←
AI for Government
Strategic · M31 · lesson 31 of 47 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
International Government AI Collaboration
📖
now learning

International Government AI Collaboration

15 min

Sofia Castellanos spent three days at a multilateral AI governance forum in Brussels before she understood why she had been sent. She is the Director of AI Policy at a U.S. federal regulatory agency, and her agency head had told her to "represent the U.S. position on AI transparency standards." What that meant in practice was not obvious until the second day, when she watched the European delegation table a draft transparency standard that, if adopted as international guidance, would require disclosure of training data provenance in a format the procurement rules governing her agency's AI contracts did not currently require vendors to provide. If the standard passed as drafted, her agency's next major AI procurement, scheduled to go to market in eight months, would be compliant with U.S. law but out of alignment with international best practice as defined by a standard her own government had not shaped.

Sofia was in the room because her agency had an interest in that outcome. She had not known, until that moment, what the interest was or how to represent it. This lesson is about how to prepare for and operate effectively in international AI governance settings, and about why it matters for agencies that assume international standards are somebody else's problem. The material below covers bilateral programs, information sharing across classified and unclassified channels, multilateral coordination, and standards harmonization, which are the four channels through which international collaboration actually touches a domestic agency.

Why International AI Collaboration Reaches Domestic Agencies

International AI governance decisions affect domestic agencies through two channels, and the first one is direct. International standards that the U.S. government adopts or endorses become reference points for OMB guidance, for procurement requirements, and for Inspector General audit criteria. An agency whose AI systems were designed before an international standard was adopted may face significant compliance costs in its next procurement cycle, not because anyone changed the law but because the reference point moved underneath the acquisition. That cost lands on a program office that had no representation in the room where the reference point was set.

The second channel is indirect and reaches further. International regulatory frameworks, particularly the EU AI Act, which entered into force in 2024, shape the AI products that vendors sell globally, including to U.S. government buyers. A vendor who designs a product to satisfy EU transparency requirements may include features that U.S. agencies never asked for and may price the product accordingly. You end up paying for a foreign regulator's requirements whether or not you value them, which is an argument for understanding those requirements rather than discovering them in a bid.

Neither channel is a reason to resist international collaboration. Both are reasons to participate actively, so that U.S. government operational realities are understood and accommodated in international standards while those standards are still being drafted. Those realities are specific and they are not obvious to a foreign delegation: the constraints of the federal procurement system, the constitutional due process requirements that govern AI in public benefit administration, and the FOIA transparency obligations that apply to government AI systems. Nobody else in the room will raise them for you.

The Three U.S. Realities Nobody Else Will Raise

The three constraints named above are worth taking one at a time, because each of them can turn an internationally sensible provision into something a U.S. agency cannot execute. The first is the federal procurement system. International drafters frequently assume a government can simply require a thing of a supplier. A federal agency requires things through an acquisition vehicle, on a schedule, with evaluation criteria that have to be defensible against protest, and often against a solicitation that closed before the requirement existed. A provision that assumes continuous renegotiation with a vendor describes a relationship the federal acquisition system does not have.

The second is constitutional due process, which governs AI used in public benefit administration. When a government decision affects an entitlement, the person affected has process rights, and those rights shape what an AI system may do, what must be explained, and what a person may contest. This is not a transparency preference that can be traded against another design goal. Carry it into an international discussion as a fixed constraint on the U.S. side, and be precise about which decisions it attaches to rather than asserting it over the whole portfolio, because a claim that proves too much will be discounted.

The third is FOIA. Transparency obligations apply to government AI systems, which cuts in a direction international drafters rarely anticipate: material a private company would treat as confidential may be disclosable when a government agency holds it. That affects what a vendor is willing to hand over, what an agency can promise to protect, and what a partner government can expect to stay private in a joint program. Raise it early in any collaboration where a foreign partner assumes commercial confidentiality will hold.

How a Standard Becomes a Procurement Requirement

The chain from an international standard to a line in your solicitation is short and mostly invisible while it is happening. A standards body publishes guidance. The U.S. government endorses it, references it, or simply declines to object. It becomes a reference point in OMB guidance or in an agency framework. From there it appears in evaluation criteria, in contract terms, and eventually in the criteria an Inspector General uses to judge whether your program was well run. At no point in that chain does anyone notify the program office that a requirement is forming.

The consequence is that the cost of a provision is decided years before you feel it, and the cheapest moment to influence it is the moment when it is still a draft paragraph in a working group document. That is Sofia's whole point. By the time a provision reaches your solicitation it is a cost. While it is a draft it is a design question, and design questions accept input from people who can explain why the current wording will not work in a specific real system.

This is also why the audit end of the chain deserves attention. An IG or GAO reviewer asking whether your agency followed applicable frameworks is not going to distinguish carefully between a binding requirement and an endorsed reference point. Knowing which standards your agency's guidance actually points at, and how current those pointers are, is a cheap piece of housekeeping that prevents an expensive conversation later.

Bilateral Programs and the Instruments That Govern Them

Bilateral government AI programs, meaning partnerships between two countries' agencies on specific AI applications, are the most operationally concrete form of international collaboration. Several U.S. federal agencies have established them with peer agencies in allied countries on defined application domains: joint development of AI-assisted customs screening, shared training data for biosurveillance systems, and cooperative testing of AI tools for international disaster response coordination. These are working programs with deliverables, not communiques.

They are governed by Memoranda of Understanding or Executive Agreements that specify data sharing protocols, intellectual property arrangements, classification and security requirements, and the conditions under which information developed in the partnership can be disclosed publicly. That last clause is the one people skip and then regret. For classified or sensitive law enforcement applications, these agreements require extensive interagency coordination with State, Justice, and the intelligence community. For civilian applications such as disease surveillance, trade data analysis, or environmental monitoring, the agreements are more straightforward, though they still require legal review and in many cases OMB notification.

It is worth being precise about what an MOU does. It records what two agencies intend to do together and on what terms. It is not itself an authority to share data that you would otherwise lack, and it does not resolve the technical question of how conflicting requirements get handled in a live system. If your program plan says "the MOU covers it," identify which specific authority the MOU relies on and what happens at the point where two sets of requirements actually collide in code. That question has an owner. Make sure it is a named person and not the document.

For most civilian agency leaders, the relevant question is not whether to establish a new bilateral program, since those are typically initiated at the diplomatic level, but how to engage productively with existing structures when a specific operational need arises. The pathway runs through your agency's international affairs or policy office, which maintains relationships with State Department counterparts and can identify existing agreement frameworks that might already cover the collaboration you have in mind. Find that pathway now. Discovering it during a live request costs you the weeks you do not have.

Bilateral programs also run in both directions, which agencies new to them consistently underestimate. A partner who shares training data or evaluation results will expect comparable access in return, and the terms of that reciprocity are set in the instrument rather than negotiated later in good faith. Before you sign, work out what you will actually be able to provide once classification review, privacy review, and FOIA exposure have all been applied to it. An agreement that commits you to reciprocity you cannot deliver damages the relationship more than declining the collaboration would have.

Information Sharing and the Channels You Cannot Use

Information sharing is the quiet backbone of international AI collaboration, and it runs on two very different sets of rails. On the unclassified side, sharing happens through the bilateral instruments above, through multilateral working groups, and through the ordinary professional exchange of practice: published evaluation methods, shared test sets, incident write-ups, and model documentation. This is the material most civilian agency leaders can actually reach, and the constraint on it is usually legal review and classification review rather than access.

On the classified side sit the intelligence-sharing arrangements, of which Five Eyes coordination is the one most often named in AI governance discussions. AI coordination through those channels is real and it matters for defense, homeland security, and law enforcement missions. What it is not, for a civilian agency leader, is an access route. If a question you are working on appears to require information moving through a classified intelligence-sharing channel, the correct move is to route it through your agency's security office and international affairs office and let them determine what is possible, rather than to approach a counterpart directly and create a problem for both of you.

The practical discipline for a program office is to know, before you need it, which of your questions can be answered on the unclassified side. Most can. Evaluation methodology, bias testing approaches, procurement language, documentation formats, and incident patterns are almost always shareable, and they are usually the things you actually wanted. Treat the classified channel as the exception it is, and do not let its existence become a reason to stop asking questions you were entitled to ask anyway.

Multilateral Coordination: OECD, G7, and NATO

The major multilateral AI governance forums each operate at a different level of specificity and with a different membership and mandate, and confusing them wastes a lot of preparation time. The OECD AI Policy Observatory is the most relevant for civilian agency leaders. The OECD AI Principles, first adopted in 2019 and updated since, are the reference point for most allied government AI governance frameworks, and OECD working groups produce practitioner-level guidance on transparency, accountability, and public sector AI deployment. U.S. participation in OECD AI work is coordinated through the National Science and Technology Council and the relevant federal agencies, and civilian agency leaders with domain expertise can contribute through their agency's international affairs function.

The G7 Hiroshima AI Process, launched in 2023, produced the International Code of Conduct for Advanced AI Systems, a voluntary framework for frontier AI developers that has influenced vendor practice globally. For agencies, the Hiroshima Process is most useful as a signal of where allied governments are heading on AI safety and transparency norms. Reading the commitments in the Code tells you which vendor practices are likely to become standard offerings and which governance requirements may eventually harden into formal procurement conditions. It is a forecast you can act on before it becomes a requirement you must satisfy.

NATO's AI strategy, adopted in 2021 and updated at the 2024 Washington Summit, governs AI use in alliance defense and security applications. For defense and national security agencies the curriculum states this strictly: NATO AI governance is directly binding through alliance commitments. Confirm with your own counsel how that obligation attaches to your specific mission rather than reasoning from the general statement. For civilian agencies, the NATO framework is relevant primarily as a model for how a large multilateral organization governs AI in high-stakes operational contexts, which is a genuinely useful comparator when you are designing oversight for a consequential system.

A practical way to keep the three straight is to ask which question each one can answer for you. If the question is how a peer government handles a governance problem you also have, the OECD working group output is where the answer lives. If the question is what your vendors are about to start doing anyway, the G7 code is the forecast. If the question is what a joint operation with allies will require of a system, NATO is the authority and your counsel is the interpreter. Preparation aimed at the wrong body produces interventions that body cannot act on.

Standards Harmonization

The most concrete outcome of international government AI collaboration for domestic operations is standards harmonization: the process by which different national standards are aligned so that agencies and vendors operating across jurisdictions face less friction. Sofia's experience in Brussels illustrated both halves of it. A standard developed without adequate U.S. government input can create compliance requirements that U.S. procurement rules do not support. A standard developed with active U.S. participation can reflect U.S. operational realities and reduce future compliance costs. The difference is whether anyone showed up while the text was still movable.

The NIST AI Risk Management Framework was explicitly designed with international harmonization in mind. Its structure is compatible with ISO/IEC 42001, the AI management system standard, and with EU AI Act documentation requirements. Agencies that adopt the NIST framework as their primary governance approach are well positioned to demonstrate alignment with international standards, which is both a best-practice argument and a procurement argument, since vendors who can demonstrate NIST alignment can generally also demonstrate international alignment. The word doing the work there is demonstrate. A vendor's claim of alignment is a claim until you have read the artifact behind it and confirmed it covers the system you are buying rather than a sibling product.

Harmonization also has a limit worth naming. Frameworks converge on what to require and diverge on what evidence proves it. Two standards can both demand human oversight and disagree entirely about what documentation shows that oversight exists. When you write an RFP against a harmonized expectation, specify the artifact you want to receive, not just the property you want the system to have. Otherwise you will get a paragraph of assurance where you needed a record. The same discipline applies in reverse when you are the one being asked. A partner government that requests evidence of your human oversight is asking for an artifact, and the honest answer is either the artifact or an admission that the oversight exists as practice rather than as record. Agencies that keep those two states clearly separated in their own minds are the ones that stay credible across several frameworks at once.

Preparing for a Forum, Not Reacting Inside One

Sofia's first two days were wasted because she arrived with a mandate rather than a position. A mandate is a sentence from your agency head. A position is a statement of what your agency needs from the specific text on the table, grounded in something concrete you would otherwise have to pay for. The gap between the two is the entire difference between attending and participating, and it is closed before the flight, not during the coffee break.

The preparation that would have made her first two days useful is not elaborate. Read the drafts under discussion and identify which of your agency's systems or procurements the draft would touch. Work out, in specific terms, what each provision would require your agency to obtain from vendors and whether your existing acquisition vehicles can obtain it. Identify the one or two provisions where your agency's operational reality genuinely differs from the drafters' assumptions, because those are the only places your intervention will be both credible and necessary. Clear your position internally so that you are speaking for the agency rather than for yourself.

Then take the practical step of finding out who else in the room shares your problem. Standards work moves on coalitions, and the delegations from other federal systems of government frequently have the same procurement and due process constraints you do. A concern raised by one delegation is a national quirk. The same concern raised by three is a design flaw in the draft.

What Sofia Brought Home

Sofia's lesson from Brussels was specific rather than philosophical. She returned to her agency with a recommendation to add training data provenance documentation to the next AI procurement, eight months ahead of the international standard's likely adoption. The procurement team adopted the recommendation and the solicitation went to market with the requirement included. Two of the three finalists had already developed compliant documentation because of EU AI Act requirements, and the third was able to meet the standard within the evaluation timeline. What could have been a compliance gap became a procurement advantage.

Two things in that outcome are worth separating. The first is that anticipatory procurement worked: writing a likely future requirement into a live solicitation cost the agency nothing and saved it a retrofit. The second is a claim to make carefully. Requiring the artifact selected for vendors who could produce the artifact. That is correlated with operating at a higher standard and it is not the same thing, and an evaluation team should read the provenance documentation it receives rather than scoring the fact that it arrived.

From Trip Report to Live Change

The failure mode of international engagement is not that nobody goes. It is that the output of going is a trip report. A trip report circulates, gets read by four people, and changes nothing, because it describes what happened rather than what should now be different. Sofia's Brussels trip mattered because its output was a change to a solicitation that was still being drafted, owned by a procurement team that accepted it, on a schedule that made the change free.

The general form is worth stating. Before you travel, identify the specific decision inside your own agency that could plausibly change based on what you learn: a solicitation still in draft, an evaluation criterion not yet fixed, a system architecture decision still open. Name the person who owns that decision and tell them you will come back with something. That commitment does more to focus your reading of the drafts than any amount of general preparation, because it forces you to look for the provision that touches a live decision rather than the provision that is most interesting.

Afterwards, deliver into that decision first and write the trip report second. If nothing in your agency was going to change either way, that is worth knowing before you spend the travel budget, and it is an argument for sending someone from a program office with a live procurement rather than someone from a policy office with a general portfolio.

Anti-Patterns

  • Sending a delegate with a mandate instead of a position. "Represent the U.S. position on transparency" is not a position; it is a job title. A delegate who has not read the draft, has not traced its provisions to specific agency systems and procurements, and has not cleared a view internally will spend the session learning what the stakes were. By the time the stakes are clear, the text has usually moved on.
  • Assuming that domestic-only means internationally insulated. Agencies that never operate abroad still buy from global vendors and still answer to OMB guidance and IG audit criteria that reference international standards. The reach arrives through the acquisition, not through the mission. An agency that treats international standards as out of scope will meet them anyway, at the worst possible moment, which is after a solicitation has closed.
  • Treating a vendor's alignment claim as evidence of alignment. "NIST AI RMF aligned" and "EU AI Act ready" are marketing statements until someone reads the underlying artifact. Ask for the document by name, confirm it covers the exact configuration being offered rather than a sibling product, and have someone qualified read it. A claim you accepted without reading is a gap you have agreed to inherit.
  • Waiting for a standard to be adopted before writing it into a solicitation. The window where a requirement is cheap to add is before the RFP goes out, and the window where a standard is cheap to influence is while it is still a draft. Agencies that wait for formal adoption get both windows closed at once and then pay for a retrofit that anticipatory language would have avoided.
  • Treating an MOU as an authority. A Memorandum of Understanding records intent and terms between two agencies. It is not a substitute for the underlying legal authority to share the data, and it does not decide how conflicting technical requirements will be resolved in a working system. Name the authority the MOU relies on and name the person who owns the conflict, or you have documented an agreement to have a problem later.
  • Approaching a foreign counterpart directly on a sensitive question. The instinct to email the person you met at the forum is understandable and, on classification-sensitive or law enforcement matters, it creates a problem for both of you. Route through your international affairs and security offices. They exist partly to make the request possible and partly to make sure the request does not become an incident.

Practice Prompts

  1. Trace your pathway. Identify, by name and office, the person in your agency who handles international engagement on technology policy, and the State Department counterpart office they work with. Write down what you would have to provide them to get a specific question raised in an international forum. Do this before you have a question, because the answer takes longer to find than you expect.
  2. Read a draft against your portfolio. Take a current international AI standard or guidance document under development. For each substantive provision, identify which of your agency's AI systems it would touch, what it would require you to obtain from a vendor, and whether your existing acquisition vehicles can obtain it. Mark the provisions where your agency's operational reality differs from the drafters' assumptions.
  3. Write an anticipatory requirement. Choose one requirement you expect to become standard before your next major acquisition, such as training data provenance documentation. Draft the solicitation language that would obtain it, the evaluation criteria that would score it, and the response you would give a vendor who argues the requirement is premature.
  4. Audit an alignment claim. Take a vendor claim of alignment with a framework or standard in one of your current systems. Request the underlying artifact. Confirm whether it covers the configuration you actually operate. Write down what you learned about the distance between the claim and the document.
  5. Map a bilateral opportunity. Identify one operational problem your agency shares with a peer agency in an allied country. Determine whether an existing bilateral framework already covers collaboration in that domain, what instrument would govern it, what interagency coordination would be required, and what the disclosure terms would need to say.

Reflection

Take twenty minutes and answer these in writing. Which international standards or frameworks are currently referenced, directly or indirectly, in the guidance and audit criteria your agency answers to, and when did you last check? If a draft international standard were tabled tomorrow that touched your largest AI system, would anyone in your agency know in time to say anything about it, and through what channel? Which of your current vendor relationships rest on alignment claims that nobody has actually read the artifact behind? And if a peer agency in an allied country asked to collaborate on an AI problem you both have, do you know who in your agency would answer, and what they would need from you to say yes?

Glossary

  • Bilateral AI program. A partnership between two countries' agencies on a specific AI application domain, such as customs screening, biosurveillance, or disaster response coordination, with defined deliverables rather than general cooperation.
  • Memorandum of Understanding. An instrument recording what two agencies intend to do together and on what terms, covering data sharing protocols, intellectual property, classification and security requirements, and public disclosure conditions. It records terms; it is not itself an authority to share data.
  • Standards harmonization. The process by which different national standards are aligned to reduce friction for agencies and vendors operating across jurisdictions. Frameworks converge on requirements faster than they converge on what evidence satisfies them.
  • OECD AI Policy Observatory. The OECD body whose working groups produce practitioner-level guidance on AI transparency, accountability, and public sector deployment, and the most directly usable multilateral resource for civilian agency leaders.
  • International Code of Conduct for Advanced AI Systems. The voluntary framework for frontier AI developers produced by the G7 Hiroshima AI Process, useful to agencies as a signal of which vendor practices are becoming standard.
  • Training data provenance documentation. Records describing where a model's training data came from and under what terms, increasingly requested by international transparency standards and obtainable as a procurement deliverable.
  • Anticipatory procurement. Writing a requirement into a live solicitation ahead of a standard's formal adoption, so that the cost of meeting it is absorbed at acquisition rather than paid later as a retrofit.

Closing

International government AI collaboration looks, from inside a domestic agency, like an activity for other people. It is not. The standards set in those rooms become the reference points in the guidance you answer to and the audit criteria you are measured against, and the products your vendors build are shaped by regulators you will never meet. The question is never whether international decisions will reach your procurement. It is whether they reach it as a requirement you helped shape or as a gap you discover after the solicitation closes.

Sofia's three days in Brussels turned a mandate into a working method: know your agency's operational stakes in the text under discussion before the session, find the delegations that share your constraint, and turn what you learn into a concrete change in a live procurement rather than a trip report. None of that required a diplomatic career. It required reading the draft against her own portfolio and being willing to say, in a room full of people who had not thought about it, what the U.S. federal procurement system can and cannot actually deliver.

Key Takeaways

  • International standards affect domestic procurement with or without your participation. They arrive through OMB guidance, IG audit criteria, and the products global vendors build. Agencies that shape a standard in draft face fewer retrofit costs than agencies that meet it after a solicitation has closed.
  • Know your agency's international affairs pathway before you need it. The route to bilateral and multilateral engagement runs through your international affairs or policy office and its State Department counterparts. Finding that pathway during a live request costs you weeks you will not have.
  • The OECD AI Policy Observatory is the most usable multilateral resource for civilian agencies. Its working group outputs are practitioner-level guidance, and U.S. participation is coordinated through the National Science and Technology Council, with individual agency experts contributing through that channel.
  • Read the Hiroshima Code of Conduct as a vendor practice forecast. The G7 voluntary commitments shape what leading AI vendors do globally, which tells you which features and artifacts will become standard offerings and which may harden into procurement conditions.
  • An MOU records terms; it is not an authority and it does not resolve technical conflicts. Name the underlying legal authority and name the person who owns the point where two sets of requirements collide in a working system.
  • Use the NIST AI RMF as a harmonization foundation, and still read the artifact. Its structure is compatible with ISO/IEC 42001 and EU AI Act documentation requirements, so it positions an agency to demonstrate alignment. A vendor's claim of alignment remains a claim until someone reads the document behind it.
  • Prepare before the forum, not inside it. The draft stage is when influence is available. Arriving with a mandate rather than a position means arriving without influence, and a concern raised by three delegations carries weight that the same concern from one does not.
  • Anticipatory procurement beats retrofit. Adding a likely future requirement to a solicitation ahead of formal adoption costs little and avoids a rebuild. Just remember that it selects for vendors who can produce the artifact, which is not identical to vendors operating at a higher standard, so read what arrives.

Frequently Asked Questions

My agency has no international mission. Why is this my problem? Because the reach arrives through your acquisitions and your oversight, not through your mission. Global vendors build to the strictest market they serve, so their products carry foreign requirements and foreign pricing into your solicitation. Meanwhile, standards the U.S. endorses become reference points in OMB guidance and IG audit criteria. You will meet these standards either as a requirement you anticipated or as a finding you did not.

How do I actually get involved in an international standards process? Through your agency's international affairs or policy office, which holds the State Department relationships and knows which delegations and working groups your agency can join. For OECD AI work specifically, U.S. participation is coordinated through the National Science and Technology Council and the relevant agencies. Individual domain experts contribute through that channel rather than by applying directly, so the first call is internal.

What is the difference between the OECD, G7, and NATO tracks? Level and mandate. The OECD produces practitioner-level guidance and principles that most allied frameworks reference. The G7 Hiroshima process produced a voluntary code of conduct aimed at frontier AI developers rather than at governments. NATO governs alliance defense and security applications, and for those agencies the curriculum states it as directly binding through alliance commitments. Preparing for one forum as though it were another wastes the preparation and produces interventions the body cannot act on.

Can I just email the counterpart I met at the forum? On general practice questions, usually yes, and that professional exchange is one of the most valuable things a forum produces. On anything touching classification, law enforcement sensitivity, or a live negotiation, route it through your international affairs and security offices instead. A direct approach on a sensitive matter creates a problem for your counterpart as well as for you.

What does Five Eyes coordination mean for a civilian agency leader? In practice, that it is not your channel. AI coordination through classified intelligence-sharing arrangements is real and it matters for defense, homeland security, and law enforcement missions, but it is not an access route for a civilian program office. If your question appears to need it, hand the question to your security and international affairs offices and let them determine what is possible. Most of what you actually wanted, meaning evaluation methods, documentation formats, and incident patterns, is available on the unclassified side.

Should I write a not-yet-adopted standard into an RFP? Often yes, and Sofia's case is the argument for it: a provenance documentation requirement added eight months ahead of adoption cost nothing and turned a future gap into a present advantage. Two cautions. Write it as a deliverable you will read rather than a box a vendor checks, and be prepared to explain to a bidder why a draft standard is a reasonable basis for a requirement, which is easier when you can point to the specific operational reason you want the artifact.