Two governance blocs, one supplier list
The World Artificial Intelligence Cooperation Organization, founded in Shanghai in July 2026, joins a field already holding the EU regime, the US approach and a set of national rules. For an enterprise the consequence is not geopolitical — deployment location has become a governance attribute.
In July 2026, twenty-nine countries signed an agreement in Shanghai establishing a new intergovernmental body for AI cooperation, headquartered there and oriented towards states outside the existing standard-setting arrangements. It is known as WAICO. The announcement from the Chinese government sets out the founding membership and the stated aims. Early academic work on it — including a mapping of where it sits in the wider governance landscape — treats it as a new node in an already crowded regime complex rather than as a replacement for anything.
For most enterprises this reads as a story about international relations. It is not, or not only. It is a story about which rules apply to a system depending on where it runs, whose components it uses and whom it serves — and that is an operational question with an operational answer.
The claim: fragmentation of AI governance converts deployment geography from a performance decision into a governance attribute, and most AI inventories do not record it.
What fragmentation costs an ordinary organisation
| The question as asked | What now has to be answered per deployment |
|---|---|
| Is this system allowed? | Allowed where — and under which regime does each deployment sit? |
| What does the model documentation say? | Which documentation regime produced it, and what does it not cover? |
| Is this supplier acceptable? | Acceptable to whom — and which of our customers have their own view? |
| What are the transparency obligations? | Which of several transparency regimes applies to this interface, in this market? |
| What happens if the rules change? | Which rules — and can we move this workload if one of them does? |
None of the right-hand column requires a view about which regime is preferable. It requires an inventory with two more columns in it than most inventories have: where the system runs, and which markets it serves.
The version of this that actually bites
The immediate exposure for a European or UK organisation is rarely direct regulation by a distant body. It is second-order, and it arrives through three routes.
Through components. A model, a dataset or a tool server developed under one regime carries the documentation and assurances that regime produces. Where those do not map onto what your regulator expects, the gap is yours to fill, and you will discover it during an assessment rather than during procurement.
Through customers. Large buyers increasingly impose their own regime-derived requirements down the supply chain, and a supplier serving customers in several jurisdictions ends up holding the union of their demands rather than the intersection. That is a commercial problem with an architectural solution — the ability to run the same capability in more than one configuration.
Through availability. Rules about where models may be used, by whom, and with what controls change on political timescales rather than product ones. A capability wired directly into one provider in one region is a business dependency on a policy decision nobody in your organisation can influence.
What to record now
The fifth line is the strategic one, and it is the same conclusion the sovereignty argument reaches from a different direction. An estate that can move a workload between destinations has converted a geopolitical risk into a configuration change. An estate that cannot has taken a position on international AI governance by accident, in application code, and will find out what that position was when something changes.
What this does not tell you
We have no view to offer on the merits of any governance regime, and we are not in a position to have one. What an institute of this kind can usefully say is narrower: the number of regimes is increasing, the differences between them are substantive rather than cosmetic, and an organisation with one set of answers is implicitly assuming a single regime applies.
It is also not a prediction that these arrangements converge. They may. The useful planning assumption is that they do not, because that assumption produces an architecture that survives either outcome, and the reverse assumption produces one that survives only the convergent case.
The reader who should act is whoever owns the AI inventory. Add the two columns — where it runs, whom it serves. It is an afternoon of work, and the resulting table is the one that will be asked for the first time a customer, a regulator or a board member asks a question that begins “in which jurisdiction”.