The Beginner's Guide to AI Governance

Introduction

I recently finished the London School of Economics' programme on AI Law, Policy, and Governance. What follows is a series built from the notes I took along the way. This has been written for people who want to understand how AI is being regulated without reading the regulations themselves. The seven lessons roughly follow the six modules of the course, but I have split and rearranged the sequence where it made more sense to do so. I also added material to cover recent updates in the world of AI, since the info provided in the LSE course itself was current as of early to mid 2025.

This is not a substitute for the programme, so if this subject interests you, I do recommend you follow the course. Nothing here is endorsed by LSE, and the notes reflect my own reading on the subject. AI governance moves very quickly, so some material will go out of date in a few months - if you see something that is dated, please reach out to me here.

The guide is divided into seven lessons:

  • Lesson 1: Why AI is a policy problem
  • Lesson 2: How AI rules get made
  • Lesson 3: Six ways to govern AI
  • Lesson 4: Why the EU wrote the AI Act
  • Lesson 5: Complying with the EU AI Act
  • Lesson 6: China, the UK, and the US
  • Lesson 7: The International arena and the future of AI governance

Lesson 1: Why AI is a policy problem

A lot of people carry misconceptions about AI from things they see on films, or see on headlines. In the programme we learnt that AI is not simply another software that can answer your questions, and neither a "sentient presence", a robot that can make decisions on our behalf.

AI is the use of computational algorithms to interrogate data at speeds no human can match, learning through mathematics, and analysing and recommending in ways people cannot. So, searching for a word on this document is not AI, while Spotify serving you a playlist assembled from your listening history, and what other millions of users have preferred, is AI.

The point here is that "unless you've agreed to define AI in a common way", setting rules or frameworks for governance becomes very difficult, in Professor Evans' own words.

A GPT, moving unusually fast

Economists call innovations that shape entire economies rather than single industries as 'general purpose technologies', GPTs. Steam power, the internal combustion engine, electricity, IT, the internet, these are all GPTs. Jovanovic and Rousseau back in 2005, identified three markers of GPTs:

  • Pervasiveness - it shows up across industries and sectors
  • Improvement - performance rises over time while the cost of use stays low
  • Innovation spawning - it makes new products and processes possible that weren't feasible before

Artificial Intelligence has all three, but what makes it different from its predecessors is the speed of adoption. While electricity needs grids, and computing needed hardware, networks, and services, AI runs on general purpose technologies that already exist. There is no infrastructure lag to slow diffusion down.

N.B - The 'GPT' in general purpose technology is an economics term that predates AI entirely. It has nothing to do with the generative pre-trained transformer architecture behind OpenAI's ChatGPT.

The macro picture

Work - General purpose AI models can automate a lot of parts of jobs that depend on thinking, learning, memory etc. Roles with high exposure to this, like telemarketing or clerical work, are the most obvious. Reports of AI ending human labour are likely to be greatly exaggerated, and new roles will emerge that don't currently exist. At the same time, displaced workers actually reaching these new roles depends on reskilling rates and individual worker characteristics, which is a very different claim from "it will all work out".

Employers face their own version of the problem too - the productivity gains with AI are real, but only if the workforce is trained and workflows are redesigned. There are also ethical costs to manage like job losses, AI-enabled surveillance that can erode workers rights, and management by algorithm, which strips employees of their agency in how they do their own work.

Regulatory competition - A global study on public trust found that 71% of people expect AI to be regulated, which aligns with an accompanying finding (Gillespie et al., 2023), that 61% believe that AI's long-term impact on society is uncertain and unpredictable. Governments hear this, but because each country or jurisdiction sets its own rules, the field has become ripe for regulatory competition. States are building more favourable environments to attract investment, and companies engage in regulatory arbitrage by simply relocating to the friendliest one.

There is a positive thing in being the first in this space, however. The EU's experience with GDPR produced the "Brussels Effect", where large tech firms complied with the higher European standard and then applied it globally, because it would be more costly for them to have two different systems rather than one. The EU is now betting that the AI Act does the same thing.

Security - AI could really improve threat detection by parsing unstructured data at speed, surfacing insights early. The main three categories of risk are:

  • Miscalculation - LLMs generate fluent language but don't reason at human level, and cannot grasp how cause and effect relate. Over-reliance without a human-in-the-loop practice creates a real risk of misjudgement.
  • Escalation - An AI tool may read an adversary's activity as more hostile than a human would. Add autonomous weapon systems, which lower the effort and cost of conflict, and there's a plausible future where escalation could outpace our ability to de-escalate.
  • Proliferation - Chemical language models can generate novel molecules for drug discovery, and in the wrong hands, for biowarfare. The concern isn't only capability but access, where domain knowledge that once required years of study and experimentation is now far more readily available.

The public sector and the tech cold war - Governments want the efficiency gains from AI but carry a heavier duty of care, so the risks around data privacy, algorithmic transparency and discriminatory outcomes carry more consequences. Some have banned specific applications outright, such as facial recognition. Others have taken a lighter approach, with usage policies and codes of conduct built to leave room for innovation while still holding government to its duties on safety, fairness, and transparency. The UK's AI Opportunities Action Plan positions the country as an aspiring "AI superpower" on the back of being the third-largest AI market globally. The Dutch strategy, by contrast, is built around fundamental liberties and ethical boundaries.

Underneath all of this sits the US-China rivalry. Both have declared their intention to lead the space, with China aiming to be a global innovation centre in AI by 2030, and both use sanctions, embargoes, subsidies, and state investment as instruments. Other nations are pushed towards picking sides and building self-sufficient tech sectors, which is how techno-nationalism became the defining trait of the era. Despite this, the US and China share an entangled economic relationship and therefore full decoupling remains unlikely.

The micro picture

If we zoom in, the picture is messier. Hospitality and construction depend on physical work that a human must do or closely supervise. Any gains through AI sit at the margins, such as scheduling shifts, or optimising stock of raw materials, rather than in the work itself. Where the core work is not physical though, AI reaches much further in, with four areas in particular:

Regulatory compliance - Machine learning, natural language processing, and predictive analysis can monitor, detect, and prevent regulatory breaches, the financial sector is a prime example here, while generative AI helps businesses navigate the compliance process itself.

Capital investment - The two things AI changes in markets are speed and novel insight. Investment strategy has historically relied on structured data; AI can work across unstructured sources, bank announcements, legal documents, social media, financial reports etc, to improve predictive modelling. The same speed is also the risk, particularly during market stress, alongside cyber and market manipulation concerns. Notably, algorithmic trading systems are still used mainly as initial signals for human traders rather than replacements for them.

Profitability - Personalised service and round-the-clock chatbots reduce cost and raise service levels. At the same time, integrating AI into existing systems carries an upfront cost, staff need training in genuinely new skills, and workflows have to be redesigned before the technology pays for itself.

Human capital - This is where the empirical research is most interesting because it refuses to line up neatly and all point for more ongoing studies about this ever-evolving technology:

  • Strategic consultants using ChatGPT saw significant gains in speed, performance, and in completing the tasks, but only within the "frontier" of the model's capabilities. When the same people used it on everyday tasks sitting outside those capabilities, their performance got worse.
  • Customer support agents using AI resolved 14% more cases. The effect was concentrated among less-experienced, lower-skilled workers, who gained 34%, while experienced staff saw minimal improvement.
  • Freelancers doing writing and design work saw a decrease in both employment and monthly earnings. A track record of high-quality work did not protect them.

Nobody agrees what happens next

The problem with writing policy aimed at AI is that credible forecasts differ in both the degree and direction where this emerging technology will take us.

On economics, Goldman Sachs projected a 7% rise in annual GDP, around $7 trillion over a 10 year period. McKinsey puts the global boost at an annual $17.1 to $25.6 trillion. Daron Acemoglu, a Nobel laureate in economic sciences, estimates 1% GDP growth over ten years. Luciano Floridi argues the whole thing may be another tech bubble on the pattern of dot-com and telecoms.

On work, the most dramatic projections have roughly two-thirds of the jobs that were studied exposed to some degree of AI-enabled automation, with generative AI capable of substituting up to a quarter of current work. David Autor suggests AI could instead complement existing skills and help rebuild the middle class. Other research found only around 5% of US firms reporting any change in employment levels at all.

On elections, Emilio Ferrara warns that generative AI makes online interference materially more sophisticated. A separate study by Sam Stockwell at the Centre for Emerging Technology and Security found no evidence that AI-enabled disinformation or deepfakes meaningfully affected UK or European election results. Maybe less so now.

On capability, Dario Amodei has suggested (in October 2024) that an AI smarter than a Nobel Prize winner could arrive as early as 2026, though he accepts it may take much longer. Sam Altman puts superintelligence at "a few thousand days", with the same caveat. Chomsky, Roberts, and Watumull argue that statistical prediction will always be superficial and fails to emulate genuine intelligence. Gary Marcus holds that AGI isn't imminent and that the real harms are more mundane, like malfunctions, abuse of systems, concentration of power, and enormous resources misallocated to the wrong thing.

Each of these positions implies a completely different regulatory agenda. If Amodei is right, we should be planning for mass displacement and maybe some sort of Universal Basic Income. If Marcus is right, we should be writing antitrust policies.

We cannot write good rules for a technology whose trajectory the experts cannot agree on, but waiting for an agreement is itself a decision.

The EU AI Act is a cautionary tale. It had already been drafted when ChatGPT became accessible for everyone in November 2022, and it was drafted so narrowly that general purpose capabilities fell outside its scope, leaving the most consequential technologies exempt from regulation and liability despite the risks they carried. The fix required an overhaul of the legislative process and produced some controversy between EU institutions before consensus was reached. 

Who actually makes the rules

While it is tempting to imagine a government anywhere in the world, even dictatorships, as a single actor with a single view, in any central government there are three distinct communities:

  1. Economics, business, and growth - Treasury and business development officials, commerce and trade, science and technology, innovation.
  2. National security - Home and defence ministries, foreign ministries, security and intelligence agencies, all focused on risk.
  3. Justice and rights - Policy makers concerned with human rights, equality, inclusion and discrimination; asking who AI includes and excludes. This is considered to be the weakest community in the system, though even authoritarian states register concerns about disproportionate effects on minorities.

These three communities are not always in competition, but they frame the same opportunity and risk very differently. Around them sit regulators, who translate policy direction into rules that bind businesses, civil society and governments, and those who police privacy, data protection, and AI safety. The next layer is members of parliament and advisory councils, who shape debate and inject ideas. The final layer is what Professor Evans in the LSE called "the apex", such as the White House in the US, the Chinese presidency, or 10 Downing Street in the UK, which make the important calls such as on how much to invest, what is permitted, what access there should be to national data, and what guardrails apply.

Apex decisions set direction, but most of the action happens one or two levels down, inside regulators and individual line ministries, through individual pieces of legislation.

Four jurisdictions, four different bets

Is your country home to any of the firms building AI models, and how do they rank against global competitors? This is the main reason why jurisdictions diverge so sharply. A country that hosts the leaders writes the rules that protect them. A country that hosts none has less or blunter instruments available.

The United States is currently in the pole position, most of the major AI firms are based there, the intellectual property is largely American, and the training data and infrastructure largely American-operated. The policy goal for the US is to, naturally, cement this lead. Domestically that means a market-driven approach built on the "move fast, break things" model, with risk management distributed across federal agencies and no overarching legal oversight. This brings inconsistent policy, limited accountability, and weaker data protection. 

The European Union, has one major global AI firm, Mistral in France, and a much harder balancing act: benefit from the AI rollout, advantage European companies where possible, and protect European citizens, using regulation as the primary instrument. The EU moved early on AI, a regulatory framework proposal and impact assessment in 2021, an innovation package in 2024, the AI Act itself, as well as the latest simplification process, known as the AI Omnibus package, in mid 2026. The EU AI Act itself is the first legal framework of its kind, built on a risk-based model that divides AI systems into four tiers based on their potential harm, as well as a separate category for general purpose AI models. The EU is, at the same time, criticised that over-regulation is a barrier to European innovation.

The United Kingdom isn't an AI leader by the number of companies based there, but it is a significant contributor to AI policymaking, law, and intellectual property, and hosts many of the experts shaping the global debate. Its ambition is to be a superpower in safe innovation, while its constraints are a smaller economy and a later start. The creative and AI industries have been at odds over intellectual property for years, and in pledging to set out AI regulation, UK policy actors have committed to a copyright regime that somehow serves both sectors at once.

The Global South is "a rules taker rather than a rules maker", according to Professor Evans, since AI firms are concentrated in the Global North. Countries can ban any system from operating, but as he notes, banning is "a very blunt instrument", essentially, a binary choice between having a capability and not having it. The structural challenges are severe: 43% of the population in these countries are without internet access, have limited AI literacy, have systems that don't cater for many local languages, as well as shortages of skilled personnel, and a tension between data protection laws requiring local storage and the foreign investment those laws might deter. Boakye et al. (2025) describe the resulting power dynamic as marked by exploitation and the undermining of local control, a "new era of digital colonialism".

Underneath all four jurisdictions run two further threads - Data lakes, with the largest sitting in China, India, and potentially the US and the EU. These can determine who can train effectively, but two things hold them back: the law, which sets what data can be accessed, shared and used; and fragmentation, with data siting in separate databases across companies and public bodies.

The other thread is national champions, such as Microsoft for the US, DeepSeek for China, and Mistral for France. Professor Evans mentions the airline industry as the precedent, Boeing vs Airbus, with the same logic applying to AI here. Governments will always try to implement policy to the advantage of their national champions.

This strategy can also backfire. US export controls were designed to deny Chinese firms cutting-edge chips. Instead, they pushed Chinese competitors to innovate towards greater efficiency. In January 2025 DeepSeek R1 matched or outperformed OpenAI's o1 model at a fraction of the computing cost, shocking global markets, and raising a fresh set of economic and regulatory questions. In this case, trade policy met uncertain technology and technology won.

Anticipate > React

Traditional policymaking is reactive by design. It puts out fires, manages short term problems around the electoral cycle, and where health checks exist they sit inside long, inflexible cycles of review, research, analysis, and drafting. Policymaking also wants to be relatively sure about cause and effect before it acts, which is precisely the problem with AI.

Anticipatory policymaking works on two dimensions instead:

What is happening now. Ethical risks are addressed through data diversity and representative datasets, regular audits, bias detection tools, diverse development teams, and ethical AI training. In risk regulation, rather than trying to establish who caused what and whether the harm could have been foreseen after the event, it sets rules up front about how systems must be designed. That allows potential harms to be tackled strategically and collectively rather than one case at a time.

What is happening next. Forecasting AI's trajectory relies on several methods; Using stakeholder collaboration through expert surveys and consultations, and capturing not just consensus, but also disagreement, since disagreement flags the areas of uncertainty that may merit further research. Scenario planning and road mapping, and technological foresight, are the obvious next moves, but also weak signals, adjacent industries, and low-probability, high-impact outliers.

There have been attempts at coordinating this internationally. The Statement on Inclusive and Sustainable Artificial Intelligence for People and the Planet, agreed at the Paris AI Action Summit in February 2025, was signed by around sixty countries along with the EU, and the African Union Commission. The same summit also launched the Coalition for Sustainable AI, which brought together 91 parties from tech companies, countries, and international organisations, to address AI's environmental impact.

However, shared stated values like inclusive growth, sustainability, human rights, transparency, security, safety, and accountability, have so far coexisted with approaches that are, in practice, more protectionist than collaborative. The clearest evidence is who declined to sign in Paris; the United States, and the United Kingdom.

💡
Key takeaway from Lesson 1

AI is hard to regulate for three main reasons: there is no settled definition to anchor rules to, no expert consensus on where the technology is heading, and no single actor inside government with authority over the answer. Every jurisdiction is making a bet under uncertainty - the EU on rules, the US on markets, the UK on being the honest broker, the Global South on influence it does not yet have. Anticipatory policymaking is the proposed response - design for a range of futures instead of waiting for certainty.

This is a good point to explain some of the terms used throughout the next lessons.

Generative AI is the systems that produce new, seemingly original content, text, images, audio, code, from a prompt by drawing on patterns learned from enormous volumes of training data rather than retrieving a fixed answer.

Foundation models are the underlying models most generative AI is built on, trained broadly enough to be adapted to almost any downstream task. This is also why any fault in the training data ends up propagating into everything built on top. GPT-5.6 is one example, underpinning ChatGPT, and a list of other products.

Frontier models are simply which foundation models currently sit at the capability ceiling, the most powerful systems that exist today. The definition moves as the technology does. Today's frontier model, becomes an ordinary one tomorrow. Indeed, when I took the course GPT-4 was a frontier model (!)