In our first post on the AI Wonk, Aliki Foinikopoulou, our Head of Global Public Policy, discussed the rapid evolution of the AI landscape. Less than a year later, the emergence of new technologies and a rapidly evolving regulatory landscape have added new layers of complexity. Against this backdrop, trust is more critical than ever. AI presents a generational opportunity, but harnessing it responsibly requires governments to play an active, deliberate role in shaping its development and deployment.
Salesforce was pleased to be one of the first companies to contribute to the reporting framework developed by the OECD under the Hiroshima AI Process (HAIP), and we were pleased to have contributed to the second version of the reporting framework, which offers an expanded view of the AI value chain. Over the last year, enterprise agentic AI has fundamentally shifted the business landscape, transforming organisations from simply using AI to becoming agentic enterprises. Now, more than ever, a common framework and language to articulate a path to trusted AI are critical.
The governance gap we can’t afford to ignore
The most consequential shift in artificial intelligence is not happening in a research lab. It is happening right now through decisions in boardrooms, legislatures, and the daily choices of millions of people. Governance frameworks need to keep up.
These decisions and choices are more critical today because AI has expanded beyond large, generative models that respond to prompts into the era of agentic AI, where systems autonomously plan, execute and adapt across complex, multi-step workflows. These agents can browse the web, write and run code, negotiate, make purchases and decisions. All with real-world consequences.
The AI value chain has expanded dramatically, spanning model developers, cloud infrastructure providers, orchestration platforms, data brokers, enterprise deployers and end users. Each new layer introduces fresh challenges: accountability gaps, opaque decision-making, and the potential erosion of meaningful human control.
The question is no longer whether AI should be governed. The question is how governance frameworks can keep pace.
Fragmentation is the real threat
The primary hurdle to responsible AI adoption today is not only technical but also regulatory fragmentation. As nations race to establish frameworks to govern AI, we are seeing a patchwork of rules that sometimes take different approaches. The divergent definitions of risk and transparency across jurisdictions not only create compliance headaches; they also contribute to governance gaps that small businesses cannot afford to bridge, leaving the advantage solely with the largest incumbents.
Consider a mid-sized logistics company deploying AI agents to manage cross-border freight and customs compliance. Unlike large incumbents, it has no dedicated AI governance team. In a fragmented regulatory environment, demonstrating responsible AI use means navigating a different set of voluntary and mandatory rules in every market where it operates, an effective barrier to entry that has nothing to do with the quality or safety of its technology. A harmonised framework with clear, tiered requirements based on risk level rather than company size would change that calculus entirely, enabling broader participation in the responsible AI economy.
A global bank using AI agents to automate processes is another good example. The EU requires human-interpretable reasoning trails; US regulators focus on disparate impact testing; the Monetary Authority of Singapore (MAS) applies its own Fairness, Ethics, Accountability, and Transparency (FEAT) principles. Without a common standard, the bank either builds to the most restrictive version globally, which is expensive, or limits deployment to certain markets, leaving genuine value unrealised.
These aren’t hypothetical edge cases. They are the daily reality for Salesforce customers operating across jurisdictions.
We have seen this dynamic before. In the early days of the internet, cybersecurity was a fragmented landscape of jurisdiction-specific standards. It was not until we moved toward global interoperability through frameworks such as NIST and ISO that businesses could demonstrate their security programmes at scale. AI governance must follow the same blueprint to avoid fragmentation as the final reality.
Why HAIP matters
At Salesforce, my team in the Office of Ethical and Humane Use guides the responsible design, development, and deployment of our technologies. Ethical considerations must be embedded from the start in the product design of the AI platform and the agents themselves, and not just because of regulations, but because it is what our customers expect from Salesforce. But internal commitment alone is not enough. It must be paired with strong, globally coherent governance.
That’s why we are pleased to once again participate in the HAIP reporting framework and in the process to both streamline and broaden its base of participation. The ubiquity of AI means that frameworks like this need to be accessible and relevant to companies of all sizes across markets worldwide.
HAIP matters for several reasons, including:
A common language: The HAIP Reporting Framework provides a standardised baseline that allows regulators and companies to compare compliance processes across the industry, an essential in a world where agentic AI means different things to different people. For a company like Salesforce, whose Agentforce platform is deployed by enterprises across the EU, US, Japan, and beyond, this matters enormously. Today, a multinational client must configure separate compliance documentation for each jurisdiction, even when the underlying agent and its safeguards are identical. A common language means that responsible design, built once, can be recognised everywhere.
Global interoperability: In a fragmented regulatory environment, HAIP acts as a diplomatic bridge, ensuring that a company’s safety commitments in San Francisco carry weight in Tokyo and Brussels. Salesforce voluntarily publishes its responsible AI practices and invests heavily in making them robust, but without interoperability, those commitments must be re-translated for every regulatory context. That is not a problem of intent; it is a problem of infrastructure. HAIP provides that infrastructure.
From “trust me” to “show me”: By making reports public on the OECD.AI platform, HAIP transforms transparency from a compliance burden to a competitive advantage and inspires a race to the top. Companies currently publish reports, such as Salesforce’s Trusted AI and Agents Report, on a voluntary basis. Centralising this kind of information from across industries on a single platform can further bolster the industry by publicly demonstrating a strong commitment to responsible AI. Critically, it also lowers the barrier for smaller companies: a streamlined, interoperable voluntary framework means that responsible AI is no longer a signal only large incumbents can afford to send.
A blueprint worth protecting
Just as the internet required global standards to scale safely, so too does AI. Just as the Payment Card Industry Data Security Standard created a single payment security standard that allowed small businesses to accept credit cards globally without a compliance army, a coherent AI governance framework provides companies of all sizes with a clear, achievable bar rather than an ever-shifting patchwork of national rules. The Hiroshima AI Process is that tool, a shared blueprint for trust that governments and the private sector must now work together to strengthen and expand.
Realising the opportunity of agentic AI responsibly demands more than good intentions. It demands frameworks that are globally coherent, publicly accountable, and built to keep pace with the technology itself. Salesforce remains committed to that work because the future of AI should be governed by shared principles that are ethical, agile, humane, and built to last.
This three-part blog series explores the growing complementarity between artificial intelligence (AI) and quantum technologies. The first post introduced quantum technologies and outlined their strengths and the challenges of combining AI with quantum systems. The second examined how AI can support the development of quantum technologies, helping to optimise systems and accelerate progress towards practical applications. In this third and final instalment, we turn to the reverse relationship: how quantum technologies – including computing, sensing and communication – could support the future evolution of AI systems.
Although large-scale, fault-tolerant quantum computers remain a long-term goal, early-stage quantum devices and their integration with existing AI systems are already paving the way for quantum-enhanced AI. These developments could eventually lead to meaningful improvements across many sectors of the economy and in daily life.
What technical breakthroughs could quantum computing bring to AI?
In recent years, AI systems have become more powerful and data-intensive, particularly through large language models (LLMs). These developments have made the limitations of classical computing, especially in speed, energy consumption and scalability, increasingly apparent. Quantum technologies could offer a pathway to expand the frontiers of classical computing, potentially overcoming today’s computing bottlenecks. However, quantum computers are not expected to replace existing AI systems. They are likely to coexist, with quantum systems excelling at solving specific types of problems that are difficult or intractable for conventional computers.
As quantum computing evolves, it is expected to strengthen AI in two main ways. First, quantum computers could significantly improve energy efficiency. Training AI requires substantial computing resources that consume vast amounts of electricity, raising economic, energy security, and environmental concerns. This is particularly true of LLMs.
These pressures apply more broadly across statistical AI techniques, such as machine learning, where increasing model complexity and data intensity are pushing the limits of classical computing. This is often characterised by experts as the slowing of or end to Moore’s Law.
Second, quantum computing could enhance the performance and capabilities of AI systems. This has fuelled growing interest in quantum machine learning (QML), which refers to machine learning methods implemented using quantum algorithms. QML is expected to improve AI system learning performance in areas such as optimisation, pattern recognition and high-dimensional data analysis.
In the long term, QML may reduce the computational requirements and energy footprint of some AI workloads by performing complex computations more efficiently, although this remains to be demonstrated at scale. QML remains in an early stage of development and faces three key bottlenecks:
Data transfer constraints: Moving large volumes of classical data (bits) into and out of quantum systems (qubits) remains slow, limiting the suitability for data-intensive AI tasks.
Unproven advantage: Demonstrating performance gains over highly optimised algorithms on classical computers remains challenging.
Unclear hardware requirements: Defining hardware specifications for QML, including qubit counts and coherence times, remains difficult, making it challenging to develop practical QML roadmaps.
While QML is a longer-term prospect, quantum-inspired AI techniques are already delivering practical benefits. These approaches adapt concepts from quantum physics for use on classical computing hardware. One prominent example is the use of tensor networks, originally developed to simulate quantum systems, to compress LLMs.
These techniques have significant practical implications for AI developers. As neural networks such as LLMs become larger and more complex, deployment is constrained not only by fixed hardware limits such as memory and processing capacity but also by the computational and energy costs of training and running these systems.
Tensor-network compression to reduce memory use
Some researchhasshown that tensor-network compression can reduce memory use and computational demands by 10-100x, often with only modest reductions in accuracy after fine-tuning. These efficiency gains enable advanced AI models to run on conventional CPUs, edge devices and legacy infrastructure, expanding access beyond specialised high-performance computing environments.
Because these techniques do not require quantum hardware, they are already being embedded in commercial applications. Startups and technology providers are offering tensor-network-based compression tools and positioning them as a path to lower costs and energy consumption while improving deployment flexibility.
In practice, quantum-inspired compression is best understood as complementary to established methods such as pruning and quantisation for optimising neural network efficiency. Because they target different forms of redundancy in neural networks, tensor approaches can be combined with conventional techniques and, in some cases, outperform them in both efficiency and performance. Together, these developments illustrate how insights from quantum information science are already shaping the evolution of AI, even before large-scale quantum computers become widely available.
Hybrid quantum-classical computing
The most realistic near-term pathway for combining AI with actual quantum computers is through hybrid quantum-classical systems that leverage the strengths of both AI and quantum computing. In these systems, quantum processors perform specific sub-tasks, such as optimisation or simulation, while classical AI models handle data processing, interpretation and control. In this direction, several computinginfrastructures are integrating quantum processors into high-performance computing environments, enabling researchers and industry actors to experiment with quantum-enhanced AI workflows. At the same time, cloud-based quantum platforms are lowering access barriers, allowing AI developers to test quantum algorithms, such as optimisation or sampling routines, that can be integrated into machine learning workflows.
These advances could eventually translate into practical applications across multiple sectors. In materials science and chemistry, quantum computing combined with AI may accelerate the discovery of new materials and drugs by enabling more accurate simulations of molecular behaviour. In manufacturing and logistics, hybrid quantum-AI approaches could improve the performance of complex optimisation tasks such as scheduling, resource allocation and supply chain planning. Financial services actors are also exploring quantum-enhanced modelling for portfolio optimisation and risk analysis, where large combinatorial search spaces pose challenges for classical AI methods.
How could quantum sensing expand AI’s possibilities, and where?
Beyond computing, quantum technologies may also enhance AI through advances in sensing. Quantum sensors can detect extremely small changes in magnetic fields, temperature, motion, or chemical composition, often with higher precision, stability, or spatial resolution than classical devices, thereby producing novel data streams. For AI systems, access to richer and more accurate data can translate directly into new applications across multiple sectors.
In healthcare, more sensitive sensing technologies could enable earlier disease detection and more accurate monitoring of health indicators. By capturing subtle biological or chemical changes that might otherwise go unnoticed, quantum sensors could provide richer data for AI systems to analyse, supporting faster diagnosis and more personalised treatment decisions.
In agriculture, improved sensing precision may help monitor soil conditions, crop health and environmental variables in greater detail, allowing AI tools to optimise irrigation, fertilisation and resource use for higher yields and greater efficiency. Similar approaches could support environmental monitoring, in which higher data quality can strengthen forecasting models and inform policy responses to climate and sustainability challenges.
Quantum sensing also has potential applications in infrastructure and industry. Sensors capable of detecting minute physical changes could help identify early signs of structural stress or equipment degradation in bridges, transport systems or energy facilities. When combined with AI-driven predictive maintenance, this information could enable earlier interventions, reduce operational disruptions and improve safety outcomes. More broadly, the integration of advanced quantum sensing with AI highlights an important dimension of technological progress: improvements in data quality and reliability can be just as transformative as advances in computing capabilities.
How could quantum communication support AI?
Quantum communication could enable secure networking conditions for federated learning and multi-agent systems, where multiple devices collaboratively train models without sharing raw data. Quantum-secure communication channels could make it easier for different parties to share sensitive information (e.g., in healthcare, finance, or critical infrastructure) while reducing the risk of interception or data leakage, especially when training or inference occurs in distributed cloud environments. Research and patentapplications are exploring whether entanglement-enabled networks or quantum-secured links could support distributed training architectures across geographically separated computing resources. Although these concepts remain largely experimental, early prototypes are already exploring secure distributed machine learning architectures built on quantum communication protocols.
Quantum communication may also become important for integrating AI with quantum sensing systems. Some advanced quantum sensors generate information directly in quantum states, which cannot always be measured or transmitted using conventional classical channels without losing valuable information. Quantum networking could allow these states to be transferred between devices or processing nodes while preserving their quantum properties, enabling more sophisticated analysis pipelines that combine sensing, computation and AI-driven interpretation.
Leveraging quantum and AI complementarities for a shared technological future
This three-part series examined the potential and challenges of combining AI and quantum technologies, from foundational concepts to emerging applications and future pathways. As we have seen, AI is also accelerating progress in quantum technologies themselves, for example, by improving calibration, noise reduction and experimental design. This bidirectional relationship (AI for quantum and quantum for AI) is likely to shape the next phase of innovation in both fields.
As outlined in this series, the integration of AI and quantum technologies could reshape scientific discovery, healthcare, industry and sustainability. At the same time, significant challenges remain, including technical limitations, talent shortages at the interface between the two technologies, ethical considerations and the need for international collaboration.
As we stand at the early stages of this transformation, one conclusion is clear: the digital future will not be built by AI or quantum technologies alone, but rather through their interplay and collaboration.
Global agri-food systems are under growing strain. Even though the world produces enough calories to feed more than the world’s entire population, one in eleven people – or nearly 700 million people – still face hunger. Climate shocks, fragile supply chains, and labour shortages increasingly threaten the resilience of agri-food systems worldwide. As pressure on farmers and supply chains intensifies, artificial intelligence (AI) is a promising tool to ensure that all stakeholders – including vulnerable populations – can benefit from the transition towards more resilient agri-food systems.
Agri-food systems face growing strain – AI tools offer solutions
The agricultural sector plays an essential role in economies and societies around the world, providing communities with reliable, quality food and tens of millions of jobs. Yet the global agri-food system is under pressure, as various issues, from climate challenges to workforce shortages, put strain on farmers and global supply chains.
AI offers opportunities to address the needs of farmers and other actors in the agri-food system across diverse local contexts. And AI is already transforming agriculture and related supply chains. It helps farmers predict droughts, reduce pesticide use and identify crop diseases before they spread. It supports buyers, traders and retailers in making decisions regarding product availability, quality and prices. AI-enabled precision spraying can reduce pesticide use by up to 30% without compromising yields. Drought-tolerant traits identified using AI in sorghum and chickpea crops boost yields by up to 25% during dry seasons. And the Global AI Hybrid Rice Platform shortens breeding cycles by predicting optimal parent combinations.
However, challenges persist in the adoption of AI and other digital technologies. Access to these promising tools is starkly uneven, and so is the distribution of information throughout supply chains. In Australia, nearly 96% of farmers use digital tools, whereas in Chile, just 12% do. In addition, issues persist in data interoperability between different stakeholders and jurisdictions, which hinder data sharing opportunities and limit the impact of digital tools. Digital tools need to be accessible, trusted and designed to respond to local user conditions.
Cybersecurity must also be treated as a foundational prerequisite for AI-enabled agri-food systems (e.g. through secure-by-design approaches). Without robust protections from cyber threats and concrete actions such as building digital literacy and aligning policy agendas, there is a risk that the potential of using digital technologies will not be realised or will have adverse consequences. At the same time, the lack of agri-food-specific AI governance could create regulatory uncertainty, making the case for targeted frameworks that promote the trustworthy deployment of AI while accounting for the sector’s unique characteristics.
These issues were at the centre of a flagship session on AI for Inclusive and Resilient Food Systems, co-hosted by the Kingdom of the Netherlands and the OECD at the India AI Impact Summit in New Delhi in February 2026. The session leveraged the work of the Summit’s Working Group on Economic Growth and Social Good, co-chaired by India, Indonesia and the Netherlands. Examples from these three countries and field‑level research highlighted where AI is already showing great promise and where critical bottlenecks remain.
These insights point to three areas where deeper international co-operation and policy analysis facilitated by organisations such as the OECD could help countries make meaningful progress. Specifically, the OECD’s Global Partnership on AI (GPAI), could take next steps and examine where AI is delivering results in agri-food systems across various regions and what it will take to ensure benefits are widely shared.
The opportunity: How AI can help build efficient and resilient supply chains for global food security
Efficient and resilient supply chains are cornerstones of the agriculture sector and global food security. Strengthening global food security is a strategic priority for countries like the Netherlands because reliable, sustainable and affordable food systems are essential for societal stability and economic development, particularly in vulnerable regions. After the United States, the Netherlands is the world’s second-largest exporter of agricultural products. The Dutch have already seen tangible results from AI applications in agriculture. According to research from Wageningen University, AI tools for advanced greenhouses have yielded water savings of up to 90% through smart irrigation, compared to traditional open-field systems.
The challenge is that successful solutions in countries like the Netherlands cannot always be exported to other countries due to the diversity of agricultural contexts worldwide. In view of this complexity, partnerships are an important tool. Examples from the Netherlands highlight the importance of co-creation as a vital strategy for tangible results. The Netherlands works with other countries to develop locally relevant AI solutions that are inclusive and accessible to farmers through knowledge sharing, capacity-building and co-creation.
The use of AI can also help reshape how companies engage with stakeholders across supply chains and help to manage risks. Tools intended to improve efficiency (e.g. automated advisory systems, remote monitoring, or worker feedback platforms) can enhance visibility and responsiveness, but they can also displace meaningful human engagement if not carefully implemented. Managing these trade-offs is therefore essential to ensure that AI contributes positively to sustainability efforts. The OECD Due Diligence Guidance for Responsible Business Conduct and AI-specific due diligence guidance provide a practical framework for managing these risks. It promotes a risk-based, continuous approach grounded in stakeholder engagement, with step-by-step operational guidance to identify, prevent, mitigate, and account for adverse impacts.
Despite promising tools and guidance, in practice, there are persistent problems with AI adoption across agri-food systems and supply chains, including among farmers. Below are three key challenges which would benefit further from OECD and GPAI analysis and co-operation.
Solving the data problem: improving interoperability and shared agricultural data
Across regions, the most consistent barrier to effectively using AI in agriculture is data: not enough of it, not widely shared, not of high enough quality and often not interoperable. Addressing these challenges is at the core of many initiatives of the Dutch Ministry of Agriculture (LVVN), as well as EU initiatives such as the Common Agriculture European Data Space and the European Digital Infrastructure Consortium for Agri-Food.
When agricultural data remains siloed between ministries, supply‑chain actors or countries, AI tools underperform in real‑world conditions. This challenge surfaces in examples such as global crop mapping efforts, which struggle when key national data is unavailable, and contrasts sharply with locally tailored tools. Data interoperability is critical not only for enhancing transparency and traceability but also for enabling benchmarking that drives competitiveness and for unlocking new market opportunities.
In the cocoa industry, for example, which is suffering heavily from climate change, researchers from Wageningen University built a chatbot in the farmers’ local languages to identify plant diseases using computer vision trained on local data in the form of images. It worked because it was built with locally sourced data using the farmers’ perspective, not the researchers’. This shows that not only are data availability, quality, and interoperability important, but trust also plays a critical role in AI uptake. The same is true for AI literacy. For example, an AI tool’s success in the field depends greatly on a farmer’s ability to generate, manage and apply high‑quality, context‑specific data. This could include skills spanning data literacy (e.g., collection, quality control, labelling), applied digital skills (e.g., the use of sensors), and general skills for successfully interpreting and assessing AI outputs.
Building shared and trustworthy data infrastructures is a challenge well suited to multilateral co-operation. The OECD and GPAI could help countries examine which types of agricultural data are most critical for AI uptake, how to enable cross-border interoperability, and how governance, incentives, and standards can encourage responsible data sharing without disadvantaging farmers or exposing sensitive information. Such analysis would complement ongoing OECD and GPAI work on AI governance and help countries design data ecosystems – for example, through bilateral agreements – that support resilience rather than reinforce fragmentation.
Small but mighty: ensuring AI works for small farmers through local relevance and co-design
AI will only advance global food security if it also works for small farmers – who grow roughly one‑third of the world’s food but are also most vulnerable to climate and market shocks. Many tools fail to provide the expected socio-economic value because they are built for ideal conditions or assume a baseline of digital maturity that simply does not exist. The most effective way to address these issues is to begin with the farmer’s perspective.
Examples from India illustrate this opportunity. A voice-first AI tool developed by the Government of India, called BharatVistaar, provides farmers with a breadth of agricultural advisory information on subjects ranging from shrimp cultivation to pest control. It comes as a simple phone call or text message from a chatbot, in their local language, with no smartphone required. This accessible, low-tech solution shows how AI can benefit farmers who lack access to complex technology or reliable internet.
This is an area where the OECD and GPAI’s evidence base and global reach could offer unique value. Through comparative analysis and its global network of experts, the OECD could help countries better understand what farmer-centred AI design looks like in practice; which models scale across different agricultural contexts; and how to build trust by aligning tools with real-world decision‑making. Sharing case studies through the OECD.AI Policy Observatory, sharing concrete field-level agri-food system AI tools through the OECD.AI Catalogue of Tools and Metrics, contributing policies to the OECD.AI Policy Navigator, leveraging the OECD.AI Policy Toolkit, and sharing local lessons at GPAI meetings could help countries learn from each other’s successes and pitfalls.
Moving from pilots to scale
Scaling AI solutions in agri-food settings is not easy. Solutions that perform well technically often falter in field conditions, and many projects remain stuck as promising pilots that never achieve systemic impact. Factors such as infrastructure gaps, cybersecurity threats, institutional capacity, financing constraints and lack of local adaptation all limit the path from prototype to widespread adoption.
Scaling and resilience in agri-food systems must extend beyond agriculture itself to the AI infrastructures that underpin it, as cyberattacks can render systems unavailable – particularly impacting smallholder farmers. An emphasis on accessibility without security could lead to unsustainable outcomes, making cybersecurity a critical precondition for success.
Countries like the Netherlands are working with partners to co-create AI solutions that are secure and deeply adapted to local ecosystems to be successful in scaling up. Indonesia also offers a compelling example. With more than 17 000 islands with varied soil conditions and uneven infrastructure, the country sees AI as essential to developing resilient agriculture and has integrated AI into its national strategy for climate-resilient agriculture to combat scaling challenges related to its diverse geography.
A structured examination of what it takes to scale AI responsibly for agriculture – across geographies, farm sizes and value chains – could provide actionable insights for governments worldwide. This could include analysing enabling policies, public‑private partnerships, field-level capacity building, and pathways for adapting successful models to regions with differing levels of infrastructure development.
With its cross-country reach and evidence-based approach, the OECD, through GPAI, is well-positioned to convene comparative analysis of scaling and cybersecurity challenges, identifying practical levers to help countries move from fragmented experimentation to system-wide adoption.
Looking ahead: tackling these challenges through the Global Partnership on AI
AI has the potential to transform global agri-food systems, but technology alone cannot deliver this outcome. The choices made around governance, access and partnerships will determine whether AI strengthens resilience broadly or deepens existing divides. Advancing AI for sustainable agri-food systems depends on addressing the three imperatives discussed above – ensuring access to high-quality data by building interoperable, trusted data ecosystems; designing farmer-led, locally relevant solutions; and creating the conditions to scale securely and sustainably through robust infrastructure, governance, and strong cybersecurity to safeguard system resilience. These topics are at the core of the Dutch Ministry of Agriculture’s (LVVN) priorities and must be complemented by fit-for-purpose policy frameworks alongside viable financial models, knowledge exchanges, and innovation partnerships to enable effective and inclusive adoption.
The OECD works with countries – including the Netherlands – at various levels of economic development to establish AI governance based on the OECD AI Principles. The OECD.AI Policy Navigator gives access to AI policy initiatives in the agriculture sector, covering more than 2,000 AI policies and initiatives across 80 jurisdictions. Any country can use it to benchmark and strengthen its approach. Further analysis of the challenges and opportunities for AI in agri-food systems could be undertaken as part of initiatives such as GPAI and groups like the OECD-FAO Advisory Group on Responsible Agricultural Supply Chains.
Interested countries and partners are invited to contact ai@oecd.org to explore this topic further.
Artificial intelligence (AI) is both a technology story and a policy challenge. Governments across sectors and regions are grappling with the same question: how to effectively support the safe, trustworthy development and use of AI in ways that align with their countries’ needs?
Whether setting a national AI strategy or designing concrete initiatives to implement it, governments need guidance that meets them where they are. From experience, I can attest that the hardest part is rarely agreeing on principles; it is finding concrete, comparable examples of how others made them work. That is the gap the OECD AI Policy Toolkit closes.
Released yesterday by the OECD under the Global Partnership on Artificial Intelligence (GPAI), the AI Policy Toolkit is the first version of a practical, non-prescriptive guide for policymakers to translate the OECD AI Principles into action—a deliberate shift from defining what good AI policy requires to showing how to build it.
What the Toolkit does
The Toolkit is an interactive, evolving platform to support policymakers throughout the AI policy cycle. It complements OECD.AI’s broader ecosystem of tools for data, analysis and AI governance.
The Toolkit helps governments target and prioritise where to act. Through AI-powered semantic search, it surfaces relevant policy examples and guidance drawn from real-world practice, turning the OECD’s accumulated evidence into options a policymaker can use the same day—rather than a library to be read.
Built with policy-makers, not just for them
A year ago, the 2025 OECD Ministerial Council Meeting set this work in motion. What followed was less a drafting exercise than a year of listening—and the Toolkit released today reflects what countries told us they needed.
Far from being a top-down exercise, the OECD Secretariat developed the Toolkit with end-users through co-creation across regions. Targeted interviews and four co-creation workshops across Southeast Asia, Latin America and Africa—one of which Costa Rica was proud to host—brought policymakers, industry and experts together to shape its design around how governments actually work and make decisions.
Not only did these co-creation workshops highlight both shared challenges and region-specific priorities. They grounded the Toolkit in fundamental policy questions:
How to navigate trade-offs between local and global AI models, or between innovation and regulation?
How to address infrastructure gaps, such as AI compute capacity?
How to scale AI in agriculture, education or healthcare?
Two lessons that shaped the Toolkit
Moreover, the collaborative approach to developing the Toolkit has yielded important collective lessons.
First, context is decisive: AI policy must reflect national needs and preferences, institutional capacity and levels of digital maturity.
Second, addressing shared global challenges such as managing risks posed by advanced AI systems or ensuring diverse linguistic and cultural representation in AI models requires international cooperation as well as tailored policy responses.
Our sincere thanks go to the governments and organisations that, alongside Costa Rica, made this possible—notably Italy, France, Korea, Japan, the United Kingdom, the European Union, the French Development Agency and the Inter-American Development Bank—and to the policymakers and experts who contributed their time and insight. I also commend the OECD Secretariat for its sustained work.
What comes next
The OECD Ministerial Council Meeting (MCM) marks the Toolkit’s first release, which is an important milestone, but it is far from the finish line.
As AI technologies and related policy issues develop, the OECD remains dedicated to ensuring the Toolkit stays relevant through regular updates by:
Refining and improving the Toolkit through ongoing feedback and iteration
Incorporating more policy examples and use cases to strengthen its practical relevance via the OECD.AI Policy Navigator
Expanding its coverage of emerging policy issues, including sector-specific guidance, infrastructure and regulatory approaches
From shared principles to shared practice
The OECD AI Policy Toolkit results from a collaborative effort to transform AI principles into implementation. By integrating OECD standards with regional insights, it guides policymakers in leveraging AI’s opportunities while responsibly and effectively managing its challenges.
The Toolkit’s success will be measured not by its launch but by the policies it helps shape. Its impact depends on sustained collaboration and support. A year from now, I expect us to point to concrete cases where this tool moved a country from principle to practice—better AI policies for better lives.
Emerging AI capabilities in coding, tool utilisation, and multi-step reasoning, which is core to agentic AI, are shaping a more complex digital security environment. AI-based applications and services are becoming increasingly integrated into software, public services, vital sectors, and the broader economy, offering new opportunities for productivity and innovation. However, they also introduce new types of security exposure – misconfigurations and weaknesses that can lead to unauthorised access.
What AI security means in practice
AI security builds on traditional cybersecurity and goes beyond it. Today’s AI applications are trained on vast, diverse data and increasingly embedded in workflows that retrieve information, use tools, store memory, and perform multi-step tasks. Distinct AI security risks arise because models learn from data, behave probabilistically, and, in agentic systems, act more autonomously.
Many of the most important AI security risk patterns are only beginning to emerge. The evidence base remains uneven across issues such as prompt injection, agentic misuse, model poisoning, and the security of connected tools. AI technologies are by nature cross-border and cross-sectoral, meaning that no single country, company, or institution can adequately address the security challenges they create alone. This is especially true as AI agents become more capable and more embedded in real-world contexts.
Because AI models and applications operate across borders, security measures require international cooperation on shared methods, common tools and information-sharing channels. The same foundational research can also support adjacent safeguards, from content provenance against deepfakes to safer AI chatbot design.
To meet new security requirements, AI developers and governments across jurisdictions and sectors will need to drive additional joint research, more comparable evaluation methods and robust best practices. These should cover the full AI security lifecycle, from protecting models and pre-deployment assets such as model weights and datasets to the security and resilience of AI applications and services during deployment, especially in critical sectors.
A first approach to strengthening AI security requirements would be to pool resources across three areas: resilience against scalable, reusable attacks, such as prompt injection, particularly at the interaction layer; ensuring the secure connection of AI agents to tools and services; and strengthening safeguards for models, model weights, and training data integrity.
Priority 1: Defending against transferable and automated prompt-injection attacks
Direct and indirect prompt-injection attacks are becoming more reusable, scalable, and security relevant. That is why security researchers at the Open Worldwide Application Security Project (OWASP) rank prompt injections among the most prevalent AI security risks. While evidence on transferability is still developing, recent research suggests that some attacks can be adapted across harmful tasks and, in some cases, across different models.
For example, an AI assistant used in a workplace might be asked to summarise a document or webpage. If that content contains hidden malicious instructions, the system could be manipulated into ignoring the user’s request, revealing sensitive information, or taking an unintended action. That raises practical questions for enterprise deployment, testing, and incident response.
This matters because reusable or automated prompt-injection methods reduce attacker costs and make attacks easier to repeat. For policymakers, this shifts the question from whether a model can be bypassed in a lab setting to whether it remains resilient to attacks that are reused, adapted and improved over time.
The frontier security community should prioritise understanding why some prompt-injection attacks transfer more readily than others and develop evaluations that reflect adaptive, automated attack strategies. Rather than simply blocking known prompt patterns, they should also identify techniques that improve robustness. Recent benchmark work from MLCommons, a technical safety organisation, suggests that classifying attacks by model-manipulation techniques would help evaluators get closer to the underlying mechanisms of vulnerability.
Automated prompt-injection techniques are becoming more transferable and scalable, making it easier to discover, reproduce and act on vulnerabilities across systems. Evaluation capacity will therefore need to support ongoing assessment of how advances in frontier AI may accelerate vulnerability discovery and exploitation. This will be critical both for ensuring defensive testing keeps pace with evolving attack methods and for helping countries use AI more effectively to strengthen cyber resilience.
International collaboration could improve prompt injection evaluations and universal jailbreaks by making it easier to identify reusable and transferable vulnerabilities. International collaboration could improve evaluations of prompt injection and universal jailbreaks by identifying reusable and transferable vulnerabilities. It could also help to direct research investments from governments and frontier labs toward more robust evaluations and more durable defences.
Priority 2: Securing AI agents
AI agents create a new set of security challenges. Attacks can manipulate content before an agent application retrieves it, misuse connected tools, or hide malicious instructions in documents processed by the agentic system.
Consider an AI agent connected to email, calendars or payment tools. With broad permissions and malicious instructions, failures can become concrete: the agent may share sensitive information, trigger unwanted actions, or move the user’s money in unintended ways.
Because agents can plan tasks, use tools, retain memory and interact with other systems, each capability creates new opportunities for misuse and failure. Three examples illustrate this challenge:
Memory poisoning: Attackers insert malicious content into an agent’s memory or long-lived context, causing harmful behaviour that goes undetected and persists in future interactions.
Tool misuse: As AI systems adopt standardised methods, such as the Model Context Protocol (MCP), to connect to external tools, databases, and services, weak identity controls or excessive permissions can create new security gaps.
Context-based instruction attacks: Malicious instructions are hidden in emails, documents, or web pages and then retrieved by an agentic AI system, which treats them as part of its working context, potentially leading to unintended actions or data leakage.
These patterns go beyond traditional threat models. Recent work, including OWASP’s Top 10 for Agentic Applications, reflects a broader recognition that memory, connected tools, identity, permissions and multi-step autonomy create a distinct security profile for agentic systems.
Developments in the financial sector illustrate how quickly these questions are becoming pressing. On 2 March 2026, Banco Santander and Mastercard announced what they described as Europe’s first live, end-to-end payment executed by an AI agent within a regulated banking framework. As agentic AI systems move into higher-stakes domains, coordination on security baselines and implementation practices will become increasingly important.
AI agents will need to be made secure by design, and the external tools and services they connect to will need to be made secure. Design improvements could include stronger memory safeguards, better permission design and more effective sandboxing. Measures to make services reliant on agentic AI more robust could include research into deterministic controls that constrain how an agent can transfer information among untrusted content, memory and tool actions.
Cybersecurity institutions need to be involved from the beginning because issues related to AI agents—such as permissions, connected tools, and secure deployment in sensitive settings—build on well-understood challenges faced by cyber agencies. International collaboration among AI Institutes could help adapt existing security practices to agentic systems, identify shared vulnerabilities, and promote more uniform methods for testing, incident management, and secure deployment.
Priority 3: Detecting and mitigating model poisoning
Model poisoning happens when attackers introduce vulnerabilities or alter a model’s behaviour by manipulating training or fine-tuning data. Until recently, it was often assumed that this would require control over a significant share of a model’s training data, implying that larger models trained on broader datasets would be harder to compromise.
In practice, this means that poisoned content can propagate through the AI supply chain, shaping the behaviour of downstream models even when the original model developer has not been directly compromised.
That can have serious consequences for the security of open-weight models. An attacker could seed a small number of poisoned public documents that would propagate into multiple downstream training runs and forks without access to the original developer’s pipeline.
Promising research by Microsoft’s AI Red Team has explored ways to detect backdoored models at scale after they have been trained and shared. Early techniques identify poisoned models by analysing behavioural signatures and links between backdoors and memorisation, pointing to a promising solution in a previously difficult-to-detect risk area.
However, simply demonstrating that poisoning is possible is not enough. Research to improve the detection of compromised models and to strengthen safeguards during training and fine-tuning would help. So would developing more practical methods for recovery when poisoning is suspected. Promising research techniques are emerging, but they are not yet reliable across all models and deployment settings. This is where coordinated action and international collaboration among universities, frontier labs and AI institutes would be particularly valuable.
What shared AI security could look like in practice
These three security priorities show that no country is likely to build the necessary evidence base, testing capacity and operational practices on its own. The more effective objective is therefore to strengthen the foundations of shared AI security: maturing best practices, advancing targeted research, building clearer expectations around deployment conditions and improving cross-country coordination in ways that support more secure adoption over time.
Practical progress can start by establishing building blocks that enhance interoperability and gradually boost the effectiveness of national efforts.
International efforts led through the G7 and the OECD – GPAI are well placed to advance this agenda through a few practical building blocks :
Shared benchmarks and testing environments are essential. Countries and research organisations require standardised methods to evaluate poisoning risks, agentic vulnerabilities, indirect prompt injections and resilience to jailbreaks across various models and deployment scenarios.
Better channels for information-sharing on vulnerabilities. AI-related vulnerabilities often do not align well with existing cyber-disclosure procedures. Enhancing AI security calls for reliable means for sharing exploit techniques, mitigations and lessons learned in ways that support both transparency and the secure handling of sensitive information.
Common reference points for secure design. International coordination can help align threat-modelling practices that clarify emerging failure modes, risk-management approaches that translate those risks into governance best practices and security standards for critical components and infrastructure, including model weights. Together, these can support more secure implementation in practice.
Enhanced public-private dialogue. AI security is evolving too quickly for governments, researchers and companies to work in isolation. Regular exchange channels can help policymakers understand emerging risks while giving researchers and firms clearer signals on where shared benchmarks, disclosure practices and secure design guidance are most needed.
AI institutes, including members of the AI Network for Advanced AI Measurement, Evaluation and Science, can help align evaluation priorities and testing methods. Universities and independent researchers can deepen the knowledge base in fast-moving domains where attack and defence techniques evolve rapidly. Cybersecurity authorities can help turn emerging lessons into operational practices for secure deployment, especially in higher-stakes environments.
These communities should invest in resources, tools, policies, and operational capabilities to assess how frontier AI might. speed up vulnerability discovery. Beginning with France’s G7 Presidency, the next immediate steps could facilitate closer alignment on key research and evaluation priorities and improve information-sharing channels to manage these risks effectively.
For nations aiming to expand AI throughout their economies, integrating security into AI development and deployment processes will be crucial to promoting AI diffusion and adoption. As new models develop stronger reasoning and coding capabilities, governments, researchers, and companies will need better ways to measure their capabilities and define limitations. That makes shared research roadmaps, stronger testing methods and practical security practices more urgent for trusted deployment.
Across major economies, trustworthy artificial intelligence is rapidly moving from high-level policy to deployment in core industries such as health, manufacturing and mobility. The European Union is positioning itself for this shift by focusing not only on innovation capacity but also on trustworthy and coordinated implementation across its Member States. Gaining a deeper understanding of where AI is already being applied and gathering evidence on determinants of adoption are essential to assess Europe’s competitiveness and policy readiness.
The European Union is pursuing its ambition to become a global leader in trustworthy AI, moving from high-level policy to on-the-ground implementation. The OECD worked closely with the European AI Office to monitor efforts to develop trustworthy AI and promote its development across the European economy, with a two-volume publication series analysing how this transition is taking place in practice. The first volume focuses primarily on national strategies, initiatives and governance mechanisms for AI in EU Member States. The second, Progress in Implementing the European Union Coordinated Plan on Artificial Intelligence (Volume 2), shifts the lens to sector-specific impact.
The report supports efforts by the European Commission and EU Member States to promote the development, deployment, and use of AI technologies across priority sectors. It draws on extensive multi-stakeholder engagement, including semi-structured interviews with industry experts and insights from dedicated stakeholder workshops. It focuses on concrete use cases that address specific needs in agriculture, healthcare, manufacturing and mobility, selected high-impact sectors where AI can contribute to digitalisation, sustainability and economic resilience. These sectors are most prominently featured across national AI strategies (Figure 1) as priority sectors for AI applications.
Figure 1. Key priority sectors in national AI strategies and policies of EU Member States
Agriculture: from precision to sustainability
Globally, agricultural producers are increasingly turning to AI-enabled precision tools to address labour shortages, environmental pressures and resource constraints. Within Europe, similar dynamics are shaping experimentation with AI-supported farming systems aligned with environmental targets under the European Green Deal.
As AI-driven solutions help optimise resources, reduce chemical inputs and maintain yields, the EU’s agricultural sector is exploring AI deployment to address structural workforce shortages and sustainability requirements. AI-powered agricultural robots and crop and soil monitoring systems are playing a growing role in improving resource efficiency.
Robs4Crops, for instance, illustrates how computer vision and sensor-based systems can enable autonomous mechanical weeding and spraying in vineyards, crop fields and apple orchards. AI4SoilHealth, in turn, is developing an open-access, AI-driven digital infrastructure to help assess and monitor soil health metrics across Europe.
At the same time, many initiatives remain at pilot or experimental stages. Limited digital infrastructure in rural areas, fragmented and inaccessible datasets (due to the resources required to collect high-quality, diverse data across crops, soil, and livestock, and to limited interoperability of existing public datasets), financial barriers, and uncertainty over return on investment continue to constrain large-scale adoption.
Healthcare: enhancing diagnostics and operations
Health systems worldwide are using AI to improve diagnostic accuracy and manage increasing service demand. In Europe, demographic ageing and workforce shortages are strengthening the case for deploying AI across both clinical and operational settings.
AI can help address rising costs and workforce shortages in healthcare while improving patient outcomes through faster and more accurate diagnostics.
One of the most impactful use cases is AI-enhanced medical imaging for the early detection of conditions such as cancer, supported by initiatives including the European Cancer Imaging Initiative. Similar approaches are already being deployed in the United States and Japan, where AI-assisted radiology is helping reduce diagnostic backlogs, highlighting the strategic importance of scaling comparable capabilities across Europe.
Beyond clinical care, the report explores how AI is improving hospital operations. Predictive and optimisation AI systems can help forecast patient inflows and manage bed occupancy, helping healthcare providers reduce staff pressure and waiting times. Perplex, an EU-funded initiative, illustrates how AI can help automate and optimise scheduling and resource management in the outpatient department of a hospital in Madrid.
Despite this potential, barriers such as fragmented health data environments and trust challenges remain significant constraints.
Manufacturing: the rise of industrial intelligence
Competitiveness in the manufacturing sector increasingly depends on integrating AI into production systems, supply chains, and quality control processes. While other major economies are accelerating investment in smart factories, adoption across Europe remains uneven.
AI adoption in EU manufacturing remains modest and highly fragmented, with pharmaceuticals and electronics leading the way, while traditional industries such as textiles and food processing progress more slowly.
Despite these differences, there are areas where AI could have a substantial impact. The report highlights three priority use cases: predictive maintenance, quality assurance and control, and supply chain optimisation.
Predictive maintenance systems, such as those developed through the Made in Europe Partnership, analyse sensor data to forecast equipment failures and reduce costly downtime. In quality control, AI-powered inspection improves efficiency by identifying defects in real time. Comparable smart-manufacturing deployments in East Asia and the United States demonstrate how scaling such applications can strengthen productivity growth and industrial resilience.
Mobility: navigating toward a connected future
Transport systems are becoming increasingly data-driven as cities and logistics operators deploy AI to improve safety, efficiency and sustainability. Across Europe, mobility-sector deployment is closely linked to broader digital and climate transition strategies.
AI can help transport and mobility systems become safer, more efficient and more sustainable. AI-enabled traffic management systems, such as those explored in the AI4Cities project, can reduce congestion by dynamically adjusting traffic-light patterns. Automated driving technologies and intelligent freight logistics systems can further optimise routes and scheduling efficiency. Here, the EU Connected, Cooperative and Automated Mobility (CCAM) Partnership aims to accelerate the transition from research prototypes to real-world applications.
These developments are intended to align with the Sustainable and Smart Mobility Strategy, although gaps in infrastructure readiness and investment capacity remain important constraints for many operators.
Overcoming barriers to scale
Progress in Implementing the European Union Coordinated Plan on Artificial Intelligence (Volume 2) demonstrates significant sectoral potential for AI deployment, while identifying persistent bottlenecks that continue to slow implementation. Addressing these constraints will be critical to moving from experimentation with pilots to widespread deployment that fundamentally transforms the European economy for the better. To do so, the report puts forward a number of key recommendations, including the following:
Focus on concrete sector-specific AI use cases
Targeted policies, investment, and collaboration will be essential to unlock AI’s full potential in key sectors of the EU’s economy. Public-private-academic partnerships, open innovation platforms, and cross-border collaborations can accelerate AI development and adoption, particularly when grounded in sector-specific needs. Focusing on concrete AI use cases, building ownership and trust through transparency and co-design with end-users, and demonstrating tangible benefits will be key to ensuring that AI strengthens Europe’s economic competitiveness, sustainability, and societal well-being.
Strengthen data foundations
Investing in high-quality datasets, common standards and shared governance frameworks can enable secure, privacy-preserving data sharing across borders and sectors. Improving data representativeness and reducing fragmentation will lower entry barriers and support downstream AI adoption.
Expand infrastructure and compute capacity Investments in broadband connectivity, cloud and edge computing, 5G networks and AI compute environments—including AI factories and high-performance computing centres—are essential to bridging regional gaps. Initiatives such as EuroHPC are helping ensure that economic actors, including SMEs, can access the computational resources required to train and deploy advanced AI models.
Close the skills and talent gap Unlike their larger counterparts, who tend to have more resources at their disposal, smaller firms and public organisations require access to technical expertise and sector-specific training before large-scale deployment of AI becomes feasible. European Digital Innovation Hubs (EDIHs) are supporting this process through a “test before invest” approach that lowers adoption risks.
Enhance trust and regulatory coordination Regulatory sandboxes allow firms to test innovative AI applications under supervisory conditions, enabling regulatory learning and improving compliance readiness before market entry. Providing clearer guidance and harmonising regulatory interpretation across Member States will remain particularly important for start-ups and SMEs operating under the EU AI Act, alongside relevant existing rules such as the GDPR.
Many of the report’s findings align with the European Commission’s Apply AI Strategy, which focuses strongly on accelerating adoption and the active deployment of AI across the economy. The OECD and the European Commission will continue working together to support implementation of the Strategy and to ensure that lessons from European AI deployment experiences contribute to the broader global AI policy community.
The authors would like to thank John Leo Tarver for his contributions to this report series and blog posts.
In countries around the world, the public sector must ensure the trustworthiness of any algorithmic tools it wants to deploy by verifying that they function as intended, ensuring fair and acceptable use, and guaranteeing explainability of outputs.
Still, numerous high-profile incidents have emerged in which failing to consider one or more of these factors has led to undesirable events or outcomes in areas such as educational qualifications, social security, and debt. The truth is that the widespread use of AI is still new and much remains to be done to standardise approaches to safe deployment.
Nobody notices infrastructure until it fails
This is a common saying in the public sector. To this end, much of the important work in AI governance is routine day-to-day processes, guidance documentation, and activities within organisations that lead to the safety and responsible use critical for trustworthy AI.
The Algorithmic Transparency Recording Standard (ATRS) fits this description. It is a UK government initiative that establishes a standardised way for public sector organisations to publish information about how and why they use algorithmic tools.
In 2024, GPAI ran a project on Algorithmic transparency in the public sector, led by Juan David Gutierrez from Universidad de los Andes in Colombia and supported by CEIMIA (Centre d’Expertise International de Montréal en Intelligence Artificielle) – one of the three Centres of the GPAI Expert Community. The study reviewed global best practices and featured three case studies from Chile, the European Union and the UK. At its core, it explored why countries pursue such initiatives and how championing transparency can help avoid controversies and improve public trust. Before diving into the details of the standard, it is worth looking at a few cases that illustrate why such a standard is necessary.
Figure showing the reason why democracies might adopt algorithmic transparency initiatives, taken from the GPAI 2024 Algorithmic Transparency report
A ‘mutant algorithm’, or just opaque?
In the UK, one of the most high-profile controversies occurred in 2020, involving a school exam grading algorithm that estimated grades for students who did not sit formal exams due to COVID. The algorithm was subsequently found to unfairly benefit private school students while limiting test scores from publicly funded schools. There are also several examples of opaque uses of algorithms within benefits systems. Australia’s ‘Robodebt’ scheme assessment programme fell under scrutiny for generating false debts, resulting in significant impacts on affected individuals. In Denmark, algorithms used by the country’s welfare agency have been the subject of reports of potential mass surveillance, discrimination and social scoring.
Beyond governments, equally high-profile cases have involved algorithms used in hiring systems or credit scoring that discriminated against people based on their gender, race or ethnicity.
Many of these controversies were exacerbated by the opacity of the algorithms used: certain impacts could have been reduced by proactively sharing information about tools and by working with the public and civil society during testing, development and implementation to identify risks ahead of deployment. The tools’ developers would have had the opportunity to engage with comprehensive information in the public domain, rather than relying on incorrect or incomplete information. This is all essential to ensure our emerging ‘algorithmic infrastructure’ stays ‘routine’, behind the scenes, and working as intended.
To address this, the UK government published the ATRS in November 2021. In a nutshell, ATRS provides a structured template and public repository to improve transparency, accountability and public trust by documenting how algorithmic tools work, their purpose, and their impact on decisions that affect citizens. In 2025, reporting the use of algorithms via the ATRS became mandatory for central government departments and Arms-Length Bodies (a specific classification of public bodies in the UK).
To build on the momentum, the government committed to the Roadmap for Modern Digital Government to compile and publish records of all identified in-scope algorithmic tools (as of March 2025) in government departments (excluding their associated public bodies) by the end of 2025. This was achieved, and at the time of writing, 125 ATRS records have been published, with more in progress.
International engagement and CEIMIA initiatives to improve ATRS
The Standard received international attention, with the OECD identifying it as a world-leading initiative and featuring it on the Observatory of Public Sector Innovation. In Europe, the Estonian government translated the Standard and piloted it as part of the UK-Estonia Tech Partnership, providing insights into how the Standard can be implemented across different jurisdictions.
Following the 2024 GPAI project on algorithmic transparency, the UK government’s Department for Science, Innovation and Technology (DSIT) entered into a partnership with CEIMIA under the brand of the Centres of the GPAI Expert Community to review the existing UK transparency standard and obtain rapid feedback as the standard continues to develop. ATRS also benefits from input from a group of international experts, many of whom participated in the initial 2024 GPAI project. The results informed a set of recommendations, which the UK government is currently considering for a future update.
Testing the Standard through international partnerships, such as the one with Estonia and the Centres of the GPAI Expert Community, is a way for the UK to share best practices, a cornerstone of driving responsible data and AI practices globally.
Transparency and security must work together
Responsibility in a public technology context is often about striking a balance, which can require difficult trade-offs. Transparency matters, but so does security, especially in today’s geopolitically unstable environment.
How algorithms interact with and shape public life remains a major focus worldwide. One of the key themes at the India AI Impact Summit 2026 was Safe and Trusted AI, under which transparency was a specific concern, and the G7 could discuss it as a critical issue.
Transparency is essential for governments adopting algorithmic tools to enhance productivity and growth. Ensuring that it is a priority for public-sector organisations is an ongoing learning process. As the ATRS Standard gains wider recognition and adoption in the UK and beyond, DSIT continues to explore ways to improve it. Part of this involves researching how public-sector teams interact with the ATRS process and balancing security and safety considerations, including those related to cyber threats.
In the end, all of this helps DSIT to create a healthy balance between maximising transparency – protecting citizens – and ensuring that digital government services remain safe and secure.
Participatory AI initiatives are meant to bring together diverse stakeholders to design and oversee AI systems that are fair and trustworthy. However, a recent review of 80 participatory AI initiatives revealed that, rather than providing participants with genuine decision-making power, the vast majority consult specific communities on narrow implementation details.
Meanwhile, every major AI lab now conducts some form of public consultation, the EU AI Act requires stakeholder involvement, and the OECD AI Principles regard stakeholder engagement as a fundamental element of trustworthy AI. Participation in AI governance has become more popular than ever. But an uncomfortable pattern is emerging: the more we discuss participation, the less we discuss meaningful engagement, real influence and power.
Many participatory approaches primarily involve communities during the early stages of the AI system lifecycle: design, data collection, and model development, while later stages, such as deployment, monitoring and system evolution, attract far less attention. During my fieldwork across Kenya, Malawi, and the Philippines, a troubling question keeps surfacing: once the participatory design phase concludes, who truly governs the AI system? Even highly participatory processes often dissolve once the system is launched. Governance then shifts back to those who built or commissioned the system. Communities involved in shaping the design often have little influence over how systems evolve to meet ongoing community needs or how they expand beyond their initial scope.
The old lesson we keep relearning
Back in 1969, urban planner Sherry Arnstein published a deceptively simple insight: not all participation redistributes power. Her “ladder of citizen participation” described eight levels, from manipulation at the bottom to citizen control at the top. She called the middle rungs “tokenism”: processes that perform inclusion without actually transferring authority. Arnstein was writing about urban planning in American cities, but her framework resonates powerfully in today’s AI landscape.
Over fifty years later, AI researchers are revisiting this lesson. Recent studies have introduced the concept of “participation washing”: the act of claiming inclusion without the necessary redistribution of power. Other researchers have documented how participatory rhetoric often conceals the ongoing centralisation of decision-making authority.
These findings paint a consistent picture. Participatory AI, despite methodological progress, largely remains at Arnstein’s “consultation” and “informing” levels rather than reaching the “partnership” or “delegated power” levels. The reasons for this are understandable. Genuine participation is costly, slow, and fosters accountability relationships that complicate rapid development and deployment cycles. Organisations optimising for scale naturally minimise governance complexity. However, this means participatory AI often reproduces the very power imbalances it seeks to address.
Sherry Arnstein’s ladder of citizen participation
The real divide: Methods versus infrastructure
Despite all this, the field has made genuine progress in developing methods to meaningfully involve people in AI design. The repository of tools and metrics on the OECD.AI Policy Observatory showcases participatory frameworks that now guide humanitarian and public sector AI initiatives globally. Methods have become increasingly sophisticated, moving beyond superficial consultation towards authentic co-design. What remains underdeveloped is the infrastructure for ongoing governance after deployment.
Think of it this way. Methods answer: “How do we involve people in design?” Infrastructure addresses: “How do people exercise authority after deployment?”
This distinction matters because AI systems, as the OECD definition emphasises, are adaptive. They are never “finished.” They evolve continuously through new training data, model updates, and deployment expansions. Each evolution requires governance decisions.
AI also relies on collective data. These are not tools that individuals choose to use; rather, they are infrastructure that processes communal information and makes decisions that affect entire populations. Without proper governance, participation during the design phase can inadvertently legitimise systems that centralise power. “We consulted the community” becomes a justification for deployment, even if communities no longer hold any authority over the system’s future.
What commons governance looks like in practice
If the challenge is institutional, what institutional forms could address it? One promising approach draws on principles from natural resource commons. Economist Elinor Ostrom received the Nobel Prize for demonstrating that communities can effectively manage shared resources such as fisheries, forests and irrigation systems. The application of commons governance to knowledge and digital resources has been extensively developed in later work, from Hess and Ostrom’s study of knowledge commons to comprehensive frameworks for analysing knowledge commons governance across various institutional contexts.
Commons governance models have several features that matter for AI: collective ownership, where communities hold rights to the resource; participatory decision making, where rules for usage and development are established through community processes; value sharing, where benefits are returned to the community; and continuous stewardship, where governance continues as long as the system operates.
The work I contribute to involves exploring whether these principles can guide AI system development in resource-limited settings. In Malawi, our research team at NYU and our local partners are creating a voice-based crisis reporting system designed to ensure that community governance councils oversee data practices, model updates, and deployment decisions. In the Philippines, we are collaborating with Kalinga State University on an Indigenous Knowledge Data Collaborative that allows communities to control how their traditional knowledge is digitised and used. The CARE Principles for Indigenous Data Governance, emphasising Collective benefit, Authority to control, Responsibility, and Ethics, offer a powerful framework here. These principles emerged from broader movements around Indigenous data sovereignty and represent a significant way to reshape data governance around community authority rather than external oversight.
While the OECD AI Principles mention data trusts as a mechanism for ethical data sharing, commons models take this logic further. Data trusts typically delegate authority to trustees acting on a community’s behalf. Commons models place community decision-making at the centre. The community does not transfer control to a benevolent intermediary; it retains authority itself.
Initiatives like Mozilla Common Voice and various Indigenous data-sovereignty movements are exploring this path worldwide, yet critical questions persist. Can commons governance operate effectively in resource-limited humanitarian settings? What occurs when commons governance moves too slowly for operational needs? Our fieldwork aims to address these exact questions.
What we are learning and what presents challenges
I want to be frank about the limitations of this work. These are early-stage experiments, not established models. However, they reveal important tensions that the wider field needs to address. If participatory AI governance is to go beyond words, we must be honest about what makes it challenging.
Power redistribution is costly. Governance meetings involve travel expenses, translation services, and participant compensation. In our work in Malawi, these costs are significant and surpass typical AI development budgets. However, this should be viewed not just as an expense but as an investment in risk mitigation. Without this investment, systems in complex environments risk rejection, non-adoption and even obsolescence.
Democracy is slow, and crises are urgent. Emergency responses demand quick decisions. Community governance takes time. The challenge is to differentiate between decisions that truly require rapid centralised action and those that only seem urgent to technical implementers.
“Community” is not uniform. Gender, age, and ethnicity influence who takes part and whose voice carries weight, and commons governance does not automatically resolve representation issues. However, it does make them visible and demands specific mechanisms to address them.
Sustainability remains uncertain because meaningful participation requires ongoing resources; governance cannot be an afterthought funded by short-term grants. It must be incorporated into budgets from the outset and treated as operational expenditure. International development finance models will need to adapt to support this. A system that works brilliantly for two years and then collapses because governance funding runs out is not a success.
What this means for AI policy
These experiments demonstrate methods to strengthen international frameworks for stakeholder engagement.
First, we need clearer distinctions between engagement levels. Consultative engagement involves gathering input to inform others’ decisions. Governance authority means stakeholders exercise binding power over system operation. Frameworks often conflate these two very different concepts. When a government or company says it has “engaged stakeholders,” does that mean it sought feedback or that it shared power? Making this distinction explicit helps implementers understand what they are truly committing to, and helps communities know what to expect.
Second, resource models need to change. Governance infrastructure, including ongoing meetings, capacity building, and conflict resolution, should be seen as a way to protect assets rather than as overhead. Current assessments of AI pilots rarely differentiate between technical and governance factors when a project fails. This complicates the process of allocating resources effectively. Funding structures must recognise that governance is the mechanism that maintains an AI system’s viability and trust over time.
Third, we need governance metrics. The OECD effectively monitors AI policy implementation. But we also need ways to measure the quality of power distribution. Who makes binding decisions about how a system evolves? Just as “technical debt” builds up when code is rushed, “governance debt” accumulates when engagement is overlooked. Eventually, the interest is paid in the form of lost trust or system failure. Recent work on AI accountability frameworks suggests promising directions for creating such assessments.
Finally, community data ownership has an unclear legal status in most jurisdictions. Cross-jurisdictional research on legal frameworks that support collective governance would be very valuable. Experiments such as New Zealand’s Māori data sovereignty frameworks and Barcelona’s data cooperatives offer promising models to learn from. The goal is not to impose universal frameworks but to document what works, what does not, and where the legal gaps are most severe.
Community governance authority as infrastructure
The participatory turn in AI governance represents genuine progress. However, involving people during design without engaging them in governance risks becoming a sophisticated form of consultation that maintains existing power structures. This is exactly what Arnstein warned against more than fifty years ago.
Moving from participation to power involves treating community governance authority as infrastructure: something that requires investment, upkeep, and institutional backing comparable to the technical systems it oversees. It means funding that supports governance alongside technical development. It means metrics that evaluate power distribution, not just engagement processes. And it means honest recognition that meaningful participation is slower and more costly than consultation, but also more likely to produce systems that communities genuinely trust and use over the long term.
Eighty participatory AI initiatives were reviewed, and most of them never moved beyond consultation. That finding should concern anyone who values participation. If we are serious about closing the gap between engagement and authority, we must start building the governance infrastructures to do it. AI remains in its early stages, and there is much we still need to understand. But one thing is becoming clear: if AI is considered infrastructure, it requires governance infrastructure. Otherwise, there is no trustworthy AI.
The international community has made significant progress in defining what responsible AI looks like. The next step is investing in the unglamorous, difficult, and necessary work of establishing governance structures to uphold these standards. This involves supporting communities not only as participants in design but also as equal partners in decision-making.
Among the various tools available to policymakers, regulatory sandboxes have gained considerable prominence in the AI governance landscape because they enable supervised innovation testing under controlled conditions and within limited timeframes. This can help to identify risks early, foster regulatory learning and refine regulatory requirements before they are applied at scale.
As AI regulatory sandboxes expand across jurisdictions and sectors, common design principles, recurring challenges and opportunities for greater effectiveness and policy coherence are emerging. As this happens, institutional co-operation and knowledge sharing are more important for ensuring coherent and effective regulatory experimentation both nationally and across borders.
In November 2025, the OECD webinar “AI Sandboxes: Sharing knowledge for success” brought together government officials, regulators and policy experts from seven countries to discuss the design and implementation of AI regulatory sandboxes. Here are the event’s key takeaways.
What is an ‘AI regulatory sandbox’?
Although there is no universally accepted definition, a regulatory sandbox generally offers temporary regulatory flexibility or waivers, allowing innovative products, services, or business models to be tested under controlled conditions and regulatory oversight. This approach promotes responsible experimentation and innovation while protecting the public interest.
To cite a few examples, Singapore’s AI healthcare sandbox offers guidelines for synthetic data to minimise privacy risks while allowing realistic testing. In the UK and other countries, AI-powered innovations in financial services are being tested under supervision that helps to prevent consumer harms such as biased scoring and automated decision-making.
In AI, this approach aligns with the OECD AI Principles – specifically Principle 2.3, which encourages governments to promote experimentation to enable the safe testing and scaling of AI systems. Similarly, the Recommendation of the Council for Agile Regulatory Governance to Harness Innovation urges governments to facilitate greater experimentation, testing, and trialling to stimulate innovation under regulatory supervision.
AI regulatory sandboxes are valuable for testing new technologies and rules in a safe, controlled way before full rollout. They offer less benefit if risks are low or if rules are already well established, but can be useful for compliance and learning in more complex regulatory environments. Decisions to utilise sandboxes should follow clear criteria to ensure efforts are appropriately targeted. Generally, initiatives with high innovation potential, substantial risks, and opportunities for regulatory discovery and improvement (including by removing barriers to beneficial innovation) should be prioritised. Key regulators, industry actors and other relevant stakeholders should be involved in this process.
In July 2023, the OECD published the policy paper Regulatory Sandboxes in artificial intelligence. Building on lessons from fintech, the report highlights the benefits of AI sandboxes, including accelerating market entry, improving regulatory understanding, and stimulating investment. It also explains why adapting the traditional sandbox model to AI presents unique technical and governance challenges. As a cross-sectoral technology, AI covers multiple legal, ethical, and technical domains, requiring strong coordination among several regulatory authorities.
Since the paper’s release, the use of AI sandboxes has accelerated. By February 2025, the Datasphere Initiative identified over 60 sandboxes worldwide related to AI, data, and technology. Furthermore, key regulatory and policy frameworks, including the European Union’s AI Act and America’s AI Action Plan, view regulatory sandboxes as essential tools for fostering AI innovation and ensuring the safe development and adoption of AI.
Insights shared during the webinar by experts from Spain, Thailand, Luxembourg, Brazil, Korea, Israel and Singapore offer valuable lessons on how different jurisdictions design and operate AI sandboxes, highlighting what works, where challenges arise, and how approaches vary across contexts. For example, Spain provides appropriate, tailored guidance to ensure effectiveness and facilitate regulatory compliance further down the line. Brazil’s sequenced approach includes capacity-building to enable participants to contribute to effective experimentation and evaluation.
Six insights about AI regulatory sandboxes from around the globe
1. AI sandboxes are not uniform
According to the Datasphere Initiative, three primary types of sandboxes are emerging worldwide, especially within the context of AI. Regulatory sandboxes: Collaborative processes where regulators work with innovators to test innovations under regulatory supervision.
Operational sandboxes: Testing environments and infrastructure where data can be hosted and accessed in controlled conditions.
Hybrid models: Combining regulatory oversight with operational capabilities, sometimes offering infrastructure and operational spaces for testing and experimentation (e.g., “supercharged sandbox” in the UK).
These models intervene at different phases of the policy and regulatory lifecycle. Some are employed before formal regulation to identify gaps and suggest necessary updates. Others operate during the development process, supporting iterative regulatory design. Some focus on helping understand legal obligations and ensure regulatory compliance, such as under the EU AI Act. Sector-specific sandboxes are also common, with countries adopting different approaches depending on regulatory priorities and institutional settings. Across these models, regulatory waivers are frequently used to enable experimentation under regulatory supervision.
Several experimentation-related initiatives, such as regulatory testbeds, living labs, or policy prototyping, share certain features and objectives with regulatory sandboxes. What truly distinguishes sandboxes is that they are the most institutionalised form of regulatory experimentation, usually led by regulators and integrated with regulatory supervision.
2. Coordination is essential
AI does not always fit neatly within existing sectoral, jurisdictional, or administrative boundaries. Its development and deployment span multiple regulatory domains, making effective coordination crucial. Luxembourg’s approach demonstrates this well, showing that AI sandboxes are more than testing spaces—they are platforms for regulatory collaboration and coordination. Luxembourg’s model brings together 11 authorities and innovation actors to align priorities and prevent fragmentation, emphasising the need for skilled project management alongside legal and technical expertise.
Specific stakeholders within the AI ecosystem pursue different objectives: data protection authorities concentrate on privacy, cybersecurity authorities on resilience, and innovators on efficiency and speed. They also offer different kinds of expertise. Sandboxes can offer a neutral space to reconcile these priorities, fostering trust and mutual understanding. To achieve this, managing the expectations of involved parties and clearly defining the objectives of a sandbox are particularly important steps.
In Thailand, a multi-faceted approach to AI regulatory sandboxing shows how balancing safety and flexibility depends on agile cooperation between sectoral regulators and industry. This approach integrates three complementary pathways: in the short term, fostering AI deployment where existing rules already allow it; in the medium term, establishing sector-specific sandboxes to manage domain-specific risks and opportunities; and eventually, developing system-wide sandboxes, including for government use, to test cross-cutting applications. Together, these mechanisms help promote AI-driven innovation within current legal frameworks while leveraging testing and experimentation to better understand the implications of emerging AI applications. Effective coordination is essential to prevent duplication of effort, regulatory gaps or conflicting rules.
Sandboxes can also play a valuable role in involving expert and academic communities in the development of AI regulation, with countries such as Spain, Luxembourg, and Brazil benefiting from such expertise at multiple stages of sandbox design and operation.
3. From policy to practice, and back again
AI sandboxes are increasingly used to bridge the gap between regulatory frameworks and real-world implementation. For example, Spain’s regulatory sandbox pilot translates the EU AI Act’s requirements for high-risk AI applications into practical compliance steps, enabling early identification of gaps and clarifying obligations for deployers. In December 2025, the Spanish AI Supervision Agency (AESIA) published a series of introductory and technical resources, developed from insights gathered during the regulatory sandbox pilot, that demonstrate how sandboxes can support evidence-based compliance guidance. Luxembourg’s AI sandbox, in turn, acts as a coordination platform to ensure lessons learned on overlapping obligations feed into the domestic operationalisation of the EU AI Act and related future guidance.
In July 2025, Singapore launched its Global AI Assurance Sandbox, building on insights from a previous pilot phase, to create a testing environment where creators or deployers of GenAI applications can have their applications evaluated by expert technical testers. Key risk aspects examined during testing include hallucination, undesirable content, data leakage, and vulnerability to adversarial prompts, with the findings informing policy guidance. Brazil’s Regulatory Sandbox on AI and Data Protection also exemplifies this trend. It aims to promote transparency, privacy by design and responsible innovation in AI systems that handle personal data, using structured experimentation to help innovators achieve regulatory compliance and assist regulators in understanding how rules work in practice and where adjustments may be necessary.
Simultaneously, AI sandboxes continue to shape future regulatory frameworks. In Thailand, sector-specific sandboxes for digital payments, digital assets, banking and insurance are expected to help regulators understand real-world AI applications and prepare for system-wide governance. As sandboxes move regulation from theory to practice and back to policy, they create an iterative loop that can strengthen trust and adaptability in AI governance. To achieve this, sandboxes should generate insights to inform better regulation. This, in turn, requires consistent reporting, sharing of results, and the establishment of feedback loops across sectors and countries to boost compliance and policy development.
This is one example of a knowledge-sharing process in AI regulatory sandboxes.
Nevertheless, translating sandbox results into regulatory improvements remains challenging, even in countries like Korea, which has considerable experience conducting regulatory experiments across sectors.
4. Incentives matter
Participation in AI sandboxes is not automatic. Clear and well-designed incentives are essential for both innovators and regulators. Israel, for instance, has introduced a government fund that provides financial support, legal counselling and mentorship for regulators launching AI sandboxes, while also offering grants to participating firms. Similarly, Singapore reduces testing-related barriers to GenAI adoption through practical guidance and access to specialised testing partners.
These models recognise a fundamental challenge: AI experimentation is resource-intensive and needs to focus on areas where it matters most. Without targeted support, regulators may struggle to operate sandboxes, and companies might be hesitant to participate. Furthermore, when offering incentives, authorities should encourage a diverse mix of participants—small firms, big players, different sectors, and different AI applications—to ensure that sandbox insights are both representative and robust. The complex nature of regulatory sandboxes themselves may also pose challenges for some applicants or even participants. In this context, Brazil outlined a three-stage execution framework, starting with capacity building for selected participants undertaken by a partner university, before advancing to the experimentation and evaluation phases.
5. The growing need for interoperability and cross-border collaboration
As AI systems operate across borders, there is a growing need for AI sandboxes to extend beyond national borders. Without international coordination, firms may engage in ‘jurisdiction hopping’, seeking the most permissive regulatory environments. Interoperability between sandboxes is thus becoming a governance necessity. Cross-border collaboration is also crucial for international regulatory cooperation. In Brazil’s case, preparatory work to develop the sandbox included international consultations on the experimental methodology. This approach enables the benefit from international practices and standards and facilitates the sharing of experiences in later stages of the project.
Cross-border sandboxes have already proven their worth. Singapore’s Global AI Assurance Pilot, for example, involved 17 AI deployers from nine countries collaborating with 16 specialised testers from the US, UK and Europe. Use cases include summarisation, chatbots to AI applications in healthcare, finance and human resource management. These cross-border tests allowed regulators and companies to understand how AI performs in different legal, cultural and technical environments. For example, a chatbot that safely managed English queries inadvertently leaked confidential information when prompted in Mandarin, demonstrating the importance of multilingual testing.
6. AI sandboxes come with challenges of their own
AI sandboxes face several challenges. Regulators often encounter capacity limitations and lack the technical expertise or project management skills necessary to supervise complex AI systems. Fragmentation and coordination issues also arise, as AI spans multiple sectors and necessitates collaboration among numerous authorities, including across borders.
Designing suitable requirements and safeguards for sandbox frameworks can be challenging, especially when multiple regulatory regimes are involved, as demonstrated by Brazil. Deciding the appropriate level of transparency, human oversight, and data governance can be particularly difficult when firms seek waivers to speed up testing.
At the same time, Korea’s experience demonstrates that although safety and consumer protection rules are vital, excessively strict requirements may deter participation, especially among SMEs, and hinder experimentation. Safeguards should therefore be proportionate to and aligned with the risks posed by the technology, as overly complex procedures can undermine the agility required in regulatory sandboxes in a rapidly evolving AI landscape.
Measuring the impact of AI sandboxes is also difficult. Without clear metrics, sandboxes risk becoming isolated experiments rather than influential policy tools. Ideally, impact should be monitored across various areas, such as faster time-to-market for compliant AI systems, increased regulatory clarity and coherence (including through less fragmentation), and tangible updates to laws and standards shaped by sandbox insights.
Furthermore, as highlighted in a 2024 OECD policy paper, there are potential limitations concerning legality, feasibility, resources, and equity. Regulatory experiments should adhere to constitutional norms, including those concerning equal treatment.
A vital element for responsible innovation and public trust?
As a relatively new regulatory tool designed to address a rapidly evolving general-purpose technology, AI sandboxes raise significant questions about their role. Some of the questions raised during the online workshop include:
What role might civil society play in AI sandboxing?
How can public institutions build the expertise required to supervise regulatory sandboxes involving frontier-level AI systems?
How can sandboxes balance flexibility with protecting long-term societal values (e.g., what types of safeguards should be in place regarding regulatory exemptions)?
What measures, such as reporting and documentation requirements, talent management, and capacity building, are necessary to ensure transparency and build trust in AI regulatory sandboxes?
As AI governance develops and these questions are addressed, AI sandboxes hold the potential to become key tools for promoting responsible innovation, enhancing governance and building public trust in AI systems across the globe.
The OECD is well placed to advance these objectives by facilitating the systematic exchange of knowledge and expertise, and by developing standardised, comparable frameworks for measuring outcomes. It can also use its convening role to support alignment on guidance for the targeting, design and implementation of AI regulatory sandboxes. By grounding this work in empirical evidence and practical experience, the OECD can help strengthen the overall evidence base and inform more effective policy approaches.
The authors would like to thank Natalie Cohen, Lucia Russo, Guillermo Hernandez, Xavier Pearson, Viktor Samek and John Leo Tarver for their contributions to this piece.
AI agents and agentic AI based on large language models are becoming more autonomous and capable of interacting with both physical and virtual environments. As the capabilities of these AI systems grow, they are gaining visibility, and with reason. It is reaching a point where they could become the driving force behind innovation, investment and improved productivity across sectors by streamlining processes and enabling more efficient operations.
While ideas related to agency have long been explored in academic research in fields such as philosophy, economics and computer science, recent advances in AI are stretching conceptual boundaries. As AI’s capabilities evolve, so do our shared understanding of what qualifies as AI agent and agentic AI.
The OECD report, The agentic AI landscape and its conceptual foundations, developed by the OECD.AI Expert Group on Agentic AI, helps clarify what AI agents and agentic AI are and how they differ. Grounded in the OECD AI system definition, the analysis examines how these terms are defined and used across the literature. By analysing key features, overlaps and distinctions and mapping them to thecore elements of the OECD definition of an AI system, the report helps to establish more precise and consistent terminology. And in a rapidly evolving field, conceptual precision is essential for effective, well-informed governance.
Three key messages stand out in the report:
AI agents and agentic AI are closely related, but not interchangeable.
Agentic AI ought to be seen as a socio-technical paradigm.
Despite technological gaps and varying levels of maturity in areas such as digital security and privacy, uptake is growing.
The common foundations and meaningful distinctions of AI agents and agentic AI
Our analysis shows that AI agents and agentic AI share foundational characteristics. Both involve systems with a degree of autonomy that pursue goals and can perceive and act within physical and virtual environments.
However, there are differences that mean these terms are not interchangeable.
AI agents can be understood as systems that perceive and act on their environment with a degree of autonomy, using tools as needed to achieve specific goals and adapt to changing inputs and contexts.
By contrast, agentic AI generally refers to systems composed of multiple co-ordinated AI agents that can break down tasks, collaborate and pursue complex objectives autonomously over extended periods. Agentic AI systems are designed to operate in more open-ended, less predictable physical and virtual environments, and to function with minimal human supervision.
In short, agentic AI is more complex, as it can co-ordinate multiple agents, perform task decomposition and delegation, and sustain operations over longer periods. It can also operate in more complex, less predictable environments with limited human oversight.
Agentic AI as a socio-technical paradigm
Agentic AI systems are not isolated technical artefacts. They are frequently embedded in social contexts and interactions and operate within a socio-technical paradigm.
Their value lies not only in autonomous action, but in interaction with other AI agents, humans and institutional processes. Co-ordination and negotiation across these actors require advanced reasoning capabilities, robust infrastructure and reliable communication protocols.
This relational perspective is an essential part of what agentic AI is. This means that understanding how they interact within broader ecosystems is essential to designing agentic AI systems that function responsibly and effectively, particularly in open or high-stakes environments.
Uptake is accelerating, but maturity is uneven
The report also presents descriptive evidence on trends in AI agent adoption. Many developers have already integrated them into their toolkits, and survey data indicate that nearly half of respondents on Stack Overflow use them or plan to do so.
To be clear, adoption should not be confused with maturity. Developers highlight opportunities to further strengthen the security, privacy and accuracy of AI agents. These concerns underscore an important point: as the capabilities of agentic AI advance rapidly, progress in robust, trustworthy AI systems must keep pace.
A foundation for further analysis
Overall, the report provides a descriptive overview of the agentic AI landscape, clarifying key concepts and characteristics and establishing a shared analytical foundation. By anchoring the discussion in the OECD AI system definition, it aims to promote coherence across technical and policy communities.
Looking ahead, an improved understanding of real-world use will be essential to identify where safeguards, standards, and governance mechanisms will be most effective. Policy-relevant typologies that build upon this work could help guide governance efforts to distinguish systems by level of autonomy, degree of adaptiveness, domain of operation and scale of impact. Evidence-based policymaking will require more empirical data on how AI agents and agentic AI are being adopted and used across sectors, as well as clearer evidence of their broader implications and impacts.
This report contributes to a clearer, shared understanding of agentic AI and provides a basis for thoughtful, forward-looking policy grounded in conceptual clarity. As agentic AI systems become more capable of coordinating multiple AI agents, taking action and operating over longer periods, governance conversations have to keep pace.
Companies hoping to take advantage of AI’s opportunities need to be trustworthy. Whether investing in, developing, or using AI, the OECD’s new Due Diligence Guidance for Responsible AI provides businesses with an internationally agreed, government-backed tool to demonstrate that markets and societies can trust their AI systems.
Recent international reporting underscores a growing consensus: AI is not just a technological shift. It is a major geopolitical, economic, and societal phenomenon that demands coordinated action amongst all actors, including companies.
AI has the potential to transform society through productivity, economic value and solutions to complex challenges, but for these benefits to materialise, AI needs trust. So far, the technology seems to advance faster than its guardrails. The gap between AI systems and appropriate safeguards is now one of the defining challenges for policymakers and global businesses alike. Both are under pressure to balance AI innovation and diffusion with safety and risk management. Success depends on getting the balance right.
Risks throughout the AI value chain are continually evolving
Risks to people and the environment can manifest at any point along the AI value chain. The OECD actively tracks and categorises risks through its AI Incidents and Hazards Monitor.
Here are a few examples. At one end of the AI value chain, there are the people who label, clean, and moderate the vast datasets required to train AI models. They can face low wages, long hours, and suffer psychological distress from exposure to harmful content. Companies need to ensure decent work for data enrichment workers.
The environmental costs of running AI systems can also be significant, particularly for energy and water consumption by data centres that power AI development and deployment, which may lead to higher energy prices.
Data privacy is another critical concern. AI models are trained on massive datasets that may include personal or sensitive information. If these datasets are not properly anonymised and secured, it can lead to data breaches. If AI models “memorise” and reproduce sensitive data in their outputs, they can expose confidential details, creating legal and ethical dilemmas.
At the other end of the AI value chain, the potential for AI misuse poses risks such as reputational harm and the spread of misinformation. AI-generated deepfakes, for instance, can be used to create realistic but fabricated content, damaging reputations or manipulating public opinion. Similarly, AI can be used to generate and disseminate mis and dis-information at speed and scale, eroding trust in institutions and potentially influencing events.
Worldwide, governments, consumers, and markets are calling for responsible and trustworthy AI. This is one of the reasons for the surge in mandatory and voluntary AI risk management frameworks, responsible AI initiatives, global agreements, academic research and statements from industry leaders and investors. However, this surge in frameworks is also increasing complexity for companies, as risk management is defined differently across jurisdictions and understanding of AI-related risks is evolving.
OECD Due Diligence Guidance for Responsible AI: A flexible, whole-of-value-chain approach to support businesses in navigating evolving risks and rules
This is why the OECD has now developed the first internationally agreed, government-backed Due Diligence Guidance for Responsible AI. Backed by all the OECD’s member countries, plus 17 partner governments and the EU, this Guidance helps enterprises navigate the complex terrain of AI risk management. It is designed to help businesses ensure that the AI systems they develop are trustworthy, used and developed safely and responsibly, and aligned with broad societal values.
A step-by-step framework for enterprises to set up internal management systems capable of proactively identifying and responding to risks related to human rights, labour standards, and environmental impacts.
Recommendations and implementation examples for everyone in the AI value chain, from data suppliers and infrastructure providers to financiers and end-users – including enterprises. The guidance emphasises a “whole-of-value-chain” approach to support secure and resilient AI value chains more resistant to supply chain shocks and interference.
A roadmap of related provisions in existing frameworks, indicating how each step complements and relates to relevant provisions from AI risk management frameworks. This feature helps enterprises understand how implementing this guidance can help them meet expectations from multiple sources and navigate the current landscape of AI risk management frameworks.
Responsibility and trust can give a competitive edge
Responsibility and innovation not only coexist but also reinforce each other. Companies that show a commitment to responsible AI and actively address potential risks can gain trust from investors, customers, regulators, and policymakers. This trust leads to a competitive edge. Instead of hindering innovation, responsible AI practices can speed up growth by reducing obstacles and preventing costly damage to reputation, legal issues, and society.
Responsible and trustworthy AI is becoming increasingly crucial for accessing global markets as international regulatory and voluntary risk management frameworks evolve. Companies in the AI value chain that meaningfully implement the Guidance’s recommendations can position themselves advantageously for cross-border expansion, potentially avoiding the substantial costs of retrofitting systems to meet various regional requirements.
As AI continues to develop rapidly, frameworks and best practices for responsible AI are likely to evolve as well. To help stakeholders keep pace, the OECD will launch an online navigation tool later this year with updates on new frameworks and use cases.
Artificial intelligence is changing fast, and the world is feeling both excited and uneasy about it. People use AI tools every day in hospitals, classrooms, companies and public services, yet the rules that guide these tools are still developing. Many governments are trying to find a balance between innovation and safety. Others are trying to make sure that AI actually improves people’s lives without widening gaps.
These summits did not occur in isolation but are part of broader global efforts to coordinate responsible approaches to AI. The G7 Hiroshima Process in 2023–24 established a shared commitment to trustworthy, human-centric AI, leading to the adoption of the Hiroshima Declaration, which calls for international cooperation on safety, transparency, and risk mitigation.
Building on that, the Paris AI Summit in 2025 moved the conversation toward implementation, with an early agreement on safety evaluations, incident-reporting mechanisms and commitments to support countries with limited technical capacity. The India AI Action Summit represents the next step in this progression: translating these collective principles into measurable on-the-ground outcomes.
In recent months, people have repeatedly asked me two questions. Why should India host such a major global meeting? And is this summit actually useful for India and the world?
The simple answer here is that the next phase of AI will not be decided by a small number of companies or countries. It will depend on whether billions of people, especially in the Global South, can use AI safely, affordably and accountably. India, with its linguistic diversity, strong digital public infrastructure and experience deploying technology at a population scale, is well positioned to help shape this practical phase.
However, AI comes with challenges related to privacy, digital exclusion and the balance between innovation and oversight. But these very tensions make India’s experience pertinent to other countries facing the same trade-offs.
This blog post explains why that matters, what the international community can expect in Delhi, and how we should measure progress at the end of the summit.
Why India, and why now
AI deployment in the Global South will shape global outcomes
Much of the world’s discussion on AI has focused on frontier models, international competition and long-term safety. These debates are important, but AI’s greatest impact will be felt in how it reaches ordinary people. From farmers and students to small businesses, frontline health workers and local governments.
More than half of the world’s population lives in countries categorised as the Global South — a term first popularised in the late 1960s to describe post-colonial economies, and one I don’t fully agree with, as it often flattens diverse countries into a single broad category.
If AI is to be truly global, it must work for multilingual, resource-constrained and diverse environments. This includes reliable translations, culturally grounded datasets, accessible interfaces and low-cost deployments. It also means designing systems that respect human rights and democratic norms even in places with limited regulatory capacity.
India sits at the intersection of these challenges. With over a billion people, 22 official languages and thousands of dialects, any technology deployed at scale must be inclusive by design. India’s experience offers lessons for many other countries navigating the same realities.
India has a strong track record in large-scale digital public infrastructure
India’s digital public infrastructure, or DPI, is one of the most widely referenced success stories of how technology can enable access and accountability. Systems like Aadhaar, UPI and DigiLocker have helped millions access identification, financial services and digital records. These platforms were built with interoperability and openness in mind, which has led to a wave of public and private innovations.
At the same time, these systems have also raised important questions about privacy, data security, and exclusion of marginalised communities who lack documentation or digital access. India’s ongoing work to address these concerns—through data protection legislation, improved grievance mechanisms, and efforts to reach the digitally excluded—provides practical lessons about implementation challenges that other countries will inevitably face.
The India AI Impact Summit is expected to draw on this experience, including both successes and areas for improvement. The global community is watching to see how India will frame the link between AI and digital public goods, and how these tools can be used responsibly in sectors such as education, healthcare and social protection.
International expectations are focusing on implementation leadership
The earlier global AI safety and governance summits created momentum. They helped identify risks, promote transparency and encourage cooperation. But now, many countries and organisations want clarity on what should happen next.
The India summit is an opportunity to shift the conversation from what AI might do to what it should deliver. This includes measurable improvements in public services, clearer accountability mechanisms and more inclusive access to AI tools. By focusing on implementation, India can complement the work of the OECD-GPAI, UNESCO and other international bodies.
What the India AI Impact Summit should prioritise
A conversation about measurable, real-world outcomes
The summit should begin by asking a straightforward question: What changes on the ground when AI is deployed responsibly at scale? To answer it, discussions need to move beyond broad aspirations and focus on concrete domains like public healthcare triage, classroom support tools, agricultural advisory systems, and other public-sector applications where impact can be seen and measured.
Government delegates should be encouraged to present evidence, not statements of intent. That means clear baselines, transparent evaluation methods, and metrics that reflect real improvements: higher diagnostic accuracy, increased crop yields and shorter benefit-processing times all achieved without compromising fairness or human oversight.
If the summit succeeds, it will shift the global conversation toward what works, for whom, and under what conditions.
Three ways the Global South can shape the international agenda
A meaningful summit requires a wide range of voices—especially from regions where AI deployment will shape social and economic outcomes for decades to come. Countries across Asia, Africa, Latin America and the Middle East bring their lived experiences of linguistic diversity, data scarcity, affordability constraints and uneven digital access.
The summit should create space for these countries to set priorities rather than simply respond to frameworks developed elsewhere. Their perspectives are vital for building governance models that reflect the realities of low-resource contexts, rather than idealised assumptions from high-income environments.
A more pluralistic conversation would reinforce a simple principle: responsible AI cannot be universal if it is not also contextual.
Rebalancing the narrative with the immediate societal, environmental and institutional challenges
One of the most important roles the summit can play is to broaden the global AI discourse. Today, existential risk narratives dominate many international forums, often overshadowing more immediate and systemic issues. The India AI Impact Summit should refocus attention on the present: AI’s energy footprint, labour displacement, rising misinformation, digital exclusion and the growing pressure on public institutions to oversee algorithmic systems they are not adequately equipped to oversee.
The environmental dimension deserves particular attention. Training and deploying large AI models require significant energy resources, disproportionately affecting the Global South. Many of these countries face climate vulnerability, fragile grids and competing development priorities. For regions already grappling with heatwaves, droughts and energy shortages, the cost of “AI at scale” cannot be separated from broader planetary concerns. If AI is to be deployed responsibly, discussions must also consider energy and natural resource efficiency and equitable access to compute.
These issues determine how people experience AI today and whether they trust it tomorrow. Giving them equal weight would help correct the imbalance in global discussions and lead to governance that addresses risks people actually face, not only those imagined at the far horizon.
Potential wins for the India AI Impact Summit
Practical pathways for responsible public-sector deployment
Across sectors, governments are eager to use AI to strengthen healthcare, expand access to education and streamline welfare delivery. Yet many lack clarity on how to procure, evaluate or oversee these systems responsibly. A meaningful outcome of the summit would be simple, actionable pathways that public agencies can adopt without specialised expertise. These might take the form of evaluation checklists with acceptable error and bias thresholds, procurement templates with human oversight requirements, or clear guidance on when and how officials should override an AI recommendation. Transparent case studies and training for civil servants would also help countries move from hesitation to informed, confident experimentation.
Strengthened mechanisms for trust and accountability
Concerns about misinformation, bias, privacy and security continue to rise, and many countries, particularly those with limited technical capacity, need practical tools to manage these risks. The summit could make a real contribution by advancing shared approaches to incident reporting, auditing and assurance, as well as safety testing methods that work across varied deployment contexts. Small pilot frameworks would help establish a common baseline of accountability. Such efforts would not only support global cooperation but also build public trust at a time when many citizens and policymakers remain uncertain about the reliability of AI systems.
Broader cooperation on multilingual and inclusive AI with robust safety infrastructure
Many countries struggle with adapting AI to their unique linguistic profiles. India’s long-standing work in language technologies positions it to convene collaborations on multilingual and inclusive AI. New partnerships on datasets, dialect-specific models, local-first interfaces and research on linguistic bias could meaningfully expand access for millions of people worldwide.
But inclusion must be matched with safeguards. As AI tools become more widely available, countries will need parallel investments in risk-assessment expertise, regional coordination on harmful content and support for the development of first-generation regulatory frameworks. Striking the right balance between openness and safety would reinforce core OECD AI Principles and help ensure expanded access does not bring greater vulnerability.
Broader implications for global AI policy
Everyday impact before frontier risks
Research on frontier AI risks must continue, but the India AI Impact Summit signals an important rebalancing of global attention, as mentioned before. It asks policymakers to look beyond hypothetical future scenarios to acknowledge how AI is already shaping critical aspects of our daily lives, from healthcare triage and classroom instruction to welfare delivery, agricultural advice and urban mobility.
For most people, the urgent question is not whether AI poses an existential threat, but whether the systems they encounter today are reliable, safe and genuinely useful. The summit’s focus on practical impact aligns global governance with lived reality.
Ensuring AI benefits for everyone
A second implication is the reaffirmation that inclusion is not a downstream concern but a prerequisite for responsible AI. Global conversations often gravitate toward powerful models built in highly resourced environments, yet billions of people rely on limited connectivity, low digital literacy and minority-language interfaces.
India’s leadership places these conditions at the centre of the global agenda. It broadens the imagination of what “good AI” must account for, reminding the world that both equitable deployment and cutting-edge capability are essential to whether AI helps or harms societies.
Building a more open and collaborative ecosystem
The summit also nudges the world toward a more open and cooperative model of AI development. Some countries can share tools, datasets, and governance mechanisms to help each other build their own capabilities rather than remain passive consumers. Openness here is not about lowering standards; it is about raising the global floor and ensuring that safety capacity grows alongside access. Many countries want to participate meaningfully in the AI economy, and the summit offers a platform to explore practical pathways for doing so.
What the world should take away from Delhi
The India AI Impact Summit 2026 is more than just another international meeting because it represents a shift from abstract debates to concrete action. Its core question — how to make AI useful, safe and inclusive at scale — goes to the heart of global governance. If the summit delivers practical tools, clearer deployment pathways and stronger cross-regional collaboration, it will set a new benchmark for what international coordination on AI can achieve.
The world is watching India, not because it claims to have all the answers, but because it has repeatedly demonstrated the ability to turn large-scale ideas into real-world outcomes. And it has done so while openly confronting the tensions and trade-offs that accompany such efforts. In a period of rapid technological change, this experience is invaluable.
As AI evolves, the global community will increasingly need countries that can translate principles into practice at a population scale. The India AI Impact Summit is a chance to advance that work. If successful, its influence will extend far beyond India, shaping how the world understands and pursues responsible AI in the years ahead.