The concept of generative AI risk is becoming increasingly fragmented according to the priorities of different countries. Here, we look at where the global picture is heading.
This content was originally published for clients. Find out more about our Emerging Tech service.
Key takeaways
The concept of generative AI risk is becoming increasingly fragmented according to the priorities of different countries. Broadly speaking, the perception of generative AI risk can be split into three categories: the EU’s view, the US view and the doomsday view. These different perspectives are important in the context of potential regulatory fragmentation as new sets of AI governance rules continue to emerge from the major jurisdictions.
The EU’s AI Act is a product safety-based legislation. The latest twists and turns of the political drama over how to regulate foundation models and general-purpose AI (GPAI) systems in the Act should not distract from the fact that the end goal of the legislation remains to protect end users from potential harm arising from malfunctioning systems. This view, very broadly speaking, is shared globally by Singapore and China, among others.
The US is focused on mitigating the risk of bad actors using AI to compromise national security, such as through the creation of AI bioweapons, nuclear weapons or cybersecurity threats to critical national infrastructure. These concerns, as much as the issue of AI product safety, informed the direction of President Biden’s recent Executive Order on AI.
The UK focus is on long-term rather than short-term risks. The AI Safety Summit focused narrowly on the ‘doomsday’ view of the potentially existential risks arising from future frontier AI systems. At the same time, domestically, Prime Minister Rishi Sunak continues to back a pro-innovation, light-touch regulatory approach while the technology is still in its relative infancy.
The latest in the EU
In the EU, the debate on the AI Act and generative AI in particular is evolving daily. A new path to a potential compromise is now beginning to form ahead of next Wednesday’s trilogue.
A two-tier approach is most likely, with only the next generation of more powerful systems falling under the higher ‘systemic’ category. The basic tier of regulation is likely to be extended from earlier compromise drafts to incorporate some aspects of Parliament’s thinking – in particular, the requirement for developers to share relevant information about the model with downstream providers in order to better allocate responsibility along the value chain. We think the latest compromise makes an agreement of some form at next week’s trilogue more likely to succeed.
Brussels effect unlikely
Even if the AI Act can be finalised by the end of 2023, it is unlikely to generate the fabled Brussels effect, in large part due to the increasingly different views of how generative AI risk should be defined that are beginning to emerge around the world.
At its heart, the EU’s AI Act is a piece of product safety legislation. For this reason, the bloc’s policy focus has long been on the consumer harm risks from current AI systems if they malfunction (such as hallucinations, biases, etc.). The EU treaties preclude legislators from extending the AI Act debates onto defence and national security matters.
This debate on how generative AI could be used in defence and how advanced AI systems may pose a threat to national security is being held within NATO instead. Such concerns are much closer to the US perspective – and one which we saw infused at the G7 level in the latest round of developments.
In a somewhat different approach still, the UK’s AI Safety Summit in November focused international attention on the potential extinction-level risks from Artificial General Intelligence and other frontier AI systems.
Broadly, therefore, the global views on generative AI risk can be divided into three camps – the EU view, the US view, and the doomsday view.
As countries and jurisdictions sharpen their priorities for AI regulation, these differences around generative AI risk are becoming more and more apparent. They matter both for influencing the direction of multilateral policy coordination and for anticipating the potential for regulatory fragmentation to emerge.
The US
The US is traditionally known for its light-touch approach to tech regulation. However, in the wake of Biden’s Executive Order, this perception now looks outdated, with the US now signalling an increasingly interventionist AI policy direction.
After initially taking a back seat in the AI regulatory debate, the US’s view has begun to crystallise on the potential for a malicious state or non-state actor to abuse generative AI systems (both current and future models) to compromise democracy or national security.
As well as targeting the safe and trustworthy development of AI systems, Biden’s Executive Order on AI, announced on 30 October, put a particular focus on mitigating national security risks from bad actors with access to AI systems.
For instance, the Order directs the Department for Energy to develop testing and evaluation tools specifically for AI outputs that “may represent nuclear, non-proliferation, biological, chemical, critical-infrastructure, and energy-security threats or hazards.” Similar directives have been given to other departments, such as Defence and Homeland Security on the cybersecurity implications of AI, the risks of using AI in critical national infrastructure, and the potential for AI to be used to make Chemical, Biological, Radiation or Nuclear (CBRN) threats.
The stand-out regulation in the Executive Order is the use of the Defense Production Act to mandate that providers of “dual-use foundation models” must disclose to the Government any plans to train new models, the ownership of those model weights, and the results of red-teaming exercises for those models.
Significantly, the computing threshold for models to meet these reporting requirements is set at above the level of any model on the market today. The focus of the US’s security concerns is on the next generation of more powerful models, whose potential capabilities developers may be less able to control.
The prioritisation of the national security implications of AI misuse, along with the focus of reporting standards on future rather than current models, is already creating a clear dividing line with the EU, given the AI Act is focused squarely on the consumer protection issues arising from the commercial or public use of AI systems already on the market. In the context of the developing open (or quasi-open) source debate, there is also a risk of this policy divide growing further in the future.
The UK
As the US moves away from a laissez-faire approach to AI and the EU finalises the AI Act, it seems the UK is currently pursuing the most hands-off approach to domestic regulation of the three, as outlined in its unashamedly ‘pro-innovation’ AI White Paper.
However, we expect the UK to change course towards a more EU-aligned product-safety perspective on AI risks if, as expected, Labour comes into power at the general election next year.
The UK is more concerned with long-term harm than short-term issues while the technology is still developing fast. It has so far prioritised highlighting the possible extinction-level risks from future AI systems.
This ‘doomsday’ approach to generative AI and AGI risks is at least partially aligned with the US’s defence and security focused concerns, given the potentially existential risks associated with AI bioweapons and nuclear weapons.
Indeed, the UK’s AI Safety Summit itself was planned in lockstep with the US. Prime Minister Rishi Sunak only announced the event after Biden had effectively given it his blessing at their bilateral meeting in June, while the eventual decision to narrow the focus of the Summit to frontier AI alone also demonstrates the UK’s amenability to the US’s future-looking concerns.
The UK is not just following the US, however. The Government’s focus on the potential catastrophic and existential risks of AI can also be seen as part of a wider UK pivot towards improving the country’s resilience and risk preparedness planning for high-impact, low-probability events in the wake of the coronavirus pandemic. In part, the UK’s Safety Summit was a test case for scenario planning in a sector where the nature of the risks cannot yet be fully understood.
Asia
The political narrative on AI in Singapore is one of opportunity and effectiveness. Recently, President Tharman spoke of AI’s potential to allow elderly Singaporeans to work and serve their nations longer – a deeply regional view on technology and citizenship.
An AI safety rulebook is being led by the financial services regulator, the Monetary Authority of Singapore. A Generative AI Risk Framework was previewed in mid-November. In an evolution to ongoing AI work, this framework too is based on seven risk criteria. A whitepaper due in Q1 2024 will present a platform-agnostic generative AI reference architecture for FIs, underpinned by these seven dimensions.
In this sense, Singapore is most aligned with the EU, in that it seeks to ensure the deployment of AI does not malfunction. However, it applies these policy principles through a different policy toolkit, mostly via public-private partnerships and experimentation.
As one of the first countries to introduce dedicated generative AI rules, China is often perceived as having taken a strongly risk-averse stance to generative AI. To an extent, this is true: the initial version of the rulebook, published as draft rules for consultation in April this year, was certainly stringent in its requirement that all models or systems available to the public would have to undertake a security assessment and be recorded by the state.
However, in the final version of the rules published in August, the strictest provisions were either relaxed or watered down, particularly for business rather than public-facing use cases and for international users of Chinese-made AI, in order to foster a more obviously pro-business regime.
Aside from the big ideological differences between China and the EU on content moderation and privacy, the two jurisdictions are aligned in their focus on product safety, particularly through data quality and transparency requirements, as well as testing and risk assessments. China’s announcement last month of a Global AI Governance Initiative sought to present the country as open to engagement with the G7 and other like-minded countries on areas of AI governance where consensus can be found.
Conclusion
The divergence in opinion over which generative AI risks different countries are concerned with is beginning to lead to very different policy choices.
In the EU, the primary focus is on safeguarding the deployment of AI in high-risk activities. Even the rules which will fall onto foundation models serve to primarily support AI deployers to protect consumers from unintended consequences.
In the UK, the Government wants to prevent a catastrophic scenario. That is why it will focus on public-private partnerships testing AI models against such scenarios, via the AI Safety Institute.
In the US, Biden’s Administration is most worried about AI being exploited by malicious actors, which is why it will test and safeguard against the usage of AI in weapons and dual-use goods.



