The Global Governance Challenge
As artificial intelligence transforms economies and societies, governments worldwide face an urgent challenge: how to develop effective governance frameworks for AI systems. According to the OECD’s June 2024 report, almost all OECD countries are developing or updating strategies and plans for AI that include specific objectives for its use in the public sector. However, AI strategies specifically targeted to the public sector remain very limited, creating a governance gap. This has prompted a wave of institutional innovation as governments explore how to secure AI’s benefits while mitigating its risks.
Two contrasting approaches have emerged: adapting existing regulatory bodies to encompass AI oversight, or creating specialized new institutions focused specifically on AI governance. The Cyberspace Administration of China (CAC) and Spain’s Agency for the Supervision of Artificial Intelligence Systems (AESIA) exemplify these divergent pathways, offering valuable lessons for institutional innovation in AI governance.
China's Collaborative Multi-Agency Framework
China has developed a sophisticated multi-agency approach to AI governance centered around the Cyberspace Administration of China (CAC). Established in 2014 as China’s central internet regulator, the CAC has since undergone a transformation into the country’s primary AI regulator. This evolution was accelerated by ChatGPT’s release in December 2022, which prompted domestic tech companies to rapidly develop competing models.
Rather than creating an entirely new agency, Chinese authorities strategically expanded the CAC’s mandate while establishing a collaborative governance framework that includes multiple agencies working in concert:
- The Cyberspace Administration of China (CAC) serves as the primary coordinator
- The National Development and Reform Commission addresses economic impacts
- The Ministry of Education guides AI curriculum development
- The Ministry of Science and Technology directs research priorities
- The Ministry of Industry and Information Technology oversees industrial applications
- The Ministry of Public Security addresses security implications
- The National Radio and Television Administration monitors content-related concerns
Each agency focuses on sector-specific responsibilities while jointly shaping and enforcing AI policies. This integrated approach to digital governance views internet content, data flows, and algorithmic systems as interconnected elements requiring coordinated oversight.
The CAC’s evolution faced significant challenges, including rapidly developing technical expertise while coordinating with multiple ministries. Its success stems from several key institutional design features:
- Direct reporting lines to top leadership through the Central Cyberspace Affairs Commission
- Cross-ministerial coordination powers to align policies across government bodies
- A nationwide network of provincial and local offices ensuring implementation capacity
- A regulatory approach combining framework legislation with detailed implementation rules
By August 2023, the CAC had implemented the world’s first comprehensive generative AI regulations through the “Administrative Provisions on Deep Synthesis Internet Information Services.” The CAC’s continued evolution of its regulatory framework demonstrates how existing institutions can effectively adapt their mandates and capabilities to address emerging technological challenges.
Spain's AESIA: Creating a Specialized AI Supervisor
Spain took a different approach. In July 2023, as the European Union finalized its landmark AI Act, Spain announced the formation of AESIA (Agencia Estatal de Supervisión de la Inteligencia Artificial) as part of its National AI Strategy.
A catalyst for AESIA’s creation was Spain’s Presidency of the Council of the European Union in the second half of 2023, which gave Spain both opportunity and motivation to establish a national entity aligned with European regulations.
AESIA faced immediate implementation challenges, particularly building technical capacity while competing with private industry for scarce AI expertise.
The agency’s design reflects these challenges:
From the outset, AESIA faced a core challenge: how to build technical capacity and public legitimacy in a field where expertise is scarce and competition with the private sector is fierce. Spain responded not with hesitation, but with purposeful design.
The agency was set up as an independent body with dedicated resources, giving it the autonomy and credibility needed to act swiftly. Multidisciplinary teams combined technical and policy expertise, bridging the gap between innovation and regulation. An advisory board brought in voices from industry, academia, and civil society, grounding decisions in a broad societal perspective. And a risk-based oversight model ensured focus on high-stakes applications, avoiding regulatory overreach. Together, these four elements formed a smart institutional response that balanced agility with accountability in shaping the future of AI.
Although still in its early days, AESIA has moved with impressive speed for such a newly created institution, particularly in a field as complex and fast-evolving as AI. Within a short period, it has begun to put in place the building blocks of a national governance system: a risk-based AI certification framework to ensure oversight where it matters most, transparency where it matters least, and the foundations for legislative enforcement. Perhaps more importantly, AESIA has opened space for experimentation, with plans for a regulatory sandbox that signals a commitment to learning-by-doing, allowing innovation to flourish while shaping the rules of the game in real time. These early moves point not just to institutional agility, but to a broader ambition: to govern emerging technologies with both foresight and flexibility.
Diversifying Institutional Responses
Beyond these two case studies, governments across the world are exploring diverse institutional arrangements for AI governance. The table below synthesizes examples of organizational structures along with key dates and additional context.
Organizational Structures for AI Governance
Territory / Country | Organizational Structure / Action | Description |
United Arab Emirates (UAE) | Ministerial Leadership | Appointed a dedicated Minister for AI in 2017 to elevate AI governance to the cabinet level and integrate it with national strategic goals. |
United Kingdom | Specialized Office for AI | Established an Office for AI—now integrated into the Department of Science, Innovation and Technology (integration evolving from circa 2018 to 2021)—to drive cross-government AI innovation and policy. |
Singapore | Technical Agency | GovTech, established in the mid-2010s (around 2016), acts as the technical arm for digital transformation, managing both product development and the Government Tech Stack, with AI initiatives included. |
Australia | Transformation Agency | The Digital Transformation Agency, created in 2015, focuses on developing digital products and services while embedding governance into the country’s digital transformation strategy. |
Denmark | Skills-Focused Entity | GovTech Academy, launched around 2019, is designed to build digital capability and upskill public servants to manage and implement AI innovations effectively. |
Canada | Federated System | Implements a distributed governance model—with common standards across federal and provincial governments—that has evolved since the early 2010s, balancing local innovation with centralized guidelines. |
New Zealand | Federated System | Uses a decentralized approach that sets national standards while empowering local agencies to innovate, a model that has developed since the late 2010s. |
India | Coordinating Agency | NITI Aayog’s AI Task Force—introduced in 2018 as part of the country’s National Strategy for AI—focuses on multi-stakeholder collaboration and policy coordination to support inclusive AI innovation. |
Brazil | Coordinating Agency | The Ministry of Science, Technology and Innovation coordinates AI initiatives since around 2019, fostering cross-sector public-private partnerships and addressing regulatory challenges. |
South Africa | Specialized Office for AI | Under the Department of Science and Innovation, the National AI Strategy (published in 2019) has led to the creation of dedicated units aimed at promoting ethical AI deployment and innovation. |
Malaysia | National AI Office | Established in December 2024, this office centralizes policy coordination and regulatory measures for high-stakes AI applications across the government. |
Qatar | AI Committee | Created in 2024 as part of its National AI Strategy, the committee ensures coordinated implementation of AI policies across various government agencies. |
European Union | Multi-layered Institutional Ecosystem | Under the EU AI Act approved in March 2024, the framework includes multiple bodies such as the European AI Office, European Artificial Intelligence Board, and the European Centre for Algorithmic Transparency (ECAT) to manage risk-based AI governance. |
United States | Decentralized Governance Model | Federal agencies have been required to designate Chief AI Officers and establish AI Governance Boards since the early 2020s, integrating AI policy and oversight at the agency level without a centralized AI office. |
Switzerland | Multi-Stakeholder Governance Model | Features distributed oversight among multiple federal entities (e.g., the Federal Data Protection and Information Commissioner, Financial Market Supervisory Authority) along with cantonal authorities, supporting coordinated yet flexible AI governance. |
Complementary Governance Instruments
Beyond institutional arrangements, governments are deploying a diverse toolkit of complementary governance instruments to shape AI development and use. These include voluntary standards and guidelines (such as Australia’s AI Safety Standard and Malaysia’s National Guidelines on AI Governance and Ethics), regulatory sandboxes for controlled experimentation, public procurement policies that leverage government purchasing power, sectoral regulations for high-stakes domains, algorithmic impact assessments, and third-party certification schemes. Together, these instruments create a layered governance ecosystem that offers flexibility and targeted oversight without necessarily requiring new dedicated agencies. Their effectiveness typically depends on strategic coordination between public and private actors and complementary deployment alongside formal institutional frameworks.
Community-Driven Governance Initiatives
In addition to state-led efforts, some countries are seeing grassroots and civil society initiatives fill critical AI governance gaps. For example, Kabakoo – an African EdTech platform – establishes community standards by blending advanced technology with indigenous knowledge. Similarly, Lelapa AI implements governance through culturally sensitive practices, including the deployment of the first African large language model (LLM). In New Zealand, the Māori Data Governance initiative exemplifies how Indigenous communities can assert data sovereignty by creating culturally centered frameworks that view data as taonga (treasure), ensuring AI and data systems honor traditional knowledge while enabling self-determination. These initiatives help ensure that AI oversight reflects local languages, cultural values, and regional priorities – counterbalancing external frameworks and challenging the dominance of foreign tech models.
Key Lessons for Institutional Innovation
Despite their different forms, these institutional responses face remarkably similar challenges. The experiences of these diverse approaches offer a few critical lessons:
- Capabilities matter more than structure: Across all organizational models—from China’s expanded CAC to Spain’s specialized AESIA, from the UAE’s ministerial approach to federated systems in Canada and New Zealand—three factors consistently determine effectiveness:
- Concentrated technical capacity to understand and evaluate complex AI systems
- Cross-boundary authority to coordinate data, standards, rules, and procurement
- Strong leadership with both technological understanding and institutional credibility
- Adaptability is essential: Successful governance institutions—whether adapted existing bodies or newly created ones—continuously evolve their capabilities and approaches as AI technology advances. The CAC’s transformation from internet regulator to AI overseer exemplifies this adaptability.
- Layered governance works best: The most effective approaches combine multiple tools—binding regulations, voluntary standards, sector-specific rules, and innovation sandboxes—creating comprehensive frameworks that balance oversight with innovation.
- Context shapes implementation: Effective governance reflects national priorities and existing legal traditions rather than following a universal template, as seen in China’s focus on content governance versus Australia’s principles-based approach.
These lessons demonstrate that effective AI governance depends less on specific organizational forms and more on building the right capabilities with appropriate authority and leadership. Creating concentrated centers of expertise with the mandate to work across traditional boundaries represents the most promising approach to addressing the governance challenges posed by artificial intelligence.
At UNDP Istanbul Innovation Days
How can countries design effective institutions for AI governance that balance innovation with appropriate safeguards? What can we learn from contrasting institutional approaches across different contexts?
Photo Credit: InsideTelecom
