International Governance Coordination
Hassan Mehta chaired his nation's AI regulatory authority, and he had just finished a framework he was proud of: clear risk tiers, mandatory testing for high-risk systems, real enforcement teeth. Then a domestic medical-AI company asked to meet. They had built a diagnostic tool that passed his country's certification. To sell it in the European market they had to certify again, under different rules, at a cost of eighteen months and several million in duplicate testing. To sell it in a third country, a third certification. The founder put it bluntly: "Your rules are good. So are theirs. But there are five sets of good rules, and we can only afford to comply with two. So we're choosing the biggest markets and skipping yours."
Hassan had built excellent national governance and accidentally walled his own companies out of the world. The problem was not the quality of any one country's rules. It was that none of them talked to each other. This lesson is for national AI leaders and senior officials who design governance that must coexist with other nations' rules. We follow Hassan's diagnostic-tool problem through the core challenge of harmonization and its practical tools, mutual recognition, standards diplomacy, and the management of trade consequences, so you can build governance that protects citizens without isolating your economy.
The Coordination Problem: Good Rules That Do Not Interoperate
Every serious government wants AI rules that protect its citizens. The trouble is that each builds them in isolation, with different definitions, different risk categories, different testing requirements, and different paperwork. The result is not a regulatory gap but a regulatory traffic jam: a company must navigate five separate systems to operate in five markets, each demanding its own proof of the same underlying property. Nothing in that arrangement makes any citizen safer than a single well-designed regime would. It simply makes compliance a fixed cost that only the largest firms can pay.
Hassan's mistake was treating governance as a purely domestic project. Other sectors worked this out over decades: testing and certification regimes for goods grew arrangements under which a product assessed once could be accepted elsewhere, because regulators eventually accepted that duplicate testing of the same property produced duplicate cost and no additional protection. AI governance has barely begun that work, and it is starting from a harder place, because AI systems change after they are certified in a way that a bolt or a boiler does not.
The strategic task for a national leader is therefore not to write the best rules in the world. It is to write rules that are compatible with those of key partners, so that meeting your standard makes it easier, not harder, to meet theirs. Compatibility is a design property. It has to be built in at the point where definitions and risk categories are chosen, because it is nearly impossible to retrofit onto a framework whose vocabulary was invented from scratch.
Four Kinds of Divergence, and Which Ones Are Worth Keeping
Hassan's first useful move was to stop describing his framework as different from everyone else's and start describing exactly how. Divergence between AI regimes falls into four kinds, and they are not equally defensible. Two of them usually encode a genuine national choice worth protecting. The other two are almost always accidents of drafting that impose real cost on your own firms while protecting nobody. Sorting them is a week of work that changes every subsequent negotiation, because it lets you concede the accidents cheaply and defend the choices credibly.
Definitions are the most expensive place to be original. If your rules define an AI system, a provider, a deployer, or an operator differently from your partners, every downstream obligation lands on a different set of actors and nothing maps cleanly. Definitional divergence rarely reflects a value; it reflects the fact that somebody drafted in isolation. This is the divergence to give up first, and giving it up costs a government almost nothing in protection while buying a great deal in compatibility.
Risk categories are where genuine values usually live. A country that treats a particular use as impermissible, or that places a category in a higher tier because of its own history, is making a choice its citizens can recognize and its legislature can defend. Expect these to differ and design for the difference rather than negotiating it away. What you can align is the structure: a tiered scheme with comparable evidence duties at each tier can interoperate with another tiered scheme even when the tiers contain different things.
Testing and evidence requirements are mixed. Where two regimes demand different evidence for the same underlying property, that is duplicate cost with no additional protection and it should be removed. Where one regime demands evidence about a property the other does not care about, that is a value difference and it stays. Distinguishing the two requires someone technical enough to read both requirement sets, which is why this triage cannot be done by lawyers alone.
Documentation and paperwork divergence is pure accident and the easiest to fix. Different file formats, different field names, different submission portals, and different retention conventions carry no policy content whatsoever, yet they force firms to rebuild the same dossier repeatedly. Aligning the container while leaving the contents to national discretion is the cheapest coordination win available to any government, and it is the one most often overlooked because it feels administrative rather than strategic.
Two Roads: Harmonization and Mutual Recognition
There are two ways out of the traffic jam, and officials routinely confuse them in ways that waste years.
Harmonization means nations adopt the same or closely aligned rules. It is the cleanest solution and the hardest to achieve, because rules encode values and values differ. A country that prizes innovation speed will not happily adopt a stricter regime, and a country that has decided certain uses are simply impermissible will not trade that decision for market access. Full harmonization is rare, slow, and usually confined to blocs that already share legal traditions and institutions. Treating it as the default goal produces long negotiations that end in a communique and no change to anyone's compliance burden.
Mutual recognition is the pragmatic alternative. Nations keep their own rules but agree to accept each other's certifications as equivalent for a defined scope. Hassan's company would certify once, at home, and that certification would be honored abroad. This does not require identical rules. It requires enough confidence that the other side's process is rigorous, that its assessors are competent, and that its enforcement is real. Mutual recognition is how Hassan could let his companies sell globally without forcing every nation into one rulebook, and it is the workhorse of practical coordination.
The distinction matters operationally because the two roads demand different work. Harmonization is a drafting exercise conducted between legislatures and ministries. Recognition is a trust exercise conducted between regulators and conformity assessment bodies, and it usually requires domestic legal authority that a regulator does not automatically have. Hassan discovered that his own statute did not permit his authority to accept a foreign certificate at all, which meant his first move was not a negotiation but an amendment.
What Recognition Actually Requires
Recognition sounds like a signature and is really a structure. Before a regulator can accept another country's certificate, four questions have to be answered, and answering them honestly is what separates a durable arrangement from an announcement.
- Scope. Exactly which systems, risk categories, and conformity procedures does the arrangement cover? A recognition arrangement is never general. A product outside the agreed scope still certifies twice, and firms consistently assume broader coverage than the text provides.
- Equivalence basis. On what evidence did each side conclude the other's process is adequate? A shared underlying technical standard is the strongest basis, a documented comparison of procedures is the next, and diplomatic goodwill is not a basis at all.
- Assessor competence. Who accredits the bodies that do the testing, and does each side accept the other's accreditation? Recognition of certificates without recognition of accreditation collapses the moment a certificate looks doubtful.
- Suspension and dispute handling. What happens when one side loses confidence? An arrangement with no suspension mechanism is one incident away from being repudiated in public, which is worse for firms than never having had it.
Hassan added a fifth question of his own after the first round of talks. Because AI systems are updated continuously, he asked what triggers a re-assessment: which changes to a model, its training data, or its deployment context invalidate a recognized certificate. No partner had a clean answer, and the honest ones admitted their domestic regimes had not solved it either. That shared gap turned out to be the most productive item on the agenda, because it was a problem neither side could solve alone.
Standards Diplomacy: Building the Shared Language
Mutual recognition needs a common reference point, and that is where standards diplomacy comes in: shaping the international technical standards that let different regimes speak the same language. If both countries' rules are built on the same underlying standard for how AI is tested and documented, recognizing each other's certifications becomes far easier, because both sides are measuring the same things with the same instruments and arguing only about thresholds.
This is why national leaders invest in international standards bodies. A shared standard is the translation layer that makes recognition possible, and it does something a treaty cannot: it lets two governments align on method while disagreeing about policy. Hassan realized his authority should not only write national rules but actively participate in setting the international standards those rules reference, so his system would be natively compatible with others built on the same foundation. The country absent from the standards table ends up with rules that fit no one else's and recognize nothing.
There is a drafting technique that follows from this. Rules that reference a standard rather than restating its content in statute stay aligned as the standard evolves, and they let a regulator update requirements without reopening legislation. The technique has a cost that Hassan underestimated: it delegates real authority to whoever writes the standard, and it obliges your agency to maintain staff who can read, interpret, and influence that text. A rule that cites a standard nobody in the agency has read is not coordination. It is dependency with extra steps.
The Trade Dimension: Governance as Market Access
Hassan learned that AI governance is now trade policy. Rules incompatible with major markets function as a barrier against your own exporters, whatever their intent. Rules well coordinated with partners function as a passport. The diagnostic tool's fate, sold globally or stuck at home, depended less on its quality than on whether Hassan's governance interoperated with the markets that mattered. The founder's arithmetic was brutal and correct: with a fixed compliance budget and rising per-market certification costs, a firm rationally serves the largest markets first and drops the rest, and a small home market is the one most easily dropped.
This cuts both ways. Coordination opens markets, but it can also pressure a nation to accept rules that do not reflect its values, as the price of admission to a large market. That pressure is asymmetric: the larger the partner's market, the more the arrangement resembles adoption rather than negotiation, and the smaller economy becomes a rule-taker while telling itself it is a rule-shaper. Hassan's protection against this was not refusal. It was writing down, in advance, which protections his country would never trade for access, so that concessions were decisions rather than drift.
There is a third position between isolation and adoption that Hassan eventually used. Coordinating with a group of similarly sized economies, on a foundation of shared international standards, gives each of them recognition benefits and a larger combined voice in the standards bodies. Coordination among peers changes the arithmetic of asymmetry without requiring anyone to copy a larger power's rulebook.
Drawing the Non-Negotiables Before You Need Them
Every leader in Hassan's position says they have limits. Very few have written them down, and an unwritten limit is not a limit. The concessions that hollow out a national framework are almost never announced as concessions. They arrive as harmonization details in a late session, framed as technical alignment, argued for by your own trade ministry, and conceded by a negotiator who does not know that the clause in front of them was the reason a protection existed at all.
The defense is procedural and it is cheap. Before talks open, write a single page naming the protections your country will not trade for market access, in language specific enough to be recognized when it appears in someone else's drafting. Vague commitments to privacy and fairness do not survive contact with a negotiation; a named requirement, tied to the harm it exists to prevent, does. Have the officials responsible for rights and for trade both sign the page, because a limit that only one ministry believes in will not hold.
Then attach an escalation rule. Any proposed departure from the page goes to a minister rather than being settled at the table, and it goes with a written statement of what protection is being reduced and for what access in return. This does not make concessions impossible, which is not the goal. It makes them visible and attributable, which is the goal. Hassan drew three bright lines on privacy and safety this way, and the value of writing them down was not that he never moved. It was that he always knew when he was moving.
An International Coordination Readiness Checklist
Before finalizing national AI rules, run them through these questions to ensure they protect citizens without isolating your economy. Hassan now requires a written answer to each before any draft goes to his minister.
- Compatibility audit. How do our risk tiers, testing requirements, and definitions compare to our top trading partners'? Where do they clash needlessly, and where does the clash reflect a genuine difference in values that we intend to keep?
- Standards foundation. Are our rules built on widely used international technical standards, or on a unique national framework no one else shares?
- Mutual recognition potential. Which partners' certification processes are rigorous enough that we could accept them, and would they accept ours? What would each side have to see to say yes?
- Duplicate-burden test. If a domestic company certifies here, how many times must it re-certify to reach our main export markets, and what does each repetition cost?
- Legal authority. Does our regulator actually have the power to accept a foreign certificate, and if not, what has to change first?
- Standards-table presence. Are we actively shaping the international standards our rules reference, or only adopting what others wrote?
- Non-negotiables. Which protections, covering privacy, safety, and fairness, will we never trade for market access, and are they written down clearly enough that a negotiator cannot concede them by accident?
- Trade impact. Do our rules function as a passport or a barrier for our own AI exporters, and can we show the working?
- Review cadence. How will we keep our rules aligned as partners' frameworks evolve, and who owns that watch?
Why This Matters for National Leaders
The world is not converging on a single AI rulebook, and it will not. The European Union's binding risk-tiered approach, the United States' framework-based approach anchored in the voluntary AI Risk Management Framework published by its National Institute of Standards and Technology together with federal agency guidance, and other national regimes will coexist. The question for every other nation is not which one to copy, but how to coordinate with all of them well enough that its citizens are protected and its companies can compete. Governance built in isolation, however excellent, becomes a trap for the economy it was meant to serve.
Coordination is also a citizen-protection strategy, not only an export strategy. When regimes are incompatible, the systems that reach your market are the ones large enough to absorb duplicate compliance, and specialized tools that would serve smaller populations well never arrive. Incompatibility quietly narrows what your citizens can be offered, and it does so invisibly, because nobody files a complaint about a product that was never launched.
Hassan revised his framework. He rebuilt its risk tiers on a widely adopted international standard, sought the legal authority to accept foreign certificates, opened mutual-recognition talks with three major trading partners, sent technical staff to the standards bodies, and drew three bright lines on privacy and safety he would not cross. The next diagnostic-tool company that came through certified once and reached four markets, its home market plus the three partners. His rules were no less protective. They were simply built to connect. International governance coordination is not the surrender of sovereignty. It is the difference between rules that open the world to your citizens and rules that quietly close it.
Anti-Patterns to Avoid
- The recognition arrangement treated as a passport. Announcing an agreement and letting firms believe everything they build is now covered. Arrangements have a defined scope of systems, risk categories, and procedures; anything outside it certifies twice as before. Publish the scope in plain language and say explicitly what is not included.
- Copying the largest market's rulebook. Importing another jurisdiction's text without its institutions, its interpretive guidance, or its enforcement capacity. The words arrive; the meaning does not. You end up enforcing a regime whose ambiguities are resolved elsewhere, by people who do not answer to your legislature.
- Mistaking adoption for recognition. Believing that because your rules now reference the same international standard, other regulators will accept your certificates. Adoption is a step toward recognition and is never recognition itself; recognition requires a decision by the other regulator, on evidence, with a scope and a suspension clause.
- Coordination as a one-time project. Completing a compatibility audit, declaring alignment, and moving on. Partner frameworks are revised continuously, and alignment achieved once decays without a named owner and a review cadence. A completed audit describes the day it was run.
- Conceding protections by accident. Entering negotiations without written non-negotiables, then trading a fairness or privacy requirement in a late session because it looked like a technical detail. If the red lines are not written down before the talks, they are not red lines.
- Referencing standards your agency cannot read. Citing an international specification in regulation while employing nobody who can interpret it, monitor its revision, or represent your position when it is rewritten. That is dependency, and it worsens as the standard evolves.
- Treating incompatibility as a moral position. Defending a unique national framework as evidence of higher standards when the divergence is merely historical. Distinguish differences that encode a genuine value choice from differences that are accidents of drafting, and remove the accidents.
Practice Prompts
- Take your national AI framework and your largest trading partner's, and build a two-column comparison of definitions, risk categories, and required evidence. Mark each divergence as a value choice or a drafting accident, and propose removing every accident.
- Interview domestic firms that export AI-enabled products. Ask how many certifications they hold for the same system, what each cost in time and money, and which markets they abandoned. Bring the answers to your next rulemaking meeting.
- Write the scope clause you would want in a mutual recognition arrangement with one named partner: which systems, which risk categories, which conformity procedures, and what triggers re-assessment when a model is updated.
- Check whether your regulator currently has legal authority to accept a foreign certificate. If not, draft the amendment that would grant it, with the safeguards you would attach.
- Draft your country's non-negotiables on privacy, safety, and fairness in one page, in language specific enough that a negotiator under time pressure cannot concede them without noticing.
Reflection
- Where does your national framework diverge from your partners' for reasons you can actually defend, and where does it diverge simply because it was drafted separately?
- If a domestic firm told you it was skipping your home market because compliance was not worth the volume, would you hear about it, and from whom?
- Who in your government owns the watch on partners' evolving frameworks, and what happens to what they find?
- Which protections would you refuse to trade even if it cost your exporters access to your largest market, and have you written them down?
- Are you a rule-shaper or a rule-taker in the standards bodies your regulation references, and what would it cost to change that?
Glossary
- Harmonization. Nations adopting the same or closely aligned rules, producing the cleanest interoperability and requiring the most political agreement.
- Mutual recognition. An arrangement under which nations keep their own rules but accept each other's certifications as equivalent for a defined scope.
- Equivalence assessment. The evidence-based judgment that another jurisdiction's process achieves a comparable outcome, which is the basis on which recognition is granted.
- Conformity assessment. The testing, documentation, and certification process by which a system is shown to meet a standard or regulatory requirement.
- Accreditation. The process by which an authority confirms that a conformity assessment body is competent to certify, which recognition arrangements depend on as much as the certificates themselves.
- Standards diplomacy. Deliberate national participation in international technical standards bodies in order to shape the specifications that domestic and foreign rules will reference.
- Regulatory divergence. The condition in which two jurisdictions require different evidence for the same underlying property, imposing duplicate cost without additional protection.
- Rule-taker. A jurisdiction that adopts another's requirements in substance because market access depends on it, while retaining formal regulatory independence.
Related Lessons
- International AI Diplomacy covers the choice of venues and the diplomatic portfolio that coordination work depends on.
- International Standards: EU AI Act and OECD gives the detailed content of the two reference points most coordination conversations start from.
- Contributing to Standards Bodies (NIST, ISO, IEEE, OECD) is the practical guide to staffing the technical committees this lesson tells you to join.
- International AI Governance and International Government AI Collaboration extend the institutional and working-level dimensions.
- AI Regulatory Design and Legislative Framework Development cover the drafting choices that determine whether your rules can be coordinated at all.
- Multi-Level Government AI Governance applies the same interoperability problem inside a single country, across national and subnational rules.
- Sovereign AI: Data Residency and National Security takes up the limits of coordination where sovereignty claims are non-negotiable.
Closing
Hassan's framework did not get weaker when it got connected. That is the point most leaders miss, because coordination is usually argued about as though it were a dial running from sovereignty to surrender. It is not. It is a design discipline: choose definitions others can map to, build on standards you helped write, secure the legal authority to accept a partner's work, and write down what you will never trade. Do that, and your rules protect the same citizens while reaching a great deal further. Skip it, and you will have built the finest regulatory framework nobody outside your borders can use.
Key Takeaways
- The problem is incompatibility, not quality. Five sets of excellent but disconnected rules create a traffic jam that walls your own companies out of global markets and narrows what your citizens are offered.
- Aim for compatible, not identical. Full harmonization is rare because rules encode differing values; the realistic goal is rules that interoperate, and compatibility must be designed in when definitions are chosen.
- Mutual recognition is the workhorse. Accepting each other's certifications as equivalent lets companies certify once and sell widely without forcing one global rulebook.
- Recognition is a structure, not a signature. It needs a defined scope, an evidence-based equivalence basis, accepted accreditation, and a suspension mechanism, plus an answer to what a model update does to a certificate.
- Shared standards are the translation layer. Building national rules on common international technical standards is what makes recognition feasible, and referencing a standard obliges you to staff the committee that writes it.
- AI governance is now trade policy. Well-coordinated rules act as a passport for your exporters; isolated rules act as a barrier against them, and the smallest home market is the one firms drop first.
- Protect your non-negotiables in writing. Coordination pressure is asymmetric, so decide in advance which privacy, safety, and fairness protections you will never trade for access.
- Coordination decays. Partners revise their frameworks continuously, so alignment needs a named owner and a review cadence rather than a one-time audit.
Frequently Asked Questions
Is mutual recognition just a slower way of adopting someone else's rules?
No, and the difference is the whole point. Under recognition each side keeps its own requirements and accepts the other's process as adequate for a defined scope. Under adoption you replace your requirements with theirs. Recognition preserves your ability to regulate differently where your values differ, which is exactly what a smaller economy loses when it copies a larger one's rulebook to secure access.
Our market is small. Does anyone have a reason to recognize our certifications?
Sometimes, and more often than officials assume. Recognition is cheap for the larger partner when your process rests on the same international standard, because the assessment work is already comparable. Where a bilateral arrangement is genuinely unattractive, coordinating with a group of similarly sized economies on a shared standards foundation gives all of you recognition benefits among yourselves and a larger combined voice where the standards are written.
Does coordinating with a large market mean accepting its values?
Only if you have not decided in advance what you will not trade. Coordination pressure is real and asymmetric, and it works by presenting concessions as technical harmonization details late in a negotiation. The defense is procedural: write the non-negotiables down before talks begin, make them specific rather than aspirational, and require a minister rather than a negotiator to sign off on any departure.
How do we handle the fact that AI systems change after certification?
Treat it as an open problem and raise it early with partners rather than hiding it. Decide domestically which changes to a model, its training data, or its deployment context invalidate an assessment, and write that trigger into your own regime first. A recognition arrangement built on top of two regimes that both ignore post-deployment change will fail at the first significant model update, and it will fail publicly.
Should our rules restate international standards or reference them?
Referencing keeps you aligned as the standard evolves and lets you update requirements without reopening legislation, which is usually the better choice. The condition attached is that your agency must employ people who can read the standard, track its revision, and represent your position when it is rewritten. Referencing a standard you cannot influence hands real regulatory authority to a body you do not sit on.
Where should a national leader start if none of this exists yet?
Start with the compatibility audit and the legal authority question, because both can be answered internally and both determine everything downstream. The audit tells you whether your divergences are value choices or drafting accidents. The authority question tells you whether recognition is even available to your regulator today. Together they take weeks, not years, and they turn a vague ambition to coordinate into a specific list of amendments and conversations.
Skill.re