The AI Power Map #13: ISO/IEC

Where AI Is Governed Before It Is Legislated

By Javier Surasky

Versión en español (ES) el viernes

International network of artificial intelligence standards with technical documents, certification seals, expert committees, companies, governments, and a balance between regulation, rights, and technological power.

A significant part of the struggle to lead the field of artificial intelligence (AI) globally takes place far from the press, in spaces where experts, companies, national standards bodies, and public officials negotiate definitions, procedures, metrics, and certification systems. This is where we place the focus of our AI power map in this new entry.

Two organizations stand out in the field of technical standard-setting: the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Their work occupies an intermediate zone between technological production and state regulation: ISO/IEC turn general principles into organizational processes, technical vocabularies, management systems, and evaluation criteria that form part of the technical infrastructure of AI (ISO, n.d.-b).

Formally, ISO and IEC are made up of national standards bodies, an architecture that reproduces the fiction of sovereign equality while the real capacity to exert influence depends on resources that are unequally distributed.

International standardization work on AI takes place mainly in the joint ISO/IEC subcommittee responsible for general AI standardization and for coordination with committees devoted to specific technologies, industries, and systems (International Organization for Standardization [ISO], n.d.-a).

However, participation in these organizations and their committees requires specialists, institutional time, access to information, continuity in meetings, and the capacity to submit proposals, all of which not every country has. Added to this is the lobbying, open or otherwise, of large companies in the sector. Walter Mattli and Tim Büthe (2003, p. 4) show that the outcomes of international standardization depend on elements such as institutional structures and national coordination capacity.

To this I add what Mattli and Büthe call “first-mover advantage in internationalized standards setting”: the advantage gained by actors able to intervene early and structure the agenda (2003, p. 4). Whoever presents the first draft forces the other participants to discuss within an already defined framework, and in the field of AI this creates the risk that practices developed by large companies or technologically advanced economies will become reference points from the very beginning of standardization debates.

Even so, the ISO/IEC power map cannot be reduced to states and companies. Academia also produces concepts and methodologies there; consulting firms translate standards into internal systems; certification bodies verify compliance, a topic to which we will return; and civil society organizations work to strengthen rights-based approaches, the consideration of impacts, and the perspectives of vulnerable groups.

ISO/IEC is, therefore, an infrastructure for coordination among multiple actors, and part of its power is tied to the extent to which it succeeds in producing agreements among them.

This logic is especially important for AI, a field undergoing rapid transformation. In this context, Araz Taeihagh points to the risk that “the speed and scale of adoption of AI threatens to outpace the regulatory responses” (2021, p. 138), given that many regulatory concepts are still only partially defined: explainability, bias, trustworthiness, human oversight, data quality, and acceptable risk do not have a single meaning, and defining them distributes responsibilities and costs among actors in the ecosystem. As Busch (2011, p. 3) says, “standards are where language and world meet,” and their definition is a space of struggle over language.

Here a critical problem emerges: translating concepts into processes is never a neutral act and, as noted, in practice it is not exempt from the power inequalities among those who take part in those translations.

For that reason, certification should not be understood as an absolute declaration that an AI system is ethical, safe, or respectful of human rights, but only as a statement that the certified organization complies with certain formal requirements. It also creates its own “intermediate layer,” made up of accreditation bodies, certification bodies, auditors, and consultants that apply—and, in applying, interpret—the requirements and the evidence provided by the institution undergoing certification. In this way, those who define whether an institution complies with a standard are also part of the power structure that emerges from standardization.

All of this takes place within voluntary ISO/IEC standards, since they do not impose any obligation on companies: they will simply be “certified,” or they will not.

Still, a standard can be incorporated into private contracts, supplier requirements in public procurement, or even import and export rules: both a state and a company can require those in their supply chain to adopt certain management systems, turning a non-mandatory standard into a requirement for accessing markets, financing, or contracts. This can be positive, but it also means that different actors must adapt to those standards, even when they did not take part in drafting them.

In AI, for example, standards can facilitate interoperability across jurisdictions while also creating barriers to entry by imposing accreditation costs that are relatively higher for small companies than for large ones.

This exposes another element to be analyzed when considering ISO/IEC’s place in the AI power map, and one we have already touched on tangentially: technical regulation always involves political elements, and for that reason it should not be reduced to the pursuit of efficiency.

Marion Ho-Dac warns that “fundamental-rights-oriented standards are not self-evident” (2023, p. 2): standardization does not necessarily take fundamental rights as its guide, nor can it resolve conflicts among legal principles. For that reason, allowing expert knowledge on technical issues being standardized to monopolize the definition of standards that affect social and working life, among other areas, is a mistake with potentially serious consequences.

Standards can complement law, but they cannot replace it.

The power of ISO/IEC begins before the law, when the concepts with which states will later legislate are given shape. Before the law says what is permitted or prohibited, and under what conditions, standards have already begun to organize the boundaries of what is normal, what is acceptable, and the responsibilities involved in the development, deployment, and use of AI, because “standards are the recipes by which we create realities” (Busch, 2011, p. 2).

Basic data

  • ISO was created in 1947 and is headquartered in Geneva, Switzerland. It is an international non-governmental organization that currently brings together representatives of 176 national standards bodies. Although its name is International Organization for Standardization, the organization uses “ISO” as a short name derived from the Greek isos, meaning “equal.”
  • IEC was founded in 1906 and is also headquartered in Geneva, Switzerland. It specializes in international standards for electrical, electronic, and related technologies and works through national committees. It also has an Affiliate Country Programme, designed to facilitate the participation of developing or newly industrializing countries.
  • ISO and IEC jointly develop information technology standards through the ISO/IEC JTC 1 committee, created in 1987. Its Subcommittee 42 functions as the main joint space for general standardization on artificial intelligence globally.
  • The main strength of ISO/IEC lies in its capacity to transform general principles into internationally recognized technical and organizational procedures. ISO/IEC 42001:2023 is one of the central standards in the ecosystem, establishing requirements for AI management systems within organizations.
  • Its main vulnerability lies in inequalities of participation, the limited transparency of some processes, access costs, and the potential predominance of large companies and technologically advanced countries.
  • The construction of standards produces a tension between technical effectiveness and democratic legitimacy, because it combines technical elements with political decisions.

 

References

Busch, L. (2011). Standards: Recipes for reality. MIT Press.

Ho-Dac, M. (2023). Considering fundamental rights in the European standardisation of artificial intelligence: Nonsense or strategic alliance? In K. Jakobs (Ed.), Joint proceedings EURAS & SIIT 2023. Verlag Günter Mainz. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4633788

International Organization for Standardization. (2023). ISO/IEC 42001:2023. Information technology—Artificial intelligence—Management system. https://www.iso.org/standard/42001

International Organization for Standardization. (s. f.-b). Standards by ISO/IEC JTC 1/SC 42: Artificial intelligence. https://www.iso.org/committee/6794475/x/catalogue/

Mattli, W., & Büthe, T. (2003). Setting international standards: Technological rationality or primacy of power? World Politics, 56(1), 1–42. https://www.jstor.org/stable/25054244

Taeihagh, A. (2021). Governance of artificial intelligence. Policy and Society, 40(2), 137–157. https://doi.org/10.1080/14494035.2021.1928377