THE BIIRGS RESOURCE
AI is becoming more capable, more widely available, and more deeply embedded in decisions about work, access, information, health, public services, and everyday life.
The systems responsible for governing these developments are not advancing at the same pace. Law, regulation, institutional capacity, professional standards, public understanding, and routes for recourse are often slower to develop than the technologies they are intended to oversee.
This does not mean that no rules exist. It means there is a growing distance between what AI systems can do, where they are being deployed, and the safeguards capable of keeping pace.
That distance is the AI governance gap.
The Acceleration Problem
Regulatory systems are designed to establish authority, define obligations, assess risks, consult affected interests, and create mechanisms for enforcement. These processes take time because durable rules require legitimacy, clarity, institutional capacity, and public accountability.
AI development operates on a different tempo. Capabilities can change through successive model releases, new forms of deployment, expanded access, and rapid integration into products and services. A system may move from experimental use to widespread public exposure before regulators, institutions, workers, and affected communities have had a meaningful opportunity to understand its implications.
By the time a rule is proposed, the technology may have changed. By the time a standard is adopted, the system may already be embedded across multiple sectors. By the time harm becomes visible, responsibility may be distributed across developers, deployers, vendors, operators, and public authorities.
Technological acceleration does not make governance unnecessary. It makes governance more difficult and more urgent.
Governance Is More Than Regulation
Regulation is one part of governance, but governance extends beyond legislation.
It includes the laws that establish boundaries, the agencies that interpret and enforce them, the standards that define responsible practice, the institutions that decide whether a system should be used, the procurement rules that shape what enters public life, and the mechanisms through which affected people can challenge decisions or seek remedy.
It also includes the capacity to monitor systems after deployment. A rule that exists on paper but cannot be understood, enforced, or adapted may offer less protection than its existence suggests.
Recent review research makes this distinction concrete. Papagiannidis, Mikalef, and Conboy identify three dimensions of responsible AI governance: structural practices, such as roles, policies, and resources; relational practices, such as coordination, participation, and accountability; and procedural practices, such as design, deployment, monitoring, and evaluation.
Their review highlights a persistent challenge: responsible AI principles are more developed than the organizational practices needed to operationalize them. Read the review
A policy statement or ethical framework therefore does not, by itself, demonstrate governance. Governance is demonstrated through the capacity to identify responsibility, assess impacts, monitor systems, respond to complaints, and change or withdraw systems when evidence requires it.
A Fragmented Governance Landscape
There is no single global system governing artificial intelligence.
In the United States, governance is distributed across existing sectoral law, agency action, state initiatives, standards, procurement requirements, litigation, organizational policies, and voluntary commitments. This can produce important protections, but it can also create uneven coverage and uncertainty about which safeguards apply.
Internationally, jurisdictions are developing different approaches to risk, transparency, safety, accountability, data, competition, labor, and human rights. The European Union’s AI Act represents a major regulatory development, while the OECD and United Nations have advanced broader international principles and governance proposals.