A Short & Happy Guide to AI Governance and Regulation
A guide to AI ethics, industry standards, professional responsibilities, and the laws and institutions shaping AI around the world.

By Kashyap Kompella and James M. Cooper
How should AI be governed—and by whom?
AI governance takes shape through legislation, industry standards, professional obligations, and the choices institutions make. Kashyap Kompella and James M. Cooper examine these overlapping sources of authority and the debates behind them, making a complex regulatory landscape easier to navigate.
The book argues for safeguards that have practical force. It considers how societies can respond to harmful uses of AI while accounting for innovation, national interests, and differing legal traditions. Its scope extends from organizational responsibilities to the international contest over how AI should develop.
Inside the book
- Governance and regulation: their different purposes, the forms AI harm can take, and the mechanisms through which rules acquire force.
- Contested questions: privacy, copyright, open-source models, competition, environmental impact, data sovereignty, and national security.
- Ethics and institutions: corporate AI principles and the work of international organizations, regional bodies, and safety institutes.
- Regulatory approaches: dedicated coverage of the United States, European Union, and China, alongside developments in countries including India, Japan, Singapore, and the United Kingdom.
- Professional responsibilities: bar association guidance on competence, confidentiality, supervision, communication, and fees.
- A framework for action: comparative lessons and the authors’ AIM-AI governance framework, with four governance zones and an appendix on policy implementation.
Who it is for
Readers seeking a clearer understanding of AI oversight in organizations, public institutions, and society. The guide is relevant to lawyers, policymakers, business leaders, and students examining how legal rules, ethical principles, and institutional responsibilities fit together.
Browse the table of contents (PDF) ↗
- Published
- 2025
Questions about governance and regulation.
What does AI Governance and Regulation cover?
The book examines industry debates and standards, national and international policies and laws, and the developing structures for AI governance.
The broader governance landscape also raises a practical organizational question: how should principles influence everyday conduct? Kashyap’s governance-framework article examines the organizational questions involved in establishing oversight. It offers a useful companion perspective for readers moving between institutional questions and organizational practice. Read more about an AI governance framework.
Who is the book for?
It is for readers seeking to understand AI oversight in organizations, society and government. Kashyap Kompella and James M. Cooper connect technology questions with governance and regulation.
Readers responsible for enterprise decisions may also want to understand how oversight affects the use of information. Kashyap’s work on cross-functional data governance shows why business, data and security teams need to coordinate. It connects the wider governance discussion to responsibilities that arise within an organization. Read more about cross-functional AI governance.
Is AI governance the same as regulatory compliance?
Compliance is one part of governance. Organizational accountability also requires clear ownership, monitoring and the ability to correct failures throughout the life of an AI system.
A compliance review asks whether relevant requirements have been met; an operational risk review also asks how failures will be detected and handled. Kashyap’s language-model risk guide addresses ongoing monitoring and third-party changes, illustrating why oversight continues after an initial approval. Read more about ongoing AI risk management.
Can an ethics statement substitute for operational oversight?
No. Principles need mechanisms that assign responsibility and address failures. A statement of intent alone does not establish accountability.
An organization also needs tools and working arrangements that make its intended controls usable. A policy can be difficult to apply consistently if teams lack visibility into systems and decisions. Kashyap’s governance-platform review considers technology that supports this work within a broader governance approach. Read more about AI governance platforms.
Does buying an AI service transfer accountability to the vendor?
No. The organization using AI still needs owners for its decisions and outcomes, along with arrangements to detect failures and respond to them.
Supplier arrangements should be considered alongside the organization’s own handling of information. External provision does not remove questions about access, purpose and permissions. Kashyap’s article with Tom Walat explains why privacy responsibilities and AI oversight must remain connected as systems and data relationships become more complex. Read more about integrated oversight.