Intelligence

ai

Position: AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws

Source
arXiv — Computers and Society
Published
Last verified
19 Aug 2026
Confidence
High
Evidence
Original document retained
Reading time
1 min
Country
International
Relevant to
Policy & Regulation, Risk & Compliance, Technology & Data, Research & Evidence, Board & Governance

Executive summary

What happened, and why should leadership care?

As Artificial Intelligence (AI) systems increasingly integrate into critical global infrastructure, the current landscape of AI governance is fragmented by jurisdiction-specific laws and voluntary frameworks. This fragmentation hinders effective oversight. A recent analysis argues that AI governance requires a shift from solely relying on laws to adopting ISO-like interoperability protocols that facilitate standardized, machine-readable risk communication across international borders, drawing parallels with the operationalization of GDPR through standards like ISO 27001.

Why this matters

Why is this strategically important?

The fragmentation of AI governance poses a significant challenge to managing risks associated with AI systems integrated into critical infrastructure. Adopting internationally recognized, interoperable standards would enable consistent risk communication and management, fostering trust and efficiency while mitigating regulatory compliance complexities for multinational operations.

Key insights

What should be noted from the evidence?

  • AI systems are becoming deeply integrated into critical global infrastructure, intensifying the need for robust governance frameworks.
  • Current AI governance approaches are fragmented, stemming from jurisdiction-specific laws (e.g., EU AI Act, China's algorithm governance) and voluntary frameworks (e.g., NIST AI RMF).
  • The analysis advocates for AI governance to be built on ISO-like interoperability protocols, rather than solely on laws.
  • Such protocols should enable standardized, machine-readable risk communication across borders.
  • The success of GDPR, operationalized through standards like ISO 27001, is cited as a precedent for this approach.

Evidence and confidence

How far can this assessment be trusted?

High confidence. Named institution, original document retained and analysis corroborated.

Analysis is prepared editorially by Aziz Shuaib Ausi. The original publication remains the authoritative record, and executive judgement remains entirely human.

Source

Where does this originate?

Reported by arXiv — Computers and Society · International. This briefing summarises the publication for executive use; the document itself is not reproduced here.

Read the original publication