Sentient Staff
Field notes

Nine ways to regulate AI, sorted by whether they reach the person

UNESCO maps nine ways governments are choosing to regulate AI, from principles to liability. Read for compliance and they look similar. Read for who they actually protect, and the gap this business exists to close starts to show.

← All resources

UNESCO's 2025 consultation paper on AI regulation maps nine distinct approaches governments are taking, from a soft set of principles to hard financial liability. It is a genuinely useful map, but it answers a legal question, which approach applies where, not the one we actually care about: does any of this reach the person on the other side of the system, or does it stop at the institution operating it?

Nine levers, not a ladder

The nine approaches are not options an organisation picks between.

Most jurisdictions layer two or three at once, and the paper itself orders them loosely from light-touch to binding rather than ranking them by merit. That matters for how to read what follows: a country using a principles-based approach has not necessarily chosen the weak option, it may simply be earlier in a sequence that ends in liability, or building the softer layers on purpose because the harder ones take longer to legislate.

The honest way to use this map is descriptive, what a jurisdiction is actually doing, not evaluative, which approach is objectively best.

Principles and standards: setting the tone, not the enforcement

The first two approaches shape expectations without directly compelling anyone. A principles-based approach, UNESCO's own Recommendation on the Ethics of AI and the OECD's parallel Recommendation are the clearest examples, offers a set of propositions:

  • human-centred,
  • non-discriminatory,
  • transparent, and

leaves each adopter to work out what that means in practice.

A standards-based approach goes one step further without becoming law itself: the EU AI Act's Recital 121 hands technical precision to standard-setting bodies, so that an organisation aligning its system with the resulting standard earns a presumption of conformity with the law.

Both are aimed at the organisation building or deploying the system. Neither, on its own, gives the person affected by it anything to point to.

Sandboxes and enabling environments: room to try, before anyone has to comply

The agile and experimentalist approach, regulatory sandboxes, is about giving room to test.

The EU AI Act's Article 3 defines a sandbox as a controlled framework letting a provider develop, train, and test an AI system, in real-world conditions where appropriate, under a regulator's supervision rather than under full compliance from day one.

The facilitating and enabling approach sits next to it: UNESCO's own Readiness Assessment Methodology exists to help a country work out how ready its institutions and rules actually are for ethical AI, before legislating rather than instead of it. Both approaches are about building capacity in the system doing the building. The person that system will eventually touch is still not in the room.

Adapting existing law: the one that can go either way

Amending sector rules, health, finance, education, justice, and transversal rules, data protection, labour, criminal codes, procurement, sounds like a technical, institution-facing move, and mostly it is. But the example UNESCO cites for this approach happens to be one of the few genuinely person-facing mechanisms on the whole list: GDPR's Article 22, which gives an individual the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. That is not a principle or a standard, it is a right a specific person can invoke about a specific decision.

The lesson is not that adapting existing law is inherently more protective, it is that which existing law gets adapted decides whether this approach reaches the person or stays entirely institutional. Adapt a procurement rule and nothing changes for the individual. Adapt a data protection right and it does.

Transparency mandates: information, which is necessary and not sufficient

Access-to-information and transparency approaches require public bodies to publish something about how an algorithmic decision gets made.

  • France's Law No. 2016-1321 requires public bodies to publish the rules behind algorithmic processes used in individual decisions.
  • Colombia's 2023 decree pushes public bodies toward open data portals for AI projects.

These genuinely put the person closer to the system than principles or standards do, in theory they can go and read how a decision about them was reached. But publishing a rule is not the same as being able to contest a decision made under it, which is exactly the gap Article 22 closes and a transparency mandate on its own does not.

Risk, rights, and liability: where the language finally gets specific about people

The last three approaches are where the paper's own language shifts from institutions to individuals.

A risk-based approach, Canada's Directive on Automated Decision-Making is the paper's example, sets obligations according to the risk a specific use of AI poses in a specific context, which at least asks the right question, even though risk to whom, and how much, still has to be answered honestly each time rather than assumed from a tier label.

A rights-based approach is more direct still: new or reaffirmed rights, held by the individual, that a duty-bearer, state or company, is obliged to respect.

Liability is the most binding of the nine: the EU AI Act's penalty regime, fines up to EUR 35 million or seven percent of global turnover for the most serious infringements, assigns consequence to a specific failure. It is also, notably, aimed back at the institution again. The fine lands on the company, not a remedy that reaches the individual who was actually affected.

The question worth asking about your own seat, or job description

Lay the nine out this way, and the pattern is not weak versus strong regulation, that framing is the paper's, not a values one.

It is institution-facing versus person-facing, and most of the nine sit closer to the first. Even where a rule can, in principle, be enforced against an organisation, that is a different thing from a specific person's situation getting looked at, understood, and answered by someone with the standing to actually reach in. That is what a regulatory architecture, however binding, cannot do by itself, and it is the same gap our piece on what most AI ethics work never covers is about.

Whichever mix of these nine governs a given deployment, the human question underneath it, what is this doing to the person on the other end of it, still needs someone in the room asking it, not just a rule filed away that says the organisation should be asking too.

Field notes · reading UNESCO's 2025 Consultation Paper on AI Regulation: Emerging Approaches Across the World, not a legal analysis

See how we evidence it.

Every placement we make is evidenced against the same framework, with the reasoning shown.