Position: AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws
06:00 · August 18, 2026 · arXiv cs.AI RSS

As Artificial Intelligence (AI) systems become deeply integrated into critical global infrastructure, the urgency for robust governance frameworks has intensified. However, current approaches, led by jurisdiction-specific laws, policies, and voluntary frameworks such as the EU AI Act, China's algorithm governance, and the NIST AI Risk Management Framework in the U.S., create a fragmented regulatory landscape. In this position paper, we argue that \textbf{\textit{AI governance must be built not on laws alone, but on ISO-like interoperability protocols that enable standardized, machine-readable risk communication across borders}}. Drawing on the success of the GDPR, which was operationalized through standards like ISO 27001 and Privacy by Design, we propose the development of standardized AI \textit{nutrition labels} containing unified metrics for bias, energy usage, and data provenance to facilitate cross-jurisdictional compliance. These manifests would lower barriers for small and medium enterprises (SMEs), reduce redundant regulatory efforts, and build public trust. The paper addresses concerns that standards may stifle innovation by advocating for modular, versioned protocols designed to evolve in tandem with technological change. Overall, we call for a shift from siloed legal compliance toward interoperable technical conformance, enabling a shared global language for responsible AI deployment.
Summary
As AI systems integrate into critical infrastructure worldwide, governance efforts have centered on jurisdiction-specific rules such as the EU AI Act, China’s algorithm regulations, and the NIST AI Risk Management Framework. These measures have produced a fragmented landscape in which organizations must navigate overlapping yet incompatible requirements, raising compliance costs especially for smaller firms.
The position paper contends that laws alone are insufficient and that governance should rest on ISO-style interoperability protocols capable of conveying risk information in standardized, machine-readable form across borders. Drawing on the GDPR’s implementation through ISO 27001 and Privacy by Design, the authors propose uniform “AI nutrition labels” that would report consistent metrics on bias, energy consumption, and data provenance. Such manifests, they argue, would enable technical conformance checks that satisfy multiple regulatory regimes simultaneously.
To address concerns that formal standards could hinder innovation, the paper advocates modular, versioned protocols designed to evolve alongside technical capabilities. The intended outcome is a shift from isolated legal compliance toward shared technical specifications that lower redundant effort, ease market entry for SMEs, and support clearer public communication about AI system properties.
Why it matters
Directly engages EU AI Act and ethical AI priorities central to Dutch policy and SME adoption; offers practical interoperability concepts applicable to Dutch enterprises operating under EU rules.







