Where AI Is Governed Before It Is Legislated
By Javier
Surasky
Versión en
español (ES) el viernes
A
significant part of the struggle to lead the field of artificial intelligence
(AI) globally takes place far from the press, in spaces where experts,
companies, national standards bodies, and public officials negotiate
definitions, procedures, metrics, and certification systems. This is where we
place the focus of our AI power map in this new entry.
Two
organizations stand out in the field of technical standard-setting: the
International Organization for Standardization (ISO) and the International
Electrotechnical Commission (IEC). Their work occupies an intermediate zone
between technological production and state regulation: ISO/IEC turn general
principles into organizational processes, technical vocabularies, management
systems, and evaluation criteria that form part of the technical infrastructure
of AI (ISO, n.d.-b).
Formally,
ISO and IEC are made up of national standards bodies, an architecture that
reproduces the fiction of sovereign equality while the real capacity to exert
influence depends on resources that are unequally distributed.
International
standardization work on AI takes place mainly in the joint ISO/IEC subcommittee
responsible for general AI standardization and for coordination with committees
devoted to specific technologies, industries, and systems (International
Organization for Standardization [ISO], n.d.-a).
However,
participation in these organizations and their committees requires specialists,
institutional time, access to information, continuity in meetings, and the
capacity to submit proposals, all of which not every country has. Added to this
is the lobbying, open or otherwise, of large companies in the sector. Walter
Mattli and Tim Büthe (2003, p. 4) show that the outcomes of international
standardization depend on elements such as institutional structures and
national coordination capacity.
To this I
add what Mattli and Büthe call “first-mover advantage in internationalized
standards setting”: the advantage gained by actors able to intervene early and
structure the agenda (2003, p. 4). Whoever presents the first draft forces the
other participants to discuss within an already defined framework, and in the
field of AI this creates the risk that practices developed by large companies
or technologically advanced economies will become reference points from the
very beginning of standardization debates.
Even so,
the ISO/IEC power map cannot be reduced to states and companies. Academia also
produces concepts and methodologies there; consulting firms translate standards
into internal systems; certification bodies verify compliance, a topic to which
we will return; and civil society organizations work to strengthen rights-based
approaches, the consideration of impacts, and the perspectives of vulnerable
groups.
ISO/IEC is,
therefore, an infrastructure for coordination among multiple actors, and part
of its power is tied to the extent to which it succeeds in producing agreements
among them.
This logic
is especially important for AI, a field undergoing rapid transformation. In
this context, Araz Taeihagh points to the risk that “the speed and scale of
adoption of AI threatens to outpace the regulatory responses” (2021, p. 138),
given that many regulatory concepts are still only partially defined:
explainability, bias, trustworthiness, human oversight, data quality, and
acceptable risk do not have a single meaning, and defining them distributes
responsibilities and costs among actors in the ecosystem. As Busch (2011, p. 3)
says, “standards are where language and world meet,” and their definition is a
space of struggle over language.
Here a
critical problem emerges: translating concepts into processes is never a
neutral act and, as noted, in practice it is not exempt from the power
inequalities among those who take part in those translations.
For that
reason, certification should not be understood as an absolute declaration that
an AI system is ethical, safe, or respectful of human rights, but only as a
statement that the certified organization complies with certain formal
requirements. It also creates its own “intermediate layer,” made up of accreditation
bodies, certification bodies, auditors, and consultants that apply—and, in
applying, interpret—the requirements and the evidence provided by the
institution undergoing certification. In this way, those who define whether an
institution complies with a standard are also part of the power structure that
emerges from standardization.
All of this
takes place within voluntary ISO/IEC standards, since they do not impose any
obligation on companies: they will simply be “certified,” or they will not.
Still, a
standard can be incorporated into private contracts, supplier requirements in
public procurement, or even import and export rules: both a state and a company
can require those in their supply chain to adopt certain management systems,
turning a non-mandatory standard into a requirement for accessing markets,
financing, or contracts. This can be positive, but it also means that different
actors must adapt to those standards, even when they did not take part in
drafting them.
In AI, for
example, standards can facilitate interoperability across jurisdictions while
also creating barriers to entry by imposing accreditation costs that are
relatively higher for small companies than for large ones.
This
exposes another element to be analyzed when considering ISO/IEC’s place in the
AI power map, and one we have already touched on tangentially: technical
regulation always involves political elements, and for that reason it should
not be reduced to the pursuit of efficiency.
Marion
Ho-Dac warns that “fundamental-rights-oriented standards are not self-evident”
(2023, p. 2): standardization does not necessarily take fundamental rights as
its guide, nor can it resolve conflicts among legal principles. For that
reason, allowing expert knowledge on technical issues being standardized to
monopolize the definition of standards that affect social and working life,
among other areas, is a mistake with potentially serious consequences.
Standards
can complement law, but they cannot replace it.
The power
of ISO/IEC begins before the law, when the concepts with which states will
later legislate are given shape. Before the law says what is permitted or
prohibited, and under what conditions, standards have already begun to organize
the boundaries of what is normal, what is acceptable, and the responsibilities
involved in the development, deployment, and use of AI, because “standards are
the recipes by which we create realities” (Busch, 2011, p. 2).
Basic data
- ISO was created in 1947 and is headquartered in Geneva, Switzerland. It is an international non-governmental organization that currently brings together representatives of 176 national standards bodies. Although its name is International Organization for Standardization, the organization uses “ISO” as a short name derived from the Greek isos, meaning “equal.”
- IEC was founded in 1906 and is also headquartered in Geneva, Switzerland. It specializes in international standards for electrical, electronic, and related technologies and works through national committees. It also has an Affiliate Country Programme, designed to facilitate the participation of developing or newly industrializing countries.
- ISO and IEC jointly develop information technology standards through the ISO/IEC JTC 1 committee, created in 1987. Its Subcommittee 42 functions as the main joint space for general standardization on artificial intelligence globally.
- The main strength of ISO/IEC lies in its capacity to transform general principles into internationally recognized technical and organizational procedures. ISO/IEC 42001:2023 is one of the central standards in the ecosystem, establishing requirements for AI management systems within organizations.
- Its main vulnerability lies in inequalities of participation, the limited transparency of some processes, access costs, and the potential predominance of large companies and technologically advanced countries.
- The construction of standards produces a tension between technical effectiveness and democratic legitimacy, because it combines technical elements with political decisions.
References
Busch, L.
(2011). Standards: Recipes for reality. MIT Press.
Ho-Dac, M.
(2023). Considering fundamental rights in the European standardisation of
artificial intelligence: Nonsense or strategic alliance? In K. Jakobs (Ed.), Joint
proceedings EURAS & SIIT 2023. Verlag Günter Mainz. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4633788
International
Organization for Standardization. (2023). ISO/IEC 42001:2023. Information
technology—Artificial intelligence—Management system. https://www.iso.org/standard/42001
International
Organization for Standardization. (s. f.-b). Standards by ISO/IEC JTC 1/SC
42: Artificial intelligence. https://www.iso.org/committee/6794475/x/catalogue/
Mattli, W.,
& Büthe, T. (2003). Setting international standards: Technological
rationality or primacy of power? World Politics, 56(1), 1–42. https://www.jstor.org/stable/25054244
Taeihagh,
A. (2021). Governance of artificial intelligence. Policy and Society, 40(2),
137–157. https://doi.org/10.1080/14494035.2021.1928377
.png)