Position: AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws
This position paper argues that effective global AI governance requires a shift from fragmented, jurisdiction-specific laws to ISO-like interoperability protocols and standardized, machine-readable "nutrition labels" that enable cross-border risk communication, reduce compliance burdens for SMEs, and foster public trust without stifling innovation.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Artificial intelligence is no longer just a tool for sorting photos or recommending songs; it has become the invisible engine running the world's most critical systems, from hospitals diagnosing patients to banks approving loans. As these systems grow more powerful and complex, governments around the world have rushed to create rules to keep them safe and fair. However, these rules are currently written in different languages. One country might demand a specific type of safety check, while its neighbor requires a completely different set of documents, and a third might rely on voluntary guidelines that companies can choose to ignore. This patchwork of conflicting regulations creates a confusing maze for developers, making it difficult to deploy helpful technology across borders and leaving the public unsure if the systems they use are truly safe.
A team of researchers argues that the solution to this global confusion is not to write more laws, but to build a universal technical language that sits alongside them. In their view, relying solely on legal statutes is like trying to manage a global shipping industry by writing new treaties for every single port; it is slow, expensive, and prone to error. Instead, they propose creating a set of standardized, machine-readable "nutrition labels" for artificial intelligence. Just as food labels tell a consumer exactly what is in a package—calories, ingredients, and allergens—these new digital labels would tell regulators and users exactly what is inside an AI system: how much energy it consumes, where its training data came from, and how it performs on fairness tests.
The researchers, drawing on the history of how the world successfully managed data privacy, suggest that laws should set the goals, but technical standards should do the heavy lifting of proving those goals are met. They point to the European Union's General Data Protection Regulation, a strict privacy law that became effective globally not just because of the law itself, but because it was supported by practical, standardized security protocols that companies could actually follow. For artificial intelligence, they propose a similar path: a shared technical format that allows an AI system to carry its own proof of safety and compliance as it moves from one country to another. This would mean that a company in Seoul could create a single, standardized document that proves their system meets the safety requirements of the European Union, the United States, and China simultaneously, without having to rewrite their code or retrain their models for each region.
To make this idea work, the team designed a specific structure for these labels, which they call "AI risk manifests." These are not simple summaries written for humans to read; they are structured data files that computers can automatically scan and verify. The researchers identified three critical pieces of information that every label must contain. First, it must report on bias, showing how the system treats different groups of people and whether it makes unfair decisions. Second, it must track energy consumption, detailing the electricity used to train and run the model, which is a growing concern for the environment. Third, it must provide a clear history of the data used to teach the system, tracing its origins to ensure it was not stolen or manipulated. By standardizing how this information is reported, the researchers argue that regulators can stop guessing and start checking, using automated tools to verify that a system is safe before it is allowed to operate.
The paper also addresses a common fear: that creating such strict standards will stifle innovation or make it too hard for small companies to compete. The authors counter this by suggesting that the current fragmented system is actually the biggest barrier to innovation, as it forces small businesses to navigate a dozen different, incompatible rulebooks. Their proposed solution is to make the standards modular and flexible, allowing them to evolve as the technology changes, much like software updates. They envision a system where the core rules remain stable, but specific details can be adjusted as new types of AI emerge. This approach, they argue, would lower the cost of compliance for everyone, allowing smaller players to enter the market while giving large corporations a clear path to operate globally.
Ultimately, the researchers are calling for a shift in how the world thinks about governing technology. They believe that while laws are necessary to define what is right and wrong, they are not enough on their own to ensure that complex, fast-moving systems behave safely. The real work of safety, they suggest, happens in the technical details—the metrics, the data logs, and the verification steps. By building a shared, machine-readable language for these details, the world can move from a state of regulatory confusion to one of global cooperation, where trust is built not on promises, but on verifiable facts that travel with the technology itself.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.