
Governance Level
The governance level refers to the tier at which rules for the use of technology are established and monitored – from the individual company up to international agreements. Anyone who wants to know who is responsible for an AI rule must first clarify at which level it originates.
Rules for new technology do not arise in a single place. Some are decided within a company, others in a parliament, and still others between several states. Each of these tiers is called a governance level. The word governance comes from the practice of steering and overseeing a matter. A level therefore always encompasses two things: who sets the rules and how far they reach. Anyone reading about artificial intelligence and its regulation will almost always come across this distinction.
Why responsibility determines impact
A rule is only as strong as the body that can enforce it. A company can commit itself to testing AI systems before launch. If it breaks this pledge, at most it risks reputational damage. A law, on the other hand, can impose fines or pull a product from the market. That is why the question of level is not a mere formality but determines the actual impact.
The levels also interlock and sometimes contradict one another. A corporation operates worldwide, but a national law ends at the border. A language model from the USA is used in Europe, trained in India, and sold in Japan. Which rules then apply? It is precisely at this gap that the debate over international agreements begins.
A common misconception is that a higher level is automatically the better one. Worldwide rules are hard to negotiate and are often formulated very generally. Internal company rules, by contrast, take effect immediately and can be adapted quickly. In practice, both levels need each other.
From the company handbook to the global agreement
At the very bottom is the corporate level. Here, companies determine which systems they build, which data they use, and who grants approval. Often there is a committee that reviews risky projects. This level works quickly because no outside approval is required.
Above that are industry and standardization bodies. They write technical standards that many companies voluntarily follow. One example is testing standards that describe how an AI system is checked for errors. Such standards are not law, but they are often adopted by laws as a benchmark.
The next tier is the state level, with laws and regulatory authorities. Above that lies the supranational level, such as the European Union with its AI Act. At the very top are international agreements between many states. One can imagine this like a school: classroom rules, school regulations, state education law. The higher the level, the more people are affected, and the longer a change takes.
Where the term appears in the news
The term appears most often in reports about the European Union’s AI Act. There, discussions focus on what Brussels mandates and what individual member states are allowed to regulate themselves. This is precisely a question of governance level. The same applies to reports on AI summits, where states agree on common principles.
The term also plays a role in corporate news. When a technology company sets up an internal safety board, that is governance at the lowest level. Critics sometimes call this self-regulation and doubt whether it is sufficient. Anyone evaluating the stocks of such companies pays attention to whether the rules apply only internally or are legally binding.
The term should be distinguished from compliance. Compliance means adhering to existing rules in the day-to-day operations of a business. The governance level, by contrast, describes where these rules actually come from in the first place. Anyone who confuses the two only half understands discussions about AI regulation.