can also help bridge gaps between policy and technical implementation, and support capacity-building so that all countries can apply these frameworks effectively. At the same time, there is a clear need to develop a dedicated global standard for IoT security, particularly for AI-enabled devices, which introduce additional risks and complexities. In this way, the AI Dialogue can move from multiple parallel initiatives toward a more coordinated and practical global governance system.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Different stakeholders should contribute based on their expertise. Governments can provide regulatory direction and ensure alignment with international law. Industry can share real-world implementation experience and emerging risks. Academia can contribute research, and civil society can highlight human rights and societal impacts. Importantly, security practitioners should be included to bring practical insight into real vulnerabilities and system behavior. In terms of format, the AI Dialogue should combine high-level policy discussions with technical working groups. It should be multi-stakeholder, but also action-oriented, with clear outputs such as guidelines, standards, or recommendations. It would also be valuable to include dedicated tracks—for example on AI security, IoT systems, and critical infrastructure—where more detailed and technical discussions can take place. Finally, the Dialogue should ensure continuity, not just one-time discussions, but ongoing cooperation with measurable outcomes and follow-up mechanisms.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Several key voices remain underrepresented in global AI governance—especially from a security perspective. First, security practitioners, including engineers and architects, who work directly with AI systems and understand real-world vulnerabilities, attack vectors, and system behavior. Their insights are often missing, even though they see how systems fail in practice. Second, stakeholders from developing countries, who may lack the capacity to secure AI systems, yet are increasingly exposed to risks, particularly in critical infrastructure and IoT environments. Third, operators of real-world systems—such as those managing banking platforms, surveillance systems, or industrial infrastructure—who face security challenges daily but are rarely included in governance discussions. To address this, the AI Dialogue should create dedicated technical tracks, ensure stronger representation from underrepresented regions, and actively integrate hands-on security expertise into policy development. Without these perspectives, AI governance risks remaining theoretical, while real-world vulnerabilities continue to grow.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
To foster meaningful engagement, the AI Dialogue should go beyond traditional panel discussions. First, scenario-based simulations could be highly effective—for example, responding to an AI security incident such as system takeover or data compromise. This allows stakeholders to engage with real-world complexity. Second, technical breakout sessions should be included, where experts can work through concrete challenges, such as securing AI-enabled IoT systems or defining accountability in case of failure. Third, cross-sector workshops that bring together policymakers, engineers, and operators can help bridge the gap between policy and implementation. Finally, the Dialogue should include continuous collaboration formats, such as working groups with clear outputs and follow-up, rather than one-time discussions. These approaches would make the Dialogue more practical, dynamic, and outcome-oriented.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
8
Several existing policies and approaches already provide useful foundations for effective AI governance. For example, the EU AI Act introduces a risk-based approach, linking obligations to the level of impact of AI systems. The NIST AI Risk Management Framework provides practical guidance on identifying and mitigating risks, including security. From a technical perspective, practices such as security-by-design and continuous monitoring are essential, especially for AI systems that evolve over time. Red-teaming and adversarial testing are also increasingly important to identify vulnerabilities that traditional audits may miss. There are also emerging platforms and collaborative approaches, including open-source tools and shared datasets, which can improve transparency and accessibility. However, these efforts remain fragmented. A key solution is to better connect policy frameworks with technical implementation, and ensure that security is integrated from the beginning, not addressed only after incidents occur.