←
AI for Government
Visionary · M26 · lesson 26 of 46 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
International AI Diplomacy
📖
now learning

International AI Diplomacy

15 min

Ambassador Lena Okafor had negotiated trade pacts, climate accords, and a fisheries treaty that took four years to land. Now, as her nation's first envoy for digital and AI affairs, she sat in a Geneva conference room facing a problem unlike any of those. Three blocs were drafting AI rules at once: the European Union pushing a binding, risk-tiered law; a coalition of nations advancing voluntary principles through an economic-cooperation forum; and a fast-moving group writing technical standards almost no diplomat in the room understood. Her instructions from the capital were one sentence: "Protect our companies' access to global markets and our citizens' rights, and don't let anyone else write the rules we'll have to live under."

Lena understood the trap immediately. If her country waited for clarity, the rules would be set without it. If it moved too fast and picked the wrong forum, it would spend years bound to a framework that did not fit. AI diplomacy, she realized, was not about technology. It was about deciding, under deep uncertainty, where to spend a nation's limited influence. This lesson is for agency heads and national AI leaders who shape how their country engages the world on artificial intelligence. We follow Lena's mandate through the four arenas of AI diplomacy, the instruments that actually bind, and the framework she used to choose where to invest scarce diplomatic capital.

Why AI Resists the Old Diplomatic Tools

Lena's instinct was to seek a treaty, a binding agreement among nations, because that was her trade. But AI fights the treaty model in three specific ways. Treaties take years to negotiate and ratify, while AI capability moves in months. Treaties need precise, stable definitions, and AI's very definition keeps shifting, which is why so much diplomatic energy has gone into agreeing what an AI system even is. And treaties assume nations can verify compliance. Verifying what is inside another country's models is far harder than counting missiles or inspecting a factory floor.

So governance has fragmented across many venues moving at different speeds. The binding law, the voluntary principles, and the technical standards in Lena's room were not redundant. They were three different tools for three different problems, and a smart diplomat engages each on its own terms rather than waiting for one grand bargain that will never come. The discipline is to stop asking which forum will settle the question and start asking which forum settles which part of it.

The other lesson from Lena's first month was that soft law is not the same as no law. A non-binding principle that major economies adopt will show up later inside a binding domestic regulation, a procurement clause, or a certification requirement your companies cannot avoid. Treating a voluntary instrument as optional because it carries no penalty is how a country ends up implementing text it never helped write.

The Four Arenas of AI Diplomacy

1. Standards bodies: where the practical rules get written

Lena's most counterintuitive lesson was that the most consequential AI rules are often written not by diplomats but by engineers in technical standards organizations. A standard is a detailed technical specification, covering how AI systems should be tested, documented, and managed, that becomes the practical definition of acceptable. Companies build to standards to sell across borders, so the country that shapes the standard shapes the global market. Lena reallocated staff to send technical experts, not only diplomats, into these rooms, because absence there meant living under rules others designed.

2. Treaties and binding agreements

Binding instruments still matter for the highest-stakes issues, such as military applications and frontier-model safety, where nations want enforceable commitments. But Lena treated these as slow, narrow tools for narrow problems rather than the main event. The realistic ask is often a framework convention setting broad principles, with details filled in later, rather than a comprehensive code negotiated up front. It is also worth remembering that signature is not ratification, and ratification is not domestic implementation, so a treaty's presence on a list tells you less than officials often assume.

3. Multilateral coordination: aligning without binding

Between non-binding talk and binding law sits coordination, in which nations voluntarily align their approaches so their rules interoperate. This is where forums advancing shared AI principles do their work. The payoff is interoperability: if your country's rules are broadly compatible with those of key partners, your companies and citizens move more freely. Lena's pragmatic goal was not identical rules everywhere, but rules different enough to reflect national values and similar enough to avoid a fractured world in which every market demands its own proof.

4. Digital sovereignty: the line you will not cross

Digital sovereignty is a nation's claim to control its own data, infrastructure, and AI within its borders. It is the counterweight to global harmonization, and it has a hard technical edge: sovereignty claims are only as strong as a country's access to compute, models, and the supply chain beneath them. Lena had to define, before negotiating, where her country insisted on control, meaning sensitive citizen data and critical infrastructure, and where it would accept common global rules for the sake of market access.

The Standards Landscape Lena Had Been Ignoring

When Lena finally sent an engineer to sit in the technical committees, the reporting cable that came back was a shock to her ministry. The joint technical committee subcommittee responsible for artificial intelligence, established in 2017, had already published a substantial body of AI standards with many more in draft, and its output was being written straight into national regulations and procurement documents. None of her diplomats had ever read one. The standards were not abstractions. They were the instruments through which every principle her ambassadors argued about would eventually be tested.

InstrumentWhat it coversDiplomatic significance
ISO/IEC 42001AI management systems, modeled on the information-security management standardThe first certifiable AI management standard, so it becomes a procurement and market-access requirement
ISO/IEC 23894AI risk management guidanceSupplies the shared vocabulary regulators reach for when they define risk
ISO/IEC 5338AI system life cycle processesDetermines what counts as a documented, governed development process
ISO/IEC 24029Robustness of neural networksTurns contested assurance arguments into testable properties
IEEE 7000 seriesEthical and value-based design processesProvides an alternative route by which ethics language enters engineering practice

The bridge between these standards and government frameworks is the crosswalk. The United States National Institute of Standards and Technology publishes crosswalks between its AI Risk Management Framework and these international standards, mapping its own subcategories onto their control sets. That document is a diplomatic artifact disguised as a spreadsheet. It is how a voluntary national framework acquires international currency, and how a country that never joins a treaty can still shape what compliance looks like everywhere.

What Actually Binds, and What Only Declares

Lena's staff built her a single page separating instruments that create obligations from instruments that create expectations. The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, catalogued as CETS 225, opened for signature in 2024 and is described as the first legally binding international treaty on AI; early signatories included the United States, the United Kingdom, the European Union, and Israel. Its commitments run to human oversight, remedies, and non-discrimination. Signature alone does not make those commitments enforceable at home, so confirm the ratification and implementation status of any party before you rely on it.

The declaratory instruments are a different species and should be read differently. The Bletchley Declaration of 2023 committed a broad group of governments, including the United States, the United Kingdom, China, India, and the European Union, to cooperate on frontier AI safety. A 2024 summit in Seoul broadened that commitment, and a further summit in Paris in 2025 continued the sequence. The UNESCO Recommendation on the Ethics of AI sets out ethical expectations without enforcement machinery. The G7 Hiroshima process produced International Guiding Principles and a Code of Conduct for organizations developing advanced AI systems, which leading developers have said they are implementing voluntarily.

Two coordinating institutions sit underneath all of this. An economic-cooperation observatory maintains the definition of an AI system that most governments now use, an updated text that replaced the 2019 original and has been absorbed into both American implementation guidance and the European Union's legislative text. Separately, a global partnership on AI launched in 2020 by French and Canadian initiative ran expert working groups on responsible AI, data governance, the future of work, and commercialization, and was later brought together with the economic-cooperation organization's AI program to stop the two forums duplicating each other.

Governments also stood up national bodies to evaluate frontier models and, in 2024, convened them as an international network through a meeting in San Francisco. Several of those bodies have since been renamed or restructured, so state the network historically and confirm the current name, mandate, and host ministry of any such body before naming it in a cable or a briefing. The mechanism matters more than the masthead: what those bodies established was a route for pre-deployment evaluation results to move between governments.

Four Regulatory Philosophies and Where They Can Meet

A diplomat cannot negotiate interoperability without a working map of what the other side is actually building. Lena's team reduced the major approaches to four, and the point of the exercise was not to rank them but to find the seams where alignment is plausible. The seams are real: risk tiering, documentation, and incident reporting recur in every approach, even where the underlying legal theory differs completely.

JurisdictionAnchor instrumentsCharacter
United StatesOMB Memorandum M-24-10; the NIST AI Risk Management Framework; the Blueprint for an AI Bill of Rights; Executive Order 14110, stated historicallyAgency guidance plus a voluntary framework; the Blueprint is a non-binding White House document, never a statute
European UnionThe EU AI ActA single binding law organized around risk tiers, with registration duties for high-risk systems
United KingdomA pro-innovation white paper directing existing regulatorsSector regulators applying cross-cutting principles rather than one new AI statute
People's Republic of ChinaInterim Measures for the Management of Generative AI ServicesService-specific administrative measures with filing and content obligations

The European Union's Act sorts systems into four bands: unacceptable, high, limited, and minimal. That fourth band matters diplomatically, because the Act is often summarized elsewhere as having three tiers, and negotiators then discover that the prohibited category is where the sharpest disagreements actually live. American agency guidance instead flags systems as rights-impacting or safety-impacting. The two schemes overlap substantially without matching, which is the ordinary condition of AI diplomacy and the reason crosswalks exist at all.

This lesson deliberately stays at the diplomatic altitude. For the detailed anatomy of the European Union's risk tiers and the economic-cooperation principles, work through International Standards: EU AI Act and OECD, which is the deepest treatment of those two instruments in this program.

The Crosswalk Problem: Document Once, Present Twice

The most common practical request Lena received from her own ministries was not for a treaty. It was for relief from doing the same compliance work twice. When the European Union's Act entered into force in 2024, agencies procuring European or dual-listed systems faced a puzzle. The Act's risk management article, its data governance article, and its transparency article each have a recognizable counterpart in the map, measure, manage, and govern functions of the American risk framework, and a joint transatlantic body published a roadmap on evaluation and measurement tools and a shared terminology document to make the correspondence explicit.

The temptation is to conclude that a well-built artifact can be produced once and presented twice. Treat that as an efficiency, not a discharge. Overlapping structure reduces duplicated effort; it does not mean a single model card, risk register, or incident report satisfies two regimes at once. Each regime has its own scope, its own evidentiary standard, its own competent authority, and its own view of what counts as a deficiency. The practical target is a documentation set with one shared core and thin jurisdiction-specific layers, maintained by someone who reads both texts and can say precisely where they diverge.

The Hard Power Arena: Compute, Chokepoints, and Dependency

Halfway through her first year Lena stopped thinking of export controls as somebody else's file. Trade and technology ministries had become the loudest actors in AI diplomacy, and the instruments were technical. The United States restricted exports of advanced semiconductors and manufacturing equipment to China in a 2022 rule; when chip designers responded with variants engineered to sit just below the stated thresholds, a 2023 rule closed that gap. A further 2025 framework recast the regime around country tiers governing access to compute. Treat that country-tier framework historically and confirm its current status before relying on it, because compute controls are revised often and allied reaction to them is a live negotiation.

The diplomatic consequences of these technical measures were immediate. Partners hosting critical steps in the supply chain, including the fabrication, foundry, and lithography firms concentrated in a handful of jurisdictions, had to negotiate their own export regimes to match. Alongside export controls under the commerce regulations, governments use investment screening for inbound transactions, an outbound investment screening program established by executive order and stated here historically, entity listing and sanctions, participation in the Wassenaar Arrangement, and a published list of critical and emerging technologies that signals what a government intends to protect next.

Dependency is the flip side of the same coin, and it is what turns sovereignty from rhetoric into arithmetic. A country that cannot access frontier compute, cannot host its own inference, and has no domestic capability to train models is making sovereignty claims it cannot enforce. That is why national and regional efforts to build sovereign language models, cloud data residency requirements, and sovereign cloud initiatives have become diplomatic instruments in their own right. Lena's ministry began treating compute access as a trade file, an industrial file, and a security file simultaneously, because it was all three.

The security file extends further still. Dual-use questions place AI alongside existing arms-control machinery, including the Biological Weapons Convention and the long-running discussions on autonomous weapons under the conventional weapons convention. These forums move slowly and are easy for a small ministry to skip. Skipping them means the definitions that will eventually govern military AI are written without you.

A Diplomatic Engagement Prioritization Framework

Lena built a simple framework to decide where to spend her country's limited influence. For any AI governance venue or initiative, score it across these dimensions; the pattern shows where to lead, where to participate, and where to merely monitor.

  1. National interest at stake. Does this venue affect our companies' market access, our citizens' rights, or our security? High stakes justify leadership.
  2. Influence available. Can we realistically shape the outcome through expertise, alliances, or market weight, or can we only react to it?
  3. Speed and bindingness. Is this fast voluntary coordination or slow binding law? Match your effort to the nature of the tool.
  4. Who else is in the room. Are key partners and rivals shaping this? Absence cedes the rules to others.
  5. Sovereignty line. Does this touch areas where we insist on national control? Flag non-negotiables before negotiating, not during.
  6. Interoperability payoff. Will alignment here let our people and firms operate more freely abroad?
  7. Resource cost. Does engagement require diplomats, technical experts, or both, and do we have them to spare for the duration?

The output is a portfolio: a few venues to lead, several to actively participate in, and many to monitor. No nation can lead everywhere, and the discipline is choosing. Rescore the portfolio on a fixed cycle, because a venue that mattered little when it was drafting a glossary matters enormously once it starts drafting conformity criteria.

A Two-Year Engagement Plan for an Agency

Diplomacy fails when it stays with the principals. The plan below is written for a mid-sized department rather than a foreign ministry, because that is where the obligations eventually land, and it follows the sequence a program manager can actually staff.

  1. Months 1 to 3. Stand up an international AI coordination cell reporting to the chief AI officer your agency is already required to designate.
  2. Months 4 to 6. Inventory your current international exposure and identify three priority forums, using the prioritization framework above rather than existing travel habits.
  3. Months 7 to 12. Dispatch representatives and co-author at least one technical document per forum. Co-authorship, not attendance, is what buys influence.
  4. Months 13 to 18. Align internal compliance to the standards you are helping to shape, and adopt an AI management system standard in at least one program.
  5. Months 19 to 24. Review what the engagement bought, renew what worked, and drop what did not.

Three rhythms run underneath the whole plan. Brief your agency head quarterly so that international work stays visible at the level where budgets are set. Coordinate monthly with the foreign, security, science, and budget offices that hold the other half of the file. Track the trade, sanctions, and investment-screening actions published in your official register weekly, because those are the instruments most likely to change your obligations without warning.

Why This Matters for National Leaders

For most countries, the rules of the global AI order are being set right now, and largely without them. The default outcome of disengagement is not neutrality; it is living under frameworks written by larger powers and then scrambling to comply. This is no longer a foreign-ministry specialty. An agency that procures or fields AI inherits obligations negotiated in rooms it has never entered, and it will be told to adopt them eventually whether or not it helped shape them. Engaging early is how a government gets to shape the vocabulary rather than translate it.

Lena did not chase a grand treaty. She built a portfolio. Her country led in two standards working groups where it had genuine expertise, joined the multilateral principles forum to keep its rules interoperable, defined three sovereignty red lines it would not trade, and monitored the binding-law negotiations without overcommitting. A year later the global rules were still forming, but her country's fingerprints were on the parts that mattered most to it. AI diplomacy rewards the leader who decides early where to spend influence, not the one who waits for the dust to settle.

Anti-Patterns to Avoid

  • Diplomacy as a principals-only activity. Sending ambassadors to plenaries while the technical committees write the operative text. The plenary produces the communique; the working group produces the requirement your exporters will have to meet. Staff the working group.
  • Conflating soft law with no law. Dismissing a voluntary principle because it carries no penalty, then meeting the same text later inside a binding regulation or a procurement clause. Read voluntary instruments as drafts of future obligations.
  • Assuming English-language dominance means concept dominance. The negotiating language is not the conceptual frame. Terms such as risk, oversight, and remedy carry different legal weight in different systems, and a translated agreement can hide a substantive disagreement for years.
  • Document once, present twice as a compliance claim. Treating one artifact as satisfying two regimes because their structures overlap. Shared structure saves effort; it does not transfer legal sufficiency from one authority to another.
  • Stovepiping diplomacy from domestic policy. Negotiating international commitments that nobody in the implementing agencies has read, or writing domestic rules that ignore what your own negotiators just signed.
  • Ignoring standards because the national metrology institute will handle it. Standards participation is a resourcing decision made by ministries, and the technical body can only carry the positions somebody gave it.
  • Forgetting the export-control dimension of cloud compute. Treating access to remote compute as a procurement question when it is increasingly a controlled-technology question.

Practice Prompts

  1. List every international AI forum, standards committee, and bilateral dialogue your government currently attends. For each, name the official who attends, the document they last co-authored, and what your country asked for. Any entry where the last two columns are empty is monitoring dressed up as participation.
  2. Score your three most important venues against the seven dimensions of the prioritization framework. Where the scores disagree with your current travel budget, write one paragraph explaining which one is wrong.
  3. Draft your country's sovereignty red lines in a single page. For each line, state what you would refuse even at the cost of market access, and have a trade official and a rights regulator both sign it before any negotiation.
  4. Take one AI system your agency operates and map its documentation against two jurisdictions' requirements. Identify the shared core and the jurisdiction-specific layers, and name the person who owns the divergences.
  5. Write the two-year engagement plan for your own agency using the phased structure above. Name the coordination cell's reporting line, the three priority forums, and the standard you would adopt in a live program.

Reflection

  • Which international AI rules is your government already living under without having helped write them, and how did that happen?
  • If your ministry had to choose between leading in one standards committee and observing in many forums, which would serve your citizens better, and can you defend that answer to a legislature?
  • Where does your country's stated commitment to a declaration diverge from what its domestic law actually requires, and who is responsible for closing that gap?
  • How dependent is your national AI strategy on compute, models, or supply-chain access that another government controls, and what would you do if that access changed?
  • Who in your government reads the technical standards, and what happens to their findings?

Glossary

  • Framework convention. A treaty that sets broad principles and institutional machinery, leaving detailed obligations to later protocols or domestic implementation.
  • Soft law. Declarations, principles, codes of conduct, and recommendations that create expectations rather than enforceable obligations, and that frequently harden into binding rules later.
  • Standard. A published technical specification for how something should be built, tested, documented, or managed, developed by a standards body and often referenced by regulation or procurement.
  • Crosswalk. A published mapping between two governance frameworks showing which provisions of one correspond to which provisions of the other.
  • Interoperability. The condition in which two jurisdictions' rules are compatible enough that a system compliant in one can be brought into compliance in the other without being rebuilt.
  • Digital sovereignty. A nation's claim to control the data, infrastructure, models, and compute operating within its borders.
  • Dual-use technology. Technology with both civilian and military applications, which is why AI capability falls within existing export-control and arms-control machinery.
  • Investment screening. Government review of inbound or outbound investment transactions for national security effects, used alongside export controls to manage technology transfer.
  • Conformity assessment. The testing, documentation, and certification process by which a system is shown to meet a standard or a regulatory requirement.

Closing

The hardest thing about AI diplomacy is that there is no moment when the rules are finished and you can read them. There are only rules in formation, in many rooms, at many speeds, and a finite number of officials you can put in those rooms. Lena's contribution was not a signature on a document. It was a decision rule her successors could apply after she left: know what you will not trade, go where you can actually shape the text, co-author rather than attend, and rescore the portfolio before the drafting turns technical. That is what a small country's influence looks like when it is spent well.

Key Takeaways

  • AI resists the treaty model. It moves too fast, defies stable definitions, and is hard to verify, so governance fragments across many venues moving at different speeds.
  • Standards bodies write the practical rules. Technical specifications on management systems, risk, life cycle, and robustness quietly define what is acceptable worldwide; send experts there, not just diplomats.
  • Soft law is not no law. Voluntary principles and codes of conduct reappear as binding regulation and procurement conditions, so engage them as drafts of future obligations.
  • Know what actually binds. A framework convention creates obligations only through ratification and domestic implementation; a declaration creates expectations. Check the status before you rely on either.
  • Crosswalks are efficiency, not discharge. Overlapping structure between regimes reduces duplicated work but never makes one artifact legally sufficient for two authorities.
  • Compute is a diplomatic instrument. Export controls, investment screening, and supply-chain chokepoints now decide how much sovereignty a country can actually exercise.
  • Build a portfolio of influence. Lead in a few venues, participate in several, monitor the rest, and rescore on a cycle; no nation can lead everywhere, so choosing is the job.
  • Absence cedes the rules to others. Disengagement is not neutrality; it means living under frameworks larger powers designed and being told to adopt them anyway.

Frequently Asked Questions

Is there a single international AI treaty we should be focused on?

No, and organizing your strategy around one would be a mistake. The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the instrument usually described as the first legally binding international AI treaty, but its obligations reach your agencies only through ratification and domestic implementation, and it sits alongside declarations, codes of conduct, technical standards, and export-control rules that will affect your operations sooner. Map all of those categories before deciding where to spend effort.

Our ministry has almost no staff for this. Where do we start?

Start with the sovereignty red lines, because they cost nothing to write and they determine every later negotiation. Then score venues against the prioritization framework and pick one committee to lead in, chosen for genuine national expertise rather than prestige. One committee where you co-author text buys more influence than several where you take notes. Everything else moves to monitoring, and monitoring means one person reading published outputs on a schedule.

Why do technical standards matter more than the principles our ministers sign?

Because principles are implemented through standards. A principle such as human oversight becomes real only when a specification says what oversight evidence looks like, who must retain it, and how a conformity assessor tests it. Whoever writes that specification decides what the principle means in practice. This is also why the crosswalks between national frameworks and international standards are worth reading closely: they are where abstract commitments acquire enforceable shape.

How do we handle bodies that keep getting renamed or restructured?

State them historically and describe the mechanism rather than the masthead. Several national AI evaluation bodies established in 2023 and 2024 have since been renamed or reorganized, and citing a body that no longer exists under that name undermines an otherwise sound brief. Confirm the current name, mandate, and host ministry before any citation, and write the underlying function into your documents so the text survives the next reorganization.

Does aligning with another jurisdiction's rules mean surrendering sovereignty?

Not if you define the trade in advance. Coordination is a bargain: you accept some constraint on your rules in exchange for market access and interoperability for your citizens and firms. Sovereignty is surrendered only when you have not decided beforehand which protections are non-negotiable and therefore concede them one at a time under time pressure. Write the red lines first and the negotiation becomes a trade rather than a slide.

What is the single most common failure in AI diplomacy?

Attendance mistaken for influence. Delegations attend plenaries, file reports, and record engagement, while the operative text is drafted in working groups they never joined. The measurable test is co-authorship: name the documents your government helped write in the past year. If the list is empty, you are a spectator in rooms where your obligations are being decided, however many flights your officials took.