• Home
  • News
  • Blog
  • Releases
  • LLM history
  • Compare LLMs
  • Library
  • About
⌘K
Sign in

A blog and notes on development. The easiest way to reach me is via the social links below.

Contacts
talalaev.misha@gmail.com
Documents
Personal data processing policyPersonal data processing consent
Photo: Markus Spiske / Unsplash

AI needs more than laws: it needs a common format for checking risk

Sh0ny
Sh0ny
18 August 2026
  1. Home
  2. Blog
  3. AI needs more than laws: it needs a common format for checking risk
2 min read

In short

Countries are already bringing in their own AI rules, but companies run into incompatible requirements. The paper's authors propose supplementing the laws with machine-readable standards, so that model risk can be described the same way worldwide.

The main problem with regulating AI may turn out to be not a shortage of laws but their incompatibility. A company operating in several countries has to translate the same information about a model into different languages of requirements — and repeat the checks.

The authors of a position paper propose adding ISO-like interoperability protocols to the laws. The idea is simple: a system should supply a standardised, machine-readable set of information about its risks so that a regulator, client or partner can compare them quickly regardless of jurisdiction.

As a practical format they propose AI "nutrition labels". These could state unified metrics of bias, energy consumption and data provenance. That does not cancel any individual country's requirements but creates a common technical layer for checking them.

There is an important shift in thinking here. At present compliance is often formalised as a set of documents and manual procedures. A unified manifest would turn part of that work into an exchange of structured data — much as information security standards helped operationalise privacy requirements.

For small companies that is potentially useful: one basic set of information could be adapted to several markets without assembling everything anew for each regulator. But a standard does not make a model safe by itself. It merely sets a common way of describing risk — and leaves open the question of how far the chosen metrics really reflect actual harm.

The proposal's limitations are obvious. A universal standard can start holding back new approaches if its indicators grow obsolete quickly or turn into mandatory bureaucracy. So the authors speak of modular, versionable protocols that must change along with the technology. Besides, the paper offers a direction and an argument rather than a finished international specification: it does not say who will maintain such a format or how countries will agree on the metrics themselves.

The practical conclusion is for now more modest than the promise of "a single global language for AI": companies would already do well to separate legal compliance from the technical description of a model. The first depends on the country, while the second can be standardised gradually within the organisation — for data, energy use, known limitations and test results.

If you had to choose what to introduce first: one more AI law, or a single machine-readable passport for a model? Source: cs.AI updates on arXiv.org

NewsaiSecurityTechnology
More AI-tool write-ups on the Telegram channel — short and to the point
Subscribe

Comments

(0)
​