China Is Building a Second Pole in Global AI Governance
A new AI governance bloc just launched. Operators across Asia and Europe will have to navigate two increasingly incompatible frameworks

Every year since 2018, Shanghai has hosted the World Artificial Intelligence Conference—a showcase of Chinese AI ambition that has grown from a regional industry event into one of the most politically significant technology gatherings on the calendar. This year’s edition, which opened on July 17, was different in kind. Xi Jinping delivered a keynote in person for the first time in the conference’s history. The UN Secretary-General attended, along with heads of state and government leaders. There were delegations from more than 100 countries and international organizations. But the most consequential moment happened the day before the conference opened.
On July 16, representatives from 29 countries signed the founding agreement for the World Artificial Intelligence Cooperation Organization—WAICO—a new intergovernmental body headquartered in Shanghai. Unlike the EU AI Act, which is binding legislation with enforcement mechanisms and financial penalties, WAICO is currently built around common principles and cooperation, and does not yet require members to adopt a common regulatory code. The founding members include Indonesia, Pakistan, Kazakhstan, Russia, Malaysia, among others. What is as interesting as who’s being included is who’s not. No major Western democracy signed. No EU member state. No Japan. No South Korea. And no India, whose absence seems to reflect a cautious attitude against WAICO’s governance implications.
On August 2, the EU AI Act’s transparency obligations take effect, requiring chatbots to disclose they are AI, AI-generated content to carry machine-readable labels, and deepfakes to be identified. This is part of a broader rollout arriving in stages, with the more consequential high-risk system rules taking effect in December 2027 for standalone systems and August 2028 for AI embedded in regulated products.
An AI system deployed across EU and WAICO-member markets will increasingly encounter divergent obligations, standards and political expectations built on different assumptions about what AI governance should require.
Why This Is Not Just a Geopolitical Story
It would be easy to read WAICO’s founding as a diplomatic development that belongs in the foreign policy inbox rather than the technology strategy one. But this could be a turning point in how the world organizes itself around AI.
The EU and WAICO represent two markedly different starting points for AI governance. The EU AI Act asks: what could this AI system do wrong, and who is accountable if it does? It classifies systems by risk. The higher the potential harm to people or society, the stricter the requirements before the system can operate. An AI that influences whether someone gets a job, a loan, or medical treatment is treated as high-risk, and must pass detailed checks and maintain human oversight before it reaches users.
WAICO starts from a different place entirely. Its founding principles are as follows: AI for good, respect for sovereignty, development orientation, safety and controllability, fairness and inclusivity, and open cooperation. While WAICO does not yet require its members to adopt a common risk framework or regulatory code, its significance lies in the institutional direction it creates and the coordination it could enable over time. It notably prioritizes each nation’s right to govern AI on its own terms, with no values test and no common risk framework required for membership. Any sovereign state can join. The question WAICO asks is not what AI could do wrong, but what the world looks like if certain countries never get meaningful access to AI at all. In his speech on July 17, Xi pledged to help developing nations build AI capabilities, and warned against the emergence of “new historical injustices” from unequal access to technology.
Governance splits of this kind usually accumulate through a series of institutional choices that over time create fragmented operating environments. The internet offers the closest precedent. In theory, it’s one global system. In practice, it is a collection of regional versions, with some firewalls stronger than others. That outcome wasn’t planned. Rather, it arrived through accumulated decisions. AI governance appears to be on the same path.
What the Split Looks Like on the Ground
The divergence is already producing different outcomes for operators today.
The most immediate evidence is in model availability. Companies have already begun staggering AI product releases by region. ChatGPT remains blocked in mainland China entirely. Claude went live on Microsoft Foundry for the US before EU data residency support existed, limiting deployment among European organizations requiring guaranteed EU-based processing or strict data residency. In June, the Trump administration ordered Anthropic to cut off all foreign access to its two most advanced models—including users in allied countries—citing national security concerns. The ban was lifted less than three weeks later, but not before prompting Macron to call it a “wake-up call” and Canadian PM Mark Carney to warn against over-reliance on US-controlled AI. In July, China’s cybersecurity authority warned users of affected Claude Code versions to uninstall or upgrade the software over an alleged security risk. For an operator running AI-dependent workflows across both China and Europe, this means no single vendor can currently guarantee uninterrupted availability in both markets simultaneously; a dependency that needs to be designed around.
Vendor dependency has also taken on a political dimension that most procurement processes have not yet caught up with. On the hardware and supply chain side, the US-led Pax Silica initiative—now counting 24 signatories including Japan, South Korea, the UK, Australia, India, and Singapore—is building a coordinated framework for trusted semiconductors, AI infrastructure, and critical minerals, explicitly designed to reduce reliance on Chinese supply chains. On the governance side, WAICO anchors the alternative for its twenty-nine member states. Building critical workflows around a US-origin AI vendor creates real exposure in Asian markets where that vendor may be restricted. Building around a Chinese-origin vendor creates the inverse problem in Europe. For procurement teams, this means vendor origin is now a supply chain risk variable worth mapping explicitly before contracts are signed.
What makes this more urgent than it might first appear is that China is not waiting for WAICO’s governance standards to be written before establishing technological footholds in member states. At WAIC, Xi announced that over the next five years China will enable 30 countries to use MAZU, an AI-powered meteorological early-warning system already used by agencies in over 40 countries, as part of China’s own cooperation commitments to the Global South. This is a deliberate sequencing choice. By the time WAICO produces compliance obligations, many member-state ministries will already be running Chinese-stack applications. For operators building AI products or services for markets in WAICO-member countries, the practical implication is that the compliance environment that operators will eventually face is being shaped now, at the application layer, by tools governments are already running.
What This Means for Decisions Being Made Now
The governance split does not require operators to choose between frameworks. It requires them to understand which rules apply where, and to build AI procurement and deployment decisions that are not premised on a unified global environment.
Three questions are worth answering before the next AI procurement or deployment decision:
One, on vendor risk. Which AI vendors in your current stack have commercial or regulatory exposure risks in the markets you operate in, and what happens to your workflows if one of those vendors becomes unavailable or restricted in a specific market? The temporary US restriction on foreign access to Anthropic’s models established that this is not a hypothetical scenario.
Two, on compliance coverage. Is your AI compliance built around one jurisdiction’s requirements? A framework designed for the EU AI Act’s documentation and oversight requirements does not automatically cover what WAICO-member governments are likely to require as they develop their own rules.
Three, on architecture. Is your AI architecture portable enough to accommodate different documentation, data handling, and oversight obligations across jurisdictions? Or would satisfying one market’s requirements mean rebuilding for another?
In practical terms, operators should favor architectures with replaceable models, customer-controlled data and portable compliance layers. They should delay deployments where hosting locations, government-access exposure or transition rights remain unclear. They should reject critical workflows that cannot continue in degraded mode if one provider or model becomes unavailable.
The organizations best prepared for a more divided AI governance landscape will not be those that correctly predict which side prevails. They will be those that can change models, providers and compliance controls without rebuilding the operational workflow underneath them.
Go Deeper on Asia Tech Lens
At WAIC Hong Kong, the AI Conversation Has Moved Past the Model Race
Asia Tech Lens was on the ground at WAIC UP! Hong Kong in January, where the conversation had already shifted from model performance to ecosystem power and the choices operators face between US and Chinese AI stacks.
India’s AI Push Is Real. Production Access Is the Constraint
India is pursuing a different position in the global AI landscape: building domestic compute and deployment capacity rather than simply choosing between US- and China-led ecosystems. For operators, the test is whether that infrastructure provides reservable capacity, auditable controls and portability.
Vietnam’s New AI Law: The Road Ahead For Businesses
Vietnam’s transition window gives operators limited time to build the documentation, logging and vendor controls needed before compliance gaps begin blocking deployments.
Indonesia Is Racing To Regulate AI. The Messy Part Is Implementation
Indonesia’s emerging AI rules show why the biggest operator risk may not be the regulation itself, but uncertain implementation, enforcement and transition requirements.
AI Middleware Promises Flexibility. In Asia, It Can Create Jurisdictional Lock-In
Middleware may reduce dependence on one model while creating a harder dependency through embedded routing, storage and compliance decisions.

