Big question: Which institution can turn a principle into an enforceable practice?
Research lock: 2026-08-28

Why this week matters

AI governance is not a list of principles or laws. It is a stack: definitions, prohibited uses, risk classification, sector rules, standards, procurement, documentation, testing, incident reporting, liability, regulators, courts, worker agreements, and organizational controls. Students should map a use to actors and obligations, then ask whether institutions have the evidence and capacity to enforce them.

Deeper teaching spine

1. Compare governance mechanisms by what they do

  • Principles: align expectations and vocabulary; usually weak on verification and remedy.
  • Standards/frameworks: operationalize practices and evidence; may be voluntary or incorporated into contracts/law.
  • Risk regulation: imposes obligations by use/capability category.
  • Sector law: applies existing health, employment, credit, privacy, safety, or consumer duties.
  • Procurement: changes market access through buyer requirements.
  • Liability/enforcement: assigns consequences and remedy after or before harm.
  • Collective bargaining/professional rules: govern work and domain practice.

Ask who sets each rule, who must act, what evidence demonstrates compliance, who investigates, and what happens when the rule fails.

2. Read the EU AI Act as an implementation system

The Act entered into force in August 2024 and applies progressively. As of the research lock, the Commission states that enforcement powers and transparency requirements began applying on 2 August 2026; prohibited-practice and AI-literacy provisions applied earlier, and high-risk timelines were extended by later simplification measures. Students must consult the live official timeline rather than memorize a frozen chart.

Map provider, deployer, importer, distributor, affected person, national authority, and AI Office. For one system identify risk class, documentation, data governance, logging, human oversight, accuracy/robustness, transparency, post-market monitoring, incident reporting, and complaint route.

3. Compare U.S. infrastructure/procurement with rights-based regulation

America's 2025 AI Action Plan emphasizes innovation, infrastructure, adoption, security, and international competition. Executive and agency action can reshape procurement and standards quickly but can also change between administrations. Compare this with sector enforcement by bodies such as the FTC, EEOC, CFPB, FDA, and NHTSA, and with state/local laws. “The U.S. has no AI regulation” is analytically useless.

4. International coordination has different force

The OECD AI Principles are non-binding but influential and were updated in 2024. The Council of Europe Framework Convention is the first legally binding international AI treaty framework, opened for signature in September 2024, with duties around rights, transparency, accountability, remedies, and iterative risk/impact assessment. The UN General Assembly's March 2024 resolution was adopted without a vote and emphasizes safe, secure, trustworthy systems and closing digital divides. Compare legal force, membership, monitoring, and domestic implementation.

5. Governance requires technical and administrative capacity

A risk-based law fails without registries, standards, auditors, evaluation methods, complaint handling, inspectors, courts, documentation access, and skilled deployers. Ask who pays for compliance, whether small organizations can comply, how regulators inspect proprietary systems, and how affected people discover and challenge a use.

6. Use the Collingridge dilemma productively

Early in development, intervention is easier but impacts are uncertain; after diffusion, impacts are clearer but systems and interests are entrenched. Pair staged obligations, sandboxes, pilots, monitoring, review clauses, incident reporting, and updateable standards with non-negotiable rights and red lines. “Wait for evidence” and “regulate now” are not the only designs.

Case-study dossier

EU AI Act role map

Choose an AI résumé screener used by an EU employer and supplied by a non-EU vendor. Students map actors, timeline, high-risk category, provider/deployer duties, transparency, logs, oversight, standards, complaint, and enforcement. Then change the use to a spam filter and explain why the regime changes.

Government procurement and ideological neutrality

Use EO 14319 as a primary receipt for government defining “truth-seeking” and “ideological neutrality” in procured language models. Students identify which claims could be tested, who defines bias, how evaluators handle contested facts, and what procurement evidence would be auditable without pretending the evaluation is value-free.

International AI Safety Report

Treat the report as a shared evidence process rather than law. Select one risk claim and trace evidence type, uncertainty, dissent, and policy relevance. Ask what coordination a scientific report can enable and which decisions remain political.

Canada federal automated decisions

Apply the Directive on Automated Decision-Making and the Algorithmic Impact Assessment to a federal eligibility tool. Compare ex ante questionnaire obligations with independent audit, public notice, explanation, human intervention, recourse, and outcome monitoring.

Governance comparison worksheet

For each instrument record:

  1. Scope and AI definition.
  2. Regulated actor and lifecycle stage.
  3. Trigger: sector, use, capability, risk, or purchaser.
  4. Required action and evidence artifact.
  5. Supervising/enforcing institution.
  6. Complaint, appeal, liability, or remedy.
  7. Territorial reach and supply-chain effect.
  8. Effective/application date and transition.
  9. Known capacity or standardization dependency.
  10. Update mechanism.

Visual evidence plan

VisualCapture targetTeaching useGuardrail
EU AI Act risk/timeline pageEuropean Commission live framework pageCapture current application timeline and one high-risk duty list.Date the screenshot; the timeline changed after adoption.
EU enforcement architectureCommission enforcement pageMap AI Office, national authorities, complaints, and phased powers.Official explanation is not an independent effectiveness assessment.
OECD principlesOECD AI PrinciplesCompare human-rights values with implementation recommendations.Non-binding principles are not enforcement.
Council of Europe conventionofficial convention pageCapture principles, remedies, and risk/impact duties.Signature, ratification, entry into force, and domestic effect differ.
UN resolutionUN meeting recordHighlight safe/secure/trustworthy AI and digital-divide commitments.General Assembly resolution is not a treaty.
Canadian AIAofficial tool pageCompare risk tier to required mitigation.Scope is covered federal automated decisions.

Reading and citation ledger

  1. European Commission, AI Act regulatory framework and live timeline.
  2. Regulation (EU) 2024/1689, official text.
  3. European Commission, AI Act enforcement framework.
  4. OECD AI Principles, updated 2024 and update explanation.
  5. Council of Europe Framework Convention on AI.
  6. UN General Assembly, March 2024 AI resolution meeting record.
  7. The White House, America's AI Action Plan (2025).
  8. Executive Order 14319 (2025).
  9. Canada, Directive on Automated Decision-Making and Algorithmic Impact Assessment.
  10. International AI Safety Report 2026.

Watch list

  • Re-check every implementation date and legal-status statement before class.
  • Distinguish proposal, political agreement, adopted text, entry into force, application, enforcement, and judicial interpretation.
  • Ask whether standards and conformity-assessment infrastructure are available, not only whether a law names them.
  • Include sector and subnational governance; omnibus AI laws are only part of the stack.