AI Policy is the ensemble of government strategies, regulatory instruments, voluntary guidelines, and international agreements through which states and intergovernmental bodies shape the development, deployment, and societal impact of artificial intelligence systems. Policy instruments span public research funding, national AI strategies, procurement standards for government AI use, export controls on frontier hardware and models, and binding requirements for transparency, accountability, and fundamental-rights compliance in high-stakes applications. Effective AI policy must balance national competitiveness, safety assurance, equitable access, and interoperability with allied jurisdictions, making it an inherently multi-stakeholder and multi-domain governance challenge.

Semantic Classification

Content

Compositional Relationships (Components)

SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:AiGovernanceFramework))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:RiskAssessment))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:ImpactAssessment))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:StakeholderConsultation))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:AiAudit))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:ConformityAssessment))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:IncidentReportingObligation))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:hasPart gov:NationalAiStrategy))

Dependency Relationships

SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:requires gov:RiskManagement))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:requires gov:Transparency))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:requires gov:HumanOversight))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:requires gov:AlgorithmicAccountability))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:requires gov:AiEthics))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:dependsOn gov:AiGovernance))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:dependsOn gov:DataGovernance))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:dependsOn gov:RegulatoryCompliance))

Capability Relationships

SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:AiGovernanceFramework))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:AlgorithmicAccountability))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:AiAudit))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:ComputeGovernance))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:ConformityAssessment))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:enables gov:TrustworthyAi))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:supports gov:AiSafety))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:supports gov:DigitalSovereignty))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:supports gov:ResponsibleAi))

Implementation Relationships

SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:implements gov:EuAiAct))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:implements gov:OecdAiPrinciples))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:implements gov:NistAiRmf))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:implements gov:IsoIec42001))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:standardizedBy gov:OecdAiPrinciples))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:standardizedBy gov:EuAiAct))

Reduction Relationships

SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:reducesTo gov:TechnologyPolicy))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:reducesTo gov:RegulatoryInstrument))
SubClassOf(gov:AiPolicy
  ObjectSomeValuesFrom(gov:reducesTo gov:GovernanceFramework))

About

AI policy has evolved from a marginal sub-field of science-and-technology policy into one of the highest-priority governance challenges facing states and intergovernmental bodies. The trajectory can be divided into three overlapping phases. The first phase (roughly 2016–2019) was characterised by voluntary ethics guidelines and national AI strategy documents produced in large numbers — the Jobin et al. (2019) survey identified 84 ethics policy documents from 36 countries published in this window, finding widespread convergence on abstract principles (transparency, justice, non-maleficence, responsibility, privacy) but little agreement on how to operationalise them. The UK published its AI Sector Deal (2018) and established the Centre for Data Ethics and Innovation; the EU High-Level Expert Group on AI produced the Ethics Guidelines for Trustworthy AI (2019); and major technology companies including Google, Microsoft, IBM, and Salesforce released internal AI ethics frameworks that functioned as de facto industry self-regulation. The OECD adopted its AI Principles in 2019 (since revised in 2024), providing the most politically robust voluntary framework, adopted by 46+ countries. This phase established the vocabulary of AI ethics as a governance discourse — trustworthy AI, fairness, transparency, accountability — but produced limited binding obligation or enforcement capacity.

The second phase (2020–2023) saw the transition to binding or quasi-binding instruments, catalysed by the mainstreaming of harmful AI-system deployments (facial recognition by law enforcement agencies, algorithmic decision-making in welfare and criminal justice), the emergence of Generative AI at scale (GPT-3, DALL-E, Stable Diffusion), and intensifying geopolitical competition over AI leadership between the US and China. The EU published its proposal for an AI Act in April 2021 — the first comprehensive horizontal AI regulation by a major jurisdiction — establishing a risk-tiered approach that would become globally influential as a regulatory model. The US Executive Order on the Safe, Secure, and Trustworthy Development and Use of AI (October 2023) established compute-threshold reporting requirements and directed NIST, CISA, and other agencies to develop AI-specific guidance. The Bletchley Declaration (November 2023) marked the emergence of frontier AI risk as a geopolitically salient issue: 28 countries — including the US, China, the EU, the UK, and major AI-producing states — agreed that frontier AI systems posed potentially catastrophic risks and committed to collaborative evaluation and information-sharing. The UK’s position during this phase was distinctive: rather than creating a horizontal AI regulation analogous to the EU AI Act, it took a sector-led, principles-based approach relying on existing regulators, preserving flexibility while sacrificing legal clarity.

The third phase (2024–2026) is characterised by implementation of binding instruments, multilateral institutional capacity-building, and the emergence of Compute Governance as a new policy lever targeting not AI applications but the computational substrate that makes frontier AI Model training possible. The EU AI Act entered into force in August 2024 with a phased applicability schedule: GPAI model obligations applied from August 2025; most high-risk system obligations will apply from August 2026 (extended by the Omnibus amendment agreed May 2026). The Council of Europe Framework Convention on AI (2024) provides the first legally binding international treaty on Human Rights Law in AI deployment. National AI Safety and Security Institutes (UK AISI/AISI→UKASI, US AISI, Japan AISI, Singapore AI Verify Foundation, the EU AI Office) are conducting pre-deployment evaluations of frontier AI Model systems, institutionalising safety assessment as a governance function. The AI Summit series (Bletchley 2023, Seoul 2024, Paris 2025, India 2026) has become the premier multilateral forum for frontier AI governance discussions, producing declarations that operationalise Bletchley-style commitments into more specific expectations for information-sharing, voluntary capability testing, and interoperable governance frameworks.

Three core drivers structure AI policy agendas across all jurisdictions, creating tensions that shape the specific instrument mix chosen. First, economic competitiveness: states perceive AI capability as a determinant of long-term economic productivity, technological sovereignty, and global influence. U.S. private AI investment reached 12.4 billion. The EU AI Act is partly designed to create a level competitive playing field within the EU’s single market and to export European regulatory standards globally (the “Brussels Effect”); it is simultaneously criticised as potentially handicapping European AI development relative to less-regulated US and Chinese competitors, a tension evident in the Omnibus simplification amendment of May 2026. Second, safety and risk management: the deployment of AI Model systems in high-stakes domains — healthcare, criminal justice, critical infrastructure, financial services, autonomous vehicles — creates accountability gaps that markets do not self-correct. Policy must define ex-ante obligations (conformity assessment, technical documentation, Bias Mitigation, Human Oversight) and ex-post mechanisms (incident reporting, liability frameworks) to ensure harmful deployments are caught and addressed. Third, geopolitical positioning: AI capability is increasingly treated as a dimension of National Security, analogous to nuclear or space technology, driving export controls on AI Chips (GPU hardware and high-bandwidth memory), restrictions on cross-border AI research collaboration, industrial subsidies to reshore semiconductor manufacturing, and allied coordination to prevent strategic competitors from accessing frontier AI Model training capabilities.

The instruments through which AI policy operates are diverse and operate at multiple governance levels simultaneously, creating a layered and sometimes inconsistent regulatory environment. At the national level, legislatures enact statutes (the EU AI Act, China’s Provisional Measures for Generative AI Services 2023, Canada’s Artificial Intelligence and Data Act), executive agencies issue guidance and interpretations (the UK’s Information Commissioner’s Office on data protection in AI, the US Federal Trade Commission on deceptive AI marketing, the UK’s Financial Conduct Authority on model risk in financial services), and sector-specific regulators apply existing frameworks to AI (the FDA on AI-enabled medical devices, the European Medicines Agency on AI-supported clinical trials, the Basel Committee on Banking Supervision on AI model risk). At the intergovernmental level, the OECD’s AI Policy Observatory tracks national policy developments across 70+ jurisdictions and maintains the most widely adopted voluntary framework; the G7’s Hiroshima AI Process (2023) produced a Code of Conduct for Advanced AI Systems adopted by 28 countries; and the Council of Europe’s Framework Convention on AI (2024) is the first legally binding international treaty focused on Human Rights Law compliance in AI deployment, requiring public-sector AI systems in signatory states to meet requirements aligned with democratic values and rule-of-law constraints. International standards bodies — particularly ISO/IEC JTC1 SC42 — produce technical standards such as ISO/IEC 42001 (AI management systems, 2023), ISO/IEC 23894 (AI risk management guidance), and ISO/IEC 42005 (AI system impact assessment) that serve as benchmarks for Conformity Assessment, can be incorporated by reference into binding regulatory instruments, and provide internationally harmonised certification pathways for multinational AI developers. The interplay between standards (voluntary, technically precise, internationally harmonised), regulation (binding, legally enforceable, jurisdictionally specific), and voluntary commitments (normatively significant, rapid, but unenforced) constitutes the multi-layered texture of AI policy as a governance field.

Components / Architecture

AI policy as a governance system comprises several distinguishable components:

National AI Strategies set the overall direction and ambition of a government’s AI engagement. They typically include investment commitments (in research, compute, talent), sector-specific deployment priorities (health, defence, education, transport), and regulatory philosophy (risk-based, principles-based, rules-based). Key examples: the UK AI Opportunities Action Plan (2025, committing to sovereign compute infrastructure including the Isambard-AI supercomputer and the Dawn HPC cluster at Cambridge); the US National AI Initiative; China’s New Generation AI Development Plan; the EU Coordinated Plan on AI.

Binding Regulation imposes legally enforceable obligations on AI developers and deployers. The EU AI Act (Regulation (EU) 2024/1689, entered into force August 2024) is the most comprehensive example: it establishes a four-tier risk taxonomy (unacceptable risk — prohibited; high-risk — conformity assessment required; limited risk — transparency obligations; minimal risk — unregulated), and adds obligations for general-purpose AI (Foundation Model) providers above compute thresholds. GPAI model obligations (transparency, copyright compliance, technical documentation, cooperation with authorities) applied from August 2025. An “AI Act Omnibus” amendment agreed in May 2026 extends compliance deadlines for high-risk systems and adds rules on AI-generated intimate content. The Council of Europe Framework Convention on AI (2024) is legally binding on ratifying states, requiring that AI systems used in the public sector comply with Human Rights Law and democratic process requirements.

Voluntary Guidelines and Codes of Conduct provide norms ahead of legislation or across jurisdictions where legislation has not yet materialised. The OECD AI Principles (2019, updated 2024) cover inclusive growth, human-centred values, Transparency, Trustworthy AI, robustness, and Algorithmic Accountability; adopted by 46+ countries. The White House Voluntary Commitments (2023) and Seoul AI Safety Commitments (2024) bind leading AI developers (Anthropic, Google DeepMind, Meta, Microsoft, OpenAI, and others) to Red Teaming, information sharing with governments, and safe deployment practices for frontier models. The G7 Hiroshima Process International Code of Conduct (2023) provides a 10-point code for organisations developing advanced AI, endorsed at the G7 Digital and Technology Ministerial Declaration (May 2026).

Export Controls and Industrial Policy weaponise supply-chain chokepoints as AI policy instruments. U.S. Bureau of Industry and Security (BIS) controls on advanced GPUs (notably the A100, H100, H200, and Blackwell-class chips), high-bandwidth memory, and semiconductor manufacturing equipment restrict adversarial access to frontier AI training capability and bridge AI Policy to Semiconductor Export Controls and Supply Chain Security. The CHIPS and Science Act (US, 2022) and the EU Chips Act (2023) provide industrial subsidies to reshore semiconductor manufacturing. South Korea’s Ministry of Science and ICT (MSIT) committed approximately USD 1.1 billion in July 2025 to procure 13,000 high-performance GPUs for domestic AI compute infrastructure, illustrating how industrial AI policy and Compute Governance are converging globally.

Procurement Standards for government use of AI create de facto market standards that ripple into private-sector practice. Requirements for Algorithmic Accountability, Explainable AI, Bias Mitigation, and human review of automated decisions in public-sector systems create demand for compliant products and development practices. The UK Government’s Algorithmic Transparency Recording Standard (ATRS) requires public bodies to publish information about algorithmic tools used in significant decisions.

International Coordination institutions provide forums for multilateral norm-setting and information-sharing on frontier AI risks. The Global AI Summit series (Bletchley 2023, Seoul 2024, Paris 2025, India 2026) has evolved from ad hoc gatherings to a structured leader-level platform for AI governance discussion. The Seoul Declaration called for AI governance frameworks interoperable across countries and endorsed the Hiroshima Process Code of Conduct. The GPAI (Global Partnership on AI) supports applied AI research and policy in lower-income countries.

Compute Governance is an emerging policy lever targeting frontier model training through compute thresholds. The US Executive Order (2023) required reporting for training runs above 10^26 FLOPs and identified compute as a policy target for National Security risk management. The EU AI Act uses 10^25 FLOPs as the threshold for general transparency obligations and 10^26 FLOPs for systemic-risk designation. As algorithmic efficiency improves — reducing the FLOPs required to achieve a given capability level — FLOP-based thresholds risk obsolescence, prompting discussion of capability-based or deployment-context-based thresholds.

Use Cases / Major Families

AI policy applies across a range of high-stakes application domains, each with specific instrument configurations:

  • Healthcare and medical devices: AI policy determines whether diagnostic AI must be cleared as a medical device (FDA in the US; MDR/IVDR in the EU), what clinical validation evidence is required, and how liability is allocated when AI-assisted diagnosis errs. The EU AI Act classifies AI used in medical diagnosis as high-risk, requiring Conformity Assessment and technical documentation before deployment.

  • Criminal justice and law enforcement: Policy restricts or regulates algorithmic risk-assessment tools in bail, sentencing, parole, predictive policing, and immigration decisions, grounded in Human Rights Law, Algorithmic Accountability, and anti-discrimination principles. The EU AI Act prohibits certain biometric categorisation uses; high-risk classification applies to law enforcement AI.

  • Autonomous vehicles and robotics: National frameworks determine testing authorisation, liability regimes, and minimum safety standards for self-driving systems deployed on public roads. These frameworks bridge AI policy to Cybersecurity Policy and product safety regulation.

  • Financial services: Supervisory guidance on model risk management (SR 11-7 in the US), Explainable AI requirements for credit-scoring algorithms, and systemic risk analysis for AI-driven trading strategies. The EU’s Digital Operational Resilience Act (DORA) adds resilience requirements for financial-sector AI.

  • Employment and recruitment: NYC Local Law 144 (2023) requires bias audits of automated employment decision tools; the EU AI Act classifies recruitment AI as high-risk, requiring Conformity Assessment, worker notification, and human oversight.

  • Generative AI and copyright: Policy frameworks address authorship, licensing, and training-data rights for Large Language Models and image-generation systems. The UK government’s March 2026 report on copyright and AI stated it would not introduce immediate copyright reforms but committed to further work; the EU AI Act requires general-purpose AI providers to disclose training data summaries and comply with copyright law.

  • Critical infrastructure: Cybersecurity Policy-adjacent AI policy addresses AI-enabled attacks on energy grids, water systems, communications networks, and financial market infrastructure. The EU AI Act classifies AI in critical infrastructure as high-risk.

  • Defence and national security: Separate policy frameworks (beyond the EU AI Act’s scope) govern AI in weapons systems, autonomous lethal systems, intelligence analysis, and command-and-control. The Campaign to Stop Killer Robots and political declarations on autonomous weapons are developing norms in this space.

  • Education: AI detection tools, AI-assisted grading, and adaptive learning systems create policy questions around fairness, Transparency, and academic integrity that intersect with data protection (GDPR) and child safety.

    Academic Context

    AI policy as a scholarly discipline is deeply interdisciplinary, drawing on political science, public administration, administrative law, economics, science and technology studies (STS), philosophy (particularly ethics and philosophy of technology), and computer science. Its emergence as a recognised field is recent — the first dedicated academic programmes, journals, and research centres appeared in the 2017–2020 period — but it builds on longer traditions in technology policy, media regulation, data protection law, and the sociology of technology.

    Foundational intellectual contributions predate the modern AI policy field. Winner’s “Do Artifacts Have Politics?” (1980) established the argument that technical systems embed political choices and power relationships, providing a theoretical foundation for treating AI system design as a political act requiring governance. Nissenbaum’s contextual integrity framework for privacy (2004, “Privacy as Contextual Integrity”, Washington Law Review) provided a normative account of when information flows respect context-appropriate norms, directly applicable to AI training data governance and the GDPR question of whether web-crawling for Foundation Model training respects the informational norms of the original publication context. O’Neil’s “Weapons of Math Destruction” (2016) provided the first widely-read account of algorithmic decision-making harms in consumer-facing applications, catalysing public and political attention to AI governance. Pasquale’s “The Black Box Society” (2015) focused specifically on opacity and accountability deficits in algorithmic systems. Eubanks’s “Automating Inequality” (2018) documented how automated decision systems in US public welfare programmes disproportionately harmed marginalised populations, providing empirical grounding for Algorithmic Accountability and Impact Assessment requirements.

    The landmark Jobin et al. (2019, Nature Machine Intelligence) survey of 84 AI ethics guidelines from 36 countries found convergence on five high-level principles (transparency, justice and fairness, non-maleficence, responsibility, and privacy) but deep divergence on implementation mechanisms, prioritisation across principles when they conflict, and the political economy of who bears compliance costs. Floridi et al.’s “An Ethical Framework for a Good AI Society” (2018, Minds and Machines) synthesised four AI ethics principles — beneficence, non-maleficence, autonomy, and justice — structured around the concept of AI for Responsible AI that benefits people in their physical, mental, and social dimensions. Dafoe’s “AI Governance: A Research Agenda” (2018, Future of Humanity Institute) provided the first systematic mapping of AI governance as a research field, identifying the principal-agent problems, commitment problems, coordination problems, and epistemic challenges that make AI governance institutionally difficult. Cath et al. (2018, Science and Engineering Ethics) provided early comparative analysis of US, EU, and UK approaches, identifying the tension between innovation-friendly and risk-precautionary regulatory philosophies that continues to define inter-jurisdictional AI policy debates.

    The post-2020 literature has grown to encompass legal analysis of specific regulatory instruments (Veale and Borgesius, 2021, on the EU AI Act draft; Chesterman, 2021, “Artificial Intelligence and the Limits of Legal Personality”), empirical AI auditing research (Raji et al., 2020, on internal algorithmic auditing; Buolamwini and Gebru, 2018, “Gender Shades”, establishing systematic racial and gender bias in commercial facial analysis AI models that directly motivated regulatory attention), and policy-design research on how to operationalise risk-based regulation, Conformity Assessment, and AI Audit frameworks in practice (Mökander and Floridi, 2021, on the ethics and governance of AI auditing; Raji et al., 2022, on the limitations of model cards and AI auditing as accountability mechanisms).

    Key research institutions contributing to AI policy scholarship and practice include: the Ada Lovelace Institute (UK, specialising in data and AI governance, foundational work on AI Audit, Algorithmic Accountability, and algorithmic impact assessment); the Alan Turing Institute (UK national AI research institute, hosting AI policy research through the Public Policy Programme, with collaborations with government departments including DSIT, UKDSI, and NHS); the Centre for AI and Digital Policy (CAIDP, US, tracking international AI policy developments across 75+ jurisdictions through the AI Governance Database); the AI Now Institute (New York University, focusing on social implications, labour impacts, and accountability in AI systems deployed by government and corporations); Future of Life Institute (existential risk and AI governance, organisational home of the original 2023 pause letter signed by 1,000+ researchers); the Leverhulme Centre for the Future of Intelligence (Cambridge, interdisciplinary AI ethics and society research); the Oxford Internet Institute (internet governance, digital rights, and AI policy); the Centre for the Governance of AI (GovAI, Oxford, focused on transformative AI governance and international coordination); and the Edinburgh Futures Institute (interdisciplinary AI policy and futures research, building on Edinburgh School of Informatics’ AI research strengths). EU-based institutions include the European AI Office (established under the EU AI Act to oversee GPAI model compliance and systemic risk assessments), AI4EU, and the AI HLEG (High-Level Expert Group on AI that produced the original EU ethics guidelines). The OECD AI Policy Observatory serves as the most comprehensive global repository of AI policy documents and national strategy analyses, tracking developments across 70+ jurisdictions.

    The interdisciplinary nature of AI policy means that key contributions span computer science venues (FAccT, AIES, NeurIPS policy workshops), peer-reviewed social science journals (AI and Society, Big Data and Society, Policy and Internet, New Media and Society), law journals (Stanford Technology Law Review, European Journal of Risk Regulation, Journal of Artificial Intelligence and Law, International Journal of Law and Information Technology), and practitioner publications (OECD AI Policy Observatory reports, NIST publications, government white papers from DSIT, DCMS, and the Cabinet Office in the UK).

    Current Landscape (2026)

    The AI policy landscape in June 2026 is characterised by five major dynamics, each generating distinctive implementation challenges and cross-jurisdictional tensions:

    EU AI Act implementation in full swing: The General-Purpose AI (Foundation Model) provisions became applicable on 2 August 2025, requiring providers of GPAI models above 10^25 FLOPs training compute to publish technical documentation, comply with copyright law, and produce AI Model Card-equivalent transparency disclosures. Providers of GPAI models with systemic risk (above 10^26 FLOPs) face heightened obligations including adversarial Red Teaming, incident reporting to the European AI Office, and cooperation with model evaluations. A political agreement on the AI Act Omnibus (7 May 2026) agreed to simplify and streamline rules: it extends compliance deadlines for some high-risk system obligations by 12 months, removes the mandatory national competent authority involvement for conformity assessment in some lower-risk high-risk categories (enabling self-assessment), and introduces new specific obligations regarding AI-generated intimate images (expanding the restricted practice prohibitions). The Omnibus reflects EU political concern that the original regulation imposed disproportionate burdens on European AI developers and SMEs relative to large US and Chinese competitors, illustrating the perennial innovation-protection tension in AI policy. The European AI Office, established to oversee GPAI model compliance, has published an inaugural Code of Practice for General-Purpose AI Models (2025) developed through multi-stakeholder consultation with model providers, civil society, and researchers, covering capability evaluation methodologies, safety testing requirements, Red Teaming protocols, and transparency disclosure templates.

    UK AI regulation trajectory: The UK has maintained a principles-based, sector-led approach, relying on existing regulators (ICO for data protection in AI, FCA for financial AI, CMA for competition implications of AI platform dominance, MHRA for AI medical devices, Ofcom for AI-generated content on regulated services) to address AI harms within their existing sectoral competence, rather than creating a new horizontal AI regulator or statute. The UK AI Security Institute (renamed from AI Safety Institute in 2025, signalling a shift in framing from existential safety risk to National Security misuse risks) continues frontier model evaluations in partnership with US, Japanese, and Singaporean counterparts, conducting pre-deployment assessments of frontier AI Model systems from Anthropic, Google DeepMind, Meta, OpenAI, and others. The UK Government’s October 2025 AI Growth Lab consultation proposed cross-economy regulatory sandboxes for AI innovation, reflecting the wider “pro-innovation” philosophy. An AI Bill addressing frontier safety, copyright and training data, Transparency obligations, and broader governance framework was widely anticipated for introduction in 2026 but had not been published as of June 2026, creating ongoing legal uncertainty for AI developers regarding whether UK law will converge with or diverge from the EU AI Act framework.

    US policy evolution under changed administration: Following the Biden Executive Order on the Safe, Secure, and Trustworthy Development and Use of AI (October 2023), which established compute-threshold reporting requirements and directed federal agencies to develop AI safety standards, the Trump administration rescinded it on its first day in office (January 2025). US AI policy in 2026 is primarily driven by sector-specific regulatory agencies (FTC enforcement on deceptive AI marketing, FDA on AI-enabled medical devices, financial regulators on model risk management), DARPA and the defense innovation apparatus (which has intensified AI procurement for military and intelligence applications), and the voluntary NIST AI RMF framework. The US AI Safety Institute was maintained within NIST with a narrowed mandate focused on AI measurement science rather than policy prescription. The Trump administration’s approach treats AI principally as a National Security and economic competitiveness asset, resulting in a more permissive domestic regulatory environment and a more aggressive export control posture (further restricting Chinese access to frontier AI Chips).

    International coordination advancing despite US-EU divergence: The Global AI Summit series (Paris 2025, hosted by France as G7 president; India 2026, hosted by India as G20 AI co-chair) continues, with the G7 Digital and Technology Ministerial Declaration (May 2026) reaffirming commitments to the Hiroshima Process Code of Conduct and calling for improved mutual understanding and comparability of AI risk assessment frameworks. The OECD AI Policy Observatory tracks policy developments across 70+ jurisdictions and has published updated OECD AI Principles (2024 revision) incorporating lessons from frontier model deployment. The Seoul Declaration’s call for interoperable AI governance frameworks is advancing through bilateral AI Safety Institute evaluation information-sharing between the UK, US, Japan, and Singapore, with the EU AI Office expressing interest in joining this network. International coordination on AI governance faces the structural challenge that the US has retreated from multilateral commitments domestically, while maintaining strong bilateral security-cooperation agreements with allied AI-producing states.

    Compute Governance cementing as frontier policy: FLOP-based compute thresholds (US EO, EU AI Act), export controls on frontier AI Chips (extending US BIS controls to additional chip families and new restricted jurisdictions, with allied coordination through multilateral export control bodies), and proposals for mandatory training-run registries are cementing Compute Governance as a distinct AI policy sub-field with its own technical experts, inter-agency processes, and international coordination mechanisms. The intersection of AI policy with Semiconductor Export Controls and Supply Chain Security is increasingly managed at the National Security level — through intelligence services, defence ministries, and security councils — rather than at the technology-policy level in major AI-producing states. South Korea’s KRW 1.46 trillion (approximately USD 1.1 billion) commitment to procure 13,000 high-performance GPUs (July 2025) exemplifies how Compute Governance is now a dimension of national AI strategy, with states seeking sovereign compute capacity to reduce dependency on external providers for frontier model training.

    AI policy and emerging technology intersections: Several policy areas that were previously distinct are now intersecting with AI policy in ways that complicate governance. The AI-biosecurity intersection — concern about AI Model systems that could provide meaningful assistance to actors seeking to create biological weapons — has become a priority for national biosecurity agencies and is reflected in the UK AI Security Institute’s dangerous capability evaluations. The AI-cybersecurity intersection — AI-enabled offensive cyber operations, AI-generated phishing, AI-assisted vulnerability discovery — is reshaping Cybersecurity Policy priorities and creating pressure to integrate AI policy with national cyber resilience frameworks. The AI-democracy intersection — large-scale AI-generated disinformation, synthetic media, AI-assisted influence operations — is a priority for electoral integrity agencies globally and is addressed partially by EU AI Act deepfake disclosure requirements and the UK Online Safety Act’s AI-generated content provisions.

    UK Context

    The UK occupies a distinctive position in the global AI policy landscape: it is a significant AI research nation (home to DeepMind, Wayve, Stability AI, and the Graphcore IPU hardware company; host of the first Global AI Safety Summit at Bletchley Park in November 2023), but is no longer subject to EU regulation post-Brexit, enabling a divergent regulatory strategy.

  • Alan Turing Institute: The UK’s national AI research institute hosts the Public Policy Programme, which produces policy-relevant research on Algorithmic Accountability, fairness, and Trustworthy AI. The Institute has collaborated with the OECD and UNESCO on AI policy frameworks.

  • Ada Lovelace Institute: London-based independent research institute specialising in the social impact of data and AI; produced foundational work on AI Audit and algorithmic impact assessment that has influenced UK and EU policy thinking.

  • AI Safety Institute / AI Security Institute: Established after Bletchley (November 2023) as the world’s first government body dedicated to frontier AI model evaluation, the UK AISI conducted pre-deployment evaluations of frontier models from leading labs. Its 2025 rebranding as the AI Security Institute reflects a shift in emphasis from existential to near-term National Security risks from frontier AI misuse.

  • Office for AI (DSIT): Co-ordinates cross-government AI strategy, publishes the National AI Strategy, and manages the AI Opportunities Action Plan. The Plan commits to sovereign AI compute (Isambard-AI at Bristol, Dawn at Cambridge), to attracting international AI investment, and to AI adoption across public services.

  • UK Regulators’ Forum on AI: A cross-sector forum including the ICO, FCA, CMA, MHRA, and Ofcom that co-ordinates sector-specific AI regulatory guidance, reducing risk of inconsistent obligations across domains.

  • Northern England and Industrial AI: Manchester hosts significant AI research at the University of Manchester (home to the original Ferranti Mark 1 computer, 1951) and within the Alan Turing Institute collaboration; Leeds and Sheffield contribute through the N8 Research Partnership’s AI activities. The proximity of the Northern Powerhouse industrial base — advanced manufacturing, logistics, and NHS health systems — creates regional demand for AI policy frameworks addressing industrial safety, worker rights in automated workplaces, and public-sector AI deployment in deprived communities.

  • Scotland: Edinburgh’s School of Informatics, ranked #1 in the UK for NLP research, contributes expertise to Scottish Government AI strategy and to international AI policy discourse through its Bayes Centre and Turing Institute node. The Edinburgh Futures Institute conducts interdisciplinary AI ethics and futures research. The Scottish AI Strategy (2021, updated 2024) emphasises ethical AI, public-sector adoption, and AI skills development, with specific attention to AI’s implications for Scottish devolved services (NHS Scotland, Police Scotland, Scottish Government administration).

  • Wales: Cardiff University is part of the UCL-led Generative AI Hub; Welsh Government AI strategy focuses on public-sector AI adoption, digital inclusion, and Welsh-language AI capabilities — the latter connecting AI policy to cultural and linguistic rights dimensions absent from most policy frameworks. The Welsh-language AI dimension is particularly distinctive: ensuring that AI systems deployed in Wales can serve Welsh speakers, and that Welsh-language text is not marginalised in AI training data and capability evaluations, is an explicit Welsh Government policy objective with no close parallel in most AI governance frameworks.

  • Northern England industrial AI policy: Manchester’s history as the birthplace of the stored-programme computer (Manchester Mark 1, 1948, and the subsequent Ferranti Mark 1, 1951) and its strong tradition in AI research (Geoffrey Hinton conducted key early neural network research at Edinburgh and later Manchester before moving to Toronto) gives it a distinctive perspective on AI governance. Sheffield’s Advanced Manufacturing Research Centre (AMRC) — a collaboration between Sheffield Hallam and the University of Sheffield with industry partners including Boeing, Rolls-Royce, and McLaren — focuses on AI applications in advanced manufacturing, raising sector-specific AI policy questions about worker displacement, safety-critical AI in precision manufacturing, and IP rights in AI-designed components. Leeds’s growing tech sector and the N8 Agri-Food consortium’s precision agriculture AI applications connect Northern England AI deployment to rural and agricultural AI policy dimensions. The Northern Powerhouse’s investment in AI as an economic development strategy frames AI policy partly as regional economic policy, with Northern local authorities exploring AI for local government efficiency, healthcare delivery improvement, and transport optimisation in ways that generate distinctive accountability and transparency requirements.

  • UK sovereign compute and industrial policy: The UK AI Opportunities Action Plan’s commitment to building sovereign AI compute infrastructure — Isambard-AI (University of Bristol, NVIDIA Grace Hopper superchips, approximately 5,000 Arm-based NVIDIA GH200 GPUs) and Dawn (University of Cambridge, Intel Gaudi 2 accelerators) — represents a significant industrial AI policy commitment, worth approximately £225 million. This infrastructure is designed to provide UK academic researchers and spinout companies with access to frontier-class compute without dependency on US commercial cloud providers, reducing strategic vulnerability in AI training capability. The UK’s Exascale supercomputer commitment (target: 2026) would further strengthen this position. Sovereign compute infrastructure is explicitly framed in the Action Plan as a national security and economic sovereignty asset, not merely a research facilitation measure.

    Future Directions (2026-2030)

    The AI policy landscape is in rapid transition, with several near-certain and several speculative developments expected over the 2026–2030 horizon. The overarching tension is between the accelerating pace of AI capability development and the structural inertia of governance institutions — a pacing problem that AI policy must solve rather than merely acknowledge.

  • Capability-based regulation: As algorithmic efficiency improvements make FLOP-per-training-run thresholds obsolete proxies for capability and risk (a model that achieves GPT-4-class performance with 100x fewer FLOPs should face equivalent obligations to one trained with 100x more), AI policy is expected to shift toward capability-based evaluation thresholds — defining obligations based on what an AI Model can demonstrably do (design biological or chemical weapons, autonomously acquire computational resources, generate child sexual abuse material, defeat human oversight mechanisms) rather than how it was trained. The network of national AI Safety Institutes (UK, US, Japan, Singapore, EU AI Office) is actively developing capability evaluation methodologies that could serve as the technical foundation for such regulation.

  • AI liability frameworks: The EU AI Liability Directive (in trilogue as of mid-2026) will establish fault-based and no-fault liability regimes for AI-caused harm, complementing the EU AI Act’s ex-ante conformity assessment obligations with ex-post compensation mechanisms for victims. Proposed provisions include a presumption of causality where it is excessively difficult for claimants to establish fault by a high-risk AI system, and mandatory disclosure of training data and model documentation to support liability claims. UK courts have begun applying existing product liability law (Consumer Protection Act 1987), negligence doctrine, and discrimination law to AI-caused harms without specific legislation, generating a body of case law that will inform the eventual UK AI Bill.

  • Interoperability and mutual recognition: Negotiation of mutual recognition agreements between major AI regulatory jurisdictions (EU, UK, US, Japan, Singapore, Canada) for Conformity Assessment results would reduce compliance duplication for multinational AI developers by allowing a conformity assessment conducted in one jurisdiction to satisfy obligations in another. The Seoul Declaration’s call for interoperable governance frameworks is being operationalised through bilateral evaluation information-sharing between the UK AI Security Institute and the US AI Safety Institute, with the EU AI Office expressing interest in joining this network.

  • Compute Governance institutionalisation: International bodies (OECD, G7, or a new dedicated intergovernmental body analogous to the Nuclear Suppliers Group for AI hardware) are expected to develop frameworks for monitoring and coordinating Compute Governance measures — including harmonised export control lists for AI Chips and HBM memory, training-run registries enabling governments to know which organisations are training models above specified capability thresholds, and standards for sovereign compute infrastructure. The transition from unilateral US BIS export controls to a multilateral framework involving allied jurisdictions (EU, UK, Japan, South Korea, the Netherlands) is a major policy challenge for the 2026–2030 period.

  • AI in public services and democratic accountability: Governments are expected to accelerate AI adoption in healthcare (diagnostic support, administrative burden reduction, drug development), welfare administration (fraud detection, needs assessment, benefits processing), justice (legal research, case prediction, case management), tax and regulatory compliance, and education (adaptive learning, automated assessment). Each application domain requires AI policy frameworks calibrated to democratic accountability requirements, Human Oversight obligations, Transparency to affected citizens, and protection against Bias Mitigation failures in high-stakes administrative decisions. The UK Government’s AI Opportunities Action Plan and equivalent programmes in the EU, US, Australia, and Singapore are driving rapid expansion of government AI deployment subject to governance frameworks that have not yet been legislated.

  • Frontier AI institutional infrastructure: The UK AI Security Institute (UKASI), the US AI Safety Institute, and counterparts in Japan, Singapore, South Korea, Australia, and the EU (the European AI Office) are establishing bilateral evaluation frameworks and information-sharing protocols for frontier AI Model assessments, potentially evolving into a more formal international institution. Precedents from nuclear (IAEA), chemical weapons (OPCW), and financial regulation (FSB, BIS) suggest that institutionalisation of international AI oversight is feasible but will require significant political investment in treaty-level commitment.

  • AI Alignment as regulatory target: As AI systems become more capable and more autonomously deployed in Agentic Workflow contexts — browsing the web, executing code, managing files, interacting with external services on users’ behalf — AI policy may increasingly target alignment properties directly. Requirements that developers demonstrate through standardised evaluation that systems do not pursue harmful objectives, resist Human Oversight, or engage in systematic deception could become regulatory baselines rather than voluntary responsible scaling commitments. The EU AI Office’s Code of Practice for GPAI models (2025) includes provisions on “systemic risk from model behaviour” that point in this direction.

  • Responsible AI and sustainability co-regulation: The environmental footprint of AI model training and inference — energy consumption, water for data centre cooling, e-waste from frequent hardware refresh cycles — is attracting increasing regulatory attention. The UK Environment Act and EU sustainability reporting requirements are beginning to capture data centre AI workloads; AI-specific energy and carbon disclosure requirements are expected to materialise as AI model training energy consumption (GPT-4 training reportedly consumed approximately 50 GWh; frontier 2025–2026 training runs are estimated to require multiples of this) becomes visible in corporate sustainability reporting.

  • Global South inclusion and AI governance diversity: Current AI policy frameworks are predominantly designed by OECD economies whose interests (protecting domestic AI industries, managing risks from powerful frontier models produced within their borders) differ substantially from those of lower-income countries (accessing AI benefits without building domestic frontier capability, resisting regulatory frameworks that advantage incumbent producers, protecting data sovereignty). UNESCO’s AI Ethics Recommendation (2021, 193 member states) and ITU AI for Good are the most globally inclusive AI governance fora; the G7 and OECD remain structurally OECD-centric. Meaningful Global South participation in AI standard-setting — at ISO/IEC JTC1 SC42, at the AI Summit series, and in treaty-level negotiations — is a governance imperative that the 2026–2030 period must address to avoid a fragmented global AI governance architecture in which standards reflect only the interests of powerful incumbent states.

  • Generative AI and intellectual property: The intersection of AI policy with Copyright Law, Intellectual Property rights, and data protection (specifically GDPR Article 6 lawful bases for training data processing) remains deeply contested. The UK Government’s March 2026 decision not to introduce immediate copyright reforms leaves substantial uncertainty for both AI developers (who face infringement litigation risk) and rights-holders (who lack clear compensation mechanisms). The EU AI Act’s transparency requirement for training data summaries is a partial solution; a comprehensive licensing framework — whether voluntary collective licensing, statutory licensing, or regulatory safe harbours — is expected to emerge within the 2026–2030 window across major jurisdictions.

    Research and Literature

    1. Jobin, A., Ienca, M., and Vayena, E. (2019). “The global landscape of AI ethics guidelines.” Nature Machine Intelligence 1, 389–399. Systematic survey of 84 AI ethics policy documents across 36 countries; identified convergence on principles and divergence on implementation.
    2. Dafoe, A. (2018). “AI Governance: A Research Agenda.” Future of Humanity Institute, University of Oxford. First systematic mapping of AI governance as a scholarly and policy field.
    3. Floridi, L., Cowls, J., Beltrametti, M., et al. (2018). “An Ethical Framework for a Good AI Society: Opportunities, Risks, Principles, and Recommendations.” Minds and Machines 28, 689–707. Synthesised four AI ethics principles widely cited in policy frameworks.
    4. O’Neil, C. (2016). Weapons of Math Destruction: How Big Data Increases Inequality and Threatens Democracy. Crown Books. Seminal popular account of algorithmic decision-making harms; influenced early AI policy debates.
    5. OECD. (2019, revised 2024). “Recommendation of the Council on Artificial Intelligence.” OECD Legal Instruments. The most widely adopted voluntary AI policy framework; provides foundational principles for OECD AI Principles.
    6. NIST. (2023). “Artificial Intelligence Risk Management Framework (AI RMF 1.0).” National Institute of Standards and Technology, US Department of Commerce. US voluntary framework organising AI risk governance around Govern, Map, Measure, Manage functions.
    7. European Parliament and Council. (2024). “Regulation (EU) 2024/1689 — AI Act.” EUR-Lex. The world’s first comprehensive AI statute; defines risk tiers, GPAI obligations, prohibited practices, and conformity assessment requirements.
    8. Bletchley Declaration. (2023). “AI Safety Summit: Bletchley Declaration.” UK Government (DSIT). International agreement on frontier AI safety signed by 28 countries, committing to collaborative evaluation and information-sharing.
    9. Council of Europe. (2024). “Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law.” Council of Europe Treaty Series No. 225. First legally binding international AI treaty; applies to public-sector AI in signatory states.
    10. UNESCO. (2021). “Recommendation on the Ethics of Artificial Intelligence.” UNESCO General Conference, 41st Session. Adopted by 193 member states; most globally inclusive AI ethics framework; influences Global South AI policy.
    11. ISO/IEC. (2023). “ISO/IEC 42001:2023 — Information Technology — Artificial Intelligence — Management System.” International Organization for Standardization. Auditable AI management system standard, analogous to ISO 27001 for information security.
    12. Cath, C., Wachter, S., Mittelstadt, B., Taddeo, M., and Floridi, L. (2018). “Artificial Intelligence and the ‘Good Society’: the US, EU, and UK approach.” Science and Engineering Ethics 24, 505–528. Comparative analysis of AI governance approaches across major jurisdictions.
    13. Hadfield-Menell, D., and Hadfield, G. (2019). “Incomplete Contracting and AI Alignment.” Proceedings of the 2019 AAAI/ACM Conference on AI, Ethics, and Society. Analyses the limits of contractual mechanisms for ensuring AI Alignment in policy contexts.
    14. Veale, M., and Borgesius, F. Z. (2021). “Demystifying the Draft EU Artificial Intelligence Act.” Computer Law Review International 22(4), 97–112. Legal analysis of the EU AI Act’s risk categorisation, scope, and enforcement mechanisms.
    15. Ada Lovelace Institute. (2022). “Algorithmic Impact Assessment: A Case Study in Healthcare.” Ada Lovelace Institute. UK-focused case study on implementing Impact Assessment for AI in NHS contexts.
    16. Raji, I. D., Smart, A., White, R. N., et al. (2020). “Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing.” FAccT 2020. Framework for organisational AI auditing; influenced AI Audit methodologies in policy compliance.
    17. Whittlestone, J., Nyrup, R., Alexandrova, A., and Cave, S. (2019). “The Role and Limits of Principles in AI Ethics: Towards a Focus on Tensions.” AIES 2019. Analysis of tensions between AI ethics principles as operationalised in policy frameworks.
    18. Hadfield, G. K. (2023). “Rules for a Flat World: Why Humans Invented Law and How to Reinvent It for a Complex Global Economy.” Oxford University Press. Legal theory of regulatory design applicable to AI policy institution-building.
    19. UK Government. (2023). “A Pro-Innovation Approach to AI Regulation.” DSIT White Paper CP 815. Defines UK’s principles-based, sector-led AI regulatory strategy, distinguishing from the EU AI Act’s horizontal approach.
    20. Seoul AI Safety Summit. (2024). “Seoul Ministerial Statement for Advancing AI Safety, Innovation and Inclusivity.” Republic of Korea Government. Successor to Bletchley; established AI Safety Institute network and extended frontier model voluntary commitments.
    21. G7 Digital and Technology Ministerial. (2026). “G7 Digital and Technology Ministerial Declaration.” Italian G7 Presidency. Reaffirmed Hiroshima Process and Code of Conduct; addressed AI in critical infrastructure and Compute Governance.
    22. Novelli, C., Casolari, F., Rotolo, A., Taddeo, M., and Floridi, L. (2024). “Generative AI in EU Law: Liability, Privacy, Intellectual Property, and Cybersecurity.” AI and Society. Analyses intersections between EU AI Act, GDPR, Intellectual Property, and Cybersecurity Policy for Generative AI systems.
    23. Ryan, M., and Stahl, B. C. (2021). “Artificial intelligence ethics guidelines for developers and users: clarifying their content and normative implications.” Journal of Information, Communication and Ethics in Society 19(1), 61–86. Content analysis of AI ethics guidelines adopted into policy frameworks.
    24. Mittelstadt, B., Russell, C., and Wachter, S. (2019). “Explaining Explanations in AI.” FAccT 2019. Analyses Explainable AI in policy contexts; distinguishes technical explanation from accountability.
    25. European AI Office. (2025). “Code of Practice for General-Purpose AI Models.” European Commission. Operationalises EU AI Act GPAI obligations through industry co-design; covers capability evaluation, safety reporting, and Red Teaming requirements for frontier models.
    26. UK AI Safety Institute. (2024). “Evaluations for Advanced AI: A Summary of the UK AISI’s Approach.” Department for Science, Innovation and Technology. Describes frontier model evaluation methodology, including dangerous capability assessments, conducted by the AISI on models from Anthropic, Google DeepMind, Meta, OpenAI, and others.
    27. Conseil d’État. (2026). “Artificial Intelligence Regulation: From Risk to Governance.” Conseil d’État, French Republic. Comparative analysis of EU, US, UK, and Chinese AI regulatory strategies; influential in Omnibus amendment discussions.
    28. ITU. (2025). “Annual AI Governance Report 2025: Steering the Future of AI.” International Telecommunication Union. Comprehensive survey of global AI governance developments, with particular attention to Global South inclusion and ITU AI for Good.

Provenance