SkycrumbsSkycrumbs
AI News

AI Governance and International Cooperation in 2026: Who Makes the Rules?

September 3, 2026·9 min read
AI Governance and International Cooperation in 2026: Who Makes the Rules?

AI Governance and International Cooperation in 2026: Who Makes the Rules?

No technology develops in a political vacuum, and AI is no exception. In 2026, the question of who governs AI — what standards it must meet, who enforces compliance, how nations coordinate and where they compete — has moved from academic policy discussions to active geopolitical maneuvering.

The result is a rapidly evolving patchwork of governance frameworks, international working groups, bilateral agreements, and outright regulatory competition. Understanding where AI governance stands — and where it's heading — is essential context for anyone building, deploying, or investing in AI.

Why Governing AI Is Hard

AI governance faces several inherent challenges that make it genuinely harder than governing prior technologies:

Speed of development: AI capabilities are advancing faster than regulatory frameworks can adapt. Laws written for today's systems may not address tomorrow's capabilities — and may over-regulate systems that turn out to be benign.

Global supply chains and development: AI development is global. Training data comes from everywhere. Models are trained by companies in some jurisdictions and deployed in others. The supply chain for AI chips involves manufacturing in Taiwan, design in the U.S., and use globally. No single jurisdiction can govern AI unilaterally.

Defining "AI": The scope of AI governance depends on what counts as "AI." The EU AI Act uses a definition broad enough to cover rule-based systems alongside neural networks — a choice that has generated significant debate about overreach.

Balancing innovation and risk: Overly restrictive AI governance could drive development to less regulated jurisdictions without actually making AI safer — a race to the bottom problem. Too-permissive governance allows actual harms to materialize.

Enforcement across borders: Even well-designed regulations are only as effective as their enforcement. Enforcing EU standards on a non-EU company's AI systems requires extraterritorial reach that is difficult to exercise in practice.

The Three Major Governance Blocs

AI governance in 2026 is dominated by three distinct regulatory philosophies:

The European Union: Rules-Based, Risk-Tiered

The EU AI Act, now fully enforced for high-risk AI systems, represents the world's most comprehensive AI regulatory framework. Its risk-based structure — banning some uses, requiring compliance processes for high-risk applications, applying transparency requirements to lower-risk systems — has become a reference point for other jurisdictions.

The EU approach emphasizes fundamental rights, transparency, and human oversight. It has been criticized by some in the AI industry as potentially hampering innovation, and praised by civil society organizations as providing meaningful protection against AI harms.

The EU is complementing the AI Act with additional initiatives: the AI Liability Directive provides a civil law framework for AI-related damages, and the AI Office in Brussels is building capacity to regulate general-purpose AI models.

The United States: Sector-by-Sector, Executive-Driven

U.S. AI governance has been more fragmented than Europe's. The Biden-era Executive Order on AI (October 2023) established safety standards for frontier AI and created reporting requirements for developers of powerful AI systems, but executive orders lack the permanence of legislation.

Congress has struggled to pass comprehensive AI legislation, resulting in sectoral regulation: the FTC has addressed AI-enabled fraud and deceptive practices, the EEOC has issued guidance on AI in employment, the FDA has approved dozens of AI medical devices with its own regulatory framework, and financial regulators have addressed AI in their domains.

The practical effect is that U.S. AI governance is more permissive than the EU's for many applications, creating a genuine difference in what can be deployed. Some AI use cases permitted in the U.S. require compliance processes or are restricted in the EU.

The state-level patchwork adds complexity. California, Illinois, Colorado, and Texas have all passed AI-related legislation, creating compliance requirements that vary by jurisdiction within the U.S.

China: State-Directed, Application-Specific

China's approach to AI governance is the most state-centric. Multiple regulations govern specific AI applications: algorithmic recommendation systems, deepfakes and synthetic content, generative AI services. These regulations are not rights-based (there is no equivalent to the EU's fundamental rights framing) — they focus on ensuring AI systems support social stability and do not undermine Party governance.

China's approach includes requiring generative AI services operating in China to register with the Cyberspace Administration of China, implement content filters, and ensure outputs align with "core socialist values." Foreign AI services generally cannot operate in China without complying with these requirements.

China has simultaneously made AI development a national strategic priority, with state investment in AI research, chip development (to reduce dependence on U.S.-designed chips following export controls), and AI deployment in government services and infrastructure.

International Coordination Efforts

Despite divergent national approaches, several international coordination mechanisms have emerged:

AI Safety Institutes Network: Following the UK's Bletchley Park AI Safety Summit in 2023, a network of national AI Safety Institutes has formed. The UK, U.S., EU, Japan, South Korea, Singapore, and others have established or are establishing national AI safety institutes focused on evaluating frontier AI systems. The network shares evaluation methodologies and, increasingly, actual evaluation results — though the degree of information sharing remains limited by national security considerations.

OECD AI Principles: The OECD's AI Principles, endorsed by member countries, provide a high-level framework around transparency, accountability, and human-centric AI. These are non-binding but influential in shaping national regulatory thinking.

G7 and G20 AI processes: Both forums have ongoing AI working groups. The Hiroshima AI Process established in 2023 under Japan's G7 presidency produced the International Guiding Principles for Organizations Developing Advanced AI Systems and a voluntary code of conduct for AI developers — adopted by major AI companies.

UN Advisory Body: The UN Secretary-General's Advisory Body on AI published recommendations in 2024 calling for international AI governance institutions. Progress on implementing those recommendations has been slow, reflecting genuine disagreement among member states about the appropriate form of global AI governance.

The U.S.-China AI Competition Dimension

AI governance cannot be fully understood separately from U.S.-China geopolitical competition. AI is explicitly central to both countries' national security and economic competitiveness strategies.

U.S. export controls on advanced AI chips — specifically NVIDIA's highest-performance data center GPUs and the equipment used to manufacture them — represent a deliberate attempt to slow Chinese AI development relative to U.S. development. China's response has been an accelerated domestic chip development program, with SMIC and other Chinese manufacturers achieving meaningful progress, though still trailing TSMC.

This competition complicates international AI governance. Coordination on AI safety between the U.S. and China is politically difficult even when both governments acknowledge shared interests. The U.S.-China joint statement on AI risk, agreed at the Biden-Xi summit in 2023, committed both countries to discussing AI safety but has not produced substantive technical cooperation.

Frontier AI Safety: A Separate Thread

Distinct from regulatory frameworks for AI products is the question of governance around frontier AI development — the training of powerful general-purpose AI models that might pose systemic risks.

The AI Safety Institutes are the primary mechanism here: they work with major AI developers to evaluate frontier models before and after deployment, assessing whether systems exhibit concerning capabilities (deception, dangerous knowledge provision, autonomous goal-pursuing behavior). This is currently voluntary in most jurisdictions, though the EU AI Act's obligations for GPAI models with systemic risk are moving in a mandatory direction.

The frontier AI governance discourse also includes debates about:

  • Pre-training notification requirements: Should governments be notified when AI developers begin training models above certain scale thresholds?
  • Compute thresholds: Current frameworks often use training compute (FLOPs) as a proxy for capability — a pragmatic choice given that directly measuring capability is harder, but one that may become less accurate as training efficiency improves
  • International verification: Can international inspection regimes for AI development — analogous to nuclear non-proliferation inspections — be designed and implemented?

These questions remain largely unresolved in 2026. The international community is still building the shared vocabulary and institutions needed to address frontier AI risks cooperatively.

What This Means for Organizations

For organizations building or deploying AI, the governance landscape creates practical compliance obligations:

  • Operating in the EU requires EU AI Act compliance for applicable systems — a genuine legal obligation with enforcement teeth
  • U.S. operations face a mix of federal sector-specific requirements and state-level obligations that are actively evolving
  • Global operations require managing a complex compliance matrix that varies by jurisdiction and use case
  • Frontier AI developers must navigate increasingly detailed voluntary frameworks that may become mandatory

The organizations best positioned are those that have invested in AI governance infrastructure: processes for cataloging AI systems by risk, compliance teams with AI expertise, technical documentation practices, and engagement with regulatory bodies.

The patchwork of AI governance in 2026 is messy, but it is real. The compliance costs are real. And the trajectory is clear: AI governance is intensifying, not moderating.

Conclusion

AI governance in 2026 is a domain of genuine international tension and incomplete coordination. The EU has the most developed regulatory framework. The U.S. has sector-specific rules and a fragmented state-level landscape. China has application-specific regulations oriented toward state priorities. International coordination efforts exist but remain limited.

For organizations, the practical challenge is compliance with a shifting, multi-jurisdictional regulatory environment while continuing to develop and deploy AI at a pace that justifies the investment.

For policymakers, the challenge is designing governance that addresses real AI risks without ceding innovation advantage to less regulated jurisdictions — a genuinely difficult balance with no obvious right answer.

The fundamental question — who makes the rules for AI globally — remains unanswered in 2026. The answer will shape the trajectory of AI development and its societal impact for decades.

For coverage of a specific major AI governance development, see EU AI Act Compliance in 2026: What Businesses Must Know.

Comments

Loading comments...

Leave a comment