Emerging technologies rarely arrive to a single, waiting rulebook. By the time a technology is consequential enough to need governance, three different kinds of authority are usually already reaching for it at once: a legislature drafting binding statute, an industry consortium drafting a voluntary consensus standard, and a human-rights body insisting that whatever gets built must still answer to entitlements that predate it by decades. Artificial intelligence over the past several years has made this collision unusually visible, because all three modes have produced finished, citable instruments in a short span: the European Union’s Artificial Intelligence Act, a binding regulation with fines attached [1]; ISO/IEC 42001 and IEEE 7000, voluntary management- system and process standards that organizations may adopt without any government requiring it [2, 3]; and a cluster of human-rights instruments, from the 1948 Universal Declaration of Human Rights to the Council of Europe’s 2024 Framework Convention on Artificial Intelligence, that frame the technology as one more thing states and increasingly businesses must answer for against pre-existing rights [8, 6].

This article compares these three approaches on dimensions that make the comparison mean something: enforceability, adaptability, legitimacy, and reach into questions of consent, liability, access, and intergenerational effect. It does not rank them. Scholars in law and philosophy who work on technology governance are largely in agreement on one point even when they disagree on everything else: these are complementary instruments answering different questions, not competing answers to the same question, and a governance regime that relies on only one of them is missing something the others were built to supply.

Three mechanisms of authority, not three opinions

The first thing to get right is that “approach to ethics and governance” is doing double duty here. Ethics, in the philosophical sense, is a set of claims about what is right, owed, or permissible. Governance is the machinery that makes any ethical claim binding, contestable, or enforceable in practice. The three approaches compared in this article are best understood as three different answers to a prior, structural question: where does the authority to bind a technology developer actually come from, and what happens when they refuse?

ADVERTISEMENT

Hard law answers that question with the state. A regulation like the EU AI Act derives its authority from a legislature’s sovereign power to compel, and its teeth are administrative fines, market withdrawal, and conformity-assessment failure — a company that places a prohibited AI practice on the EU market, or fails required conformity assessment for a high-risk system, faces penalties set in the regulation itself, up to a percentage of global turnover for the most serious violations [1]. Voluntary standards answer it with reputational and market incentive: ISO/IEC 42001 gives an organization something to certify against, and IEEE 7000 gives engineering teams a documented process for surfacing ethical concerns during design, but neither carries a sanction of its own — adoption is a choice, and non-adoption is not, by itself, unlawful anywhere [2, 3]. Human-rights instruments answer it with a claim of prior, universal entitlement: a right to privacy, non-discrimination, or an effective remedy does not originate with the technology and cannot be voided by a company’s terms of service, though whether and how it is enforced against a private AI developer, as opposed to a state, is exactly the point of ongoing legal disagreement discussed below [8, 9].

A technical-documentation binder open mid-page beside a metal compliance-stamp jig on a bright bench.
Figure 1. Hard law works through documentation and enforceable sanction: a technical file, assembled and stamped, is the artefact a binding regime like the EU AI Act actually asks for.Image prompt and art direction by Brecht Corbeel; generation pending.

Enforceability: sanction, certification, and complaint

Enforceability is the dimension people reach for first, and it is the one on which the three approaches differ most sharply and most clearly.

The EU AI Act is enforceable in the ordinary legal sense: it creates obligations tiered by risk category (unacceptable, high, limited, minimal), assigns conformity-assessment duties to providers of high-risk systems, and backs the whole structure with market-surveillance authorities empowered to demand technical documentation, order corrective action, and fine noncompliant firms [1]. This is what “hard law” means in practice: an entity outside the regulated industry, with police power behind it, can compel compliance whether or not the target firm agrees with the rule.

ISO/IEC 42001 and IEEE 7000 are enforceable only in the sense that certification bodies can withdraw a certificate, and a market can penalize firms that lose one. ISO/IEC 42001 specifies requirements for an organization’s AI management system — risk treatment, impact assessment, supplier oversight — and a firm can seek third-party certification against it, but nothing compels any firm to seek that certification in the first place [2]. IEEE 7000 is further still from sanction: it is a process standard for surfacing and documenting ethical concerns during system design, adopted because an engineering organization decides the process is useful or because a customer or regulator increasingly expects to see it referenced, not because refusing it is unlawful [3]. The enforcement mechanism here is market and reputational, not administrative: a firm that cannot show a recognized standard behind its AI practices may lose contracts, insurance terms, or public trust, but it commits no violation.

Human-rights instruments occupy a third, more complicated position. The Universal Declaration of Human Rights is not itself a binding treaty — it is a General Assembly declaration whose norms have since been given binding force through separate covenants and, regionally, through instruments like the European Convention on Human Rights [8]. The Council of Europe’s Framework Convention on Artificial Intelligence is a binding treaty among its state parties, the first of its kind for AI specifically, but its obligations run principally to states, and it explicitly leaves states latitude in how they extend equivalent protection to private-sector activity within their jurisdiction [6]. The UN Guiding Principles on Business and Human Rights fill part of that gap: they articulate a state duty to protect against private human-rights abuses and a distinct corporate responsibility to respect rights even where domestic law does not require it, plus a right of access to remedy — but the Guiding Principles themselves are a UN Human Rights Council endorsement, not a treaty, and rely on states and courts to give their remedy provisions actual legal force [9]. The upshot is not that rights-based governance is toothless; it is that its enforceability is indirect and layered, running through states, courts, and increasingly domestic statutes that incorporate human-rights language, rather than through a single sanctioning body the way the EU AI Act does.

ADVERTISEMENT
A redlined draft standard and stacked ballot folders on a long committee table.
Figure 2. Voluntary standards such as ISO/IEC 42001 and IEEE 7000 move through consensus and redline, not statute — a slower, more revisable route to the same governance questions.Image prompt and art direction by Brecht Corbeel; generation pending.

Adaptability: how fast each regime can move

Enforceability and adaptability trade off in something close to the opposite direction, and this is the part of the comparison scholars in technology law return to most often.

A binding statute is slow to write and slow to amend. The EU AI Act took years of negotiation to reach its 2024 text, and its risk-tiered categories, drafted against a snapshot of AI systems as they existed during drafting, will predictably need formal amendment or delegated-act updates as new system types appear that do not fit its existing categories cleanly [1]. This is an inherent property of hard law’s legitimacy, not a drafting failure: the slowness that makes it hard to update is the same deliberative process that gives it democratic legitimacy in the first place.

Voluntary standards are built for the opposite trade. ISO/IEC 42001 and IEEE 7000 are maintained by technical committees that can revise, profile, or extend a standard on a much shorter cycle than a legislature can amend a statute, because a standards body is not constrained by a legislative calendar or an executive veto [2, 3]. The U.S. NIST AI Risk Management Framework demonstrates this directly: NIST published the core framework in January 2023 and followed it with a generative-AI profile the following year, adding a specific supplementary document rather than rewriting or waiting to rewrite the whole framework [7]. The OECD AI Principles show the same pattern at the intergovernmental-guidance level, adopted in 2019 and revised in May 2024 specifically to address generative AI, safety, and information integrity — issues that barely existed in the original text [5]. Guidance documents and standards can be versioned the way software is; statutes generally cannot.

Human-rights instruments sit at neither extreme, because they adapt by interpretation rather than by amendment. The Universal Declaration’s text has not changed since 1948, but what counts as a violation of privacy or non-discrimination has been reinterpreted repeatedly as new technologies create new ways to violate it — this is precisely what UNESCO’s 2021 Recommendation on the Ethics of Artificial Intelligence does: it does not create new rights, it applies existing human-rights language (dignity, non-discrimination, oversight) to a technology unmentioned when those rights were first codified [4, 8]. This gives rights-based governance a kind of adaptability hard law lacks — it can reach a technology the drafters never imagined without new legislative text — but it comes at a cost in predictability: whether a given AI practice violates a right is often contested and resolved only case by case, through courts, treaty bodies, or UN-level interpretive guidance, rather than settled in advance the way a risk-tiered statute settles it.

Bound human-rights instrument volumes on a shelf beside a lectern reading stand with a treaty-body report open on it.
Figure 3. Human-rights instruments frame emerging technology as a question of pre-existing entitlement rather than new rulemaking, reaching back to documents like the Universal Declaration of 1948.Image prompt and art direction by Brecht Corbeel; generation pending.

Legitimacy: whose authority is this, and who consented to it

Legitimacy is the dimension least often made explicit, and it is where the philosophical stakes of “ethics and governance” separate most clearly from a purely technical comparison.

Hard law’s legitimacy claim is democratic: the EU AI Act binds because it passed through an elected Parliament and a Council of national governments, a chain of accountability that traces back to voters, however imperfectly [1]. Its critics do not usually dispute this chain; they dispute whether the resulting rules are well-designed, and whether a single jurisdiction’s rules functionally set a global standard for firms that would rather comply with one Act than build separate products for separate markets — a dynamic sometimes called the “Brussels effect,” an analytical claim about market power rather than a claim anyone in the drafting text asserts about itself.

ADVERTISEMENT

Voluntary standards’ legitimacy claim is expertise and consensus among the people who build the technology: ISO/IEC and IEEE standards are produced through working groups of practitioners and technical experts operating by consensus procedures, which gives them a legitimacy grounded in competence and buy-in from the regulated community itself, rather than in electoral accountability [2, 3]. The corresponding worry, raised consistently in the ethics-of- technology literature, is that a standard written mostly by the industry it applies to can end up calibrated to what is feasible or profitable for that industry rather than to what outside stakeholders, including the people affected by deployed systems, would have asked for had they been in the room.

Human-rights instruments claim a third kind of legitimacy: universality prior to any particular state’s consent, grounded in the idea that certain entitlements attach to persons as such and are not created by any government or committee. The Universal Declaration’s own drafting, spanning representatives from across the (then much smaller) United Nations, was explicitly an attempt at this kind of universal grounding rather than one nation’s export of its own values [8]. The Council of Europe’s Framework Convention and UNESCO’s Recommendation both root their AI-specific obligations explicitly in this pre-existing rights framework rather than inventing new AI-specific values from scratch [6, 4]. The open question here, on which legal scholars disagree rather than converge, is how directly a universal-rights claim binds a private company rather than a state — the UN Guiding Principles’ answer, a “responsibility to respect” distinct from a state’s binding “duty to protect,” is one resolution among several on offer, not a settled consensus [9].

Two side-by-side incident log binders on a desk, one open mid-entry.
Figure 4. Liability and remedy differ sharply by regime: statutory penalty, standards-body decertification, and human-rights complaint mechanisms each log harm differently and reach different remedies.Image prompt and art direction by Brecht Corbeel; generation pending.

Where the three approaches actually meet: access, liability, and future generations

Comparing enforceability, adaptability, and legitimacy in the abstract can make the three approaches sound like separate universes. They meet concretely on four questions any technology-governance regime eventually has to answer, and it is worth being explicit that here, too, none of the three approaches answers all four alone.

Consent and access. A binding regulation can require that a high-risk AI system meet transparency obligations toward the people subject to it, but it does not by itself guarantee that underserved populations get access to compliant systems at all — that is a market and infrastructure question, not a legal one, and the AI Act does not purport to solve it [1]. A voluntary standard says even less about access, since adoption itself is optional. A rights framework is the one of the three that puts access on the table explicitly, because a right that only the well-served can exercise is, in the human-rights literature’s own terms, not being fulfilled — but naming the problem this way does not supply the funding or infrastructure to fix it.

Liability and remedy. This is where the practical differences are starkest, and it is captured in this article’s own liability-registry and case-intake figures: a violation of the EU AI Act triggers an administrative-penalty process inside a designated market-surveillance authority; a lapsed ISO/IEC 42001 certification triggers, at most, decertification and whatever contractual consequences follow from that; and a rights violation, per the UN Guiding Principles’ “access to remedy” pillar, is supposed to reach a judicial or non-judicial grievance mechanism, but which mechanism, in which jurisdiction, and with what actual power to compel a remedy from a private company, remains one of the least settled parts of the entire framework [9].

Intergenerational effects. None of the three approaches was built with a long time horizon as its organizing question, and it would overstate the record to claim otherwise. The AI Act’s risk tiers are calibrated to present-day system types and will need revisiting as new categories emerge [1]. NIST’s own supplementary profiles are an implicit admission that a framework published in 2023 needs continual extension just to keep pace with systems a year or two old [7]. Rights instruments come closest to an intergenerational frame by virtue of their open-ended language — a right to non-discrimination does not expire — but applying that language to harms distributed across future populations who cannot yet participate in any current standard-setting or legislative process is, at present, an aspiration in the literature rather than a mechanism any of these instruments actually operationalizes.

A stack of enforcement case folders sliding into an intake tray on a bright desk.
Figure 5. How fast each regime can adapt to a new technology shows up here first: which stack of folders moves, and how long a new case waits at the intake tray before any of the three processes can act on it.Image prompt and art direction by Brecht Corbeel; generation pending.

Scenario: a plausible near-term equilibrium, stated as a scenario

It is tempting to predict which of the three approaches will “win.” That framing is a mistake, and scholarship in this area is largely explicit that it is a mistake, because the three approaches answer different questions and a firm operating across jurisdictions is already subject to more than one simultaneously. What can be stated instead is a conditional scenario, with its assumptions and disconfirmation condition made explicit rather than left implicit.

Scenario, horizon 2026–2030: hard law and voluntary standards increasingly interlock rather than compete, with regulators referencing standards like ISO/IEC 42001 as one accepted route to demonstrating regulatory compliance, while human-rights instruments continue to function mainly as an interpretive backstop invoked in litigation and treaty-body reporting rather than as a freestanding enforcement track. This rests on three assumptions: that standards bodies keep revising faster than legislatures, that no single high-profile AI harm forces an emergency legislative response that bypasses standards-referencing entirely, and that no major jurisdiction outside Europe adopts a comparably binding AI statute in this window. Observable indicators would include regulators formally naming specific standards in guidance documents, and courts citing UN-instrument language directly in AI-related rulings. The scenario would be disconfirmed by a jurisdiction enacting AI legislation that explicitly rejects standards-referencing as a compliance pathway, or by a binding supranational human-rights ruling that directly overrides a certified-compliant AI deployment.

What the comparison is for

The point of setting hard law, voluntary standards, and human-rights instruments side by side is not to crown one the “real” governance mechanism and the others as decoration. Each does something specific: hard law compels and sanctions; voluntary standards translate ethical commitments into auditable, revisable technical practice faster than any legislature can move; human-rights instruments hold open a claim of universal entitlement that survives any single jurisdiction’s statute or any single industry’s consensus. A firm, a regulator, or a citizen trying to reason about a specific emerging technology is usually asking a specific version of one of these three questions — can I be compelled, can I certify, can I claim a violation — and the answer depends on which of the three mechanisms of authority is actually being invoked. Treating them as interchangeable, or as competitors for the same office, is the surest way to misread what any one of them can actually do.