23 August 2026Governance & Risk

The Need for an AI Stability Board

Global AI governance is fragmenting exactly as frontier capability crosses new risk thresholds. What the Financial Stability Board, the IAEA, and the Montreal Protocol got right that the current run of voluntary AI declarations does not.

Executive Summary

Every institution built to manage a genuinely global risk, nuclear proliferation, systemic financial contagion, ozone depletion, took shape after a body with standing to act was formed, not before. AI governance has run the sequence backwards: three summits in three years, an advisory body with no enforcement power, and a retreat from the word “safety” itself, while frontier models cross capability thresholds the summits were convened to watch for. A stability board for AI would not regulate deployment. It would do what the Financial Stability Board does for finance and the IAEA does for nuclear material: hold the common risk picture, run the independent evaluation, and raise the alarm before a national regulator can.

28 + EU

countries signed the Bletchley Declaration in November 2023, the first attempt at a shared position on frontier AI risk

62 → 2

nations signed the Paris AI declaration in February 2025; the US and UK, hosts of the two prior summits, refused

15 months

between the UK opening the world’s first AI Safety Institute and renaming it the AI Security Institute

0

binding international bodies with standing to independently evaluate a frontier model before it ships

Core conclusions

  • Three summits produced three declarations, and each one carried less binding commitment than the last. That is not stalled progress. It is a visible retreat, driven by the same competitive pressure the summits were meant to manage.
  • The UN’s High-Level Advisory Body did the analytical work correctly in 2024 and was given no operational teeth. Its seven recommendations became a mandate for an AI Office and a scientific panel, not a body that can flag a dangerous capability before deployment.
  • The working precedent already exists, three times over. The Financial Stability Board, the IAEA, and the Montreal Protocol each show a different piece of what a functioning AI stability body would need: systemic monitoring without direct regulatory power, treaty-backed inspection, and a binding schedule tied to independent scientific findings.

1. The pattern so far

Start with the sequence, because the sequence is the argument.

In November 2023, the United Kingdom hosted the first AI Safety Summit at Bletchley Park. Twenty-eight countries and the European Union signed the Bletchley Declaration, agreeing in general terms that frontier AI carried risks serious enough to warrant “urgent” international attention. It named no enforcement mechanism and created no standing body. It was, deliberately, a statement of shared concern rather than an agreement to act.

Six months later, at the Seoul AI Safety Summit in May 2024, the commitments got more specific and stayed voluntary. Sixteen companies, including OpenAI, Anthropic, Google DeepMind, and Meta, signed the Frontier AI Safety Commitments, pledging to define capability thresholds beyond which they would treat a model as too dangerous to release without additional safeguards. Ten countries and the EU agreed to stand up a network of national AI Safety Institutes to share evaluation methods. Twenty-seven nations and the EU agreed to work toward common thresholds for “severe risk.” None of this created an external check. Each company set its own thresholds, evaluated its own models against them, and decided for itself whether a threshold had been crossed.

By February 2025, at the Paris AI Action Summit, the coalition split. Sixty-two nations, along with the African Union Commission and the EU, signed a joint declaration on “inclusive and sustainable” AI. The United States and the United Kingdom, the two governments that had hosted the prior summits and set the safety agenda, refused to sign. The US vice president used the summit stage to warn that AI regulation would hand the future to “authoritarian regimes.” Ten days later, the UK renamed its AI Safety Institute the AI Security Institute, and the international network of AI Safety Institutes formed at Seoul was renamed the International Network for Advanced AI Measurement, Evaluation and Science. The word “safety” did not survive fifteen months of institutional life. The United States made the same move, renaming its own institute the Center for AI Standards and Innovation.

The India AI Impact Summit in February 2026 produced a New Delhi Declaration endorsed by more than eighty countries and a large public pledge campaign on responsible use. It did not reverse the trend. Each summit since Bletchley has produced a document with less binding language than the one before it, hosted by a wider and more loosely committed coalition.

Meanwhile the thing the summits exist to monitor kept moving. The second International AI Safety Report, chaired by Yoshua Bengio and drawing on more than a hundred experts nominated by thirty-plus countries and the EU, OECD, and UN, reported in early 2026 that some frontier models had begun showing early signs of situational awareness, strategic deception, and test-gaming behaviour in evaluation settings, developments the first edition of the same report, a year earlier, had treated as theoretical. The gap the report describes is not a gap in knowledge. It is a gap between what independent researchers can now observe and what any government or body has standing to do about it.

Timeline of international AI summits from 2023 to 2026 showing declining binding commitment. Bletchley Park November 2023: 28 countries plus EU sign a statement of concern. Seoul May 2024: 16 companies sign voluntary Frontier AI Safety Commitments. Paris February 2025: 62 nations sign a joint declaration, the United States and United Kingdom refuse. New Delhi February 2026: more than 80 countries endorse the New Delhi Declaration
Each summit since Bletchley Park has produced a wider coalition and a weaker commitment. That is the opposite of what institution-building normally looks like.

2. Why the existing bodies do not close the gap

It would be easy to conclude that the UN’s 2024 effort already did this work and the problem is adoption, not design. It is worth being precise about why that is not so.

The UN Secretary-General’s High-Level Advisory Body on AI, thirty-nine members from thirty-three countries, convened in October 2023, produced an interim report in December 2023 and a final report, Governing AI for Humanity, in September 2024. The final report made seven recommendations, including the creation of an independent international scientific panel on AI and a small AI Office within the UN Secretariat. The Global Digital Compact, adopted at the same September 2024 Summit of the Future, gave the Secretary-General a political mandate to act on those recommendations.

What it did not do, because it was never structured to, is give any UN body the standing to independently evaluate a specific model before deployment, to compel disclosure of a dangerous capability, or to issue a finding that a national regulator or a company would be obliged to act on. The scientific panel it proposes is modelled explicitly on the IPCC: a body that synthesises evidence and publishes assessments, not one that inspects, licenses, or enforces. That is a real and useful function. It is also, on its own, the same function international climate science has performed since 1988 without a binding global emissions regime resulting from it. The synthesis was never the missing piece for climate; the political will to act on the synthesis was. The parallel risk for AI governance is building the IPCC-equivalent and stopping there.

National AI Safety Institutes, now rebranded around security rather than safety in the US and UK, evaluate models under voluntary access arrangements with the labs that build them. They are genuinely useful technical bodies. They also report to national governments, evaluate against national priorities, and have no mechanism for cross-border escalation if one country’s institute reaches a finding another country’s does not want to hear. A systemic risk, by definition, does not respect the jurisdiction of the institute that happens to catch it first.

Free tool

AI Trust, Risk & Governance Dashboard

The domains a national institute already checks, bias, data lineage, security posture, are exactly the domains a cross-border body would need a shared baseline for before it could compare findings across jurisdictions.

3. What “stability board” should mean

The name is deliberate, and it is worth being specific about what it borrows and what it does not.

The Financial Stability Board, established by the G20 in April 2009 in direct response to the 2008 crisis, does not regulate any bank. It has no power to block a transaction or fine an institution. What it does is monitor the global financial system as a whole, identify systemically important institutions, coordinate the national and regional regulators who do have enforcement power, and set standards those regulators then implement in their own jurisdictions. It exists because the 2008 crisis demonstrated that a risk can be invisible to every national regulator individually while being obvious in aggregate, and that no single national body had either the mandate or the vantage point to see it coming.

That is the function missing from AI governance today. Not a global licensing regime for models, which would be unworkable and would concentrate exactly the kind of power a stability board should exist to check. A body with the standing and the technical access to hold the aggregate risk picture: which labs across which jurisdictions are approaching which capability thresholds, whether a dangerous capability discovered by one national institute has appeared elsewhere, and whether the sum of individually defensible national decisions is producing a systemic exposure no one signed up for.

Two other precedents fill in pieces the FSB model does not cover. The International Atomic Energy Agency, established in 1957 after Eisenhower’s 1953 Atoms for Peace proposal, holds something the FSB does not: a treaty-backed right to inspect. IAEA safeguards under the Non-Proliferation Treaty give it standing to verify, on site, that fissile material is not being diverted to weapons use, regardless of whether the country in question wants that verification performed. An AI stability board’s equivalent would be independent, compelled access to evaluate a frontier model’s dangerous-capability profile before release, not after a lab volunteers it.

The Montreal Protocol, agreed in 1987 after the atmospheric science on ozone depletion became settled, shows the other missing piece: a binding phase-down schedule tied to an independent scientific finding, with trade measures against non-parties. It succeeded, nearly universally ratified, ozone-depleting substances phased out on schedule, because the science and the enforcement were connected by a mechanism, not by good faith. The International AI Safety Report already does the scientific-synthesis half of that job. Nothing currently connects its findings to any obligation on anyone.

Three working precedents for a global AI stability body. Financial Stability Board, established by the G20 in 2009: coordinates national financial regulators and monitors systemic risk across borders, does not regulate a single bank directly. International Atomic Energy Agency, established 1957: holds a treaty-backed right to inspect nuclear material regardless of whether the country being inspected wants it performed. Montreal Protocol, agreed 1987: sets a binding phase-down schedule tied to an independent scientific finding, backed by trade measures against non-parties
None of the three is a template to copy whole. Each one shows a different piece of the function currently missing from AI governance.

4. Four functions, not one

A body built on those precedents would need four functions the current architecture lacks entirely.

Independent, compelled evaluation. Not a lab’s own red team reporting its own thresholds, and not a voluntary pre-deployment demo to a national institute that the lab can decline to repeat next quarter. A standing technical capability, modelled on IAEA inspection rights, to evaluate a frontier model against agreed dangerous-capability benchmarks before it is released at scale, with the right to require access rather than request it.

Cross-border incident and near-miss reporting. Aviation safety improved as fast as it did in the twentieth century largely because ICAO, established under the 1944 Chicago Convention, built binding norms around incident investigation and information sharing across airlines and states that were otherwise commercial competitors. A dangerous capability or a near-miss discovered by one national institute currently has no obligatory channel to reach the others. That is a solvable, mechanical gap, not a philosophical one.

A common threshold registry. The twenty-seven nations that agreed at Seoul to work toward shared thresholds for severe risk have not published one. Each lab that signed the Frontier AI Safety Commitments defines its own thresholds and its own remediation. A registry, maintained by the board rather than by any single lab or government, is the difference between twenty companies each grading their own homework and a comparable, auditable standard.

An escalation and disclosure mechanism with real consequence. This is the piece none of the current architecture attempts. The FSB can name a systemically important institution and require it to hold more capital. The Montreal Protocol backed its schedule with trade restrictions on non-parties. A stability board without an equivalent, a public finding that a specific system exceeded an agreed threshold, a required disclosure, a coordinated response among the jurisdictions that recognise the board, is a scientific panel with better branding, not a stability body.

Mindmap of four functions a global AI stability board would need. Independent compelled evaluation: standing access, not voluntary. Cross-border incident reporting: dangerous capability found in one country, no obligatory channel to reach the others. Common threshold registry: twenty companies each define severe risk themselves, no shared standard. Escalation with real consequence: public finding, required disclosure, coordinated response
The first three are mechanical gaps a registry and a reporting channel can close. The fourth is the one no current body has attempted.

Free tool

Board AI Oversight Checklist

The same escalation question at the level of a single organisation: can your board name who is accountable when an internal finding needs to reach someone with the authority to act on it.

5. The objections, and why they do not hold

“This hands power to whichever government dominates the board.” The FSB precedent answers this directly: it does not regulate, it coordinates regulators who retain their own enforcement power. A stability board modelled on it would issue findings and thresholds. National and regional bodies, the EU AI Office, the US and UK institutes under whatever name they currently hold, would retain the authority to act on those findings within their own jurisdictions. The board’s power is informational and coordinating, not executive.

“Frontier labs will simply relocate to avoid it.” This is a real constraint, and it is also the exact argument made against every prior regime of this kind, including the Montreal Protocol in 1987 and early financial-stability coordination in the 1970s. Trade and market-access mechanisms, not moral suasion, are what made those regimes stick for jurisdictions that wanted to defect. A stability board’s leverage would need to run through the same channel: market access to the jurisdictions that recognise its findings, not through voluntary compliance from labs with an incentive to relocate.

“Safety regulation will cede the field to less careful competitors.” This was JD Vance’s argument at the Paris summit in February 2025, and it deserves to be named rather than waved off, because it is the argument actually driving the retreat documented in Section 1. It assumes that the absence of a shared floor benefits the country that removes its own floor first. The FSB counterexample argues the opposite: the 2008 crisis was not caused by insufficiently innovative finance. It was caused by systemic risk that no single national regulator had the mandate to see, precisely the condition a stability board exists to prevent from recurring in a different domain.

“Governance can’t move at model-release speed.” True, and it is an argument for building the standing capability now rather than after the fact, not an argument against building it. The IAEA’s inspection function did not appear the week a state first sought fissile material. It existed in advance because the alternative, discovering the gap during a crisis, was judged less acceptable than building the institution during a period of comparative calm. The current period, before a systemic AI incident forces the question, is the equivalent window.

6. A workable path, not a utopian one

The realistic route does not start from a UN General Assembly vote or a new global treaty. It starts from the infrastructure that already exists and needs a mandate, not an invention.

The International Network for Advanced AI Measurement, Evaluation and Science, formed at Seoul and still standing under its renamed mission, already connects the national institutes of the UK, US, Japan, France, Germany, Italy, Singapore, South Korea, Australia, Canada, and the EU. That is the closest existing analogue to the Basel Committee of central bank supervisors that preceded the FSB by three decades. The realistic first step is not a new body. It is a coalition of the willing among that existing network, formalising shared thresholds, mutual recognition of each other’s findings, and a joint disclosure mechanism, without waiting for the US or any single holdout to rejoin a unanimous declaration first.

The Frontier AI Safety Commitments already have twenty organisations naming their own thresholds. The realistic second step is converting that into an externally audited registry rather than twenty separate self-reports, using the International AI Safety Report’s existing technical credibility as the basis for the audit rather than building new scientific capacity from nothing.

Neither step requires the US and UK to reverse the position taken in Paris. It requires the countries and institutions still willing to coordinate, a group that on the New Delhi Declaration’s own signature count is more than eighty strong, to build the enforcement mechanism the last three summits declined to build, and to make market access to that coalition the incentive for the rest to join later. That is how the Montreal Protocol actually worked: it opened for signature with a smaller group, held a binding schedule, and used trade measures to bring holdouts in over the following decade, rather than waiting for universal agreement before setting any schedule at all.

7. What is actually at stake

The case in this piece is not that frontier AI is certain to cause a catastrophe an international body would have prevented. It is narrower and, I think, harder to argue against: the sequence of the last three years, broader coalitions signing weaker commitments, safety renamed as security, capability advancing faster than the institutions meant to track it, is the same sequence that preceded the 2008 financial crisis in a different domain. Individually defensible decisions, made by regulators and companies each acting within their own remit, summed to a systemic exposure that no single one of them had the mandate or the vantage point to see.

The Financial Stability Board, the IAEA, and the Montreal Protocol were each built by connecting a piece already in place, a supervisors’ committee, an inspection mandate, a scientific consensus, to an enforcement mechanism that had been the missing piece all along. AI governance already has its version of the supervisors’ committee, the scientific report, and the voluntary thresholds. What it does not have is the connective piece, the disclosure obligation and the escalation path, that turned the other three from documents into institutions. That piece can still be built before the crisis that would otherwise force it.


Sources

  1. UK Government. (2023, November 1). The Bletchley declaration by countries attending the AI Safety Summit, 1–2 November 2023. GOV.UK.
  2. UK Government. (2024, May 21). Frontier AI safety commitments, AI Seoul Summit 2024. GOV.UK.
  3. Australian Government Department of Industry, Science and Resources. (2024, May 22). The Seoul declaration by countries attending the AI Seoul Summit.
  4. UN High-Level Advisory Body on Artificial Intelligence. (2024, September). Governing AI for humanity: Final report. United Nations.
  5. U.S. and Britain snub international AI accord in Paris. (2025, February 11). CNBC.
  6. UK and US refuse to sign international AI declaration. (2025, February 11). BBC News.
  7. International Network of AI Safety Institutes renamed without “safety”. (2025, February). MLex.
  8. UK renames AI Institute following Paris Summit. (2025, February). Americans for Responsible Innovation.
  9. Bengio, Y. (Chair). (2026, February). International AI safety report 2026.
  10. India AI Impact Summit 2026. (2026, February 16–21). About summit.
  11. Press Information Bureau, Government of India. (2026, February). India AI Impact Summit 2026: Landmark global declaration.
  12. Financial Stability Board. (2009, April). Established by the G20, London.
  13. International Atomic Energy Agency. (1957). Established following Eisenhower’s “Atoms for Peace” address to the UN General Assembly (1953).
  14. Montreal Protocol on Substances that Deplete the Ozone Layer. (1987).
  15. Convention on International Civil Aviation (Chicago Convention). (1944).
Apply this in your organisation.

Work with Terence Kok — enterprise AI strategy, governance, and deployment.

Book a Session