ResearchFlagship Brief #1November 202518 min read
Download the full whitepaper

Responsible AI Trust

Global AI governance alignment map

Navigating AI regulation, standards, and what’s coming next.

Mike WoodLehar GuptaPatrick Sullivan

Foreword from the founder

At Responsible AI Trust, our purpose is simple yet vital: to strengthen global confidence in intelligent systems.

Across industries and borders, AI is redefining how decisions are made, risks are managed, and accountability is shared. With this transformation comes a collective responsibility to ensure that technology remains aligned with human values, transparency, and fairness.

Each brief we publish represents collaborative work from researchers, advisors, and practitioners who believe that trust must be earned through clarity, governance, and evidence. Together, we translate complex regulation into actionable insight, helping leaders navigate uncertainty with structure and foresight.

Responsible AI is not a trend. It is the foundation of sustainable innovation. As systems grow more capable, our frameworks for oversight must grow equally intelligent, adaptive, and globally connected.

Thank you for being part of this effort to turn principles into practice, and ideas into accountability.

Lehar GuptaFounder & CEO, Responsible AI TrustLehar@ResponsibleAITrust.com

About this brief

Global AI governance alignment map

This is Responsible AI Trust’s flagship map of how regulations, standards, and voluntary codes align and diverge, from the EU AI Act to ISO/IEC 42001 and the NIST AI Risk Management Framework. It identifies the principles that are starting to make global interoperability possible.

Purpose and motivation
AI governance has moved from aspiration to implementation. The brief translates fragmented rules into a framework leaders can act on.

Audience. Executives, policymakers, compliance officers, and investors who have to align innovation with governance, strategy, and assurance.

Methodology. Primary and secondary research across more than 30 binding laws, voluntary principles, and technical standards. Comparative matrices and expert review were synthesised into one alignment model.

Authors. Mike Wood, Research Associate. Lehar Gupta, co-author and Research Director. Reviewed by Patrick Sullivan, VP of Strategy and Innovation, A-LIGN.

Version. Public Release 1.0, November 2025. Flagship Series: Responsible AI Trust Brief #1.

Leader’s dashboard

The world is converging on three anchors, and still diverging on three others.

Risk management
The organising principle across the EU AI Act, ISO 23894, and NIST
Transparency
Disclosure through registries, system cards, and provenance
Security-by-design
The passport for interoperability, from NIS2 to the Cyber Resilience Act
Now, 2025–2030
  • Implement AI Bills of Materials and model evaluation frameworks.
  • Align ISO/IEC 42001 with NIS2 and the EU AI Act.
  • Treat security-by-design as a baseline, not an option.
Next, 2030–2040
  • Prepare for an International AI Safety Accord and compute thresholds.
  • Adopt universal provenance layers and AI ESG metrics.
  • Link AI governance to trade, procurement, and ESG reporting.

Governance has shifted from principles to proof. Risk management, transparency, and security-by-design are becoming the backbone of regulation. Assurance, precision, and incident reporting are not.

Maturity model: TrustScore readiness

LevelDescriptionAnalogy
1. UnverifiedAd-hoc policies, no formal evidencePre-compliance
2. DocumentedPolicies mapped to frameworksPolicy readiness
3. AuditableInternal assurance, partial ISO alignmentEmerging compliance
4. CertifiedThird-party audit against ISO 42001 and NISTMarket-ready
5. TrustedDemonstrable, portable complianceAI trade passport

Key takeaways for leaders

  • Proof beats promise. Regulators are moving from intent to evidence.
  • Security is global currency. Align cybersecurity and AI governance early.
  • Transparency is reputation. Public trust is earned through explainability.
  • Harmonisation is coming. The next decade favours organisations ready for interoperability.
Build a portable AI governance file: a risk register, model evaluations, an incident log, an AI Bill of Materials, and provenance documentation. That file is tomorrow’s licence to operate.

Executive takeaways

Three alignments, three splits, and a wider map

  1. Risk management, security-by-design, and transparency are the universal anchors of AI governance.
  2. Enforcement, clarity, and incident reporting still split sharply across jurisdictions.
  3. Brazil’s PL 2338/2023, the African Union AI Strategy, and Gulf initiatives show the map is no longer only European or American.
  4. AI Bills of Materials, provenance systems, compute thresholds, and ESG-style AI reporting are on the way to becoming baseline requirements.

Abstract and introduction

AI governance now sits alongside economic stability, democratic resilience, and trade. The EU AI Act is in force. The Council of Europe has opened the first treaty that ties AI to human rights, democracy, and the rule of law. National laws, standards, and voluntary codes are rewriting how systems are designed, deployed, and audited.

AI underpins healthcare, defence, finance, critical infrastructure, and democratic processes. Governments are racing to regulate. Industry is trying to operate across frameworks that do not agree. That is both a risk and an opening.

This brief compares the EU AI Act, the NIST AI RMF, and ISO/IEC 42001, then sets them against cybersecurity overlays such as NIS2, the Cyber Resilience Act, and ENISA and ETSI guidance. It also marks what is next: model evaluation, provenance, and compute governance.

The risk
Compliance fatigue, and gaps where no framework yet applies
The opportunity
A shared foundation in risk, transparency, and security-by-design

The decade ahead will be defined less by new flagship statutes and more by making existing ones work. The EU AI Act will be operationalised through standards. Supply-chain security will harden. Model evaluation will move from a voluntary practice to a procurement requirement. Companies that cannot produce AI governance reporting will be left out of tenders.

Beyond 2030, incident taxonomies, sector playbooks, certification, and ESG-style AI metrics will accelerate alignment. Beyond 2040, an International AI Safety Accord, compute thresholds, universal provenance, and secure-by-design trade rules may become the baseline.

Background and context

A live regulatory landscape, not a theory

The EU AI Act is the first comprehensive binding law, with risk tiers and conformity assessment. The Council of Europe convention, opened in 2024, is the first global treaty linking AI to rights and the rule of law. Denmark and the Netherlands have prioritised anti-deepfake rules. The United States has relied on executive orders, the NIST AI RMF, and OMB guidance, while Colorado has written its own statute. The TAKE IT DOWN Act became public law in May 2025. Canada’s AIDA is in progress. Brazil has passed a Senate bill. Singapore, Japan, and South Korea mix guidelines with statute. China already enforces rules on generative AI and synthetic media. The African Union has endorsed a continental strategy.

Voluntary instruments still matter. The OECD AI Principles, the G7 Hiroshima Process, and GPAI’s move into the OECD show multilateral coordination. Bletchley and Seoul show industry self-commitment. ISO/IEC 42001 and ISO/IEC 23894 supply a management system and a risk method. ETSI and ENISA are defining cybersecurity baselines for AI.

Where alignment still fails

  • Assurance and enforcement. What counts as proof, and what happens if you fall short, varies widely. Some markets over-engineer. Others under-shoot. Evidence rarely travels.
  • Clarity and precision. Prescriptive regimes create certainty and slow product cycles. Principle-based regimes leave teams guessing what good enough means.
  • Incident reporting. Thresholds, definitions of serious harm, and clocks differ, and in many places they do not exist.

Fragmented definitions of AI, role duties, and cross-border data rules complicate supply chains even when the underlying controls are similar. New guidance is landing faster than governance programmes mature. Overlapping audits drain capacity, especially for smaller firms.

NIST gives a shared risk vocabulary without enforcement. ISO/IEC 42001 can certify a management system, but adoption is early and the cost is real. OECD, UNESCO, and UN texts set goals without an assurance path. Bletchley and Seoul are pledges. Pledges are not proof.

The alignment blueprint

From fragmentation to foresight

Leaders need one structured view that compares obligations, shows convergence, and flags what is coming. The blueprint has four parts.

Framework matrix
Laws, standards, and codes as rows. Scope, risk, lifecycle controls, transparency, security, oversight, reporting, enforcement, and cross-border rules as columns.
Crossroads analysis
Pairwise comparisons, including the EU AI Act against NIST and ISO/IEC 42001, and AI rules against NIS2 and the Cyber Resilience Act.
Regional snapshots
Current obligations, upcoming measures, and alignment opportunities for the EU, US, UK, China, Africa, Brazil, and peers.
Timeline
A roadmap from early data-protection treaties to 2040, including model evaluation, provenance, compute thresholds, and AI Bills of Materials.

What the matrix shows

Each instrument is broken into the same dimensions: scope, risk categories, lifecycle controls, transparency, security, human oversight, incident reporting, assurance, enforcement, cross-border rules, and sector carve-outs. A treaty and a technical specification can then be read against the same obligations.

  • Risk management is the universal denominator, from the EU AI Act to ISO/IEC 23894 and the NIST AI RMF. Enforcement is what differs.
  • Security-by-design is becoming a global passport. NIS2 and the Cyber Resilience Act write it into law. ETSI, ENISA, and Singapore’s CSA treat it as practice.
  • Transparency is now both a regulatory duty and a reputation lever, through EU registries, NIST system cards, and C2PA provenance.

The gaps are as useful as the overlaps. Assurance is patchy. Incident reporting is fragmented. Healthcare, elections, media, and finance are already building their own overlays, from BS 30440 to C2PA and MAS FEAT. One governance file can travel across some borders. Local adaptation is unavoidable at others.

Overlaps, obligations, and omissions

PairingWhat it means
EU AI Act and ISO/IEC 42001Strong fit on management systems and auditability. ISO is the organisational backbone for EU compliance.
EU AI Act and NIST / OECDThe EU mandates conformity and penalties. NIST and the OECD stay voluntary. Organisations need an assurance layer.
NIST and OECD, Singapore, JapanShared voluntary, risk-proportional approach. No enforcement route, unlike the EU.
ISO/IEC 42001 as a bridgePortable across the EU and NIST. It does not cover China’s filings and localisation duties.
China and the EU AI ActShared transparency signals. China adds licensing, content controls, and localisation.
South Korea’s AI Framework ActCloser to the EU’s binding model than to Japan or Singapore. An Asia-Pacific enforcement anchor.
NIS2, CRA, ETSI, ENISA, Singapore CSASecurity-by-design converges here, and stays optional in OECD and NIST.
G7, Bletchley, SeoulUseful for reputation and evaluation commitments. Not legally sufficient.

ISO/IEC 42001 is the practical bridge. It is close to both the EU AI Act and the NIST RMF on evidence, roles, and continuous improvement. It does not cover China’s filing, localisation, and content duties, so global operators still bolt those on. The Council of Europe convention aligns national law with rights. It is not a content-control regime.

Inside Asia-Pacific the split is already visible. South Korea’s Framework Act is binding. Japan’s guidelines and Singapore’s Model AI Governance Framework stay voluntary and proportional. They are strong operating templates, and they do not by themselves satisfy European assurance. Colorado’s SB 24-205 is the first US state foothold with a risk-based, anti-discrimination duty and real enforcement. Canada’s AIDA sits between the EU and NIST: the risk language is there, and the penalties are still forming.

NIS2 and the Cyber Resilience Act are the EU’s non-negotiable security spine. BS 30440 is the fast path for healthcare. C2PA is the practical provenance rail for media, elections, and brand integrity, even though it is market-driven rather than a legal assurance route. The OECD principles remain the shared language of dialogue, and only when they are paired with something certifiable or binding.

Regional postures

Two anchors, two bridges, two emerging baselines

United States
A bridge. NIST, OMB guidance, and executive orders set a voluntary federal baseline. Colorado’s AI Act is an early binding foothold. The US leads on operational vocabulary and lags the EU on penalties.
European Union
A hard anchor. The AI Act is the first comprehensive binding law, with risk tiers, conformity assessment, and links to NIS2 and the Cyber Resilience Act.
United Kingdom
A bridge. No single AI statute. Regulator-led guidance, the Bletchley Declaration, and sector overlays. Influence as a convener exceeds domestic enforcement.
China
A hard anchor. Generative AI Measures and Deep Synthesis Provisions already require filings, algorithm registration, localisation, and content controls.
Africa
An emerging baseline. The African Union Continental AI Strategy sets rights, inclusion, and capacity goals. Enforcement is still left to member states.
Brazil
An emerging baseline. PL 2338/2023 follows the EU’s risk scaffolding. Assurance and penalty systems are not yet at European maturity.

From privacy treaties to an AI safety accord

PeriodWhat lands
Foundations, 1980–2002OECD Privacy Guidelines, Convention 108, the EU Data Protection Directive, and FISMA.
Cyber baselines, 2003–2019HIPAA Security Rule, the first NIS Directive, and the EU Cybersecurity Act.
Convergence, 2020–2025NIS2, NIST AI RMF 1.0, China’s generative AI rules, the EU AI Act, the Cyber Resilience Act, and South Korea’s AI Framework Act.
Implementation, 2025–2030EU AI Act standards, the GPAI Code of Practice, CRA obligations, and model evaluation becoming procurement-grade.
Consolidation, 2030–2040Shared incident taxonomies, certification ecosystems, sector playbooks, continuous monitoring, and AI Bills of Materials.
Harmonisation, 2040+An International AI Safety Accord, compute governance, universal content authenticity, and AI ESG reporting.

Conclusion

Mapping today, preparing for tomorrow

Risk management, security-by-design, and transparency keep appearing because they are recognisable, implementable, and politically defensible. The words change. The logic does not.

Start with risk. Risk tiers in the EU, high-impact categories in Canada, and lifecycle functions in NIST are the same idea. Assessing risk early shows where value and controls belong before obligations harden.

Double down on security. Binding laws now point at cybersecurity duties. A strong baseline reduces direct harm and travels further than a policy statement.

Invest in transparency. Documentation, model cards, and disclosure serve regulators, buyers, and the public at once.

The three divergences that still decide the cost

  • Proof and penalty. Design for the strictest credible regime, then downshift. A living register of tests, evaluations, and decisions can satisfy EU assurance or a lighter framework without being rebuilt.
  • Innovation and control. Use flexible regimes to test, and document the choices so they can be lifted into stricter ones. Be precise in the markets you already know you will enter.
  • Incident reporting. Report more, not less. One register of harms and near-misses can be formatted for each jurisdiction. ISO/IEC 27035 and ISO/IEC 42001 are a baseline. They do not replace local thresholds.

From 2025 to 2030, implementation matters more than new flagship laws. Model evaluation becomes expected in procurement. Certification tied to ISO/IEC 42001, safety cases, continuous monitoring, and an AI Bill of Materials become ordinary. From 2030 to 2040, an International AI Safety Accord, compute reporting, universal provenance, and secure-by-design marks start to function as trade passports. AI ESG reporting moves toward the status of financial and carbon disclosure.

What this means for you

Leaders
Put model evaluation and AI-BOM deliverables into procurement. Map product-security frameworks such as the Cyber Resilience Act onto AI controls, starting with shared harm and incident taxonomies. Support cross-border work toward an International AI Safety Accord.
Enterprises and suppliers
Keep a portable file: risk register, evaluations, incident logs, transparency packs, AI Bills of Materials, and provenance. Treat security-by-design and continuous monitoring as non-negotiable, aligned to ISO/IEC 42001 and the NIST AI RMF. Pilot authenticity measures such as C2PA on synthetic outputs.
Standards bodies and multilateral institutions
Align incident taxonomies, publish assurance templates, define practical compute thresholds and evaluation benchmarks, and make ESG-for-AI metrics comparable.

Final words

Convergence is real, and it is incomplete. Risk management, transparency, and security-by-design are becoming a shared language. Assurance, enforcement, incident reporting, and even the definition of harm still decide the friction.

The task is not only compliance. It is governance that can adapt as the map shifts. Organisations that treat it as a discipline, rather than a burden, will be the ones able to operate and lead.

Reflections

Mike Wood

Researcher reflections

Governance has to work as a living system.
Mike Wood, Research Associate, Responsible AI Trust. Head of Technology Operations and Compliance Lead, Hadean. Author, Global AI Governance Alignment Map.

Every nation and company wants its own AI rulebook. The technology does not recognise borders. The work was to connect innovation, leadership, and policy in a way that holds up in practice.

Three ideas do the heavy lifting: risk management, transparency, and security-by-design. They are the shared language of developers, policymakers, and auditors. The real story is in the divergences. Assurance is enforced in Europe and voluntary elsewhere. Precision helps compliance and can slow creativity. Incident reporting and penalties mean different things on different sides of a border.

  • Anchor national frameworks in shared principles so obligations are not duplicated.
  • Move from pledges to measurable standards and AI Bills of Materials.
  • Draft governance that leadership teams can act on and explain.
  • Standardise harm definitions and reporting timelines.
  • Treat ISO/IEC 42001, the NIST AI RMF, and the EU AI Act as complementary.
Patrick Sullivan

Advisor reflections

Proof, not intent, is what will define trust.
Patrick Sullivan, VP of Strategy and Innovation, A-LIGN. ISO/IEC 42001 Lead Implementer and SC 42 delegate. Advisor and reviewer.

The map shows a field that is still fragmented and starting to align. Risk management, transparency, and security-by-design turn policy language into something leaders can use. ISO/IEC 42001 is the connective tissue. It links the EU’s binding Act with the voluntary, lifecycle structure of the NIST AI RMF. Without that link, compliance stays reactive. With it, governance becomes measurable across markets.

Enforcement still varies. Rules differ in precision. Incident reporting still lacks one standard. Risk is not only a control function. It is how purpose and accountability stay aligned.

  • Build a governance file with risk registers, evaluations, transparency records, and AI Bills of Materials.
  • Treat security-by-design as a baseline.
  • Prepare for a market where proof, not intent, defines trust.
The organisations that succeed will operationalise governance. Appearing responsible is no longer the standard. Demonstrating it is.
Lehar Gupta

Research director reflections

Responsible AI has to be demonstrated, not declared.
Lehar Gupta, Founder & Research Director, Responsible AI Trust. Co-author, Global AI Governance Alignment Map.

This map is more than a comparison of frameworks. It marks a moment in how trust in intelligent systems is being defined. Mike Wood’s research showed the common ground forming across jurisdictions. Patrick Sullivan’s review made the consequence plain: proof, not principle, is becoming the currency of responsibility.

Risk management, transparency, and security-by-design are no longer optional ideals. They are the earliest signals of a shared standard. The work at Responsible AI Trust is to operationalise those anchors so enterprises, regulators, and innovators can navigate complexity with evidence.

This brief is one step in turning governance from a checklist into a measurable trust system. The alignment map is the first structured demonstration of that direction.

Appendix

Primary sources

The downloadable brief includes the full source list, regional explainers, the cybersecurity timeline, and the framework comparison matrix.

  1. EU AI Act, Regulation (EU) 2024/1689.
  2. Council of Europe Framework Convention on Artificial Intelligence (2024).
  3. NIS2 Directive, Directive (EU) 2022/2555.
  4. EU Cyber Resilience Act, Regulation (EU) 2024/2847.
  5. NIST AI Risk Management Framework 1.0 (2023) and Cybersecurity Framework 2.0 (2024).
  6. China Generative AI Measures (2023) and Deep Synthesis Provisions (2023).
  7. South Korea AI Framework Act (2025, effective 2026).
  8. Colorado AI Act, SB 24-205 (2024, effective 2026).
  9. Canada Artificial Intelligence and Data Act, Bill C-27.
  10. Brazil PL 2338/2023.
  11. Japan AI Business Guidelines (2024) and Singapore Model AI Governance Framework.
  12. African Union Continental AI Strategy (2024).
  13. OECD AI Principles (2019, updated 2024).
  14. G7 Hiroshima Process and Code of Conduct (2023).
  15. Bletchley Declaration (2023) and Seoul Frontier AI Safety Commitments (2024).
  16. ISO/IEC 42001 (2023) and ISO/IEC 23894 (2023).
  17. ENISA Threat Landscape for AI, ETSI Securing AI, and C2PA.

Download the full whitepaper

Public Release 1.0, November 2025.

Download the full whitepaper

Disclaimer

The Global AI Governance Alignment Map has been independently developed by Responsible AI Trust. The analyses, views, and recommendations are those of the authors and do not necessarily represent the organisations referenced. This publication is provided as is, without warranty. Responsible AI Trust accepts no liability for actions taken based on its content. It is for information only and should not be relied upon as legal or regulatory advice.

All rights reserved. No part of this report may be reproduced, distributed, or transmitted without the prior written permission of Responsible AI Trust, except for brief quotations with proper citation. Report concerns to info@responsibleaitrust.com.

Back to research