Summary of National AI Strategies / Random Thoughts on the Legal Complexity of Implementation as Shown in the World Bank Handbook
0 Introduction
Legal discussions surrounding AI tend to lean toward the binary opposition of whether or not to create regulations. It is natural for interest to be concentrated on the design of prohibited categories and obligations while referring to comprehensive regulations like the EU AI Act. On the other hand, what real-world governments and companies are facing is a problem one step prior to the regulatory text. That is the problem of implementation: 'In which areas, in what order, with what resource allocation, and who bears the responsibility for advancing AI?'
Regarding this implementation problem, the handbook for policymakers published by the World Bank Group in 2025, 'Devising a Strategic Approach to Artificial Intelligence: A Handbook for Policy Makers,' presents a set of tools that, while somewhat understated, are strangely poignant. Using this handbook as a guide, this paper reinterprets national AI strategies as 'administrative plans' and offers some random thoughts on where and how the law should mesh with them.
1 The Location of the Problem
A national AI strategy is neither a law nor an ordinance. In many cases, it is a 'plan,' a 'policy,' or a 'roadmap.' Therefore, it formally lacks legal binding force. However, it is premature to equate this 'lack of binding force' with a lack of legal significance. Administrative plans bundle internal administrative decision-making such as budgeting, procurement, human resource allocation, and the setting of evaluation indicators. Furthermore, they influence the formation of expectations for private investment, and as a result, intervene in market allocation. Since law is a technology of not only 'rules' but also 'authority allocation,' 'procedures,' and 'resource allocation,' national AI strategies are not outside the reach of the law, but rather are positioned in the area where the law is most likely to have an impact.
What is somewhat troublesome here is that AI strategies often embrace both ethics and growth. AI as a growth strategy requires long-term investment in industrial policy, research and development, startup support, and education policy. AI as an aspect of ethics and safety includes cross-cutting and highly immediate issues such as personal information protection, cybersecurity, discrimination, explainability, and auditing. When these two coexist in the same document, flashy visions tend to take precedence, and the division of responsibility for implementation easily becomes ambiguous. As a result, the strategy becomes a fine piece of writing, and in the field, 'which department does what and by when' is left hanging. Legally speaking, a plan that lacks a design for the attribution of responsibility is fragile as a governance document.
2 The Problem of Fragmentation and the Meaning of Strategy
The field of AI governance is fragmented. Data is drawn toward personal information protection legislation, cyber is discussed in a different context, cloud is linked to procurement and security, and generative AI is sucked into discussions of copyright and unfair competition. Regulatory authorities also discuss 'AI' in their respective siloed worlds: industry, healthcare, finance, education, administration, competition, and consumers. As a result, a strange situation occurs where, although everyone is supposed to be talking about AI risks, no one is pointing to the same risk.
The greatest cost of this fragmentation is that it becomes difficult to identify causal relationships. When an accident or scandal occurs, it is impossible to break down whether the cause was a model defect, bias in training data, flaws in operational procedures, deficiencies in procurement specifications, or a gap in the supervisory system. Since it cannot be broken down, corrective measures tend to swing between doing everything or doing nothing. Neither is sustainable.
What is interesting about the World Bank handbook is that it attempts to solve this fragmentation not by unifying regulations, but by managing the process of the plan. That is, it presents the necessary components as a roadmap for how a nation should approach AI, breaks them down into seven modules, deploys tools such as diagnostic questions and templates, and extracts lessons from the analysis of over 30 national AI strategies. It treats strategy formulation not as a work to be completed in one go, but as an iteratively updated process. It is precisely this design of the process that the law excels at.
3 The Framework of the World Bank Handbook
The handbook presents several 'building blocks' as a common language for thinking about national AI strategies. At the center is the vision of driving sustainable and inclusive economic development through the development, deployment, and use of responsible AI. On top of that, the side using AI and specific use cases are placed. And as a premise to support them, foundations and enablers are placed.
Emphasized as foundations are connectivity, computing resources, and data as context. Without electricity and broadband, data centers and computing resources, and data that reflects local needs and values, AI will not 'work.' As enablers, governance and policy, capabilities and skills, and the innovation ecosystem are cited. What is important here is that AI is grasped not as software, but as a stack that includes everything from infrastructure to human resources and systems. Even if you only uphold ethical principles, if electricity is unstable, AI will stop, and if there is no framework for data sharing, administrative use will not progress. Conversely, even if you only develop computing resources, if there is no mechanism for supervision or relief, trust will collapse. This obvious fact is often forgotten in policy documents.
The handbook also suggests that the pillars of the strategy can be organized as the 'four Cs': Connectivity, Computing, Context, and Capabilities. In a situation where discussions about AI tend to be drawn toward model performance, the message is to first inspect the foundation of electricity, communications, computing resources, data, and skills. Before using AI, inspect the infrastructure that AI depends on. This reversal of order is critically important in practice.
4 The Seven Modules
The handbook divides strategy formulation into seven modules. First, set up the structure. Define the government organization that will be the responsible entity and form a task force. Second, map the current situation. Inspect existing policies, stakeholders, and the status of foundations and enablers. Third, set the direction. Verbalize the mission, vision, and objectives. Fourth, set the focus. Choose priority areas and use cases. Fifth, design the action. Establish pillars and incorporate specific measures. Sixth, prepare for implementation. Institutionalize the implementation structure and prepare an outcome framework, division of responsibilities, and communication plan. Seventh, adopt, launch, and adjust. Monitor progress and update the strategy as necessary.
What is noteworthy is that supervision and updating are explicitly incorporated here. A strategy can become obsolete the moment it is announced. This is not because technology is fast. It is because the data, computing resources, international rules, and industrial structures that are the premises of the policy move. Therefore, the strategy must also move. While the World Bank assumes a period of about 8 to 10 months for strategy formulation, it states that the modules can also be used individually. This is a realistic attitude of starting from the necessary parts without making the plan gargantuan.
This module design, while being a national AI strategy, is strangely isomorphic to the design of corporate AI governance. First, establish a responsibility system, take stock of the current situation, set objectives and priorities, drop measures into a schedule, monitor implementation, and update. In the end, whether it is a nation or a company, AI is an organizational problem. The fact that there is significant room for law to be involved in organizational design also stems from this point.
5 The Legal Problem of Who Has Jurisdiction
When formulating a national AI strategy, the first point of contention is often not the content, but the jurisdiction. Which ministry or agency becomes the responsible entity is not merely a matter of internal administrative dynamics. That choice dictates the framing of whether the strategy will lean toward growth or rights protection, and further, whether it will become an industrial policy or a public service reform. The World Bank handbook provides examples of how various countries have assigned responsibility and even presents a task force model because this initial misstep can derail all subsequent processes.
Here, questions inherent to law lie hidden. Specifically, these involve the clarification of authority allocation, relationships with other agencies, and the form of accountability. When an AI strategy ends with the creation of a task force, it may result in the dilution of responsibility rather than its creation. The strength of an iterative process can simultaneously be its weakness as an eternal warm-up exercise. That is precisely why it is necessary to fix the designation of the responsible entity, the deadlines, and the methods for evaluating outcomes from the start.
6 Points where law intervenes
There are three points where law intervenes in the process.
First is the design of legitimacy. As long as a strategy remains an internal administrative plan, external control is difficult to exert. However, an AI strategy changes the allocation of social resources. That is why the transparency of the formulation process, the participation of stakeholders, and the location of accountability are important. It is not merely out of kindness that the World Bank provides diagnostic questions, templates, guides for stakeholder engagement, and toolkits for communication planning. It is because establishing procedures increases the durability of the plan.
Second is the connection between data and responsibility. Data as the 'context' for AI is directly linked to personal information protection and data utilization. Here, it is not enough for the law to simply draw lines between prohibition and permission. It is necessary to design a range of motion for the administration to share data, collaborate with the private sector, and promote research and development. At the same time, the question arises of how to set safeguards for AI, data, and cyber security. While the OECD AI Principles and the UNESCO Recommendation on the Ethics of AI provide a common axis that countries can refer to, effectiveness cannot be achieved unless they are connected to domestic authority allocation and redress systems.
Third is the auditability of implementation. A common failure in corporate AI governance is the reversal phenomenon where people feel more secure as the number of documents increases. The state falls into the same trap. It is necessary to create an outcome framework, clarify who does what and by when, disclose progress, and explain the reasons for any revisions. This series of processes is legally close to the issue of administrative self-binding and the duty to explain. Just as the NIST AI Risk Management Framework attempts to integrate 'trustworthiness' into the processes of design, operation, and evaluation, national strategies must also be constructed as auditable processes. Hard law like the EU AI Act has strong binding power in certain areas, but it does not directly replace national prioritization or investment allocation. Regulation calls for strategy, and strategy selects regulation. This reciprocal movement is necessary.
7 Conclusion
The value of the World Bank handbook does not lie in discussing 'what an AI strategy is' through grand philosophy. Rather, it lies in breaking down the state's activities surrounding AI into processes, responsibilities, and updates, and providing the components needed to get to work. AI governance is not about ethical declarations or a single regulation, but a series of mundane implementations. And it is precisely those mundane implementations that are the domain where law is inherently skilled.
For legal scholars, the research challenge becomes positioning the national AI strategy as an administrative plan and determining what principles of control should be embedded within it. For corporate AI personnel, it serves as a clue to reading what the state considers a prerequisite and where it intends to invest resources. For the general reader, it serves as an opportunity to reaffirm the stark truth that AI is, after all, a matter of electricity, data, talent, and institutions. AI is not magic. That is precisely why it seems there is a role for planning and law.
Reference Materials
World Bank Group, 'Devising a Strategic Approach to Artificial Intelligence: A Handbook for Policy Makers' (2025)
https://documents1.worldbank.org/curated/en/099060525125542871/pdf/P506884-a1130fff-9c6f-4a78-8216-191b979d44b9.pdf (Last accessed January 26, 2026)
OECD, 'Recommendation of the Council on Artificial Intelligence' (OECD/LEGAL/0449)
https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 (Last accessed January 26, 2026)
UNESCO, 'Recommendation on the Ethics of Artificial Intelligence'
https://unesdoc.unesco.org/ark:/48223/pf0000380455 (Last accessed January 26, 2026)
NIST, 'AI Risk Management Framework'
https://www.nist.gov/itl/ai-risk-management-framework (Last accessed January 26, 2026)
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (Last accessed January 26, 2026)
(Magazine) 'AI and Law - Reflections'
*Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content created by the creator belongs to the creator.
