Global AI governance moves into implementation
Global AI governance is shifting from broad principles to operational compliance, with organizations expected to navigate a layered system of norms, binding laws, voluntary frameworks, standards and internal controls. UNESCO, the UN, the OECD, the G7, the EU AI Act, the Council of Europe AI Framework Convention, NIST AI RMF and ISO/IEC 42001 each serve different roles, from setting legitimacy and common language to creating enforceable obligations and auditable management systems.
The EU AI Act remains the central hard-law reference point for companies connected to the EU market. Its risk categories range from prohibited systems to high-risk, limited-risk and minimal-risk uses, with extraterritorial reach when AI outputs are used in the EU. Penalties can reach 7% of global turnover, while high-risk obligations were postponed to 2027/2028 and transparency rules under Art. 50 remain scheduled for August 2, 2026.
Organizations are advised to combine hard-law compliance with voluntary frameworks and market-driven certification. NIST AI RMF offers an internal governance cycle built around Govern, Map, Measure and Manage, with a GenAI Profile added in July 2024. ISO/IEC 42001 provides a certifiable AI management system using a Plan-Do-Check-Act cycle and Annex A containing 38 controls, supporting trust with clients, boards and regulators.