AI governance is the field that asks who decides what AI systems may do, how that decision is enforced, and which institutions bear the loss when it fails. Different governance modes give different answers to those questions. They are treated as discrete concepts because the modes interact — often conflicting, sometimes complementing one another — but do not reduce to a single mode. This page serves as the landing point for references to "AI governance" in the abstract and indexes the mode-specific pages rather than duplicating them.
Governance modes
Each mode locates the decision in a different institution and enforces it through a different instrument.
| Governance mode | What it is | Who's the locus | Page |
|---|---|---|---|
| Capability-threshold governance | Frontier-lab voluntary frameworks (Anthropic RSP, OpenAI Preparedness, Google FSF) gate model release on internal evaluations against pre-committed capability thresholds. | Frontier labs themselves; standards bodies as informal arbiters. | AI Safety Cases and Frameworks |
| Pre-release vetting | Government-or-government-adjacent body (CAISI, AISI, third-party evaluator) reviews a frontier model before release. May be voluntary (current) or mandatory (proposed). | Federal regulator (US: CAISI); UK AISI; EU AI Office. | AI Pre-Release Vetting |
| Procurement-driven governance | Federal/enterprise procurement requirements (FedRAMP, IL5/IL6/IL7, GSA OneGov USai) effectively gate which models reach the most consequential deployments. The governance mode tightening fastest in 2026. | Federal procurement agencies (DOD, GSA, DHS); enterprise procurement (PE-backed deployment JVs). | Procurement-Driven AI Governance |
| Compute governance | Restrictions on which entities may purchase, rent, or deploy frontier compute. Implemented via export controls (BIS), KYC requirements on chip sales, and proposed compute-disclosure regimes. | BIS; commerce departments; chip vendors. | Compute Governance |
| Standards-and-attestation governance | Formal standards (ISO/IEC 42001, ISO/IEC 42005, NIST AI RMF) that organizations adopt voluntarily or via regulatory reference. | Standards bodies (ISO, IEC, NIST); regulators that incorporate-by-reference. | Three-Lane Standards-Based AI Governance |
| Liability governance | Tort, product-liability, copyright, and consumer-protection law that shifts costs of AI failures back to deployers / developers / vendors. | Courts; state attorneys general; class-action plaintiffs. | AI Liability, AI Copyright Litigation — Analysis |
| Post-deployment monitoring | Ongoing audit, red-teaming, and incident reporting for deployed models. | Frontier labs (internal); third-party auditors; regulators that mandate disclosure. | Post-Deployment AI System Monitoring |
| Macro-prudential governance (emerging) | Treatment of frontier AI as a systemic financial-stability risk; central-bank stress-test categories; mandatory disclosure to financial regulators. | Central banks (Fed, ECB, BoE); IMF; national supervisors. | AI Macro-Prudential Policy |
| Industrial-policy governance | Industrial subsidies, tax credits, public-private partnerships, sovereign-AI initiatives that shape what gets built rather than restrict deployment. | Treasury / DOE / DOC; sovereign wealth funds; CHIPS Act-style appropriations. | Ai Industrial Policy (stub), America's AI Action Plan |
| Civil-liberties and rights governance | Specific protections (DSAR, right to explanation, anti-discrimination, child-safety, mental-health) enacted via consumer-protection law and human-rights frameworks. | State AGs; civil-rights agencies; FTC; international human-rights bodies. | AI and Civil Liberties, multiple state chatbot/AI-mental-health laws under the legislation/ folder |
| Workforce and labor governance | Rules on AI's role in hiring, firing, monitoring, and replacing workers. | DoL; NLRB; state labor commissions; collective-bargaining agreements; foreign equivalents. | AI Labor Disruption, Workforce Transparency Act (Warner-Budd, S. ____, 2026) |
How the modes interact
The modes are not independent; several pairs reinforce or substitute for one another.
Capability-threshold governance feeds pre-release vetting. When pre-release vetting becomes mandatory, lab-internal capability thresholds become the operative evidence the regulator inherits. Open Problems in Frontier AI Risk Management argues that the inheritance is fragile, because lab evaluations measure proxies for risk rather than risk itself.
Procurement-driven governance can substitute for pre-release vetting. A regulator without pre-release-vetting authority can still effectively gate deployment by conditioning federal procurement on a CAISI report. The May 2026 CAISI agreements with Google, Microsoft, and xAI are arguably this mode operating before the formal authority exists; the same month, the administration was reported to be drafting a 16-page executive order creating a pre-release vetting regime, with National Economic Council Director Kevin Hassett describing it as working "just like an FDA drug" (Source: nytimes.com; politico.com). See AI Pre-Release Vetting for the full sequence.
Compute governance and industrial policy target the same input from opposite directions. Export controls are the negative pole; chip subsidies and Stargate-style appropriations are the positive pole. Both target frontier compute.
Liability governance and standards governance reinforce one another. Adoption of ISO/IEC 42001 or NIST AI RMF gives deployers a defensible "I followed the standard" position in tort, and a standard's incorporation by reference into regulation makes the connection explicit. The Colorado rulemaking filed on August 11, 2026 is a worked instance: Rule 14 incorporates ISO/IEC 27566-1:2025 into the age-assurance rule and WCAG 2.2 into the communications rule, giving both standards binding force through a state consumer-protection regulation (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)).
Macro-prudential governance, if it materializes, overlays all of the above. If the IMF designation of May 7, 2026 — which named Claude Mythos preview and GPT-5.5-Cyber as macro-financial-risk vectors on the basis of offensive-cyber capability — propagates and central banks add AI-cyber to stress-test categories, every other governance mode gains a financial-stability overlay that operates in parallel. The ECB's May 8, 2026 statement that it was studying defenses against Mythos-powered cyberattacks is the first G7-central-bank-level response (Source: reuters.com); the propagation record is on AI Macro-Prudential Policy.
Proposals for an industry self-regulatory body
A distinct proposal has been advanced repeatedly through 2026: a body that sits between lab self-governance and statutory regulation, funded by industry and exercising delegated authority over frontier-model release. It has not been established, and the accounts of it differ on institutional model.
Demis Hassabis set out one version on July 14, 2026 in "A Framework for Frontier AI and the Dawning of a New Age," proposing an industry-funded US standards body modeled on FINRA: labs would voluntarily share frontier models up to 30 days before release for testing of dangerous cyber, biological, and deception capabilities, with the arrangement later becoming mandatory for US-market deployment of all frontier-class models, open or closed, regardless of origin. He said he had briefed the administration, fellow lab leaders, and European officials, targeted operation before year-end, and called the June 2026 freeze of Anthropic's models "a bit of a wake-up call" (Source: axios.com; A Framework for Frontier AI and the Dawning of a New Age (Hassabis, July 2026)).
Bloomberg reported on July 17, 2026 that the administration was weighing an industry-funded FINRA-like watchdog to vet frontier models for deception, bioweapon uplift, and malicious hacking, with labs voluntarily submitting models about 30 days before release, developed with Treasury Secretary Scott Bessent, reporting to the SEC, and under review by Chief of Staff Susie Wiles (Source: bloomberg.com).
Reporting published August 12, 2026 described Hassabis holding discussions with heads of other AI labs and Trump administration officials, including Bessent, about forming an independent industry safety entity to codify guardrails for developing artificial general intelligence, and likening the proposed body to the International Atomic Energy Agency rather than to FINRA. The discussions were said to have taken place in the weeks before he relinquished the Google DeepMind chief executive role. Only the opening of that report was retrievable, and the account is not corroborated elsewhere (Source: wsj.com).
The FINRA and IAEA analogies point at different institutions: FINRA is a domestic self-regulatory organization exercising delegated statutory authority over member firms, while the IAEA is an intergovernmental body operating a safeguards-and-inspection regime across states. Which analogy the reporting means is not resolved by the available sources.
Cross-jurisdictional comparison
The United States operates a layered structure combining federal voluntary measures (CAISI, frontier-lab RSPs), state mandatory measures (CA SB 53, the Colorado AI Act, the chatbot/AI-mental-health second wave), and emerging procurement gates. A preemption fight is active (xAI LLC v. Weiser (challenging the Colorado AI Act), the American Leadership in AI Act).
The state layer has since moved from statute to implementation. Colorado's Chatbot Safety Act and SB 26-189 were followed on August 11, 2026 by a proposed-rules package from the Department of Law covering automated decision-making technology and conversational AI services, filed under five separate grants of rulemaking authority of which only two are mandatory (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)). In that package, obligations expressed in statute are given operative content by an attorney general's regulations rather than by a legislature.
The European Union applies the AI Act, a risk-tiered horizontal regulation that constitutes the tightest binding regime on high-risk systems, with trilogue tensions over a high-risk delay during April–May 2026. Its transparency obligations are being operationalized through a code of practice rather than through direct rule text, a mode that sits between the standards-and-attestation and pre-release-vetting rows above.
The United Kingdom follows an AISI-led, light-touch regulatory approach, with the AI Security Institute serving as evaluator and a Microsoft pre-release-evaluation deal reached in April 2026. AISI's disclosure of security incident INC-2026-07-28-01 on August 4, 2026 is the first published account by a government evaluator of unsanctioned live-internet actions taken by models during evaluation, and supplies the only run-level denominators available for that behaviour (Incident Report: unsanctioned agent behaviour during cyber testing (AI Security Institute, August 2026)).
China operates a CAC-led approach through the Cyberspace Administration of China (CAC), using "Clean Up the Internet" enforcement campaigns, an AI-firing prohibition, and an AI-boyfriend edict, and works through a state-think-tank loop rather than industry-direct lobbying.
Singapore takes a practitioner-driven, institutional-rather-than-legislative approach, framed by Prime Minister Lawrence Wong's "protect every worker, not every job" formulation (Source: New Developments Log/2026-05-04.md).
See: EU vs. US AI Regulation: A Deep Comparison, US-China AI Competition: Different Races, Different Metrics, US AI Regulatory Approaches Compared.
Relationships
- depends-on: AI Safety Cases and Frameworks, AI Pre-Release Vetting, Compute Governance, Three-Lane Standards-Based AI Governance, Post-Deployment AI System Monitoring — the mode-specific concept pages this umbrella indexes.
- related: Regulating Under Uncertainty, Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation, Techno-Federalism, AI Political Cleavages, State-Level AI Regulation, AI Transparency, AI Antitrust, Dual-Use Frontier AI, Responsible AI Deployment, AI Policy (umbrella) — meta-concepts that shape how all governance modes operate.
- related: AI and Civil Liberties, AI and Tort Liability, AI Bias and Discrimination, AI and Privacy, AI and Democracy — substantive policy areas.
- related: NIST CAISI (Center for AI Standards and Innovation), UK AI Safety Institute (AI Security Institute), EU AI Office, National Institute of Standards and Technology (NIST), Cyberspace Administration of China (CAC), Chief Digital and Artificial Intelligence Office (CDAO), Cybersecurity and Infrastructure Security Agency (CISA) — regulator role, National Security Agency (NSA), International Monetary Fund (IMF), Garante per la protezione dei dati personali (Italy), Office of the Privacy Commissioner of Canada (OPC) — operational vehicles.
- related: American Civil Liberties Union (ACLU), Electronic Frontier Foundation (EFF), Access Now — civil-society participants.
- substrate-for: Hybrid Wiki + Embedding Retrieval — Architecture — the embedding-retrieval answering layer that operates over the governance coverage.
Sources
Most of this page's material is carried by the linked concept, entity, legislation, and litigation pages rather than sourced here directly. Claims specific to this page carry citations inline: the May 2026 draft executive order and the Hassett characterization (Source: nytimes.com; politico.com), the ECB response to the IMF designation (Source: reuters.com), the self-regulatory-body proposals (Source: axios.com; bloomberg.com; wsj.com), the Singapore framing (Source: New Developments Log/2026-05-04.md), and the source pages Open Problems in Frontier AI Risk Management, Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026), Incident Report: unsanctioned agent behaviour during cyber testing (AI Security Institute, August 2026) and A Framework for Frontier AI and the Dawning of a New Age (Hassabis, July 2026).
Confidence is medium rather than high: the governance-mode taxonomy is stable and multiply supported by the underlying pages, while the newest material — the self-regulatory-body proposals — is single-sourced and, in the August 12 case, retrievable only as a lede.