AI Governance Institute
← News
Research2026-05-01

AI Governance Rules Are Forming Outside Transparent Processes, IAPP Warns

Source

IAPP

What happened

The International Association of Privacy Professionals published an op-ed on April 28, 2026, identifying three specific non-legislative events that are actively shaping global AI governance without transparent deliberation or meaningful input from affected governments and populations. The analysis argues that geopolitical pressures and government procurement decisions are functioning as de facto AI rulemaking mechanisms, bypassing formal regulatory channels and creating accountability gaps that most compliance teams are not currently tracking. The IAPP urges privacy and governance professionals to engage civil society organizations, secure sustainable funding for oversight initiatives, and build direct partnerships with regulators to address these structural shortfalls. The finding is particularly relevant for enterprise teams assessing AI deployment risk in markets where procurement frameworks or bilateral agreements may function as de facto regulatory instruments. Organizations operating across multiple jurisdictions are advised to audit their governance tracking practices to account for non-legislative standard-setting activity.

Why it matters

  • ·Regulatory exposure: Material AI governance obligations may emerge from informal procurement specifications or bilateral agreements rather than published legislation, meaning standard regulatory monitoring workflows may leave organizations unknowingly non-compliant in key markets.
  • ·Operational impact: Government procurement frameworks in rapidly acquiring markets are increasingly embedding AI standards that private sector vendors and partners must meet to remain eligible, creating operational configuration requirements that arise outside formal rulemaking dockets.
  • ·Organizational risk: Compliance functions that lack direct engagement with civil society organizations and regulators before formal rules are published face a structural early-warning gap, increasing the likelihood of being caught off-guard by binding obligations that formed through opaque processes.

Governance controls affected

What to do now

  • Audit current regulatory monitoring scope to determine whether it captures procurement specifications, bilateral technical agreements, and informal international coordination processes in addition to published legislation and finalized standards.
  • Map each jurisdiction where the organization operates to identify markets where government procurement functions as a dominant market-entry condition and where non-legislative standard-setting exposure is elevated.
  • Establish or review direct engagement relationships with civil society organizations active in AI governance to obtain early-warning signals on informal rulemaking activity.
  • Update third-party and vendor risk assessment processes under PRC-001 and PRC-002 to flag AI-related procurement or interoperability requirements that may carry de facto compliance obligations.
  • Brief senior compliance and legal stakeholders on the IAPP analysis and schedule a structured review of whether current governance tracking models provide sufficient coverage for informal standard-setting channels.

What to watch next

Compliance teams should monitor whether additional intergovernmental bodies or bilateral partnerships publish procurement or interoperability frameworks that embed specific AI requirements, particularly in markets undergoing rapid government AI acquisition. The IAPP analysis signals a broader pattern, and further op-eds, working papers, or formal guidance from the IAPP and peer organizations are likely to follow as concrete examples of informal standard-setting accumulate. Teams should also watch for enforcement or eligibility decisions tied to procurement specifications in the United States and EU that could clarify the legal weight of non-legislative AI standards.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-21

California's Seven Data Center Bills Impose Disclosure and Cost Obligations on AI Operators

California Governor Gavin Newsom signed seven bills imposing new environmental and infrastructure obligations on AI data center operators. Facilities must disclose estimated water use, energy efficiency plans, and drought preparedness to local governments before approval. Operators must also fund local power grid and water system upgrades rather than shifting those costs to ratepayers.

Corporate Policy2026-09-18

$875M FAA AI Contract Exposes Advisory-Role Accountability Gap

The FAA has awarded a 12-year, $875 million contract to Air Space Intelligence for its SMART AI system, which will advise air traffic controllers on congestion management across U.S. airspace. The system is explicitly advisory and does not change controller or airline procedures. Governance experts are calling for written accountability frameworks and performance gates before any scope expansion.

Enforcement2026-09-22

BC Sues OpenAI Over Alleged Safety Override Before School Shooting

British Columbia filed a lawsuit against OpenAI and CEO Sam Altman in September 2026, alleging that OpenAI overrode its own human review team's recommendation to share a user's violent ChatGPT chat logs with police before the February 2026 Tumbler Ridge Secondary School shooting. The province seeks compensation for rebuilding the school and covering emergency response costs. The suit also requests a court order requiring ChatGPT to automatically terminate violent conversations.