University of Victoria · Department of Computer Science

Governing AI Across Borders

A comparative survey of global AI regulatory frameworks through the People–Processes–Platforms analytical lens.

170

Coded Classifications

10

Jurisdictions

17

PPP Sub-dimensions

87.6%

AI-Human Agreement

The PPP Analytical Framework

Regulatory provisions are analyzed across three interdependent dimensions, each decomposed into codable sub-dimensions.

People

  • Human oversight requirements
  • Accountability structures
  • Regulator and stakeholder roles
  • Workforce training and AI literacy
  • Affected persons' rights

Processes

  • Risk assessment
  • Auditing and compliance
  • Transparency requirements
  • Certification and governance
  • Incident reporting
  • Regulatory sandboxes

Platforms

  • AI system classification
  • Infrastructure and deployment
  • Data governance
  • Safety and robustness
  • Content labeling and provenance
  • GPAI / foundation model provisions

Jurisdictions Under Study

The survey examines regulatory frameworks across ten jurisdictions and international initiatives, selected for regulatory significance, typological diversity, and geographic coverage.

European Union

Europe

Comprehensive risk-based

Artificial Intelligence Act (Regulation (EU) 2024/1689)

In force (August 2024); phased implementation through 2027

United States (Federal)

North America

Sector-based, innovation-driven

Executive Order on Safe, Secure, and Trustworthy AI (2023)

Issued October 2023; revoked January 2025

United States (Colorado)

North America

State-level risk-based

Colorado Artificial Intelligence Act (SB 24-205, 2024)

Signed 2024; effective June 30, 2026 (extended by SB25B-004)

Canada

North America

Public-sector focused

United Kingdom

Europe

Principles-based, pro-innovation

Singapore

Southeast Asia

Voluntary, innovation-first

Japan

East Asia

Promotional, cooperative

OECD

International

Normative-international

OECD AI Principles

Adopted 2019; updated 2024

UNESCO

International

Normative-international

Key Findings

Two structural features account for substantial variation in regulatory coherence across the jurisdictions studied.

Classification as Regulatory Trigger

Jurisdictions with formal AI classification schemes exhibit a cascading obligation structure where a single taxonomic decision activates calibrated requirements across all three PPP dimensions.

11.5

avg. mandatory provisions
with classification

0.2

avg. mandatory provisions
without classification

Observed in EU, China, Colorado, Canada (cascading) vs. UK, Singapore, Japan, OECD, UNESCO (flat)

Institutional Creation Threshold

Jurisdictions converge on provisions implementable through existing institutions but diverge on provisions requiring new governance infrastructure, independent of regulatory philosophy.

76%

adaptation provisions
addressed

27%

creation provisions
addressed

Creation provisions: certification (PR4), incident reporting (PR5), regulatory sandboxes (PR6)

Research Questions & Findings

RQ1

How do major AI regulatory frameworks distribute requirements across People, Processes, and Platforms dimensions?

Finding

The EU is the only jurisdiction with mandatory coverage across all 17 sub-dimensions (17M). Among binding frameworks, mandatory coverage ranges from 17 (EU) to 1 (Japan). The three light-touch frameworks (UK, Singapore, Japan) converge on 0–1 mandatory and 8–11 recommended provisions.

RQ2

What regulatory philosophies underpin different frameworks, and how do they shape PPP emphasis?

Finding

Six regulatory philosophies identified. Philosophy predicts which PPP dimension receives emphasis (rights-based → People; state-directed → Platforms), but does not predict total coverage — which is determined by architectural features.

RQ3

On which PPP sub-dimensions do frameworks converge or diverge most?

Finding

Highest convergence: transparency (PR3) and accountability (P2) are addressed by all 10 jurisdictions. Highest divergence: GPAI provisions (PL6), certification (PR4), and content labeling (PL5) are mandatory in at most 2 jurisdictions.

RQ4

How do interdependencies between PPP dimensions manifest across regimes?

Finding

AI system classification (PL1) functions as a cross-dimensional regulatory trigger. Jurisdictions with classification (EU, China, Colorado, Canada) average 11.5 mandatory provisions; those without average 0.2.

RQ5

What gaps emerge, and what do they imply for international harmonization?

Finding

Five critical gaps: GPAI regulation (PL6), certification (PR4), incident reporting (PR5), content labeling (PL5), and workforce training (P4). These are bounded by the institutional creation threshold — they require new governance infrastructure that most jurisdictions have not built.

Interactive Regulatory Heatmap

Hover any cell to see provision details. Filter by dimension or regulatory intensity. All 170 classifications at a glance.

Filter:
Sub-dimensionEUUS FedUS COChinaCanadaUKSingaporeJapanOECDUNESCO
P1Human Oversight
P2Accountability
P3Regulator & Stakeholder Roles
P4Workforce Training & AI Literacy
P5Affected Persons' Rights
PR1Risk Assessment
PR2Auditing & Compliance
PR3Transparency Requirements
PR4Certification & Governance
PR5Incident Reporting
PR6Regulatory Sandboxes
PL1AI System Classification
PL2Infrastructure & Deployment
PL3Data Governance
PL4Safety & Robustness
PL5Content Labeling & Provenance
PL6GPAI / Foundation Model Provisions
Mandatory
Recommended
Absent
17 sub-dimensions × 10 jurisdictions = 170 classifications

Key Figures

Visual representations of the paper's principal findings.

Two Regulatory Architectures

Cascading (classification-triggered) vs. flat (independent provisions). The paper's central theoretical contribution.

Diagram showing cascading vs flat regulatory architectures

Regulatory Profiles: Radar Comparison

PPP intensity profiles for six key jurisdictions. Shape differences encode the philosophy–dimension mapping.

Radar charts comparing PPP regulatory profiles across six jurisdictions

Regulatory Philosophy Typology

Six regulatory philosophies identified from observed PPP configuration patterns. Philosophy predicts emphasis but not total coverage.

PhilosophyJurisdiction(s)CharacteristicsPPP Profile
Comprehensive risk-basedEUBinding legislation; risk-tiered obligations; balanced PPP coverage17M / 0R / 0A
State-directedChinaBinding regulations; application-specific; state-supervised; Platforms emphasis13M / 2R / 2A
Public-sector focusedCanadaMandatory for government use; strong People and Processes; limited Platforms8M / 2R / 7A
Sector-based decentralizedUSA (Fed + CO)No central AI authority; voluntary federal + binding state; fragmented8M / 13R / 13A
Light-touchUK, Singapore, JapanGuidance-oriented or narrow legislation; Recommended-heavy profiles1M / 29R / 21A
Normative-internationalOECD, UNESCOValues-based; no enforcement; broad principled coverage0M / 21R / 13A

Cite & Export

Copy the citation or download the full coding dataset.

@article{potka2026ppp,
  title   = {People, Processes, Platforms: A Coding Framework and Comparative Benchmark for Global AI Governance},
  author  = {Potka, Shera and Weber, Jens},
  year    = {2026},
  institution = {University of Victoria, Department of Computer Science},
  note    = {Available at https://ppp-ai-governance.vercel.app}
}
2026

Publication

Potka, S. & Weber, J.

People, Processes, Platforms: A Coding Framework and Comparative Benchmark for Global AI Governance

Department of Computer Science, University of Victoria, 2026.

Survey PaperAI GovernanceComparative Regulatory AnalysisPPP Framework

This paper introduces a 17-sub-dimension coding framework for AI regulatory analysis, applies it across 10 jurisdictions (170 classifications validated at 87.6% AI-human agreement), and identifies two structural determinants of regulatory coherence: classification as a cross-dimensional trigger and the institutional creation threshold.