AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws
A recent position paper published on arXiv (2608.14568) contends that AI governance should rely on interoperability protocols similar to ISO standards rather than solely on legislation. It points out the disjointed regulatory environment shaped by laws specific to different jurisdictions and voluntary frameworks, such as the EU AI Act, China’s algorithm governance, and the U.S. NIST AI Risk Management Framework. Citing the effective implementation of the GDPR through standards like ISO 27001 and Privacy by Design, the authors advocate for the creation of standardized AI 'nutrition labels' that include consistent metrics for bias, energy consumption, and data origin to aid compliance across borders. The paper stresses the importance of machine-readable risk communication as AI technologies become integral to global infrastructure, arguing that such protocols would enhance governance effectiveness, lessen compliance challenges, and improve transparency. This position paper, which presents an argument rather than new empirical findings, is accessible on arXiv as a new submission.
Key facts
- Paper ID: arXiv:2608.14568
- Published on arXiv
- Argues for ISO-like interoperability protocols for AI governance
- Criticizes fragmented regulatory landscape
- References EU AI Act, China's algorithm governance, NIST AI Risk Management Framework
- Cites GDPR as successful model operationalized through ISO 27001 and Privacy by Design
- Proposes AI 'nutrition labels' with metrics for bias, energy usage, data provenance
- Focuses on cross-border risk communication
Entities
Institutions
- arXiv
- EU
- China
- NIST
- ISO
Locations
- United States
- China
- European Union