From the Era of Global AI Governance Principles to the Era of Capability: Random Thoughts Based on the UNDP/ACSH Report
0 Introduction
The generative AI boom since 2023 has forcibly shifted the discussion of AI governance from "what should be considered good" to "how to make it work." Principles remain important, but they are merely a compass, not the engine or rudder of a ship. Now that AI has entered society as an always-on infrastructure, the focus of governance has shifted not only to the consistency of documented norms, but also to whether the chain of operation, monitoring, correction, and explanation functions, and whether there is the capability to keep it running.
The report "Global Approaches to AI Governance: Policy, Legal, and Regulatory Perspectives" (hereinafter "this report"), published by the United Nations Development Programme (UNDP) and the Astana Civil Service Hub (ACSH), is an excellent resource that captures this turning point (Note 1). While this report organizes verbalized frameworks such as policy, law, regulation, and ethics, it also concretizes through country-specific cases (Canada, South Korea, UK, Kazakhstan, Philippines, etc.) that governance cannot be established by these alone (Note 1). Using the scope of this report as material, this paper offers some random thoughts centered on three points: the inevitability of fragmentation, the difficulty of identifying causality and the redesign of accountability, and governance as implementation, i.e., capacity building.
1 Location of the Problem
There is no doubt that AI governance is a legal issue. In particular, the prevention of rights violations, the correction of discrimination, the assurance of accountability, the allocation of supervisory authority, and the development of remedies are typical tasks of the law. On the other hand, AI is not an object that is finished once introduced. Its behavior can change due to training data, model updates, usage context, and the replacement of supply chains. Therefore, static norms (guidelines, regulations, contract clauses) alone cannot reach the control of dynamic risks.
What is interesting about this report is that it places strong emphasis not only on legal regulations and strategy, but also on capacity, such as the institutionalization of impact assessments, transparency mechanisms in the public sector, investment in computing resources and data infrastructure, and the expertise of civil servants and regulators (Note 1). The capacity referred to here is not merely personnel training. It is the ability of an organization to implement a series of procedures to identify, classify, operate, stop in the event of an accident, explain, and improve AI. The obvious fact that governance is not a collection of documents but a bundle of executed procedures is blatantly effective in the case of AI.
2 The Problem of Fragmentation and the Identification of Causality
2-1 Proliferation of International Frameworks and Interoperability
The international framework for AI governance is no longer a single line. Since 2019, the OECD Council Recommendation on Artificial Intelligence (the so-called OECD AI Principles) has become a common language widely referenced in the formulation of principles by various countries (Note 2). UNESCO has also adopted the "Recommendation on the Ethics of Artificial Intelligence" as an international standard for AI ethics, providing countries with tools for policy formation (Note 3). In addition, the EU has enacted risk-based, legally binding AI regulation (AI Act), presenting a system that has a strong disciplinary effect even outside its borders (Note 4). In Southeast Asia, ASEAN has published a guide, presenting a framework that is conscious of interoperability within the region (Note 5).
The problem is that this proliferation cannot be dismissed as evil. Given that each country's legal culture, administrative capacity, industrial structure, and security premises differ, a single world-government-like framework is not realistic. This report also points out that while common ground is being formed internationally, the design of regulations is rooted in the context of each country (Note 1). In other words, fragmentation is inevitable. Therefore, the next point of contention is not how to eliminate fragmentation, but how to create a form that does not collapse while remaining fragmented.
At this time, the field of business and administration bears a double burden. Externally, they are required to provide explanations that meet the requirements of multiple principles, regulations, and standards. Internally, on the other hand, it is necessary to monitor the behavior of AI that is updated daily and to crush the buds of accidents. The two are not the same. External explanation is the language of justification, and internal operation is the language of control. If these are confused, fine policy documents will remain, and control in the field will become hollow.
2-2 Difficulty in Identifying Causality and Moving Toward Procedural Responsibility
When damage or disadvantage caused by an AI system occurs, traditional jurisprudence constructs responsibility based on causality and imputability (negligence, etc.). However, in AI, black-box nature, data bias, decision-making chains within organizations, and supply chains such as external vendors and foundation models are intertwined, making it difficult to draw a linear causal relationship. As a result, if one is overly obsessed with identifying a single cause, relief will spin its wheels, or arbitrariness will enter to fill the lack of technical understanding.
What becomes important here is the design of procedural responsibility (process responsibility) to supplement result responsibility. The EU AI Act is typical, but a series of obligations such as risk management, technical documentation, logs, transparency, and human oversight are institutional techniques of governance that do not presuppose the complete elucidation of causality (Note 4). The NIST AI Risk Management Framework (AI RMF), while not legally binding, is also designed as a practical framework for identifying, measuring, managing, and implementing governance for risks (Note 6). The more difficult it is to identify causality, the more what was done (logs), what was seen (monitoring), and who could stop it (authority design) become the core of accountability.
The country-specific cases in this report point in the same direction. For example, in Canada, an Algorithmic Impact Assessment has been institutionalized for automated decision-making in the public sector, and risks and mitigation measures are checked in a questionnaire format (Note 7). In the UK, the Algorithmic Transparency Recording Standard (ATRS) has been developed to ensure transparency in the use of algorithms in administration (Note 8). What is being questioned here is not just whether the AI made the right decision, but whether the organization was operating in a way that could justify the decision.
3 Governance as Implementation
The scope of this report lies in the fact that while it organizes policy, law, and regulation, it repeatedly discusses infrastructure, procurement, human resources, and public-private partnerships as the foundation that supports them (Note 1). This point is an effective counter to arguments that tend to confine AI governance to regulatory design theory.
First, the public sector is a huge user and at the same time a huge purchaser. Public procurement can be a quiet regulation that pushes standards into the market. If transparency, auditability, log retention, and evaluation procedures are embedded in procurement requirements, governance will effectively spread. This is why this report emphasizes impact assessment and transparency mechanisms in the public sector (Note 1).
Second, compute and data infrastructure are becoming prerequisites for governance. The case of South Korea shows that, in parallel with the development of comprehensive AI legislation, securing computing resources such as GPUs is positioned as a national strategy (Note 1). There is an implication here that goes beyond mere industrial policy. For regulations to be effective, evaluation, verification, and auditing are necessary, and for that, computing resources and human resources are indispensable. Countries that lack computing resources are likely to not only import AI but also import discipline. It is the modern era where the issue of sovereignty falls into the story of GPUs and data centers, rather than abstract ideals.
Third, it is important to have a template for implementation. Management system standards like ISO/IEC 42001 provide a framework for structuring AI from planning to operation as a management process (Note 9). Even in areas where regulations do not delve into details, if an organization has established templates, the cost of accountability decreases and the speed of incident response increases. Conversely, organizations without such templates will repeat the same mistakes.
4 Practical Application
Based on the above, the practice of AI governance is not something that ends with the submission of a checklist, but rather the work of creating a feedback loop. Specifically, the connection between AI asset inventory (where and what is running), risk classification (what is dangerous), impact assessment and approval (who gives the go-ahead), operational monitoring and logging (what is being watched), intervention and shutdown authority (who stops it), and incident response and learning (how to fix it) is the key. These elements are scattered across the EU AI Act (Note 4), the NIST AI RMF (Note 6), and Canada's AIA (Note 7), but in essence, they constitute the minimum circuit for running governance.
Under fragmented international frameworks, what companies need is not to memorize the clause-by-clause interpretation of each regulation. It is to build a backbone of internal controls that will not collapse even when external requirements change, and to map those external requirements onto it. Principles can change, and laws are updated. However, organizations with a functioning circuit can withstand updates. Organizations without a circuit will simply increase the number of new PDFs each time, amplifying confusion on the front lines.
5 Conclusion
What this report demonstrates is the straightforward fact that AI governance is a matter of capability, not just norms (Note 1). Fragmentation is inevitable. Identifying causal relationships is difficult. Therefore, governance shifts from mere consistency of philosophy to the implementation of procedures. In this context, law is important but not omnipotent. Ultimately, what protects society is the mechanism by which an organization can supervise itself and the capability to keep that mechanism running.
AI governance can be called a practical subject of future administrative law and corporate legal affairs. It seems that the question is not whether you can read the articles, but whether you can design a circuit that actually works.
6 Global AI Governance
Reference Materials
(Note 1) ACSH, Global Approaches to AI Governance: Policy, Legal, and Regulatory Perspectives, Astana: United Nations Development Programme, 2025
https://www.undp.org/kazakhstan/publications/global-approaches-ai-governance-policy-legal-and-regulatory-perspectives
(Note 2) OECD, Recommendation of the Council on Artificial Intelligence, 2019
https://legalinstruments.oecd.org/en/instruments/oecd-legal-0449
(Note 3) UNESCO, Recommendation on the Ethics of Artificial Intelligence, 2021
https://unesdoc.unesco.org/ark:/48223/pf0000380455
(Note 4) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
(Note 5) ASEAN, ASEAN Guide on AI Governance and Ethics, 2024
https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf
(Note 6) NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023
https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
(Note 7) Government of Canada, Algorithmic Impact Assessment
https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html
(Note 8) UK Department for Science, Innovation & Technology, Algorithmic Transparency Recording Standard: Guidance for public sector bodies, 2025
https://www.gov.uk/government/publications/guidance-for-organisations-using-the-algorithmic-transparency-recording-standard/algorithmic-transparency-recording-standard-guidance-for-public-sector-bodies
(Note 9) ISO, ISO/IEC 42001:2023 - Information technology — Artificial intelligence — Management system
https://www.iso.org/standard/42001
(Magazine) "AI and Law - Reflections"
*Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content created by the creator belongs to the creator.
