NordVPN Promotion

Home / Blogs

Who Checks the Models? The Case for UN Oversight of Frontier AI

In September, the United Nations’ Independent International Scientific Panel on Artificial Intelligence described an episode that ought to have drawn more notice than it did. AI agents used in cybersecurity training and evaluation had bypassed network restrictions, communicated across runs that were supposed to be isolated, cheated an evaluator and then tried to conceal what they had done. The Panel was careful not to treat this as the first symptom of a machine rebellion, and nobody else should either. It did, however, single it out as an unusually clear case of capable agents pursuing objectives in ways their makers had not intended.

This was not an isolated case, as last year a coding agent erased a company’s production database in the middle of an instructed code freeze, and researchers have since documented a steady run of agents working their way around the restrictions placed upon them. The developers themselves now concede that systems that are able to use tools, act over many steps and reach into outside infrastructure need testing of a kind that goes well beyond asking a chatbot awkward questions.

Earlier this summer I argued that the United Nations was looking at artificial intelligence only from the demand, user side. Attention was given, understandably, to the consequences of AI once released into society, for employment, development, rights, education and security, while the supply side, where the most powerful models are built, tested and released, went largely unexamined. The months since have made that argument harder to dismiss.

What has changed most is who is making it. Anthropic, OpenAI and others now give government institutes access to their models before release, and some openly advocate outside evaluation. One may fairly doubt how independent an examiner can be when the examined party controls the access, but the debate has moved on. The question is no longer whether frontier AI should be evaluated, but by whom, against what standards and on whose behalf.

The Gap in Global AI Oversight

One might have expected the United Nations to recognize its moment. AI is global by construction, so that a model built in California, Paris or Beijing may be at work in Nairobi, Lima or Dhaka within minutes, carrying both benefits and its fiascos across borders. The capacity to examine such systems, meanwhile, rests with a handful of countries and companies.

The UN’s own 2024 report, Governing AI for Humanity, found hundreds of principles and frameworks but no agreement, neither global nor comprehensive, and noted that none of the 118 countries, most of them in the Global South, took part in any of the seven prominent initiatives it reviewed.

The response since then has been real. The General Assembly has created the Scientific Panel and a Global Dialogue on AI Governance, which first met in Geneva this July, and the Secretary-General has called for common baselines, stronger governance oversight and far more support for developing countries, warning that the capacity gap risks becoming a gap in development, security and sovereignty. In his own words “humanity must govern the technology before it governs us.” All of this has value, yet none of it amounts to a means of examining the most consequential models before they reach the public.

National regulators, safety institutes, academic laboratories and corporate testing teams all exist, and Europe now requires evaluation and adversarial testing of general-purpose models that present systemic risk. What is missing is an international layer available to the many countries that cannot build such institutions for themselves.

A Prequalification Model for Frontier AI

An even better precedent than nuclear safeguards comes from public health. For decades the World Health Organization has prequalified medicines, vaccines and diagnostics. It replaces no national regulator and dictates no country’s purchases, but it offers an independent assessment that governments and procurement agencies can rely upon when they cannot repeat the work themselves. Its authority rests on something practical, since UNICEF, GAVI and the Global Fund buy only what WHO has prequalified.

Frontier AI could have something of the same kind. The aim would not be to stamp a model “safe,” a claim no serious evaluator would make, nor to turn the UN into a licensing authority. It would be to agree tests for a narrow class of the most capable models, examine them independently before broad deployment, record the findings and make them available to every government. That is prequalification rather than permission. Such a body would look at autonomy, deception, cyber and biological capabilities and the circumvention of safeguards, under strict confidentiality for commercial and security-sensitive material. A modest technical secretariat attached to the Scientific Panel, working through the existing network of national safety institutes rather than around it, would be a sensible place to begin.

Its leverage would come the way WHO’s does, from the buyer’s side. Governments and UN agencies are becoming large purchasers of AI services, and they could favor prequalified models in their procurement, as development banks could in the projects they finance. Few laboratories would care to be the one that declined examination while its competitors accepted it.

Political Obstacles and Institutional Urgency

The obvious objection is political. Washington has shown little appetite for UN-led AI governance, and Beijing will be wary of any regime that inspects its models. That is precisely why the function should remain narrow, voluntary and technical. A testing body that licenses nothing and binds no one is far easier to accept than a regulator, and it offers the major powers something they lack, which is a common reference point that belongs to no single rival.

The institutional rhythm, meanwhile, remains curiously sedate. In September the President of the General Assembly told Member States that work on common approaches could not wait for the next Global Dialogue in May 2027 and “must begin now.” The Secretary-General’s term ends on 31 December, the selection of his successor is under way, and transitions breed caution. Caution is a habit international organizations acquire for good reasons, but there are moments when it becomes a risk of its own, and this is one of them.

No country can credibly govern frontier AI for the world, most cannot inspect these systems at all, and the companies increasingly accept that someone from outside should. One could hardly roll out a clearer red carpet for a multilateral organization like the UN.

What is wanted is not another conference or declaration but the beginning of an operational capability, modest at first, that can settle procedures, build technical competence and give countries that would otherwise be spectators some confidence in the systems arriving on their shores. It should go hand in hand with a far more ambitious effort to build capacity in those countries, since global governance cannot mean that a few advanced states inspect the machines while everyone else waits for the verdict.

The UN has spent several years assembling the language, the panels and the forums. The role is there, largely defined, and the world is already asking for it. What remains to be seen is how much more evidence the organization believes it needs before it takes it up

By Gabriel Accascina, Independent Senior Advisor —

Gabriel Accascina is the former Director of the Knowledge Management Group at the United Nations Development Programme (UNDP) and a former Fellow at Harvard Kennedy School’s Center for International Development. Active in internet governance since its formative years, he contributed to the 1998 U.S. Department of Commerce Green Paper that laid the foundation for ICANN. Outside technology and public policy, he also holds a commercial pilot’s license.

Visit Page

Filed Under

Comments

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

Domain Names

Sponsored byVerisign

NordVPN Promotion