Responsible AI Trust
Global AI governance alignment map
Navigating AI regulation, standards, and what’s coming next.
Mike Wood
Lehar Gupta
Patrick Sullivan
Foreword from the founder
At Responsible AI Trust, our purpose is simple yet vital: to strengthen global confidence in intelligent systems.
Across industries and borders, AI is redefining how decisions are made, risks are managed, and accountability is shared. With this transformation comes a collective responsibility to ensure that technology remains aligned with human values, transparency, and fairness.
Each brief we publish represents collaborative work from researchers, advisors, and practitioners who believe that trust must be earned through clarity, governance, and evidence. Together, we translate complex regulation into actionable insight, helping leaders navigate uncertainty with structure and foresight.
Responsible AI is not a trend. It is the foundation of sustainable innovation. As systems grow more capable, our frameworks for oversight must grow equally intelligent, adaptive, and globally connected.
Thank you for being part of this effort to turn principles into practice, and ideas into accountability.
Lehar GuptaFounder & CEO, Responsible AI TrustLehar@ResponsibleAITrust.com
About this brief
Global AI governance alignment map
This is Responsible AI Trust’s flagship map of how regulations, standards, and voluntary codes align and diverge, from the EU AI Act to ISO/IEC 42001 and the NIST AI Risk Management Framework. It identifies the principles that are starting to make global interoperability possible.
Leader’s dashboard
The world is converging on three anchors, and still diverging on three others.
Governance has shifted from principles to proof. Risk management, transparency, and security-by-design are becoming the backbone of regulation. Assurance, precision, and incident reporting are not.
Maturity model: TrustScore readiness
Key takeaways for leaders
- Proof beats promise. Regulators are moving from intent to evidence.
- Security is global currency. Align cybersecurity and AI governance early.
- Transparency is reputation. Public trust is earned through explainability.
- Harmonisation is coming. The next decade favours organisations ready for interoperability.
Build a portable AI governance file: a risk register, model evaluations, an incident log, an AI Bill of Materials, and provenance documentation. That file is tomorrow’s licence to operate.
Executive takeaways
Three alignments, three splits, and a wider map
- Risk management, security-by-design, and transparency are the universal anchors of AI governance.
- Enforcement, clarity, and incident reporting still split sharply across jurisdictions.
- Brazil’s PL 2338/2023, the African Union AI Strategy, and Gulf initiatives show the map is no longer only European or American.
- AI Bills of Materials, provenance systems, compute thresholds, and ESG-style AI reporting are on the way to becoming baseline requirements.
Abstract and introduction
AI governance now sits alongside economic stability, democratic resilience, and trade. The EU AI Act is in force. The Council of Europe has opened the first treaty that ties AI to human rights, democracy, and the rule of law. National laws, standards, and voluntary codes are rewriting how systems are designed, deployed, and audited.
AI underpins healthcare, defence, finance, critical infrastructure, and democratic processes. Governments are racing to regulate. Industry is trying to operate across frameworks that do not agree. That is both a risk and an opening.
This brief compares the EU AI Act, the NIST AI RMF, and ISO/IEC 42001, then sets them against cybersecurity overlays such as NIS2, the Cyber Resilience Act, and ENISA and ETSI guidance. It also marks what is next: model evaluation, provenance, and compute governance.
The decade ahead will be defined less by new flagship statutes and more by making existing ones work. The EU AI Act will be operationalised through standards. Supply-chain security will harden. Model evaluation will move from a voluntary practice to a procurement requirement. Companies that cannot produce AI governance reporting will be left out of tenders.
Beyond 2030, incident taxonomies, sector playbooks, certification, and ESG-style AI metrics will accelerate alignment. Beyond 2040, an International AI Safety Accord, compute thresholds, universal provenance, and secure-by-design trade rules may become the baseline.
Background and context
A live regulatory landscape, not a theory
The EU AI Act is the first comprehensive binding law, with risk tiers and conformity assessment. The Council of Europe convention, opened in 2024, is the first global treaty linking AI to rights and the rule of law. Denmark and the Netherlands have prioritised anti-deepfake rules. The United States has relied on executive orders, the NIST AI RMF, and OMB guidance, while Colorado has written its own statute. The TAKE IT DOWN Act became public law in May 2025. Canada’s AIDA is in progress. Brazil has passed a Senate bill. Singapore, Japan, and South Korea mix guidelines with statute. China already enforces rules on generative AI and synthetic media. The African Union has endorsed a continental strategy.
Voluntary instruments still matter. The OECD AI Principles, the G7 Hiroshima Process, and GPAI’s move into the OECD show multilateral coordination. Bletchley and Seoul show industry self-commitment. ISO/IEC 42001 and ISO/IEC 23894 supply a management system and a risk method. ETSI and ENISA are defining cybersecurity baselines for AI.
Where alignment still fails
- Assurance and enforcement. What counts as proof, and what happens if you fall short, varies widely. Some markets over-engineer. Others under-shoot. Evidence rarely travels.
- Clarity and precision. Prescriptive regimes create certainty and slow product cycles. Principle-based regimes leave teams guessing what good enough means.
- Incident reporting. Thresholds, definitions of serious harm, and clocks differ, and in many places they do not exist.
Fragmented definitions of AI, role duties, and cross-border data rules complicate supply chains even when the underlying controls are similar. New guidance is landing faster than governance programmes mature. Overlapping audits drain capacity, especially for smaller firms.
NIST gives a shared risk vocabulary without enforcement. ISO/IEC 42001 can certify a management system, but adoption is early and the cost is real. OECD, UNESCO, and UN texts set goals without an assurance path. Bletchley and Seoul are pledges. Pledges are not proof.
The alignment blueprint
From fragmentation to foresight
Leaders need one structured view that compares obligations, shows convergence, and flags what is coming. The blueprint has four parts.
What the matrix shows
Each instrument is broken into the same dimensions: scope, risk categories, lifecycle controls, transparency, security, human oversight, incident reporting, assurance, enforcement, cross-border rules, and sector carve-outs. A treaty and a technical specification can then be read against the same obligations.
- Risk management is the universal denominator, from the EU AI Act to ISO/IEC 23894 and the NIST AI RMF. Enforcement is what differs.
- Security-by-design is becoming a global passport. NIS2 and the Cyber Resilience Act write it into law. ETSI, ENISA, and Singapore’s CSA treat it as practice.
- Transparency is now both a regulatory duty and a reputation lever, through EU registries, NIST system cards, and C2PA provenance.
The gaps are as useful as the overlaps. Assurance is patchy. Incident reporting is fragmented. Healthcare, elections, media, and finance are already building their own overlays, from BS 30440 to C2PA and MAS FEAT. One governance file can travel across some borders. Local adaptation is unavoidable at others.
Overlaps, obligations, and omissions
ISO/IEC 42001 is the practical bridge. It is close to both the EU AI Act and the NIST RMF on evidence, roles, and continuous improvement. It does not cover China’s filing, localisation, and content duties, so global operators still bolt those on. The Council of Europe convention aligns national law with rights. It is not a content-control regime.
Inside Asia-Pacific the split is already visible. South Korea’s Framework Act is binding. Japan’s guidelines and Singapore’s Model AI Governance Framework stay voluntary and proportional. They are strong operating templates, and they do not by themselves satisfy European assurance. Colorado’s SB 24-205 is the first US state foothold with a risk-based, anti-discrimination duty and real enforcement. Canada’s AIDA sits between the EU and NIST: the risk language is there, and the penalties are still forming.
NIS2 and the Cyber Resilience Act are the EU’s non-negotiable security spine. BS 30440 is the fast path for healthcare. C2PA is the practical provenance rail for media, elections, and brand integrity, even though it is market-driven rather than a legal assurance route. The OECD principles remain the shared language of dialogue, and only when they are paired with something certifiable or binding.
Regional postures
Two anchors, two bridges, two emerging baselines
From privacy treaties to an AI safety accord
Conclusion
Mapping today, preparing for tomorrow
Risk management, security-by-design, and transparency keep appearing because they are recognisable, implementable, and politically defensible. The words change. The logic does not.
Start with risk. Risk tiers in the EU, high-impact categories in Canada, and lifecycle functions in NIST are the same idea. Assessing risk early shows where value and controls belong before obligations harden.
Double down on security. Binding laws now point at cybersecurity duties. A strong baseline reduces direct harm and travels further than a policy statement.
Invest in transparency. Documentation, model cards, and disclosure serve regulators, buyers, and the public at once.
The three divergences that still decide the cost
- Proof and penalty. Design for the strictest credible regime, then downshift. A living register of tests, evaluations, and decisions can satisfy EU assurance or a lighter framework without being rebuilt.
- Innovation and control. Use flexible regimes to test, and document the choices so they can be lifted into stricter ones. Be precise in the markets you already know you will enter.
- Incident reporting. Report more, not less. One register of harms and near-misses can be formatted for each jurisdiction. ISO/IEC 27035 and ISO/IEC 42001 are a baseline. They do not replace local thresholds.
From 2025 to 2030, implementation matters more than new flagship laws. Model evaluation becomes expected in procurement. Certification tied to ISO/IEC 42001, safety cases, continuous monitoring, and an AI Bill of Materials become ordinary. From 2030 to 2040, an International AI Safety Accord, compute reporting, universal provenance, and secure-by-design marks start to function as trade passports. AI ESG reporting moves toward the status of financial and carbon disclosure.
What this means for you
Final words
Convergence is real, and it is incomplete. Risk management, transparency, and security-by-design are becoming a shared language. Assurance, enforcement, incident reporting, and even the definition of harm still decide the friction.
The task is not only compliance. It is governance that can adapt as the map shifts. Organisations that treat it as a discipline, rather than a burden, will be the ones able to operate and lead.
Reflections
Appendix
Primary sources
The downloadable brief includes the full source list, regional explainers, the cybersecurity timeline, and the framework comparison matrix.
- EU AI Act, Regulation (EU) 2024/1689.
- Council of Europe Framework Convention on Artificial Intelligence (2024).
- NIS2 Directive, Directive (EU) 2022/2555.
- EU Cyber Resilience Act, Regulation (EU) 2024/2847.
- NIST AI Risk Management Framework 1.0 (2023) and Cybersecurity Framework 2.0 (2024).
- China Generative AI Measures (2023) and Deep Synthesis Provisions (2023).
- South Korea AI Framework Act (2025, effective 2026).
- Colorado AI Act, SB 24-205 (2024, effective 2026).
- Canada Artificial Intelligence and Data Act, Bill C-27.
- Brazil PL 2338/2023.
- Japan AI Business Guidelines (2024) and Singapore Model AI Governance Framework.
- African Union Continental AI Strategy (2024).
- OECD AI Principles (2019, updated 2024).
- G7 Hiroshima Process and Code of Conduct (2023).
- Bletchley Declaration (2023) and Seoul Frontier AI Safety Commitments (2024).
- ISO/IEC 42001 (2023) and ISO/IEC 23894 (2023).
- ENISA Threat Landscape for AI, ETSI Securing AI, and C2PA.
Download the full whitepaper
Public Release 1.0, November 2025.
Disclaimer
The Global AI Governance Alignment Map has been independently developed by Responsible AI Trust. The analyses, views, and recommendations are those of the authors and do not necessarily represent the organisations referenced. This publication is provided as is, without warranty. Responsible AI Trust accepts no liability for actions taken based on its content. It is for information only and should not be relied upon as legal or regulatory advice.
All rights reserved. No part of this report may be reproduced, distributed, or transmitted without the prior written permission of Responsible AI Trust, except for brief quotations with proper citation. Report concerns to info@responsibleaitrust.com.


