AI Governance Institute
← News
Research2026-09-10

Brookings: Middle-Power AI Hedging Creates a Multi-Jurisdiction Compliance Gap

What happened

The Brookings Institution published Middle power AI agency: Preserving choice between the United States and China, a commentary arguing that a significant group of nations, including Australia, Canada, South Korea, Singapore, Saudi Arabia, the UAE, and Brazil, are resisting full alignment with either the U.S. or Chinese AI governance frameworks. The analysis contends that these governments view strategic flexibility as a national interest, choosing selectively from each bloc's norms rather than adopting either wholesale. The governance implication is not abstract: middle-power hedging produces hybrid and jurisdiction-specific requirements around model assurance, hardware sourcing, data handling, and platform access that do not map cleanly onto any single leading framework. For enterprises, this means a compliance program calibrated to the EU AI Act or NIST standards may satisfy regulators in Brussels or Washington while creating undetected gaps in Riyadh, Seoul, or Canberra. The commentary does not set binding obligations, but it represents a credible analytical baseline for understanding why middle-power regulatory divergence is accelerating rather than converging.

Why it matters

  • ·Multi-jurisdiction AI compliance mapping programs built around leading frameworks such as the EU AI Act or the NIST Artificial Intelligence Risk Management Framework Playbook are structurally underbuilt for middle-power markets, where hybrid governance expectations are emerging independently of either major bloc. Organizations operating in Australia, South Korea, Singapore, or the Gulf states need jurisdiction-specific coverage, not framework extrapolation.
  • ·Procurement and vendor due diligence controls face compounding risk as middle-power governments introduce independent requirements around model provenance, hardware origin, and assurance documentation. A vendor cleared under U.S. export control rules or EU conformity assessments may face additional or conflicting requirements in markets that have chosen not to adopt either framework as a reference standard.
  • ·Board-level AI risk reporting must account for geopolitical alignment risk as a distinct category. As middle-power governments make deliberate choices about which AI governance bloc to adopt selectively, the regulatory surface for multinational AI programs becomes harder to predict, and material gaps can emerge between reported compliance status and actual regulatory exposure in specific markets.

Governance controls affected

What to do now

  • Audit your multi-jurisdiction AI regulatory map to identify which middle-power markets your AI-enabled products or services touch, and flag where your current framework coverage (EU AI Act, NIST, etc.) has not been validated against local requirements.
  • Assign a named owner in regulatory affairs or compliance to monitor AI governance developments in at least three of your highest-exposure middle-power jurisdictions on a quarterly basis.
  • Review AI vendor and hardware procurement due diligence checklists to ensure they capture country-of-origin and alignment-related assurance requirements that may apply in markets outside the U.S. and EU.
  • Update your board AI risk report to include a geopolitical alignment section that flags jurisdictions where regulatory divergence from leading frameworks creates unresolved compliance exposure.
  • Assess whether your current voluntary framework commitments (such as adherence to NIST or OECD principles) are being treated by middle-power regulators as sufficient assurance, or whether local assurance processes are required.

What to watch next

Compliance teams should monitor whether middle-power governments translate their strategic hedging postures into binding procurement restrictions, mandatory assurance requirements, or model-access controls over the next 12 to 18 months. Developments in Singapore, South Korea, and the Gulf Cooperation Council states are particularly worth tracking, given those governments' active AI strategy programs and history of independent standards development. The Singapore National AI Strategy 2.0 and related frameworks from the IMDA Model AI Governance Framework illustrate how middle-power governance can develop with enough specificity to create genuine compliance obligations that diverge from EU or U.S. baselines. Teams should also watch whether the Commerce Department Evaluation of State AI Laws signals any federal intent to influence how middle-power governments perceive U.S. AI governance norms.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-09

OpenAI's $1B Cyberdefense Commitment Creates Vendor Intake Obligations for Critical Infrastructure

OpenAI announced it will provide $1 billion in subsidized access to AI cybersecurity tools, training, and technical support for organizations protecting critical services. The commitment responds to growing concern about AI-enabled cyberattacks and is framed as a safety and societal contribution. Compliance teams at critical infrastructure operators and regulated enterprises must treat acceptance of the offer as a vendor intake event, not a procurement shortcut.

Corporate Policy2026-09-07

Data Center Fire Exposes Accountability Gap in Anthropic and Google's Supply Chain

A fire at the Lake Mariner AI data center in New York, operated across four corporate layers involving TeraWulf, Fluidstack, Google, and Anthropic, revealed missing safety alarms, suppression systems, and accessible safety documents. The incident exposed how accountability for physical infrastructure safety, environmental performance, and legal liability fragments when frontier AI companies rely on multi-tier third-party operators. Anthropic's published ratepayer commitments could not be independently verified at the leased site, highlighting a structural gap in AI supply chain governance.

Research2026-09-07

CISO AI Confidence Tracks Governance Readiness, Not Control Effectiveness

An IANS Research survey of 113 CISOs found that optimism about managing AI security risks over the next 24 months correlates more strongly with organizational readiness factors than with verified technical controls. Factors such as leadership understanding of AI risk, defined governance ownership, CISO budget authority, and adequate staffing drive confidence levels. Analysts caution that these signals reflect favorable conditions rather than demonstrated control outcomes, and that third-party AI risk and agent authorization gaps remain broadly unaddressed.