This article is Part 1 of "Governing the Machine"--a five-part series translating UNESCO's 2026 survey of global AI law into plain language.
Figure 1: UNESCO’s nine approaches to governing AI, ordered from light-touch to most stringent. Created by the Author using Canva AI
Governments are being asked to regulate a technology that changes faster than any legislative calendar can accommodate. Since 2016, a growing number of countries have passed laws that explicitly mention artificial intelligence, and the volume of AI bills under debate has risen sharply over the past three years (UNESCO, 2026). The question facing lawmakers is no longer whether to act, but how. This article introduces the nine broad approaches that a 2026 UNESCO policy brief identifies as the emerging global menu of options.
Introduction
Rather than prescribing a single model, UNESCO maps a spectrum of regulatory strategies that runs from soft guidance to binding sanction. The organisation has standing to do so: 193 Member States adopted the Recommendation on the Ethics of Artificial Intelligence in November 2021 (UNESCO, 2021), and the 2026 brief translates those high-level norms into concrete legislative form. The drafting was not conducted in isolation. Between August and October 2024, the consultation drew more than 100 submissions from individuals and organisations across 36 countries and territories (UNESCO, 2026). The resulting taxonomy therefore reflects lived legislative experience rather than abstract theory, and it rests on a single organising insight: the nine approaches are not mutually exclusive, and most laws combine two or more.
A Spectrum, Not a Hierarchy
The report orders the approaches deliberately, from the least to the most demanding, while stressing that the sequence implies neither importance nor desirability (UNESCO, 2026). The nine, in that order, are the following:
- Principles-based--fundamental propositions that orient ethical and human-centric AI.
- Standards-based--technical standards that give operational precision to mandatory rules.
- Agile and experimentalist--flexible schemes such as regulatory sandboxes and testbeds.
- Facilitating and enabling--measures that build talent, infrastructure and institutions.
- Transparency mandates--obligations to disclose basic information about AI systems.
- Adapting existing laws--incremental amendments to sector-specific and cross-cutting rules.
- Risk-based--obligations scaled to the assessed risk of a given use.
- Mandatory rights-based--new enforceable rights and binding duties to protect them.
- Liability--responsibility and sanctions attached to harmful development and use.
Because the approaches combine, a legislature is not choosing one door and closing the others. It is assembling a bespoke instrument from parts that can reinforce one another.
The Light-Touch End: Principles and Standards
At the softest end sits the principles-based approach, which offers stakeholders a set of fundamental propositions to guide ethical and human-rights-abiding AI. Peru's Law No. 31814 of 2023, for instance, enshrines principles such as risk-based security, an ethical and multi-stakeholder approach, and privacy (UNESCO, 2026). Principles alone impose no obligations and carry no legal consequence; their function is to shape how other rules are interpreted and enforced.
A step firmer is the standards-based approach, which uses technical standards developed by standard-setting bodies to give mandatory rules operational precision. Article 40 of the European Union's AI Act, for instance, grants systems that comply with harmonised standards a presumption of conformity with the law's requirements (UNESCO, 2026). The soft-law terrain here is dense: the United Kingdom's AI Standards Hub has catalogued nearly 500 AI-relevant standards, and AlgorithmWatch's global inventory documents 167 separate AI ethics guidelines (UNESCO, 2026). Standards, notably, often precede formal regulation and quietly shape it.
Why a Menu Suits the Problem
There is a psychological logic to preferring a menu over a mandate. Herbert Simon's concept of bounded rationality holds that decision-makers facing genuine complexity cannot optimise; they satisfice, selecting an option that is good enough given the limits of time, information and cognitive capacity (Simon, 1955). A single universal rule assumes a clarity that fast-moving technology does not provide. A combinable set of approaches, by contrast, lets a legislature act under uncertainty and revise as it learns.
The report reaches a compatible conclusion by a different route, warning that a one-size-fits-all regulation applied indiscriminately to all AI can be counterproductive, while broad and lax rules risk fostering a false sense of security without solving any concrete problem (UNESCO, 2026). The taxonomy's value is precisely that it does not tell any country where to arrive. It shows the terrain, so that a jurisdiction might begin with principles today and layer standards, transparency or risk tiers on top tomorrow.
The remaining four articles in this series each take one region of that terrain and examine it closely--beginning with the sharpest philosophical fork on the map: whether to govern AI by managing its risks or by guaranteeing people's rights.
References (APA style)
OECD. (2019). Recommendation of the Council on Artificial Intelligence. Organisation for Economic Co-operation and Development.
Simon, H. A. (1955). A behavioral model of rational choice. The Quarterly Journal of Economics, 69(1), 99–118.
UNESCO. (2021). Recommendation on the ethics of artificial intelligence. United Nations Educational, Scientific and Cultural Organization.
UNESCO. (2026). Governing AI: Nine emerging approaches for lawmakers worldwide. United Nations Educational, Scientific and Cultural Organization. Read the full report.
AI Disclosure: This article was drafted with the research assistance of AI (Claude) and edited under human editorial oversight. Its factual claims are drawn from UNESCO's 2026 policy brief Governing AI: Nine Emerging Approaches for Lawmakers Worldwide and the public legal instruments it cites. No private or personal data was accessed in its preparation.
→ Next week: Risk or Rights: Two Instincts for Protecting People from AI or Return to Series Hub
Comments
Post a Comment