AI Safety

New AI Governance Paper Argues Deployers, Not Providers, Should Hold Final Authority

Zexun Wang's paper says enterprise deployers should control high-stakes AI decisions, not frontier model providers.

Deep Dive

In a new paper on arXiv, researcher Zexun Wang tackles a critical question for enterprise AI governance: who should have final say when capable AI systems are embedded in business workflows? The paper compares two competing models. The first, 'frontier-provider sovereignty,' gives privileged authority to the maker of the most powerful models—reflected in arguments for release gating, transparency duties, and compute controls. The second, 'action-centered deployer sovereignty,' places final authority with the organization that authorizes the action, embeds it in a business process, and bears the downstream consequences.

Wang systematically reviews five major governance frameworks—EU AI Act, NIST AI Risk Management Framework, Singapore's Model Framework for Agentic AI, recent Japanese instruments, and Canada's voluntary code—and finds stronger support across them for distributed operational accountability rather than unilateral provider control. The paper further argues that rapid enterprise adoption, declining provider transparency, and widening control gaps increase the value of a portable governance layer centered on governed action rather than provider-native session objects. The conclusion is nuanced: strong upstream authority remains justified for frontier capability gating, but final authority over concrete enterprise action should rest with the deployer and consequence-bearer.

Key Points
  • Compares frontier-provider sovereignty vs. action-centered deployer sovereignty across five global AI governance frameworks (EU AI Act, NIST, Singapore, Japan, Canada).
  • Finds stronger support for deployer-led operational accountability than for provider-centric control in all reviewed frameworks.
  • Proposes a 'portable governance layer' focused on governed actions, especially as provider transparency declines and enterprise adoption accelerates.

Why It Matters

Enterprise AI teams now have a clear governance model: keep final authority with deployers who bear legal and operational risk.

📬 Get the top 10 AI stories daily