The first two pieces in this series walked through a pattern using America’s digital ID rollout as the case study: independent authorities each building their own piece of a system, with no one coordinating across them. The same pattern is playing out right now with far more visibility and far higher stakes, in AI governance. As of today, it’s a live case, not a hypothetical one.
Polycentric governance, the term from the second piece in this series, describes a structure:
multiple independent authorities, each with real power in its own lane, none reporting to a shared boss.
It doesn’t say anything about who, if anyone, is actively working to keep those authorities lined up. In practice, someone usually is, even informally, even without the title for it.
Public management researchers have a term for that work: metagovernance. Louis Meuleman, who wrote the main academic book on the subject, defines it as designing and managing, shifting between, and combining different styles of governance rather than picking one and sticking with it. A more recent review of the literature puts it more plainly: metagovernance is a practice, mainly by public authorities, of coordinating across governance modes with different instruments and strategies, specifically to fix governance failures that show up when nobody’s doing that coordinating.
Where that work is missing right now
AI governance is that gap, live, at global scale.
The European Union’s AI Act became fully enforceable on August 2, 2026, the first time any jurisdiction has imposed comprehensive, binding regulation on AI systems. That’s one governance mode: hierarchy, backed by enforcement.
The US is running a completely different mode, or rather, 38 different modes. There’s still no comprehensive federal AI law. States enacted 145 AI laws in 2025 alone, with major frameworks now in force in California, Texas, and Illinois, and Colorado’s AI Act taking effect June 30, 2026.
That’s a patchwork built state by state, each one legislating independently, closer to competition than coordination.
Sitting underneath all of it is a fourth mode: NIST’s AI Risk Management Framework, a voluntary technical standard rather than a law. Colorado explicitly built a safe harbor into its own AI Act for companies that follow it, and the framework lines up with both ISO/IEC 42001 and the EU AI Act’s requirements, which makes it one of the few things in this picture actually built to bridge jurisdictions rather than compete with them. The OECD’s AI Policy Observatory is tracking more than 1,000 AI policy initiatives across 69 countries, which gives some sense of how many separate authorities are making this same set of decisions on their own.
Four modes, running at the same time, with no one authority deciding which one applies where: a binding EU law, a state-by-state legislative patchwork, a federal attempt to override that patchwork that hasn’t succeeded, and a voluntary technical standard that happens to be the only thing all sides can plug into. Any company operating across US states and the EU is the one actually absorbing the cost of that gap, piecing together compliance across all four modes itself, because no one else is doing that coordinating for them.
A diagnostic for your own program
The same setup shows up in smaller systems, including the kind most people manage day to day: a program built from multiple offices, vendors, or legal authorities that are each real and each partly in charge.
A few questions to check for it: Are you dealing with more than one governance mode at the same time: some hierarchy, some negotiated agreement, some market-style competition among vendors or teams? Is the choice of which mode to use for a given problem being made deliberately, or is it just whichever tool happens to be closest at hand? And is anyone actually doing the work of switching between modes as the situation calls for it, or is each part of the system running its own default, the way California, Texas, and the EU currently are?
If the answer is nobody, that’s not necessarily a crisis yet. It’s a gap that tends to stay invisible until the cost of it lands on someone, the way it’s currently landing on any company trying to operate across all four AI governance modes at once.
What this changes
None of this requires appointing a new authority or restructuring anything. Metagovernance is usually informal, done by whoever in the system is already paying attention to more than one piece at a time. Naming it just makes that work visible, both to the person doing it and to whoever they answer to.
For AI governance, that coordinating work barely exists yet, and the bill for that gap is already coming due for anyone operating across more than one of these jurisdictions. For a program you manage yourself, the more useful question is whether that work is happening at all, and whether it’s happening on purpose. More on Metagovernance.
Nicole
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.