ARTONexa
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
Success for the first Global Dialogue means producing governance commitments that are technically grounded, enforceable, and applicable beyond the regulatory environments of high-income member states. Three concrete outcomes would constitute success. First, agreement on a shared taxonomy of AI risk that distinguishes between event-level failures and trajectory-level failures. Current governance frameworks are built around detecting discrete violations, whereas empirical adversarial research demonstrates that the most dangerous AI agent failures accumulate across multiple interactions before any threshold is crossed. Governance frameworks that cannot see sequences cannot govern agentic systems; a shared taxonomy that recognizes this distinction would give member states a common foundation for designing oversight mechanisms that actually match the threat model. Second, a commitment to mandatory pre-deployment capability evaluation with third-party verification for frontier AI systems, covering a defined set of catastrophic capability thresholds. This is the last enforceable gate before dangerous capabilities reach deployment. Without it, all downstream governance operates on systems whose risk profile has not been independently verified. Third, explicit inclusion of low-regulatory-capacity contexts in the governance architecture. Most current frameworks assume enforcement infrastructure (data protection authorities, technical regulatory capacity, judicial AI literacy) that does not exist in large parts of Africa, Southeast Asia, and Latin America. Governance designed exclusively for high-capacity environments will fail the majority of the global population interacting with these systems. The Dialogue should produce binding commitments to capacity-building pathways that make governance implementable in these contexts, not just aspirationally applicable to them. A Dialogue that produces these three outcomes will have moved AI governance from a collection of national frameworks toward a coordinated international architecture. One that does not will have produced a communiqué.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Transparency, accountability, and human oversight
- Interoperability of governance approaches
- AI capacity-building
Please briefly explain your selection.
5
Safe, secure, and trustworthy AI is the foundation Empirical adversarial research on AI agents (including my own work measuring safety decay across multi-turn attack sequences) demonstrates that current deployed systems have structural blind spots. Per-request monitoring, the dominant oversight architecture, catches zero percent of multi-turn adversarial sequences. Governance frameworks need to be built on accurate models of how these systems actually fail, not on assumptions about single-interaction violations. Transparency, accountability, and human oversight follow directly In multi-agent architectures, safety decay compounds at handoff points between agents; we measured a 2.3x amplification factor. When harm occurs across a chain of individually acceptable actions, identifying the responsible human decision point becomes extremely difficult. Accountability frameworks need to be technically specific about what constitutes meaningful human oversight within an agentic sequence, rather than merely asserting that humans remain in the loop. Interoperability of governance approaches is urgent because AI systems do not respect jurisdictional boundaries. A model evaluated and deployed in one jurisdiction operates globally. Fragmented national frameworks create regulatory arbitrage opportunities that undermine every individual framework. The Dialogue needs to produce interoperability standards, not just parallel national regimes. AI capacity-building is non-negotiable Governance frameworks that cannot be implemented in low-regulatory-capacity environments are governance frameworks for a minority of the world. Nigeria, and the broader African context in which I operate, is deploying AI systems in financial services, healthcare, and infrastructure, with limited enforcement infrastructure. Capacity-building is not a secondary agenda item. It is a precondition for governance that actually protects people.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
2
Two issues are materially absent from the listed themes. The first is multi-agent and agentic AI governance. The thematic areas reflect a model of AI as a single system producing outputs in response to inputs. Deployed AI in 2026 looks nothing like this. Enterprise and government AI deployments chain multiple autonomous agents, each with tool access, each capable of taking real-world actions, each passing behavioral context to the next. The governance problem is not the behavior of any single agent, it is the emergent behavior of the chain. Safety decay that accumulates across a session does not reset at agent handoff points. It compounds. No current governance framework addresses this. The Dialogue should establish it as a named priority before deployment of multi-agent systems outpaces the standards designed to govern them. The second is the governance gap in low-regulatory-capacity contexts. This is distinct from capacity-building, capacity-building addresses the resources and skills needed to implement governance. The gap I am naming is architectural; current governance frameworks are designed with implicit assumptions about enforcement infrastructure, judicial capacity, and institutional maturity that simply do not hold in most of the world. When an AI system causes harm in a jurisdiction without a functioning data protection authority or AI-literate judiciary, the governance framework provides no remedy, the people most likely to be harmed by ungoverned AI are in exactly these contexts. The Dialogue should produce governance architecture that is designed from the ground up for low-regulatory-capacity environments, not frameworks that assume those environments will eventually catch up to the ones where the frameworks were written. Both issues require technical specificity to address, they cannot be resolved through political commitments alone. That is precisely why the Technical Community stakeholder track must have substantive influence on the Dialogue's outputs.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
I operate as an AI security researcher based in Lagos, Nigeria, conducting adversarial research on agentic AI systems and contributing to international standards through the OWASP AI Exchange. From this position, I observe governance gaps that are simultaneously technical and structural. In Nigeria and across sub-Saharan Africa, AI deployment is accelerating in sectors where failure has direct human consequences: financial services, healthcare triage, agricultural advisory, and identity verification for public services. These deployments are happening inside regulatory environments where enforcement infrastructure is thin, technical auditing capacity is limited, and AI-specific legal frameworks are either nascent or absent. The most significant challenge is that the governance frameworks being referenced by African institutions are frameworks designed elsewhere, for elsewhere. They assume data protection authorities with technical capacity, AI literacy in the judiciary, and private sector accountability mechanisms that function under regulatory pressure. Where those assumptions do not hold, the framework produces no remedy when harm occurs, and the person harmed has no recourse. This is not a theoretical risk; it is the current operating reality. The technical governance gap compounds this; my adversarial research demonstrates that current AI monitoring architectures have structural blind spots, specifically, that per-request monitoring catches zero percent of multi-turn adversarial sequences against AI agents. If deployed systems in high-income environments with strong governance are already operating with this blind spot, deployed systems in environments with weaker governance are operating with it and no backstop. The opportunity is that Africa is early enough in its AI governance development to build frameworks that account for these failure modes from the start, rather than inheriting frameworks designed for a different context and patching them later. The Global Dialogue is the right moment to ensure that the international architecture being established makes that possible, rather than defaulting to frameworks that will require the world to catch up to assumptions it does not share.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue occupies a position no existing mechanism holds: a UN-convened forum with the mandate to involve both governments and all relevant stakeholders, including the technical community, in producing governance architecture that applies across jurisdictions. The most important role it can play is closing the translation gap between technical safety research and enforceable international governance commitments. That gap is the primary failure mode in AI governance today. Technical researchers produce findings about how AI systems fail, and governance bodies produce frameworks about how AI systems should be overseen. The two communities rarely produce outputs that are directly legible to each other, and the result is governance frameworks that are technically underspecified and technical research that never reaches the standard-setting level where it would have a real impact. The Dialogue can close this gap by structuring its working process to require technical grounding for every governance commitment it produces. Not technical appendices added after political agreement, but a technical specification as a precondition for any binding recommendation. This means the technical community stakeholder track must have substantive influence on outputs and not just consultative presence. The second role is establishing a coordination mechanism that prevents regulatory arbitrage. AI systems deployed in one jurisdiction operate globally, and without a coordination layer, divergent national frameworks create gaps that can be exploited. The Dialogue is the only forum with the standing to establish that coordination layer across the full range of member states, including those without existing bilateral AI governance relationships. The third role is giving low-regulatory-capacity member states a legitimate seat in shaping the architecture they will be governed by rather than receiving frameworks designed without their input. Governance produced without that input will not fit the contexts it is meant to govern.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
Several existing initiatives have produced substantive technical and governance foundations that the Dialogue should build upon rather than duplicate. The OWASP AI Exchange has produced the most comprehensive open-source framework for AI security risk assessment, covering attack taxonomies, control specifications, and vulnerability scoring through the AI Vulnerability Scoring System. As a contributing author to the OWASP AI Exchange, I can attest that this work represents accumulated technical consensus from practitioners across jurisdictions, and the Dialogue should formally reference this framework as a technical foundation for its security-related governance commitments rather than commissioning parallel work. The NIST AI Risk Management Framework provides a structured approach to AI risk governance that has influenced national frameworks across multiple jurisdictions. Its Govern, Map, Measure, and Manage structure is directly applicable to international governance architecture and should inform how the Dialogue structures its own risk management recommendations. The EU AI Act represents the most developed binding regulatory framework currently in force. Its risk classification approach and mandatory requirement structure provide a template for how binding international commitments could be structured, while its limitations, particularly its assumptions about regulatory capacity, should inform what the Dialogue does differently. UNIDIR's ongoing work on AI governance at the intersection of security and international law is directly relevant to the Dialogue's mandate, and the Dialogue should formally connect with UNIDIR's research outputs rather than treating them as a parallel track. The added value the Dialogue brings that none of these initiatives provide is universal applicability. OWASP produces technical standards, NIST produces national guidance, and the EU AI Act applies within one jurisdiction. None of them has the mandate or standing to produce governance architecture that applies across the full range of member states, including those without existing technical governance capacity. That universality is what the Dialogue uniquely offers and must protect.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
The Dialogue will only produce governance architecture that is both technically credible and globally legitimate if its structure gives different stakeholder categories substantive influence rather than consultative presence. The distinction matters as consultative presence means stakeholders submit inputs and attend sessions, and the substantive influence means stakeholder technical findings can block or require revision of governance commitments that are not technically grounded. Governments bring enforcement authority and political legitimacy, but often lack the technical depth to evaluate whether governance commitments will hold against sophisticated adversaries. The private sector brings deployment experience and technical capability, but has structural incentives that do not always align with public interest governance. Civil societies bring the perspective of affected communities, academia brings research rigor, and the technical community brings the empirical foundation that tells you whether any of it actually works in practice. The structure should reflect these complementary roles. Technical community and academia stakeholders should participate in drafting working groups, not just review panels, so that technical specification happens before political negotiation rather than after. Civil society representatives from affected regions should have formal speaking rights in plenary sessions, not just written submission channels. Private sector participation should be structured to separate technical contribution from lobbying influence through clear conflict of interest disclosure requirements. On format, the Dialogue should avoid the standard pattern of government statements followed by stakeholder remarks at the margins. A more effective structure would organize sessions around specific governance questions where each stakeholder category contributes the dimension it is best positioned to address, and outputs are synthesized across categories before any commitment is finalized.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
The most systematically underrepresented voices in global AI governance are technical practitioners from the Global South, affected communities in low-regulatory-capacity environments, and independent researchers operating outside academic or institutional affiliation. Technical practitioners from Africa, Southeast Asia, and Latin America are building and deploying AI systems in contexts that high-income governance frameworks do not account for. Their operational experience with how AI systems fail in environments without regulatory backstops is not captured in any existing governance framework because they are not present in the rooms where those frameworks are written. The Dialogue should establish funded participation pathways specifically for technical practitioners from these regions with selection criteria that prioritize demonstrated technical contribution rather than institutional affiliation. Affected communities, meaning the people who will live with the consequences of ungoverned AI deployment in contexts with limited legal recourse, are almost absent from global governance discussions. Their inclusion requires more than the translation of existing participation formats; it requires governance processes that can receive and act on experiential evidence of harm, not just technical or legal submissions. Independent researchers present a structural participation problem; most global governance forums recognize governments, corporations, academic institutions, and civil society organizations as legitimate participants. Independent researchers who produce relevant technical work outside those categories have no clear participation pathway. The Dialogue should establish an individual technical expert category with a transparent selection process based on demonstrated research contribution. Specifically on the African context, the AU's work on AI governance through its continental AI strategy and the emerging regulatory work of national bodies like NITDA in Nigeria represent regional governance thinking that the Dialogue should actively incorporate rather than treat as implementation recipients of frameworks produced elsewhere.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
The formats that would most effectively foster meaningful engagement are those that require stakeholders to work on specific technical and governance problems together rather than present prepared positions to each other. The most valuable format would be structured adversarial review sessions where governance proposals are stress-tested by technical practitioners before being finalized. The format works as follows: a draft governance commitment is presented, a technical working group is given a defined period to identify the conditions under which it would fail or be circumvented, and the commitment cannot advance without addressing the identified failure modes. This mirrors the red-team review processes used in security research and produces governance outputs that have been tested against adversarial thinking rather than just negotiated between parties. The second format is cross-stakeholder working groups organized around specific governance gaps rather than thematic areas. Thematic areas are broad enough that discussions can remain abstract. Specific governance gaps, such as the absence of any framework for multi-agent AI system oversight or the lack of enforceable standards for pre-deployment capability evaluation, force concrete technical and policy responses. Mixing government, technical community, and civil society representatives in small working groups focused on a single gap produces more actionable outputs than large plenary sessions on broad themes. The third format is a live technical demonstration track running alongside the formal Dialogue sessions. Governance discussions about AI risks are more grounded when participants have directly observed the failure modes being discussed. A demonstration track where technical practitioners show how current systems fail under adversarial conditions would give government and civil society participants a common empirical reference point that written submissions cannot provide. All three formats share the same underlying principle: the Dialogue produces better governance when participants engage with evidence rather than position papers.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
4
The most effective AI governance practices share a common characteristic: they are technically grounded, produce verifiable outputs and are designed for the contexts where they will actually be enforced rather than the contexts where they were written. The OWASP AI Exchange represents the most mature open-source governance practice currently available to the global technical community. It provides a structured attack taxonomy, control specifications and the AI Vulnerability Scoring System for rating AI-specific vulnerabilities. As a contributing author I have observed how this framework gets adopted by practitioners across jurisdictions precisely because it is technically specific, openly accessible and not tied to any single regulatory regime. Governance frameworks that build on open technical standards like this one are more likely to achieve global adoption than those that require institutional access to implement. The UK AI Security Institute's approach to pre-deployment model evaluation represents an emerging good practice at the government level. Establishing an independent government body with the technical mandate to evaluate frontier AI systems before deployment, outside the lab conducting the evaluation, is the right structural principle even where the specific methodology is still developing. The independence of the evaluating body from the deploying organization is the critical design feature. From my own research practice, session-level trajectory monitoring for AI agent systems represents a technical governance approach that fills a gap current frameworks do not address. Per-request monitoring, which is the dominant deployed oversight architecture, catches zero percent of multi-turn adversarial sequences against AI agents. Session-level trajectory monitoring catches 73% of the same sequences. Governance frameworks that specify monitoring requirements without distinguishing between these two architectures are specifying oversight that does not match the threat model. Embedding this distinction into technical governance standards, as I have contributed to through the OWASP AI Exchange, is a concrete practice the Dialogue should reference and scale.