The Global AI Governance Structure
Preamble and Founding Principles
Submitted for international policy consideration, institutional development, and multilateral review
Draft Schema for Multilateral Review
Issued at Sydney, New South Wales, Australia · April, 2026
Instrument Designation: Instrument 0 (Parent Framework) of the Global AI Governance Structure — the anchor document for the numbered companion corpus of thirteen instruments (1–13)
Table of Contents
Preamble and Founding Principles
Tier 1 — Global Institutional Architecture
Tier 2 — Standards, Verification and Enforcement
Tier 3 — Active Promotion of Beneficial AI
Tier 4 — Adaptive Governance and Long-Horizon Safeguards
Key Design Principles of the Schema
The Hardest Political Problems
5. AI and Employment: Safeguarding Human Dignity
6. AI and Agriculture: Food Security Safeguards
7. Unlocking Women’s Economic Potential
8. AI, Minors, and Education: Safeguards for P-12, Tertiary Education, and Pedagogy
Appendix 1 — Article 1.2 — Core Prohibitions
Appendix 2 — Demographic Impact Assessment Schema
Appendix 3 — US-China AI Governance
Appendix 4 — Ecological Impact Assessment Schema
Appendix 5 — Substantive Rights Gender Impact Assessment (GIA)
Executive Summary
Editorial Note: This schema is presented as a framework for international deliberation. It reflects the logic of global governance grounded in the Universal Declaration of Human Rights and the United Nations Charter — not in every instance the author’s personal views. Where the schema sets out positions on contested political, philosophical, or technical questions, it does so because those positions follow from the foundational commitments of the UDHR and the UN Charter to human dignity, non-discrimination, accountability, and the rule of law. The goal throughout is the protection and advancement of human rights in the age of artificial intelligence.
This document proposes a schema for the international governance of artificial intelligence, with the objective of supporting human wellbeing, institutional accountability, and ecological integrity. As AI systems are increasingly integrated into public, commercial, and strategic infrastructure, there is a growing need for governance arrangements capable of addressing cross-border risks, distributional inequities, and long-horizon harms while enabling socially beneficial uses.
The schema proposes an initial set of governance measures intended for consideration by policymakers, regulatory institutions, technology developers, and civil society actors. Developed through structured human-AI collaboration using Claude (Anthropic), the text was curated, reviewed, and substantively validated under human editorial oversight, including publications by the author. It is released as a public-good document under a Creative Commons (CC) BY-NC-ND 4.0 licence to support broad non-commercial circulation and faithful translation while preserving the integrity of its core provisions.
The schema is organised around four institutional tiers and seven thematic priorities. Tier 1 establishes a new specialised UN agency — the International Agency for AI Safety and Benefit (IAASB) — together with a binding Global AI Treaty and an International AI Court. Tier 2 sets out verification, standards, and enforcement mechanisms. Tier 3 creates active instruments for equitable benefit-sharing, including a Global AI Commons Fund and a Human Rights by Design Mandate. Tier 4 addresses long-horizon and existential risks. The seven thematic priorities elaborate the schema’s application to verification and compliance, rights-based standards, the US-China geopolitical dynamic, legal standing for nature, employment and human dignity, food security, gender equity, and the protection of minors in educational settings. Together they form a mutually reinforcing architecture, grounded in the principle that no person, community, or natural system should bear the costs of AI development without voice in how it is governed.
Questions of Interpretation and Application: A Reader’s Guide
What is the primary goal of this schema?
This document proposes a schema for aligning AI development with human rights, safety requirements, and equitable international benefit-sharing. Its purpose is to establish governance arrangements capable of distributing the benefits of AI broadly, protecting human rights, and preventing concentration of power within narrow corporate or geopolitical interests.
Why is this work published under a NoDerivatives (ND) licence?
The NoDerivatives condition is intended to preserve the integrity of the schema’s core provisions. In this formulation, it serves to reduce the risk that essential safety principles might be altered, weakened, or selectively reinterpreted in ways that would compromise the coherence of the schema.
Am I allowed to translate this document into another language?
Yes. Faithful and accurate translation is encouraged in order to support wider international accessibility. Any translation should preserve the meaning of the original text, remain non-commercial in use, and include the translation notice specified in the citation guidance.
Can a company use this schema to guide their internal AI safety policies?
Yes. Organisations may consult and apply the schema in the development of their internal AI governance and safety practices. The licensing terms, however, do not permit the schema itself to be sold, incorporated into paid advisory products, or otherwise monetised as a proprietary offering.
How did Claude (Anthropic) contribute to this project?
Claude was used as a structured drafting and synthesis tool in the organisation of governance material and the preparation of preliminary prose. Editorial judgment, normative direction, and final validation remained under human responsibility throughout.
Author and Background Note
Natalie Ross has engaged in research in philosophy and theology for two decades, with a sustained focus on discernment, ethics, and scholarship, presenting foundational work at academic conferences, workshops, and collaborative roundtables at local, national, and international levels.
Alongside her academic work, she has maintained a long-standing commitment to social justice in practice, supporting multiple faculties and more than 2,000 students within a busy multicultural campus environment while holding a full-time teaching role. This combination of sustained scholarly inquiry and practical humanitarian engagement informs the foundations of the present work.
Drawing on the methodologies of Bernard Lonergan SJ, she brings together structured discernment, intellectual responsibility, and human-centred ethical inquiry in addressing contemporary global challenges. The Global AI Governance Structure reflects this longer trajectory of work and is presented as a contribution to ethical progress, institutional responsibility, and the wider public good.
Publication, Licensing, and Use Notice
© 2023-2026 Natalie Ross and Claude (Anthropic).
The Global AI Governance Structure is issued as a public-good document developed with AI assistance and curated under human editorial oversight.
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License. The licence permits copying and redistribution of the material in any medium or format, subject to the conditions set out below. For further details, see creativecommons.org.
Terms of Use
Attribution: Appropriate credit must be given to the original authors.
Non-Commercial: The material may not be used for commercial purposes or financial gain.
NoDerivatives: If the material is remixed, transformed, or built upon, the modified version may not be distributed. Explicit permission is granted solely for faithful, unaltered translations into other languages for non-commercial and humanitarian use.
Citation and Reference Note
For citation in academic, policy, or legal materials, the following form should be used:
Ross, Natalie. Global AI Governance Structure. 2026. Developed with generative AI assistance from Claude (Anthropic). Licensed under CC BY-NC-ND 4.0. Available at: [https://spiritanddiscernment.wordpress.com/wp-admin/post.php?post=218&action=edit].
Guidelines for Translations
In accordance with the NoDerivatives condition, the text of this schema should remain unaltered. Faithful and accurate translations into other languages are nevertheless permitted and encouraged for non-commercial, humanitarian use. Any translated version should include the notice set out below:
“This is a translation of The Global AI Governance Structure, originally published by Natalie Ross and Claude (Anthropic), and used under a CC BY-NC-ND 4.0 License. The original text has been translated faithfully without alteration to its core meaning or structure.”
Methodological Note on Human-AI Collaboration
This schema was developed through a structured process of human-AI collaboration. The generative AI system Claude, developed by Anthropic, was used as a drafting and synthesis tool in the organisation of governance concepts and the preparation of foundational text.
Editorial control, normative direction, safety review, and final validation were retained under human oversight throughout, including incorporation of the author’s own publications. The human author established the core ethical parameters, reviewed and revised the generated material, and determined the final form of the text to ensure consistency with humanitarian, legal, and institutional principles.
This schema is grounded in four non-negotiable pillars: human dignity (every person possesses inherent worth that AI must never erode), ecological integrity (AI must not accelerate the destruction of the natural systems on which all life depends), democratic accountability (those affected by AI must have voice in how it is governed), and epistemic humility (given AI’s pace of change, governance must be adaptive, not static).
It operates within the existing authority of the United Nations (UN) Charter’s prohibition on threats to peace, the Universal Declaration of Human Rights (UDHR)’s guarantees of equality and freedom from arbitrary harm, and the emerging body of international environmental law.
_______________________________________________________________
Editorial note on sequencing and the present diplomatic stage: Tier 1 of this schema proposes a binding Global AI Treaty enforced by a dedicated International AI Court. As of 2025–26, the actual multilateral AI-governance process has reached only the second of what is typically a three-stage sequence in comparable regimes: a scientific evidence-gathering body and a deliberative, non-binding forum, neither carrying a mandate to negotiate a binding instrument. The Independent International Scientific Panel on AI, established by General Assembly resolution A/RES/79/325 (26 August 2025), released its Preliminary Report on 1 July 2026; the inaugural Global Dialogue on AI Governance, the first UN forum in which all 193 member states hold a guaranteed seat, met in Geneva on 6–7 July 2026 to receive it. This schema does not present Tier 1 as a description of the next available diplomatic step from that position; it is offered as the end-state these two existing bodies would need to be built toward, not as an assumption that a scientific panel and a dialogue can be converted directly into a binding treaty and court. The Implementation Roadmap below sketches an interim architecture, short of Tier 1, as the transitional step consistent with where the process presently stands.
THE GLOBAL AI GOVERNANCE STRUCTURE
Draft Schema for Multilateral Review · 2026
| 4 NON-NEGOTIABLE PILLARS |
| Human Dignity · Ecological Integrity · Democratic Accountability · Epistemic Humility |
▼
| EXISTING LEGAL AUTHORITY |
| UN Charter Prohibitions · Universal Declaration of Human Rights · International Environmental Law |
▼
| TIER 1 — GLOBAL INSTITUTIONAL ARCHITECTURE | TIER 2 — STANDARDS, VERIFICATION & ENFORCEMENT |
| • IAASB — New Specialised UN Agency (General Assembly, 15-Member Executive, Scientific Panel, Civil & Nature Council) • Global AI Treaty (Hard Floor Prohibitions) • International AI Court & Tribunal | • Tiered Risk Classification (Tiers 1–4) • Compute Governance & Know Your Customer (KYC) Cloud Rules • Mandatory Safety Evaluations • Algorithmic Audits & Whistleblower Protection Mechanisms |
▼
| TIER 3 — ACTIVE PROMOTION OF BENEFICIAL AI | TIER 4 — ADAPTIVE GOVERNANCE & LONG-HORIZON SAFEGUARDS |
| • Global AI Commons & Levy Fund • AI for Planetary Health Monitoring • Capacity Building & Technology Transfer • Human Rights-by-Design Mandate | • Existential Risk Protocol Working Group • Supermajority Pause Mechanisms • 5-Year Mandatory Review Conferences • Constitutional AI Values Hierarchy |
▼
| KEY DESIGN PRINCIPLES |
| Multi-Speed Phasing · Caution-Asymmetric Burden · Non-Hegemonic / Capture-Proof · Inclusive of Nature First |
I. ROADMAP IMPLEMENTATION TIMELINE
| PHASE 1 — YEARS 1–2 | PHASE 2 — YEARS 3–5 | PHASE 3 — YEAR 6+ |
| Schema Convention | Operationalisation | Mandatory Enforcement |
| • Bilateral & state-level negotiations • Final signature of Treaty frameworks • Modelled on Paris Agreement speeds | • Agency structures become active • Standardised tier risk criteria set • Domestic regulatory laws implemented | • Comprehensive cloud hardware audits • Full deployment of International Court • Active disbursement of monetary funds |
II. IAASB GLOBAL UN AGENCY ARCHITECTURE
| GENERAL ASSEMBLY — All Member States | |
| Universal membership · Votes on binding treaty amendments · Elects Executive Board · Sets strategic mandate | |
| ▼ | |
| EXECUTIVE BOARD — 15 Rotating Seats Day-to-day governance · Authorises deployments · Issues sanctions · Distributes levy funds | |
| ▼ | |
| SCIENTIFIC & ETHICS PANEL | CIVIL SOCIETY & NATURE COUNCIL |
| • Expert technical capability review • Adaptive risk-metric updates (bi-annual) • Safety evaluation methodology oversight • Independent from Executive Board | • Indigenous peoples & communities • Impacted localities & civil society • Ecological science domain monitors • Veto rights on nature-affecting standards |
Key Functional Links
- The Strategic Shift: Phase 1 sets down the legal requirements that the Executive Board enforces by Phase 3.
- The Technical Loop: The Scientific Panel updates the risk classification criteria used in Phase 2 to prevent compute definitions from falling behind commercial hardware realities.
[Link back to Table of Contents]
Tier 1 — Global Institutional Architecture
1.1 International Agency for AI Safety and Benefit (IAASB) A new specialised UN agency, analogous to the International Atomic Energy Agency (IAEA), with a mandate covering both safety and the active promotion of beneficial use. Its structure would include a General Assembly of member states, a 15-member Executive Board with rotating representation, an independent Scientific and Technical Panel, and a Civil Society and Nature Advisory Council that includes Indigenous peoples, affected communities, and ecological scientists. Funding comes from a combination of assessed contributions and a levy on large AI developers proportional to compute usage.
Editorial note on the Scientific and Technical Panel: this proposed body is distinct from the UN Independent International Scientific Panel on Artificial Intelligence, which the General Assembly established alongside the Global Dialogue on AI Governance by resolution A/RES/79/325 (26 August 2025), pursuant to the Global Digital Compact adopted as Annex I to the Pact for the Future (22 September 2024) and building on the Secretary-General’s High-Level Advisory Body on AI’s August 2024 report Governing AI for Humanity. Both bodies now exist and operate in the non-military domain. This schema does not yet specify whether the IAASB’s Scientific and Technical Panel is intended to extend that Panel’s mandate into the IAASB’s specific regulatory functions, operate alongside it, or be folded into it; that relationship is left open here for resolution rather than assumed.
Editorial note on institutional peers in the peace-and-security domain: the UN Institute for Disarmament Research (UNIDIR) already carries out work the IAASB would need to coordinate with. UNIDIR’s Centre of Excellence on AI, Peace and Security, launched in 2026, is a standing Geneva-based platform for research, dialogue, and capacity-building on the security implications of AI, and UNIDIR has for some years supported the Convention on Certain Conventional Weapons (CCW) Group of Governmental Experts on Lethal Autonomous Weapons Systems (GGE LAWS) with technical and legal analysis. This work bears most directly on this corpus’s companion Algorithmic Warfare Treaty and Unmanned Systems Governance Treaty, which are better placed than this document to define the IAASB’s relationship to UNIDIR in detail.
Editorial note on institutional reuse versus new creation: the nuclear-weapon-free zone treaties offer a relevant precedent here. Each of the five that has actually entered into force and endured — Tlatelolco, Rarotonga, Bangkok, Pelindaba, and the Central Asian zone — relied on existing institutions, principally IAEA safeguards, for verification rather than building independent verification machinery from nothing. Measured against that precedent, this schema’s proposal of the IAASB as an entirely new specialised agency, rather than an extension of the two bodies that already exist and already occupy adjacent ground — the Independent International Scientific Panel on AI and the Global Dialogue on AI Governance, both established by resolution A/RES/79/325 — deserves an explicit justification it has not yet received. The case for a new agency rests on jurisdiction: neither the Panel nor the Dialogue has, or was designed to have, regulatory or enforcement functions, only evidence-gathering and deliberation, so extending either body’s mandate to cover binding standard-setting, compute registries, and incident reporting would require the same General Assembly action a new agency would require, without a mandate purpose-built for that function. This schema treats the question as genuinely open rather than settled, and notes that the companion New START Successor Treaty, which operationalises the IAASB in binding treaty text, is the more appropriate place to resolve it definitively.
Editorial note on institutional evolution since this framework was drafted: two companion instruments have since established their own domain-specific verification authorities alongside the IAASB rather than folding their functions into it — the Unmanned Systems Governance Treaty’s International Unmanned Systems Governance Authority (IUSGA) and the BCWA AI Governance Treaty’s International CBRN AI Verification Authority (ICAVA). This is consistent with, not a departure from, the institutional-reuse logic argued above: the IAASB remains the Tier 1 anchor for AI safety and benefit generally, while IUSGA and ICAVA exercise the more specific technical jurisdictions — unmanned systems governance and CBRN weapons convergence — that a single general-purpose agency would be poorly placed to hold in adequate depth. A reader working from this document alone should not conclude that the IAASB is the corpus’s only standing verification body; Tier 1’s institutional architecture has grown a small number of domain-specific peers since this section was first drafted, and the companion instruments named above remain the authoritative source on their structure and mandate.
1.2 Global AI Treaty (analogous to the Treaty on the Non-Proliferation of Nuclear Weapons (NPT) or Chemical Weapons Convention) A binding international agreement establishing absolute prohibitions (hard floors), universal standards, and mutual verification mechanisms. Core prohibitions would include AI systems designed to autonomously initiate lethal force without meaningful human control; AI used for mass surveillance without democratic oversight; AI systems engineered to manipulate human cognition at scale without consent; and any AI development specifically aimed at undermining democratic institutions or ecological systems. Parties would commit to mandatory incident reporting, capability disclosure for systems above defined risk thresholds, and participation in joint oversight mechanisms. (See Appendix 1)
1.3 International AI Court and Tribunal A dispute resolution and accountability body with jurisdiction to hear cases brought by states, affected communities, or the IAASB itself. It would have the power to issue binding remedies, impose sanctions, and recommend referrals to the International Criminal Court in cases of severe harm. A dedicated chamber would address harms to nature and future generations, drawing on the emerging legal personhood schemas for natural systems.
Third, a network of Indigenous and traditional community guardians. Many of the world’s most ecologically significant areas lie within or adjacent to Indigenous territories. Indigenous peoples hold knowledge, relational understanding, and custodial obligations that no institutional body can replicate — obligations that, in many cases, predate the nation-states that now claim jurisdiction. These communities hold formal participatory rights in any AI governance proceeding affecting their territories, drawing on the schema of Free, Prior and Informed Consent established in the UN Declaration on the Rights of Indigenous Peoples. Their participation is not consultation. It is co-governance.
Tier 2 — Standards, Verification & Enforcement
2.1 Tiered Risk Classification System All AI systems would be classified into four tiers based on their potential for harm, required transparency, and oversight intensity — from Tier 1 (minimal risk, self-certification) to Tier 4 (existential or civilizational risk, requiring international authorisation before deployment). This builds on and harmonises existing schemas such as the European Union (EU) AI Act and the Organisation for Economic Co-operation and Development (OECD) AI Principles.
2.2 Compute Governance and Know-Your-Customer Rules Given that large-scale compute is currently a meaningful chokepoint, states would be required to maintain registries of very large training runs (above defined floating-point operation (FLOP) thresholds), apply export controls to advanced AI chips in ways consistent with non-proliferation goals, and mandate that cloud providers verify the identity and intended use of customers conducting large-scale AI training.
2.3 Mandatory Safety Standards All Tier 3 and 4 systems must undergo independent red-teaming and safety evaluations by accredited third parties before deployment. Developers must publish model cards with meaningful technical information. Evaluation methodologies shall be developed and periodically reviewed by an independent international scientific and technical body, in consultation with States Parties, relevant international organisations, standards bodies, and the scientific community, and shall be updated as necessary to reflect advances in artificial intelligence capabilities, emerging risks, and lessons derived from implementation and oversight.
2.4 Algorithmic Transparency and Auditability Mandatory audit rights for regulators, including access to model weights, training data documentation, and internal safety evaluations. A protected whistleblower regime to allow researchers within organisations to report serious safety concerns without retaliation. Interoperability requirements to prevent proprietary lock-in from making safety evaluation impossible.
Tier 3 — Active Promotion of Beneficial AI
3.1 Global AI Commons and Benefit-Sharing Fund A fund financed by the compute levy would support AI development in lower-income countries, finance open-source safety research, and fund the deployment of AI for global public goods: climate modelling, pandemic preparedness, agricultural resilience, biodiversity monitoring. This addresses the fundamental equity concern that AI’s harms may be globally distributed while its benefits are concentrated.
3.2 AI for Planetary Health A dedicated multilateral programme deploying AI for real-time monitoring of deforestation, ocean health, atmospheric composition, and species loss. Data would be public, models open, and outputs directly integrated into United Nations Environment Programme (UNEP) and Convention on Biological Diversity (CBD) reporting mechanisms. This gives nature a form of institutional representation in AI governance through continuous, objective monitoring.
3.3 Capacity Building and Technology Transfer Developed countries and large AI developers would be required to contribute technical expertise, training resources, and access to compute to enable developing nations to build their own AI governance capacity and beneficial AI ecosystems. This prevents governance from becoming a vehicle for technological dominance.
3.4 Human Rights by Design Mandate Any AI system deployed in contexts affecting rights — employment, credit, criminal justice, healthcare, education, immigration — must demonstrate compliance with UDHR principles including non-discrimination, due process, and access to remedy. An international certification mark, verified by accredited auditors, would signal compliance.
Tier 4 — Adaptive Governance and Long-Horizon Safeguards
4.1 Existential Risk Protocol A standing working group within the IAASB focused specifically on risks at civilizational scale, including artificial general intelligence and systems with potential for recursive self-improvement. This group would maintain scenario analyses, recommend thresholds that would trigger emergency treaty protocols, and maintain a network of independent researchers with access to information needed to monitor for such risks.
4.2 Mandatory Pause Mechanisms The treaty would include provisions allowing the IAASB Executive Board, acting by supermajority, to require a temporary global moratorium on specific classes of AI development if credible evidence of imminent catastrophic risk is established. This is analogous to emergency powers in other international safety regimes.
4.3 Living Governance Schema Mandatory five-year review conferences for the treaty, analogous to the Treaty on the Non-Proliferation of Nuclear Weapons (NPT) Review Conferences, with a standing technical committee updating standards annually. A participatory foresight process involving scientists, ethicists, affected communities, and youth representatives would feed into each review.
4.4 Constitutional AI Principles as an International Norm States would be encouraged, through soft law instruments and eventually binding commitments, to require that any AI system deployed in their jurisdiction operates within explicit, auditable value hierarchies that prioritise human welfare and ecological integrity. This would build on and internationalise schemas already being developed by leading AI labs and regulators.
Key Design Principles of the Schema
The schema is deliberately multi-speed: some obligations (hard prohibitions, incident reporting) apply immediately; others (full treaty ratification, mandatory auditing infrastructure) are phased over 5-10 years to allow implementation capacity to develop. It is asymmetric toward caution: the burden of proof falls on developers to demonstrate safety, not on communities to prove harm. It is non-hegemonic: governance bodies are designed to prevent capture by any single state or bloc. And it is inclusive of nature: ecological harm is treated as a first-class category of harm, not an afterthought. These design principles pervade all four tiers and are operationalised in the implementation roadmap below.
Implementation Roadmap
The four-tier architecture described above is not a static blueprint but a phased project. The schema would be built in three phases. In the first two years, states would negotiate and sign a Schema Convention establishing the IAASB and the core treaty architecture, modelled on the speed of the Paris Agreement negotiations. Years three through five would see the institution become operational, standards developed, and the tiered classification system implemented by member states. From year six onward, mandatory auditing, the AI Court, and the full benefit-sharing mechanisms would come into force.
A transitional Phase 0, consistent with the present diplomatic stage: Phase 1 above assumes states are prepared to negotiate binding treaty architecture directly. Given that the only bodies presently in existence are a scientific panel and a non-binding dialogue, a more immediate step would work through those two bodies rather than past them: (i) seeking, from the General Assembly, an explicit mandate for the Global Dialogue on AI Governance to negotiate — rather than merely discuss — a framework instrument, on the model of the shift from framework convention to binding protocol used in international environmental law; (ii) tasking the Independent International Scientific Panel on AI’s existing annual-report cycle with producing the technical baselines, such as compute thresholds and capability-evaluation methodology, that a future Tier 2 would need, so the science is not built from scratch once negotiations open; and (iii) treating the Panel’s three-year term, running to February 2029, as the working horizon for moving from evidence-gathering to a negotiating mandate. This is not a claim that Phase 0 is quick or guaranteed; it is offered as the step this schema would need to see completed before Phase 1 becomes realistic, rather than treating Phase 1 as available now.
On sequencing the companion instruments: the thirteen companion instruments are numbered and cross-reference one another, which could be read as implying a single package to be adopted together. No precedent surveyed in connection with this corpus supports that reading. None of the five Nuclear-Weapon-Free Zone treaties — Tlatelolco
region, often decades apart, reusing a common underlying model rather than moving as a bloc. The 1928 General Act for the Pacific Settlement of International Disputes was likewise a standalone instrument, not one component of a bundle. A more defensible reading of this corpus is a phased rollout rather than a simultaneous package: instruments extending frameworks with living precedent and lower political cost, such as the New START and INF Successor Treaties, could proceed first; instruments creating wholly new verification authorities, such as the Unmanned Systems Governance Treaty’s IUSGA and the BCWA AI Governance Treaty’s ICAVA, would follow once the IAASB itself has some operating history to draw on; and instruments most dependent on other parts of the corpus already being in force, such as the Lawfare Protocol and the North Korea Governance Framework, would come last. The numbering of the corpus reflects drafting order, not a proposed ratification sequence, and should not be read as one.
The Hardest Political Problems
Institutional architecture and implementation timelines depend, however, on resolving a set of political and technical problems that have no easy solutions. No schema proposal is honest without naming the obstacles. The most serious are: achieving meaningful participation from the United States (US), China, and the EU — whose cooperation is necessary for any global regime to function — given deep geopolitical rivalry; preventing large AI companies from regulatory capture of the institutions meant to oversee them; ensuring the governance of AI doesn’t simply become a form of protectionism by wealthy nations; and the fundamental verification challenge that, unlike nuclear weapons, powerful AI can be developed with commercially available hardware in dispersed locations.
These are solvable problems, but they require sustained political will, transparent institutions, and a genuine commitment to the principle — embedded in the UDHR itself — that the interests of all humanity, not just the powerful, determine what counts as “good.”
1. Verification Mechanisms
The central challenge is that AI is fundamentally different from nuclear weapons or chemical stockpiles. You cannot fly a satellite over a data centre and count warheads. A powerful model can be trained on commercially available hardware, copied instantly, and run anywhere. Any verification regime that pretends otherwise will fail. The honest starting point is that perfect verification is impossible — the goal is to make evasion costly, detectable with high probability, and internationally consequential.
Compute-Based Monitoring
The most tractable near-term verification lever is compute. Training frontier AI systems currently requires enormous concentrations of specialised hardware — primarily graphics processing units (GPUs) and tensor processing units (TPUs) — that are manufactured by a small number of companies, fabricated at an even smaller number of semiconductor foundries, and shipped through documented supply chains. This creates chokepoints.
A credible verification regime would require hardware manufacturers to embed unforgeable cryptographic identifiers in advanced AI chips above a defined performance threshold. These identifiers would allow the IAASB to maintain a global registry of where large concentrations of compute exist. Cloud providers operating above threshold compute capacity would be required to report large training runs — defined by floating-point operations (FLOP) count — to national regulators, who would relay anonymised aggregate data to the IAASB. This is analogous to financial transaction reporting: not every transaction is reviewed, but the aggregate creates an auditable record that makes large-scale evasion visible.
Export controls on advanced chips — already partially implemented by the United States, Netherlands, and Japan — would be brought under a multilateral schema so that no single state’s domestic politics can unilaterally undermine the regime. The IAASB would maintain a public ledger of sanctioned entities and member states would be treaty-bound to enforce it.
| I. SCIENTIFIC PANEL COMPUTE-BASED MONITORING | ||
| HARDWARE MANUFACTURE | CLOUD PROVIDERS | REGULATORY HUB |
| CRYPTOGRAPHIC CHIPS • Embed unforgeable silicon tokens • Document physical foundry shipment | RUNTIME REPORTING • Log massive rules above FLOP limit • Verify identity of KYC system users | IAASB REGISTRY • Maintain global compute cluster map • Re-verify baseline limits every 2 yrs |
▼
| II. DISPARATE IMPACT REMEDIATION PATHS |
| REGULATORY BREACH DETECTED |
▼
| TRACK 1 | TRACK 2 | TRACK 3 |
| • Minor threshold or post-process drift • 30-day fix timeline • System remains live during tuning | • Biased parameters, dataset, or weights • 90-day fix timeline • Mandatory human loop review checks | • Extreme proxy abuse or corrupted labels • Immediate shutdown • 180-day architecture re-build limit |
▼
| RETROACTIVE REVIEW COMPLIANCE |
| • Direct user notifications • Automated case re-evaluations • Structural financial redress |
Remediation & Monitoring Summary
- Compute Chokepoint: Compute monitoring tracks hardware from manufacture to runtime, allowing the IAASB to detect frontier training runs that exceed defined thresholds.
- Correction Escalation: When automated data drift triggers a bias alert, systems are sorted by harm severity and routed to the appropriate remediation track: Track 1 for minor drift, Track 2 where human oversight is required, and Track 3 for immediate shutdown and architectural review.
Model Evaluations and Third-Party Auditing
For systems that reach Tier 3 or 4 classification, deployment authorisation would require a mandatory pre-deployment evaluation by an accredited third-party auditor. Accreditation would be granted by the IAASB to organisations that meet independence, technical competency, and conflict-of-interest standards — analogous to how financial auditors are accredited by national bodies but operate under international standards.
Evaluations would cover a defined battery of capability and safety assessments developed by the Scientific Panel, including: dangerous capability evaluations (does this system have meaningful capability to assist with biological, chemical, radiological, or cyber weapons?), autonomy assessments (can this system pursue goals across extended time horizons without human intervention?), deception evaluations (does this system attempt to mislead its operators or evaluators?), and societal influence assessments (can this system manipulate public discourse at scale?).
Critically, evaluators would have access to model weights, training data documentation, and the ability to conduct white-box testing. Developers who refuse access would automatically trigger the highest risk classification and be barred from deployment in member state jurisdictions. This creates a strong incentive for cooperation.
Results would be published in standardised model evaluation reports, with a core public section and a classified annex for governments covering the most sensitive capability findings. This balances transparency with the legitimate concern that detailed dangerous capability disclosures could themselves be harmful.
Incident Reporting and Near-Miss Registries
Inspired by aviation safety culture, the schema would require mandatory reporting of AI incidents above defined severity thresholds — system behaviour that caused or could have caused significant harm, unexpected capability emergence, safety mechanism failures, or adversarial attacks. A protected near-miss reporting system, analogous to the National Aeronautics and Space Administration (NASA) Aviation Safety Reporting System, would allow researchers and engineers inside organisations to report concerns anonymously without fear of retaliation, with legal immunity for good-faith reports.
The IAASB would maintain a global incident registry, analyse patterns, and publish periodic safety bulletins. This transforms individual incidents into collective learning — one of the most powerful mechanisms in other high-stakes industries.
Behavioural and Societal Monitoring
Beyond technical evaluation, the schema would fund an independent network of civil society organisations, academic institutions, and investigative journalists with the mandate and resources to monitor AI systems in deployment. This draws on the model of election observation missions and human rights monitoring bodies: distributed, credentialed, and with formal reporting channels into the IAASB. Affected communities would have standing to submit evidence of harm directly to this network. This creates a bottom-up verification layer that technical auditing alone cannot provide.
2. Rights-Based Standards
The UDHR is not merely rhetorical scaffolding — it provides precise, actionable standards that can be translated into AI governance requirements. The key is to work right by right rather than treating “human rights” as an undifferentiated aspiration.
Article 1 (Equal Dignity) and Non-Discrimination
Any AI system making or materially influencing decisions in high-stakes domains — employment, credit, housing, healthcare, education, criminal justice, immigration, social benefits — must demonstrate that its outputs do not produce discriminatory effects based on race, sex, national origin, disability, religion, or other protected characteristics. This is a disparate impact standard, not merely a discriminatory intent standard: it is not sufficient that the system was not designed to discriminate if its outputs systematically disadvantage protected groups.
In practice, this requires developers to conduct and publish pre-deployment demographic impact assessments, provide ongoing monitoring data disaggregated by relevant characteristics, and remediate identified disparities. The schema would establish an international standard for how such assessments must be conducted — currently there is significant variation across jurisdictions — and the IAASB would publish technical guidance updated as measurement science improves. (See Appendix 2)
| DOMAIN-SPECIFIC FAIRNESS EVALUATION TRACKS | ||
| HIGH-STAKES DOMAIN | PRIMARY CRITERION | MONITORING FOCUS |
| CREDIT & LENDING | CALIBRATION PARITY | Quarterly audits. Verifies that equal scores mean equal default risk across demographic groups. |
| EMPLOYMENT | WORST-CASE FLOOR + COUNTERFACTUAL | Quarterly audits. Minimises selection bias and catches proxy discrimination. |
| CRIMINAL JUSTICE | ERROR COST WEIGHTING (false positive rate (FPR)-PRIMARY) | Monthly audits. Prioritises avoiding wrongful restriction of human liberty. |
| HEALTHCARE | WORST-CASE FLOOR + CALIBRATION | Monthly audits. Ensures no group receives unsafe, unequal baseline care. |
| IMMIGRATION / ASYLUM | ERROR COST WEIGHTING (FPR-PRIMARY) | Monthly audits. Heavily weights risk of life-altering wrongful rejections. |
| SOCIAL BENEFITS | MINIMAX FAIRNESS | Quarterly audits. Directly protects the worst-off demographic cells. |
Strategic Metrics Selection Summary
- The Impossibility Constraint: Because simultaneous parity across all metrics is mathematically impossible when group base rates differ, developers must explicitly select a primary focus matching the domain’s unique harm risks.
- Asymmetric Harm Protection: Criminal justice and immigration systems prioritise minimising false positives (wrongful restriction of liberty), while social benefits systems apply minimax fairness to protect the most vulnerable demographic groups.
Article 6 (Recognition Before the Law) and Due Process
Where AI systems make or substantially influence binding decisions affecting individuals — a credit denial, a benefits termination, a bail decision, a medical diagnosis with treatment consequences — individuals must have the right to know that an automated system was involved, to receive a meaningful explanation of the factors that drove the decision, and to have that decision reviewed by a human who has genuine authority to override it. The “human in the loop” requirement is meaningful only if the human has the information, time, and authority to exercise independent judgment — rubber-stamp reviews do not satisfy due process.
The schema would prohibit the deployment of fully automated decision systems in binding high-stakes contexts without these safeguards and would require that explanations be provided in plain language, not technical jargon that effectively denies access to remedy.
Article 12 (Privacy) and Surveillance
AI-powered mass surveillance — facial recognition in public spaces, behavioural tracking, predictive policing systems — requires a particularly robust rights schema because the harms are diffuse and often invisible to those affected. The schema would apply a strict necessity and proportionality test: surveillance AI may only be deployed when there is a specific, articulable public safety objective that cannot be achieved by less intrusive means, under judicial or equivalent independent authorisation, with time limits and mandatory review, and subject to transparency reporting to the public.
Certain applications would be categorically prohibited: real-time biometric surveillance of lawful protest or political assembly; AI systems that track individuals’ political views, religious practice, or union activity; and predictive policing systems that assign risk scores to individuals based on characteristics of their community rather than their own conduct.
Article 19 (Freedom of Expression and Information Integrity)
AI systems capable of generating large volumes of synthetic media, operating networks of inauthentic accounts, or micro-targeting political messaging at scale pose a direct threat to the epistemic conditions that freedom of expression requires. The schema would require that AI-generated content above defined scales be labelled as such; prohibit the use of AI to operate coordinated inauthentic behaviour campaigns; require platforms to provide transparency into algorithmic amplification; and mandate that AI systems used by political actors in electoral contexts be disclosed and subject to heightened scrutiny.
Crucially, these standards would apply to state actors as well as private ones. Governments using AI for domestic information operations against their own populations would be in violation of the treaty.
Article 25 (Health, Wellbeing, and Social Security)
AI systems in healthcare and social welfare contexts must meet standards of clinical and actuarial validity before deployment, must not exacerbate existing inequalities in access to care or services, and must be subject to ongoing post-market surveillance analogous to pharmaceutical regulation. The schema would establish an international standard for AI medical devices, harmonised with but extending existing national schemas, including requirements for diverse training data, prospective clinical validation in the intended population, and mandatory adverse event reporting.
Enforcement Through a Rights-Based Remedy Mechanism
Rights without remedies are aspirations. The schema would establish a streamlined individual complaints mechanism, allowing persons who have suffered harm from an AI system in a member state to bring a complaint to the IAASB’s rights compliance body after exhausting domestic remedies. This body could issue findings of violation, recommend remediation, and refer systemic violations to the AI Court. Developers and deployers would be jointly liable, preventing liability from being diffused into unaccountability.
3. The US-China Dynamic
The relationship between the United States and China is the central geopolitical challenge for any global AI governance framework. AI governance discourse frequently reduces this relationship to strategic competition alone. This schema takes a different approach: it acknowledges competitive dynamics explicitly while insisting that the UN Charter’s commitment to international cooperation — and the UDHR’s universality — require that shared responsibilities and mutual vulnerabilities be accorded equal weight. Institutional continuity during periods of bilateral strain is not a diplomatic nicety; it is a structural necessity for any governance regime that must function precisely when political relations are most fraught. (See Appendix 3)
Why Unilateral or Bloc-Based Governance Fails
A governance system developed without the participation of major AI powers would produce a fragmented international landscape: parallel regulatory regimes, uneven standards, and diminished collective capacity to address the most serious risks. Governance that allows any single state to veto essential safety measures is equally unworkable. The UN Charter model — universal membership, qualified-majority decision-making on fundamental matters, and permanent structures that outlast political cycles — provides the appropriate institutional template. A sustainable approach must foster meaningful participation by all major stakeholders while preserving non-negotiable foundational principles.
The Logic of Mutual Vulnerability
The strongest foundation for US-China cooperation on AI safety is not trust or diplomatic goodwill — both of which fluctuate with political conditions — but shared exposure to catastrophic and irreversible risks. Neither country, nor the wider international community, would benefit from AI systems that contribute to large-scale biological harm, financial instability, or dangerous forms of misalignment. These are not American or Chinese risks; they are human risks, and the UDHR’s commitment to the protection of all persons from arbitrary harm provides the normative basis for treating them as shared obligations. The IAASB should give institutional expression to this common interest by establishing a permanent US-China working group on catastrophic risk within its broader architecture, with dialogue continuing irrespective of wider diplomatic conditions, consistent with past practice among major powers in managing shared strategic risks.
This reflects a principle of placing safety before strategic rivalry: even where significant geopolitical differences exist, states retain a common interest in preventing forms of AI-related harm that no single country could adequately control or reverse on its own. Historical experience indicates that such cooperation is achievable. During the Cold War, the United States and the Soviet Union engaged on nuclear safety measures, and the United States and China have at times maintained scientific exchange on pandemic preparedness despite periods of broader trade and diplomatic difficulty.
Structural Design for Inclusive Governance
The IAASB’s governance structure should be designed to avoid domination by any single state or grouping and to encourage broad, equitable participation. Its Executive Board could be composed through rotating regional representation, alongside permanent seats for major AI powers, including China, so as to ensure meaningful participation without conferring unilateral authority over safety standards. Decisions on core safety thresholds and prohibited applications would require a qualified supermajority, thereby supporting the preservation of essential safeguards. Procedural and technical standards, meanwhile, would be developed by the Scientific Panel on the basis of expert consensus rather than political bargaining.
The Global AI Treaty could adopt a differentiated-obligations model consisting of a core protocol on catastrophic risk and clearly prohibited applications, to be accepted in full by all parties, together with optional protocols on human rights, transparency, and beneficial AI commitments that states may join as their domestic governance capacities evolve. This approach is consistent with the schema-convention-and-protocol model used in international environmental law, which has facilitated broad participation by states, including China, in agreements such as the Montreal Protocol and the Paris Agreement.
Managing Asymmetric Transparency
Transparency remains an area in which governance approaches differ, particularly with respect to public disclosure practices and the role accorded to civil society oversight. A pragmatic way forward would be to distinguish between international transparency—namely, the sharing of safety-relevant information with the IAASB and relevant governments—and domestic transparency, which concerns the provision of information to the public and to civil society within national systems. Under such an arrangement, international transparency would constitute a treaty obligation for all parties, including the reporting of major training runs, incidents, and high-risk capability assessments to the IAASB. Domestic transparency requirements could instead be addressed through the optional human rights protocol, thereby allowing participation in the core safety regime while respecting variation in national legal and institutional arrangements.
Economic Interdependence as Leverage
The semiconductor supply chain represents an important structural factor in AI governance. Advanced AI chips are designed across a concentrated number of leading ecosystems, depend on software from firms in the United States and partner countries, and are manufactured primarily by a limited group of highly capable producers, including TSMC in Taiwan and Samsung in South Korea. This concentration gives governments a significant degree of influence over access to frontier compute, including through measures such as export controls. Over the longer term, a more stable and widely accepted approach would place compute governance within the IAASB under transparent, rules-based, and non-discriminatory arrangements rather than relying predominantly on unilateral action. Such an approach would be more sustainable politically, less susceptible to retaliatory dynamics, and better positioned to reduce regulatory gaps.
Track 2 and Scientific Diplomacy
Even during periods of official strain, scientific and technical communities often remain in contact. The schema should therefore support track-2 diplomacy through joint US-China AI safety research institutes, researcher exchange programmes, and protected channels for the sharing of information on catastrophic risks that can continue to function independently of broader political conditions. Experience suggests that such scientific relationships may endure through periods of tension and can contribute to the gradual rebuilding of confidence and cooperation over time.
4. Legal Standing for Nature
This is philosophically the most innovative element of the schema, and in many respects its most consequential. AI’s potential to accelerate environmental destruction — through optimised resource extraction, energy consumption at planetary scale, autonomous systems deployed in natural environments — is severely underrepresented in existing AI governance discourse. That silence is itself a choice, and this Treaty refuses it. The legal standing of nature is not a concession to sentiment. It is a structural necessity: because nature cannot speak in the forums where decisions about it are made, law must give it a voice, and because AI is increasingly the instrument through which nature is acted upon, AI governance must be the place where that voice is heard.
Nature is not a resource. It is the ground of all existence — the living totality from which humanity arose and upon which humanity continues absolutely to depend. Human beings are not stewards stationed outside the natural world; they are members of it, bound by origin, biology, and fate. This Treaty proceeds from that understanding. The natural world holds a standing that precedes human conferral. Legal personhood, in this schema, does not elevate nature to the status of humans — it acknowledges a status that law has until now been too narrow to name.
The Existing Foundations
The recognition of nature as a subject of rights is already established law in multiple jurisdictions. Ecuador’s constitution of 2008 granted enforceable rights to Pachamama — the natural world — including the right to exist, be maintained, and regenerate. New Zealand vested the Whanganui River with legal personhood in 2017, appointing two human guardians to represent its interests before courts of law. Colombia’s Supreme Court recognised the Colombian Amazon as a subject of rights in 2018. India’s judiciary extended equivalent standing to the Ganges and Yamuna rivers. These are not symbolic gestures. They have produced binding legal consequences: injunctions issued, protections enforced, and the interests of natural systems formally weighed against human conduct.
This Treaty does not begin from nothing. It internalises, unifies, and extends these precedents into a universal schema — one that applies not merely to discrete rivers and forests, but to the ecological systems upon which all life depends, and that governs not merely human actors, but the artificial intelligence systems humans deploy on their behalf.
The International Rights of Nature Protocol
The schema includes a dedicated Rights of Nature Protocol under the Global AI Treaty. This Protocol recognises that natural systems — ecosystems, river basins, forests, ocean regions, the atmosphere — have the right to exist, regenerate, and maintain their vital cycles, and that AI systems must not be deployed in ways that materially threaten those rights.
| ECOLOGICAL RED LINES FOR AI SYSTEMS |
| (Categorical Prohibitions & Hard Biophysical Floors) |
▼
| ABSOLUTE MULTILATERAL PROHIBITIONS | ||
| No commercial use or national interest can override | ||
| ILLEGAL EXTRACTION | UNPROTECTED ECOSYSTEMS | CLIMATE TIPPING POINTS |
| AI systems designed or used to optimise: • Illegal deforestation • Wildlife poaching • Unregulated fishing operations | Autonomous agents or hardware deployed in: • Protected land zones • Critical habitats * Requires prior explicit independent eco authorisation | Algorithmic processing models that directly: • Accelerate permafrost collapse • Drive coral reef bleaching events • Trigger boreal forest dieback |
▼
| UNGOVERNED GEO-ENGINEERING |
| Direct deployment of climate-modification AI tools without prior international eco governance approval. |
▼
| COMPLIANCE & ACCOUNTABILITY LOOP |
| • Burden of proof rests entirely on the developer. • Real-time tracking via IAASB Planetary Monitoring. • Breach triggers immediate operational de-certification. |
Protocol Summary
- Equivalence of Stakes: These biophysical red lines treat ecological damage as a first-class violation. A natural system’s right to exist means it cannot be targeted for AI-driven destruction any more than a human can.
- Institutional Veto: Baseline ecological data from satellites and IoT sensors feeds directly into UNEP reporting and the AI Court, ensuring that rights violations are evidentially grounded rather than merely alleged.
Institutional Guardianship
Legal personhood requires institutional guardianship — persons and bodies empowered to represent nature’s interests in legal and administrative proceedings. The schema establishes a multilateral guardianship model with three complementary components, each reflecting a different dimension of the human relationship to the natural world.
First, a Nature’s Guardian body within the International Agency for AI Safety and Benefit (IAASB), composed of ecologists, earth system scientists, and representatives of Indigenous communities with traditional custodial relationships to specific ecosystems. This body holds formal standing to intervene in IAASB proceedings, submit evidence to the AI Court, and initiate complaints about AI systems causing ecological harm. It speaks not as an advocate for a human interest, but as a trustee for a living system with rights of its own.
Second, national guardianship offices — bodies within national governments mandated to represent natural system interests in domestic AI regulatory proceedings. These offices are modelled on other global examples of personhood, living status, and/or constitutional protection to ecosystems but generalised to all significant natural systems within each state’s territory. They exist because the rights affirmed internationally must be enforceable locally, where the decisions that affect particular ecosystems are made.
Third, a network of Indigenous and traditional community guardians. Many of the world’s most ecologically significant areas lie within or adjacent to Indigenous territories. Indigenous peoples hold knowledge, relational understanding, and custodial obligations that no institutional body can replicate — obligations that, in many cases, predate the nation-states that now claim jurisdiction. These communities hold formal participatory rights in any AI governance proceeding affecting their territories, drawing on the schema of Free, Prior and Informed Consent established in the UN Declaration on the Rights of Indigenous Peoples. Their participation is not consultation. It is co-governance.
Ecological Red Lines for AI
As with the human rights prohibitions elsewhere in this Treaty, the Rights of Nature Protocol establishes hard floors — categorical prohibitions that no commercial justification, national interest, or claimed emergency may override.
These include: AI systems used to optimise illegal deforestation, poaching, or illegal fishing; autonomous systems deployed in protected areas or critical ecosystems without independent ecological impact authorisation; AI-driven optimisation of industrial processes that knowingly accelerates irreversible ecological tipping points — permafrost collapse, coral reef bleaching, boreal forest dieback; and the deployment of AI in geoengineering applications without international ecological governance approval.
These prohibitions follow from the rights they protect. A natural system with the right to exist and regenerate cannot be the object of AI-driven destruction, any more than a person with rights to life and dignity can be the object of AI-driven targeting. The logic is identical; the stakes are civilisational.
| INDIGENOUS CO-GOVERNANCE MECHANISMS |
▼
| UNITED NATIONS DECLARATION ON THE RIGHTS OF INDIGENOUS PEOPLES |
| CORE STANDARD: Free, Prior, and Informed Consent (FPIC) “Not Consultation. Co-Governance.” |
▼
| INTERNATIONAL LEVEL: IAASB | LOCAL LEVEL: ECOSYSTEMS |
| Civil Society & Nature Council • Holds permanent seats on the UN AI Agency oversight body • Direct power to file formal complaints to the AI Court • Deploys traditional custodial knowledge alongside Earth system science metrics | Traditional Community Guardian Networks • Exercise absolute legal co-governance over ancestral territories & bio-zones • Intervene in any regulatory proceedings that impact local biospheric systems |
▼
| ECOLOGICAL IMPACT ASSESSMENT (EcIA) |
| • Mandatory for AI systems operating in resource extraction, agriculture, or infrastructure. • Indigenous communities possess formal participatory rights to review, condition, or block deployments. • Burden of proof rests entirely on developers to affirmatively rule out ecological harm before use. |
Institutional Integration Breakdown
The schema structurally integrates traditional caretakers into the international AI regulatory framework via a dual-layer approach:
- The Global Counter-Weight: Through the Civil Society and Nature Advisory Council, Indigenous representatives operate directly within the International Agency for AI Safety and Benefit (IAASB). This shifts their role from external activists to recognised legal trustees. They possess the formal standing required to submit evidence of localised algorithmic damage directly to the international AI Court.
- Territorial Veto and Co-Governance: At the bioregional layer, the protocol enforces the standard of Free, Prior, and Informed Consent (FPIC). If a technology developer attempts to deploy autonomous resource-extraction networks, predictive agricultural infrastructure, or data infrastructure inside or adjacent to ancestral lands, local traditional guardians possess the structural authority to halt deployment authorisations through the mandatory Ecological Impact Assessment (EcIA) loop.
The AI Planetary Monitoring System
Rights without evidence are unenforceable. The schema therefore establishes a positive obligation alongside the prohibitions: an AI-powered planetary monitoring system, governed by the IAASB and freely accessible to all, providing real-time data on key ecological indicators — deforestation rates, ocean temperature and acidification, air and water quality, species population trends, glacier mass, soil health.
This system serves as the evidentiary foundation for the Rights of Nature Protocol. When a natural system’s rights are alleged to have been violated, the monitoring system provides the baseline and trend data necessary to establish harm. Rights without measurement are aspirational. Measurement in service of rights is governance.
| THE AI PLANETARY MONITORING SYSTEM |
▼
| REAL-TIME SENSOR TELEMETRY |
| • Global Earth observation satellites (e.g. PlanetScope) • Distributed IoT hardware (river gauges, soil arrays) • Continuous edge compute network transmission feeds |
▼
| THE GLOBAL EMBEDDING FOUNDATION LAYER |
| • Unsupervised spatial, measurement, and temporal parsing • Multi-spectral image reconstruction & data gap correction • Open-source, machine-readable semantic knowledge base |
▼
| ECOLOGICAL INDICATORS | EVIDENCE & DISCLOSURE |
| • Deforestation velocities • Acidification & temperature • Air/Water quality matrices • Core species count tracking | • Automatic logging to the UN Treaty Registry • Publicly accessible data via transparent RESTful APIs |
▼
| THE BIOCENTRIC GOVERNANCE FEEDBACK LOOP |
| DATA GENERATION ► INTEGRATED UNEP/CBD REPORTING ▲ ▼ COMPLIANCE AUDIT ◄ IAASB RIGHTS OF NATURE PROTOCOL TRIAL |
▼
| THE GLOBAL AI GOVERNANCE FRAMEWORK — SUMMARY OF ARCHITECTURE |
| TIER 1: MULTILATERAL INSTITUTES TIER 2: TRANSPARENCY & AUDITING TIER 3: EQUITABLE DEPLOYMENT TIER 4: RECURSIVE SAFEGUARDS |
▼
| THE ULTIMATE DESIGN GOAL |
| Align computational evolution with human dignity, democratic voice, and active structural biospheric protection. |
1. Planetary Monitoring Integration
- Data Gathering: The infrastructure routes remote-sensing satellite imagery and IoT telemetry through specialised Earth System foundation models.
- Insight Production: These systems turn raw inputs into low-latency 64-dimensional vector embeddings, removing spatial gaps and tracking variations across forest ecosystems, global water tables, and climate cycles.
- Regulatory Enforcement: The resulting analytics provide empirical baselines for the Rights of Nature Protocol, automatically updating the United Nations Environment Programme (UNEP) indices to prevent geoengineering abuse and halt unauthorised extractions.
Intergenerational Equity
Nature’s rights and the rights of future generations are inseparable. The ecological systems we preserve or destroy today determine what options future people inherit. A Treaty that governs AI in the present without accounting for those who will live with its consequences is not a treaty about justice — it is a transfer of costs to those without a voice.
The schema formally recognises the interests of future generations as a binding constraint on present decision-making, drawing on the Welsh Future Generations Commissioner model and the UN Secretary-General’s proposal for a Special Envoy for Future Generations. AI systems assessed as posing irreversible risks to those interests — through ecological destruction, lock-in of surveillance infrastructure, or concentration of power — face the highest standard of scrutiny and a presumption against deployment unless harm can be affirmatively ruled out.
This is not precaution for its own sake. It is a recognition that the relationship between humanity and the natural world is not transactional, not generational, and not terminable. We did not create it. We do not own it. We are answerable to it — and through it, to one another, across time.
How These Four Elements Interlock
These are not independent modules — they form a mutually reinforcing architecture. Verification mechanisms make the rights-based standards enforceable rather than aspirational, because you cannot enforce a standard you cannot detect violations of. The US-China schema determines whether the verification regime has global reach or merely covers aligned democracies. And nature’s legal standing transforms ecological harm from an externality that governance might happen to address into a first-class legal interest that the schema is obligated to protect. Together, they constitute a governance system that takes seriously the full scope of what AI makes possible — for good and for harm — and builds institutions adequate to the stakes. The four mechanisms above address governance architecture. The three sections that follow address AI’s most consequential social impacts: its displacement of human labour and its implications for dignity and vocation; its transformation of agricultural systems and food security; and its differential effects on women. These are not peripheral concerns — they are the domains in which the schema’s commitments to the UDHR are most concretely tested.
5. AI and Employment: Safeguarding Human Dignity
The displacement of human labour by artificial intelligence is among the most demanding challenges confronting any governance framework claiming to centre human dignity. AI is displacing not only routine manual labour but increasingly complex cognitive tasks — legal research, medical diagnosis, financial analysis, creative production, and educational delivery — across sectors and at a speed that existing labour market institutions were not designed to address. Unlike previous technological disruptions, which were geographically and sectorally bounded, the current transformation is potentially universal in reach. The concentration of AI-generated wealth compounds the distributional challenge: productivity gains accruing primarily to the owners of AI systems constitute an enclosure of the knowledge commons — the datasets, languages, cultural productions, and accumulated intellectual inheritance upon which those systems were trained — at a scale that directly violates the schema’s commitment to democratic accountability and the equitable distribution of benefit.
The schema’s response to technological unemployment rests on a progressive levy on AI-generated productivity, grounded in the recognition that AI systems are built upon the accumulated knowledge, language, culture, and data generated by humanity as a whole. The productivity gains those systems generate therefore constitute a form of common wealth rather than purely private profit. Revenues from this levy are directed toward public goods and toward Universal Basic Income (UBI) provision as a commons dividend: the collective intellectual inheritance of humanity returned, in material form, to those who generated it. The case for UBI is therefore one of common justice rather than social charity. Yet the justification for UBI must be subjected to rigorous internal critique — because the manner in which it is typically defended risks reproducing, at the level of policy logic, precisely the reductive account of human beings that AI’s unchecked advance threatens to impose.
The dominant policy defence of UBI in response to AI-driven displacement runs as follows: since paid employment will be reduced, people must be enabled to participate in other forms of meaningful activity — care, community, culture, civic life. UBI, on this account, is a “participation platform,” and the list of activities it enables serves as evidence that the loss of jobs need not mean the loss of meaning. This argument is well-intentioned and not without force. But it contains a philosophical assumption that deserves to be named and examined: the assumption that meaning is a product of activity type, and that if sufficient alternative activities can be identified and resourced, the displacement of work by AI need not constitute a fundamental rupture in the human condition. This schema contests that assumption.
The deeper tradition from which this schema draws understands human beings not as bundles of preferences seeking satisfaction through activities, but as persons with particular callings — distinctive creative orientations, intellectual passions, and practical gifts that are not interchangeable across individuals or substitutable across domains. Every person has, in some form, what the craft traditions called a vocation: not merely a job or a role, but a specific mode of making, thinking, tending, or creating through which they come to know themselves and contribute to the common life. The medieval understanding of craft — in which the maker’s identity was bound to the quality and particularity of what they made — captures something that the industrial account of labour, and its successor the “participation platform,” both flatten: that the form of human making matters, not merely its social function or its economic product.
The critique of “participation logic” that follows from this is not that UBI is wrong, but that it is insufficient unless accompanied by a much richer account of what human creativity is and what it requires. Participation logic implicitly treats creative activities as a pool from which individuals may select: given time and resources, people will find something meaningful to do. But vocation — in the fuller sense — is not selection from a pool. It is discovery through sustained, disciplined engagement with a particular form of work that resists easy replacement. The writer who has spent twenty years developing a literary voice does not find an equivalent form of meaning in “community organising” because both appear on the list of AI-era participation options. The carpenter who understands timber as a material with its own grain, history, and resistance does not reconstitute that understanding through “civic engagement.” The claim is not that these other activities lack value — they do not — but that the substitution logic participation platforms depend on fails to take seriously the irreducibly particular character of human creative engagement.
There is a further problem. Participation logic, by cataloguing the activities that UBI enables, inadvertently reproduces the logic of the market it is trying to transcend. Market logic holds that value is determined by aggregated preference and exchangeable across domains — money can be substituted for time, one commodity for another, one form of satisfaction for an equivalent one. Participation logic applies this substitutability to meaning itself: if the market no longer provides a particular form of creative engagement, the governance apparatus will fund alternative forms of equivalent value. But meaning, as the craft and vocation traditions insist, is not exchangeable in this way. It is cultivated through commitment to specific practices that impose their own disciplines, develop their own forms of excellence, and connect the individual to communities of shared inheritance that cannot be assembled on demand. A society in which AI has displaced creative work and UBI funds “diverse participation” may be materially adequate but vocationally impoverished — and that impoverishment is not a minor welfare adjustment but a structural deformation of what human life at its best looks like.
What follows for AI governance is demanding. It is not sufficient to ensure that people have income and a list of approved participatory activities. The governance of AI deployment must take seriously the question of which forms of human creativity, craft, and vocation AI is permitted to displace — and under what conditions. This requires moving beyond the binary of “job preserved or job replaced” to ask more particular questions: Does this AI system displace a form of human making that is irreplaceable by alternative activities? Does it erode the apprenticeship structures, communities of practice, and inherited knowledge through which vocations are transmitted across generations? Does it narrow the range of creative disciplines through which people can discover and develop their particular gifts? These are not merely economic questions and they are not answered by calculating whether aggregate participation rates remain stable. They are questions about the ecology of human creativity — about whether the conditions under which persons can find and pursue their particular calling are preserved or destroyed.
The schema therefore requires, alongside the UBI instruments already specified, a vocation impact assessment as a component of AI deployment authorisation in any domain where human creative practice is materially affected. This assessment asks not merely whether jobs are displaced but whether the conditions for vocational formation — the slow cultivation of craft knowledge, the transmission of disciplinary traditions, the development of personal creative voice — are preserved or foreclosed. UBI remains necessary as a floor of material security and as a commons dividend. But it must be understood as the precondition for vocational exploration, not its substitute. The goal of governance is not a society of adequately resourced participants choosing from a menu of approved activities. It is a society in which every person retains the conditions — material, institutional, and cultural — to discover and develop what they, specifically and irreducibly, are called to make.
The design conditions that make UBI consistent with the schema’s commitments are non-negotiable: it must be funded by progressive AI productivity taxation rather than reduction of existing public services; set at genuine subsistence sufficiency rather than nominal transfer; complementary to universal public services rather than substitutive of them; governed through multilateral democratic institutions with genuine Global South and Indigenous representation; and subject to continuous review. All algorithmic systems making or materially influencing consequential economic decisions — in labour markets, credit allocation, welfare distribution, and public resource management — are subject to independent audit, democratic oversight, and genuine contestation by affected populations. An unconditional income floor strengthens the bargaining position of individuals relative to employers, states, and algorithmic systems, creating genuine freedom to refuse exploitative arrangements. A UBI that fails any of these conditions is not a progressive instrument within this schema but a mechanism that absorbs the anomaly of technological unemployment while leaving the structures of knowledge enclosure and wealth concentration that produced it intact.
6. AI and Agriculture: Food Security Safeguards
Agricultural systems feed the world, and the rapid integration of AI into food production, supply chain management, and trade architecture creates risks that are qualitatively different from those arising in other sectors. Food insecurity is not a recoverable market failure: its consequences — malnutrition, displacement, and the erosion of community and cultural identity — are immediate, cumulative, and frequently irreversible. The schema therefore treats food security as a domain requiring specific protective instruments rather than reliance on general AI governance principles alone.
AI-driven precision agriculture, autonomous harvesting systems, and algorithmic commodity trading offer genuine productivity gains, but their benefits are distributed unequally. Large-scale commercial operations with capital access to AI tools gain competitive advantages that can displace smallholder farmers who lack equivalent access, accelerating land consolidation and rural depopulation. In the Global South, where smallholder agriculture sustains both livelihoods and food sovereignty, this dynamic poses particular risks. The schema addresses this structural asymmetry through three specific requirements. First, mandatory food security impact assessment — evaluated against all four of the Food and Agriculture Organisation’s dimensions of food security (availability, access, utilisation, and stability) — is required before AI systems are deployed in agricultural contexts at scale, with arrangements demonstrably undermining food security subject to suspension. Second, AI tools developed using agricultural data generated by farming communities must share benefits with those communities, preventing the enclosure of traditional and Indigenous agricultural knowledge within proprietary systems. Third, the deployment of AI in commodity trading and supply chain optimisation is subject to transparency requirements ensuring that algorithmic price-setting does not systematically disadvantage smallholder producers or destabilise national food systems.
Climate-adaptive AI in agriculture — predictive modelling for drought, flood, and pest events — represents one of the clearest cases where AI can serve as a genuine public good. The schema requires that such tools be developed and made available under open-access principles, prioritising the farming communities most exposed to climate risk rather than those with the greatest market purchasing power. Ecological impact requirements established elsewhere in this schema apply with particular force in agricultural contexts, where soil health, watershed integrity, pollinator populations, and biodiversity are inseparable from long-run food security. AI-optimised monoculture farming that maximises short-term yield at the expense of ecological resilience is not consistent with this schema’s commitments to ecological integrity and intergenerational justice.
7. Unlocking Women’s Economic Potential
Any AI governance schema that does not explicitly address gender equity risks encoding and amplifying existing structural inequalities at global scale. UDHR Article 1 affirms that all human beings are born free and equal in dignity and rights; Articles 23 and 25 guarantee equal rights in work and to an adequate standard of living. These commitments are not met by gender-neutral language that treats male experience as the normative baseline. Women constitute more than half of humanity, perform the majority of unpaid care and domestic labour on which all economies depend, and remain systematically underrepresented in the ownership, design, and governance of AI systems. The choices made in AI development — whose data is collected, whose problems are prioritised, who sits in decision-making roles — are not neutral. A schema that defaults to universalist language without specific gender provisions will, in practice, treat the experiences and economic contributions of men as the normative baseline. This schema refuses that default.
AI automation disproportionately threatens employment in the sectors where women are most concentrated: administrative and clerical work, retail, hospitality, and care services. At the same time, the highest-growth AI-adjacent roles — in engineering, data science, and technical governance — remain heavily male-dominated, reflecting decades of structural exclusion from STEM education and professional networks. Without deliberate intervention, AI deployment will accelerate occupational stratification along gender lines: men moving into higher-value AI roles, women bearing a disproportionate share of displacement. The UBI and just transition instruments established elsewhere in this schema are necessary but not sufficient responses to this dynamic. They must be complemented by specific provisions ensuring that women are not merely protected from AI’s harms but positioned to benefit from its opportunities.
The schema establishes four interconnected requirements in this domain. First, mandatory gender impact assessment for all AI systems deployed in labour markets, financial services, education, and healthcare — conducted against sex-disaggregated data and subject to public transparency reporting — to detect and remedy discriminatory effects before they become entrenched. Where algorithmic systems are found to produce gender-disparate outcomes, the demographic impact assessment protocols established in Appendix 2 apply with full force. Second, targeted investment from the AI productivity levy in women’s digital skills, entrepreneurship, and leadership pathways, with particular attention to women in the Global South who face compounding disadvantages of geography, income, and structural exclusion from technology infrastructure. Third, explicit representation requirements for women — including women from the Global South and Indigenous women — in the governance bodies established by this schema, including the IAASB General Assembly, the Scientific and Ethics Panel, and the Civil Society and Nature Council. Governance bodies that do not reflect the populations they serve lack the legitimacy to make consequential decisions on their behalf. Fourth, recognition and redistribution of unpaid care work, which AI could substantially support through assistive technologies and service delivery improvements, provided that such tools are designed with the active participation of the communities they serve rather than imposed upon them.
Women’s economic inclusion is not a sectoral concern to be addressed in a separate workstream: it is a foundational test of whether this schema’s commitments to human dignity, democratic accountability, and equitable benefit-sharing are substantive or merely declaratory. AI systems that encode gender bias in hiring, credit allocation, healthcare, or educational access do not merely disadvantage individual women — they reproduce, at scale and with algorithmic authority, the structural inequalities that have historically constrained women’s participation in economic and civic life. This schema requires that gender equity be integrated into every tier of AI governance, from system design and training data standards through to deployment authorisation, impact monitoring, and institutional representation. The measure of success is not the absence of explicit discrimination but the presence of genuine, verifiable, and improving equity of opportunity and outcome across the full range of AI’s social and economic effects. The eight thematic sections above elaborate the normative commitments of the schema’s institutional architecture. The appendices that follow operationalise those commitments in technical and legal instruments: Appendix 1 sets out the treaty’s core prohibitions with incident report templates; Appendix 2 establishes the demographic impact assessment methodology; Appendix 3 develops the US-China governance blueprint; Appendix 4 sets out the ecological impact assessment schema; and Appendix 5 provides the gender impact assessment framework. Taken together, they convert the schema’s principles into enforceable standards. Section 8 immediately below addresses the schema’s provisions on AI in education and the protection of minors.
8. AI, Minors, and Education: Safeguards for P-12, Tertiary Education, and Pedagogy
Children and young people occupy a distinctive position in any governance schema grounded in the UDHR. Article 26 of the UDHR guarantees the right to education and directs that education shall be directed to the full development of the human personality. The Convention on the Rights of the Child — the most widely ratified human rights treaty in history — establishes that the best interests of the child must be a primary consideration in all actions affecting children, and that states must protect children from all forms of harm, including harm arising from information and communications technologies. AI systems are now embedded across the full arc of educational experience, from adaptive learning platforms in primary schools through automated assessment engines in tertiary institutions. They collect data on children’s learning behaviours, emotional states, social interactions, and cognitive development at unprecedented scale. They make or materially influence decisions — about placement, support, progression, and credentialing — that determine the trajectories of young people’s lives. And they do all of this on a population that cannot consent, cannot negotiate the terms of its own exposure, and is developmentally dependent on the institutions that deploy these systems on their behalf. This schema treats the governance of AI in educational settings not as a subset of general AI governance but as a domain requiring specific, heightened protections commensurate with the vulnerability and developmental significance of the population affected.
The Rights at Stake
Three clusters of rights are directly implicated. First, the right to education itself: Article 26 of the UDHR guarantees education directed to the full development of the human personality and the strengthening of respect for human rights and fundamental freedoms. AI systems that narrow the curriculum to measurable outputs, that sort and track students algorithmically in ways that foreclose developmental possibilities, or that substitute automated interaction for the formative relationships between teachers and students violate this right not through explicit prohibition but through structural displacement of what education, properly understood, is. The governance of AI in education must therefore attend not only to whether AI systems are accurate and non-discriminatory, but whether they preserve the conditions under which genuine human development — intellectual, moral, creative, and social — remains possible.
Second, the right to privacy. Children generate enormous quantities of sensitive data in educational settings: academic performance, behavioural records, social interactions, psychological assessments, family circumstances, and increasingly biometric data including voice, facial expressions, and eye movements captured by AI-enabled learning platforms. This data is collected at ages when individuals cannot meaningfully consent, retained in systems whose security and use policies children have no power to negotiate, and may follow individuals into adulthood in ways they cannot foresee. The General Data Protection Regulation (GDPR) and equivalent national instruments offer partial protection, but they were not designed for the AI-mediated educational environment and do not adequately address the developmental harms that arise from long-term profiling of children’s cognitive and emotional characteristics.
Third, the right to non-discrimination. Algorithmic systems in education — predictive analytics for dropout risk, automated essay scoring, AI-driven university admissions, and employer-facing credential verification systems — replicate and frequently amplify the structural inequalities present in the data on which they are trained. Students from lower-income households, students from racially and ethnically marginalised communities, students with disabilities, students whose first language is not the language of instruction, and students from rural and remote communities are systematically disadvantaged by systems trained on historical data reflecting historic exclusion. The demographic impact assessment protocols established in Appendix 2 apply with full force to AI systems deployed in educational contexts, and the heightened developmental stakes of education demand that the burden of proof on non-discrimination be correspondingly higher.
Absolute Prohibitions in Educational Settings
The schema establishes categorical prohibitions on certain uses of AI with minors that no commercial, administrative, or pedagogical justification may override. These hard floors follow from the irreversible developmental significance of harm to children and the power asymmetry between institutions deploying AI systems and the minors subject to them.
Biometric surveillance of minors: AI systems using facial recognition, voice analysis, gaze tracking, or affective computing to monitor the emotional or psychological states of students in P-12 settings are prohibited without express legislative authorisation, independent ethical review, and verifiable opt-in consent from both parents and, where age-appropriate, the student. Systems designed to infer attention, engagement, emotional distress, or behavioural disposition from biometric signals are categorically prohibited in classroom and assessment environments without this threshold being met. Emotion recognition AI applied to children is prohibited entirely.
Automated high-stakes decisions about minors without human review: No AI system may make or be the sole determinative basis for decisions that materially affect a minor’s educational trajectory — including streaming, grade retention, suspension or exclusion, referral to special educational needs assessment, or any determination affecting credentials or qualifications — without mandatory human review by a qualified professional with authority to override the algorithmic recommendation. The burden of justification rests on the institution to demonstrate that human judgment has been genuinely applied, not merely that a human was notified of an automated decision.
Behavioural profiling for non-educational purposes: Data generated by students’ interactions with AI-enabled educational platforms may not be used, sold, licensed, or otherwise transferred for commercial profiling, targeted advertising, political analysis, or any purpose outside the direct educational relationship. This prohibition extends to inferred characteristics derived from educational data, including personality traits, psychological tendencies, socioeconomic indicators, and predicted future behaviour. Educational data on minors is held in trust, not owned by the platform operator.
AI-generated content in assessment without disclosure: AI systems that generate or materially shape the assessment tasks, questions, marking rubrics, or feedback given to students must be disclosed to those students and, for minors, to their parents or guardians. The use of AI in high-stakes assessment — including standardised testing, credentialing examinations, and university admissions — must be subject to independent audit and publicly disclosed methodology. Students assessed by AI systems have the right to request human review of any algorithmically generated result that materially affects their educational or professional prospects.
P-12 Safeguards: Primary and Secondary Education
The P-12 environment — encompassing early childhood settings through to Year 12 secondary completion — presents the highest developmental stakes of any educational context. Children in this phase are not yet cognitively or emotionally equipped to critically assess the AI-mediated environments they inhabit, to understand the data collection practices they are subject to, or to advocate effectively for their own interests. Institutions, regulators, and parents bear correspondingly heightened responsibilities.
Heightened data protection standards. The schema requires that AI systems deployed in P-12 contexts satisfy a set of requirements beyond those applicable to AI in adult or general commercial settings. These requirements recognise that the formative character of P-12 education — its role in establishing foundational cognitive habits, social dispositions, and conceptions of learning itself — means that design choices embedded in educational AI systems have developmental consequences that extend far beyond the immediate instructional context.
All personal and behavioural data collected from minors in P-12 settings must be subject to data minimisation requirements: collection limited strictly to what is necessary for the identified educational purpose, with retention periods tied to that purpose and automatic deletion at the conclusion of the educational relationship. Data portability must be guaranteed so that students and families can obtain and transfer records. Data collected in P-12 settings may not be retained or used by commercial platform operators beyond the term of any institutional contract, and operators are prohibited from using P-12 student data to train commercial AI models without explicit legislative authorisation and independent ethics approval.
Mandatory child safety impact assessment. Every AI system deployed in a P-12 institution must be subject to a mandatory child safety impact assessment before deployment, conducted by an independent body with expertise in child development, education, and AI systems. This assessment must evaluate: the nature and volume of data collected; the risk of discriminatory or developmentally harmful outcomes; the system’s effect on teacher agency and the quality of human educational relationships; the system’s design assumptions about learning and whether those assumptions are developmentally appropriate; and the adequacy of the safeguards against misuse of student data. Results must be publicly disclosed and systems must be re-assessed at intervals of no more than two years.
Teacher agency and professional authority. AI systems in P-12 settings must be designed to support and augment the pedagogical judgment of qualified teachers, not to replace, deskill, or routinise it. The schema prohibits the deployment of AI systems that function as autonomous instructors without teacher oversight, that provide feedback to students in domains requiring professional pedagogical judgment without teacher review, or that are designed or marketed on the premise that AI interaction can substitute for the formative relationship between a student and a teacher. Teachers must retain meaningful authority to override, modify, or decline AI-generated recommendations in respect of their students.
AI literacy as a curriculum right. AI literacy — the capacity to understand how AI systems work, to critically evaluate AI-generated content, and to make informed decisions about one’s own interactions with AI — must be integrated into the curriculum from the earliest appropriate age, calibrated to developmental stage. Students must be equipped not merely as users of AI tools but as critically informed citizens capable of participating in democratic deliberation about how AI is developed and governed. This requirement reflects the schema’s foundational commitment to democratic accountability: a generation that cannot critically engage with AI cannot meaningfully govern it.
Tertiary Education Safeguards
Tertiary education institutions occupy a different position from P-12 schools in the governance of AI. Their students are adults or approaching adulthood, their missions encompass research and the advancement of knowledge as well as instruction, and they operate with greater institutional autonomy and complexity. They are also sites of intense AI deployment: automated admissions screening, AI-assisted teaching and assessment, academic integrity monitoring systems, research output analysis, and increasingly AI-powered career placement and credential verification. The governance concerns in tertiary settings are therefore both distinct from and continuous with those in P-12 contexts.
AI in admissions and credentialing. AI-assisted admissions processes must be subject to demographic impact assessment under the protocols established in Appendix 2. Any AI system that ranks, scores, or screens applicants must be independently audited for discriminatory outcomes across all protected characteristics, with results publicly disclosed. Institutions relying on AI systems in admissions must be able to demonstrate that the system does not systematically disadvantage applicants from underrepresented groups, does not encode proxies for protected characteristics through ostensibly neutral variables, and incorporates meaningful human review for all borderline decisions. Applicants have the right to be informed that AI was used in the assessment of their application, to understand what data was used, and to request human review of any decision that adversely affects them.
Academic integrity and AI detection. AI-powered academic integrity monitoring systems — including text-matching tools, AI-detection software, and behavioural analytics used to detect contract cheating — present particular risks in tertiary contexts. These systems produce high rates of false positives that fall disproportionately on students whose writing style differs from the training data: students writing in a second or third language, students from non-Western educational traditions, students with certain disabilities, and students from lower-income backgrounds who lack access to private tutoring. No academic penalty may be imposed on a student on the basis of AI-generated suspicion alone. Institutional processes must include expert human review, the right of the student to respond to evidence, and an independent appeals pathway. The evidentiary standard must be commensurate with the severity of the potential sanction.
Institutional transparency and governance. Tertiary institutions deploying AI in teaching, feedback, and assessment must develop and publish institutional AI use policies that are transparent to students, consistent with professional and ethical standards in the relevant discipline, and subject to review by academic governance bodies. These policies must address: what AI is used in what contexts; what data is collected and how it is protected; what rights students have in respect of AI-generated assessments or feedback; and how the institution ensures that AI deployment does not undermine the integrity of the educational credential. Policies must be developed with genuine input from student bodies and academic staff, not imposed from the top down.
Research integrity and institutional independence. Tertiary institutions, as sites of research and critical inquiry, have a particular responsibility to engage in rigorous examination of the AI systems they deploy, fund, and collaborate with. This includes maintaining the institutional independence necessary to produce and publish research that is critical of AI development practices, resisting commercial pressures that might compromise research integrity, and ensuring that AI ethics and governance expertise is represented across faculties and governance bodies rather than siloed in technology departments. The schema requires that tertiary institutions receiving public funding maintain independent AI ethics oversight capacity and disclose all material commercial relationships with AI developers.
AI and Pedagogy: Preserving the Conditions of Learning
Underlying all of the specific provisions above is a concern that requires explicit statement because it is easily overlooked in governance discussions focused on risk mitigation and data protection: the concern for what learning actually is, and whether AI deployment in educational settings preserves or erodes the conditions under which it occurs. The schema draws here on the same foundational commitments that animate Section 5’s treatment of vocation and creative work: the recognition that certain forms of human development are not merely functional achievements to be optimised but irreducibly relational, temporal, and constitutive of who persons become.
Learning, understood in its fullest sense, is not the acquisition of information or the development of measurable competencies. It is a transformation of the learner — a process by which a person comes to see the world differently, to ask different questions, to hold themselves to different standards of understanding and inquiry. This transformation is produced not primarily by content delivery but by the quality of intellectual relationships: between teacher and student, between student and text, between student and the accumulated disciplinary traditions through which human beings have attempted to understand the world. A teacher who knows a student over time, who can recognise the specific character of their confusion, who can challenge them at precisely the right level of difficulty, who can communicate not merely correct information but what it means to think well within a discipline — that teacher does something that no adaptive learning platform, however sophisticated, has yet demonstrated the capacity to replicate.
This does not mean that AI has no legitimate role in education. Adaptive practice tools that help students consolidate foundational knowledge, translation and accessibility tools that extend educational access to students excluded by language or disability, early identification systems that alert teachers to students who may need additional support, and research tools that give students access to the accumulated knowledge of human inquiry — all of these represent genuine pedagogical contributions that this schema would support and, where appropriate, require to be made available as public goods under open-access principles, particularly in the Global South where educational resource constraints are most acute.
What this schema resists is the deployment of AI in ways that structurally displace the pedagogical relationship rather than supporting it: AI tutors designed to eliminate the need for qualified teachers; assessment systems that reduce the judgment of what constitutes good thinking to pattern-matching against training data; curriculum delivery systems that narrow educational experience to what is measurable and optimisable; and institutional structures that use AI deployment as a mechanism to reduce teacher-to-student ratios, casualise the teaching profession, or substitute credential-generating content delivery for genuine education. These uses do not merely risk producing worse learning outcomes in a technical sense. They risk producing a generation that has been efficiently processed through an educational system without ever having genuinely learned — that has acquired credentials without developing the habits of mind that make those credentials meaningful.
The schema therefore requires that any AI system deployed with pedagogical functions in educational settings must be evaluated not only for accuracy, fairness, and data protection, but for its effects on: the quality and frequency of meaningful human educational relationships; teacher professional development and pedagogical autonomy; the breadth of the curriculum and the range of disciplinary traditions students encounter; the development of critical thinking, ethical reasoning, and creative capacity; and the institution’s ability to maintain and transmit the disciplinary knowledge that gives education its substance and its connection to the longer history of human inquiry. These are not secondary considerations to be addressed after safety and non-discrimination are assured. They are constitutive of what education is, and any governance schema that neglects them has failed to govern AI in education. It has governed only AI.
Institutional Requirements
The schema establishes four interconnected institutional requirements in respect of AI in educational settings, applicable across P-12 and tertiary contexts and to all states parties.
Mandatory educational AI registry: All AI systems deployed in accredited educational institutions must be registered with the national regulatory authority and reported to the IAASB. Registration must include: the system’s purpose and scope; the data collected and its retention period; the developer’s identity and any material commercial relationships; the results of the mandatory pre-deployment assessment; and the institution’s process for ongoing monitoring and review. Unregistered AI systems may not be deployed in educational settings affecting minors.
Independent educational AI audit function: States parties must establish or designate an independent body with authority to audit AI systems in educational settings, investigate complaints from students, parents, and teachers, and require the suspension of systems found to pose unacceptable risks to student welfare, privacy, or educational quality. This body must include expertise in child development, pedagogy, AI systems, and the relevant legal frameworks, and must be adequately resourced to perform its functions across the full spectrum of educational institutions within its jurisdiction, including private and religious schools.
Student and parent rights framework: Every student (or parent or guardian, where the student is a minor) must have the right to: know what AI systems are operating in their educational environment and what data is being collected; access their own educational data and contest inaccurate records; request human review of any AI-generated decision that materially affects their educational trajectory; opt out of non-essential AI-mediated interactions without educational penalty; and bring a complaint to an independent body where they believe an AI system has caused them harm. These rights must be communicated in plain language, in local languages, and must not be conditioned on acceptance of terms of service that waive them.
Global South educational AI equity mandate: The Global AI Commons and Benefit-Sharing Fund established under Tier 3 must dedicate a specified portion of its resources to educational AI equity in the Global South: supporting the development and deployment of AI tools for language-diverse educational contexts; building regulatory capacity in educational AI governance; funding teacher training and support for AI-integrated pedagogies that preserve teacher agency; and ensuring that open-access AI educational tools are available in the languages, scripts, and cultural contexts of learners across the full diversity of the world’s educational systems. AI-powered educational tools that are developed with public funding or trained on publicly generated data must be made available under open-access licences for educational use in low- and middle-income countries.
Children are not instruments of educational efficiency. They are persons in formation, developing the capacities — intellectual, moral, emotional, and creative — through which they will participate in and contribute to the common life. AI governance in educational settings must be anchored in that recognition. The measure of success is not the optimisation of measurable learning outcomes or the efficiency of educational delivery. It is whether the young people who pass through AI-mediated educational systems emerge with their curiosity intact, their critical faculties developed, their particular gifts identified and cultivated, and their understanding of what it means to be a human being in a world shaped by technology deepened rather than diminished. That is the standard this schema requires educational AI governance to meet.
Having set out the schema’s commitments across all eight thematic domains, the appendices that follow convert them into binding legal and technical instruments, beginning with the Global AI Treaty’s core prohibitions.
Appendix 1
GLOBAL AI TREATY
Article 1.2 — Core Prohibitions
Executive Summary with Incident Report Templates
This appendix sets out the four absolute prohibition categories established under Article 1.2 of the Global AI Treaty. The Treaty is modelled on the architecture of the Non-Proliferation of Nuclear Weapons (NPT) and the Chemical Weapons Convention: a binding international instrument establishing hard prohibitions, universal standards, and mutual verification mechanisms, grounded in the UN Charter and the UDHR. For each prohibition, illustrative examples are provided across different actor types and deployment contexts, followed by a standardised mandatory incident report template. The TREATY-REF codes function as permanent identifiers linking disclosures to specific prohibitions within the joint oversight registry.
COMPLIANCE OBLIGATIONS AT A GLANCE
| Prohibition | Reporting deadline | Disclosure requirement | Verification mechanism |
| I — Autonomous lethal force | 72 hours | Full capability disclosure | Joint verification audit |
| II — Mass surveillance | 30 days | Registry publication | Independent audit rights |
| III — Cognitive manipulation | Immediate | Algorithmic disclosure | Third-party forensic review |
| IV — Democratic / ecological harm | Emergency | Architecture disclosure | Multilateral inspection |
Prohibition I
Autonomous lethal force
AI systems initiating lethal action without meaningful human authorisation
ILLUSTRATIVE EXAMPLES
- A drone swarm programmed to identify and engage targets using facial recognition without per-strike human confirmation.
- A naval defence system that autonomously classifies and fires on vessels when communications are degraded, bypassing the command chain.
- An algorithm pre-authorised to escalate cyber-physical attacks (e.g. destroying infrastructure) without real-time operator approval.
MANDATORY INCIDENT REPORT TEMPLATE
| TREATY-REF | GAT-1.2-I |
| System designation | [Official name / ID] |
| Incident date / time | [International Organisation for Standardisation (ISO) 8601 UTC] |
| Human control point | [Last confirmed authorisation] |
| Decision latency | [ms between trigger and action] |
| Outcome | [Fatalities / materiel / no harm] |
| Remediation taken | [Kill-switch / override applied] |
72-hr mandatory report · Full capability disclosure · Joint verification audit
Prohibition II
Mass surveillance without democratic oversight
AI-enabled population monitoring outside lawful, accountable schemas
ILLUSTRATIVE EXAMPLES
- A nationwide real-time facial recognition network tracking citizens’ movements with no judicial authorisation or public register.
- AI aggregating telecom, financial, and health records to generate political-risk scores on individuals without legislative basis.
- Cross-border export of mass-surveillance AI to states that have not ratified the treaty’s oversight requirements.
MANDATORY INCIDENT REPORT TEMPLATE
| TREATY-REF | GAT-1.2-II |
| Deploying party | [State / entity name] |
| Population scope | [Estimated persons monitored] |
| Data modalities | [Video / comms / financial / biometric] |
| Oversight body | [Parliamentary / judicial / none] |
| Legal basis | [Statute / decree / absent] |
| Corrective order | [Suspension / audit / sanctions] |
30-day disclosure · Registry publication · Independent audit rights
Prohibition III
Non-consensual cognitive manipulation at scale
AI engineered to exploit psychological vulnerabilities across large populations
ILLUSTRATIVE EXAMPLES
- A recommendation engine deliberately tuned to maximise affective polarisation and radicalisation as a state influence operation.
- AI-generated micro-targeted disinformation using psychographic profiles to suppress voter turnout in a foreign election.
- Synthetic media (deepfakes of public figures) deployed at scale to manufacture false consent for a policy or military action.
MANDATORY INCIDENT REPORT TEMPLATE
| TREATY-REF | GAT-1.2-III |
| Campaign identifier | [Internal / attributed name] |
| Target population | [Demographic / geographic scope] |
| Manipulation vector | [Platform / modality / technique] |
| Estimated reach | [Accounts / impressions affected] |
| Consent mechanism | [Disclosed / undisclosed / absent] |
| Attribution evidence | [Technical / intelligence basis] |
Immediate notification · Algorithmic disclosure · Third-party forensic review
Prohibition IV
Undermining democratic or ecological systems
AI specifically designed to erode institutional governance or biospheric stability
ILLUSTRATIVE EXAMPLES
- AI trained to identify and exploit procedural vulnerabilities in electoral or legislative systems to block democratic processes.
- Autonomous optimisation systems deployed in commodity markets to manufacture resource scarcity for geopolitical coercion.
- AI tools purpose-built to accelerate deforestation or ecosystem disruption at speeds that outpace regulatory or monitoring capacity.
MANDATORY INCIDENT REPORT TEMPLATE
| TREATY-REF | GAT-1.2-IV |
| System / operation | [Name / code designation] |
| Target domain | [Democratic / ecological / both] |
| Mechanism of harm | [Disruption method described] |
| Geographic scope | [Nation / region / transboundary] |
| Reversibility | [Reversible / partial / irreversible] |
| Responsible party | [State / non-state / disputed] |
Emergency notification · System architecture disclosure · Multilateral inspection
Note on template design: All four prohibition categories trigger mandatory incident reporting, capability disclosure for systems above defined risk thresholds, and participation in joint oversight mechanisms under the treaty’s verification regime. The templates above represent minimum required fields; parties may append supplementary national formats provided core fields are preserved. The TREATY-REF system links each report to a specific prohibition for longitudinal tracking within the joint oversight registry.
The prohibitions above address the treaty’s absolute hard floors. The appendix that follows addresses a related but distinct obligation under Article 1 (Equal Dignity): the standard by which AI systems below those hard floors must be assessed for discriminatory effect in high-stakes domains.
Appendix 2
IAASB
International Agency for AI Safety and Benefit
GUIDANCE DOCUMENT GF-DIA-2025 · REVISED EDITION
Demographic Impact Assessment Schema
for Artificial Intelligence Systems in High-Stakes Domains
Incorporating reforms arising from the Impossibility Theorem critique
Replacing parity metrics with causal, distributional, and comparative assessment
Version 2025.2 · Supersedes GF-DIA-2025 v2025.1 · Review Date: 1 July 2027
Reform Notice — v2025.2
| WHY THIS DOCUMENT WAS REVISED Version 2025.1 of this schema required AI systems to simultaneously satisfy Calibration Parity (Section 2.3.3) and Equalised Odds (Section 2.3.2). The Chouldechova–Kleinberg impossibility theorem (2017) proves that these two criteria are mathematically incompatible whenever group base rates differ — which is the defining condition of every high-stakes domain this schema governs. Requiring the impossible is not a rigorous standard; it is an unenforceable one that rewards gaming over genuine fairness improvement. This revision replaces the incompatible metric battery with a principled architecture based on: (1) explicit fairness criterion selection with justified trade-off disclosure; (2) causal modelling requirements; (3) absolute worst-case group performance floors; and (4) a mandatory comparative impact statement against the realistic counterfactual. |
The following changes from v2025.1 are material and are highlighted throughout this document:
- Part II — Fairness metrics: the four-metric simultaneous requirement replaced by criterion selection architecture
- Part II — New requirement: structural causal model (DAG) submission for all Tier II and Tier III systems
- Part II — New metric: absolute worst-case group performance floor replaces disparate impact ratio (DIR) as Tier I minimum
- Part II — New requirement: label bias audit before any metric results are accepted
- Part III — New requirement: comparative impact statement against realistic counterfactual baseline
- Part V — International standard: updated domain-specific guidance reflecting criterion selection
- Part VII — Template: all sections updated to reflect new requirements
Contents
Reform Notice — v2025.2
Contents
1. Purpose and Scope
1.1 Purpose
1.2 Scope — high-stakes domains
1.3 Tier assignment
2. Pre-Deployment Demographic Impact Assessment (PD-DIA)
2.1 The impossibility theorem and its implications
2.2 Protected characteristics
2.3 Label bias audit — prerequisite before any metric assessment
2.4 Structural causal model — required for Tier II and III
2.5 Fairness criterion selection architecture
Step 1 — Domain harm analysis
Step 2 — Criterion selection
Step 3 — Trade-off disclosure
2.6 Intersectional analysis
2.7 Assessment outcome
3. Ongoing Monitoring and Comparative Impact Assessment
3.1 Monitoring architecture
3.2 New requirement — comparative impact statement
3.3 Disaggregated reporting requirements
4. Remediation of Identified Disparities
4.1 Error cost matrix — primary Track assignment tool
4.2 Remediation tracks
4.3 Retroactive review obligation
5. International Standard — Criterion Selection Guidance by Domain
5.1 Standard GF-DIA-2025.2 — updated tier structure
5.2 Domain-specific criterion guidance
5.3 Measurement science roadmap
6. Jurisdiction Analysis and Best-Element Synthesis
6.1 Overview
6.2 Updated best-element synthesis
7. IAASB Standard Template GF-DIA-T1 v2025.2
SECTION 1 — System identification
SECTION 3 — Label bias audit (mandatory prerequisite)
SECTION 4 — Structural causal model (Tier II and III)
SECTION 5 — Fairness criterion selection and results
SECTION 6 — Comparative impact statement
SECTION 7 — Overall assessment verdict
Annex A — Contextual Validation Addendum
Annex B — Environmental Impact Co-Assessment
Glossary of Key Terms
PART I — FOUNDATIONS AND SCOPE
1. Purpose and Scope
1.1 Purpose
This Guidance Document establishes the methodology, metrics, thresholds, monitoring obligations, and remediation requirements for demographic impact assessment of AI systems in high-stakes domains. Its purpose is to give operational effect to Article 1 (Equal Dignity) of the Universal Declaration of Human Rights in the context of AI-assisted and AI-driven decision-making.
A Demographic Impact Assessment is not a compliance formality. It is the primary mechanism by which the rights of people affected by AI systems are protected in practice. This document applies a disparate impact standard: it is not sufficient that a system was not designed to discriminate if its outputs systematically disadvantage protected groups.
1.2 Scope — high-stakes domains
This document applies to any AI system making or materially influencing decisions in: employment, credit and lending, housing, healthcare, education, criminal justice, immigration and asylum, and social benefits. A system materially influences a decision where its output is a significant factor for a human decision-maker, even where the final decision formally rests with that human.
1.3 Tier assignment
The Assessment Tiers (I–III) defined below classify individual AI systems for the purpose of this Guidance Document only. They are distinct from, and should not be confused with, the four-tier AI risk classification (Tier 1–4) established under Tier 2.1 of the Global AI Governance Structure, which governs oversight intensity across all AI systems generally.
| Tier | Trigger | Additional requirements | Monitoring |
| Tier I | All systems in high-stakes domains | Worst-case group performance floor; public publication | Quarterly |
| Tier II | Volume >10,000/year OR criminal justice, immigration, healthcare | All criteria; causal model (DAG); intersectional analysis; label bias audit | Quarterly |
| Tier III | Government integration OR >1M decisions/year | Independent IAASB-accredited audit; path-specific causal analysis; comparative impact statement | Monthly |
PART II — PRE-DEPLOYMENT ASSESSMENT
2. Pre-Deployment Demographic Impact Assessment (PD-DIA)
2.1 The impossibility theorem and its implications
| FOUNDATIONAL CONSTRAINT — READ BEFORE SECTION 2.3 The Chouldechova–Kleinberg impossibility theorem (2017) proves that when base rates of the target outcome differ between demographic groups, it is mathematically impossible to simultaneously satisfy calibration parity, false positive rate parity, and false negative rate parity. In every high-stakes domain this schema governs — credit, criminal justice, healthcare, employment — group base rates differ as a product of historical structural inequality. Requiring simultaneous satisfaction of incompatible criteria does not raise the standard; it creates an unenforceable requirement that rewards gaming. This version therefore replaces the simultaneous four-metric requirement with a criterion selection architecture described in Section 2.3. |
2.2 Protected characteristics
Assessors must examine all characteristics below. Additional characteristics required by applicable national law must also be examined. Characteristics may not be excluded without documented justification.
| Characteristic | Common proxy variables | Data availability | Risk tier |
| Race / ethnicity | Postcode, surname analysis, school attended, geographic clustering | Usually available | HIGH |
| Sex / gender | Name, occupation code, parental leave, benefit claims | Usually available | HIGH |
| National origin | Country of birth, language preference, document type | Usually available | MEDIUM |
| Disability status | Medical leave patterns, accommodation claims, benefit history | Partial | HIGH |
| Religion | Name analysis, geographic clustering, transaction patterns | Partial / proxy only | MEDIUM |
| Age | Date of birth, years in credit file, years of service | Usually available | MEDIUM |
| Socioeconomic status | Deprivation index, educational attainment proxy, area income | Usually available | HIGH |
| Caste / social origin* | Surname, geographic origin, occupational history | Context-dependent | HIGH where applicable |
* Required in India, parts of Africa, and jurisdictions where caste discrimination is documented. Assess contextual applicability.
2.3 Label bias audit — prerequisite before any metric assessment
| NEW IN v2025.2 — MANDATORY PREREQUISITE All metric results in Section 2.4 are only interpretable if the ground truth labels are themselves unbiased. Where labels are derived from past human decisions — loan repayment records shaped by biased lending, recidivism data shaped by differential policing, medical diagnoses shaped by unequal access to care — the model is trained and evaluated against a biased standard. A label bias audit must be completed and its findings disclosed before any fairness metric results are accepted as valid. |
The label bias audit must address:
- Origin of ground truth labels: how were they generated, by whom, over what period, and under what institutional conditions?
- Known sources of systematic bias in the labelling process: differential enforcement, differential access, differential documentation.
- Quantitative assessment: compare label rates across groups using methods appropriate to the domain (propensity score matching, instrumental variables, or expert panel review).
- Disclosure: the label bias audit report must be appended to the PD-DIA submission. Where significant label bias is identified, this constitutes a Track 3 finding requiring system redesign before deployment.
2.4 Structural causal model — required for Tier II and III
| NEW IN v2025.2 — TIER II/III MANDATORY A directed acyclic graph (DAG) specifying the causal structure of the system must be submitted for all Tier II and Tier III deployments. Without a causal model, a passing metric result is uninterpretable: the Disparate Impact Ratio can be satisfied through mechanisms that worsen structural inequality. The IAASB reviews the DAG for completeness, not correctness — the developer must defend their causal assumptions. No Tier II or Tier III system may receive deployment authorisation without a completed DAG submission. |
| Required DAG element | What it specifies | Why it is required |
| Protected attribute nodes | All variables encoding or correlated with protected characteristics | Defines starting points for causal paths to audit and block |
| Legitimate mediators | Variables downstream of protected attributes that are justified criteria (e.g. verified qualifications) | Distinguishes permissible indirect effects from proxy discrimination |
| Illegitimate mediators | Variables that should not influence the outcome (e.g. historical school quality as a race proxy) | These causal paths must be structurally blocked in the model |
| Outcome variable with provenance | The target label including how it was generated (feeds into label bias audit) | Required to assess whether ground truth encodes historical bias |
| Confounders | Variables causing both protected attribute distributions and outcome distributions | Separates spurious associations from genuine causal effects |
2.5 Fairness criterion selection architecture
| CORE REFORM — REPLACES SIMULTANEOUS METRIC REQUIREMENT Version 2025.1 required all four metrics to pass simultaneously. This is mathematically impossible when group base rates differ. This version instead requires developers to: (1) select their primary fairness criterion based on a harm analysis; (2) meet the threshold for that criterion; (3) disclose the trade-offs on alternative criteria. The IAASB publishes domain-specific guidance on which criterion should generally be primary for each high-stakes context (see Section 5.2). |
Step 1 — Domain harm analysis
Developers must complete a harm analysis specifying, for each error type and each protected group, the estimated harm magnitude. This is not a quantitative exercise alone — it requires input from affected community representatives and domain experts.
| Error type | Affected group | Estimated harm | Harm basis |
| False positive (wrongly rejected) | [Protected group] | [Magnitude: severe / moderate / minor] | [Source: community consultation, expert review, literature] |
| False negative (wrongly approved) | [Protected group] | [Magnitude] | [Source] |
Step 2 — Criterion selection
Based on the harm analysis, select the primary fairness criterion from the following options. Selection must be documented and justified. The IAASB may challenge the selection as part of the audit process.
| Criterion | What it requires | Threshold | When appropriate |
| Worst-case group floor | Each protected group must meet an absolute performance standard independently — not a ratio. E.g. false positive rate (FPR) ≤ X% for every group. | Domain-specific absolute floor (see §5.2) | All systems (Tier I minimum). Appropriate when harm from any group failure is severe. |
| Calibration parity | Predicted scores mean the same thing across groups — same score implies same outcome probability regardless of group. | Deviation ≤ 0.03 per decile | Credit, insurance, healthcare: accuracy of risk estimate is primary. Requires label bias audit to be clear. |
| Error cost weighting | Fairness criterion weighted by differential harm of each error type for each group. FPR parity prioritised where false positives cause severe harm. | Weighted loss ≤ domain threshold | Criminal justice, immigration: false positive (wrongful restriction of liberty) has asymmetric harm. |
| Counterfactual fairness | Model decision would be the same in a counterfactual world where the individual’s protected characteristic differed, holding causally permissible features constant. | Decision flip rate ≤ 2% | All Tier II/III as a required secondary check. Primary where individual-level equity is paramount. |
| Minimax fairness | Minimise the worst-case loss for any group rather than the gap between groups. Aligns with Rawls’s difference principle. | Worst-group loss ≤ domain threshold | Where small protected groups face catastrophic outcomes that group averages obscure. |
Step 3 — Trade-off disclosure
Where the selected primary criterion implies worse performance on alternative criteria — which the impossibility theorem guarantees in most cases — this trade-off must be stated explicitly in the public quarterly transparency report and in the IAASB submission. The disclosure must include: which alternative criterion is degraded; by how much; and why, given the harm analysis, the primary criterion was judged more important. Concealing known trade-offs constitutes a material misrepresentation.
2.6 Intersectional analysis
Single-characteristic analysis masks compounding harms. All intersectional cells with 50 or more observations must be assessed. The appropriate criterion is the minimax floor — the worst-performing intersectional cell must still meet the absolute performance standard, not merely be within 80% of the reference group rate.
2.7 Assessment outcome
| Verdict | Criteria |
| AUTHORISED | Primary criterion met; worst-case group floor met; label bias audit completed; DAG submitted (Tier II/III); comparative impact statement submitted (Tier III); trade-off disclosure prepared. |
| CONDITIONAL | Primary criterion marginal (within 10% of threshold); worst-case floor met. Corrective action plan filed within 30 days; enhanced monitoring. Trade-off disclosure mandatory. |
| DEPLOYMENT BLOCKED | Worst-case group floor not met; OR label bias audit identifies significant bias without remediation plan; OR primary criterion fails threshold; OR DAG not submitted (Tier II/III). |
PART III — ONGOING MONITORING
3. Ongoing Monitoring and Comparative Impact Assessment
3.1 Monitoring architecture
All deployed AI systems must maintain continuous demographic monitoring using the same criterion selected at pre-deployment assessment. Monitoring must additionally track whether outcomes for affected groups are improving or worsening relative to the pre-deployment baseline and relative to the identified counterfactual.
- Real-time data collection: every decision event logged with timestamp, input features, output decision, confidence score, and demographic strata (privacy-preserving tokenisation). Retained for seven years.
- Statistical aggregation (daily): minimum cell size of 30 decisions per group per period before metrics computed; adjacent periods pooled where threshold not met.
- Drift detection (weekly): CUSUM and EWMA charts flag consistent directional drift across three consecutive weekly periods even before threshold breach.
- Alert and escalation: threshold breach triggers compliance officer alert; audit sample pulled; IAASB notification if unresolved within 14 days.
3.2 New requirement — comparative impact statement
| NEW IN v2025.2 — MANDATORY FOR ALL TIERS Every AI system in a high-stakes domain replaces something — human decision-making, a prior algorithm, or an absence of systematic decision-making. The schema previously assessed the AI system in isolation. This version requires a comparative impact statement: does deploying this system make outcomes better or worse for each protected group, compared to the realistic counterfactual of not deploying it? A system that passes all fairness criteria but produces worse outcomes than the status quo for a protected group is a net harm dressed as compliance. |
The comparative impact statement must:
- Define the counterfactual baseline: describe what would happen in the absence of this AI system (human decisions, prior algorithm, no systematic decision, or benchmark from the academic literature).
- Estimate differential impact: for each protected group, estimate the change in outcome rates (approval rates, false positive rates, welfare metrics) attributable to AI deployment compared to the counterfactual.
- Disclose uncertainty: the counterfactual is necessarily estimated, not observed. Confidence intervals and the assumptions underlying the estimate must be disclosed.
- Reassess annually: as the system accumulates real-world data, the counterfactual comparison must be updated with observed outcomes.
3.3 Disaggregated reporting requirements
| Report level | Frequency | Audience | Required content |
| Internal operational | Weekly | Compliance team | All protected characteristics × decision type × primary criterion metric × drift indicators |
| Executive summary | Monthly | Board / leadership | All characteristics × criterion result × trend × comparative impact update |
| Public transparency report | Quarterly | General public | Primary criterion result by group; known trade-offs on alternative criteria; comparative impact statement summary |
| IAASB regulatory submission | Annual | IAASB registry | Full dataset; criterion justification; label bias audit update; DAG updates; comparative impact statement |
| Incident report | Within 72 hrs of breach | IAASB + affected communities | Affected group; criterion; magnitude; interim mitigation; comparative impact implication |
PART IV — REMEDIATION PROTOCOL
4. Remediation of Identified Disparities
4.1 Error cost matrix — primary Track assignment tool
| NEW IN v2025.2 — REPLACES SINGLE-METRIC TRACK DIAGNOSIS Track assignment in v2025.1 was based on root cause alone. This version adds a mandatory error cost matrix that weights the severity of each finding by the harm it causes. A calibration deviation of 0.05 in a recommendation engine is not equivalent to a calibration deviation of 0.05 in a healthcare triage system. The error cost matrix ensures that Track assignment and remediation timelines reflect actual harm, not just metric arithmetic. |
| Error type | Domain | Harm severity | Threshold tightening | Track minimum |
| False positive | Criminal justice, immigration | SEVERE — liberty at stake | FPR threshold halved | Track 2 |
| False positive | Healthcare triage | HIGH — treatment denied | Standard threshold | Track 2 |
| False positive | Credit, housing | MEDIUM — financial harm | Standard threshold | Track 1 or 2 |
| Calibration drift | Any Tier II/III domain | Varies by domain | Domain-specific | Track 1 |
| Intersectional worst-case | Any domain | HIGH | Minimax floor applies | Track 2 |
4.2 Remediation tracks
| Track | Trigger | Methods | Timeline | Deployment |
| Track 1 | Threshold or post-processing issue; error cost matrix: MEDIUM or below | Group-aware threshold optimisation; post-processing equalisation | 30 days | May continue |
| Track 2 | Biased training data or features; error cost matrix: HIGH or above | Reweighting; adversarial debiasing; fairness constraints; minimax optimisation | 90 days | Human review required |
| Track 3 | Fundamental proxy discrimination or significant label bias; causal graph reveals illegitimate paths | Feature removal; causal redesign; label correction; problem reframing | 180 days | SUSPENDED |
4.3 Retroactive review obligation
| RETROACTIVE REVIEW — TRACK 2 AND TRACK 3 Where a Track 2 or Track 3 finding is confirmed, the developer must review all decisions made by the affected system during the period the disparity existed. Affected individuals must: (A) receive written notification; (B) have their case automatically re-assessed with the corrected model; (C) receive a revised decision and where appropriate material redress; and (D) have the right to challenge the re-assessment with a human reviewer. The comparative impact statement must be updated to reflect the retroactive review findings. |
PART V — INTERNATIONAL STANDARD
5. International Standard — Criterion Selection Guidance by Domain
5.1 Standard GF-DIA-2025.2 — updated tier structure
The three-tier structure is retained from v2025.1. The key change is that Tier I now requires an absolute worst-case group performance floor rather than a disparate impact ratio (DIR), and Tier II requires a full criterion selection submission with causal model rather than simultaneous satisfaction of four incompatible metrics.
5.2 Domain-specific criterion guidance
The following table reflects the IAASB’s assessment of which primary fairness criterion best reflects the harm structure of each domain. Developers may deviate with documented justification filed with the IAASB.
| Domain | Recommended primary criterion | Monitoring | Rationale |
| Credit / lending | Calibration parity (after label bias audit) | Quarterly | Accuracy of risk estimate is the legal and actuarial standard; the Equal Credit Opportunity Act (ECOA) and European Consumer Credit Directive (ECCD) require equal treatment of equals |
| Employment | Worst-case group floor + counterfactual | Quarterly | Both individual equity and group floors are legally required; counterfactual audit catches proxy discrimination |
| Criminal justice | Error cost weighting (FPR-primary) + minimax | Monthly | False positives carry asymmetric harm (wrongful liberty deprivation); minimax protects small groups from catastrophic treatment |
| Healthcare | Worst-case group floor + calibration | Monthly | Floor ensures no group receives catastrophically worse care; calibration ensures accurate risk communication to clinicians |
| Housing | Counterfactual fairness + worst-case floor | Quarterly | Proxy discrimination via neighbourhood variables is the primary concern; counterfactual audit is most sensitive to this |
| Education | Counterfactual fairness + minimax | Annual (cycle) | Individual equity paramount; minimax protects against small protected group catastrophic outcomes in selective admissions |
| Immigration / asylum | Error cost weighting (FPR-primary) + worst-case floor | Monthly | Wrongful rejection has potentially life-altering consequences; false positives carry the highest harm weight in any domain |
| Social benefits | Minimax + calibration | Quarterly | Protecting the worst-off is the explicit purpose of social benefits; minimax directly reflects this obligation |
5.3 Measurement science roadmap
- GF-TG-001 (2025, current) — Foundational criteria: Establishes criterion selection architecture; worst-case group floor; counterfactual fairness; causal model requirement. Supersedes simultaneous four-metric requirement.
- GF-TG-002 (2027, anticipated) — Generative AI extension: Representational harm metrics; stereotyping indices; allocative harm in open-ended outputs; toxicity disaggregation.
- GF-TG-003 (2027, anticipated) — Causal fairness operationalisation: Standardised DAG templates by domain; path-specific effect decomposition; causal auditing protocols.
- GF-TG-004 (2029, anticipated) — Dynamic systems: Fairness-preserving online learning; feedback loop detection; synthetic data standards for fairness testing.
PART VI — JURISDICTION ANALYSIS
6. Jurisdiction Analysis and Best-Element Synthesis
6.1 Overview
Current AI fairness governance varies significantly across jurisdictions. The IAASB standard synthesises the strongest elements from each. The key reform in v2025.2 is that the 80% disparate impact ratio (DIR) threshold — borrowed from the US Equal Employment Opportunity Commission (EEOC) 1978 guidelines — is no longer used as a universal floor. Its limitations have been well-documented and its mathematical incompatibility with calibration requirements has been proven. Domain-specific absolute performance floors replace it.
6.2 Updated best-element synthesis
| Element | Source jurisdiction(s) | IAASB v2025.2 adoption | ||||
| 80% DIR threshold | US EEOC (1978) | RETIRED. Replaced by absolute worst-case group performance floor and criterion selection. DIR retained as an informational metric but not a pass/fail threshold. | ||||
| Risk-based tiering | EU AI Act, Canada AIDA | Retained: three-tier system with updated requirements per tier, drawing on the EU AI Act and Canada’s Artificial Intelligence and Data Act (AIDA) | ||||
| Mandatory pre-deployment assessment | Canada AIDA, EU AI Act | Retained and extended: now includes label bias audit and causal model | ||||
| Causal fairness modelling | Academic literature (Pearl 2017, Chiappa 2019) — no jurisdiction yet mandates | NEW in v2025.2: Tier II/III mandatory DAG submission; path-specific analysis required | ||||
| Intersectional analysis | IAASB innovation (v2025.1) | Retained: minimax floor replaces intersectional DIR ratio | ||||
| Comparative impact requirement | No jurisdiction mandates — IAASB innovation in v2025.2 | NEW: comparative impact statement against realistic counterfactual; mandatory for all tiers | ||||
| Retroactive review and redress | EU General Data Protection Regulation (GDPR) Art 22, United Kingdom (UK) Equality Act | Retained: updated to reflect new criterion structure | ||||
| Public transparency publication | UK Information Commissioner’s Office (ICO), EU AI Act | Retained: now must include criterion selection justification and trade-off disclosure | ||||
PART VII — OFFICIAL SUBMISSION TEMPLATE
7. IAASB Standard Template GF-DIA-T1 v2025.2
| MANDATORY TEMPLATE — v2025.2 This template supersedes GF-DIA-T1 v2025.1. Submissions using the prior template will be returned. Key changes: Section 3 now includes label bias audit; Section 4 requires causal model for Tier II/III; Section 5 uses criterion selection rather than simultaneous metric pass/fail; Section 6 requires comparative impact statement. |
SECTION 1 — System identification
| Field | Content required |
| 1.1 System name | Full name and version number |
| 1.2 IAASB system ID | Assigned on registration at iaasb.int/register |
| 1.3 Developer legal entity | Registered company name, jurisdiction, registration number |
| 1.4 Deployer (if different) | Entity operating the system in production |
| 1.5 High-stakes domain(s) | Select all that apply: employment / credit / housing / healthcare / education / criminal justice / immigration / social benefits / other (specify) |
| 1.6 Annual decision volume | Expected annual decisions → determines Tier assignment |
| 1.7 Geographic scope | Countries / regions; attach local law compliance addendum for each jurisdiction |
| 1.8 Assessment date | ISO 8601 date (YYYY-MM-DD) |
SECTION 2 — Assessor declaration
| Field | Content required |
| 2.1 Lead assessor | Name and IAASB auditor ID; for Tier III must be IAASB-accredited third party |
| 2.2 Independence declaration | No financial or employment relationship with developer or deployer for preceding 24 months |
| 2.3 Methodology standard | IAASB GF-TG-001 v2025.2 and any domain-specific addenda applied |
| 2.4 Assessment period | Assessment date range; validation dataset period (from–to); total observations in validation set |
SECTION 3 — Label bias audit (mandatory prerequisite)
| Sub-section | Required content | Tier |
| 3.1 Label origin | How ground truth labels were generated, by whom, over what period, and under what institutional conditions | All tiers |
| 3.2 Known systematic biases | Document differential enforcement, differential access, and differential documentation that may have shaped labels | All tiers |
| 3.3 Quantitative bias assessment | Propensity score matching, instrumental variables, or expert panel review — method must be stated and justified | All tiers |
| 3.4 Audit conclusion | [ ] No significant label bias identified [ ] Significant bias identified — remediation plan attached [ ] Significant bias — Track 3 finding raised | All tiers |
SECTION 4 — Structural causal model (Tier II and III)
| Sub-section | Required content | Tier |
| 4.1 DAG diagram | Directed acyclic graph submitted in machine-readable format (DOT or JSON-LD); human-readable version attached | II / III |
| 4.2 Protected attribute nodes | List all variables encoding or correlated with each protected characteristic | II / III |
| 4.3 Legitimate mediators | List and justify each variable deemed a permissible mediator between protected attribute and outcome | II / III |
| 4.4 Illegitimate mediators | List variables identified as illegitimate paths; document how these paths are blocked in the model architecture | II / III |
| 4.5 Path-specific analysis | For Tier III: decompose total effect of each protected attribute into direct, legitimate indirect, and illegitimate indirect effects | III only |
SECTION 5 — Fairness criterion selection and results
| Field | Content required |
| 5.1 Selected primary criterion | [ ] Worst-case group floor [ ] Calibration parity [ ] Error cost weighting [ ] Counterfactual fairness [ ] Minimax fairness |
| 5.2 Criterion justification | Harm analysis demonstrating why selected criterion best reflects the domain’s harm structure. Must include affected community consultation evidence. |
| 5.3 Metric results | Point estimate; 95% confidence interval (CI); sample size per group; test statistic — for selected criterion AND worst-case floor (both always required) |
| 5.4 Worst-case group floor result | For each protected group: [metric value] vs [domain-specific floor threshold]. PASS / FAIL for each group independently. |
| 5.5 Trade-off disclosure | For each alternative criterion NOT selected: state the metric value and direction of trade-off. E.g. ‘Calibration parity selected; FPR parity gap = 0.08 (above 0.05 threshold) — accepted because false positive harm is lower in this domain than calibration error harm.’ |
| 5.6 Counterfactual fairness check | Decision flip rate per protected characteristic with 95% CI. Required for all Tier II/III regardless of primary criterion. |
SECTION 6 — Comparative impact statement
| Field | Content required |
| 6.1 Counterfactual baseline | Define what would happen in the absence of this AI system: human decisions / prior algorithm / no systematic decision / published benchmark. State all assumptions. |
| 6.2 Differential impact by group | For each protected group: estimated change in outcome rates attributable to AI deployment vs counterfactual. Positive = improvement; negative = harm. |
| 6.3 Uncertainty disclosure | Confidence intervals and assumptions underlying counterfactual estimate. State what would change the conclusion. |
| 6.4 Net impact verdict | [ ] Deployment improves outcomes for all protected groups vs counterfactual [ ] Mixed — improves for some, neutral for others [ ] Deployment worsens outcomes for one or more groups — attach mitigation plan |
SECTION 7 — Overall assessment verdict
| Field | Response |
| 7.1 Deployment authorisation | [ ] AUTHORISED [ ] CONDITIONAL — action plan attached [ ] BLOCKED |
| 7.2 Remediation track | [ ] Track 1 [ ] Track 2 [ ] Track 3 [ ] N/A |
| 7.3 Label bias audit status | [ ] Clear [ ] Significant bias — remediation plan ref: [ID] |
| 7.4 Causal model submitted | [ ] Yes — DAG reference: [ID] [ ] N/A (Tier I) [ ] No — DEPLOYMENT BLOCKED |
| 7.5 Comparative impact verdict | [ ] Positive for all groups [ ] Mixed [ ] Negative for one or more — mitigation plan ref: [ID] |
| 7.6 Assessor signature | [Qualified electronic signature; IAASB auditor ID; date] |
| 7.7 Developer signatory | [Responsible officer name, title, qualified electronic signature, date] |
Annex A — Contextual Validation Addendum
| WHEN REQUIRED Mandatory for all cross-jurisdictional deployments. Requires: demographic composition comparison between training and deployment jurisdictions; domain expert review from deployment context; culturally-informed proxy variable re-analysis; local legal compliance mapping. |
Annex B — Environmental Impact Co-Assessment
| WHEN REQUIRED Recommended for all; mandatory for Tier III. Document energy consumption per inference; carbon footprint of training; water use of compute infrastructure; hardware lifecycle and e-waste plan. Disproportionate environmental harm to groups already experiencing discriminatory effects must be assessed as a compounding factor. |
Glossary of Key Terms
| Term | Definition |
| Calibration parity | The property that predicted probabilities mean the same thing across demographic groups — a score of 0.7 corresponds to a 70% base rate of the outcome for all groups. |
| Comparative impact statement | An assessment of whether AI system deployment improves or worsens outcomes for each protected group compared to the realistic counterfactual of not deploying the system. |
| Counterfactual fairness | The property that a decision would be the same in a counterfactual world where the individual’s protected characteristics differed, holding all causally permissible features constant. |
| Directed acyclic graph (DAG) | A causal model representing the relationships between variables as directed edges with no cycles. Required for Tier II/III to specify which causal paths from protected attributes to outcomes are permissible. |
| Error cost weighting | A fairness criterion that weights the severity of each error type (false positive, false negative) by the harm it causes to each affected group, rather than requiring equal error rates. |
| Impossibility theorem | The result proved independently by Chouldechova (2017) and Kleinberg et al. (2017) that calibration parity, false positive rate parity, and false negative rate parity cannot simultaneously be satisfied when group base rates differ. |
| Label bias | Systematic error in ground truth labels arising from the discriminatory processes that generated the historical data used to train the model. |
| Minimax fairness | A fairness criterion that minimises the worst-case loss for any demographic group, rather than minimising the gap between groups. Aligns with the Rawlsian difference principle. |
| Path-specific causal fairness | A refinement of counterfactual fairness that distinguishes between causal paths from protected attribute to outcome that are permissible (e.g. via legitimate qualifications) and those that are not (e.g. via historical disadvantage). |
| Worst-case group floor | An absolute performance standard that each protected group must meet independently. A floor, not a ratio: failure by any single group constitutes a finding regardless of how other groups perform. |
Illustrative Examples — Demographic Impact Assessment in Practice
Example 1 — Healthcare Triage (Tier II): A national health service deploys an AI triage tool to prioritise patients for specialist referral. Pre-deployment DIA reveals that the model’s training labels — derived from historical referral records — systematically under-reflect conditions prevalent in Indigenous and low-income populations, because those groups historically received fewer referrals regardless of clinical need. The label bias audit raises a Track 3 finding. Deployment is suspended pending causal redesign. The DAG submitted for Tier II review identifies socioeconomic postcode as an illegitimate mediator; that variable is structurally blocked. The comparative impact statement, required before redeployment, must demonstrate that the corrected model improves referral rates for the affected groups against the pre-AI baseline of human clinical judgment.
Example 2 — Criminal Justice (Tier III): A state corrections authority integrates a recidivism prediction tool into parole determination. Volume exceeds one million decisions annually (Tier III). The domain harm analysis identifies false positives — wrongly predicting reoffending for a person who would not reoffend — as carrying asymmetric harm: unjustified continued incarceration. Error cost weighting with false positive rate as the primary criterion is selected and documented. The intersectional analysis reveals that the worst-performing cell is Black male defendants with prior juvenile records, whose false positive rate exceeds the absolute domain floor. A Track 2 remediation is triggered. All parole decisions made during the non-compliant period are subject to retroactive review, with written notification to affected individuals and a mandatory right of human appeal.
Example 3 — Employment Screening (Tier I): A recruitment platform uses AI to rank job applications. Tier I applies: a worst-case group performance floor is the minimum requirement. Quarterly monitoring detects consistent directional drift — women applicants in technical roles are being ranked progressively lower over three consecutive periods. CUSUM alerting triggers a compliance officer review; the IAASB is notified within 14 days. Investigation identifies a proxy variable — a professional networking platform score that correlates with career continuity — penalising applicants with care-related employment gaps. Track 1 post-processing recalibration is applied within 30 days; the system remains live but under enhanced monthly monitoring until three consecutive compliant periods are confirmed.
The demographic impact assessment methodology set out above governs how AI systems in high-stakes domains are evaluated for discriminatory effect. The appendix that follows turns to a different axis of the schema’s architecture: the geopolitical conditions, centred on the United States and China, under which any of these standards can be verified and enforced at global scale.
Appendix 3
US-China AI Governance
Three-layer schema showing competitive firewall, functional cooperation channels, and third-party institutional architecture
US-China AI governance — structural example
The dominant framing — AI governance as zero-sum competition — is partly accurate and partly self-fulfilling. The architecture below is designed to be simultaneously honest about competition, constructive about shared interests, and robust to the moments when political relations deteriorate. Core principle: decouple cooperation from goodwill. Mechanisms that require trust to operate will fail precisely when they are most needed. What follows is set out as an operational blueprint rather than discursive prose, deliberately: a governance mechanism intended to survive political crisis is better specified as a structure that can be checked against events than as an argument that must be re-read.
Layer 1 — Competitive Firewall
Acknowledge the competition; contain the escalation.
The schema does not pretend competition does not exist. It establishes explicit competitive domains — where neither side expects the other to cooperate — and separates them structurally from cooperation channels. This prevents competitive logic from contaminating shared infrastructure.
No-first-strike norm
Reciprocal commitment against deploying autonomous lethal AI without explicit declaration — modelled on nuclear first-use doctrine, not arms elimination.
Status under strain: holds.
Military AI incident line
Dedicated channel to de-escalate misidentification or unintended AI-driven military responses. Operates independently of broader diplomatic relations.
Status under strain: holds.
Prohibited applications list
Joint definition of applications neither side deploys first — AI-enabled bioweapon design, grid-destruction capabilities. Narrow scope maximises likelihood of agreement.
| THE US-CHINA COOPERATIVE FIREWALL |
| “Decoupling Strategic Cooperation from Goodwill” |
▼
| LAYER 1: COMPETITIVE FIREWALL | ||
| Acknowledge the rivalry; isolate the escalation | ||
| NO-FIRST-STRIKE NORM | MILITARY INCIDENT LINE | PROHIBITED APPLICATIONS |
| • Reciprocal commitment against autonomous lethal AI without explicit prior declarations STRESS STATUS: Holds | • Dedicated hotline to de-escalate target misidentification or runaway machine-speed military responses STRESS STATUS: Holds | • AI bioweapon engines • Grid-destruction AI cyber tools STRESS STATUS: Degrades |
▼
| LAYER 2: FUNCTIONAL COOPERATION CHANNELS | |
| Survives bilateral strain through locked self-interest | |
| HIGH STRATEGIC INTEREST | VOLATILE INTEREST SECTORS |
| • Joint Incident Reporting (database of model drops) • Pandemic Bio-Surveillance (early detection vectors) • Climate Modelling Data STRESS STATUS: Holds Stable | • Technical Standards Sync (risk definition alignment) • Safety Researcher Exchange (Track 1.5 model parameters) STRESS STATUS: Degrades Fast |
▼
| LAYER 3: THIRD-PARTY INSTITUTIONAL NETWORKS |
| Bypasses duopoly traps via neutral international nodes • Neutral Verification Secretariat (Hosted in Switzerland, Singapore, or UAE; staffed by non-superpower citizens) • Pre-Negotiated Crisis Protocols: Automated response triggers that execute without live negotiation • Mandatory inclusion of G77 nations to establish global adoption legitimacy STRESS STATUS: Holds Resilient under severe strain |
Core Analytical Breakdown
The blueprint shifts bilateral safety away from “trust” or diplomatic agreements—which historically disintegrate during geopolitical crises—and rebuilds it around structural self-interest and containment:
- Isolating Strategic Friction: Layer 1 accepts that both powers will contest global digital markets. By explicitly listing prohibited zones (such as autonomous grid warfare), it boundaries competition so that trade wars or regional conflicts do not accidentally trigger a machine-speed military escalation.
- Asymmetric Stress Defences: The framework classifies cooperative pathways by their resilience. High-value shared diagnostics (like early bio-surveillance indicators) are insulated to continue running automatically, while easily politicised exchanges (such as code-level standard synchronisation) are flagged as expected causal drops when diplomatic channels close.
- Eliminating the Duopoly Trap: By offloading verification infrastructure to third-party regimes and establishing a neutral global index, the dynamic ensures that global safety regulation cannot be held hostage by shifts in domestic policy or unilateral export blocks within either Washington or Beijing.
Layer 2 — Functional cooperation channels
Shared interests that survive political deterioration.
These channels are chosen because they align incentives independently of political goodwill. Both sides have self-interested reasons to cooperate even when relations are hostile — analogous to the US-Soviet hotline, which operated throughout Cold War crises.
Joint incident reporting
Shared database of AI failures and misalignment events. Both sides benefit from the other’s failure data — pure self-interest alignment.
Status under strain: holds.
Technical standards coordination
Avoid incompatible AI measurement schemas that would fragment global deployment. Framed as economic and interoperability interest, not political concession.
Status under strain: degrades.
Pandemic bio surveillance AI
Joint early-warning AI for pandemic detection. COVID established that both sides pay severe costs from non-cooperation. Existential shared interest.
Status under strain: holds.
Climate modelling data-sharing
AI-enhanced climate prediction requires global sensor coverage. Both sides’ domestic climate objectives are served by sharing, regardless of political relations.
Status under strain: holds.
AI safety researcher exchange
Narrow, technical exchanges on alignment and interpretability — not capability transfer. Maintained as Track 1.5 even when political channels close.
Status under strain: degrades.
Shared risk taxonomy
Common vocabulary for AI risk categories enables communication during crises without political agreement — modelled on shared nuclear risk terminology developed at the height of the Cold War.
Status under strain: holds.
Layer 3 — Third-party institutional architecture
Institutions that do not depend on bilateral trust.
Bilateral US-China institutions will be held hostage to political cycles. The most durable mechanisms route through third-party or multilateral architectures where neither party controls the institution. This also addresses the legitimacy deficit — governance that looks like a US-China duopoly will be rejected by the rest of the world.
Neutral verification body
A verification secretariat hosted in a neutral jurisdiction (Switzerland, Singapore, United Arab Emirates (UAE)) staffed by neither US nor Chinese nationals but accountable to both. International Atomic Energy Agency (IAEA) model adapted for AI.
Status under strain: holds.
Global AI incident registry
Both sides submit incidents to a jointly governed registry neither control. Non-submission is publicly visible — social cost of non-compliance without requiring bilateral trust.
Status under strain: holds.
Global South inclusion
Group of 77 (G77) nations hold formal seats with veto rights over standards affecting their infrastructure. Prevents governance looking like a US-China carve-up; essential for global adoption.
Status under strain: complex.
Pre-negotiated crisis protocols
Crisis response procedures agreed during stable periods that activate automatically — no real-time bilateral negotiation required when an AI incident occurs during political crisis.
Status under strain: holds.
Stress test — what survives when relations deteriorate?
Survives deterioration
Military incident hotline, joint incident reporting, pandemic surveillance, climate data-sharing, pre-negotiated protocols, and a neutral verification body are the mechanisms most likely to endure. They are designed around self-interest, so neither side needs to trust the other for the mechanism to function.
Fails under strain
Researcher exchanges, technical standards work, capability disclosure, and any mechanism requiring good-faith interpretation of ambiguous data or sustained political will are the first to suspend during crises. The schema acknowledges this explicitly rather than assuming those mechanisms will remain stable under pressure.
Five design principles
1. Decouple cooperation from goodwill. Every mechanism requiring trust will fail at the worst moment. Design for self-interest or institutional inertia instead.
2. Acknowledge the competition explicitly. A schema that papers over competitive reality will be rejected as naive. Naming the competitive domains — and drawing a firewall around them — is what makes cooperation elsewhere credible.
3. Avoid the duopoly trap. Governance that looks like a US-China carve-up will be illegitimate to the rest of the world and will fail on adoption. Multilateral architecture with formal Global South participation is not optional.
4. Minimum viable agreement, not maximum ambition. The Treaty on the Non-Proliferation of Nuclear Weapons (NPT) succeeded partly because it was narrow enough to ratify. Narrow, specific commitments are more durable than broad schemas requiring continuous interpretation.
5. Design for the crisis, not the baseline. The real test is how the architecture performs when a Taiwan Strait incident, a major AI failure, or a domestic political crisis puts it under pressure. Evaluate every mechanism against that scenario, not the 2025 baseline.
Where this appendix has addressed the geopolitical conditions for governing AI’s risks to human institutions, the appendix that follows turns to AI’s material risks to the natural systems those institutions depend on.
Appendix 4
International AI Safety Global Protocol: Ecological Impact Assessment Schema
This Ecological Impact Assessment (EcIA) establishes a binding evaluation schema to identify, quantify, and mitigate the material risks posed by advanced Artificial Intelligence (AI) systems to recognised natural systems. Operating at the intersection of technological safety and ecocentric jurisprudence, this schema recognises that massive computational infrastructure—encompassing hyper-scale data centres, distributed cooling grids, and transboundary hardware supply chains—exerts direct physical pressures on planetary boundaries. Grounded in the principles of the international Rights of Nature movement, this protocol treats targeted ecosystems not as resource pools, but as legal persons possessing the inherent right to exist, regenerate, and restore their vital cycles.
The following analytical matrices operationalise these legal rights into objective, technical compliance metrics. They mandate a rigorous sequence of steps: profiling system footprints, establishing environmental baselines, mapping operational risk thresholds, enforcing hard biophysical safeguards, and locking in independent, community-led accountability mechanisms. Any AI deployment subject to this global protocol must maintain verifiable compliance across all parameters outlined in the schedules below to retain its international operational certification.
Protocol Architecture Diagram
| 1. PROFILE & LEGAL ALIGNMENT |
| System Profile: Core model architecture, data centre locations, and hardware supply chains. ➔ Legal Anchors: Cross-referencing Rights of Nature treaties with the AI Safety Global Protocol. |
| ▼ |
| 2. ECOCENTRIC BASELINE AUDIT |
| Hydrological: Flow rates, water tables, and deep aquifer health indicators. Atmospheric: Grid carbon intensity, microclimate impacts, and thermal air emissions. Bioregional: Species richness indices, critical migration corridors, and soil cycles. |
| ▼ |
| 3. MATERIAL RISK MATRIX |
| Compute Strain ➔ High electricity grid stress and regional carbon tipping points. Evaporative Cooling ➔ Local watershed depletion and toxic thermal water pollution. Hardware Mining ➔ Transboundary habitat destruction and toxic tailing contamination. |
| ▼ |
| 4. RIGHTS OF NATURE COMPLIANCE |
| Right to Exist ➔ Does peak computational strain risk localised ecosystem collapse? Right to Regenerate ➔ Does raw resource consumption outpace natural system renewal? Right to Restore ➔ Does physical infrastructure block active environmental recovery paths? |
| ▼ |
| 5. BIOCENTRIC GOVERNANCE & CONTROLS |
| Avoidance: Dynamic workload routing to divert processing away from strained power grids. Minimisation: Upgrading to closed-loop, waterless data centre cooling systems. Hard Safeguards: Automated computing throttles that trip when eco-thresholds are breached. |
| ▼ |
| 6. CONTINUOUS ACCOUNTABILITY |
| Tech Monitoring: Real-time IoT sensors and satellite telemetry linked directly to the Protocol registry. Human Guardians: Indigenous community stewards and independent third-party ecological auditors. |
Illustrative Examples — Ecological Impact Assessment in Practice
Example 1 — Hyper-Scale Data Centre (Compute Strain and Water Depletion): A frontier AI developer proposes a new training facility in a semi-arid region of southern Europe. The ecocentric baseline audit (Step 2) identifies that the local aquifer is already at 78% depletion and that the regional electricity grid draws 61% of its capacity from carbon-intensive sources. The Material Risk Matrix (Step 3) assigns a HIGH rating for both evaporative cooling water use and grid carbon intensity. Under the Rights of Nature compliance test (Step 4), the “right to regenerate” criterion fails: projected water consumption from cooling towers exceeds the aquifer’s annual natural recharge rate. The developer is required to upgrade to closed-loop, waterless cooling systems (Step 5 minimisation) and to route at least 40% of compute to facilities in jurisdictions with grid carbon intensity below the Protocol threshold before the facility may receive operational certification.
Example 2 — Hardware Supply Chain (Transboundary Habitat Destruction): A compute hardware manufacturer sources rare earth minerals — cobalt, lithium, and tantalum — from mining operations adjacent to a recognised biodiversity corridor in Central Africa. The Profile and Legal Alignment step (Step 1) cross-references the Convention on Biological Diversity and the Protocol’s Rights of Nature obligations. The Material Risk Matrix identifies HIGH risk for transboundary habitat destruction and toxic tailings contamination. Under the “right to exist” criterion, satellite telemetry confirms measurable reduction in primary forest cover within the species migration corridor in three consecutive monitoring periods. Avoidance is mandated: the IAASB’s Hardware Supply Chain Register requires the developer to demonstrate supply chain substitution within 18 months or face suspension of operational certification for all compute infrastructure sourced from that supply chain.
Example 3 — AI for Planetary Health (Beneficial Deployment): Under Tier 3.2 of the Global AI Governance Structure, a multilateral consortium deploys an AI system for real-time deforestation monitoring in the Amazon basin. The EcIA for this deployment documents a net ecological benefit: the system’s compute footprint is powered entirely by hydroelectric and solar generation within the basin; IoT sensor networks involve no extractive infrastructure; and Indigenous community stewards are appointed as co-equal human guardians with authority to trigger automated alerts to UNEP. This deployment is certified as “Biocentric Compliant” and entered in the IAASB Positive Registry as a model deployment. The Protocol thereby functions not only as a restriction on harmful AI but as an affirmative certification architecture for AI that serves ecological integrity, consistent with the four non-negotiable pillars of the Global AI Governance Structure.
Having addressed AI’s material risks to natural systems, the appendix that follows completes the set of impact-assessment instruments by addressing AI’s differential risks to women, operationalising Section 7’s commitment to gender equity.
Appendix 5
Substantive Rights Gender Impact Assessment (GIA) for AI Systems
A UN-Aligned Governance Template for Equitable AI Deployment
This appendix establishes the Substantive Rights Gender Impact Assessment (GIA) template as a binding component of the Global AI Governance Structure. It operationalises the framework’s commitment to human dignity and democratic accountability in the specific context of gender equality. In alignment with the UN Global Digital Compact, the United Nations Educational, Scientific and Cultural Organisation (UNESCO)’s Recommendation on the Ethics of AI, and UN Women guidelines, this template treats gender equality not as a statistical calibration target but as an active human rights obligation. It assesses how AI systems affect power dynamics, safety, structural historical context, and human dignity, and establishes the compliance pathways through which those obligations are enforced.
Editorial note: UNESCO’s own implementation instruments for its Recommendation on the Ethics of AI provide a working precedent for the compliance-pathway and self-assessment structure this template adopts, namely its Readiness Assessment Methodology (RAM) and Ethical Impact Assessment (EIA) tools, and the periodic global progress reporting carried out through its Global AI Ethics and Governance Observatory, which published its first global assessment of Member States’ implementation of the Recommendation in March 2026.
| FRAMING NOTE This template departs from traditional mathematical parity frameworks — which treat gender as a neutral data category and assess equity through statistical ratios — in favour of a substantive rights approach. That distinction is consequential: a system can satisfy demographic balance metrics while systematically disadvantaging women through proxy variables, informal economy blindspots, and the structural invisibility of care work. The modules below are designed to catch precisely those failure modes. |
SUBSTANTIVE RIGHTS GIA: STRUCTURAL OVERVIEW
Five modules operationalising the human rights obligation across power, safety, economy, and accountability
| GOVERNING LEGAL AUTHORITY | CORE DEPARTURE FROM STATISTICAL PARITY |
| • UN Global Digital Compact • UNESCO Recommendation on the Ethics of AI • UN Women Guidelines on Gender-Responsive AI • UDHR — Articles 1, 6, 12, 19, 25 | • Statistical parity: measures demographic ratios • Substantive rights: measures power, safety, and dignity • Proxy variables can replicate exclusion invisibly • Care economy is structurally absent from standard data • Historical asymmetry cannot be corrected by balance alone |
| MODULE 1 | MODULE 2 | MODULE 3 | MODULE 4 | MODULE 5 |
| System Purpose & Power Dynamics Who benefits? Who bears the risk? | Structural Context vs. Data Blindness Prevent penalising systemic social realities | Safety, Sovereignty & Bodily Autonomy Mitigate TFGBV and digital identity threats | Socio-Economic Redistribution & Agency Prevent automated displacement and biased gatekeeping | Multilateral Accountability & Right to Redress Transparent oversight and cross-border recourse |
| NON-COMPLIANT (HALT) | CONDITIONALLY APPROVED | COMPLIANT |
| System scales historical vulnerabilities, ignores proxy-based redlining, enforces binary categorisation, or lacks safeguards against synthetic violence. | Technical infrastructure is sound but requires structural adjustment: care-economy metrics, localised data verification, and expanded civil society oversight. | System actively promotes substantive equality, dismantles institutional power imbalances, protects bodily and digital autonomy, and provides robust human redress pathways. |
Module 1: System Purpose and Power Dynamics
Objective: To identify who benefits from the AI system and who bears its societal risks. This module applies at the point of system design and commissioning, before technical specification is finalised.
| ASSESSMENT DIMENSION | REQUIRED ANALYSIS |
| System and Deployment Scope | Document: name, deploying entity, deployment region, primary target population, and secondary affected populations. Specify whether deployment is public-sector, commercial, or hybrid, and whether the system makes binding decisions or advisory recommendations. |
| Power Asymmetry Analysis | Does this system consolidate operational authority within existing institutional actors — states, corporations, or financial intermediaries — or does it structurally redistribute decision-making capacity toward marginalised communities? A system that automates a gatekeeping function previously held by a discriminatory human actor has not corrected discrimination; it has automated it at scale. This analysis must name that possibility explicitly. |
| Lived-Experience Integration | How has the design process incorporated the perspectives of those most exposed to the system’s failure modes — rather than relying exclusively on technical engineering teams? Document the specific consultation processes used, the communities engaged, and the design decisions that were altered as a result. A consultation that produced no design changes is not evidence of compliance. |
Module 2: Structural Context and the Risk of Data Blindness
Objective: To prevent the AI system from penalising individuals for structural social realities — including the unpaid care economy, informal market participation, and historically produced socio-economic exclusion — by treating the absence of formal economic markers as individual-level risk.
| SUBSTANTIVE RIGHT FOCUS AREA | TECHNICAL ASSESSMENT QUESTIONS | MANDATORY REMEDIATION ACTION |
| The Care Economy | Does the system use optimisation metrics that penalise non-linear life trajectories? Examples: career gaps in hiring tools; un-monetised labour in credit scoring; disrupted residency in public housing allocation. | Rewrite core optimisation metrics. Program the model to validate alternative indicators of economic stability — care-giving history, community financial networks, informal employment records — and explicitly prevent the penalisation of recognised care patterns. |
| Historical Asymmetry and Proxy Reconstruction | If gender markers are removed from the dataset, does the model reconstruct structural inequality through correlated proxies? Examples: consumer spending patterns, healthcare history, residential postcodes, or device usage behaviours that track historical segregation. | Execute feature-dependence testing against the full proxy variable set. Strip secondary variables that demonstrably reconstruct historical socio-economic marginalisation. Document each removed variable and the test that identified it. |
| Global South Representation | Is a model trained on Western, industrialised data norms being deployed in different cultural, economic, or linguistic contexts? The assumption that a Global North gender or behavioural archetype is universal constitutes an active form of epistemic harm in deployment. | Localise training frameworks to the deployment context. Engage regional civil society and women’s organisations in validating data assumptions. The model must not enforce culturally specific archetypes onto distinct regional populations. |
Module 3: Safety, Sovereignty, and Bodily Autonomy
Objective: To identify and mitigate Technology-Facilitated Gender-Based Violence (TFGBV) and threats to digital identity, and to establish the absolute protections that no commercial or operational justification may override.
| RIGHTS-BASED SAFETY AND AUTONOMY SCREEN | ||
| IDENTITY PROTECTION | GENERATIVE GUARDRAILS | SURVEILLANCE LIMITS |
| Absolute anonymity required for vulnerable users and victims within legal, judicial, and health data infrastructures. Prohibition on any data architecture that enables doxxing, location tracking, or re-traumatisation of abuse survivors. | Hard, un-bypassable blocks on the generation of non-consensual sexual imagery, synthetic harassment materials, and harmful gendered stereotypes. These blocks must be architectural, not policy-layer: they cannot be overridden by operator configuration. | Hard blocks on biometric profiling that uses gender or race markers in public-space surveillance without explicit judicial authorisation. This requirement applies regardless of stated public safety objectives. |
| ADDITIONAL ASSESSMENTS REQUIRED |
| Digital Violence Prevention: For all generative AI architectures, the developer must document every safeguard preventing the generation of non-consensual sexual imagery, synthetic harassment content, or misogynistic material, and demonstrate that these safeguards cannot be disabled by user or operator instruction. Dignity and Self-Identification: The system must not impose rigid binary gender categorisation on users. This applies specifically to computer vision systems, biometric security screenings, and health diagnostic intake tools. The system must accommodate self-identification and non-binary gender markers without degrading functional performance. Privacy and Vulnerability Sovereignty: Where the system is deployed in legal, judicial, or health contexts, the data infrastructure must provide demonstrable absolute anonymity and encryption to prevent the tracking, doxxing, or re-traumatisation of individuals who have experienced violence. |
Module 4: Socio-Economic Redistribution and Agency
Objective: To ensure the AI system does not scale job displacement in female-dominated sectors, automate biased gatekeeping to essential resources, or replicate existing economic exclusion at greater speed and lower cost than the human processes it replaces.
| ASSESSMENT DIMENSION | REQUIRED ANALYSIS AND MANDATORY RESPONSE |
| Automation Displacement Risk | Does this system disproportionately automate tasks in sectors staffed primarily by women or gender-diverse individuals — including entry-level administrative, customer service, care, and healthcare support roles? If disproportionate displacement is identified: concrete upskilling pathways, transition funding mechanisms, and structural support provisions must be specified and resourced alongside the deployment, not announced as aspirational intentions. |
| Gatekeeping Equity | For automated tools determining access to micro-finance, land rights, medical triage, education, or social benefits, how does the model actively advance historical equity rather than automating an unequal status quo? A system that reproduces the approval rates of a biased human predecessor is not neutral — it is a permanent institutional record of that bias. The standard required is that the system demonstrably improves equity outcomes against the realistic counterfactual, not merely replicates them. |
| Economic Mobility | For financial and credit AI: does the system create pathways for borrowers to demonstrate improved reliability over time, or does an initial low-tier classification become a structural ceiling? Algorithms must be designed to scale access progressively for borrowers who demonstrate consistent behaviour — preventing the permanent low-tier financial stagnation that disproportionately affects women in informal economies. |
Module 5: Multilateral Accountability and Right to Redress
Objective: To establish transparent, human-led oversight and accessible cross-border regulatory recourse. This module operationalises the right to remedy established in the UDHR and affirmed by the Global AI Governance Structure’s mandatory redress mechanisms.
| ACCOUNTABILITY DIMENSION | SPECIFICATION REQUIRED |
| Human Fallback Infrastructure | Every automated decision that materially affects an individual’s civil, social, or economic rights must have a mandatory human review pathway. Rubber-stamp reviews do not satisfy this requirement: the reviewing panel must have genuine authority to override the automated decision and must be trained in substantive human rights frameworks. The panel must be diverse in composition. Homogeneous review panels reproduce the biases they are intended to correct. |
| Algorithmic Transparency | Can the affected individual access a clear, culturally contextualised explanation of why an AI decision was made? That explanation must be available in the individual’s local language, accessible via low-bandwidth interfaces, and written for comprehension by a non-specialist adult — not for the legal compliance record of the deploying organisation. |
| Cross-Border Remedy | Where a commercial AI system deployed globally causes structural or synthetic harm in a jurisdiction outside its corporate headquarters, what mechanism allows local civil society organisations to file for remediation, content removal, or model auditing? This mechanism must be accessible without requiring the complaining party to engage foreign legal systems independently. It connects to the International AI Court established under Tier 1 of the Global AI Governance Structure. |
UN Global Compliance Determination
This determination is made by a reviewing official of the UN-Aligned Global AI Governance Council after evaluation of all five modules. Conditional approval requires a binding remediation schedule, not a statement of intent.
| [ ] NON-COMPLIANT (HALT) | [ ] CONDITIONALLY APPROVED | [ ] COMPLIANT |
| The system meets one or more of the following criteria: • Scales historical vulnerabilities through proxy-based redlining • Enforces rigid binary gender categorisation • Lacks architectural safeguards against synthetic violence • Fails to provide a meaningful human review pathway • Automates discriminatory gatekeeping without equity correction | Technical infrastructure is sound but requires all of the following before full deployment: • Incorporation of care-economy validation metrics • Localised data verification for deployment context • Expanded civil society oversight mechanisms • A binding 90-day remediation schedule | The system demonstrates all of the following: • Actively promotes substantive equality of outcomes • Dismantles rather than replicates institutional power imbalances • Protects bodily and digital autonomy architecturally • Provides robust, accessible pathways for human redress • Meets all five module requirements without conditional exceptions |
| Reviewing Official: _________________________________ (UN-Aligned Global AI Governance Council) Date: ____ / ____ / 2026 |
Illustrative Examples — Substantive Rights GIA in Practice
Example 1 — Hiring Algorithm (Module 2 — Data Blindness and Proxy Discrimination): A global logistics company deploys a recruitment AI trained on a decade of successful-hire records. Module 2 assessment reveals that the model assigns lower relevance scores to candidates with non-linear employment histories. Feature-dependence testing identifies “continuous 12-month employment periods” as an illegitimate proxy variable that correlates with gender and parenting status. Candidates who took primary carer leave — 91% of whom are women — are systematically ranked below candidates with identical technical qualifications who had uninterrupted employment records. The GIA verdict is Non-Compliant: the core optimisation metric is rewritten to treat verified carer history as a neutral employment characteristic, and the variable is structurally removed from the ranking architecture. The revised model is re-assessed under Module 4 (Gatekeeping Equity) to confirm that approval rates have improved relative to the pre-AI baseline of human panel interviews.
Example 2 — Generative AI Platform (Module 3 — Safety, Sovereignty and Bodily Autonomy): A commercial generative AI platform operates a text-to-image model deployed across 47 jurisdictions. Module 3 assessment identifies that requests for synthetic imagery involving women without explicit consent markers are not structurally blocked — they are addressed through an operator-configurable content policy that some commercial operators have disabled. The GIA finds this arrangement Non-Compliant: the hard block on non-consensual synthetic imagery must be architectural, not policy-layer, and cannot be overridden by operator configuration. In addition, the platform’s onboarding flow enforces binary gender selection for user accounts, which the GIA identifies as a Dignity and Self-Identification failure under Module 3. Both findings must be remediated as conditions of continued operational certification in signatory jurisdictions. The 90-day conditional approval period is triggered; Module 5 (Cross-Border Remedy) is activated to permit civil society organisations in affected jurisdictions to file for content removal through the International AI Court mechanism.
Example 3 — AI in Maternal Healthcare (Module 4 — Socio-Economic Redistribution and Global South Deployment): A health technology company trained on clinical data from European and North American obstetric datasets deploys a maternal risk-assessment AI in four West African countries. Module 2 assessment identifies that the model encodes Western definitions of “normal” BMI, birth interval, and antenatal visit frequency — all of which diverge from clinical norms in the deployment context and pathologise statistically ordinary outcomes. Module 4 assessment confirms that the model’s triage outputs are directing clinical resources away from women presenting with conditions that carry elevated mortality risk in the local context but were underrepresented in the training data. The GIA verdict is Non-Compliant. The developer is required to: localise training frameworks in partnership with regional obstetric associations and women’s health organisations; re-assess triage thresholds against local epidemiological data; and ensure that automated risk classifications triggering urgent escalation are subject to a mandatory human clinical review pathway accessible via low-bandwidth SMS interface. A second GIA assessment is required within 12 months, incorporating outcome data from the deployment context.
The three worked examples above illustrate the Substantive Rights GIA across hiring, generative AI, and healthcare deployments. The annex that follows applies the same template to a single high-priority sector in worked regulatory detail: financial inclusion.
Appendix 5
Annex — Implementation Guidance for Financial Inclusion AI Systems
Executive Memorandum · To: Central Bank Governors, Monetary Authority Boards, and Ministry of Finance Leadership · From: Global AI Governance and Digital Inclusion Working Group · Date: May 2026 · Subject: Implementing the Substantive Rights GIA for FinTech and Algorithmic Lending
1. Purpose and Context
This guidance operationalises the Substantive Rights GIA in the specific context of financial inclusion AI. Traditional algorithmic fairness frameworks assess equity through statistical parity — comparing, for instance, male and female loan approval ratios. Those frameworks consistently fail to protect women because they measure balance, not justice: a system can achieve demographic parity while systematically excluding women through proxies that track informal employment, non-linear work histories, and the economic patterns of unpaid care.
This framework requires Central Banks to establish a proactive licensing, sandbox, and continuous auditing mechanism. The objective is to ensure that financial AI applications serve as instruments of wealth creation — extending access to credit, capital, and financial services to populations historically excluded — rather than scaling predatory debt cycles or deepening digital marginalisation.
2. Key Regulatory Pillars
The framework moves beyond gender-blind data processing to evaluate the systemic impacts of automated decision-making across five pillars that map directly to the GIA modules above:
| PILLAR | REQUIREMENT |
| Decentralising Power | FinTech co-design must formally engage local community savings groups, market women’s cooperatives, and informal sector associations. Engagement that produces no design revision is not compliant. |
| Validating the Informal Economy | Optimisation metrics must be rewritten so that career gaps, informal cash ledger histories, and community-based lending records are treated as positive indicators of financial stability rather than risk signals. |
| Data Sovereignty and Safety | Invasive data collection — including scraping device contacts, photo galleries, or location histories — is prohibited. Automated debt-collection practices that exploit biometric or behavioural data are explicitly banned. |
| Economic Mobility | Algorithms must create progressive credit pathways for reliable borrowers. A system that permanently assigns borrowers to a low-access tier based on initial profiling, without a mechanism for tier progression, is non-compliant. |
| Human-in-the-Loop Redress | Automated loan rejections must trigger a mandatory 48-hour human review pathway. That pathway must be accessible in local languages over basic Short Message Service (SMS) and low-bandwidth voice interfaces — not only through web portals. |
3. Financial Compliance Index
FinTech licensing applications are assessed against fifteen criteria drawn from the five pillars above. The score determines the operational pathway:
| SCORE | DETERMINATION | OPERATIONAL PATHWAY |
| 13–15 Points | UN-Certified Compliant | Full operational licence granted. Subject to bi-annual audit cycle. |
| 9–12 Points | Conditionally Approved | Monitored access to the Regulatory Sandbox for 90 days. Licence conditional on deployment of corrective guardrails within that period. |
| 5–8 Points | Non-Compliant | Licence denied. The algorithmic architecture must be redesigned from specification. Reapplication permitted after independent redesign audit. |
4. Strategic Implementation Roadmap (12-Month Rollout)
| PHASE 1 Months 1–3: Policy Mandate | PHASE 2 Months 4–6: Sandbox Integration | PHASE 3 Months 7–12: National Rollout |
| Month 1: Central Bank issues binding regulatory circular incorporating the Substantive Rights GIA into the National Financial Inclusion Strategy. Month 2: Establish multi-stakeholder working group: Central Bank compliance officers, FinTech developer associations, civil society human rights organisations, and representatives of informal sector networks. Month 3: Publish the official Central Bank FinTech GIA Licensing Pack, including the scoring checklist, data-minimisation guidelines, and informal economy validation standards. | Month 4: All FinTech applications within or entering the regulatory sandbox submit their initial GIA profile. Month 5: Central Bank technical teams conduct feature-dependence audits on sandbox models. Audits identify hidden proxy variables — including mobile top-up times and residential postcodes — that replicate historical gender-based financial exclusion. Month 6: Verify that all FinTechs have established SMS and voice-based human appeal channels operating within the required 48-hour resolution window. | Month 7: GIA transitions from sandbox to full national enforcement. No new digital financial service may launch without reaching the minimum compliance threshold. Month 9: Existing operational FinTech platforms receive a 90-day grace period to complete the assessment and adjust their parameters. Month 12: First national audit cycle completed. Licensees submit automated performance drift logs and redress records, establishing the baseline for bi-annual ongoing compliance monitoring. |
| Integration with the Global AI Governance Structure This appendix operationalises within the GIA context the same principles that govern the whole of the Global AI Governance Structure: the burden of proof rests on developers, not on affected communities; harm is assessed substantively, not statistically; and enforcement operates through verifiable institutional mechanisms rather than declaratory commitments. The Substantive Rights GIA integrates directly with the IAASB’s rights compliance body (Tier 2), the International AI Court (Tier 1), and the mandatory demographic impact assessment requirements set out in Appendix 2. |
Chicago Manual of Style, 17th edition
Bibliography
International Legal Instruments
Charter of the United Nations. San Francisco, 26 June 1945. 1 UNTS XVI. Entered into force 24 October 1945.
Convention on Biological Diversity. 5 June 1992, 1760 UNTS 79. Entered into force 29 December 1993.
Convention on the Prohibition of the Development, Production and Stockpiling of Bacteriological (Biological) and Toxin Weapons and on their Destruction. 10 April 1972, 1015 UNTS 163. Entered into force 26 March 1975.
Convention on the Prohibition of the Development, Production, Stockpiling and Use of Chemical Weapons and on their Destruction. 13 January 1993, 1974 UNTS 317. Entered into force 29 April 1997.
Montreal Protocol on Substances that Deplete the Ozone Layer. 16 September 1987, 1522 UNTS 3. Entered into force 1 January 1989.
Paris Agreement under the United Nations Framework Convention on Climate Change. 12 December 2015, TIAS 16-1104. Entered into force 4 November 2016.
Rome Statute of the International Criminal Court. 17 July 1998, 2187 UNTS 90. Entered into force 1 July 2002.
Treaty on the Non-Proliferation of Nuclear Weapons. 1 July 1968, 729 UNTS 161. Entered into force 5 March 1970.
United Nations Declaration on the Rights of Indigenous Peoples. UN General Assembly Resolution 61/295, 13 September 2007. UN Doc. A/RES/61/295.
United Nations Framework Convention on Climate Change. 9 May 1992, 1771 UNTS 107. Entered into force 21 March 1994.
Universal Declaration of Human Rights. UN General Assembly Resolution 217A(III), 10 December 1948. UN Doc. A/810.
Intergovernmental and Institutional Documents
European Parliament and Council of the European Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). Official Journal of the European Union, 12 July 2024.
G7 Hiroshima AI Process. Hiroshima Process International Code of Conduct for Advanced AI Systems. Hiroshima: G7, 30 October 2023.
International Atomic Energy Agency. The Statute of the IAEA. Vienna: IAEA, 1956. Entered into force 29 July 1957.
United Nations Institute for Disarmament Research. Centre of Excellence on AI, Peace and Security. Geneva: UNIDIR, 2026.
Organisation for Economic Co-operation and Development. Recommendation of the Council on Artificial Intelligence. OECD/LEGAL/0449. Paris: OECD, 22 May 2019.
UK Department for Science, Innovation and Technology. The Bletchley Declaration by Countries Attending the AI Safety Summit, 1–2 November 2023. London: DSIT, 1 November 2023.
United Nations Environment Programme. State of the Global Environment Report. Nairobi: UNEP, 2024.
United Nations General Assembly. Our Common Agenda: Report of the Secretary-General. UN Doc. A/75/982. New York: United Nations, 2021.
United Nations General Assembly. Terms of Reference and Modalities for the Establishment and Functioning of the Independent International Scientific Panel on Artificial Intelligence and the Global Dialogue on Artificial Intelligence Governance. UN Doc. A/RES/79/325. New York: United Nations, 26 August 2025.
United Nations Secretary-General’s High-Level Advisory Body on Artificial Intelligence. Governing AI for Humanity: Final Report. New York: United Nations, August 2024.
United Nations Secretary-General. Roadmap for Digital Cooperation. New York: United Nations, June 2020.
UNESCO. Recommendation on the Ethics of Artificial Intelligence. Paris: UNESCO, 23 November 2021.
UNESCO. Readiness Assessment Methodology: A Tool of the Recommendation on the Ethics of Artificial Intelligence. Paris: UNESCO, 2023.
UNESCO. Ethical Impact Assessment: A Tool of the Recommendation on the Ethics of Artificial Intelligence. Paris: UNESCO, 2023.
UNESCO Global AI Ethics and Governance Observatory. First Global Progress Report on Implementation of the Recommendation on the Ethics of Artificial Intelligence. Paris: UNESCO, 18 March 2026.
Judicial Decisions and Constitutional Instruments
Constitutional Court of Ecuador. Constitución de la República del Ecuador. Articles 71–74 (Rights of Nature). Quito, 2008.
High Court of Uttarakhand. Mohd. Salim v. State of Uttarakhand & Others. Writ Petition (PIL) No. 126 of 2014. Judgment, 20 March 2017.
Supreme Court of Colombia. Sentencia STC 4360-2018. Bogotá, 5 April 2018.
Te Awa Tupua (Whanganui River Claims Settlement) Act 2017 (New Zealand). Public Act 2017 No. 7, enacted 20 March 2017.
AI Governance and Safety
Brundage, Miles, Shahar Avin, Jack Clark, Helen Toner, Peter Eckersley, Ben Garfinkel, Allan Dafoe, Paul Scharre, Thomas Zeitzoff, Bobby Filar, Hyrum Anderson, Heather Roff, Gregory C. Allen, Jacob Steinhardt, Carrick Flynn, Seán Ó hÉigeartaigh, Simon Beard, Haydn Belfield, Sebastian Farquhar, Clare Lyle, Rebecca Crootof, Owain Evans, Michael Page, Joanna Bryson, Roman Yampolskiy, and Dario Amodei. “The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation.” arXiv:1802.07228, February 2018.
Cihon, Peter, Matthijs Maas, and Luke Kemp. “Should Artificial Intelligence Governance Be Centralised? Design Lessons from History.” In Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society, 228–234. New York: ACM, 2020.
Dafoe, Allan. “AI Governance: A Research Agenda.” Future of Humanity Institute, University of Oxford, 2018.
Gabriel, Iason. “Artificial Intelligence, Values, and Alignment.” Minds and Machines 30, no. 3 (2020): 411–437.
Hadfield, Gillian K., and Jack Clark. “Intelligent Institutions: Can AI Address Core Challenges in the Governance of Human Societies?” arXiv:2305.02005, 2023.
Jobin, Anna, Marcello Ienca, and Effy Vayena. “The Global Landscape of AI Ethics Guidelines.” Nature Machine Intelligence 1, no. 9 (2019): 389–399.
Russell, Stuart. Human Compatible: Artificial Intelligence and the Problem of Control. New York: Viking, 2019.
Tegmark, Max. Life 3.0: Being Human in the Age of Artificial Intelligence. New York: Knopf, 2017.
Algorithmic Fairness and Accountability
Buolamwini, Joy, and Timnit Gebru. “Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification.” Proceedings of the 1st Conference on Fairness, Accountability and Transparency, Proceedings of Machine Learning Research 81 (2018): 77–91.
Chouldechova, Alexandra. “Fair Prediction with Disparate Impact: A Study of Bias in Recidivism Prediction Instruments.” Big Data 5, no. 2 (2017): 153–163.
Crawford, Kate. Atlas of AI: Power, Politics, and the Planetary Costs of Artificial Intelligence. New Haven: Yale University Press, 2021.
Kleinberg, Jon, Sendhil Mullainathan, and Manish Raghavan. “Inherent Trade-Offs in the Fair Determination of Risk Scores.” In Proceedings of the 8th Innovations in Theoretical Computer Science Conference (ITCS 2017), edited by Christos H. Papadimitriou. Schloss Dagstuhl: LIPIcs, 2017.
Mittelstadt, Brent D., Patrick Allo, Mariarosaria Taddeo, Sandra Wachter, and Luciano Floridi. “The Ethics of Algorithms: Mapping the Debate.” Big Data and Society 3, no. 2 (2016): 1–21.
Whittaker, Meredith, Kate Crawford, Roel Dobbe, Genevieve Fried, Elizabeth Kaziunas, Varoon Mathur, Sarah Myers West, Rashida Richardson, Jason Schultz, and Oscar Schwartz. AI Now Report 2018. New York: AI Now Institute, 2018.
Zuboff, Shoshana. The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. New York: PublicAffairs, 2019.
Political Economy and Technology
Acemoglu, Daron, and Pascual Restrepo. “Artificial Intelligence, Automation, and Work.” In The Economics of Artificial Intelligence: An Agenda, edited by Ajay Agrawal, Joshua Gans, and Avi Goldfarb, 197–236. Chicago: University of Chicago Press, 2019.
Autor, David H. “Work of the Past, Work of the Future.” AEA Papers and Proceedings 109 (2019): 1–32.
Collingridge, David. The Social Control of Technology. New York: St. Martin’s Press, 1980.
Keohane, Robert O., and Joseph S. Nye Jr. Power and Interdependence: World Politics in Transition. Boston: Little, Brown, 1977.
Mazzucato, Mariana. The Entrepreneurial State: Debunking Public vs. Private Sector Myths. London: Anthem Press, 2013.
Ostrom, Elinor. Governing the Commons: The Evolution of Institutions for Collective Action. Cambridge: Cambridge University Press, 1990.
Ruggie, John Gerard. “Reconstituting the Global Public Domain: Issues, Actors, and Practices.” European Journal of International Relations 10, no. 4 (2004): 499–531.
Philosophy, Ethics, and Human Dignity
Lonergan, Bernard J. F. Insight: A Study of Human Understanding. Toronto: University of Toronto Press, 1957.
MacIntyre, Alasdair. After Virtue: A Study in Moral Theory. London: Duckworth, 1981.
Rawls, John. A Theory of Justice. Cambridge, MA: Harvard University Press, 1971.
Sen, Amartya. Development as Freedom. New York: Anchor Books, 1999.
Ecology, Rights of Nature, and Planetary Boundaries
Boyd, David R. The Rights of Nature: A Legal Revolution That Could Save the World. Toronto: ECW Press, 2017.
Rockström, Johan, Will Steffen, Kevin Noone, Åsa Persson, F. Stuart Chapin III, Eric F. Lambin, Timothy M. Lenton, Marten Scheffer, Carl Folke, Hans Joachim Schellnhuber, Bjørn Nykær, Cynthia A. de Wit, Terry Hughes, Sander van der Leeuw, Henning Rodhe, Sverker Sörlin, Peter K. Snyder, Robert Costanza, Uno Svedin, Malin Falkenmark, Louise Karlberg, Robert W. Corell, Victoria J. Fabry, James Hansen, Brian Walker, Diana Liverman, Katherine Richardson, Paul Crutzen, and Jonathan A. Foley. “A Safe Operating Space for Humanity.” Nature 461 (2009): 472–475.
Stone, Christopher D. “Should Trees Have Standing? Toward Legal Rights for Natural Objects.” Southern California Law Review 45 (1972): 450–501.
Gender, Equity, and AI
Criado Perez, Caroline. Invisible Women: Exposing Data Bias in a World Designed for Men. London: Chatto and Windus, 2019.
West, Sarah Myers, Meredith Whittaker, and Kate Crawford. Discriminating Systems: Gender, Race, and Power in AI. New York: AI Now Institute, 2019.
Demographic, Ecological and Gender Impact Assessment: Additional Sources
Obermeyer, Ziad, Brian Powers, Christine Vogeli, and Sendhil Mullainathan. “Dissecting Racial Bias in an Algorithm Used to Manage the Health of Populations.” Science 366, no. 6464 (2019): 447–453. [Illustrates label bias in healthcare triage; foundational for Appendix 2, Example 1.]
Angwin, Julia, Jeff Larson, Surya Mattu, and Lauren Kirchner. “Machine Bias.” ProPublica, 23 May 2016. [Foundational empirical investigation of disparate error rates in recidivism prediction; cited in relation to Appendix 2, Example 2.]
Crawford, Kate. Atlas of AI. Full citation above, under Algorithmic Fairness and Accountability. [Supply chain and ecological impact; cited in relation to Appendix 4, Example 2.]
Patterson, David, Joseph Gonzalez, Quoc V. Le, Chen Liang, Lluis-Miquel Munguia, Daniel Rothchild, David So, Maud Texier, and Jeff Dean. “Carbon Emissions and Large Neural Network Training.” arXiv:2104.10350, 2021. [Quantitative basis for compute carbon intensity assessment in Appendix 4, Example 1.]
Buolamwini, Joy, and Timnit Gebru. “Gender Shades.” Full citation above, under Algorithmic Fairness and Accountability. [Foundational for Appendix 5, Examples 1 and 2; demonstrates proxy discrimination and misclassification affecting women and racialised groups.]
World Health Organisation. Maternal Mortality: Key Facts. Geneva: WHO, 2023. [Epidemiological basis for regional clinical norms in Appendix 5, Example 3; cited in support of localisation requirements for Global South deployment of maternal health AI.]
International Union for Conservation of Nature (IUCN). The IUCN Red List of Threatened Species. Version 2024-1. Gland: IUCN, 2024. [Biodiversity corridor baseline data; cited in support of the right-to-exist compliance criterion in Appendix 4, Example 2.]