Venturalítica
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
Three concrete outcomes would make the July Dialogue a success: **1. A commitment to an open standard for AI governance evidence exchange.** Today, compliance evidence is produced as static documents that cannot be verified across jurisdictions. Every country is building its own compliance language. The Dialogue should launch a process — building on the OECD's AI Incidents Monitor and G7 Reporting Framework — to develop a common, machine-readable format for AI governance evidence. Analogous to what XBRL achieved for financial reporting: not a new governance framework, but an interoperability layer that lets existing frameworks communicate. This would do more for cross-border governance coherence than any policy declaration. **2. A technical interoperability track where practitioners demonstrate working implementations.** The 18 March consultation showed strong consensus on principles — interoperability, evidence-based governance, dynamic compliance. What is missing is proof that these work in practice. The July Dialogue should include sessions where the technical community demonstrates cross-framework governance: showing that the same evidence base can satisfy requirements from multiple regulatory regimes simultaneously. **3. Recognition that governance must reach the engineering layer.** Only 14% of developers at SMEs are familiar with any AI governance framework (Pacific AI, 2025). 42% of companies abandoned AI initiatives due to compliance gaps. The people who build AI systems are structurally excluded from governance. Any outcome document should explicitly address the developer-governance disconnect and recommend that governance standards include technical implementation guides — not just policy text. Success means the Dialogue produces actionable infrastructure, not just another set of principles. We have enough principles. We need the technical plumbing that makes them implementable.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Open-source software, open data and open AI models
- Interoperability of governance approaches
- Safe, secure and trustworthy AI
- Transparency, accountability, and human oversight
Please briefly explain your selection.
10
**Interoperability** is the foundation. Every jurisdiction is developing AI governance independently - the EU AI Act, NIST AI RMF, China's regulations, national frameworks across the Global South. Without interoperability, organisations operating across borders face compounding compliance costs that only large corporations can absorb, while SMEs and developing-country innovators are locked out. The Dialogue's unique value is driving convergence - not on rules, but on how governance evidence is structured and exchanged. Machine-readable, open standards for compliance evidence would let any framework plug into a common infrastructure. **Safe and trustworthy AI** because governance without safety is performative. AI systems are dynamic - they drift, they are retrained, their deployment contexts shift. As IEEE's representative noted on 18 March, compliance cannot be a one-time checkpoint. We need continuous monitoring, automated compliance gates in development pipelines, and version-controlled governance artifacts that maintain audit trails throughout the system lifecycle. Safety must be engineered in, not bolted on. **Transparency and accountability** because evidence must be verifiable. The ICC called for "evidence of how systems are produced." Accenture noted that AI governance metrics lag far behind financial metrics in maturity. The Dialogue should push for governance evidence that is structured, cryptographically verifiable, and independently auditable - not narrative documents that cannot be systematically assessed. **Open-source and open data** because governance infrastructure should be a public good. If compliance tooling is proprietary, only well-funded organisations can participate in governance. Open-source reference implementations of compliance schemas, evidence pipelines, and cross-framework mappings would lower the barrier to governance participation globally - directly addressing the capacity-building mandate.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
3
**The developer-governance disconnect is the most critical cross-cutting issue missing from the listed themes.** Current governance frameworks are written by lawyers and policymakers for lawyers and policymakers. They do not translate into the technical vocabularies, tools, and workflows that AI engineers use daily. The result: 80% of firms report governance-critical information trapped in silos between engineering and compliance teams. Only 9% of small companies monitor production AI systems. Developers have no risk culture because governance was never part of their workflow. Compliance teams lack the technical literacy to extract evidence from engineering artifacts. This gap is universal - it exists in Europe, the Americas, and Asia regardless of regulatory maturity. It is also the single largest barrier to effective AI governance: if the people building AI systems do not understand or engage with governance, no amount of regulation will make those systems safe. The Dialogue should address this through three mechanisms: **1. Governance literacy as an engineering competency.** Any standards or frameworks emerging from this process should include technical implementation guides that map governance requirements to concrete engineering practices and evidence artifacts - not just policy text. **2. "Governance as code" - embedding compliance into development workflows.** Compliance evidence should be generated automatically from the same tools engineers already use (CI/CD pipelines, model registries, monitoring systems), not produced manually as a separate bureaucratic process. **3. Incentivising compliance through provable trustworthiness.** As proposed during the consultation, organisations that demonstrate governance compliance through verifiable technical means should gain tangible advantages - preferred procurement status, lower insurance premiums, access to trusted ecosystems. This shifts governance from a cost centre to a competitive asset, which is the only framing that will engage the private sector at scale. This is not captured by any single listed theme - it cuts across all of them.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
We operate in the European Union — the first jurisdiction to enact comprehensive AI legislation — and work primarily with organisations in regulated sectors: public administration, healthcare, financial services, and industrial deployers across Spain and the EU. **The challenge is not the absence of regulation — it is the absence of implementation capacity.** The EU AI Act's high-risk obligations become enforceable in August 2026. Yet in our direct work with the Spanish public sector — analysing over 2,000 AI-related public procurement tenders — we find that most public entities lack the technical maturity to classify their AI systems by risk level, let alone produce conformity documentation or implement continuous monitoring. Over half of organisations across Europe still lack a systematic inventory of their AI systems in production. For SMEs and startups — which represent 99% of EU businesses — the compliance burden is existential. Initial conformity costs for high-risk systems are estimated at €2–5 million for mid-sized organisations. Without affordable, automated governance tooling, compliance becomes a barrier to market entry that only large corporations can absorb. This directly contradicts the EU's own innovation objectives. **The opportunity is equally significant.** Europe's regulatory first-mover position means that EU-based organisations that build governance infrastructure now will set the global standard for how AI compliance works in practice. The interoperability gap is also an opportunity: if the Dialogue drives convergence on machine-readable evidence standards, European companies already investing in governance can export their compliance posture to other jurisdictions at marginal cost — turning regulatory burden into competitive advantage. The most concrete opportunity for this Dialogue: ensure that the governance infrastructure being built is open, interoperable, and accessible to SMEs — not locked behind enterprise consulting fees that reproduce the very inequalities governance is meant to address.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
## Q13: What role can the AI Dialogue play in advancing international cooperation? (Max 300 words) The Dialogue's unique value is that it is the only global forum where governments, technical community, private sector, and civil society sit together on AI governance. It should not duplicate what the OECD, ISO, or IEEE already do well. Instead, it should do what only a UN-convened process can: **build the connective tissue between existing initiatives.** **Convene, don't compete.** The OECD has AI Principles adopted by 47 jurisdictions, an Incidents Monitor, and a Policy Navigator covering 1,300+ initiatives. ISO publishes governance standards. IEEE develops technical specifications. National regulators enforce local rules. What is missing is a space where these actors align on how their outputs interoperate. The Dialogue should be that integration layer — not another standard-setting body. **Prioritise infrastructure over declarations.** International cooperation on AI governance will not advance through joint statements. It will advance through shared technical infrastructure: common evidence formats that regulators across jurisdictions can consume, shared incident reporting protocols, and open cross-framework mappings that show how requirements from different regimes relate to each other. The Dialogue should commission and maintain this infrastructure as a global public good. **Include the builders.** The 18 March consultation was rich in policy voices but thin on technical practitioners. The engineers, data scientists, and product teams who build AI systems must be part of this conversation — not as an afterthought, but as a core constituency. Cooperation that does not reach the engineering layer where AI systems are actually built will remain aspirational. **Set a governance floor.** Rather than seeking harmonisation — politically impossible in the near term — the Dialogue should identify minimum interoperable requirements that all jurisdictions can adopt: a shared risk taxonomy, a common incident reporting format, and baseline transparency obligations. A floor everyone stands on is more valuable than a ceiling no one can reach.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
**Standards and definitions:** - **OECD AI Principles** — adopted by 47 jurisdictions, the closest thing to a global governance baseline. The OECD's updated AI system definition is already embedded in the EU AI Act, the Council of Europe Framework Convention, and US federal guidance. The Dialogue should treat this as the reference vocabulary. - **ISO/IEC 42001** (AI management systems) and **ISO/IEC 23894** (AI risk management) — operational standards that translate principles into auditable organisational practices. Widely adopted in the EU and increasingly in Asia. - **IEEE 7000 series** — ethical AI system design standards with technical specificity that policy frameworks lack. **Operational infrastructure:** - **OECD AI Incidents Monitor** and the **G7 Hiroshima Code of Conduct Reporting Framework** — the embryo of cross-border incident reporting. The Dialogue should expand these from voluntary databases into interoperable operational infrastructure with machine-readable formats. - **OECD Policy Navigator** (1,300+ policy initiatives from 80+ jurisdictions) — the most comprehensive mapping of who is doing what. The Dialogue should build its programme around the gaps this mapping reveals. **Regulatory implementations:** - **EU AI Act** (enforceable August 2026) and its **General-Purpose AI Code of Practice** — the first binding regulation with operational compliance requirements. Lessons from EU implementation — both successes and failures — should directly inform the Dialogue's discussions on practicality. - **EU AI regulatory sandboxes** and **AESIA** (Spain's AI supervisory agency, first in the EU) — real-world laboratories for governance implementation. **The added value the Dialogue brings:** none of these initiatives talk to each other systematically. The OECD maps policies, ISO writes standards, IEEE specifies technical requirements, and national regulators enforce rules — but there is no integration layer that cross-walks requirements, identifies overlaps, and produces interoperable evidence formats. That is the gap only a UN-convened process can fill.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
**Structure the Dialogue by function, not by stakeholder type.** The 18 March consultation demonstrated the limitation of sequential 3-minute statements: 600+ speakers, most repeating the same principles. The July Dialogue should organise sessions around the governance lifecycle — design, deployment, monitoring, incident response — and seat policymakers, engineers, auditors, and civil society together in each session. The insight emerges from the collision of perspectives, not from each group speaking in turn. **Specific contributions by stakeholder type:** - **Governments:** Bring implementation data, not policy aspirations. Which governance requirements are working in practice? Which are unenforceable? What does compliance actually cost? The EU's experience with AI Act implementation (including failures) is more valuable to this Dialogue than another statement of principles. - **Private sector:** Open the black box. Contribute anonymised compliance data — how many AI systems are inventoried, how many classified by risk, what percentage have conformity documentation. The governance gap cannot be addressed if it is not measured. - **Technical community:** Build and demonstrate. Submit open-source reference implementations of interoperable governance tooling — evidence schemas, cross-framework mappings, automated compliance pipelines. Show, don't tell. - **Civil society and academia:** Stress-test. Subject proposed governance mechanisms to adversarial review. Identify where governance frameworks fail for marginalised communities, SMEs, or Global South contexts. **Format recommendation:** Dedicate at least one full session to **live technical demonstrations** — not presentations about technology, but working systems generating governance evidence in real time. This would be unprecedented in a UN governance forum and would signal that the Dialogue is serious about implementation, not just deliberation.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
**AI engineers and developers** are the most consequentially underrepresented group in global AI governance discussions. They build every system that governance frameworks aim to regulate, yet they are almost entirely absent from policy processes. The 18 March consultation had over 600 registered speakers — the overwhelming majority were policy professionals, academics, NGO representatives, and government officials. The people who write the code, train the models, select the datasets, and configure the deployment parameters were barely present. This is not an accident. Governance forums are designed for policy professionals — the language, format, timing, and incentive structures all select for people whose job is to attend UN consultations. Developers attend conferences like NeurIPS, deploy code on GitHub, and communicate through technical documentation. These worlds do not intersect. **How to include them:** - **Meet developers where they are.** Publish governance consultations on platforms engineers use — GitHub, Hacker News, Stack Overflow, relevant subreddits. Issue calls for input in technical language, not diplomatic language. - **Accept technical contributions as formal input.** An open-source reference implementation of a governance evidence schema is a more substantive contribution than a 300-word position statement. The Dialogue should create mechanisms to receive and evaluate code, schemas, and technical specifications alongside written inputs. - **Recruit through engineering organisations.** Partner with communities like OWASP (security), MLOps Community (deployment), and open-source AI projects to bring practitioners into the process. **Other underrepresented groups:** SMEs deploying AI systems (as distinct from large enterprises that can afford governance teams), AI auditors and conformity assessment bodies (who will operationalise whatever this Dialogue produces), and public sector IT teams in developing countries who must implement governance with minimal resources.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
**1. Governance Interoperability Challenge.** Before the July Dialogue, issue an open challenge: given a reference AI system description, produce governance evidence that satisfies requirements from at least three different jurisdictional frameworks simultaneously. Publish submissions openly. Present the best solutions at the Dialogue. This would produce more actionable insight about interoperability than any panel discussion — and would give the technical community a concrete way to contribute. **2. Live "compliance sprint."** During the Dialogue, run a real-time session where a team takes a publicly described AI system and, in 90 minutes, generates governance documentation using open tools — risk classification, data governance evidence, performance metrics, human oversight protocol. Stream it. Let the audience see what governance implementation actually looks like in practice. This makes the abstract concrete and exposes where current tools and standards fall short. **3. Cross-framework mapping workshop.** Seat regulators from different jurisdictions at the same table with a technical facilitator. Give them a concrete AI use case. Map the governance requirements each jurisdiction would impose. Identify overlaps, conflicts, and gaps in real time. Publish the resulting cross-walk as a living document. This is what interoperability looks like as a working session rather than a talking point. **4. Written input platform with structured data.** Instead of only accepting free-text submissions, provide a structured input form where stakeholders can submit governance requirements, evidence schemas, or incident definitions in a machine-readable format. Aggregate these into a public dataset that the Scientific Panel and Co-Chairs can analyse systematically — not just read as individual documents. **What all these formats share:** they produce artifacts, not just minutes. Every session should generate something reusable — a mapping, a schema, a dataset, a reference implementation. The Dialogue should be measured by what it builds, not by what it says.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
1
**Policies that work in practice:** - **EU AI Act regulatory sandboxes** - Spain's AESIA, the first EU AI supervisory agency, ran a sandbox with 9 projects testing governance requirements against real AI systems. The insight: organisations consistently struggled with risk classification and evidence production, not with the principles themselves. This confirms that the implementation gap - not the policy gap - is the binding constraint. - **EU General-Purpose AI Code of Practice** - co-chaired by Matthias Samwald, Yoshua Bengio, and Marietje Schaake. Notable for bridging safety research and regulatory practice. Its emphasis on "provable trustworthiness" - where compliance becomes a verifiable, demonstrable property - is the most promising governance model currently under development. **Platforms that operationalise governance:** - **OECD AI Incidents Monitor** (oecd.ai/incidents) - standardised definitions + live database. The closest thing to cross-border incident infrastructure. Needs to evolve from a reporting database to an operational system with machine-readable formats. - **OECD Policy Navigator** (oecd.ai/dashboards) - 1,300+ initiatives from 80+ jurisdictions. Invaluable for identifying what exists. The next step: structured cross-walks showing where requirements overlap and diverge. - **CycloneDX AI BOM specification** - an open standard for AI software bills of materials, extending SBOM practices from cybersecurity to AI governance. Demonstrates that machine-readable governance evidence is technically feasible today. **Practices that bridge engineering and governance:** - **"Governance as code"** - embedding compliance checks directly into CI/CD development pipelines. Organisations practicing this report that compliance shifts from a quarterly audit exercise to a continuous, automated process - reducing cost and increasing reliability simultaneously. - **Model cards and data sheets** (originated at Google and Microsoft) - lightweight structured documentation that developers actually produce. Imperfect, but proof that governance artifacts can emerge from engineering workflows rather than being imposed externally. Common thread: every effective example automates evidence production rather than adding manual bureaucracy.