Big question: Which institution can turn a principle into an enforceable practice?
Research lock: 2026-08-28
Why this week matters
AI governance is not a list of principles or laws. It is a stack: definitions, prohibited uses, risk classification, sector rules, standards, procurement, documentation, testing, incident reporting, liability, regulators, courts, worker agreements, and organizational controls. Students should map a use to actors and obligations, then ask whether institutions have the evidence and capacity to enforce them.
Deeper teaching spine
1. Compare governance mechanisms by what they do
- Principles: align expectations and vocabulary; usually weak on verification and remedy.
- Standards/frameworks: operationalize practices and evidence; may be voluntary or incorporated into contracts/law.
- Risk regulation: imposes obligations by use/capability category.
- Sector law: applies existing health, employment, credit, privacy, safety, or consumer duties.
- Procurement: changes market access through buyer requirements.
- Liability/enforcement: assigns consequences and remedy after or before harm.
- Collective bargaining/professional rules: govern work and domain practice.
Ask who sets each rule, who must act, what evidence demonstrates compliance, who investigates, and what happens when the rule fails.
2. Read the EU AI Act as an implementation system
The Act entered into force in August 2024 and applies progressively. As of the research lock, the Commission states that enforcement powers and transparency requirements began applying on 2 August 2026; prohibited-practice and AI-literacy provisions applied earlier, and high-risk timelines were extended by later simplification measures. Students must consult the live official timeline rather than memorize a frozen chart.
Map provider, deployer, importer, distributor, affected person, national authority, and AI Office. For one system identify risk class, documentation, data governance, logging, human oversight, accuracy/robustness, transparency, post-market monitoring, incident reporting, and complaint route.
3. Compare U.S. infrastructure/procurement with rights-based regulation
America's 2025 AI Action Plan emphasizes innovation, infrastructure, adoption, security, and international competition. Executive and agency action can reshape procurement and standards quickly but can also change between administrations. Compare this with sector enforcement by bodies such as the FTC, EEOC, CFPB, FDA, and NHTSA, and with state/local laws. “The U.S. has no AI regulation” is analytically useless.
4. International coordination has different force
The OECD AI Principles are non-binding but influential and were updated in 2024. The Council of Europe Framework Convention is the first legally binding international AI treaty framework, opened for signature in September 2024, with duties around rights, transparency, accountability, remedies, and iterative risk/impact assessment. The UN General Assembly's March 2024 resolution was adopted without a vote and emphasizes safe, secure, trustworthy systems and closing digital divides. Compare legal force, membership, monitoring, and domestic implementation.
5. Governance requires technical and administrative capacity
A risk-based law fails without registries, standards, auditors, evaluation methods, complaint handling, inspectors, courts, documentation access, and skilled deployers. Ask who pays for compliance, whether small organizations can comply, how regulators inspect proprietary systems, and how affected people discover and challenge a use.
6. Use the Collingridge dilemma productively
Early in development, intervention is easier but impacts are uncertain; after diffusion, impacts are clearer but systems and interests are entrenched. Pair staged obligations, sandboxes, pilots, monitoring, review clauses, incident reporting, and updateable standards with non-negotiable rights and red lines. “Wait for evidence” and “regulate now” are not the only designs.
Case-study dossier
EU AI Act role map
Choose an AI résumé screener used by an EU employer and supplied by a non-EU vendor. Students map actors, timeline, high-risk category, provider/deployer duties, transparency, logs, oversight, standards, complaint, and enforcement. Then change the use to a spam filter and explain why the regime changes.
Government procurement and ideological neutrality
Use EO 14319 as a primary receipt for government defining “truth-seeking” and “ideological neutrality” in procured language models. Students identify which claims could be tested, who defines bias, how evaluators handle contested facts, and what procurement evidence would be auditable without pretending the evaluation is value-free.
International AI Safety Report
Treat the report as a shared evidence process rather than law. Select one risk claim and trace evidence type, uncertainty, dissent, and policy relevance. Ask what coordination a scientific report can enable and which decisions remain political.
Canada federal automated decisions
Apply the Directive on Automated Decision-Making and the Algorithmic Impact Assessment to a federal eligibility tool. Compare ex ante questionnaire obligations with independent audit, public notice, explanation, human intervention, recourse, and outcome monitoring.
Governance comparison worksheet
For each instrument record:
- Scope and AI definition.
- Regulated actor and lifecycle stage.
- Trigger: sector, use, capability, risk, or purchaser.
- Required action and evidence artifact.
- Supervising/enforcing institution.
- Complaint, appeal, liability, or remedy.
- Territorial reach and supply-chain effect.
- Effective/application date and transition.
- Known capacity or standardization dependency.
- Update mechanism.
Visual evidence plan
| Visual | Capture target | Teaching use | Guardrail |
|---|---|---|---|
| EU AI Act risk/timeline page | European Commission live framework page | Capture current application timeline and one high-risk duty list. | Date the screenshot; the timeline changed after adoption. |
| EU enforcement architecture | Commission enforcement page | Map AI Office, national authorities, complaints, and phased powers. | Official explanation is not an independent effectiveness assessment. |
| OECD principles | OECD AI Principles | Compare human-rights values with implementation recommendations. | Non-binding principles are not enforcement. |
| Council of Europe convention | official convention page | Capture principles, remedies, and risk/impact duties. | Signature, ratification, entry into force, and domestic effect differ. |
| UN resolution | UN meeting record | Highlight safe/secure/trustworthy AI and digital-divide commitments. | General Assembly resolution is not a treaty. |
| Canadian AIA | official tool page | Compare risk tier to required mitigation. | Scope is covered federal automated decisions. |
Reading and citation ledger
- European Commission, AI Act regulatory framework and live timeline.
- Regulation (EU) 2024/1689, official text.
- European Commission, AI Act enforcement framework.
- OECD AI Principles, updated 2024 and update explanation.
- Council of Europe Framework Convention on AI.
- UN General Assembly, March 2024 AI resolution meeting record.
- The White House, America's AI Action Plan (2025).
- Executive Order 14319 (2025).
- Canada, Directive on Automated Decision-Making and Algorithmic Impact Assessment.
- International AI Safety Report 2026.
Watch list
- Re-check every implementation date and legal-status statement before class.
- Distinguish proposal, political agreement, adopted text, entry into force, application, enforcement, and judicial interpretation.
- Ask whether standards and conformity-assessment infrastructure are available, not only whether a law names them.
- Include sector and subnational governance; omnibus AI laws are only part of the stack.