WSIS Forum 2026
AI-generated report

Making AI Safe in the Real World: From Governance Principles to Operational Tools

5 speakers
Summary

This discussion focused on the challenge of translating AI governance principles into concrete implementation, with particular reference to the Council of Europe's Framework Convention on AI, Human Rights, Democracy and Rule of Law (Convention 225, known as the Vilnius Convention) .

Thomas Schneider opened by noting that principles without implementation remain mere aspiration, and that the session aimed to explore the gap between written commitments and actual practice . He later explained that the Convention's core logic is not to reinvent existing human rights standards but to ensure they apply in contexts where AI is deployed, while allowing each country to implement them according to its own legal and institutional traditions . He also highlighted the HUDERIA methodology as a practical, three-tiered tool developed collaboratively by legal, technical, and academic experts to guide risk assessment and impact mitigation .

Hoda Baraka described Egypt's experience as a concrete example of a Global South country moving from strategy to operational practice . Egypt established a National Council for AI in 2019, developed two editions of a national AI strategy, created an Egyptian Charter for Responsible AI, and founded the Egyptian Centre for Responsible AI . Egypt studied 35 governance frameworks, including HUDERIA and the UNESCO recommendation, to contextualise an approach suited to its own culture and institutions . Key lessons included embedding responsible AI early, treating procurement as a strategic governance tool, investing in capacity building, and prioritising localisation .

Peter Deussen outlined ISO's complementary role, noting that ISO/IEC standards address organisational risk management and governance processes, while HUDERIA focuses specifically on impacts to individuals and society in relation to human rights, democracy, and rule of law . He argued that bridging these two frameworks could help organisations implement HUDERIA more effectively, as ISO standards provide language and processes that industry already understands . He also identified a gap in guidance on how ISO standards can be applied in a regulatory or policymaking context .

The discussion concluded that the gap between governance principles and real-world implementation is bridgeable, provided that normative frameworks, technical standards, financial support, and technical assistance are combined and pursued collaboratively .

Keypoints
  • Overall Purpose

  • The discussion aimed to explore how AI governance principles can be translated into real-world implementation, moving beyond abstract frameworks and soft law. Specifically, it examined the role of the Council of Europe's Framework Convention on AI (Convention 225/Vilnius Convention), Egypt's practical national AI governance experience, and the contribution of international technical standards in bridging the gap between written principles and operational practice.
  • --
  • Major Discussion Points

  • The Council of Europe's Vilnius Convention as a normative anchor for global AI governance. Thomas Schneider explained that the convention does not reinvent existing human rights frameworks but instead ensures they apply in AI contexts, regardless of a country's legal system. It defines principles and mechanisms that states must fulfil whilst allowing flexibility in how they do so, creating interoperability between different national systems. The convention is open to all countries that respect human rights, democracy, and rule of law, and is expected to generate a broader cooperation community - analogous to the Budapest Cybercrime Convention - once ratified. - Egypt's practical journey from AI governance principles to operational implementation. Egypt developed a comprehensive "responsible AI governance stack," beginning with the National Council for AI in 2019 and progressing through two editions of a national AI strategy, an Egyptian Charter for Responsible AI, and the establishment of the Egyptian Centre for Responsible AI. A study of 35 international governance frameworks, including the Vilnius Convention and Hudeira methodology, informed a localised, risk-based and rights-based national framework. Key practical outputs included AI system guidelines, a procurement guideline mapped to ISO standards, a child safety guideline, and an Arabic-language large language model (Karnak) designed for contextual relevance across Arab and African countries. - The HUDERIA methodology as a practical bridge between principles and assessment. HUDERIA was highlighted as particularly useful because it moves the conversation from abstract values to structured, practical assessment, asking concrete questions about context, stakeholders, and impact evaluation. It operates across three levels of detail - from general functions to an 80-page questionnaire-based implementation guide - and was developed collaboratively by legal, technical, academic, and business communities, tested on real cases. Egypt explicitly mapped HUDERIA processes to relevant ISO standards within its procurement guidelines, enabling public officials to understand which standards to apply when procuring AI systems. - The complementary role of ISO/IEC international standards in filling technical governance gaps. Peter Deussen outlined ISO/IEC SC42's work on AI risk management, a governance management system standard (42001), and a new standard on AI system impact assessment covering impacts on individuals and society. He described ISO standards and HUDERIA as complementary - ISO provides organisational process integration and industry-understood language, whilst the latter focuses on human rights, democracy, and rule of law impacts. A key identified gap is the absence of guidance on how ISO standards can be used in a regulatory or policymaking context, with a bridging document or mapping suggested as a useful way forward. - Development finance and compute infrastructure as critical but underserved dimensions of AI governance implementation. Whilst technical assistance from bodies such as the World Bank and GIZ can support capacity building, policy development, and curriculum design, hardware and compute infrastructure remain a significant challenge for countries like Egypt. Egypt's AI audit lab is currently limited to GPU-equipped desktops rather than a full cloud-based sandbox due to funding constraints, and alternative financing mechanisms are actively being explored. The panel noted that the development finance dimension is rarely addressed in AI governance discussions and identified it as an important area requiring dedicated future sessions. ---
  • Overall Tone

  • The overall tone of the discussion was constructive, collaborative, and cautiously optimistic. From the outset, speakers framed the conversation as practical and solution-oriented rather than theoretical, with Thomas Schneider setting a purposeful tone by emphasising the gap between principles and implementation. Ayisha Piotti maintained an encouraging and inclusive moderating style throughout, drawing out concrete examples and affirming contributions. Egypt's contribution, delivered by Hoda Baraka, introduced a notably grounded and candid register - initially positive and detailed when describing achievements , but shifting to a more sobering tone when addressing compute infrastructure and funding limitations. This moment of candour added realism to what had otherwise been an upbeat account of progress.
  • Peter Deussen's contribution was measured and technical, acknowledging both the strengths of existing standards work and its gaps without overstating either. The closing remarks by Ayisha Piotti returned the tone to one of tempered optimism, affirming that the gap between governance principles and real-world implementation is bridgeable, provided normative, financial, and technical assistance dimensions are addressed together. Throughout, the discussion remained respectful, collegial, and focused, with no notable tension or disagreement between participants.
Speakers Overview
TS
Thomas Schneider
161 wpm · 13 min
AP
Ayisha Piotti
183 wpm · 11 min
HB
Hoda Baraka
127 wpm · 14 min
PD
Peter Deussen
132 wpm · 7 min
A
Audience
121 wpm · 1 min

Expanded Summary: Making AI Safe in the Real World - From Principles to Implementation

#

Context and Purpose of the Session

The discussion took place during an AI governance week in Geneva, bringing together participants both physically present and online on a Friday morning . The session was organised by the Council of Europe's CDNet Secretariat and moderated by Ayisha Piotti, managing partner of Rego Horizon and head of the AI Policy Summit at ETH Zurich . Thomas Schneider, Director for International Affairs at Ofcom Switzerland, former chair of the Council of Europe's Committee on Artificial Intelligence from 2022 to 2024, and the main lead for the organisation of the Global AI Summit scheduled for 2027 in Geneva, opened proceedings by framing the central challenge: that principles without implementation remain mere aspiration, and that the session aimed to explore whether tools now exist to close the gap between written commitments and actual practice . The panel also featured Dr Hoda Baraka, adviser to the Minister at Egypt's Ministry of Communication and Information Technology and professor of computer engineering at Cairo University, and Peter Deussen, an expert in international standards with extensive involvement in ISO and IEC .

#

The Four Dimensions of the Implementation Challenge

Piotti structured the discussion around four dimensions of the implementation challenge . The first was the normative dimension - specifically, the role of the Council of Europe's Framework Convention on AI, Human Rights, Democracy and Rule of Law, and the accompanying Huderia methodology . The second was the country implementation dimension, illustrated through Egypt's national experience . The third was the standards dimension - the technical infrastructure that can help governments and organisations implement impact assessment, risk management, and governance requirements consistently . The fourth, which could not be fully addressed due to the absence of a dedicated panellist, was the development finance and technical assistance dimension, though Piotti noted that this issue remained central and underexplored in governance discussions more broadly .

#

The Council of Europe's Framework Convention on AI as a Normative Anchor

Thomas Schneider provided a detailed account of the Council of Europe's Framework Convention on AI, formally known as Convention 225 and referred to as the Vilnius Convention after being opened for signature in Vilnius in September 2024 . The Convention is the framework convention on AI, human rights, democracy, and rule of law, and had already attracted 21 signatures globally by the time of the session, including one from the European Union on behalf of its 27 member states . Schneider noted that the EU had ratified the Convention the previous month, and expressed hope that further ratifications would follow to bring it into force .

Schneider explained that the Convention's core logic is not to reinvent existing human rights frameworks but to ensure that established standards - covering human rights, democracy, and rule of law - apply in contexts where AI is deployed, regardless of a country's legal system . Crucially, the Convention does not reference anything explicitly European; it refers to all national and international standards, making it a genuinely global instrument accessible to any country that respects human rights, democracy, and rule of law . It defines principles and mechanisms that states must fulfil for public actors and those acting on their behalf, whilst also committing states to ensuring equivalent protections apply to private actors using AI . Importantly, the Convention does not prescribe exactly how states must implement these requirements, leaving each country free to do so in accordance with its own institutional and legal traditions . By defining common principles and required mechanisms without imposing a single model, the Convention creates a degree of interoperability between different national systems whilst allowing different ways of achieving the same ends .

Schneider also highlighted the Huderia methodology as a practical, three-tiered tool designed to bridge the gap between abstract principles and operational assessment . The first tier covers general functions; the second is a 20-page document explaining the different elements of the model; and the third is an 80-page document containing detailed questionnaires for in-depth implementation . He emphasised that Huderia was developed not by lawyers alone but by a multidisciplinary team including technical standardisation experts, academics, and business practitioners, and that it is being tested on concrete cases . Looking ahead, Schneider drew an analogy with the Budapest Cybercrime Convention, which has attracted participation from approximately 150 countries despite having around 80 signatories, suggesting that the cooperation community that will emerge once the AI Convention enters into force may be as significant as the treaty instrument itself .

#

Egypt's National AI Governance Journey: From Strategy to Operational Practice

Hoda Baraka presented Egypt's experience as a concrete example of a Global South country translating AI governance principles into operational practice . She began by articulating a foundational insight that shaped Egypt's entire approach: AI governance cannot remain a set of high-level principles or a policy paper, but must become part of how government designs, procures, deploys, monitors, and evaluates AI systems, embedded in institutions, procurement processes, sectoral implementation, capacity building, and the daily decisions of public officials .

Egypt's journey began in 2019 with the establishment of the National Council for Artificial Intelligence . This was followed by two editions of a national AI strategy - the first relatively simple, the second comprehensive and launched in January 2025 - as well as the development of an Egyptian Charter for Responsible AI, aligned with OECD principles and UNESCO recommendations, and the establishment of the Egyptian Centre for Responsible AI . A critical early step was a governance framework study in which Egypt examined 35 different governance frameworks, including the Council of Europe's Framework Convention, the Huderia methodology, the UNESCO recommendation, the OECD AI principles, and the Hiroshima process . The objective was not to copy any single model but to understand the full landscape and then localise and contextualise an approach suited to Egypt's own culture, norms, and institutions .

From this foundation, Egypt developed a risk-based and rights-based national AI governance framework, drawing on the EU AI Act for the risk-based categorisation of applications and on the Council of Europe and CDNet for the rights-based approach, including stakeholder involvement . Huderia proved particularly useful in this process because it moves the discussion from abstract values to structured assessment, asking practical questions about context, stakeholders, and impact evaluation . Egypt incorporated elements of Huderia - particularly those relating to stakeholder management, pre- and post-deployment phases, and the embedding of responsible AI principles in the design phase - into its AI system guidelines .

A further practical output was the development of procurement guidelines, which Baraka described as a strategic governance tool . Public officials had struggled to translate high-level AI system guidelines into actionable steps, prompting Egypt to create a mapping between every process in the Huderia methodology and the relevant ISO standards, so that officials would know which standards to apply when procuring AI systems . Egypt is also developing a child safety guideline in collaboration with the National Telecom Regulatory Authority, targeting parents and educators in pre-university education . On the question of localisation, Egypt developed an Arabic large language model called Ozkarnak (referred to as Karnak for short) through its Applied Innovation Center, designed to reflect Egyptian cultural values and norms, and is in discussions with African countries about extending this model to the African context .

Baraka drew four key lessons from Egypt's journey. First, responsible AI must be embedded from the very beginning, with a concept of government as orchestrator balancing the protection of human rights with innovation and economic development . Second, procurement is a strategic governance tool, and Egypt is establishing an AI audit lab to train public officials on what governance and responsible AI mean in practice . Third, capacity building is essential across all segments of society, from children to elderly citizens to public officials . Fourth, localisation and international cooperation are both critical, with Egypt positioning itself as a bridge between Africa, the Arab region, and the Mediterranean .

#

The Complementary Role of ISO/IEC International Standards

Peter Deussen outlined the work of ISO/IEC's joint committee on artificial intelligence, SC42, which has developed a suite of complementary standards . These include a standard on AI risk management - for which Deussen served as an editor - a general AI management system standard (ISO 42001) providing requirements for how organisations should set up processes to deal responsibly with AI development and use, and a more recent standard on AI system impact assessment explicitly focused on impacts to individuals, groups of individuals, and society . Deussen noted that ISO standards traditionally focus on organisational risks - financial, reputational, and so on - and that a gap existed with respect to risks imposed by technology on individuals and society, which the new impact assessment standard was designed to address . He also noted that the impact assessment standard focuses on both positive and negative impacts, making it somewhat broader in scope than Huderia, which focuses on negative impacts only.

Deussen described ISO standards and Huderia as complementary rather than duplicative - two sides of the same thing . ISO standards provide the connection to what organisations should actually do internally, specifying review cycles, approval processes, and documentation requirements, whilst Huderia focuses on the substance of impacts on human rights, democracy, and rule of law . He argued that bringing the two together could be a very good approach, making it easier for organisations to implement Huderia whilst also enabling ISO standards to be used in a regulatory context . A key advantage of ISO standards in this regard is that they provide language and industry best practices that organisations already understand, making them an effective bridge between governance principles and industry practice .

Deussen also identified a significant gap: ISO has not yet produced guidance on how its standards can be used in a regulatory or policymaking context, as they are written in industry-specific language and concepts . He suggested that a guidance document or mapping bridging ISO standards and the regulatory world would be a useful way forward . This observation is particularly notable given that Baraka had already described Egypt undertaking precisely this kind of mapping exercise in practice .

#

Development Finance and Compute Infrastructure: The Underserved Dimension

When the discussion turned to development finance, Baraka introduced a more candid and sobering register. Whilst Egypt's human capital and policy capacity are strong, and whilst policies, guidelines, capacity building, and use case development can be funded through national resources, compute infrastructure represents a major challenge . Technical assistance from multilateral organisations such as the World Bank and GIZ can support capacity building, curriculum development, and policy review, but does not address hardware needs . As a result, Egypt's AI audit lab is currently limited to a modest collection of GPU-equipped desktop computers rather than a full cloud-based AI sandbox, due to funding constraints . Egypt is actively exploring alternative financing mechanisms and business models to address this gap .

Piotti reinforced this point in her closing remarks, noting that the development finance dimension is rarely addressed in AI governance discussions and calling for dedicated future sessions to explore how institutional finance mechanisms can be better connected to rights-based AI governance implementation . She framed this as one of the session's key takeaways, alongside the normative anchor provided by the Council of Europe Convention and the bridging role of technical standards .

#

Audience Contribution: The Information Infrastructure Gap

An audience member raised a further dimension that had not been explicitly addressed by the panellists: the absence of standardised, cross-jurisdictional information about where and how AI is being used across industries and companies, and what the level of human oversight versus AI autonomy is in each case . The argument was that without this foundational information, effective governance and decision-making remain impossible . Deussen acknowledged the legitimacy of this gap, noting that whilst ISO's standard ISO 42500 provides a good approach to documenting AI systems and their risks, it does not provide a catalogue or database of all industry applications . He suggested that standardisation could provide the structure for such a database - defining what information should be recorded and how it should be organised - but that populating it with actual data is beyond the scope of standardisation . This exchange highlighted a systemic information gap that sits beneath all existing governance frameworks.

#

Key Themes and Conclusions

The discussion revealed a high degree of consensus on the central challenge and the broad direction of solutions. All speakers agreed that principles without implementation tools are merely aspirational , that Huderia and ISO standards are complementary and should be used together , and that international cooperation and multi-stakeholder approaches are essential . The Council of Europe Convention was endorsed not only by Schneider but also by Baraka as a genuinely useful instrument for non-member states, with Egypt having voluntarily incorporated it and the Huderia methodology into its national governance framework .

The discussion also surfaced important contrasts between different speakers' perspectives. Schneider's framing presented the Convention, Huderia, and ISO standards as forming a coherent and largely sufficient package , whilst Baraka made clear that even with sophisticated governance frameworks in place, the inability to fund cloud-based infrastructure represents a fundamental barrier to full implementation . Deussen's identification of a gap between ISO standards and the regulatory world further underscored the distance that remains between formal frameworks and on-the-ground practice, particularly given that Egypt had already partially addressed this gap through its own mapping exercise .

In her closing remarks, Piotti synthesised the session's key conclusions with measured optimism. She affirmed that the gap between governance principles and real-world implementation is bridgeable , but emphasised that doing so requires the normative, financial, and technical assistance dimensions to be addressed together and in collaboration . She highlighted Egypt's experience as demonstrating that countries need not wait for international consensus before moving forward , the Council of Europe Convention as a normative anchor open to all , and technical standards as providing the industry-legible language needed to connect governance frameworks to practice . Her final call was for continued collaboration, a willingness to try even in the face of uncertainty, and dedicated future work on the development finance dimension that the session had identified as critical but underserved .

—
Thomas Schneider
Should we start? Did you get him? Not yet. Okay, so we'll see. So good morning everyone. Physically present here on a Friday morning in Geneva as well as online. My name is Thomas Schneider. I work for the Swiss government, but I also have been working in the Council of Europe for many years. And so I'm very happy to on behalf of the Council of Europe, welcome you to what I think is an important discussion that we should be having here in Geneva during this. important AI governance week where we heard a lot about AI governance principles and we think that the Council of Europe has contributed with the convention that has the number 225. It is now called Vilnius Convention because it was put up for signature in Vilnius in September 24. It is the framework convention on AI, human rights, democracy and rule of law. It has already gotten since then 21 signatures globally, one signature of which is from the European Union, so that counts for 27 member states. And it has last month been ratified by the EU on behalf of these 27 member states and of course we hope that more ratification will happen. It will come soon that it can enter into force. very soon. So the convention singles out a number of principles, but of course principles without implementation are just aspiration. And what we're here today to discuss is the distance between the two and whether tools now exist to close the gap between principles written on paper and actually implemented. So we have in the room a number of people who contributed to this. We'll hear from states building AI governance frameworks under real institutional and capacity constraints from the Council of Europe perspective where treaty obligations are being translated into practical methodology and from the international standards community where technical tools for implementation are being developed. Development finance is also part of this picture even if it is not represented as a separate voice on the panel today. but it is already present in the country cases that we'll discuss, digital transformation projects, AI readiness work, technical assistance, and the difficult question of how rights -based governance is embedded into real public sector reform. So this is the conversation that in our view matters, and I'm very delighted to have a hand over the floor to Ayesha Pioti, managing partner of Rego Horizon and head of the AI Policy Summit that she's been organizing for many years now at the ETH Zurich, which she built from scratch and which is now one of Europe's leading global AI policy platforms, drawing participants from over 100 countries. And she also sits on the ITU UNESCO Broadband Commission's Expert Committee on AI Capacity Building and has spent 20 years doing what very few people in this space actually do, which is to say that she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group around concrete policy solutions rather than abstract principles. She is also, as you will hear, an excellent moderator. So let me hand over to you, Ayesha. Thank you.
—
Ayisha Piotti
Thank you so much. Thank you. I mean, I wasn't expecting such a wonderful introduction, so thanks a lot. So some of the things I wanted to say have already been said, but first of all, I'd like to just welcome everybody to today's discussion on making AI safe in the real world and how we move from principles to implementation. The session is organized by the Council of Europe CDNet Secretariat, so thanks very much to all of them to have taken putting us all together. Now, in terms of the problem statement that's already been pointed out by Thomas, so I shall not basically go into it, but essentially what we're looking at is very much the implementation side of all the principles and guidelines that we already have. So in today's session, we'd like to explore, in fact, four dimensions of the implementation challenge. I'm not sure whether we will be able to do all of that since we don't have everybody here, but we will try nonetheless to have a conversation and then we can try to also bring in some of the views that you have in order to make the discussion complete. So first and foremost, we'd like to look at the normative dimension. And what I mean by that is what is the role of the Council of Europe's Convention on AI that has been just mentioned by Thomas? And of course, the subsequent Houdiera methodology, of course, frameworks that provides concrete assessment and governance tools for human rights, democracy and the rule of law commitments. The second one we'd like to explore is the country implementation dimension. So essentially, we will have from Egypt with regards to. The national context, both for working from strategy to how it actually goes into the real institutional practice. So, in this context, we will have from Egypt with regards to the country implementation dimension. third is the standards dimension and that's the technical infrastructure that can help governments and organizations to implement the impact assessment, risk management and governance requirements consistently and the fourth in fact was supposed to be finance and technical assistance dimension we had hoped to in fact include that perspective directly today but unfortunately that's not been possible but we still think that this issue is very central and I'm very I'm glad that this is something that has been raised. I have to say that I've been in many many discussions so far in governance and that the whole institutional basically development finance angle is not that much that's covered so we hope that we can in fact build something around that and have some takeaways that can be taken away from this one so before I start I would also like to introduce my fellow panel panelists and And Thomas has said good words about me, so I'll start with the master, Thomas Schneider. And for everybody, he is director for international affairs at Ofcom, Switzerland, vice chair of the CDNet. But also he was the chair of the Council of Europe's Committee on Artificial Intelligence from 2022 to 2024. And some of you might not know, but he's a very sought after person. Also, because he is the main lead for the organization of the Global AI Summit scheduled for 2027 in Geneva. So welcome, Thomas, and somebody with great depth in this area. We also have Dr. Hoda Baraka, one of principal architects of Egypt's National AI Journey. She's advisor to the minister at Ministry of Communication, Information Technology in Egypt and a professor of computer engineering at Cairo University. So welcome. on my right I have Mr. Peter Doyson from EXPERT from the world of international standards with over 15 years of experience and active, very involvement international standard bodies included ISO, IEC and I think the list goes on the list goes on pleasure to have you here with us we were meant to be also having Mr. James Cobber but I understand that he hasn't been able to make it maybe he's going to join us and if he does we'll just bring him into the conversation so without any further ado I would probably like to start with Dr. Hoda Baraka about Egypt and what I'd like to say is Egypt didn't really wait for the international community, my understanding is that you decided to move forward, you decided to move forward with the national AI strategy you created the National Council for Artificial Intelligence and of course the Egyptian Center for Responsible AI You've also, and I think that was very interesting, cited Hudi 'ira as one of the inspirations for you to have done and taken those steps, and I think that's very, very interesting. So my question would be, ow was Egypt able to translate these principles into operational practice first and foremost, and what hurdles particularly did you face when you tried to make safe AI a reality in a government context?
—
Hoda Baraka
Well, thank you very much, Aisha, and thank you, Ambassador Thomas, and thank you, of course, for the Council of Europe and CZNet to convene this important and very practical discussion. I mean, this is maybe the last day in Oasis, and everyone has heard a lot about all the challenges that encounter AI governance, and I think what Egypt is bringing here is a very important challenge. is more a practical experience of the global South countries. I think how to translate AI governance principle into operational practice, this is a very, very important question, and it's not an easy journey, actually, but it is really a journey that needs to start slowly but firmly so that we can really reach a real objective and impact from what we are implementing in the field of AI. For Egypt, the starting point was a clear recognition. AI governance cannot really remain like just a set of high -level principles or a policy paper. It has to become part of how government designs, procures, deploys, monitors, and evaluates. And that's what we're trying to do with AI systems. It has to be embedded also in institutions, in our procurement processes, in our sectoral implementation, in capacity building, and in the daily decisions of our public officials. And I think public officials, this is one of the important parts that we need to focus very much on if you want really to move with AI in a responsible and ethical way. That's why Egypt has been working on what we describe a full responsible AI governance stack. So as you mentioned, Aisha, we started with the National Council for AI, and this was back in 2019. And then we had developed our national AI strategy. We actually had two editions of the national AI strategy. The first one was very simple, and the second one is very comprehensive. It has been launched in January 2025. And we developed the Egyptian Charter for Responsible AI, very much aligned with the OECD principles and also the UNESCO. And we established what we call the Egyptian Center for Responsible AI. I think this was just last year, and it was a milestone for the government to realize the importance of having a center. We have another center for implementation and for use cases, but the part of policies, governance, capacity building is actually embedded inside the Egyptian Center for Responsible AI. One of the important steps that we undertook to start was a governance framework study. So this was really a very important point where we studied like 35 different governance frameworks. Of course, including the council. of Europe's Framework Convention, or AI, the Huderia, the UNESCO recommendation, the OCG AI principles, Hiroshima. We had 35 different governance frameworks. And our objective was not to copy, of course, any of these models, but to understand all of this and then make sure that we can localize it and contextualize it to our Egyptian culture and norms and institutions. So this study helped us actually to shape our national AI governance framework. And this was one of the first steps that we have done that is around a risk -based and rights -based approach. Importantly, very, very important that we understand how to make sure that it's a risk -based approach. Of course, we looked at the EU AI Act for this point and how we can identify four different approaches. We looked at the different categories of applications. And also on the same time, with the Council of Europe and CZNET, we also understand what does it mean to make sure that we have the rights -based approach, how to include human rights and how to make sure that we are involving the stakeholders actually as part of our process. Huderia has been particularly useful because it helps move the discussion from the very abstract value to structured assessment. And it asks practical questions. What is the context? Who are the stakeholders? How can you actually evaluate the impact? What we have done is that we actually took some of Huderia principles and included in our second important document, which was the AI system guidelines. This was the AI system workflow. And we took... We took a little bit... from Hodaria related to the part of the stakeholder management, of course, the part of the pre -deployment and the post -deployment phase, how to make sure that we include responsible AI principles in the design phase, and then include it also in the post -deployment to monitor and to audit the AI systems implementation. This took us to an important guideline, which is the procurement guideline, because we found out that all the public officials struggle in understanding. It's very nice, Dr. Hahn, that you put for us for AI system guidelines, but at the end of the day, we don't know how to realize these guidelines. So we put together, this is still a work under process. The procurement guideline, and inside the procurement guideline, we actually also are very actively working. with the ISO and we wanted to make this link and we were happy actually to find out one of the sessions here where we bring it together, the ISO from one side and Huderia from the other side. Why? Because we realized when we were writing our procurement guideline is that it's fine that we have the Huderia, this is a framework, but how can we implement it? And we did this kind of mapping between every process in the Huderia methodology and what kind of ISO standards well mapped into so that we can provide the public officials with the standards that they have to realize while procurement their AI system. One final also document we are currently working on is the AI child safety. because, again, it's not only about the procurement, the public officials, but actually at the end of the day we have the society, and we want to make sure that children are protected. So we are currently working with our regulator, the National Telecom Regulatory Authority, on making sure that we have also a guideline for parents, for educators, especially for pre -university education on the child protection. So one thing also that we have maybe put into practice is the conceptualization. Egypt, of course, is an Arabic -speaking country, and definitely we want to have our language model related to our culture, our values, our norms, and that's why our Applied Innovation Center has worked on an Arabic, Arabic LLM, Ozkarnak. and we are very proud that we can provide this LLM also to the Arab countries from one side and also to contextualize it for African countries. We are talking now with a number of African countries on how to take Karnak to the African world and I think this is also something important to understand how can we contextualize and localize foundational models. So I think this is more or less what we have done to bring things to practice and maybe one last part is related to what lessons we have learned from this journey that has been going maybe for the last two years very aggressively with all our partners. First of all, responsible AI must be embedded very early. And we need to have this concept from the beginning, from the early beginning, if you want really to move in a very steady manner and to make sure that we are definitely having this kind of orchestrating. We call it government as orchestrator, balancing between protection rights, human rights, and also on the other side, innovations, small and medium enterprises, boosting the economy. Second, procurement definitely is a strategic governance tool. And I think one of the things that we are doing now is establishing an AI sandbox, an AI audit lab to train public officials on tools of what does it mean governance and what does it mean responsible AI. Third, capacity building. Of course, we've heard a lot of capacity building going on and capacity building on different segments from children up to elderly up to public officials. And the fourth lesson is, of course, localization. I think international cooperation and what we have seen in this Geneva AI Governance Week is definitely important. Our collaboration with CGNet, with ISO, with all different other organizations. I think this is crucial. This kind of international collaboration and multi -stakeholder approach is really very important. And Egypt is always ready to to act as a bridge between Africa, between the Arab region, between also the Mediterranean, the EU. I think our location is really in the middle of everything. So we are happy to help and to provide, to exchange our experience in this important emerging technology. Thank you.
—
Ayisha Piotti
Thank you so much. I was really not aware how much Egypt was doing, so bravo. It's fantastic and it's great to see that you're able to take all of these instruments and then look at your local needs, adapt them to that and then move forward with really concrete steps. So thanks for sharing that experience. In the interest of time, I think we'll build on that point and I'm going to come to Thomas now and coming back to the convention, which is now, of course, as you said, attracting a lot of signatures, ratifications. But of course, there are many, many states outside of the Council of Europe and they are obviously looking for guidance as well. And the question really is, and that could be in Africa, Asia and many other countries. the question really is if they actually have accession to the convention, what does it really give them that they cannot get anywhere else and also what does the Council of Europe really commit to them in terms of giving them back and that would be very useful Thanks Thomas.
—
Thomas Schneider
Thank you Ayesha and it's during this week when you listen to the discussions there are many people that express the needs that we need more clear guidelines, guardrails regulatory frameworks, whatever it is called in detail and that this is something that is missed there is a lot around like a lot of soft law from the OECD work to UNESCO's recommendation, also Council of Europe soft law which is a lot of it is sectorial from the media field to health etc. etc. and there are many self-regulatory business associations, guidelines and so on and so forth you have the G7 process, the Hiroshima process and other frameworks but this is all soft law or self-regulation And then, of course, we have technical standards that we mentioned that need to play together with this. And this call for we need some clear guidelines that are reliable, that are clear, is issued not just by governments or by civil society, but it's also coming from the developers, from the technical community themselves, that they are looking for clear guidelines in the sense that what is it that they can orient themselves to, and also coming from businesses. We've heard probably Brad Smith from Microsoft also calling for a clear framework. And the thing is, I think, and this is the first answer, and we've already heard it from you, this convention gives a core element, at least, of this guidance, and it does it in a fairly intelligent way in the sense that it refers to existing standards, all the European standards. And it's a key of its convention, number 225 of the Council of Europe. it doesn't replace it doesn't try to reinvent the wheel it doesn't replace anything that is there before it refers to it but not just to the European it doesn't refer to anything explicitly European it refers to all national and international standards so it's a global instrument also all the UN and other all the compacts and all the soft law and the conventions of all the other institutions and what it does it makes sure it tries to make sure that the existing standards no matter where in which region in the world you are that you have on protecting human rights democracy and rule of law also apply to environments where AI comes into play and I think this is the very simple but very intelligent logic of this tool that it says okay we have developed over the last century a number of standards let's make sure that these apply we don't change them but we try to make sure that these apply to AI no matter in which country you are no matter what your legal system is no matter how exactly you interpret the right to freedom of expression or right to privacy where you have differences even within between Europe and the US and other continents is not human rights and all of this is not a homogeneous thing. Even in Europe, even in the EU, you have some diversity in how countries due to their history and so on see these rights and organize them. And so this is the intelligent move to build an existing framework to fill one precise gap to make sure that this all is applicable to AI and also to make this convention accessible to all countries in the world that respect human rights, democracy, and rule of law. It states the principles that states need to make sure that are fulfilled for public actors. It defines a number of mechanisms and functions that need to be in place so that people can actually exercise their rights, that they have access to documentation, that there needs to be an instance that they can go to to say my rights have not been respected. But it doesn't tell governments exactly how they need to do it. So it is up to every state to do this based on their institutional and legal history so that they can do it in the way it works for them. At the same time, by defining the same principles and requesting the existence of mechanisms with the same function, it creates a certain level of another buzzword that we hear all over the place of interoperability between different systems. So it brings everyone on the same level while allowing different ways of doing this. And it also, although the principles apply the way they are written, states are obliged to use them on public actors and those acting on behalf of the public. States also commit to, and even in a more free way, but they commit to make sure that the same level of protection is also applied when it comes to interoperability. To public, private actors using AI. So it's not just focusing. on public actors. It makes a differentiation in terms of the responsibility of the actors for protecting human rights and democracy and rule of law, which makes sense because it's true, but it includes also a responsibility for states to make sure that people's rights and democracy and rule of law is also protected when it comes to private actors. So it's a very simple but compelling logic, I think, that can be applicable in every country and allows every country to do it in their way. And Egypt is a very good example about you look at all the options and you think that this is actually a very good way of doing things. And as you said, one thing is to have these principles and the mechanisms and the intended functions on paper. The other thing is, and this is not trivial, to actually make sure that this is being implemented in a way that any regulator, any authorities that will be responsible understand how it's going to work. How this should be done, how these risks can be assessed and if they are occur or impacts, if they occur, can be mitigated. But this is also important for the industry, for the developers, that they understand, okay, what is actually my responsibility and what is maybe not my responsibility, but the responsibility of those that deploy a system in a particular machine or bigger application, what may be the responsibility of those that use this. So this Huderia methodology and model is really a useful tool, whether or not you have signed or ratified the Council of Europe Convention, everyone will need, every public, every state will need to have assessment mechanisms for risks and mitigation mechanisms for negative impact. And this Huderia model gives a very understandable guidance on how you can do this, and it has three levels. One is very general functions. The second level is the 20-page document that explains the different elements of the Huderia model also in a very general way. and then if you want to go deeper, you have like an 80-page document that really has questionnaires and goes into detail about how you could implement this, so it is really thought through, and you also realize when you read it that it hasn't developed by lawyers, by human rights lawyers, only it has been developed by people from the technical standardization community, you have academics, you have business people, and it's being tested on concrete cases. So this is a package that is really unique, and then the third thing, which is going to come as soon as we have the five ratifications, now we have one, unfortunately it's one that goes for 27 countries, though it is only one signature in the new situation of the EU, but now that the EU, the biggest block is there, the others will hopefully come soon. The other element is the cooperation. the whole community that will emerge as soon as the convention is in place. And we saw this with, and I'll stop with this, we saw this with the Cybercrime Convention, the Budapest Convention, which is also a good predecessor. It's a convention by the Council of Europe that has around 80 signatures globally, but there are around 150, so almost all countries are somehow participating in the cooperation and exchange of experience and best practice exercises around the convention. And as soon as this convention, the AI convention, is ratified, you will have the same that countries and all other actors, whether they have ratified or not, will engage, and that space is equally important than the convention itself. Thank you so much.
—
Ayisha Piotti
Thank you so much. So you mentioned a few things, and I think that was quite interesting, because first thing you said. You said, which I thought was very, very... the Council of Europe's Convention is really a clear instrument which is targeted for something specific, which is human rights, democracy, and rule of law. And I think that is very key. So we have instruments that are there that can be binding as well, but if they are focused and targeted. I think that's clear. You talked about interoperability and technical community, which brings me straight to Peter. So Peter, of course, as we are seeing that the countries are trying to have their national strategies, they're also looking at what's happening for the Council of Europe's Convention. And the question there is what is really the role of international standards? And in your opinion, essentially, when you look at the current landscape, and as you know, there's many, there's ISO, there's NCELEC, there's NIST, and all of them. To what extent do you think they're able to really fill the gaps when it comes to the technical aspects, and what could be some of the ways forward for the countries?
—
Peter Deussen
Thank you. Thank you, Ashi, and let me try to address these questions. So, what ISO has established is a committee for artificial intelligence it is actually a joint committee between ISO and IEC and that committee has developed various documents that might be of interest here. First one would be a document on risk management a couple of years ago. I had the honor to serve as an editor for this document. Then, after checking that, you know, after understanding how we could deal with risks for artificial intelligence we went to the question how to define a general governance framework for AI which led us to the development of what we call the Standardization and Management System Standard for 2001 is the number here which provides you with, you know, general requirements on how to set up processes within an organization on how to deal responsibly with artificial intelligence, with the development and use of AI systems. And then we notice we have a gap. The gap is, you know, ISO standards usually look into organizational risks, you know, risks for the organization itself, financial risks, for instance, risk of reputations and so on. They don't look that much beyond that to risks that are imposed by, you know, technology to individuals, groups of individuals, individual society. So, that was a gap that we also had in that standardization work of SC42. So, we decided to, you know, to fill that gap and to develop a standard on AI system impact assessment, which explicitly focused on impact of AI systems systems. to persons, to individuals, to group of individuals, and to society in general. That document focuses on positive impacts as well as negative impacts, so it's a little bit broader than Houdaria, which focuses on negative impacts only. It also talks a little bit more generic about impacts, while Houdaria focuses on human rights, democracy, rule of law. That's included, but you know, the document that we have developed in the Standardization Committee is not specific to that. What that document gives you, what's not in Houdaria, is how to tie the impact assessment to your internal, to your organizational processes. It talks about what kind of review cycle do you need? What kind of approval processes do you need? What kind of documentation would be appropriate to understand this? So this is the work that ISO has done in that context. And I believe, you know, if you look into this document, I felt it's very complementary to what we have done in ISO. It's, you know, like two sides of the same things. ISO gives you more like the connection to what to do actually within your organization, you know, and how this ties into the processes that you have there, while Hedaria focuses more on the matter as such, on, you know, impacts or risks on human rights, democracy and rule of law. And it gives you very precise and very good guidance on how to implement, you know, and how to understand risks in this context. My feeling is that bringing these two things together You know, like, you know, bridging between those two things might be a very good approach, you know, to, you know, to make ISO standards, you know, use them also in a regulatory context and, you know, make it better, you know, make it more easy for organizations to implement your dairy, actually. Because, you know, these documents provide you with language that industry understands. It provides you with industry best practices. So, if you want to talk about companies who, you know, developing or, you know, bringing AI in the market, that's the language they understand. So, I think, you know, it's a perfect match, actually. So, what's missing? What are the gaps? Well, good question. ISO has provided comprehensive framework on how to deal with artificial intelligence in a responsible way. What I believe they have not done yet. Yet is. to describe how these documents can be used in a regulatory context, how these documents can be used by policymakers. So they are concentrating on industry -specific language, right? They have concepts that are specific to industry. They have terminology that's used there. You know, my feeling is having some kind of guidance document, some kind of mapping that, you know, bridging between those documents and the regulatory world. That might be a very useful way
—
Ayisha Piotti
Thanks very much. I think what I really liked was what you said with regards to standards providing the language that the industry really understands. This is a new one, and I think this is very, very key, and I think that's really the real core role, I believe, of the international standard bodies as well. We have a little bit of time. I think we started late, but I was just thinking, is anybody in the room having a question? Yes. Thank you. We can hear you.
—
Audience
Thank you very much for this detailed presentation of what is going on in the different parts of the boards and the association right now. My question is addressed to Mr. Peterson about the gaps. We do have a lot of, in different institutions, a lot of guidances. But in the gap, we don't have a language that gives the information. Because every kind of decision in our particular lives, in our working activity, or on the governmental level, based on the information, if we don't have it, we can't make any decisions or govern anything. So particularly what information I do mean to say. We don't have information where exactly is used AI. in any different industries and companies, how particularly they are using, and what is the interaction between the human oversight and AI as an autonomy level. So what do you think, would this kind of information in a standardized way, of course, because it should be across all the jurisdictions and industries, can build the gap of foundation for governance and for action taking? Thank you.
—
Peter Deussen
Well, what 42 ,500 gives you is, you know, a very good approach on how to document your AI system and the risk that's imposed by it. It does not give you, you know, some kind of catalog or database or something like this where you put in all those information. It's actually beyond standardization, right? But my question is, you know, my feeling is that having such, you know, catalog or database might be, you know, actually useful. And what ISO can provide is the structure of such a database, explaining what kind of information put into this database and how to maintain it, how to organize it. I think this is what standardization can do. Of course, standardization cannot provide you with a catalog about all industry applications of artificial intelligence.
—
Ayisha Piotti
Any other questions on the floor? No? I have a question, actually, and it's one topic that we didn't really get into and I know that we were planning to. It's about development finance. And I was just wondering, so very specifically for Egypt, of course, you've done so much. To what extent have you, in fact, made use of some of those tools, I mean, World Bank, so on and so forth, and what has been the experience, if any?
—
Hoda Baraka
Thanks. maybe my first part was optimistic positive part but this question always brings the pessimistic part of the case so definitely compute infrastructure for us is a big challenge so maybe we have the minds in Egypt we have a big human capital so when we talk about policies guidelines development use cases implementation capacity building all of these parts can be really done by our local national funds but when we talk about compute infrastructure then this is becoming one of our biggest challenges in order to move forward with AI and with exploiting all the benefits that AI can bring it doesn't mean that all the other parts of our national AI strategy does not involve funding. But when we tap on, for example, the World Bank or GIZ or any multilateral organization, always we have the technical assistance part. So with technical assistance, you can do some work related to capacity building, developing the curricula, having the national standards, having the policies. They can help us in the reviewing, the revision, even with CDNet. This was a process that we are definitely seizing the opportunity for this kind of assistance. But when we talk about hardware, for example, our initial step was to establish the AI sandbox. So we couldn't actually fund a cloud -based sandbox. So we just make the AI, we call it even AI audit lab, to be humble and moderate, because it's just a lab with a number of desktops with GPUs, but we cannot make until now the full -fledged cloud -based AI sandbox because, of course, of funding. So currently we are exploring different ways of funding. And financing mechanisms so that it can help us in the full implementation of the strategy. So we hope that you can find solutions, business models, and all of that.
—
Ayisha Piotti
Thank you so much. I think we're running out of time now, so I'll quickly – anything, we wrap up? Is that okay? Yeah. So we're going to wrap up. So thank you so much. Thank you, everybody, for being here. It's been a great pleasure. I'm not going to do a very long sort of conclusion, just a few words. So I think what we've heard today, the very – first thing is that there are countries that are not really waiting. They're moving forward. There is enough out there for countries to move forward, and Egypt has really been a great example of that. And the question of course now is, if you really want to look at implementation, the first thing we should do is start trying. Take whatever we have, start working with that. So I think that has been wonderful, and it's great to see that. Well, I think I'll just follow on to what you just said. So it looks like the development and finance, and there can be much more that can be done there. And I think that is actually a takeaway that we should take away from this session as well, and I think this is a topic that I don't see very much being dealt with, and I think it would be great to have some more sessions on that to really see how we can build the bridge there for implementation. The third one I think, which I think is very, very important, is of course the Council of Europe's Treaty. It's really there. It's a normative anchor. I think it's something that can be reused. It's open for all, and I think that was a big takeaway. More and more, it could be something that can be used as as in the case of Egypt, also as an inspiration for many other countries and their support that is available also at the Secretariat if needed to move forward with that. And last but not least, I think it's, of course, the role of the technical standards. And I think what is very key is the interoperability side, the fact that we need that. And I think what I really liked today was also that it's not only allowing the interoperability, but also making the link with industry, and which is what really is what is required as well. So we can come up with anything, but if the industry is not able to implement or move forward with it, that doesn't help us very much. So I think with that, I would just say that, you know, we came here, of course, to ask whether the gap between governance and principles in the real world implementation was bridgeable. And what I hear and what I see is, yes, it is. But, of course, in order for us to do that really, really well, we will need the normative side. We will need, of course, the financial, but we will also need the technical assistance side. And if we do that together in collaboration, the way we have this kind of session here today as well, and we discuss that and move forward with that. try, and even if we fail, still try, take the risk. I think that's the way forward. So with that, I would just say thank you so much for being here. Thank you for the session. Thank you to the Secretariat for the Council of Europe for organizing it, and I wish you all the rest of the day a really nice day and a good weekend. It was a pleasure.

Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.