Skip to content

Vigilens AS

Private Sector Western Europe and Other States

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

Success for the first Global Dialogue on AI Governance should be measured not by declarations signed, but by infrastructure built specifically, whether it closes the gap between governance intent and operational reality. Three outcomes would make this dialogue genuinely meaningful. First, agreement on machine-executable governance standards. Most AI compliance today is document-based: policies written, checklists ticked, audits filed. This produces compliance theatre rather than actual oversight. A successful dialogue would commit member states to developing governance standards that can be encoded as verifiable rules integrated directly into development pipelines, not just legal departments. This is technically achievable today, and frameworks like the EU AI Act point in the right direction. The Dialogue should accelerate international convergence toward this model. Second, inclusion of SMEs in the governance architecture. Global AI governance discussions tend to be designed around large technology companies and public institutions. But the vast majority of AI systems being deployed across critical sectors healthcare, infrastructure, financial services are built or procured by small and medium-sized organisations that lack dedicated compliance resources. If governance frameworks remain inaccessible to them in practice, they become tools of competitive disadvantage rather than risk reduction. Success means producing guidance and tooling that works at the SME level. Third, a functioning science-to-policy feedback loop. The Independent International Scientific Panel on AI is the right idea. Success means the Dialogue actually uses its outputs to revise governance positions in real time not treat them as background reading. From our work building Vigilens, an AI governance platform for SMEs, the most persistent challenge we encounter is the distance between what regulators intend and what organisations can operationalise. Closing that distance practically, not rhetorically is what success looks like.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Interoperability of governance approaches
  • Safe, secure and trustworthy AI
  • Transparency, accountability, and human oversight
  • Open-source software, open data and open AI models

Please briefly explain your selection.

7

Safe, secure and trustworthy AI is the foundation. Without it, everything else is cosmetic. But trustworthiness cannot be asserted it must be demonstrated continuously, through evidence collected at the system level, not declared in policy documents filed annually. Transparency, accountability, and human oversight are what make trustworthiness verifiable. From our experience building Vigilens, an AI compliance platform for SMEs, the single most common failure mode is not malicious intent it is the absence of audit trails. Organisations deploying AI systems often cannot reconstruct why a decision was made, who approved it, or whether controls were active at the time. Governance frameworks must require continuous evidence collection as a baseline, not as an advanced option. Interoperability of governance approaches matters because fragmentation is already a competitive problem, not just a policy problem. A Norwegian SME deploying AI across EU markets faces the EU AI Act, sector-specific regulators, and emerging national frameworks simultaneously. If these regimes do not converge on shared definitions and mutual recognition mechanisms, compliance becomes a cost only large organisations can absorb effectively an entry barrier. Open-source software, open data and open AI models are the enabler that makes the other three achievable at scale. Governance tooling built on proprietary stacks will not reach the organisations that need it most. Open, interoperable infrastructure lowers the floor for responsible AI adoption globally.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

3

Three issues cut across all listed themes but are not adequately captured by any of them individually. The operationalisation gap. Governance frameworks are largely designed by legal and policy experts, but implemented or not, by engineers, product managers, and procurement officers. The most significant risk in AI governance today is not the absence of rules, but the absence of tooling that translates rules into something actionable at the system level. This is a structural problem that no amount of additional policy dialogue resolves without deliberate attention to implementation infrastructure. Continuous compliance versus point-in-time compliance. Most existing frameworks including the EU AI Act are built around conformity assessments: checks conducted at deployment or on an annual cycle. But AI systems drift. Models are retrained, data distributions shift, human oversight degrades over time. A governance architecture designed around static checkpoints will systematically miss the risks that emerge between them. The Dialogue should push for governance standards that treat compliance as a continuous state, not a periodic certification. The SME governance gap as a systemic risk. Large technology companies have legal teams, compliance officers, and resources to engage with frameworks like these. The majority of AI deployments globally are made by organisations that do not. When SMEs, which procure and deploy AI across healthcare, finance, infrastructure, and public services fall outside effective governance coverage, the overall risk profile of AI adoption is far higher than headline compliance rates suggest. This is not a capacity-building question alone; it is a framework design question. Governance architectures must be built from the start with resource-constrained actors in mind, not retrofitted for them later. These are not niche concerns. They determine whether AI governance functions in reality or only in documentation.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

Norway sits at an interesting intersection: a non-EU member fully committed to EEA alignment, a country with significant AI deployment across critical sectors energy, maritime, public services, financial infrastructure and a startup ecosystem that is disproportionately SME-driven. The governance gaps identified above manifest here in concrete ways. The compliance cost asymmetry is already visible. As the EU AI Act enters its enforcement phases, Norwegian companies operating in European markets face the same obligations as their EU counterparts, but without the same institutional support structures. Large incumbents are building internal compliance functions. SMEs are either paralysed by uncertainty or proceeding without adequate oversight. This creates a two-tier market where governance becomes a moat rather than a baseline. Critical infrastructure exposure is underappreciated. Norway's energy grid, rail network, and financial system are increasingly dependent on AI-assisted decision-making. The governance frameworks governing these systems remain fragmented across sector regulators, with limited interoperability between them and emerging horizontal frameworks like the EU AI Act. The risk is not theoretical it is a question of whether human oversight mechanisms will hold when they are most needed. The opportunity is equally significant. Norway has a strong tradition of tripartite cooperation between government, industry, and labour a governance culture that translates well to responsible AI adoption. It also has world-class research institutions, a high level of digital infrastructure maturity, and genuine political will to engage on these questions. If the Global Dialogue produces interoperable, implementable governance standards, Norwegian organisations particularly in the public sector and critical infrastructure are well-positioned to adopt them early and credibly. The gap between that potential and current reality is largely an operationalisation problem. The frameworks exist in outline. The tooling to make them work at scale does not yet.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

The AI Dialogue's most valuable role is not to produce another framework. The world does not lack AI governance principles. It lacks mechanisms that turn principles into verifiable, interoperable practice across jurisdictions. Three specific contributions would make the Dialogue genuinely useful. Convergence infrastructure, not just consensus language. The Dialogue should prioritise producing shared technical artifacts common risk taxonomies, reference control libraries, interoperability mappings between major frameworks like the EU AI Act, NIST AI RMF, and ISO 42001. These are the building blocks that allow governance to travel across borders without requiring full harmonisation. Consensus language in a final communiqué does not achieve this. Shared technical standards do. A legitimate channel for the excluded majority. One hundred and eighteen countries currently have no meaningful participation in any significant international AI governance initiative. The Dialogue's value is not in what it produces for the OECD or G7 those processes already exist. Its value is in creating governance capacity for the countries and organisations that currently have none. This means outputs must be designed for resource-constrained actors, not translated for them after the fact. A feedback loop between science and policy. The Independent International Scientific Panel on AI is only as useful as the Dialogue's willingness to act on its findings. Too often, scientific advisory bodies produce assessments that inform background documents rather than revise policy positions. If the Dialogue builds an explicit mechanism for scientific findings to trigger governance updates not just inform debate it would represent a genuine institutional innovation. What the Dialogue must avoid is becoming a venue where geopolitical positioning substitutes for practical cooperation. The US withdrawal from multilateral AI initiatives and China's growing assertiveness make this risk real. The Dialogue's credibility depends on demonstrating that inclusive governance produces better outcomes than fragmented national approaches and doing so quickly enough to matter.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

Several existing initiatives provide foundations the Dialogue should actively build on rather than duplicate. The EU AI Act is the most comprehensive binding framework currently in force. It establishes risk classification, conformity assessment requirements, and prohibited use categories that have already become a de facto global reference point. The Dialogue should treat it as a baseline and work toward mutual recognition mechanisms that allow compliance demonstrated under the EU framework to carry weight in other jurisdictions reducing duplication for organisations operating across borders. NIST AI RMF and ISO 42001 represent the leading voluntary frameworks for AI risk management. They are technically rigorous, sector-agnostic, and already widely adopted in enterprise contexts. The Dialogue should fund and coordinate work to map these frameworks against each other and against binding regulations producing the interoperability layer that currently does not exist. The OECD AI Principles and the Global Partnership on AI established the normative foundation for responsible AI at the international level. The Dialogue should not re-litigate these principles but operationalise them translating high-level commitments into implementable governance requirements. The GS AI framework (Guaranteed Safe AI, arXiv:2405.06624) and related technical safety research represent frontier thinking on verifiable AI safety guarantees. The Dialogue, through the Scientific Panel, should actively engage this body of work and explore how machine-verifiable safety properties could inform the next generation of governance standards. The added value the Dialogue brings is not more principles or parallel frameworks. It is universality and legitimacy. For the first time, every UN member state has a seat at the table. That reach if used deliberately can do what no regional or voluntary initiative can: establish a floor of governance expectations that applies globally, and build the shared infrastructure that makes meeting that floor achievable for all actors, not just well-resourced ones.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

The Dialogue's legitimacy depends on who is actually in the room and whether their participation shapes outcomes rather than decorates them. Meaningful multi-stakeholder engagement requires deliberate design, not open invitation. Governments should come with concrete national implementation experiences, not only policy positions. The most valuable government contributions will be candid accounts of what has worked, what has failed, and where regulatory capacity is genuinely lacking. The Dialogue should create structured space for this including from smaller states that rarely lead in these forums but often have the most instructive implementation stories. Industry participation must extend beyond large technology companies. The organisations building and deploying the majority of AI systems globally are SMEs and mid-market firms. Their operational realities constrained resources, limited legal capacity, genuine uncertainty about compliance requirements should directly inform governance design. The Dialogue should establish a dedicated SME advisory track, not treat industry input as synonymous with big tech input. Civil society and affected communities should have structured input at the design stage, not only at the review stage. Governance frameworks that are consulted on after the architecture is set tend to absorb feedback without changing direction. Researchers and technical experts, through the Scientific Panel, should present findings in formats that are actionable for policymakers with explicit recommendations, not only assessments. On format, the Dialogue should resist the gravitational pull toward plenary declarations. The most productive international governance work happens in focused working groups with specific mandates, clear deliverables, and defined timelines. The Geneva session in July 2026 should establish these groups and assign them concrete outputs to produce before the 2027 New York session turning the two-year cycle into a productive iteration rather than two standalone events. Continuity between sessions matters as much as what happens within them.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

The gap between who shapes AI governance and who is most affected by it is one of the most serious legitimacy problems facing the field. Several communities remain structurally underrepresented. SMEs and non-technology-sector operators. Global AI governance conversations are dominated by large technology companies, major research institutions, and well-resourced public bodies. Yet the organisations deploying AI at scale across healthcare, financial services, logistics, and public administration are overwhelmingly smaller, resource-constrained actors. Their practical experience of governance — what is implementable, what creates perverse incentives, what simply does not translate from policy to operations is largely absent from the rooms where frameworks are designed. The Global South. One hundred and eighteen countries currently have no meaningful participation in significant international AI governance initiatives. This is not only a fairness problem it is an accuracy problem. Governance frameworks designed without input from contexts where AI is deployed under different infrastructure constraints, legal traditions, and social conditions will systematically fail in those contexts. Inclusion requires more than translation of existing documents. It requires genuine co-design from the start. Frontline workers and affected publics. People whose employment, access to services, or legal status is directly shaped by AI systems — benefits claimants, gig workers, patients, migrants are almost entirely absent from governance discussions. Their experiences contain signal that no technical or legal expert can substitute. Smaller national regulators and public institutions. Not all governments are equal participants. Smaller national authorities, particularly outside the EU and North America, lack the capacity to engage meaningfully with complex technical frameworks. The Dialogue should invest in regulatory capacity-building as a precondition for genuine inclusion, not an afterthought. Inclusion is not achieved by opening a submission portal. It requires proactive outreach, translation, simplified engagement pathways, and governance structures that weight diverse input rather than merely collect it.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

The default format of international governance dialogues plenary statements, panel discussions, and negotiated communiqués is poorly suited to a technology that moves faster than diplomatic cycles. The AI Dialogue needs engagement formats designed for the problem, not inherited from prior conventions. Working prototypes over position papers. The most productive sessions should centre on concrete artifacts draft control libraries, interoperability mapping tools, compliance templates for SMEs that participants can react to, stress-test, and improve in real time. Structured critique of a working draft produces more actionable output than open-ended discussion of principles. Red team exercises. Dedicated sessions where participants are tasked with identifying failure modes in proposed governance mechanisms adversarial stress-testing rather than consensus-building would surface problems that polite multilateral dialogue tends to obscure. This format is standard in technical security contexts and should be standard here. Structured practitioner testimony. Not panels of experts speaking about implementation, but direct testimony from the people responsible for it: compliance officers at SMEs, engineers at public institutions, frontline workers affected by automated decisions. Thirty minutes of this in a plenary session would carry more information than most formal presentations. Rapid iteration cycles between sessions. The gap between Geneva 2026 and New York 2027 should not be dead time. Working groups should publish interim drafts, collect structured feedback through accessible digital channels, and present revised positions at the following session. This turns the two-year cycle into a genuine iterative process. Simulation exercises. Scenario-based exercises a cross-border AI incident, a governance failure in critical infrastructure, a rapid capability jump would force participants to stress-test their frameworks against realistic pressure rather than ideal conditions. The measure of a good engagement format is not how many stakeholders attended. It is whether the output is more useful because they did.

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

2

The most instructive examples of effective AI governance share a common characteristic: they treat compliance as an engineering problem, not only a legal one. The EU AI Act is the most significant binding framework currently in force. Its risk-based classification approach tiering obligations by potential harm rather than applying uniform requirements is the right architectural choice. Its weakness is implementation infrastructure. The framework tells organisations what to achieve; it provides limited guidance on how to demonstrate it continuously and verifiably. NIST AI RMF addresses this gap more directly. Its operationalisation of risk management across the AI lifecycle from design through deployment and monitoring provides a practical structure that legal frameworks alone do not. Its voluntary nature limits reach, but its technical quality makes it the most implementable reference available to practitioners today. ISO 42001 brings AI management systems into the established ISO certification ecosystem, giving organisations a familiar audit pathway. Its value is credibility and recognisability with procurement and board-level stakeholders who understand ISO certification but not AI-specific frameworks. The GS AI framework (Guaranteed Safe AI, arXiv:2405.06624) represents the frontier of thinking on verifiable safety guarantees moving governance from probabilistic risk assessment toward mathematically grounded assurance. This is where the field needs to go. vigilens.ai is an example of what governance looks like when these frameworks are encoded as machine-executable rules rather than static checklists. By integrating continuously with development pipelines like GitHub, Jira, MLflow it collects evidence automatically, maps controls to regulatory requirements in real time, and generates audit-ready documentation without manual effort. This approach demonstrates that the operationalisation gap is solvable. Governance tooling built this way makes compliance accessible to SMEs that cannot sustain dedicated compliance functions. The common thread across effective approaches is continuity. Governance that only activates at audit time does not govern.