Reading Deloitte’s analysis of global AI regulations gave me a language I didn’t know I was missing. I’ve spent the past year inside what looks, from the outside, like a swirl of discussion groups and Slack threads exploring alignment, working groups on AI safety, policy and governance.
Useful - yes. But I couldn’t quite name the moment we’re in.
Deloitte’s analysis gave me a simple phrase that finally fit: we are largely in an understanding phase. Governments are convening committees, mapping risks, and building basic fluency before attempting to regulate. Their scan of 1,600+ AI-related policy instruments across 69 countries and the EU shows a common pathway:
understand → grow → shape.
It’s less a race than a choreography - most states learn, then invest, then try to steer. (Deloitte) What’s easy to miss is that these phases overlap.
Understanding doesn’t end when shaping begins. Deloitte’s own language is explicit about the bleed-through: countries continue growth efforts “for decades,” even as they tentatively move into shaping.
That description matches what many nations are doing today, learning in one hand while, with the other, drafting rules that will outlast their current understanding.
I see two lanes, one road
The United States is a good example of living in two lanes at once. On one lane, the government is still learning and publishing voluntary guardrails (e.g., NIST’s AI Risk Management Framework 1.0).
On the other, it is already shaping through procurement guidance (OMB’s M-24-10), agency policy, and controls on sensitive use cases and exports. Voluntary risk guidance; binding acquisition rules. Learning and steering in parallel. (NIST)
Deloitte’s research contrasts this U.S. posture with the EU’s more prescriptive path. Both are risk-weighted in spirit, but in practice the EU AI Act uses binding obligations, including significant restrictions on real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), whereas the U.S. leans on non-binding frameworks plus sectoral law and procurement. Different legal cultures, different instruments - same desire to manage risk.
Where Risk labels and outcomes collide
Here’s where my thinking shifted...
We talk about risk-based regulation as though it were the reliable default. But risk labels are blunt; they drift as contexts change. Consider facial recognition.
The EU AI Act treats real-time remote biometric identification in public spaces as an “unacceptable risk.” Yet at the same time, the EU is rolling out the Entry/Exit System (EES), which will use facial recognition and fingerprint scanning at airports and WILL be rolled out progressively across 29 countries over six months.
For millions of travelers, biometric checks will soon be routine - the operational backbone of Schengen border control.
The U.S., meanwhile, has long normalized airport face-matching through CBP’s “Simplified Arrival.” I’ll admit: when I returned from a long trip recently, I was glad to skip the long line and walk through Global Entry.
This is the collision: the same underlying technology sits in an “unacceptable” class in one regime, while in practice becoming indispensable in another.
Risk categories meet outcomes that matter to the system - throughput, security, error rates, civil liberties. And that friction isn’t theoretical. It’s already baked into how we move across borders.
A major standout statistic from Deloitte’s research, was…
When they examined policies globally, only about 1% of regulations were outcome-based or risk-weighted, and NONE were both.
In other words, the space many of us assume exists - measurable outcomes and proportionate risk - barely shows up in current law. It means if we want regulation that ages well, we need to build the measurement scaffolding that makes “outcome-based” real.
The overlooked levers hiding in plain sight
Another lesson I took from the Deloitte work is that the most powerful tools to steer AI may be adjacent, not AI-specific. Their database shows that only 11% of the 1,600+ instruments were focused on AI-adjacent areas like data protection, cybersecurity, consumer protection, IP, and competition, even though those regimes shape what AI can learn, how it can be secured, and who gets to deploy it at scale. We over-index on “AI laws” and under-use mature levers that already exist as discussed in the same (Deloitte) research.
That observation travels well beyond rich democracies. In countries still standing up basic data governance, competition policy, and cyber hygiene, adjacent capacity is not a luxury; it’s a MUST-HAVE. Without it, “AI regulation” becomes theater.
Government wears three hats
Perhaps one of Deloitte’s most useful reminders is institutional, not ideological, government is not just a regulator. It is also an infrastructure provider and a buyer with market-shaping power. Historically, public purchasing helped push cloud providers toward stronger standards; similarly, technical infrastructure (compute sharing, representative datasets) and human capital pipelines can move an entire field without a single prohibition.
The United States is gesturing at this again in OMB’s acquisition guidance, for example, it ties buying AI to risk practices. But the opportunity is larger than compliance - it’s about structuring demand to reward trustworthy systems.
Beyond Deloitte’s research…
Here’s what the geopolitics of AI Technology transfer are telling us
When you Zoom out from domestic policy to the global AI supply chain, a harder question surfaces: Who exports governance models along with code?
Empirical work from Brookings finds that autocracies and weak democracies are disproportionately likely to import facial-recognition AI from China, especially in years with domestic unrest. (Brookings)
RAND’s new dataset on China’s officially financed AI projects in the Global South maps how tools and infrastructure travel together. The pattern is messy and not purely ideological - but the gravitational pull is clear.
Technology moves with financing and with defaults, and those defaults carry governance. (Brookings)
This is where the “understand → grow → shape” model has limits. For technology-receiving nations, the growth phase often arrives as imports - turnkey platforms, bundled surveillance suites, subsidized connectivity, vendor-managed “AI capacity building.” Understanding and shaping can find themselves outsourced.
What the Deloitte piece clarified for me
Three convictions hardened as I read and cross-checked:
Phases overlap by design, not by accident. The choreography is recursive - we learn while steering and revise while deploying. Pretending otherwise leads to brittle rules or performative bans. (Deloitte)
Outcome-based regulation is under-built. We invoke it often; we operationalize it rarely. If we want it to work, we need metrics, auditing capacity, and legal plumbing that updates as models update. (Deloitte)
Adjacent law is first-order, not peripheral. Data protection, cybersecurity, consumer and competition policy are not side gigs; they should be the support pillars for AI Governance. Today, we’re under-using them. (Deloitte)
None of this argues against risk-weighting or against bright-line prohibitions where harms are intolerable. It argues for a thicker toolkit and a deeper respect for implementation details. Ultimately…
The hard part isn’t writing principles.
It’s building institutions that can measure, adapt, and enforce them.
A Small Window into What I’m Building
All of this connects to work I’ve been developing quietly. I come up with ambitious ideas all the time - some may sound crazy at first. This one doesn’t feel crazy. It feels timely.
I call it the Responsible AI Transfer (RAIT) Framework.
The premise is simple, but uncomfortable: AI doesn’t travel alone. It travels with financing, vendor defaults, data flows, and governance assumptions. When a ministry signs an AI deal, it may be importing a governance model it didn’t debate and can’t maintain.
Here’s the question RAIT poses:
What if the transfer of progressively more advanced AI capabilities was coupled with the parallel growth of governance capacity - legal, institutional, and technical measured against clear, auditable outcomes?
This is not the - “you can’t have this.” unless you have this. Instead, a ladder process that is staged and transparent, where technology transfer is paired with capacity-building obligations and local job creation. A pathway for nations to move from passive adopters to responsible regulators, and eventually, builders. (If that sounds like blending risk-weighted and outcome-based approaches, that’s intentional.)
The key here is realism: companies want to sell, not safeguard. Left to markets alone, powerful systems will flow without concern for governance readiness. RAIT doesn’t depend on corporate goodwill - it hardwires responsibility into the deal itself. Governance becomes a term of trade, not an optional afterthought.
A framework for shared responsibility in technology transfer - codified, not ad hoc.
For now, I’ll leave you with the why:
Because in a world where outcome-based regulation is rare, where adjacent law is underused, and where the default transfer model can amplify surveillance and dependency, responsible AI transfer is not charity. It’s about protecting global security, democracy, and fair competition by making sure AI is governed well everywhere it goes.
If this caught your attention, you’ll likely want the next piece: a concrete RAIT walkthrough - how the stages work, what counts as capacity, and how to verify without paternalism.
That’s the door I’m opening next. Come with me.
Leave your comment below: Do you believe responsibility in AI transfer should come from companies, governments, or both?
If you have not yet subscribed to this substack - don’t get stuck , come join us as we unlock all things ai policy and governance.



