Logo

Rules Written Elsewhere

Rules Written Elsewhere

AI regulation is arriving, and most of the world will comply with rules it had no part in making

For most of the past decade, the debate about artificial intelligence governance was speculative. It concerned what rules ought to exist. That phase is ending. Binding regulation now exists, with defined obligations, compliance timelines, and penalties, and organisations everywhere are working out what it requires of them.

The most developed of these frameworks takes a risk-based approach, which is sensible. It sorts systems into tiers. Some practices are prohibited outright. High-risk systems, meaning those affecting employment, education, credit, essential services, law enforcement and migration, carry substantial obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity standards. Systems that interact with people carry transparency duties. Everything else is largely unregulated.

Tiering is the right instinct, for reasons worth stating plainly. Regulating a scheduling assistant with the same rigour as a system that screens asylum applications would be neither safer nor fairer. It would consume the regulatory attention that the asylum system needs, and it would teach every organisation that compliance is theatre. Proportionate scrutiny is not a concession to industry. It is what makes serious scrutiny possible.

But the arrival of binding rules raises a question that the frameworks themselves cannot address, and it is the more important one for most of the world.

Whose Rules

Regulation written in one jurisdiction does not stay there.

When a large market sets requirements, global firms tend to build to those requirements everywhere rather than maintain separate product lines. The standard becomes the default well beyond the territory that enacted it. This has happened before with data protection, chemical safety, and vehicle emissions, and it is now happening with AI.

There is something genuinely good in this. A country without regulatory capacity of its own may find its citizens protected by standards it could never have enforced. Protection arriving from elsewhere is still protection.

But it should be named accurately. Millions of people in Africa, Asia and Latin America will be governed in their dealings with AI systems by rules drafted in a legislature they did not elect, weighing risks as they appear from a particular vantage, reflecting a particular set of institutions and priorities.

This is not a complaint about bad faith. The drafters were legislating for their own citizens, which is what legislatures do. But the effect is that a great many people are governed without representation, and calling that outcome protection without also calling it asymmetry is incomplete.

What Rules Written Elsewhere Miss

Regulation reflects the conditions its authors know. Applied at a distance, gaps appear.

Language. Requirements for accuracy and non-discrimination are typically enforced against evidence available to the regulator. A model that performs adequately in widely-spoken languages and poorly in Yoruba, Igbo, Amharic or Tagalog may satisfy its obligations while failing millions of speakers, because nobody in the compliance process is measuring that.

Infrastructure. Rules assume human oversight is available, that logs can be retained, that audits can be commissioned. These assume institutional capacity and reliable connectivity. Where those are absent, obligations become paper compliance rather than real protection.

Risk profile. Which systems count as high-risk reflects a judgement about where harm concentrates. That judgement is context-dependent. In a country where electoral integrity is fragile, systems affecting voter registration or results transmission may be the highest risk of all. In a country where land tenure is contested, automated land registry decisions carry weight they do not carry elsewhere. These may not appear in a framework drafted in a different context.

Enforcement. A regulation without an enforcer is a statement of preference. Countries adopting frameworks by borrowing may find they have imported obligations without the supervisory bodies, technical expertise, and legal authority that make the obligations real.

The Alternative Is Not Isolation

The temptation, faced with rules made elsewhere, is to reject them and write something entirely local. That instinct is understandable and mostly counterproductive.

A country with a market too small to compel compliance will find its distinctive rules ignored by global providers. Fragmentation produces regulatory divergence without regulatory power, and the harms cross borders regardless.

The better path is the one subsidiarity actually describes. Adopt shared standards where the problem is genuinely global and the standard is sound, because there is no advantage in inventing a different definition of technical documentation. Then legislate specifically where local conditions differ: language performance requirements, sectors that are locally high-risk, data protection calibrated to local vulnerabilities, and enforcement bodies with real authority.

And participate in the drafting of the next generation of standards, which is where the leverage actually is. Standards bodies, international organisations, and model legislation projects are where the defaults for the coming decade are being set. Presence there is worth more than a domestic statute nobody complies with.

What Compliance Cannot Do

There is a further point that applies everywhere, in drafting jurisdictions as much as borrowing ones.

Compliance is not ethics. A framework defines a floor, and the floor is drawn by what could be agreed politically and enforced practically. It is not drawn by what human dignity requires.

A system can satisfy every documented obligation and still be deployed where it should not exist. It can pass every fairness audit while automating a decision that ought to involve a person. It can meet transparency requirements with documentation no affected citizen could understand. Compliance answers “is this permitted”, which is a different question from “is this right”.

This matters particularly because compliance regimes create their own gravity. Organisations with a checklist begin to treat the checklist as the whole of their obligation, and the questions not on it stop being asked. The most important question about any system, whether it should exist at all, appears on no compliance framework anywhere.

For the Church and Civil Society

Faith communities and civil society organisations have a specific contribution here, and it is not technical.

They can insist on the questions the framework does not ask. They can bring evidence of harms that regulators do not see, because they are present in communities that regulators are not. They can hold that a legal floor is not a ceiling, and that satisfying it is the beginning of responsibility rather than its discharge.

And they can advocate for the people who will be governed by these rules without ever having been consulted about them. That is a familiar role for the Church, and it applies as naturally to algorithmic governance as it has to trade, debt and labour.

The rules are here. Whether they protect the people furthest from where they were written depends on work that regulation itself cannot do.

If you'd like to stay up to date, .

Share:
Get Involved With Yes Catholic Hangout Today!
FooterBG
ABOUT

A Catholic mission promoting the ethical use of Artificial Intelligence and building digital solutions rooted in faith, human dignity, and the Social Doctrine of the Church.

ADDRESS:

54 Asa Road, CKC Aba, Abia State, Nigeria

101-1559 Brunswick St Halifax, Canada

Privacy Policy

copyright @ 2026 Yes Catholic Hangout. All rights reserved.