International AI Diplomacy
Learning Objectives
After completing this lecture, you will be able to:
- Map the dominant institutional venues for international AI rule-making (OECD AI Policy Observatory, G7 Hiroshima AI Process, GPAI, the UN AI Advisory Body, ISO/IEC JTC 1/SC 42, the Council of Europe's Framework Convention on AI, and the network of national AI Safety Institutes).
- Compare the regulatory philosophies of the United States (OMB M-24-10, EO 14110, NIST AI RMF 1.0), the European Union (EU AI Act risk-tiers), the United Kingdom (pro-innovation white paper plus AISI), and the People's Republic of China (Interim Measures for Generative AI Services) and explain where interoperability is plausible.
- Identify the levers U.S. agencies (State, Commerce, DOD, DOE, NIST, OSTP, NSC, USTR) actually pull in AI diplomacy: export controls under the Bureau of Industry and Security, FIRRMA/CFIUS review, Wassenaar updates, the Critical and Emerging Technology list, bilateral AI dialogues, and standards participation.
- Translate treaty-level obligations into agency-level compliance artifacts: model cards that satisfy both NIST AI RMF GOVERN-1.2 and Article 13 of the EU AI Act; incident reporting that satisfies both OMB M-24-10 and the Hiroshima Code of Conduct.
- Draft a 24-month diplomatic engagement plan for a mid-sized agency (e.g., HHS, CBP, USDA) with named counterparts, forums, deliverables, and success metrics.
Key Topics Covered
- Treaties and agreements: Council of Europe Framework Convention on AI (CETS 225, opened for signature September 2024), Hiroshima AI Process Comprehensive Policy Framework, Bletchley and Seoul Declarations, UNESCO Recommendation on the Ethics of AI.
- Standards bodies: ISO/IEC 42001 (AI Management System), ISO/IEC 23894 (AI risk), ISO/IEC 5338 (AI system life cycle), ISO/IEC 24029 (robustness), IEEE 7000 series, ITU-T Focus Group on AI for Health, and the crosswalks NIST publishes between AI RMF and these standards.
- Multilateral coordination: AI Safety Institute network (U.S. AISI at NIST, UK AISI, Japan AISI, Singapore Digital Trust Centre, Canadian AISI), G7 Hiroshima Code of Conduct, GPAI expert working groups, OECD.AI observatory.
- Digital sovereignty and dependency: compute export controls (October 2022 and October 2023 BIS rules, the January 2025 AI Diffusion framework), cloud data residency, national LLM strategies (BLOOM, Mistral, Falcon, ERNIE), and sovereign cloud initiatives.
- Trade, security, and human-rights tensions: dual-use technology, semiconductor supply chains (TSMC, SMIC, ASML), Wassenaar Arrangement, Entity List, and the intersection of AI with the Biological Weapons Convention and the CCW autonomous weapons debates.
Why This Matters for Government
International AI diplomacy has moved from a State Department niche to a whole-of-government concern in the span of three years. The 2023 Bletchley Declaration, signed by 28 states including the United States, United Kingdom, China, India, and the European Union, committed governments to work together on frontier AI safety. The 2024 Seoul Summit broadened the commitment to 27 Safety Institutes or equivalent bodies. The Council of Europe's Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS 225) became the first legally binding international AI treaty in September 2024, with U.S., UK, EU, and Israel among early signatories. Every agency that procures or fields AI now inherits obligations that were negotiated in Paris, Geneva, Seoul, or Strasbourg.
For a federal program manager, this changes procurement, monitoring, and reporting. OMB Memorandum M-24-10 (March 2024) requires agencies to appoint Chief AI Officers, publish AI use-case inventories, and apply a tiered risk regime to rights-impacting and safety-impacting AI. Many of M-24-10's definitions track the EU AI Act's high-risk category, and NIST has published a crosswalk that explicitly links AI RMF subcategories to ISO/IEC 42001 controls. An agency that ignores international work will eventually be told by OMB or OSTP to adopt it anyway; an agency that engages early shapes the vocabulary.
Diplomacy is now how the U.S. protects its AI industrial base. The Bureau of Industry and Security's October 7, 2022 rule restricted exports of advanced semiconductors and manufacturing equipment to China; the October 17, 2023 rule closed the A800/H800 loopholes; the January 13, 2025 AI Diffusion framework classified countries into three tiers for compute access. These are technical measures with enormous diplomatic consequences. Allies reacted strongly; the Netherlands, Japan, and South Korea had to negotiate their own export regimes. Agencies like Commerce, Treasury (through CFIUS and FIRRMA), and State must now speak to each other fluently in both code and cable.
AI diplomacy also affects civil-rights commitments agencies make domestically. When the United States joined the Council of Europe's Framework Convention, it accepted principles on human oversight, remedies, and non-discrimination that echo the White House Blueprint for an AI Bill of Rights and EO 14110. Agencies that operate AI systems with rights-impacting effects (CBP with facial comparison, IRS with ID.me, SSA with fraud triage, HHS with eligibility prediction) will increasingly be asked to demonstrate conformity not only to FedRAMP and FISMA but to international standards like ISO/IEC 42001 and to the bias-testing obligations implied by the Convention.
The institutional landscape is thicker than treaties alone suggest. ISO/IEC JTC 1/SC 42, established in 2017, now has over thirty published AI standards and another fifty in draft. ISO/IEC 42001:2023 is the first certifiable AI management system standard, modeled on ISO/IEC 27001 for information security. NIST participates as the U.S. national body through ANSI, and the NIST AI RMF 1.0 Playbook explicitly aligns subcategories (GOVERN-1.1, GOVERN-1.2, MAP-2.3, MEASURE-2.7) with 42001 Annex A controls. The OECD AI Policy Observatory publishes the definition of an AI system that most governments, including the U.S., UK, EU, and Japan, now use; the updated November 2023 definition replaced the 2019 text and is being incorporated into both EO 14110 implementation guidance and the EU AI Act's final text. The Global Partnership on AI (GPAI), launched in 2020 at French and Canadian initiative, has working groups on responsible AI, data governance, future of work, and innovation and commercialization; GPAI merged with the OECD AI program in 2024 to avoid forum duplication. The G7 Hiroshima Process produced the International Guiding Principles and a Code of Conduct for organizations developing advanced AI systems; U.S. labs including OpenAI, Anthropic, Google DeepMind, Meta, Microsoft, and NVIDIA are implementing the Code voluntarily.
Instruments U.S. agencies use include export controls (15 CFR Part 744), investment screening under FIRRMA and EO 14105, standards diplomacy through NIST and NTIA, bilateral dialogues such as the U.S.-EU Trade and Technology Council AI Working Group and the U.S.-UK AISI Memorandum of Understanding signed April 2024, sanctions and Entity List actions through BIS and OFAC, and multilateral coordination led by State, OSTP, and NIST at the Seoul Summit (May 2024) and the Paris AI Action Summit (February 2025).
A concrete case: aligning NIST AI RMF with the EU AI Act. When the EU AI Act entered into force on August 1, 2024, U.S. companies operating in Europe and U.S. agencies procuring European or dual-listed AI systems faced a compliance puzzle. The Act's risk tiers (unacceptable, high, limited, minimal) partly overlap with OMB M-24-10's definitions of rights-impacting and safety-impacting AI, but terminology differs. Article 9 of the Act requires a risk management system analogous to NIST AI RMF's MAP-MEASURE-MANAGE functions. Article 10 on data governance resembles MAP-2 and MEASURE-2. Article 13 on transparency maps to GOVERN-3 and MANAGE-4. The TTC published a Joint Roadmap on Evaluation and Measurement Tools and a NIST-EU AI Office terminology document. For a U.S. federal program, such as CBP's Traveler Verification Service or USCIS's natural-language processing of I-589 asylum applications, the practical outcome is document once, present twice.
A second case: export controls and the 2022-2025 compute regime. The October 7, 2022 BIS rule was the most consequential U.S. AI diplomacy action in a generation. NVIDIA designed the A800 and H800 variants to stay just below the 2022 thresholds; the October 17, 2023 rule closed those loopholes; the January 13, 2025 Framework for AI Diffusion recast the regime around countries, establishing Tier 1 (close allies), Tier 2 (most countries, license-requiring with Validated End User options), and Tier 3 (arms-embargoed). Allied responses were mixed; the UK, Germany, and France objected to Tier 2 placement, and Brazil and India sought Tier 1-equivalent status.
A third case: the AI Safety Institute network. The U.S. AISI was established inside NIST under EO 14110 Section 4.1 in 2023 and received its charter in February 2024. By late 2024 the AISI consortium included over 280 organizations and had published pre-deployment evaluation findings for Anthropic's Claude 3.5 Sonnet and OpenAI's o1 models, produced jointly with the UK AISI. The November 2024 San Francisco convening of AI Safety Institutes produced a joint statement from the U.S., UK, Australia, Canada, France, Japan, Kenya, Singapore, South Korea, and the European Commission, creating an International Network of AISIs.
Common pitfalls: treating diplomacy as a principals-only activity; assuming English-language dominance means concept dominance; conflating soft law with no law; stovepiping diplomacy from domestic policy; ignoring standards because 'NIST will handle it'; forgetting the export-control dimension of cloud compute.
A 24-month engagement plan for a mid-sized agency such as HHS, CBP, or USDA: Months 1-3, establish an International AI Coordination cell reporting to the Chief AI Officer required under M-24-10. Months 4-6, inventory current international exposure and identify three priority forums. Months 7-12, dispatch representatives and co-author at least one technical document per forum. Months 13-18, align internal compliance to the standards you are helping to shape; adopt ISO/IEC 42001 in at least one program. Months 19-24, review and renew. Throughout, brief the Secretary quarterly; coordinate with State, NSC, OSTP, and OMB monthly; track Federal Register actions from BIS, OFAC, and CFIUS weekly.
Related Lectures
L5
5.1.1 -- National AI Competitiveness
240 min - Seminar + Research
L5
5.1.2 -- AI and National Security
180 min - Seminar
L5
5.1.3 -- AI and Democratic Governance
240 min - Seminar + Discussion
Skill.re