Venturalitica
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
This response supersedes an earlier submission by the same author — please consider only this version. A successful first Global Dialogue should deliver three measurable outcomes. First, explicit recognition that the principal obstacle to interoperable AI governance is not political disagreement — the EU AI Act, ISO/IEC 42001, the NIST AI RMF, the Singapore Model Framework, Japan's Social Principles, and Korea's AI Safety Institute already converge substantively across their core governance dimensions — but the absence of technical infrastructure to translate between them. Second, inclusion in the Independent International Scientific Panel's first annual work programme of an explicit evaluation of standardised, machine-readable formats for AI governance evidence — an AI-specific extension of, or equivalent to, OSCAL. This would mirror what XBRL achieved for cross-jurisdictional financial reporting: technical infrastructure that makes mutual recognition operational without requiring prior political agreement. Third, an unambiguous distinction between assessment (diagnosing compliance posture) and assurance (continuously proving that governance measures are implemented), with a commitment to develop assurance infrastructure as a public good rather than as a competitive advantage of well-resourced providers. Pairing the Panel's scientific evaluation with a dedicated implementing counterpart — the UN Office for Digital and Emerging Technologies and the AI Governance for Humanity Lab it hosts, with its explicit interoperability mandate — would avoid the common failure mode in which recommendations are published without an implementing vehicle. A full technical rationale with reference architectures and working implementations is provided in the companion paper available through our website.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Interoperability of governance approaches
- Transparency, accountability, and human oversight
- AI capacity-building
- Safe, secure and trustworthy AI
Please briefly explain your selection.
6
These four priorities are interdependent and converge on a single operational question: how to make governance machinery - not just principles - portable across jurisdictions. (1) Interoperability of governance approaches is the most under-addressed dimension. Frameworks already converge conceptually; what diverges is format, taxonomy, and verification mechanism. Without a common technical language for expressing governance evidence, cross-jurisdictional recognition remains aspirational. OSCAL provides a proven precedent from cybersecurity that the AI community has not yet adapted. (2) Transparency, accountability and human oversight are the dimensions where the distinction between assessment and assurance matters most. Narrative audit reports resist automated verification; continuous, structured evidence does not. Human oversight must be treated as an architectural primitive - runtime-enforced, with deadline fallback to the safe action - rather than as a procedural declaration. (3) Capacity-building is the equity dimension of interoperability. If machine-readable governance evidence becomes the de facto standard for mutual recognition, jurisdictions and smaller organisations lacking technical infrastructure to generate such evidence risk exclusion from global AI markets. Open-source reference implementations, multilateral training programmes, and tiered implementation pathways are necessary so that evidence-based governance functions as an equaliser rather than as a gatekeeper. (4) Safe, secure, trustworthy AI is the umbrella outcome, but verifying it at scale is impossible without the infrastructure the other three priorities enable. Point-in-time audits do not capture governance posture in systems that evolve continuously through retraining, data drift, and model updates. Treating these as a coherent programme - rather than as parallel workstreams - is what would give the first Dialogue session operational leverage beyond communiqué-level agreements.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
4
Three cross-cutting issues deserve explicit attention beyond the themes above. First, agentic AI. Runtime governance of tool use, autonomous planning, and agent-to-agent interactions is an active gap in harmonised standards development. Current AI Act and ISO 42001 obligations are written around individual AI systems; multi-agent ecosystems introduce population-level risks (collusion, cascading failure, emergent coordination) that individual-system governance does not capture. International coordination is uniquely positioned to address this architectural gap. Second, measurement validity. Standardising evidence formats without standardising the underlying measurement methodologies locks in today's methodological limitations. Existing AI benchmarks were not designed to measure the systemic risks that regulators care about, and are vulnerable to contamination, static-evaluation artefacts, and autonomy-blindness. Formatting evidence in OSCAL does not make it valid - it makes the invalidity portable. A research agenda on regulatory-grade measurement methodologies for AI-Act-relevant risks should be paired with any format-standardisation work. Third, the ecosystem of evidence consumers. Notified bodies, market surveillance authorities, internal audit functions, and - for transparency obligations extending beyond Article 50 - the public each have divergent tooling, disclosure constraints, and technical capacity. Machine-readable evidence formats developed without parallel investment in conformity-assessment tooling risk producing artifacts that no consumer can verify at scale. Evidence-format governance and evidence-access governance are distinct policy decisions that the Dialogue should keep separate, alongside the intellectual-property tensions that have already complicated enforcement of explainability provisions under existing instruments.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
Operating as a European AI governance infrastructure company, we observe the following in Spain and the broader EU. Governance gaps: organisations subject to multiple overlapping instruments — the AI Act (product conformity), ISO/IEC 42001 (management system), the NIST AI RMF (voluntary reference), the Cyber Resilience Act, GDPR, and sector-specific regimes (Medical Device Regulation, financial services) — face compounding compliance costs because evidence generated for one instrument cannot be reused across the others. For smaller providers, the marginal cost of each additional framework becomes a market-entry barrier and, in practice, a filter that favours incumbents. Structural concentration: computational capacity, foundation-model providers, and technical governance expertise are distributed highly unevenly across regions. In such conditions, a handful of private actors risks defining de facto what global AI governance looks like — by shaping tooling, benchmarks, and implementation patterns faster than policy can catch up. Opportunities: machine-readable governance evidence — insofar as it reduces the marginal cost of cross-jurisdictional recognition — is one of the few interoperability instruments that functions as an equaliser rather than as a gatekeeper. In the European context, active standardisation work under Commission Standardisation Request M/613 (CEN-CENELEC JTC 21, including prEN 18286 on conformity assessment) and ISO/IEC 27090 on AI cybersecurity offers concrete vehicles, provided that evidence-format decisions are coordinated across these tracks rather than developed in parallel. Current practice in our sector — point-in-time audits, self-assessment checklists, disconnected maturity models — produces snapshots that do not survive the continuous retraining and deployment cycles of modern AI systems. This is a format and workflow problem, not only a compliance problem, and the Dialogue can catalyse its resolution.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The Dialogue can catalyse international cooperation on AI governance in three concrete ways that sidestep the need for prior political consensus. First, by framing governance interoperability as a technical-infrastructure question rather than as a framework-negotiation question. The four major instruments — EU AI Act, ISO/IEC 42001, NIST AI RMF, Singapore Model Framework — already converge across their core governance dimensions. What diverges is format and verification. A shared technical language for governance evidence (along the lines of what XBRL enabled between IFRS and GAAP) makes partial mutual recognition operational without requiring the frameworks themselves to converge politically. Second, by commissioning the Independent International Scientific Panel on AI — now constituted and holding its inaugural sessions — to evaluate machine-readable formats for governance evidence exchange, including the adaptation of proven precedents from adjacent domains (OSCAL for controls and assessment evidence; CycloneDX and SPDX for AI system provenance and component transparency). Scientific evaluation is a precondition for technical adoption that political processes cannot substitute. Third, by pairing scientific evaluation with a dedicated UN institutional vehicle for operational experimentation. The recently established AI Governance for Humanity Lab under the UN Office for Digital and Emerging Technologies, with its explicit mandate on governance interoperability and first outputs scheduled to coincide with the Dialogue, is the natural counterpart. Decoupling the Panel's scientific evaluation from an implementing vehicle is a common failure mode of international standard-setting — one that this Dialogue is uniquely positioned to avoid. The convening power of the Dialogue lies precisely in connecting political framing, scientific evaluation, and institutional implementation within a single multilateral process.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The Dialogue should avoid de novo development and build on proven precedents across three domains. Cybersecurity evidence: OSCAL (NIST) provides a layered, machine-readable architecture — catalogs, profiles, components, assessment plans, and results — that FedRAMP has adopted for cloud authorisation at scale. AI governance is structurally analogous to pre-OSCAL cybersecurity: overlapping frameworks with substantial conceptual convergence, organisations subject to multiple regimes simultaneously. An AI-specific extension requires defining control families (fairness, explainability, human oversight, provenance), metric schemas, and reference implementations — a two-to-three-year catalog-authoring programme, for which the Scientific Panel is the natural convenor. Financial reporting: XBRL shows that cross-jurisdictional interoperability can be built incrementally. It did not resolve the political differences between IFRS and GAAP; it provided the technical substrate that made partial mutual recognition practical. All EU-listed companies have published financial reports in Inline XBRL since 2021. Software supply chain transparency: CycloneDX (OWASP / Ecma ECMA-424) and SPDX 3.0 (ISO/IEC 5962:2021) provide mature formats for software bills of materials, with dedicated AI and Dataset profiles covering model lineage, training data provenance, and fairness metrics. Ongoing standardisation: Any evidence format must coordinate with CEN-CENELEC JTC 21 (Commission Standardisation Request M/613, including prEN 18286 on conformity assessment, public enquiry closed January 2026), ISO/IEC JTC 1/SC 42 (extending the ISO 42001 family), and ISO/IEC 27090 on AI cybersecurity — for which no published mapping to EU AI Act Article 15 yet exists. Published mappings between these work items, and a convening of the relevant technical committees alongside the Scientific Panel, should be a named deliverable of the Dialogue's technical programme rather than a parallel workstream.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Three recommendations on format and structure. First, reserve dedicated space in the Dialogue's work programme for a standing technical-infrastructure stream alongside the governance-principle stream. Future iterations should treat assurance infrastructure — the technical layer that generates, transmits, and verifies governance evidence — as a first-class agenda item. Evidence-format questions are not secondary implementation details; they determine which governance principles can be operationalised and which remain aspirational. Second, convene narrowly-scoped technical working groups with clear deliverables and short timelines, modelled on ITU-T study groups. These should operate between Dialogue sessions and report back with concrete artifacts — specifications, reference implementations, mapping documents — rather than position papers. A pattern that has worked in cybersecurity (OSCAL's NIST-led development with FedRAMP as early adopter) combines a scientific convenor, an implementation vehicle, and an early-adopter ecosystem willing to validate outputs at scale. Third, institutionalise coordination with ongoing standardisation processes (CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ISO/IEC JTC 1/SC 27) and with emerging UN institutional capacity — notably the AI Governance for Humanity Lab under the UN Office for Digital and Emerging Technologies. Outputs of the Dialogue should plug into existing tracks rather than create parallel ones; the latter is the dominant failure mode in international standard-setting. The Dialogue's distinctive convening power — bringing governments, standards bodies, scientific experts, and civil society into the same venue — is what makes it the right place to close the gap between governance principles agreed in one forum and technical standards developed in another.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Three categories of voices are currently underrepresented in global AI governance debates and should be engaged structurally, not tokenistically. Developing-country regulators and practitioners. If machine-readable governance evidence becomes the international standard for mutual recognition, jurisdictions without the technical infrastructure to generate such evidence risk exclusion from global AI markets. Meaningful inclusion requires: open-source reference implementations of governance pipelines deployable without licensing costs; multilateral training programmes for national AI regulators on evidence-based governance tools; tiered implementation pathways that allow progressive adoption, beginning with structured self-assessment and advancing to continuous evidence generation as institutional capacity grows. This must be a design constraint from the outset, not a post-hoc capacity-building addendum. Technical implementers from smaller organisations. Most AI governance discourse is shaped by large providers, major regulators, and well-resourced consultancies. The experience of startups, SMEs, and public-sector AI teams — who bear the marginal cost of each additional framework disproportionately — is underrepresented. Their operational perspective is essential to ensure that evidence formats reduce compliance friction rather than concentrating it among incumbents. Conformity-assessment professionals. Notified bodies, market surveillance authorities, internal auditors, and — for transparency obligations extending beyond AI Act Article 50 — the public each have divergent tooling, disclosure constraints, and technical capacity. Machine-readable formats developed without parallel investment in conformity-assessment tooling risk producing artifacts that no consumer can verify at scale. Evidence-consumer perspectives should be represented alongside evidence-producer perspectives. Inclusion must be architectural: standing seats in technical working groups, not speaking slots at plenary events. The governance of the standard itself must be as inclusive as the outcomes it aims to produce.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
Three formats would meaningfully raise engagement quality. Technical sprints alongside plenary sessions. Modelled on IETF hackathons, these would bring specification authors, tool implementers, and domain experts into the same room for 48 hours to produce concrete artifacts — draft mappings between frameworks, reference implementations of evidence formats, or conformance test suites. The deliverables become inputs to subsequent Dialogue sessions rather than one-off exhibitions. This pattern has sustained open-standards communities (IETF, W3C, OASIS) for decades. Continuous public commenting on technical outputs. Between annual Dialogue sessions, draft specifications, mapping documents, and reference implementations should be published for open public comment with structured response handling, following the model used by NIST for OSCAL development and by CEN-CENELEC JTC 21 for prEN 18286 public enquiries. This transforms participation from a synchronous one-week event into a continuous multilateral process and materially expands the pool of contributors. Implementation challenges and reference-deployment programmes. Invite smaller organisations, developing-country regulators, and public-sector AI teams to deploy reference implementations of governance pipelines against real workloads and report their operational experience. Pair each deployment with a working-group mentor from the Dialogue ecosystem. Both the specifications and the participants gain from the exposure. Evidence-based governance is credible only insofar as it works at scale outside the organisations that wrote it. Two cross-cutting principles: outputs over declarations (every format should produce a concrete deliverable, not a communiqué), and standing participation over one-off consultation (the same voices should be present across multiple sessions, so that expertise compounds rather than resetting annually).
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
2
We describe an operational multi-framework governance pipeline that is implemented and currently operating, documented in a companion paper submitted to IEEE Computer. Three concrete patterns illustrate that interoperable governance is not theoretical but operational today. Policy-as-Code (OSCAL-structured policies): regulatory requirements are encoded as machine-readable policy files using OSCAL's catalog and profile models. A single policy file maps simultaneously to multiple framework clauses - a data-quality control maps to EU AI Act Article 10, ISO 42001 Annex B.7, and NIST AI RMF Map 2.1-2.3. When a regulation is updated, the policy file is amended; downstream evidence generation adapts automatically. This draws on the Compliance-as-Code movement and the OECD's Rules-as-Code framework, with Open Policy Agent providing the architectural foundation. Continuous evidence generation: governance evidence is produced as a byproduct of normal development and deployment workflows, integrated into CI/CD pipelines rather than triggered by audit schedules. Each pipeline run produces structured artifacts (risk assessments, fairness metrics, data governance documentation, technical specifications) linked to specific model versions via content-addressed hashes. This represents a shift from audit-time governance to development-time governance, analogous to DevSecOps. Fail-closed governance with human oversight: for high-risk AI, a runtime governance proxy enforces governance checks at inference time. No output reaches end users without passing verification; decisions requiring human review escalate to reviewers with deadline enforcement - if no decision is made within the timeframe, the system defaults to the safe action, generating a full audit trail. Validated in a regulated healthcare deployment under ISO 42001 and the Medical Device Regulation. The pattern generalises to emerging agentic AI systems, where runtime governance is an active standards gap. Full technical documentation and architecture: https://venturalitica.ai