The UN Call on AI Safety Rules, and What Reaches the Machine Room
On the eve of the UN General Debate opening today in New York, Finland's President Alexander Stubb and Norway's Prime Minister Jonas Gahr Støre put forward a call for binding safety rules for the most capable AI models. ORF counts more than 20 signatories; Deutschlandfunk counts 18 heads of state, joined by Commission President von der Leyen and several foreign ministers. Austria is in, per the federal chancellery. The USA, China, the UK, France, Japan and India are not. Taken alone: a diplomatic footnote with good timing. The lines between them are worth the look.
The timing is the story. The call lays itself down before the General Debate, not after it, and it comes from two countries that host neither frontier labs nor data centers of this class. That is diplomacy with a clear message: whoever writes the rules refuses to be the last one getting them.
What the declaration asks for
Three obligations the call places on model providers, as the chronicles have it:
- testing of the most capable models, before and during operation
- independent evaluation by bodies that are not the manufacturer
- transparent safety protocols, under the principle that AI stays under human direction, oversight and control
The reasoning stands out. It is not abstract; it names incidents: capable systems that recently evaded safety mechanisms, exploited vulnerabilities and gained unauthorized access to computer systems. That is exactly the offense category we dissected in the rogue agent behavior post. Now a head of state signs as sender. In the same news cycle, a UN expert panel asks for safety rules modeled on aviation and nuclear plants: certified processes, reporting duties, equipment certification. Two texts, one logic. They stop treating the model as a software feature and start treating it as equipment with hazard potential.
What the text leaves out belongs in the balance too. No moratorium, no liability rules, no sanction mechanism; not even a threshold at which a model formally counts as capable. It starts at the market, not at the ban. And the absence of the USA and China weighs twice, because the largest frontier labs sit in exactly those two countries. Without them the call stays a club of users and operators, not of producers.
From declaration to questionnaire
This does not become law overnight. But regulation in this field rarely arrives as a leap; it arrives as a cascade:
The honest finding for our customer side: the New York items already sit in questionnaires today. An industrial buyer putting out an AI pipeline this autumn asks for testing before production use, for independent evaluation, and for protocols on failure behavior. Not because New York decided so, but because ISO/IEC 27001:2022, NIST AI RMF and European engineering practice have covered those fields for years. The call changes nothing about how we work. It changes how often it gets asked.
Austria: the homework already has dates
Anyone deploying or operating AI in Austria needs no UN resolution to think in deadlines:
| Duty | Date | Where we wrote it |
|---|---|---|
| AI competence proof (Art. 4 AI Act) | applies now; sanctions possible from 02.08.2027 | Article 4 post |
| NISG registration for essential entities | portal from 01.10.2026, deadline 31.12.2026 | registration post |
| CRA reporting for products with digital elements | 24 h / 72 h on incident | CRA handbook |
What should sit in the drawer
From that cascade you can distill a work list that answers every point of the call locally. Not as compliance theater, but as the four things an operation must know about a model before it gets tasks:
- Model inventory. Which model, which version, which weights, which hardware, which operator circle. Without this line, every deeper question is impossible.
- A test protocol per change. One task set, measured before and after, with pass and fail criteria. We do this with 34 everyday tasks; the number is small, but it is real.
- An independent pair of eyes. Not the vendor who built the lane gets to judge it, but someone who earns nothing from it. If that person sits inside your own company: a written role definition suffices.
- An incident format. A model that gains unauthorized access is a disturbance with a ticket, a root cause and a countermeasure, not a chat log. Our pattern for it is the patch and incident protocol.
The overlooked point about New York is exactly item four: the call treats AI safety incidents as their own event class (evaded, escaped, unauthorized entry). Anyone already running that internally will later have to rearrange nothing formal, only add the word "UN" to the customer slide.
Standpoint
A declaration without sanctions is no reason to celebrate and no reason for extra work. But it shows which way the republic's procurement offices will ask over the next two years. And the answer is the same one we practice month after month in our own tests and protocols: document model changes, measure behavior before and after, keep the records. So we take the occasion and give our task sample a date. From now on every model change in the lane gets a one-page protocol, filed in the operations folder, kept for three years. No new process, just the same measurements with a lid on. The UN is not inventing this. It is just putting twenty signatures under a sheet customers wrote themselves long ago.
Further reading
- ORF.at: UN call for stronger AI regulation: signatory list, initiators, absentees (22.09.2026)
- Deutschlandfunk: binding safety rules demanded: count of 18 heads of state, expert panel (22.09.2026)
- Bletchley AI Safety Summit 2023 (Wikipedia): the 2023 blueprint whose cascade is running now
- From this site: rogue agent behavior, NISG registration
What does the call demand concretely?+
Binding safety rules for the most capable models: testing before and during operation, independent evaluation by bodies that are not the vendor, and transparent safety protocols. Plus the governing principle that AI stays under human direction, oversight and control. The addressees are model providers, not operators; everything else is cascade.
Who did not sign?+
The USA, China, the UK, France, Japan and India are absent from the list, as ORF reports citing the initiators. Alongside Austria signed Germany, Finland, Norway, Denmark, Canada, the Netherlands, Spain, Australia and Singapore among others, plus Commission President von der Leyen and the foreign ministers of Bahrain, Turkey and the UAE.
Is this law now?+
No. A call is a declaration, not a norm, comparable to the 2023 Bletchley Declaration, from which national bodies and testing institutes only emerged years later. The path to binding rules runs through expert panels, standards and procurement. For an IT operation this means: contracts do not change today, but the questions in the purchasing questionnaire already come from this chain.
senn-tech