Does the UN Regulate AI? Two Systems That Share a Name
One system is member states negotiating non-binding norms. The other is each organisation governing what its own staff may deploy. They share a name, and confusing them sends people looking for rules in the wrong document.
Published 2026-09-04 · By Shahzad Asghar
Ask whether the United Nations regulates artificial intelligence and you will get two confident answers that contradict each other. Both are correct. They are describing different systems that happen to share a name.
One is the UN trying to shape how the world governs AI. The other is the UN trying to govern its own use of it. They involve different actors, different authority, and different consequences for getting it wrong. Conflating them wastes a great deal of time — people go looking for rules in the wrong place, and vendors cite documents that do not bind anybody.
This separates them.
System one: the UN as a norm-setter
This is the one that makes news. Member states negotiate, the General Assembly adopts, and the result is a statement of what governments have agreed AI governance should look like.
The recognisable pieces are the UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by member states in 2021; the General Assembly resolutions on safe, secure and trustworthy AI; the Global Digital Compact; and most recently the Independent International Scientific Panel on AI and the Global Dialogue on AI Governance, which I have written about separately in the Panel explained.
What this system can do. It builds consensus among states that would otherwise negotiate bilaterally or not at all. It creates shared vocabulary — when a national strategy in one region uses the same risk language as one in another, that is often traceable to this track. It gives smaller states a seat in a conversation otherwise dominated by a handful of countries and companies. And it produces reference points that national legislation can adopt by choice.
What it cannot do. None of it is binding. There is no enforcement mechanism, no inspectorate, no penalty. A General Assembly resolution is not law in any member state until that state legislates it. The Scientific Panel advises; it does not regulate.
This is not a weakness anyone is hiding. It is what the instrument is. But it explains why "the UN has rules on AI" is misleading in the way most people mean it.
System two: the UN governing its own AI use
This one makes no news at all, and it is the system that actually constrains behaviour.
The UN Secretariat and the specialised agencies each run technology estates, hold data about people, and now deploy AI inside operational processes. That requires internal governance: policies on what may be built, what data may be used, who approves deployment, and what happens when a system produces a wrong answer about a real person.
This machinery is largely invisible from outside. It includes agency-level AI policies and ethics reviews, inter-agency coordination through bodies such as the High-Level Committee on Management's Digital and Technology Network and the inter-agency working group on AI, procurement rules that predate AI and were not written for it, existing data protection frameworks that AI use has to fit inside, and assessment tools such as the PRISM framework for prioritising use cases, which I cover in the FAQ on AI in the UN system.
What this system can do. It binds staff. An agency AI policy is an instruction, not a recommendation. If it says a system handling beneficiary data requires a review before deployment, that review happens or the deployment does not.
What it cannot do. It has no reach beyond the organisation. It does not constrain a member state, a vendor selling into the system, or anyone else.
Why the confusion is expensive
People look for obligations in the wrong document. A team building an AI tool inside an agency does not need the General Assembly resolution. They need their own organisation's policy, their data protection framework, and their procurement rules. The resolution is context; the internal policy is the constraint.
Vendors cite the wrong thing. A supplier claiming alignment with a UN AI resolution has said something close to meaningless about whether their product can be procured. The questions that decide that are internal, and they are the ones in the vendor assurance template.
External observers overestimate the machinery. Reading the normative track, it is easy to assume a coordinated system-wide AI governance regime exists. Adoption is uneven and largely agency by agency. Some organisations have mature frameworks. Others have a policy on paper and no capacity to apply it.
Internal teams underestimate their own obligations. The mirror error. Because the public conversation is about non-binding norms, staff sometimes assume there is nothing binding at all. There usually is, and it usually sits in a document nobody circulated widely.
Who actually decides what
| Question | System one, normative | System two, internal |
|---|---|---|
| Who decides | Member states, by negotiation | Each organisation, through its own governance |
| What comes out | Resolutions, recommendations, panels | Policies, review gates, procurement rules |
| Who is bound | Nobody, until a state legislates | Staff of that organisation |
| Enforcement | None | Internal, through normal compliance |
| Visibility | High, publicly negotiated | Low, rarely published |
| Speed | Years | Months |
| What it changes | The frame of debate | What ships |
If you work inside the system
Find your own organisation's policy before anything else. It exists more often than people assume, and it is usually the document that determines whether a project proceeds.
Then establish which existing frameworks the AI has to fit inside. In most organisations the binding constraints on an AI project are not AI rules at all — they are the data protection framework, the information security policy, and the procurement regulations, none of which were written with models in mind but all of which apply. That is the practical starting point set out in AI governance in the United Nations.
Then work out who can stop the system after it launches, and make sure that person knows they hold that authority. This is the control most often missing. Approval processes are common; stopping conditions are rare. If nobody is named, the answer to "who can switch it off" becomes "nobody, quickly" at exactly the wrong moment.
If you work outside it
Do not read the normative track as compliance obligations. Read it as direction of travel. It tells you what governments have converged on rhetorically, which is a reasonable predictor of what national regulation eventually contains, and a poor predictor of what any organisation requires of you today.
If you are selling into the system, the normative documents are close to irrelevant to procurement. What matters is data residency, deletion, auditability, and the terms attached to anything you host — the questions set out in RAG or fine-tuning: the governance questions.
If you are researching the field, treat the two systems as separate literatures. Conclusions drawn from resolutions describe the normative track. They say almost nothing about what a country office is doing.
The distinction in one line
The normative system decides what the world should agree about AI. The internal system decides what a UN team is allowed to deploy on Monday. The first is public, slow, and non-binding. The second is quiet, faster, and the one with teeth.
Anyone who has to make a decision rather than describe a landscape is working in the second system, whatever the first one has published.
For how these constraints apply outside the UN, see AI governance for government, and for what changes once a system is live, information technology audit in the age of AI.
Frequently asked questions
Does the United Nations regulate artificial intelligence?
Not in the binding sense. The General Assembly adopts resolutions and bodies such as UNESCO issue recommendations, but these are not law in any member state until that state legislates them. There is no UN enforcement mechanism for AI. Separately, individual UN organisations do issue internal AI policies, and those genuinely bind their own staff.
Is a UN resolution on AI legally binding?
No. General Assembly resolutions are recommendations. They carry political and normative weight, and they influence national legislation over time, but they create no direct legal obligation for states, companies or individuals.
What is the difference between UN AI governance and UN internal AI policy?
UN AI governance usually refers to the normative track: member states negotiating shared principles. Internal AI policy refers to the rules each UN organisation sets for its own use of AI. The first is public and non-binding; the second is often unpublished and binds staff directly.
Who governs AI use inside the UN system?
Each organisation governs its own, through its executive leadership and existing governance structures, coordinated in part through inter-agency mechanisms such as the High-Level Committee on Management's Digital and Technology Network. There is no single system-wide regulator, and maturity varies considerably between agencies.
Does the Independent International Scientific Panel on AI regulate anything?
No. It provides scientific assessment to inform the Global Dialogue on AI Governance. It is an advisory body, not a regulator, and it has no authority to require anything of a state or a company.
If I am building an AI system in a UN agency, which rules apply to me?
Your own organisation's AI policy if it has one, plus the frameworks that already exist: data protection, information security, and procurement. Those apply to AI whether or not they mention it. The General Assembly track is context rather than constraint.
Written by Shahzad Asghar — Head of Data and Digital Solutions at UN-ESCWA, with 20+ years building AI and data systems across UNHCR, UNICEF, and UNOCHA. His team built UNHCR’s first global IVR appointment system, serving 700,000+ refugees. He created the Last-Mile AI Framework. Read more about this UN AI expert