One Technology, Many Rulebooks, The Fragmentation of Global AI Governance


Artificial intelligence may be global, but the rules governing it are anything but.
An AI system can be developed in the United States, use infrastructure in the Middle East, serve customers in Europe, draw on data from several continents and make decisions affecting people around the world.
Yet each of those places may have a very different idea of what “responsible AI” means.
As of August 2026, there is no single global model for AI governance. Instead, a patchwork is emerging: legally binding risk categories in the European Union; a regulator-led approach in the UK; federal-state tension in the United States; stronger state-directed controls in China; innovation-led frameworks in the Gulf; and yet different models in Singapore, Japan and across Africa. This fragmentation matters because it reveals something deeper.
AI governance is not simply about regulating a technology. It is about deciding what societies value, what risks they are prepared to accept and what conditions must be met before an AI system deserves our trust.
Europe: regulating according to risk
The European Union has taken perhaps the clearest legislative approach. The EU AI Act creates a horizontal legal framework applying across industries and classifies AI uses according to levels of risk.
Some practices are prohibited. High-risk systems face requirements relating to areas such as risk management, documentation, human oversight and monitoring. General-purpose AI models also have specific obligations, while transparency rules cover areas such as interaction with AI and AI-generated content.
The Act entered into force in 2024 and has been introduced in stages. Its general application began on 2 August 2026, although some high-risk provisions have later application dates. The European Commission's July 2026 guidance, for example, sets out how the Act's Article 50 transparency requirements should now be applied.
Europe's approach reflects a particular philosophy: the greater the potential impact of an AI system on people and society, the stronger the governance requirements should become.
That makes concepts including fundamental rights, accountability, transparency and human oversight central to the regulatory architecture. But travel across the Channel and the philosophy already begins to change.
The UK: regulate the context, not AI as a single category
The United Kingdom has so far resisted creating an EU-style horizontal AI law. Its approach has instead centred on five cross-sector principles, safety and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress, with existing regulators expected to interpret those principles within their own domains.
That means an AI system used in banking may be governed differently from one used in healthcare, employment or communications because different regulators, laws and risks are involved. The government's original framework explicitly described this as a context-specific, pro-innovation and risk-based approach.
The UK has also put significant emphasis on understanding the capabilities and risks of advanced AI through its AI Security Institute. The Institute tests frontier systems, studies emerging capabilities and provides evidence intended to inform government policy. In 2026, the UK has continued developing international AI security partnerships rather than replacing its existing approach with a single overarching AI Act.
Attempts have been made in Parliament to introduce a more centralised regulatory structure. Lord Holmes's Artificial Intelligence (Regulation) Bill proposed an AI Authority, regulatory principles, sandboxes and auditing arrangements. However, the 2024–26 parliamentary session ended before the Bill progressed beyond first reading.
The difference with the EU is significant.
Europe asks, in effect: which legal risk category does this system fall into? The UK is more likely to ask: where is this system being used, what harm could arise there, and which existing regulator is responsible?
The United States: fragmentation within fragmentation
The United States presents an even more complicated picture. There is still no EU-style comprehensive federal AI Act. At federal level, the current administration has emphasised AI leadership, innovation, national security and reducing regulatory barriers. Its March 2026 National AI Legislative Framework called on Congress to create a uniform national approach and explicitly argued against a conflicting patchwork of state AI legislation.
This is not an abstract concern. States have been developing their own AI laws and requirements. California, for example, enacted the Transparency in Frontier Artificial Intelligence Act, SB 53, in 2025. It requires large frontier developers to publish safety frameworks, assess catastrophic risks, report critical safety incidents and provide whistleblower protections. The law took effect in January 2026.
At the same time, the federal government has actively sought to restrict state rules it considers excessively burdensome. A December 2025 Executive Order directed the creation of an AI Litigation Task Force to challenge certain state AI laws and called for a national legislative framework capable of pre-empting conflicting state regulation. The Federal Trade Commission was still taking public comments on part of that agenda in summer 2026.
The result is governance fragmentation inside one country. A company operating across the United States can face federal policies favouring relatively light national regulation while simultaneously encountering stronger requirements in individual states. This illustrates one of the central challenges of global AI governance: even when governments agree that AI should be safe and trustworthy, they may disagree substantially about who should set the rules and how binding those rules should be.
China: governance through state oversight, security and content controls
China has developed another distinctive model. Rather than creating an exact equivalent of the EU AI Act, China has introduced targeted rules governing particular technologies and services, including algorithmic recommendations, deep synthesis technologies and generative AI.
Its Interim Measures for the Management of Generative Artificial Intelligence Services apply to generative AI services provided to the public in China. The measures combine support for AI innovation with requirements concerning national security, personal information, discrimination, intellectual property, transparency and the reliability of generated content. They also connect AI governance to mechanisms such as security assessment and algorithm registration.
China has since moved further on AI-generated content. Rules effective from 1 September 2025 require providers to apply explicit and implicit labels to certain AI-generated and synthetic content. Metadata can include information identifying content as AI-generated and identifying the provider. Platforms also have responsibilities when distributing such material.
China therefore demonstrates a model where AI governance, information governance and national security are closely intertwined. This differs significantly from the rights-based framing of the EU, the regulator-led approach of the UK and the current innovation-led federal agenda in the United States.
The Middle East: governance as part of an AI growth strategy
Another model is emerging in the Gulf. Countries including the United Arab Emirates and Saudi Arabia are investing heavily in AI while building governance around national strategies, ethical principles and institutional frameworks.
The UAE's Charter for the Development and Use of Artificial Intelligence, for example, sets out principles covering responsible AI, privacy, data security and equitable access while placing AI within the country's ambition to become a global technology hub.
Its 2026 international AI policy similarly combines progress, collaboration, ethics, sustainability and safety with an explicit ambition to strengthen the UAE's global position in AI.
Saudi Arabia has taken its own approach through the Saudi Data and Artificial Intelligence Authority, SDAIA. Its AI Ethics Principles and AI adoption frameworks place responsible use alongside the goals of Saudi Vision 2030 and national AI adoption. SDAIA describes its principles as a national reference for both public and private-sector organisations.
The important distinction is emphasis. In Europe, regulation is frequently framed around controlling risk to rights and safety. In the Gulf, governance is often embedded within a wider programme of accelerated adoption, investment and economic transformation.
Safety and ethics remain important, but governance is positioned as an enabler of innovation as much as a constraint on it.
Singapore: practical governance rather than a giant rulebook
Singapore offers another useful contrast. Rather than relying primarily on comprehensive legislation, Singapore has developed practical governance frameworks and testing tools intended to help organisations translate principles into real systems.
In January 2026 it launched what it describes as the world's first comprehensive Model AI Governance Framework for Agentic AI.
The framework recommends organisations define what agents are allowed to do, limit their access to tools and data, establish meaningful points for human intervention, implement technical controls and ensure accountability remains with humans.
An updated version released in May incorporated feedback from more than 60 organisations and included real-world examples of governing agentic systems. One case study uses tiered risk levels so low-risk reversible actions can be automated, moderate-risk actions require human approval and high-risk actions are prohibited entirely.
Singapore explicitly describes its model as a practical, balanced approach: guardrails, but room for innovation.
This is governance through tools, testing, implementation guidance and collaboration, rather than primarily through a single binding AI statute.
Japan: promote AI, govern risk through a mixture of law and guidance
Japan provides yet another model. Its 2025 law on promoting the research, development and use of AI created an AI Strategy Headquarters and a national planning framework, but was deliberately designed as a promotional rather than heavily prescriptive regulatory law. Parliamentary discussions explicitly contrasted Japan's approach with the EU's more comprehensive regulation.
Japan continues to rely substantially on guidance and existing legislation. Its AI Guidelines for Business were updated again to version 1.2 in March 2026.
Japan therefore occupies a position somewhere between hard law and soft governance: central national coordination combined with strong emphasis on voluntary implementation, existing legislation and innovation.
Africa: governance shaped around development and inclusion
The African Union's approach introduces another important dimension. Its Continental Artificial Intelligence Strategy, endorsed in 2024, calls for an Africa-centric approach that is ethical, responsible and equitable while emphasising AI's potential role in economic development, healthcare, agriculture, education and the goals of Agenda 2063.
This matters because global AI governance debates can easily become dominated by the priorities of jurisdictions already leading AI development. The African Union's strategy makes capacity, infrastructure, skills, inclusion and equitable access part of the governance conversation. In other words, trustworthy AI is not only about preventing harmful systems. It can also be about ensuring societies have the ability to participate in and benefit from AI at all.
Different laws, but surprisingly familiar principles
Despite all this fragmentation, there is also an interesting point of convergence. Look beneath the institutional structures and many familiar concepts reappear:
Safety, Transparency, Accountability, Fairness, Human oversight, Risk Management, Privacy, Security.
UNESCO's Recommendation on the Ethics of Artificial Intelligence provides perhaps the clearest evidence of this common ground. Adopted by 193 Member States in 2021, it sets out principles including human rights, fairness, transparency, safety and human oversight.
So the world does not necessarily disagree on every ingredient of trustworthy AI.
The disagreement is often about how those ingredients should be interpreted, prioritised, implemented and enforced. And that distinction is crucial.
The real challenge for organisations
Imagine an organisation deploying an AI-supported decision system internationally.
In Europe, it may need to determine whether that application falls within an AI Act risk category.
In Britain, it may need to identify the relevant sector regulator and existing legal obligations.
In the United States, it may have to consider both federal policy and state-specific legislation.
In China, different obligations may arise concerning content, algorithms, security or generated information.
In the Gulf, national ethical and AI adoption frameworks may become important.
Elsewhere, governance might depend more heavily on voluntary frameworks, standards or existing data and consumer law.
The organisation therefore faces a difficult question: Which definition of trustworthy AI should it use? The answer cannot simply be “whatever is legal”. Compliance is essential, but trust is broader than compliance. A system could satisfy the minimum legal requirements in a jurisdiction while still creating concerns for its users around fairness, explainability, privacy, reliability or human control. Equally, different stakeholders may make very different judgements about the same system. That is precisely where the work of THEMIS 5.0 becomes relevant.
From fragmented governance to contextual trust
THEMIS starts from the idea that trustworthiness cannot be reduced to one universal score or checklist. AI systems operate within socio-technical environments involving technology, organisations, users, data, decisions, values and real-world consequences.
THEMIS therefore places people and context at the centre of assessing trustworthiness.
Our aim is to help organisations understand what matters in a particular AI application, evaluate relevant risks and requirements, and identify where improvements are needed.
The Trustworthiness Optimisation Process (TOP) provides a structured methodology for doing this across the AI lifecycle.
TOP begins by identifying the socio-technical context and stakeholder requirements. It then assesses trustworthiness and risk, explores mitigation strategies and supports improvements and continuous monitoring.
Importantly, THEMIS does not present this simply as another compliance framework. Its work focuses on empowering people and organisations to make informed judgements about whether an AI system is trustworthy within its real operating environment.
That distinction may become increasingly valuable as governance fragments.
Laws will differ. Regulators will differ. Cultures and political priorities will differ. Risk tolerances will differ. But organisations will still need practical ways of asking:
Who is affected by this system?
What matters to them?
What could go wrong?
How transparent should the system be?
Where should human oversight occur?
What evidence would justify trusting its decisions?
And how should that trustworthiness change as the system, its environment and its regulatory obligations evolve?
Perhaps global AI governance will never be completely uniform
The instinctive response to regulatory fragmentation is often to call for harmonisation.
Some harmonisation is clearly valuable. Common standards can reduce duplication, support international trade and make assurance easier. But complete uniformity may be unrealistic.
AI is being introduced into societies with different legal traditions, political systems, economic priorities, cultures and attitudes towards risk. That inevitably influences the governance structures those societies create.
The challenge may therefore not be to build one rulebook for the entire world. It may be to create enough shared language, evidence and methods that trustworthy AI can be meaningfully assessed across different rulebooks. This is where projects such as THEMIS have an important role to play. Because in a fragmented governance landscape, trustworthy AI cannot simply mean following one set of rules. It means being able to understand an AI system in context, demonstrate how its risks are being managed, explain why its decisions should be relied upon and continually reassess whether the conditions for trust still hold.
The future of AI governance may be fragmented. The challenge is making sure trust does not fragment with it.
Fragmentation of Global AI
Fragmentation of Global AI




Comments