Who Governs AI? A Map of the Actual Institutions
4 min read · updated August 3, 2026
“AI governance” names a crowded field in which summits, statutes, standards bodies, model licences and voluntary commitments are discussed in the same breath. They are not the same kind of thing, and one question separates them.
One question sorts the field
For any institution with a claim on this space, ask: if it concluded tomorrow that what you are building is unacceptable, what would happen next? A fine. A ban on placing the system on a market. Loss of a contract. A lawsuit. A published report. Nothing at all. Those answers are wildly different and most public confusion comes from treating a body that can levy a penalty and a body that can write a communiqué as equivalent players.
The map below is by mechanism, not by prominence. A standards committee almost nobody has heard of can end up binding more behaviour than a heavily covered international declaration, because the standard gets referenced in a procurement rule and the declaration does not.
Six kinds of authority
| Type of body | Description |
|---|---|
| statutory regulator | Created by legislation, with powers to investigate, order changes, and impose penalties. The only category that can compel directly. Which one applies is usually decided by sector and by territory, not by technology. |
| standards body | Publishes technical specifications with no force of their own. They become binding indirectly: a statute or a contract references the standard, or conformity with it creates a presumption of compliance. This is the quietest and most underrated route to obligation. |
| procurement | A government as a buyer, imposing conditions no statute imposes. Fast, because it needs no legislature, and limited, because it only reaches suppliers who want the contract. |
| courts | Decide disputes after the fact, on the law that already exists. They set no policy in advance but they allocate losses, and an allocation of losses changes behaviour more reliably than guidance does. |
| platform intermediaries | Cloud providers, model providers, app stores and payment networks, enforcing acceptable-use terms. Private, unappealable in any meaningful sense, and in practice the fastest-acting governor of AI deployments that exists. |
| voluntary commitments | Pledges, codes of practice, summit declarations. Their power is reputational and, occasionally, evidentiary — a public commitment can later be read as a representation in a consumer-protection or contract dispute. |
International bodies are deliberately absent from that table, and their absence is the point. Summits, intergovernmental declarations, multilateral principles and treaty processes shape the vocabulary everyone else uses, which is genuinely consequential over a decade, and none of them can compel a private party directly. They act on states, and states act through the six categories above. The route from an international principle to an obligation on you runs through domestic implementation, and it is worth tracing that route before treating a declaration as a rule.
Horizontal AI law meets the regulator you already had
Almost every deployment people worry about was already regulated before any AI statute existed, because it was regulated by activity. A credit scoring model sits under financial supervision and consumer credit law. A diagnostic tool sits under medical device rules. A hiring filter sits under employment and anti-discrimination law. Anything touching personal data sits under data protection law, which in several jurisdictions already contains provisions on automated decisions.
A horizontal AI statute adds a second axis: obligations that attach to the system itself, typically tiered by assessed risk, regardless of which sector it operates in. The structural consequence is overlap. The same deployment can owe a documentation duty to an AI regime, a lawful-basis duty to a data protection regime and a fairness duty to a sectoral regulator, enforced by three different authorities with three different procedures and, sometimes, three different definitions of the same word.
Whether that overlap is redundancy or defence in depth is a genuine disagreement. Industry submissions typically argue it produces duplicative compliance cost without additional protection; civil society submissions typically argue that sectoral regulators lack the technical capacity to catch model-level problems and that the horizontal layer is what makes the sectoral one enforceable. Both descriptions can be true of different deployments.
One further mechanism deserves naming because it explains why a rule in one jurisdiction changes products everywhere. When a market is large enough and compliance is not easy to segment technically, the cheapest option for a global supplier is often to build to the strictest applicable standard and ship that everywhere. Scholars of regulation call this a de facto extraterritorial effect, and it means the practical reach of a rule is not the same as its legal reach. It also cuts the other way: where segmentation is cheap — a feature switched off in one region, a model not offered there — the effect disappears and the rule ends up reducing local availability instead of raising global standards. Which of the two happens is an empirical question about the product, not a matter of how strong the law is.
Where authority thins out
- Across borders. Jurisdiction is usually claimed on the basis of placing something on a local market or having effects on local people. Claiming it is easy; enforcing it against a developer with no local establishment is not, which is why these regimes push obligations onto importers, distributors, local representatives and deployers — parties who are reachable.
- After weights are distributed. Obligations bind the entity that released a model. They do not follow a copy into the hands of someone who fine-tunes it, and there is no recall mechanism for a file that has already been downloaded.
- Over hardware. Who may buy accelerators is decided by export control authorities in a small number of countries, on national security law that predates all of this and answers to nobody in the AI policy world.
- Between capability and application. A general model is not a product with a use. Regimes therefore split obligations between the developer, who knows the model and not the use, and the deployer, who knows the use and not the model — and the seam between them is where accountability is most often lost.
Working out who governs your case
A procedure that works better than reading the news: name the activity rather than the technology — you are not “deploying AI”, you are declining insurance applications, or triaging patients, or ranking job candidates. Identify who bears the consequence, and where they are. Then ask which of the six categories has a lever over that activity in that place. In most cases the answer includes a regulator that has existed for decades and one platform whose acceptable-use policy can end the deployment on a weekday afternoon.
Two follow-up questions are worth asking once you have the list. Which of these bodies can act fastest? Almost always the platform, because its process is a terms enforcement decision rather than a legal one, and that is where continuity risk actually lives even though it receives the least policy attention. And which can act with the widest effect? Usually the standards route, because a specification referenced by a regulation binds every supplier in a sector at once without anyone bringing a case.
Whether the current allocation of authority is the right one is a value question, and a live one. This page is only about who currently holds which lever. None of it is legal advice, and the specific allocation in any jurisdiction changes; check the current text before relying on it.