SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

ISO Policy Brief and AI Governance: Reflections on Standardization Infrastructure as a Socio-Technical System



1. Introduction

 Since this piece also serves as a sequel to the following article, I would appreciate it if you could read it as well. It is a quick read that takes about a minute.

 The ISO policy brief published in 2025, "ISO policy brief: Harnessing International Standards for responsible AI development and governance," is compact in length but extremely suggestive for predicting the future of AI governance.


 Discussions surrounding AI governance have changed significantly over the past few years. The former debate over whether or not AI should be regulated has subsided, and the focus has now shifted to concrete design discussions such as "what architecture should be used to build governance" and "which toolsets should be combined." As the EU AI Act, national AI strategies, and Japan's AI Act (Act on the Promotion of Research, Development, and Utilization of Artificial Intelligence-Related Technologies) emerge one after another, the ISO is presenting how to build the infrastructure for AI governance from the seemingly modest yet robust perspective of "international standards."

 In this article, I would like to use this policy brief as a starting point to share some thoughts on the fragmentation of AI governance and the role of standardization.


2. The Message of the ISO Policy Brief: AI Governance is Not a Technical Issue but a "Socio-Technical" One

 First, I would like to provide an overview of the brief. After organizing the opportunities and risks brought about by AI, the ISO emphasizes the need to grasp AI not merely as a technical product consisting of "data, computing resources, and algorithms," but as a "socio-technical system" that includes interactions with the institutions, markets, and norms that exist around it.

 While the positive aspects of AI include its potential for use in fields such as economic growth, healthcare, education, environmental conservation, and crisis response, a wide range of risks are listed, including bias, privacy infringement, lack of explainability, environmental impact, employment effects, and the digital divide. These are all problems that depend on the context of "what data it is trained on, what institutions it is combined with, and what power structures it is used within," rather than just glitches in the algorithms themselves.

 It is significant that the brief explicitly uses the term "socio-technical" here. AI is not a black box isolated from humans and organizations; it only gains meaning through its interactions with people, organizations, markets, and social norms. Therefore, one can read the message that AI governance is not just about reviewing source code or creating model cards, but refers to the design and monitoring of these entire interactions.

 This perspective strongly resonates with the background of compliance and ethics. Risks rarely arise from the technology itself, but rather from the "organizational activities" of how an organization designs and introduces AI throughout its lifecycle, and who supervises it and with what responsibility. The brief reaffirms that AI governance is not a technical add-on, but a strategic necessity.


3. Fragmentation of Global AI Governance and International Standards

 In the middle of the policy brief, the movements of AI governance at the international, regional, and national levels are carefully mapped.

 The UN General Assembly's Global Digital Compact (GDC) positions international cooperation and the role of standardization bodies in AI governance, while UNESCO presents a human-rights-centered framework through its Recommendation on the Ethics of AI. The OECD AI Principles, as an intergovernmental standard with over 47 participating countries, indicate the direction of risk-based and human-centric governance.

 On the other hand, looking at the regional level, initiatives with quite different characteristics are lined up, such as the EU AI Act, the ASEAN Guide on AI Governance and Ethics, and the African Union's AI Strategy. While the EU adopts a strict hard-law approach using classifications such as prohibited and high-risk, ASEAN adopts a soft-law-oriented approach that seeks to balance innovation and ethics. At the national level as well, institutional designs are diverse, such as the US NIST AI RMF, China's algorithm regulations, and Japan's AI Act.

(Reference)

 As a result, global AI governance, while sharing common terms at the conceptual level such as "human rights," "safety," and "trust," is becoming fragmented in terms of specific requirements and terminology. The policy brief frankly points out that this fragmentation increases the compliance burden on companies and leads to the risk of "regulatory arbitrage," where companies seek out regions with looser regulations.

In this context, ISO puts forward the role of "providing a common technical language and processes through international standards." While assuming different legal regulations for each country and region, it organizes the underlying risk management, data governance, and conformity assessment mechanisms as ISO/IEC standards. For multinational corporations, this can function as a "common foundation" for translating and integrating diverse rules into a single, cohesive framework.


4. The "Governance Blueprint" Drawn by ISO/IEC AI Standards

In the latter half of the policy brief, ISO/IEC AI-related standards are organized by domain. While it may look like a dry list of standard numbers, there is a clear design philosophy behind them.

4.1 Quality, Safety, and Robustness

ISO/IEC 23894 for AI risk management, ISO/IEC 27001 for information security, robustness evaluation for neural networks (ISO/IEC 24029 series), and bias measurement (ISO/IEC TR 24027) are cited. These are technical guidelines for engineers, but from a legal perspective, they can also serve as indicators defining the "Standard of Care" internationally expected regarding the quality and safety of AI systems. In the future, when product liability or negligence is contested, compliance with these standards is highly likely to become a yardstick for determining the presence or absence of "reasonable care."

(Reference)

4.2 Data Governance

The ISO/IEC 5259 series (data quality) and ISO/IEC 38505 series (data governance) translate the norms of "what must not be done" as defined by legal regulations like the GDPR into practical, operational levels of "what processes should be followed to ensure legal resilience." This connection between legal requirements and technical processes is the crux of future governance practice.

4.3 Governance, Ethics, and Transparency

ISO/IEC 42001 (AI management system) and ISO/IEC 42005 (AI system impact assessment) provide templates for translating corporate human rights due diligence and ethical considerations into processes of "who checks what and when," rather than mere abstract ideals. These standards are useful tools for converting ethical principles into effective internal procedures.

4.4 Environment and Sustainability

ISO/IEC TR 20226 and others provide a perspective that redefines AI not just as a digital service, but as a physical infrastructure that consumes vast amounts of computational resources. The fact that the measurement and disclosure of environmental impact are being internationally standardized is a trend that cannot be ignored from the perspective of ESG management.

4.5 Conformity Assessment and CASCO

What is particularly noteworthy is the mention of "conformity assessment," centered on CASCO (ISO Committee on Conformity Assessment). ISO/IEC 42006 (requirements for certification bodies) and similar standards aim for an ecosystem like an "AI version of ISO 9001" in AI governance. This is also consistent with the EU AI Act requiring conformity assessments for high-risk AI. Of course, it would be counterproductive if obtaining formal certification became the sole goal, but the significance of establishing a foundation for objective evaluation by third parties is substantial.


5. Reading Governance as a "Catalyst" Rather Than a "Constraint"

What the policy brief repeatedly emphasizes is the perspective that "governance is not a brake on innovation, but a catalyst for responsible innovation." By clearly defining expected values for acceptable risk, safety, quality, and transparency, development teams can make decisions with foresight regarding "how far they can go" and "what conditions must be met to bring a product to market."

It is in this context that conformity assessment is emphasized. By defining and visualizing expectations for risk and quality through standards, companies gain the trust of customers, investors, and regulators. This, in turn, leads to a competitive advantage in business. Japan's AI policy also advocates for "balancing innovation promotion with risk response," and how ISO/IEC standards are combined with domestic guidelines and industry self-regulation will likely determine its success or failure.


6. The "Translator" as an AI Governance Professional

What I found most interesting in this brief is the suggestion that "AI governance requires multidisciplinary capabilities." Effective governance demands a certain level of knowledge in fields such as technology, law, ethics, human rights, cybersecurity, and organizational behavior, as well as the ability to "translate" between them.

In reality, it is nearly impossible for one person to possess deep expertise in all of these areas. What is important is the presence of "personnel who can interpret the language of different experts and weave together a common risk language." They translate the model constraints described by engineers into risk indicators that management can understand, translate concerns raised by human rights NGOs into concrete design requirements, and map national laws and regulations to internal processes aligned with ISO standards.

In the world of compliance and risk management, these roles have already been fulfilled. It could be said that AI governance is essentially the same, with the subject matter merely expanding to include algorithms and data. The reason the policy brief calls for the participation of diverse stakeholders is likely because the insights of these diverse translators are essential for weaving socio-technical perspectives into standards.


7. Implications for Japanese Companies and Government

Finally, I would like to list some points at a general level on how Japanese companies and government agencies should read this policy brief.

First, standards such as ISO/IEC 42001 should not be trivialized as "tools for obtaining certification," but rather utilized as "templates" for designing internal AI governance architecture. It is important to view them as blueprints for integrating strategy, risk assessment, and human resource development into a single cycle.

Second, be conscious of the connection to domestic laws and guidelines. By superimposing abstract legal requirements onto the concrete processes and documentation requirements defined by ISO standards, an effective governance system can be built.

Third, maintain a perspective that encompasses the entire supply chain. It is not realistic for API users and others to implement all standards themselves. Companies should use standards to clarify their own governance boundaries by confirming through contracts and audits which standards cloud providers and model suppliers comply with and to what extent they assume responsibility.


8. Conclusion: From "Boring Backstage Work" to "Strategic Resource"

International standards tend to have an image of being "things for engineers and quality departments to read" or "boring documents filled with detailed definitions." However, if you read this brief in the context of AI governance, you can see that international standards are becoming more than just backstage work; they are taking on strategic significance as a global "common infrastructure."

Just as the UNESCO guidelines stated that "AI will not replace judges, but it will change how courts function," international standards will not replace AI governance itself, but they are quietly yet steadily changing the prerequisites for its design. Which countries bring which values to the table, and which standards become the "common language"? The accumulation of those choices will shape the future of the AI ecosystem in a few years.

(Reference)

As someone who deals with AI and law, standardization documents are no longer a domain to be "left to the technicians." As a front line where law, policy, and practice intersect, we are required to take a stance of actively reading, interpreting, criticizing, and engaging with them. The ISO policy brief can be said to be an excellent entry point for that.

◾️References

International Organization for Standardization (ISO). (2025). ISO policy brief: Harnessing International Standards for responsible AI development and governance.
ISO/IEC 23894:2023, Information technology – Artificial intelligence – Guidance on risk management.
ISO/IEC 42001:2023, Information technology – Artificial intelligence – Management system.
ISO/IEC TR 24368:2022, Information technology – Artificial intelligence – Overview of ethical and societal concerns.
ISO/IEC 12792:2025, Information technology – Artificial intelligence – Transparency taxonomy of AI systems.
ISO/IEC TR 20226:2025, Information technology – Artificial intelligence – Environmental sustainability aspects of AI systems.
African Union. (2024). Continental strategy on artificial intelligence.
Association of Southeast Asian Nations (ASEAN). (2024). ASEAN Guide on AI Governance and Ethics.
European Parliament and Council. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).
Organisation for Economic Co-operation and Development (OECD). (2024). Recommendation of the Council on Artificial Intelligence (OECD AI Principles).
United Nations General Assembly. (2024). United Nations Global Digital Compact: A shared vision for the digital future.
UNESCO. (2021). Recommendation on the Ethics of Artificial Intelligence.


(Magazine) "Random Thoughts on AI and Law"

*Please refer to the following for the table of contents


Note General Provisions Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content produced by the creator shall belong to the creator.

いいなと思ったら応援しよう!