Skip to content

Independent Researcher

Civil Society Asia and the Pacific

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

Success in July 2026 in Geneva cannot be judged on the basis of the quality of a communiqué. Success can only be gauged in terms of whether the Dialogue yields outputs that alter the course of AI-enabled violence in reality. First, a clear legal statement. The output text must contain an explicit recognition that AI-enabled attacks against civilian critical infrastructure i.e. hospitals, water supplies, energy grids, financial services are in violation of the existing international human rights laws to which the states are bound, especially as regards the right to life, health, and a decent standard of living under the ICCPR and the ICESCR. This is not a new claim either, it is merely one that has been left unnamed in the AI governance discourse thus far. Second, a tangible mandate with a deadline. The Dialogue itself must produce an official recommendation to the UN General Assembly for beginning the process of negotiating a legally binding instrument regulating AI-enabled attacks against civilian critical infrastructure by means of milestones linked to the New York session in May 2027. Thirdly, the establishment of an expert body. There is currently no permanent body with sufficient expertise and authority to conduct investigations into critical infrastructure incidents involving AI technology, produce reports, and create binding technical standards for AI technology. Suggesting the formation of such a body would be an enduring recommendation. These three recommendations i.e. legal endorsement, negotiating instructions, and an expert body can all be accomplished within the mandate of the Dialogue set out in Resolution A/RES/79/325. This is also the bare minimum requirement to prove that the Dialogue is effectively governing the technology space as it currently stands, not how it did five years ago.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Protection and promotion of human rights
  • Safe, secure and trustworthy AI
  • Transparency, accountability, and human oversight
  • AI capacity-building

Please briefly explain your selection.

9

These four principles, however, are not based on mere preferences; rather, they represent the four key pillars that compose one complex governance failure that is apparent through direct interactions with the threats presented by AI technologies. The first principle concerns human rights. As has been demonstrated throughout previous cases of AI technology governance, frameworks for AI governance that fail to rely on mandatory legal mechanisms tend to backpedal towards voluntary guidelines when pressured by politics. The repercussions for AI-assisted attacks against hospitals, public water supplies, and power grids will be, in the end, repercussions of human rights violations as defined under binding treaties. The governance approach should be based on the foundation provided by those treaties. The second principle deals with transparency, accountability, and human oversight. Governance fails in practical application due to insufficient human knowledge about the systems in question and the environment in which they operate. This latter point is especially crucial, because adversarial environments are deliberately designed by threat actors to make AI and any human oversight impossible. Moreover, without human factors considerations, the demand for oversight will remain an empty legal commitment. Safe, secure, and trusted AI is the key technical precondition to any other commitment. With regards to critical infrastructures, neither safety nor security can be presumed; instead, they should be proven via adversarial robustness testing, reporting requirements, and continuous tests against real-world threats. This is not something that voluntary measures have been able to deliver. The focus on AI capacity-building is made due to the fact that there is an inherent inequality that needs to be tackled when addressing the risk of AI-enabled infrastructure. The difference in capabilities between the countries with strong capacities and with lesser capacity is an issue of human rights rather than a context to be addressed in the future.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

5

Three notable topics exist which sit between those identified above and require their own recognition. Attack surface vulnerabilities in the cognitive and neuro-cognitive realm. None of the above topics adequately covers the subject of manipulation of humans through cyber-adapted disinformation via interfaces, fake sensory data, floods of alerts, and deceptive system visuals intended to cause operator mistakes in key scenarios. This is proven by investigations into attacks on industrial control systems, such as those occurring against the power grid management infrastructure of Ukraine in 2015 and 2016, where interference with interface systems was an integral part of the attack plan. This topic should not be considered as merely a sub-topic related to safe AI use in any form. The problem of attribution as a question of governance, not just technology. Attribution of AI-enabled cyberattacks is currently considered as a purely technological challenge in contemporary discourse. In reality, however, attribution is also a governance issue, as there is currently no multilateral entity with the capacity to investigate cyberattacks involving AI and publish its findings. Therefore, the deterrence model inherent to international security law is simply unable to apply here, as the lack of governance institutions capable of conducting investigations effectively nullifies any possibility of deterring cyberattacks. Improvements in forensic technologies will not produce results without the creation of an investigative body capable of utilizing them. Dual-use dilemma for AI security research. The methods which researchers can use to examine and bolster cybersecurity measures, adversarial machine learning, hacking tools using AI, red teaming can also be used offensively by state and non-state actors. Therefore, any regulatory framework for the field must include a solution to the dual-use dilemma, as there must be a way to prevent offensive capabilities from being developed while also allowing defensive capabilities to remain available to researchers.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

These shortcomings in the areas enumerated above have tangible effects on the domain of critical infrastructure protection. The lack of transparency results in operational blindness. The operators of critical infrastructure assets and the national governments who protect these assets must often make security decisions regarding artificial intelligence-based solutions for which the model's parameters, decision-making logic, and processes are inaccessible to their oversight. This is not an abstract problem but a concrete one, inasmuch as in cases when the artificial intelligence-based industrial control system operates abnormally during an incident of possible breach, the operator cannot distinguish between the malfunction of said control system, an attack involving data poisoning of the same, or a normal reaction to a legitimate threat. Voluntary measures for improving transparency will result only in voluntary outcomes. The lack of accountability makes deterrence impossible. There is a characteristic common to all recorded cases of attacks on critical infrastructure involving the use of artificial intelligence solutions, there has been no investigation by a competent international authority, no attribution via an international process, and no remediation for those affected. It is not that deterrence efforts have failed, but rather that there has never been deterrence in place. The impact of the capability divide is experienced unequally. Wealthy nations are putting in considerable effort into using AI in their defenses and establishing frameworks for AI governance within their nations. Poorer nations, however, are increasingly adopting AI technology in their critical infrastructure but lack the legal, technical, and response capacities to deal with the risks appropriately. Therefore, the rewards from AI-secured infrastructure benefit rich nations more than poorer nations, while the repercussions of AI-related attacks will mostly be felt by the latter.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

The Dialogue occupies a unique place in the landscape of international governance institutions since it is the only body established by the General Assembly for the purpose of facilitating a dialogue between Member States, technical experts, civil society, and the private sector on the governance of AI. Its unique place in the system of international institutions gives rise to three functions that no other existing institution can fulfil. Norm crystallization: The Dialogue can elevate norms that have emerged through the various mechanisms such as voluntary codes of conduct, national laws, and soft law instruments into more official norms with sufficient authority to ground binding commitments. The acknowledgment in the Dialogue's outcome document that an attack against civilian critical infrastructure using AI technologies triggers the responsibility of states under their international human rights obligations is an example of norm crystallization. Technical-normative translation: Because of its multistakeholder composition, the Dialogue alone has the ability to bridge the gap between the technical nature of AI-based threats and the normative vocabulary of international governance that other forums lack. Policy makers without an understanding of what adversarial machine learning can do to industrial control systems are incapable of designing appropriate governance. Technical experts without knowledge of how international law imposes responsibilities on states are incapable of designing enforcement measures. The Dialogue is the only existing forum that brings both groups together under a common mandate. Creation of mandate: The Dialogue's most tangible contribution would be the formulation of a new institutional framework: a binding legal regime, a universal technical standard, and an expert mechanism endowed with real operational authority. These will not be realized by the Dialogue itself – but they will have the political legitimacy and technical grounding to become feasible within a specific time frame.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

The value added by the Dialogue comes from its potential for providing legally binding and enduring institutions which are currently lacking in the existing efforts. The Dialogue should capitalize upon, and not repeat, the following. Norms on responsible state behavior in cyberspace created by the UN GGE process since 2004 and reaffirmed by consensus in 2015 specify concrete norms prohibiting attacks against critical infrastructure as well as prohibitions against harming the critical infrastructure of other states. The Dialogue should build on these norms by elaborating and strengthening them to address AI-enabled forms of attack which were not anticipated in the GGE process. Budapest Convention on Cybercrime (2001) and Second Additional Protocol (2022) on enhanced co-operation and disclosure of electronic evidence offer an existing multilateral legal framework for cooperation in addressing cross-border cyber incidents. The Dialogue should propose extending these mechanisms specifically to AI-enabled cyber attacks, and technical assistance be offered to countries which have not ratified the convention to align their national legislation with it. OECD Principles on Artificial Intelligence (2019) and UNESCO Recommendation on the Ethics of AI (2021) offer soft law frameworks concerning transparency and human rights implications of AI. The Dialogue will add value by establishing binding obligations of these principles within the scope of critical infrastructures, which so far has failed to be achieved through voluntary compliance alone. International Telecommunication Union's(ITU) standardisation work and ISO/IEC JTC 1/SC 42 Joint Technical Committee on AI standardisation represent an existing institutional mechanism for standard-setting process. The Dialogue would make more sense to engage them in setting mandatory technical standards for AI in critical infrastructures according to a specified timeline, than to establish parallel mechanisms. Sendai Framework for Disaster Risk Reduction(2015-2030) provides an excellent practical example of the approach that combines risk reduction obligation with capacity building in different capacities.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

The Dialogue's format has to be crafted to ensure governance decisions rather than merely discussions on how to govern. Following recommendations for its particularities can be offered as follows due to the peculiarities of AI governance in terms of critical infrastructure. Incorporate technical experts in the deliberations process formally: The Dialogue currently operates in such a manner that technical experts attend separate sessions when diplomats discuss things in plenary sessions, this does not allow effective translation from technical to normative matters which is necessary for AI governance. This problem might be solved by having a formal advisory panel of technical experts that would submit their findings in plenary sessions. Formalize different roles according to the contributions made: The governments are responsible for making legal agreements. Technical community supplies evidentiary base. Civil society brings accountability issues and human rights aspect into the discussion. Private sector delivers implementation information. Formal roles need to be distinguished according to contribution type. Require formal incorporation of written submissions: The submission process is laudably transparent. In order for it to have any governance value, however, written submissions must be formally incorporated in deliberations. Final reports should be required to respond substantively to recommendations made in the written submissions, creating accountability between the expertise and the politics. Create an intersessional technical working group: There is almost a year between the Geneva session in July 2026 and the New York session in May 2027 during which time the technology will evolve further and additional events will unfold. A permanent intersessional working group charged with tracking developments and producing technical annexes for the second session will ensure the Dialogue does not deliberate on a technology landscape that has significantly evolved since its previous session.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

A number of communities with pertinent experience are disproportionately underrepresented in existing global conversations. Critical infrastructure operators and engineers: Individuals who control power grids, water purification plants, and hospital information systems; and who experience problems with AI technologies and suspect instances of adversarial behavior in real-world settings are nearly completely excluded from international governance dialogues. Their expertise regarding the true nature of human supervision, where governance demands become technologically impossible, and the actual modes of failure for AI systems in their capacities as operators cannot be matched and have not been gathered. The Dialogue should create an advisory channel for operators from the energy, water, health care, and financial sectors from different regions. Technical communities from low- and middle-income countries: Existing conversations on global AI governance are dominated by organizations in North America, Europe, and East Asia. Meanwhile, the populations most vulnerable to risk due to AI-powered infrastructures live in other parts of the world. Inclusion must involve funding for participation, pre-existing translations of all technical documents, and intentional scheduling that takes into account connectivity issues. Indigenous and geographically isolated communities: Communities relying upon a sole water utility, energy source, or communication link experience severe impacts when such infrastructure is attacked using AI technologies. They are highly vulnerable to such attacks but are not present at all within governance conversations. Civil society organizations in the region with trusted standing among those communities should be funded for participation in the Dialogue. Occupational health and human factors professionals: Cognitive effects resulting from attacks on operators, which can be found in the literature of human factors concerning decision-making under high stress conditions, provide an evidence base relevant to governance conversations that the Dialogue has yet to consider. Human factors specialists working alongside infrastructure operators have observed data to contribute to governance guidelines.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

For the Dialogue, the problem is not simply informing participants about a situation, it is enabling the creation of understanding in the face of deeply divergent technical and political perspectives, bridging the chasm between diplomats who know how to speak in the tongue of treaties and engineers who know what an attack surface means. Gamification provides an appropriate, data-driven solution. Governance simulations through gamification: For the Dialogue, a specially designed governance simulation that takes the form of a turn-based game involving multiple roles is needed. Different teams of Dialogue participants will be assigned different roles, including those of national delegations, infrastructure operators, AI developers, civil society stakeholders, and threats. At each round of the game, participants would find themselves faced with decisions that reflect reality; for example, there has been an anomaly in an AI used in the water treatment plant, the attribution has been disputed, and one national delegation wants to invoke the principle of state responsibility, while another is disputing the criteria. Points are not the currency; consequences are. Competitive norm-drafting challenges: In preparation for the Geneva event, the Dialogue would conduct an open international competition asking technical experts, lawyers, and nongovernmental organizations to write either treaty language or model clauses related to a particular governance issue, such as establishing when a violation of state responsibility occurs with an attack using AI against civilian critical infrastructure. Entries are judged by a multidisciplinary panel. The best submissions are then presented as official papers at the session. In doing so, it accomplishes three things at once: it solicits technical rigor, it engages stakeholders who can't travel to Geneva, and it generates draft language written by real experts rather than negotiated compromise language. Both models assume that governance design is a learnable skill, which, in the case of the Dialogue's first convening, it is.

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

4

A number of established frameworks offer practical and provable lessons for the governance structure of the Dialogue. The European Union Artificial Intelligence Act of 2024 is the most advanced binding legal framework on AI in situations involving significant risk. The conformity assessment provisions of the AI Act for AI systems used in critical infrastructure, post-market surveillance obligations, and notification of serious incidents to national regulatory bodies offer a legislative template from which the Dialogue could learn in its efforts at internationalization, recognizing that its geographic reach is limited to the European Union and that many of its technical implementation standards are still under development. The Chemical Weapons Convention of 1993 and the implementing organization, the Organisation for the Prohibition of Chemical Weapons, provide the most illustrative precedent for technically sophisticated prohibition frameworks. The combination of national declarations, routine verification inspections, and challenge inspections conducted by the CWC show that the international community can manage dual-use technology via an expert agency with mandatory state reporting obligations. Singapore's Model AI Governance Framework, introduced in 2019 and revised in 2020, has provided a practical and sector-specific method to address transparency and accountability issues, which have been officially recognized by other nations' AI governance frameworks in Asia. The framework's focus on implementable guidance rather than general principles gives an indication of how technical annexes can be developed to achieve any international AI standards for critical infrastructure. The FIRST (Forum of Incident Response and Security Teams) network has shown that it is feasible to voluntarily share information about cybersecurity incidents across national and organizational boundaries without the need for a mandatory requirement. Its information-sharing protocol with proper confidentiality can form a basis for the international framework for incident reporting recommended by the Dialogue, rather than building a new framework from scratch.