Two Templates, One Rulebook: What WAICO Means for AI Governance Outside Europe
By Jean-Hugues Migeon
What is WAICO?
WAICO is the World Artificial Intelligence Cooperation Organization, an intergovernmental body for artificial intelligence that did not exist a month ago. Twenty-nine states signed its founding agreement in Shanghai on 16 July 2026, on the eve of the annual World Artificial Intelligence Conference. China proposed it, hosts its secretariat in Shanghai, and has aimed it deliberately at the Global South. Chinese Foreign Minister Wang Yi signed for China, United Nations Secretary-General António Guterres attended the ceremony, and Xi Jinping announced the organization from the conference stage the following day.
If you have not heard of it, that is partly by design and partly because nobody in your regulatory perimeter joined. No EU member state signed. Neither did the United States, the United Kingdom, Japan, South Korea, Canada or Australia. The founding roster is Brazil, Indonesia, South Africa, Kenya, Malaysia, Vietnam, Pakistan, Russia, Kazakhstan, Ethiopia, Senegal, Algeria, Serbia, Oman and a dozen others, alongside China.
The most important thing to establish early is what WAICO is not. It is not a regulator. It has no legislative competence, no supervisory authority, no penalty regime and no conformity assessment machinery. Nobody will ever be fined by WAICO, audited by WAICO or required to hold a WAICO certificate. If a slide in your AI governance roadmap has a line item for WAICO compliance, delete it.
Why a Western compliance team should care anyway
The headlines framed WAICO as a China-led rival to Western AI governance. That framing is accurate and almost useless, because it invites you to file the story under geopolitics and move on. The reason to pay attention is narrower and more practical.
Two templates are now circulating for how a country that has not yet written an AI law should write one. The European Union supplies one by diffusion: it drafted a detailed rulebook, multinationals build to it because they must, and legislatures elsewhere borrow the structure because adapting a tested framework is cheaper than inventing one. Research published by the Thomson Reuters Foundation on 28 July 2026 measures how far that spillover has already travelled. WAICO supplies the other, and it comes bundled with training places, cooperation centres and infrastructure support rather than implementation costs.
My read is that this contest gets decided in two unglamorous places, neither of which is a summit communiqué: the technical committees of ISO and IEC, and the national AI bills currently in draft in WAICO member states. Both reach your control framework. Neither will announce itself.
What the founding documents actually commit to
Two texts define the organization. The first is the Action Plan for Global Governance of Artificial Intelligence, released on 26 July 2025 and distributed through Xinhua. It frames AI as an international public good, invokes the UN Pact for the Future and its Global Digital Compact, and sets out thirteen action points built on six principles: serving the people, respecting sovereignty, development orientation, security and controllability, fairness and inclusiveness, and open cooperation. The second is Xi's 2026 keynote, which condenses China's position into four points.
Most of the thirteen points are development policy: infrastructure, industrial adoption, energy efficiency, capacity building. Four have teeth for anyone running an AI governance programme.
- Point 6, data. Calls for lawful, orderly and free data flows, a global data-sharing mechanism and jointly built datasets, while also naming privacy and data security. A global data-sharing mechanism and Chapter V of the GDPR are not compatible ambitions, and any organization straddling both regimes will live with that tension rather than resolve it.
- Point 8, standards. Commits to building consensus on standards and norms through the ITU, ISO and IEC. This is the line that matters most, and the one nobody wrote about.
- Point 10, security governance. Describes classified and hierarchical management, risk testing and evaluation systems, threat-information sharing and traceability of AI services against misuse. Strip the vocabulary and this is risk tiering with conformity testing attached, structurally close to what the EU AI Act does, arrived at independently.
- Point 12, mutual recognition. Calls for mutual recognition of security assessments between leading and developing AI economies. Recognition is the question every audit function eventually asks: whose assessment travels, and how far.
Xi's keynote adds one clause worth reading twice. It calls for legal frameworks, technology monitoring, risk warning and emergency response, and for AI to remain under human control, while opposing what it describes as stretching the concept of national security in AI or putting one country's security above everyone else's. That is aimed at export controls, and it marks where the friction with Washington will sit.
Alongside the agreement, China committed five thousand training places in AI workshops for developing countries, AI application cooperation centres for ASEAN, the Arab League, the African Union, CELAC, the Shanghai Cooperation Organisation and the BRICS group, and deployment of the "Mazu" weather early-warning system in thirty countries. Capacity building is the currency WAICO trades in, and it is a currency the EU does not offer at comparable scale.
Transmission mechanism one: the standards committees
Point 8 routes WAICO's normative ambitions through the ITU, ISO and IEC. Those are the bodies that produced ISO/IEC 42001, the AI management system standard, and ISO/IEC 23894, the AI risk management guidance. Your customers already ask about 42001 in procurement questionnaires. Your auditors already work from it.
International standards are written by national standards bodies voting in technical committees. A coordinated bloc of twenty-nine national delegations, with a permanent secretariat to align positions before meetings, is a material force in that process, and it does not need to win outright to matter. Shaping the scope of a working group, the definition of a term or the acceptance criteria in a conformity clause is enough to change what an audit against that standard looks like three years later.
This cuts both ways, and I think the optimistic reading is underrated. Greater WAICO engagement in ISO/IEC could produce genuine international convergence, which would be excellent news for anyone maintaining one control set across many markets. The pessimistic reading is that standards written to accommodate irreconcilable positions come out vaguer, which pushes interpretive burden onto the organizations implementing them. Either way, ISO/IEC 42001 gains strategic importance rather than losing it. It is the layer where the two systems are most likely to meet.
Transmission mechanism two: recognition of assessments
Point 12 deserves attention from audit functions specifically, because recognition regimes decide whether work you have already done counts anywhere else. That is the difference between one assurance exercise and several.
Nothing in the EU AI Act contemplates recognising a conformity assessment carried out under a WAICO-aligned framework, and I would not expect that to change. The Act's high-risk regime runs through notified bodies designated by member states, and the Omnibus that entered into force on 27 July 2026 simplified procedures for those bodies without opening any door to external recognition.
So plan for dual assurance in WAICO member markets that build their own assessment regimes. If you operate AI systems in Indonesia, Brazil, South Africa or Kenya, assume a local assessment that neither substitutes for your EU conformity work nor is substituted by it. Duplicated assessments are survivable. Duplicated evidence gathering is what makes them expensive, and that part is avoidable.
Pax Silica is not the counterweight
The instinctive Western answer to WAICO is Pax Silica, the United States initiative launched in December 2025 under Under Secretary for Economic Affairs Jacob Helberg, which held its second summit in Washington in June 2026 and has been steadily adding partners. The symmetry that commentary implies does not exist. Pax Silica is a supply chain and economic security initiative covering critical minerals, energy inputs, semiconductors, AI infrastructure and logistics. It proposes nothing about how AI systems should be built, assessed or supervised.
On the specific question of who supplies the governance template for countries writing their first AI law, the United States is not in the contest. Europe is, and it is competing with a legal text rather than a development offer. For a ministry with limited supervisory capacity, choosing between a complete rulebook that arrives with implementation cost and a cooperation framework that arrives with funding is a real decision, not a rhetorical one.
One shift in the technical ground is worth noting alongside this. Chinese open models, including those from DeepSeek and Z.ai, went from under ten percent of tokens used by United States companies in mid-2025 to roughly forty percent in mid-2026. Open weights travel wherever licences and budgets allow, and governance conversations tend to follow the stack.
Where the two templates collide, this quarter
The timing here is unusually legible. Kenya, a founding WAICO member, has its draft Artificial Intelligence and Other Emerging Technologies Policy open for public participation right now through the Ministry of Information, Communications and the Digital Economy. Brazil, Indonesia, South Africa, Malaysia and Vietnam are each at some stage of building a national framework.
The inaugural Africa AI Governance Index, published in July 2026 and topped by Rwanda, found that African states are writing AI strategies considerably faster than they are funding, staffing or enforcing them. That gap is exactly what a capacity-building offer is designed to fill, and it explains why WAICO's training places and cooperation centres are a more serious instrument than they look on paper.
Whichever template those laws borrow from sets what multinationals get assessed against across markets representing a large share of global population and a fast-growing share of AI deployment. A state that borrows the AI Act structure hands you a familiar mapping problem. A state that borrows the classified and hierarchical management language of the Action Plan hands you an unfamiliar one, with different documentation expectations and a different relationship between regulator and assessed entity. Nobody can tell you yet which way any individual country goes, and it will not go the same way everywhere. Hedging is the only defensible posture.
The playbook
None of what follows is WAICO-specific work, which is the point. The correct answer to regulatory fragmentation is not one programme per framework. It is one control set you can aim at whichever framework arrives.
- Do not open a WAICO workstream. Nothing to comply with, nothing to file, nothing to certify. Give it to whoever runs regulatory horizon scanning and leave it there.
- Find out which of your AI systems run in WAICO member states. Most organizations cannot answer this within a day. If yours cannot, that inventory gap is the first thing to close, and it pays back against every framework rather than this one.
- Treat ISO/IEC 42001 as the hedge. Both camps route their standards ambitions through ISO/IEC, which makes the AI management system standard the likeliest common ground. Certification or credible alignment to it is the closest thing to a portable answer available today.
- Map controls to requirements, not to regulations. A control satisfying an AI Act documentation duty usually satisfies the equivalent expectation in Korea's AI Framework Act, the NIST AI RMF and whatever Kenya or Brazil enacts. Maintain each control once and record which requirements it evidences. A separate binder per regulation is how governance budgets get spent without governance improving.
- Budget the evidence, not the audits. If a market requires a local assessment you will do it. The avoidable cost is re-gathering the same evidence for each one.
- Watch the committees, not the communiqués. Announcements from Shanghai tell you about intent. ISO/IEC and ITU working group activity tells you what changes in your audit scope. If your organization sits on a national standards body, that seat is worth more this year than last.
- Respond to the consultations that affect you. Kenya's is open. A public consultation is the cheapest point at which a company can influence a framework it will later be assessed against, and almost nobody uses it.
- Keep the European work on schedule. The Omnibus pushed high-risk obligations to December 2027 and August 2028, but Article 50 transparency duties apply from 2 August 2026 and the AI Office's power to fine general-purpose AI providers becomes exercisable the same day. Nothing happening in Shanghai moves those dates.
The bet worth making
Strip away the geopolitics and every serious AI framework in circulation asks for the same four things: know which AI systems you have, understand what each one can do to people, hold evidence that your controls work, and be able to produce that evidence when someone asks. The politics diverge. The underlying demand converges.
That is why the winning strategy here is not forecasting which template prevails. It is refusing to bet at all. Anove built insAIght for exactly this: controls and evidence held once, mapped to the EU AI Act, ISO/IEC 42001, the NIST AI RMF and whatever lands next, so a new framework becomes a mapping exercise rather than a new programme. When a jurisdiction adds a requirement, the question becomes which existing controls already answer it. If you want a quicker read on how exposed you are before committing to any of that, ExplAIn will tell you where the AI tools your teams already use would struggle under scrutiny.
WAICO will not regulate anyone. It will try to shape the standards regulators lean on and the laws that have not been written yet, with twenty-nine states, a Shanghai secretariat and a funded capacity-building programme behind the attempt. Europe is answering with diffusion rather than diplomacy, and doing it effectively. Both are playing a long game, and neither will produce a clean result. Governance built to survive either outcome is not a hedge against geopolitics. It is just competent governance, and it happens to be geopolitics-proof.
Sources: Reuters and Xinhua on the 16 July 2026 signing; Al Jazeera, "China's Xi Jinping launches new AI alliance: What is it?" (17 July 2026); Action Plan for Global Governance of Artificial Intelligence (Xinhua, 26 July 2025); Elizabeth Gibney in Nature 648 (December 2025); Arindrajit Basu, "China's Pivot on Global AI", Carnegie Endowment (May 2026); US Department of State on Pax Silica and the Second Pax Silica Summit (June 2026); Thomson Reuters Foundation research on EU AI Act influence (28 July 2026); Kenyan Ministry of Information, Communications and the Digital Economy consultation (July 2026); European Commission, "AI Omnibus enters into force" (27 July 2026).
Learn more
- insAIght: Anove's AI governance and risk platform, built for framework-mapped, audit-ready compliance.
- ExplAIn: check whether the AI tools you already use would stand up to scrutiny.
- EU AI Act 2026: What the Digital Omnibus Delayed, and What Still Applies This August: the state of the European rulebook the rest of the world is borrowing from.
- India's AI Catch-Up: Innovation-First Governance: a large economy building its own alternative to the EU model.
- Stop Flying Blind with AI: Why You Need an AI Management System: why ISO/IEC 42001 is the portable answer to fragmentation.
Book a demo to see how insAIght keeps your AI governance audit-ready across the EU AI Act, ISO/IEC 42001 and whichever national framework lands next in the markets you operate in.