AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-05-26

AI Governance Problems, Policy Options, and Research Gaps Mapped in LawAI Literature Review

What happened

LawAI published the Advanced AI Governance: A Literature Review of Problems, Options and Research Challenges in January 2025, providing a structured survey of academic and policy literature on frontier AI governance mechanisms. The review covers regulatory instruments including compute security measures, software and hardware export controls, licensing regimes for advanced AI systems, structured system evaluations, and procurement rules designed to advance AI safety objectives. It also examines voluntary corporate governance proposals such as Responsible Scaling Policies adopted by several leading AI developers, and formal AI certification schemes being explored by standards bodies and regulators. The document does not make binding recommendations but synthesizes existing research to identify where evidence is strong, where significant gaps remain, and which governance questions require further empirical or legal investigation. The review is intended to serve policymakers and governance practitioners across international frameworks, with particular relevance to active policy discussions in the United States, the United Kingdom, and the European Union.

Why it matters

  • ·The review signals that licensing and pre-market certification regimes for frontier AI models are under active consideration across multiple jurisdictions, creating potential new regulatory exposure for developers who have not yet mapped their compliance posture against emerging approval obligations.
  • ·The document's detailed treatment of system evaluations connects directly to existing mandates such as the EU AI Act's conformity assessment requirements and NIST's AI Risk Management Framework, meaning organizations already subject to these frameworks may face heightened scrutiny of their evaluation and audit practices.
  • ·The inclusion of compute governance and export controls as core governance topics underscores that trade compliance functions are now organizationally implicated in AI risk management, expanding the internal stakeholder set that must coordinate on AI governance strategy.

Governance controls affected

What to do now

  • Review internal AI risk classification processes against the licensing and certification frameworks surveyed in the literature review to identify gaps ahead of potential pre-market approval obligations.
  • Assign trade compliance teams to assess the organization's exposure to current and anticipated compute-related export controls, particularly those tightened by the United States and mirrored by allied governments.
  • Evaluate existing system evaluation and conformity assessment procedures against the structured evaluation standards discussed in the review and referenced in the EU AI Act and NIST AI RMF.
  • Brief procurement and legal counsel on the review's findings regarding AI procurement rules so that vendor contracts can be updated to reflect emerging government expectations around safety and transparency.
  • Identify open research and regulatory questions highlighted in the review that are relevant to the organization's AI portfolio and determine where engagement with regulators or standards bodies would be productive.

What to watch next

Compliance teams should monitor legislative and regulatory developments in the United States, the United Kingdom, and the European Union related to compute export controls, as restrictions have been tightening rapidly and further allied government coordination is expected. Progress on formal AI certification schemes at standards bodies such as ISO and national equivalents warrants close attention, given that the review identifies certification as an area of active policy development that could result in binding pre-market obligations. Teams should also track any follow-on publications from LawAI and similar academic-policy institutions, as subsequent work addressing the open research gaps identified in this review may inform upcoming regulatory guidance cycles.

Stay ahead of stories like this

Get every ISO/OECD/UN AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-10

OpenAI's Tiered Cybersecurity Model Sets a Partner Governance Template

OpenAI has released GPT-5.6 Cyber, a specialized AI model for vulnerability research, penetration testing, and incident response. Access is restricted to approved enterprise partners through a program called Daybreak Access, which offers two tiers: Daybreak Blue for defensive security work and Daybreak Red for offensive tasks. Governance controls embedded in the program include identity verification, defined testing scopes, logging, monitoring, and mandatory human oversight.

Research2026-08-04

LLMs Fail on High-Dimensional Tabular Data, Exposing Fitness-for-Purpose Gaps

Researchers Marta Garnelo and Wojciech Czarnecki published findings showing that LLM accuracy degrades systematically as input dimensionality increases on tabular prediction tasks, while classical baselines hold flat or improve. The study tested five hypotheses across 31 benchmark datasets using a frontier LLM with no fine-tuning. Organizations using LLMs for fraud detection, risk scoring, or compliance monitoring on structured enterprise data face a direct fitness-for-purpose exposure.

Research2026-07-30

Credo AI Case Study Shows How Workflow-Integrated Governance Closes the Gap Between AI Policy and Operational Practice

Credo AI published a case study detailing how a global technology enterprise embedded AI governance directly into its InfoSec, privacy, and procurement workflows using the Credo AI platform. The implementation centralized use-case intake, automated risk and compliance checks, and applied standardized policy packs across business units. The case study offers a concrete operating model for compliance teams seeking to move AI governance from standalone committee function to embedded operational control.