← Latest papers
🤖 AI

Mapping General-Purpose AI Governance in Twenty AI Middle-Power Jurisdictions

This paper maps the GPAI governance frameworks of twenty middle-power jurisdictions, revealing that while they broadly converge on regulatory forms across key accountability areas, they significantly diverge in enforcement power, with most relying on non-binding measures, pre-existing application-layer mandates, and observational capacities rather than imposing binding duties on model developers.

Original authors: Josephine Schwab, Nathan Naidoo, Ferruccio Barazzutti, Sheryn Lee, Caio Vieira Machado

Published 2026-08-21
📖 6 min read🧠 Deep dive

Original authors: Josephine Schwab, Nathan Naidoo, Ferruccio Barazzutti, Sheryn Lee, Caio Vieira Machado

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where the most powerful artificial intelligence systems are built in just two places, yet their effects ripple across every nation on Earth. These systems, known as general-purpose AI, are not simple tools designed for a single task like sorting mail or recognizing faces. Instead, they are vast, flexible engines capable of learning almost anything, from writing code to simulating biological processes. Because they are so adaptable, they carry unique risks: they could be used to create dangerous weapons, launch cyberattacks, or behave in ways that humans cannot stop. While the companies building these systems are concentrated in a few countries, the rest of the world must still figure out how to live with them. This is the challenge facing what researchers call "AI middle-powers": nations that do not build these frontier models themselves but must still regulate how they are used, sold, and monitored within their borders.

A team of researchers set out to map how twenty of these nations are handling this problem. They did not look at broad political statements or vague promises. Instead, they dug into the actual laws, regulations, and official guidance documents to see exactly what rules have been written. They focused on four specific areas where safety must be ensured: checking for big-picture risks before a system is released, testing and verifying what the system can actually do, banning dangerous uses or capabilities, and reporting serious accidents when they happen. By reading the fine print of hundreds of documents, they built a detailed picture of the global landscape of AI governance.

What they found was a story of form without force. Across the twenty nations studied, there is a clear agreement on the shape of the rules. Almost every country is trying to address the same four safety areas. They are all talking about risk assessments, testing, bans, and reporting. However, they are failing to make those rules stick. The researchers discovered that while many countries have written down these requirements, very few have turned them into binding laws that can actually be enforced. In fact, only about 22 percent of the rules they found are written in hard law. The rest are soft guidelines, strategies, or voluntary codes that companies can choose to ignore. Even more striking, when countries do pass binding laws, they often do not define what a "general-purpose AI" actually is. They create rules for a category of technology without clearly saying what that category includes. This leaves a gap where a company might argue that its powerful new model does not fit the definition and therefore does not need to follow the rules.

The way these nations enforce their rules reveals another layer of complexity. Most of the time, the rules are not aimed at the companies that build the AI models. Instead, the laws target the people who use the models, the platforms that host them, or the government agencies that buy them. This happens because the countries in the study do not host the companies that build the most advanced AI. They cannot easily force those foreign builders to change their code or submit to inspections. So, they try to control the technology by regulating how it is deployed in their own markets. For example, a country might require a bank to test an AI tool before using it, or a hospital to report if an AI makes a mistake. While this approach is practical, it means the safety net is often woven around the application of the technology rather than the technology itself.

The researchers also looked at who is doing the checking. In many cases, the bodies responsible for testing AI are the same ones that were created for other purposes, like regulating finance or protecting data. These existing agencies are being asked to take on AI oversight without always having the specific technical power to do so. Furthermore, the new safety institutes that some countries have built to evaluate AI often lack the authority to stop a dangerous system if they find one. They can measure the risk and publish a report, but they cannot force the developer to fix the problem. It is as if a fire department could measure how hot a building is and write a report about the danger, but had no power to order the owner to install sprinklers or shut down the building.

Perhaps the most significant finding concerns the reporting of accidents. When a serious harm occurs, who is supposed to tell the authorities? The study found that half of the nations surveyed have no rule at all requiring anyone to report a serious AI incident. In the countries that do have such rules, the instructions are often incomplete. A rule might say "report an accident," but fail to say who to report it to, how quickly it must be done, or what happens if no one reports it. Without these four pieces—the recipient, the trigger, the deadline, and the consequence—a reporting rule is just a suggestion. The researchers noted that this leaves a blind spot: if an AI system fails in a way that causes no immediate data breach or financial loss, it might never be reported, even if the long-term damage is severe.

The paper also challenged the idea that having more laws means having better safety. Some countries have produced dozens of documents and guidelines, creating a thick layer of paperwork. Yet, when the researchers looked at the legal power behind those documents, they found that many were non-binding. Conversely, a few countries with fewer documents had passed strict, enforceable laws. The study showed that the number of rules a country has is a poor indicator of how safe its AI environment actually is. What matters is whether the rules are written in a way that can be enforced and whether they reach the right people.

In the end, the map drawn by this research shows a world that is trying to catch up to a technology that is moving faster than its laws. The twenty nations have agreed on the vocabulary of safety—they all know they need to assess risks, test systems, ban bad uses, and report accidents. But they have not yet agreed on the force of those words. The rules are often vague, the definitions are missing, and the enforcement mechanisms are weak. The researchers suggest that before the world can agree on a single set of international rules, these individual nations need to close the gaps in their own systems. They need to decide exactly what they are regulating, give their safety agencies the power to act, and ensure that when something goes wrong, someone is actually held accountable. Until then, the global safety net for artificial intelligence remains full of holes, woven from good intentions but lacking the strength to hold the weight of the technology it is meant to protect.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →