Risk 360

AI Laws: Ten Risks Regulators Must Address to Build Effective Global AI Governance

Getting India Risk Ready

Regulators designing AI laws should focus on ten governance risks that cut across borders, technologies, and sectors, rather than only chasing the latest headline harms. A global, risk‑based, and adaptive approach is essential if AI is a risk regulators seek to address, without freezing innovation. [1]

From data points to democratic decisions

Around the world, parliaments and regulators are racing to catch up with AI systems that are already embedded in finance, healthcare, public services, and everyday consumer apps. The regulatory choices they make now will quietly shape which values get encoded into algorithms, who benefits from AI, and who is left to absorb the downside AI risks.[2]

1. The pacing problem: law that always arrives late

AI evolves faster than most legislative cycles, creating a structural “pacing problem” where rules arrive after harms are already visible in the market or society. If AI laws are drafted as static checklists tied to current technologies, they will quickly become obsolete and may even incentivise cosmetic compliance rather than genuine risk management.[3]

Regulators should treat AI legislation as a living instrument, building in sunset clauses, mandatory periodic reviews, and mechanisms to incorporate technical updates without reopening an entire statute. Tools like regulatory sandboxes and pilot regimes can allow supervised experimentation, giving regulators real‑world data to refine rules before scaling them.

2. Fragmented global rules and regulatory arbitrage

AI services cross borders effortlessly, but most AI laws are still national or regional, creating a patchwork of overlapping and sometimes conflicting requirements. This fragmentation invites regulatory arbitrage, where powerful firms structure their operations to exploit the weakest regime or the most permissive interpretation of key concepts like “high‑risk” AI. [4]

Regulators should anticipate cross‑border dynamics from the start, designing frameworks that can interoperate with others and support mutual recognition of risk assessments and conformity checks. Aligning around shared principles—such as trustworthy AI and risk‑based proportionality—through fora like the OECD or G7 reduces compliance friction while closing loopholes that undermine governance.

3. Over‑broad or under‑baked risk classifications

Risk‑based regulation has become the dominant paradigm, with high‑risk applications subject to more stringent oversight and “unacceptable risk” uses banned outright, as in the EU AI Act. However, simplistic or politically driven categorisation can mis‑classify systems, either burdening low‑risk innovation or leaving high‑stakes deployment under‑regulated.[5]

Regulators need clear, context‑sensitive taxonomies that distinguish between risks arising from the model, the system into which it is integrated, and the deployment environment. This requires iterative refinement based on evidence of harm, structured consultation with domain experts, and the ability to reclassify systems as their use and impact evolve.[6]

4. AI transparency gaps and the black box challenge

Many AI models, especially large general‑purpose ones, operate as opaque “black boxes” where even developers struggle to fully explain how outputs are generated. When regulators rely only on self‑reported documentation or limited technical disclosures, they risk supervising systems they do not truly understand, weakening accountability for unfairness, privacy violations, and safety failures.[7]

AI laws should have hard‑wire lifecycle transparency obligations: data provenance records, model training parameters, performance monitoring logs, and audit trails for high‑risk systems. These obligations must be tailored to different audiences—internal risk teams, regulators, and the public—without forcing disclosure that would genuinely compromise security or trade secrets.

5. Lifecycle accountability instead of post‑mortem blame

Traditional legal regimes often react after harm has occurred, relying on liability and litigation to correct behaviour. In fast‑moving AI ecosystems, this reactive model is too slow and can leave vulnerable groups exposed to systemic bias, exclusion, or safety failures that compound over time.[8]

Regulators should embed pre‑deployment AI impact assessments (AIAs) as a core legal obligation for high‑risk systems, covering fairness, privacy, safety, and fundamental rights. These AIAs need to be more than paperwork; they should be reviewed by competent authorities, linked to auditable evidence, and updated as systems are retrained, repurposed, or scaled.

6. Expertise gaps inside the regulatory state

Even the best‑written AI law is ineffective if regulators lack the technical fluency to interrogate algorithms, understand model architectures, or challenge industry claims. Many agencies face an asymmetry of power and knowledge when dealing with multinational AI providers that have deep resources and specialised teams.[9]

Bridging this gap requires strategic investment in regulatory capacity: specialised technical career tracks, competitive compensation for AI and data science talent, and dedicated institutes like the UK’s AI Safety Institute. Formal partnerships with universities and independent research labs can supplement this capacity, providing test environments, external audits, and critical scrutiny.

7. Regulatory capture and concentration of AI power

A small cluster of major firms now dominate the development and deployment of general‑purpose AI systems, shaping both technical standards and the policy conversations around them. Without safeguards, these firms can steer regulation toward light‑touch self‑regulation or rules that entrench their own business models, sidelining smaller players and public interest voices.

Regulators should design governance processes that explicitly guard against capture, including multi‑stakeholder advisory bodies, transparent consultation, and strong conflict‑of‑interest rules. Co‑governance arrangements, where civil society, academia, and affected communities share a seat at the table, can rebalance influence and improve the legitimacy of AI laws.

8. Enforcement at scale in a borderless ecosystem

Crafting rules is only half the battle; enforcing them across thousands of models, millions of deployments, and multiple jurisdictions is a formidable challenge. Domestic regulators often lack the resources to police large technology firms, while cross‑border services complicate jurisdiction and remedial action.

AI laws should anticipate enforcement constraints by prioritising clear, measurable obligations, supported by risk‑based supervision and proactive market monitoring. International cooperation on joint investigations, interoperable standards, and shared testing infrastructure can help regulators move beyond purely national enforcement in a global AI market.

9. Government’s own use of AI and the legitimacy risk

Governments are increasingly using AI in core public functions—from benefits administration and fraud detection to justice systems and public sector workforce management. When state use of AI is poorly governed, it can erode trust, amplify existing inequalities, and undermine the perceived legitimacy of both AI and the institutions deploying it.[10]

Regulators should apply at least the same standards, and often higher ones, to public sector AI as they do to private actors, especially where fundamental rights are at stake. Embedding human‑in‑the‑loop safeguards, clear appeal mechanisms, and participatory design processes can prevent automated decision‑making from hollowing out democratic accountability. 

10. Missing feedback loops and post‑legislative scrutiny

AI harms often emerge only after deployment, sometimes through cumulative effects or unexpected interactions between systems. Yet many legislative processes treat post‑implementation review as an afterthought, limiting opportunities to learn from real‑world impacts and adjust course.

To prevent deployment risks, robust AI governance should build in mandatory reporting, structured feedback from affected groups, and periodic legislative scrutiny of how statutes operate in practice. Regulators can use this evidence to refine guidance, recalibrate risk tiers, and update supervisory priorities, keeping law in dialogue with technological and social change.

Designing AI laws as operational resilience architectures

The journey from AI’s promise to concrete AI legislation is not a search for a perfect, one‑off solution but an exercise in building resilient governance architectures that can absorb shocks and adapt. Regulators who build AI regulation risk strategies to improve their risk resilience, and confront these ten risks head‑on—pacing, fragmentation, mis‑classification, opacity, weak lifecycle accountability, expertise gaps, capture, enforcement limits, public‑sector misuse, and thin feedback loops—will be better placed to steward AI toward outcomes that strengthen, rather than strain, societies worldwide.

The author confirms that this article is original and has not been copied, reproduced, or derived from another author’s work, except for appropriately cited third-party references used for research purposes.

Citations 

[1] https://academic.oup.com/slr/article/47/1/hmag012/8665064 

[2] https://www.oecd.org/en/publications/2025/06/governing-with-artificial-intelligence_398fa287/full-report/ai-in-regulatory-design-and-delivery_128691e6.html 

[3] https://www.brookings.edu/articles/the-three-challenges-of-ai-regulation/ 

[4] https://www.mindfoundry.ai/blog/ai-regulations-around-the-world 

[5] https://www.csis.org/blogs/strategic-technologies-blog/ai-regulation-coming-what-likely-outcome 

[6] https://carnegieendowment.org/research/2024/11/indias-advance-on-ai-regulation 

[7] https://www.ibm.com/think/insights/10-ai-dangers-and-risks-and-how-to-manage-them 

[8] https://www.bu.edu/bulawreview/files/2023/11/KAMINSKI.pdf 

[9] https://harvardlawreview.org/print/vol-138/co-governance-and-the-future-of-ai-regulation/ 

[10] https://lordslibrary.parliament.uk/artificial-intelligence-development-risks-and-regulation/ 

FAQS

1.What is AI governance?

  • Around the world, parliaments and regulators are racing to catch up with AI systems that are already embedded in finance, healthcare, public services, and everyday consumer apps. The regulatory choices they make now is the AI governance that will quietly shape which values get encoded into algorithms, who benefits from AI, and who is left to absorb the downside risks.
  • The journey from AI’s promise to concrete AI legislation is not a search for a perfect, one‑off solution but an exercise in building resilient governance architectures that can absorb shocks and adapt. Regulators who confront these ten risks head‑on—pacing, fragmentation, mis‑classification, opacity, weak lifecycle accountability, expertise gaps, capture, enforcement limits, public‑sector misuse, and thin feedback loops—will be better placed to steward AI toward outcomes that strengthen, rather than strain, societies worldwide.

2. What are the biggest AI governance risks?

The biggest AI governance risks are as follows – 

  1. The pacing problem: law that always arrives late
  2. Fragmented global rules and regulatory arbitrage
  3. Over‑broad or under‑baked risk classifications
  4. Transparency gaps and the black box challenge
  5. Lifecycle accountability instead of post‑mortem blame
  6. Expertise gaps inside the regulatory state
  7. Regulatory capture and concentration of AI power
  8. Enforcement at scale in a borderless ecosystem
  9. Government’s own use of AI and the legitimacy risk
  10. Missing feedback loops and post‑legislative scrutiny

3. What should AI laws address?

AI Laws must address the following – 

  • The regulatory arbitrage, where powerful firms structure their operations to exploit the weakest regime or the most permissive interpretation of key concepts like “high‑risk” AI. 
  • The simplistic or politically driven categorisation that can mis‑classify systems, either burdening low‑risk innovation or leaving high‑stakes deployment under‑regulated.
  • Relying only on self‑reported documentation or limited technical disclosures. This creates the risk of supervising systems that do not truly understand, weakening accountability for unfairness, privacy violations, and safety failures.
  • Traditional legal regimes that react after harm has occurred, relying on liability and litigation to correct behaviour. In fast‑moving AI ecosystems, this reactive model is too slow and can leave vulnerable groups exposed to systemic bias, exclusion, or safety failures that compound over time.
  • The lack of the technical fluency to interrogate algorithms, understand model architectures, or challenge industry claims. 
  • Light‑touch self‑regulation or rules that entrench the business models of only a few firms, sidelining smaller players and public interest voices.
  • AI harms often emerge only after deployment, sometimes through cumulative effects or unexpected interactions between systems. Guidance must be refined, risk tiers should be recalibrated, and supervisory priorities must be updated, to ensure the law is in dialogue with technological and social change.

4. How should governments regulate AI?

Governments should regulate AI in the following manner – 

  • Regulators should treat AI legislation as a living instrument, building in sunset clauses, mandatory periodic reviews, and mechanisms to incorporate technical updates without reopening an entire statute.
  • Regulators should anticipate cross‑border dynamics from the start, designing frameworks that can interoperate with others and support mutual recognition of risk assessments and conformity checks. 
  • Regulators must perform iterative refinement based on evidence of harm and structured consultation with domain experts. They should reclassify systems as their use and impact evolve.
  • AI laws should hard‑wire lifecycle transparency obligations: data provenance records, model training parameters, performance monitoring logs, and audit trails for high‑risk systems. These obligations must be tailored to different audiences.
  • Regulators should embed pre‑deployment AI impact assessments (AIAs) as a core legal obligation for high‑risk systems, covering fairness, privacy, safety, and fundamental rights. 
  • Regulators must make strategic investment in regulatory capacity: specialised technical career tracks, competitive compensation for AI and data science talent, and dedicated institutes like the UK’s AI Safety Institute. 
  • Regulators should design governance processes that explicitly guard against capture, including multi‑stakeholder advisory bodies, transparent consultation, and strong conflict‑of‑interest rules. 
  • AI laws should anticipate enforcement constraints by prioritising clear, measurable obligations, supported by risk‑based supervision and proactive market monitoring. 
  • Regulators should apply at least the same standards, and often higher ones, to public sector AI as they do to private actors, especially where fundamental rights are at stake. 
  • Build in mandatory reporting, structured feedback from affected groups, and periodic legislative scrutiny of how statutes operate in practice. 

5. How can organisations manage AI risks? 

  • AI harms often emerge only after deployment, sometimes through cumulative effects or unexpected interactions between systems. Yet many processes treat post‑implementation review as an afterthought, limiting opportunities to learn from real‑world impacts and adjust course.
  • Organisations can manage AI risks through strong governance. Robust AI governance should build in mandatory reporting and structured feedback from affected groups. This evidence can be used to refine guidance, recalibrate risk tiers, and update supervisory priorities.
  • To understand more about managing AI risks, organisations can explore IRM’s corporate governance and risk training programmes that cover AI risks and solutions for the efficient management of digital risks.

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *

More in Risk 360