We explore three models of governance and how that applies to AI.
This is a guest blog authored by Humane Intelligence and its volunteers, exploring topics related to AI evaluations and sociotechnical topics in AI. Co-authors: Theodora Skeadas, Bianca Gay.
A portion of the featured image was generated using AI.
In 2020, EU courts struck down the agreement governing data transfers between the United States and Europe on the grounds that American law did not adequately protect Europeans from government surveillance. Thousands of companies had to restructure their data operations overnight. In China, foreign firms that want access to Chinese markets must store their data locally and accept that the government can access what they hold. In the United States, no comprehensive federal privacy law exists, making it the only G20 nation without one, and the rules depend on the industry and in which state you live.
These are not three versions of the same approach. They are three fundamentally different answers to the same question: who should data serve? And each is now spreading beyond its own borders, pulling the rest of the world into a contest over the rules of the data economy, rules that will determine who gets to build artificial intelligence, whose experiences those systems reflect, and whose communities bear the risks when systems fail.
Europe’s answer to who should data serve is the individual. Privacy is treated as a matter of human dignity, not regulatory preference, a conviction rooted in its twentieth century experience with regimes that used personal data as a tool of state control. That conviction is enforced through the GDPR, which applies to any company handling EU residents’ data regardless of where it is based, with penalties reaching €20 million or 4% of global revenue. Data transfers are permitted only to countries the EU considers to offer equivalent protections.
The United States’ answer to who should data serve has largely been the private sector. The digital economy was built around industry self-regulation, and the government has been playing catch-up ever since. That arrangement has meant that the interests shaping American data governance have largely been corporate rather than civic, a tension now compounded by national security pressures and a deepening entanglement between Washington and Silicon Valley. The resulting governance model is not defined by principles, but rather who has the most power.
China’s answer to who does data serve is the state. Data stays within its borders, flows on terms the state sets, and remains accessible to the government. Its Personal Information Protection Law offers consumers rights that look similar to GDPR , but government agencies are largely exempt from its scope. In China’s model, data governance and political control are not separate systems that occasionally intersect. They were designed together.
Due to the economic power of these countries, these models of data governance are not contained within their own borders. The EU exports its standards through market access, effectively requiring any company that wants to operate in Europe to comply with its framework. China exports its model through infrastructure deals and bilateral agreements, offering a sovereignty-first vision that has found willing adopters. The US, without a settled position of its own, exports its platforms and its dependencies. For the countries that sit outside all three, the question is not which model to prefer. It is how to survive the competition among them.
Let’s consider the position of a company operating across all three jurisdictions. China’s Data Security Law prohibits sharing data with foreign authorities without government approval. The GDPR simultaneously prohibits transferring data outside the EU. When US federal law then compels the same company to hand over data via the CLOUD Act, compliance with one jurisdiction means violation of another. In many cases, the response has not been to exit these markets, but to build entirely separate in-country infrastructure, running parallel data systems to satisfy irreconcilable requirements. It is an expensive solution that only the largest companies can afford. Many have responded by defaulting to GDPR compliance as the strictest available standard, effectively letting Brussels set the global baseline by default. For everyone else, the conflict simply persists.
Attempts at coordination have not resolved this. The EU-US Data Privacy Framework, adopted in 2023 as the third attempt to resolve this conflict after both Safe Harbor and Privacy Shield were struck down, faces fresh legal threats from the same organization that brought down its predecessors — and mounting uncertainty under the Trump administration. Broader efforts like Japan’s Data Free Flow with Trust initiative and the Global Cross-Border Privacy Rules Forum are voluntary and non-binding. The February 2026 India AI Impact Summit illustrated where there is a lack of coordination, as evidenced by the US focus on exporting American chips, cloud, and AI models while explicitly opposing formal global governance structures.
Countries that have adopted frameworks modeled on China’s approach have found themselves with something more than data localization rules. Vietnam’s cybersecurity law draws directly from the Chinese model, giving the state broad powers to suppress political speech online. Myanmar’s cybersecurity legislation handed the military junta extensive authority to access personal data and restrict expression. The framework traveled. So did its consequences.
Aligning with the US model carries different risks. Researchers have begun using the term data colonialism to describe what happens when developing countries operate primarily through American platforms: data flows outward, value accrues elsewhere, and countries find themselves dependent on infrastructure they did not build and cannot meaningfully govern. The data generated by their citizens powers systems over which they have no influence to design or develop.
For many countries, however, even selecting a data governance model is a luxury. The Global Data Barometer found that while 98 out of 109 surveyed countries have some form of data protection framework, only 46 percent have robust ones. Many lack the institutional capacity, technical infrastructure, and trained personnel to implement even basic governance. UNCTAD has warned that without meaningful representation in global data governance conversations, developing countries risk being permanently locked out of the data economy. The countries with the least leverage absorb the greatest risks while having the least say in the rules that produced them.
The infrastructure of artificial intelligence is already concentrated. Forty percent of generative AI models are produced by US-based companies, many trained predominantly on English with a self-reported US bias. The six largest US tech firms each hold market capitalizations larger than the GDP of any single African country.
Since 2017, the number of data localization laws has more than doubled, fragmenting the cross-border data on which competitive AI models training depends. The data governance contest is not just shaping who can access the data, it is shaping who gets to build the technology, and on whose terms.
The goal should not be harmonization among three governance models that have deeply held convictions about sovereignty, markets, and political control. The goal should be to build enough interoperability among regimes so that smaller economies aren’t crushed and excluded. That means mutual recognition across certification and audit regimes, so that compliance in one system doesn’t require rebuilding from scratch in another. It means taking seriously what low-and middle-income countries are already building: Digital Public Infrastructure as a sovereignty-preserving alternative to platform dependency. And it means insisting the UN Global Dialogue on AI Governance is accessible enough to actually represent the countries it claims to speak for — starting with who can get into the room.