How the World Is Governing AI: What Every Board Needs to Know | Part 1

From principles to penalties, the global regulatory landscape is taking shape. Here is what it means for your organisation.

Karl George MBE · Founder, The Governance Forum & Governance AI

May 2026

If you sit on a board or lead an organisation that uses AI, you need to understand the regulatory landscape. Not because you need to become a legal expert, but because the decisions you make about AI governance today will determine whether your organisation is ahead of the curve or scrambling to catch up when the rules harden.

The global picture is moving fast. In the past 18 months alone, the EU has brought into force the most comprehensive AI legislation in the world, China has imposed mandatory algorithm registration and content labelling with criminal penalties for executives, the US has pivoted sharply from safety-focused regulation to a deregulatory, innovation-first agenda, Singapore has emerged as a global leader in practical AI governance frameworks, the Middle East is investing hundreds of billions in AI infrastructure while building its own regulatory architectures, and Africa has adopted a Continental AI Strategy for its 55 member states. The UK, meanwhile, continues to champion a principles-based, pro-innovation approach that trusts existing regulators to apply five cross-cutting principles within their sectors.

The approaches differ significantly. But they all converge on a common set of concerns: fairness, transparency, accountability, safety and the right to challenge AI decisions. Understanding where each jurisdiction sits on the spectrum, from voluntary principles to binding enforcement, is essential for any board that wants to govern AI responsibly.

The global regulatory spectrum

UK

Singapore

Middle East

United States

OECD

Africa

EU

China

Principles Frameworks Strategies Deregulation Guidelines Emerging Binding law Enforcement

Let me walk through each approach and explain what it means for boards and directors.

Principles-based, regulator-led

United Kingdom

The UK Government’s 2023 White Paper, A Pro-Innovation Approach to AI Regulation, established five cross-cutting principles that existing regulators (the ICO, FCA, Ofcom, CMA and others) are asked to apply within their sectors. These principles are currently non-statutory: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.

The approach is deliberately flexible, allowing regulators to interpret and apply the principles in context. However, the Government has signalled that a comprehensive AI Bill could be introduced in 2026, and the King’s Speech in July 2024 proposed binding measures on developers of the most powerful AI models. Until then, the UK operates as a principles-first, law-later jurisdiction.

Board implication: The voluntary nature of the principles is not an invitation to do nothing. It is an invitation to lead. Organisations that build governance frameworks now will be compliant before the law requires it.

International consensus framework

OECD AI Principles

Adopted in 2019 and endorsed by over 45 countries, the OECD AI Principles represent the closest thing to a global consensus on AI governance. They emphasise inclusive growth, human-centred values, transparency, robustness, and accountability. The UK principles align closely with the OECD framework, as do Singapore’s and the EU’s. They are increasingly referenced in procurement requirements, investor expectations and international standards including ISO 42001.

Board implication: If you align with the OECD principles, you have a strong foundation for compliance in most jurisdictions. They are the international baseline.

Risk-based binding legislation

European Union: The AI Act

The EU AI Act, which entered into force in August 2024, creates a legal framework that categorises AI systems by risk level with binding obligations. Unacceptable risk applications (social scoring, real-time biometric surveillance) are prohibited outright. High-risk systems (hiring, credit scoring, law enforcement, critical infrastructure) face mandatory conformity assessments, human oversight and post-market monitoring. Limited risk systems must meet transparency requirements. Minimal risk systems are largely unregulated.

Non-compliance carries penalties of up to €35 million or 7% of global turnover for prohibited practices, and up to €15 million or 3% for other violations. The Act applies to any organisation placing AI systems on the EU market, regardless of where it is based.

Board implication: If you have European clients, operations or market exposure, you are already within scope. This is binding law with serious financial consequences.

State-directed, actively enforced

China

China has moved faster than any jurisdiction from principles to enforcement. The Interim Measures for Generative AI Services (August 2023) made China the first country with binding generative AI regulations. Since then: mandatory algorithm registration with the Cyberspace Administration of China (over 1,400 algorithms from 450+ companies by mid-2024), mandatory content labelling for all AI-generated content (effective September 2025), binding security standards for training data and model safety, and an ethical code requiring adherence to “mainstream values.”

Consequences of non-compliance include fines of up to 5% of annual turnover, personal liability for senior executives (fines up to RMB 1 million), bans from holding senior roles, and in serious cases, criminal prosecution. Regulators have already imposed administrative penalties on non-compliant providers.

Board implication: China demonstrates where non-compliance leads. For organisations with any Chinese market exposure, compliance is not optional and the penalties are personal.

Deregulatory, innovation-first

United States

The US presents the most dramatic policy shift. President Biden’s October 2023 Executive Order (14110) on Safe, Secure, and Trustworthy AI established comprehensive safety requirements, testing standards and ethical frameworks. It was the most significant US AI governance action to date. President Trump rescinded it within hours of taking office in January 2025, replacing it with Executive Order 14179, Removing Barriers to American Leadership in AI, which explicitly prioritises deregulation and innovation.

The December 2025 Executive Order went further, establishing a federal framework to pre-empt state-level AI legislation, creating a DOJ task force to legally challenge state AI laws, and directing federal agencies to condition grant funding on states not enacting AI laws that conflict with the administration’s pro-innovation policy. The administration characterises state-level regulation as creating a “patchwork” that hinders competitiveness.

Board implication: The US approach creates a divergence from the EU, UK and OECD trajectory. For organisations operating across jurisdictions, this means navigating very different expectations. The absence of US federal AI regulation does not mean the absence of risk; it means the risk management burden falls on the organisation, not the regulator.

Practical governance frameworks

Singapore

Singapore has quietly become one of the most sophisticated AI governance jurisdictions in the world. Its Model AI Governance Framework (first published 2019, updated for generative AI in 2024) provides practical, implementable guidance built on principles of explainability, transparency, fairness and accountability. The framework covers nine dimensions across the AI lifecycle, developed with input from over 70 global organisations including OpenAI, Google, Microsoft and Anthropic.

Singapore’s AI Verify testing framework validates AI systems against internationally recognised principles. In 2025, the IMDA launched a Global AI Assurance Pilot and published draft guidance on governing agentic AI, arguably the most forward-looking governance document of any jurisdiction. Singapore has also invested $1 billion over five years in AI computing infrastructure and talent development, and has developed interoperability crosswalks with both the US (NIST) and OECD frameworks.

Board implication: Singapore offers the best model of practical, operational AI governance. Its frameworks translate principles into actionable guidance that organisations can implement immediately, and they are designed for international interoperability.

Investment-led, strategy-driven

Middle East: UAE, Saudi Arabia and the Gulf

The Middle East is investing at a scale that dwarfs most other regions. The UAE became the first country to appoint a Minister of State for AI in 2017, with its National AI Strategy 2031 positioning it as a global leader. Saudi Arabia’s SDAIA (Saudi Data and AI Authority) is driving AI deployment under Vision 2030, with HUMAIN (a PIF subsidiary) building AI factories with projected capacity of 500MW. The combined Gulf investment in AI infrastructure runs into hundreds of billions of dollars.

On the regulatory side, the approach is predominantly “soft law,” non-binding guidelines and ethical principles, though this is maturing. The UAE issued AI Ethics Principles in 2022 and a Charter for AI development in 2024. Saudi Arabia published an AI Adoption Framework and ethics principles through SDAIA. Qatar stands out as the only GCC state with legally binding AI guidelines, applicable to Central Bank-licensed financial firms. Saudi Arabia’s Draft Global AI Hub Law of 2025 signals a transition toward hard law.

Board implication: For organisations operating in or with the Gulf, the regulatory environment is evolving from aspiration to obligation. The investment scale means AI will be embedded in regional economies rapidly, and governance expectations will follow. ISO 42001 is already emerging as the baseline for vendor eligibility in public-sector procurement.

Continental strategy, national implementation

Africa

The African Union adopted its Continental AI Strategy in July 2024, providing a framework for all 55 member states. The strategy takes a people-centric, development-oriented approach, with five focus areas: harnessing AI’s benefits, building capabilities, minimising risks, stimulating investment and fostering cooperation. Phase 1 (2025-2026) focuses on establishing governance structures and national strategies; Phase 2 (from 2028) launches large-scale initiatives.

At the national level, progress is accelerating. Kenya launched its National AI Strategy (2025-2030) with KES 152 billion allocated over five years. Nigeria rose 31 places in the 2025 Government AI Readiness Index. South Africa is developing a rights-based approach through its Artificial Intelligence Institute. Over 83% of AI startup funding in Q1 2025 went to Kenya, Nigeria, South Africa and Egypt. The April 2025 Global AI Summit in Kigali produced the Africa Declaration on AI, endorsed by 49 countries.

Board implication: Africa represents a rapidly emerging AI market with distinctive governance priorities. Organisations working across the continent should align with the AU Continental Strategy and relevant national frameworks. The emphasis on digital sovereignty and culturally relevant AI systems means governance expectations may differ from Western frameworks.

What this means for your board

Seven jurisdictions, seven approaches, but a common thread runs through all of them. Every regulatory framework, whether principles-based or legally binding, converges on the same core concerns: fairness, accountability, transparency, safety and the right to challenge AI decisions. The UK, OECD, EU, Singapore, China, the Gulf and Africa all address these themes, from different angles and with different enforcement mechanisms, but with remarkable consistency on the underlying principles.

Five questions every board should ask

  1. Which jurisdictions are we exposed to? If you have European clients, your AI use is within scope of the EU AI Act. If you operate in the Gulf, ISO 42001 is becoming a procurement baseline. If you have any Chinese market exposure, binding regulations already apply. Map your exposure.
  2. Do we have an AI governance framework? Regardless of which jurisdiction you are in, the direction of travel is toward binding regulation. Building a governance framework now, aligned with the OECD principles and your primary jurisdictions, is significantly cheaper and less disruptive than retrofitting one later.
  3. Do our directors understand AI well enough to govern it? The Gallup finding that only 15% of employees report a clear AI strategy from their employer is, at its root, a board literacy problem. Directors who do not understand AI cannot set strategy, assess risk or hold the executive to account on it.
  4. Are we managing shadow AI? Microsoft’s finding that 78% of AI users bring their own tools to work applies globally. Without governance, staff are already using AI with your data, on unapproved platforms, without oversight. This is a risk in every regulatory environment.
  5. Are we ready for what comes next? Agentic AI, which can plan, execute and deliver autonomously, is already being addressed by Singapore’s governance framework. The next wave of AI will be more powerful, more embedded and more consequential. Your governance framework needs to be ready for it.

In Part 2, I introduce a practical framework that any board can use to address these concerns: FACTS, an acronym I have developed, in the same tradition as my Effective Board Member (EBM) series, to make governance principles memorable, actionable and applicable to every AI initiative your organisation undertakes.

Part 2: The FACTS of AI Governance

In the next instalment, I introduce the FACTS framework: Fairness, Accountability, Contestability, Transparency and Safety. Through real-world analogies, failure case studies and a practical board-level application guide, FACTS gives directors a tool they can use in every meeting, every decision and every AI initiative.

Contact Karl George MBE at The Governance Forum

Speak To Our Expert

Newsletter
Location & Social Media

Company Number: 16359543