Watchdogs, diplomats, industry — and you
Lesson 5 of 5 in Who’s Who in AI Governance: Actors, Roles, and Responsibilities.
Regulators and standards bodies did not put AI governance on the agenda. Civil society did. ProPublica’s 2016 COMPAS investigation — showing a widely used recidivism score produced starkly different error rates by race — created the template: journalists and researchers measure what companies will not publish, and regulation follows the headline. Joy Buolamwini and Timnit Gebru’s Gender Shades study did the same for facial recognition; the campaign against it produced the first municipal bans (San Francisco, 2019).
The watchdog layer includes investigative journalists, academic researchers, advocacy organisations (AlgorithmWatch, Access Now, EFF and hundreds more), affected communities organising for a seat at the table — and, increasingly, whistleblowers. The law is starting to protect them specifically: EU AI Act workers can report violations under the EU whistleblowing directive, and California’s SB 53 (effective January 2026) protects employees of frontier-model developers who disclose catastrophic-risk concerns. Governance runs on information, and these are the actors who move information the market wants suppressed.
Above the states sits the diplomatic layer — no binding powers over companies, but enormous agenda-setting power over governments. The OECD wrote the 2019 AI Principles (updated 2024) that 47+ jurisdictions adopted and the EU AI Act’s definition borrows from; the Global Partnership on AI (GPAI) merged into the OECD in 2024. UNESCO’s 2021 Recommendation on the Ethics of AI was adopted by 193 states. The UN passed its first General Assembly resolution on AI in March 2024 and in August 2025 created an Independent International Scientific Panel on AI and a Global Dialogue on AI Governance — an IPCC-shaped answer for AI. The Council of Europe produced the first binding international AI treaty (the Framework Convention, opened for signature September 2024), and the G7’s Hiroshima Process delivered the first international code of conduct for advanced AI developers (October 2023).
OECD — the definitions house
Intergovernmental, 38 members, consensus-driven. Its 2019 AI Principles were the first intergovernmental AI standard; the 2023 revised definition of an AI system became the shared reference the EU AI Act, and many national laws, align to. Runs the OECD.AI Policy Observatory and its incidents monitor (AIM). Absorbed GPAI in 2024. Power: none formally; in practice, it writes the words everyone else legislates with.
UNESCO — the widest tent
Its 2021 Recommendation on the Ethics of AI is the broadest instrument by membership: 193 states, including countries with no domestic AI law. Soft law with implementation tooling (readiness assessments, ethical impact assessments). Power: legitimacy and reach, especially in the Global South — where most of the world’s AI-affected population lives.
UN — the scientific panel era
March 2024: first General Assembly resolution on AI (US-led, consensus). September 2024: Global Digital Compact. August 2025: resolution 79/325 established the Independent International Scientific Panel on AI and the Global Dialogue on AI Governance, whose first meeting ran in Geneva in July 2026. The model is deliberate: do for AI risk what the IPCC did for climate — one shared evidence base under a UN flag.
Council of Europe — the binding treaty
The Framework Convention on AI, Human Rights, Democracy and the Rule of Law (opened for signature 5 September 2024) is the first legally binding international AI treaty, open to non-European states — the US, UK and Israel were among early signatories. Caveat: signature is not ratification, and as of this writing the convention had not yet entered into force — check current status before citing it as operative law.
G7 / G20 — the leaders’ channel
The G7’s Hiroshima AI Process (2023) produced international guiding principles and a Code of Conduct for organisations developing advanced AI — the first leader-level instrument aimed directly at frontier developers rather than states. The G20 endorsed the OECD principles back in 2019, spreading them beyond the OECD club.
Finally, the industry governs itself — partly sincerely, partly pre-emptively. The instruments: usage policies and terms of service; model cards and system cards documenting capabilities and limits; responsible scaling policies / frontier AI safety frameworks in which labs pre-commit to capability thresholds and the safeguards each threshold triggers; voluntary commitments brokered by governments (the White House commitments of July 2023; the Seoul Frontier AI Safety Commitments of May 2024, where sixteen companies promised published safety frameworks); and industry bodies like the Frontier Model Forum and Partnership on AI.
Take self-governance seriously and skeptically at once. Seriously: labs’ safety frameworks contain the most detailed frontier-risk thinking publicly available, and voluntary commitments created evaluation practices law later borrowed. Skeptically: the commitments are unenforceable, self-graded, and revisable when inconvenient — the history of disbanded ethics boards (Google’s ATEAC lasted nine days in 2019) is the cautionary tale. The professional stance: self-governance is evidence of intent, never a substitute for external accountability.
Interactive sorting exercise: Sort each actor by the kind of power it wields over AI systems.
One last tool ties the whole module together: RACI thinking. For any governance task, ask who is Responsible (does the work), Accountable (owns the outcome — exactly one actor), Consulted, and Informed. Run it across the value chain and the finger-pointing problem dissolves into a table:
| Task | Provider (vendor) | Deployer (bank) | Third-party auditor | Regulator |
|---|---|---|---|---|
Pre-market conformity assessment | A / R | C — supplies use-case context | R — where notified-body review applies | I — via registration |
Fundamental-rights impact assessment | C — provides documentation | A / R (AI Act Art 27) | C | I — on request |
Human oversight in daily operation | C — designs oversight affordances | A / R — assigns competent staff | I | I |
Post-market monitoring & serious-incident reporting | A / R — monitoring plan, incident reports | R — must report incidents to provider & authority | I | I / A for follow-up |
Telling a rejected applicant an AI was involved | C — supplies explanation material | A / R — faces the applicant | I | I |
And where do you fit? Every actor in this module hires for the same emerging profession. Inside companies: responsible-AI leads, AI compliance managers, model-risk specialists. At regulators and safety institutes: policy officers and technical evaluators. In the assurance market: algorithmic auditors. The reference credential is the IAPP’s AIGP (Artificial Intelligence Governance Professional) — this academy’s curriculum maps to its body of knowledge, and the capstone domain drills its exam. The role taxonomies you just learned are not trivia: they are the org chart of your future career.
Tool: Global Governance Atlas — Explore the Governance Atlas: every regulator, safety institute, and standards body on a living world map.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.