University of Victoria · Department of Computer Science
Governing AI Across Borders
A comparative survey of global AI regulatory frameworks through the People–Processes–Platforms analytical lens.
170
Coded Classifications
10
Jurisdictions
17
PPP Sub-dimensions
87.6%
AI-Human Agreement
The PPP Analytical Framework
Regulatory provisions are analyzed across three interdependent dimensions, each decomposed into codable sub-dimensions.
People
- •Human oversight requirements
- •Accountability structures
- •Regulator and stakeholder roles
- •Workforce training and AI literacy
- •Affected persons' rights
Processes
- •Risk assessment
- •Auditing and compliance
- •Transparency requirements
- •Certification and governance
- •Incident reporting
- •Regulatory sandboxes
Platforms
- •AI system classification
- •Infrastructure and deployment
- •Data governance
- •Safety and robustness
- •Content labeling and provenance
- •GPAI / foundation model provisions
Jurisdictions Under Study
The survey examines regulatory frameworks across ten jurisdictions and international initiatives, selected for regulatory significance, typological diversity, and geographic coverage.
European Union
EuropeComprehensive risk-based
In force (August 2024); phased implementation through 2027
United States (Federal)
North AmericaSector-based, innovation-driven
Issued October 2023; revoked January 2025
Published January 2023
United States (Colorado)
North AmericaState-level risk-based
Signed 2024; effective June 30, 2026 (extended by SB25B-004)
China
East AsiaState-directed comprehensive
Effective January 2023
United Kingdom
EuropePrinciples-based, pro-innovation
Published March 2023
Singapore
Southeast AsiaVoluntary, innovation-first
UNESCO
InternationalNormative-international
Adopted November 2021
Key Findings
Two structural features account for substantial variation in regulatory coherence across the jurisdictions studied.
Classification as Regulatory Trigger
Jurisdictions with formal AI classification schemes exhibit a cascading obligation structure where a single taxonomic decision activates calibrated requirements across all three PPP dimensions.
11.5
avg. mandatory provisions
with classification
0.2
avg. mandatory provisions
without classification
Observed in EU, China, Colorado, Canada (cascading) vs. UK, Singapore, Japan, OECD, UNESCO (flat)
Institutional Creation Threshold
Jurisdictions converge on provisions implementable through existing institutions but diverge on provisions requiring new governance infrastructure, independent of regulatory philosophy.
76%
adaptation provisions
addressed
27%
creation provisions
addressed
Creation provisions: certification (PR4), incident reporting (PR5), regulatory sandboxes (PR6)
Research Questions & Findings
How do major AI regulatory frameworks distribute requirements across People, Processes, and Platforms dimensions?
The EU is the only jurisdiction with mandatory coverage across all 17 sub-dimensions (17M). Among binding frameworks, mandatory coverage ranges from 17 (EU) to 1 (Japan). The three light-touch frameworks (UK, Singapore, Japan) converge on 0–1 mandatory and 8–11 recommended provisions.
What regulatory philosophies underpin different frameworks, and how do they shape PPP emphasis?
Six regulatory philosophies identified. Philosophy predicts which PPP dimension receives emphasis (rights-based → People; state-directed → Platforms), but does not predict total coverage — which is determined by architectural features.
On which PPP sub-dimensions do frameworks converge or diverge most?
Highest convergence: transparency (PR3) and accountability (P2) are addressed by all 10 jurisdictions. Highest divergence: GPAI provisions (PL6), certification (PR4), and content labeling (PL5) are mandatory in at most 2 jurisdictions.
How do interdependencies between PPP dimensions manifest across regimes?
AI system classification (PL1) functions as a cross-dimensional regulatory trigger. Jurisdictions with classification (EU, China, Colorado, Canada) average 11.5 mandatory provisions; those without average 0.2.
What gaps emerge, and what do they imply for international harmonization?
Five critical gaps: GPAI regulation (PL6), certification (PR4), incident reporting (PR5), content labeling (PL5), and workforce training (P4). These are bounded by the institutional creation threshold — they require new governance infrastructure that most jurisdictions have not built.
Interactive Regulatory Heatmap
Hover any cell to see provision details. Filter by dimension or regulatory intensity. All 170 classifications at a glance.
| Sub-dimension | EU | US Fed | US CO | China | Canada | UK | Singapore | Japan | OECD | UNESCO |
|---|---|---|---|---|---|---|---|---|---|---|
P1Human Oversight | ||||||||||
P2Accountability | ||||||||||
P3Regulator & Stakeholder Roles | ||||||||||
P4Workforce Training & AI Literacy | ||||||||||
P5Affected Persons' Rights | ||||||||||
PR1Risk Assessment | ||||||||||
PR2Auditing & Compliance | ||||||||||
PR3Transparency Requirements | ||||||||||
PR4Certification & Governance | ||||||||||
PR5Incident Reporting | ||||||||||
PR6Regulatory Sandboxes | ||||||||||
PL1AI System Classification | ||||||||||
PL2Infrastructure & Deployment | ||||||||||
PL3Data Governance | ||||||||||
PL4Safety & Robustness | ||||||||||
PL5Content Labeling & Provenance | ||||||||||
PL6GPAI / Foundation Model Provisions |
Key Figures
Visual representations of the paper's principal findings.
Two Regulatory Architectures
Cascading (classification-triggered) vs. flat (independent provisions). The paper's central theoretical contribution.

Regulatory Profiles: Radar Comparison
PPP intensity profiles for six key jurisdictions. Shape differences encode the philosophy–dimension mapping.

Regulatory Philosophy Typology
Six regulatory philosophies identified from observed PPP configuration patterns. Philosophy predicts emphasis but not total coverage.
| Philosophy | Jurisdiction(s) | Characteristics | PPP Profile |
|---|---|---|---|
| Comprehensive risk-based | EU | Binding legislation; risk-tiered obligations; balanced PPP coverage | 17M / 0R / 0A |
| State-directed | China | Binding regulations; application-specific; state-supervised; Platforms emphasis | 13M / 2R / 2A |
| Public-sector focused | Canada | Mandatory for government use; strong People and Processes; limited Platforms | 8M / 2R / 7A |
| Sector-based decentralized | USA (Fed + CO) | No central AI authority; voluntary federal + binding state; fragmented | 8M / 13R / 13A |
| Light-touch | UK, Singapore, Japan | Guidance-oriented or narrow legislation; Recommended-heavy profiles | 1M / 29R / 21A |
| Normative-international | OECD, UNESCO | Values-based; no enforcement; broad principled coverage | 0M / 21R / 13A |
Cite & Export
Copy the citation or download the full coding dataset.
@article{potka2026ppp,
title = {People, Processes, Platforms: A Coding Framework and Comparative Benchmark for Global AI Governance},
author = {Potka, Shera and Weber, Jens},
year = {2026},
institution = {University of Victoria, Department of Computer Science},
note = {Available at https://ppp-ai-governance.vercel.app}
}Publication
Potka, S. & Weber, J.
People, Processes, Platforms: A Coding Framework and Comparative Benchmark for Global AI Governance
Department of Computer Science, University of Victoria, 2026.
This paper introduces a 17-sub-dimension coding framework for AI regulatory analysis, applies it across 10 jurisdictions (170 classifications validated at 87.6% AI-human agreement), and identifies two structural determinants of regulatory coherence: classification as a cross-dimensional trigger and the institutional creation threshold.