Before AI Governance: What Did We Learn from Data Protection, Cybersecurity and Internet Governance?
When people talk about AI governance today, the conversation often begins with recent developments.
The European Union’s AI Act.
The OECD AI Principles.
UNESCO’s Recommendation on the Ethics of Artificial Intelligence.
The rise of generative AI.
Frontier AI safety.
International AI summits.
These developments are important.
But modern AI governance did not appear suddenly.
The institutions and ideas now associated with AI governance were built on decades of earlier debates about privacy, data protection, cybersecurity, internet governance, human rights, consumer protection and automated decision-making.
Understanding this history matters because many of today’s AI governance questions are not completely new.
What is new is the scale, speed and general-purpose nature of modern AI.
Societies have already spent decades trying to answer questions such as who should control personal data, how digital systems should be secured, what rights people have when automated systems affect them and how technology companies should be held accountable.
AI governance has inherited many of these questions.
At the same time, increasingly capable AI systems are exposing the limits of some existing approaches.
THE FIRST GOVERNANCE PROBLEM: DATA
One of the earliest foundations of modern AI governance was the governance of data.
This is not surprising.
AI systems depend heavily on data.
Modern machine-learning systems can require enormous quantities of information for training, testing and operation. The more AI became dependent on data, the more questions about how data could be collected, stored, processed and shared became relevant to AI.
But data governance predates modern AI by decades.
As computers became increasingly capable of storing and processing personal information, governments began confronting a new problem.
How should societies protect individuals when information about them can be collected and processed at scale?
This question eventually contributed to the development of modern data protection frameworks.
One of the most important milestones was the emergence of data protection principles in Europe during the 1970s and 1980s.
These early frameworks established ideas around lawful data processing, purpose limitation, data quality, security and individual rights.
The underlying principle was significant:
The ability to process information does not automatically create an unlimited right to use it.
That principle remains highly relevant to AI.
THE EVOLUTION OF PRIVACY GOVERNANCE
As digital technologies expanded, privacy governance became increasingly sophisticated.
The Council of Europe adopted Convention 108 in 1981, establishing an international legal framework concerning the protection of individuals with regard to the automatic processing of personal data.
The OECD also developed privacy guidelines in 1980, later revised in 2013.
These developments reflected a growing recognition that information technologies could create new forms of power.
Organisations that control large quantities of personal information can potentially know more about individuals than those individuals know about the organisations processing their information.
This imbalance became increasingly important as digital platforms expanded.
The emergence of the internet dramatically increased the scale of information flows.
And eventually, AI would transform the problem again.
Instead of simply storing information, increasingly sophisticated systems could use data to infer patterns, generate predictions and produce decisions.
The governance question therefore evolved.
It was no longer only:
Who has my data?
It increasingly became:
What can an AI system infer about me?
How is that inference being used?
Can the result affect my rights or opportunities?
Can I challenge it?
This is one reason why privacy and AI governance are now closely connected.
FROM DATA PROTECTION TO THE GDPR
The development of the European Union’s General Data Protection Regulation, or GDPR, represented another major step in the evolution of digital governance.
The GDPR entered into application in 2018 and established a comprehensive framework for personal data protection across the European Union.
Its importance for AI extends beyond privacy.
The GDPR reinforced principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation and accountability.
It also strengthened individual rights concerning personal data and automated decision-making.
This created an important precedent.
Digital governance was increasingly becoming a system in which organisations were expected not simply to use technology responsibly, but to demonstrate that they were complying with defined obligations.
That concept would later become important in AI regulation.
THE SECOND GOVERNANCE PROBLEM: CYBERSECURITY
Data protection was not the only governance challenge created by digital technology.
As societies became dependent on interconnected computer systems, another problem became unavoidable:
How do we protect digital infrastructure from malicious activity?
Cybersecurity developed partly as a response to this challenge.
Unlike privacy governance, which focuses heavily on rights and control over information, cybersecurity focuses on protecting systems, networks, data and infrastructure from disruption, misuse and attack.
The two areas increasingly overlap.
A compromised AI system can create privacy risks.
A compromised dataset can affect model behaviour.
A manipulated AI system can create operational risks.
And increasingly capable AI can itself become a tool used in cyber operations.
This means that the relationship between AI governance and cybersecurity is becoming increasingly important.
But the underlying governance lesson is older:
Technology governance must account not only for intended use, but also for misuse.
THE INTERNET GOVERNANCE EXPERIENCE
The development of the internet introduced another important governance problem.
Unlike traditional national infrastructure, the internet was inherently transnational.
Information could move across borders without requiring permission from each government through which it passed.
This created questions about standards, interoperability, infrastructure management, domain names, technical protocols, security and public policy.
Internet governance developed through a mixture of governments, technical organisations, private companies, researchers and civil society.
This multi-stakeholder experience offers an important lesson for AI governance.
Technology governance does not always fit neatly into a government-versus-company model.
Technical communities often possess expertise that governments need.
Companies control important infrastructure.
Researchers develop new technical methods.
Civil society raises questions about rights and social impact.
International institutions provide coordination mechanisms.
AI governance is increasingly developing within a similar multi-actor environment.
THE HUMAN RIGHTS FOUNDATION
Another important foundation of AI governance is human rights.
Modern AI governance did not invent the idea that technology should respect human dignity.
Human rights frameworks had already established principles concerning equality, privacy, freedom of expression, non-discrimination and due process.
As automated decision-making expanded, policymakers and researchers increasingly asked how these existing rights applied to algorithmic systems.
This became particularly important in areas where automated systems could affect people’s lives.
Employment.
Credit.
Education.
Healthcare.
Public benefits.
Law enforcement.
Border control.
Migration.
An AI system does not exist outside society.
If it affects access to opportunities or services, questions of rights and accountability naturally emerge.
This is why human rights became an important foundation for AI governance.
ALGORITHMIC ACCOUNTABILITY EMERGES
As algorithms became more influential, another concept began gaining attention:
Algorithmic accountability.
The basic concern was straightforward.
If an automated system influences an important decision, there should be mechanisms for understanding, challenging and correcting that decision.
This was not necessarily an argument against automation.
Instead, it was an argument for accountability around automation.
That distinction remains important today.
The governance question is not always:
Should AI make this decision?
It can instead be:
Under what conditions should AI be allowed to contribute to this decision?
What oversight should exist?
What evidence should be available?
Who remains responsible?
What happens when the system is wrong?
These questions became increasingly relevant as machine-learning systems became more complex.
THE PROBLEM OF THE BLACK BOX
Traditional software is often programmed using explicit rules.
Modern machine-learning systems can work differently.
A model may learn statistical patterns from large quantities of data rather than relying only on manually specified rules.
This can make certain systems difficult to interpret.
The result is often described using the broader idea of the “black box” problem.
The concern is not simply whether a model works.
It is whether people can understand why it produced a particular output and whether that output can be meaningfully challenged.
This became especially important when AI systems were used in high-impact contexts.
If an AI system recommends a song, limited explainability may be relatively unimportant.
If an AI system contributes to a decision about someone’s employment, healthcare or access to public services, the governance implications are much greater.
This helped push AI governance toward risk-based thinking.
NOT ALL AUTOMATION CREATES THE SAME GOVERNANCE PROBLEM
The history of technology governance also teaches another important lesson:
Context matters.
A technology can create very different governance concerns depending on how it is used.
Consider two hypothetical systems.
One helps a person organise their personal notes.
Another evaluates applicants for employment.
Both may use machine learning.
But their potential social consequences are very different.
The second system can affect people’s economic opportunities.
This is why modern AI governance increasingly considers the context and potential impact of an AI system rather than simply asking whether AI is being used.
THE RISE OF PLATFORM POWER
The expansion of large digital platforms added another layer to technology governance.
Companies operating major online platforms increasingly controlled enormous amounts of data, infrastructure, communication channels and digital services.
This raised questions about competition, market power, content moderation, privacy and social influence.
Governments began examining whether traditional regulatory approaches were sufficient for digital platforms whose operations crossed national borders and whose economic influence extended across multiple sectors.
This experience is highly relevant to AI.
Today’s largest AI companies are not simply software vendors.
Some operate large cloud platforms.
Some control access to advanced computing infrastructure.
Some develop foundation models.
Some provide consumer applications.
Some participate in semiconductor and data-centre ecosystems.
This concentration of technological capability creates governance questions that extend beyond the behaviour of individual AI models.
It raises questions about infrastructure, competition, access and strategic dependence.
AI GOVERNANCE INHERITS THESE LEGACIES
By the time governments began developing dedicated AI governance frameworks, they already had decades of experience in related areas.
They had learned that data requires governance.
They had learned that digital infrastructure requires security.
They had learned that technology can affect fundamental rights.
They had learned that automated systems can create accountability problems.
They had learned that internet technologies require international coordination.
They had learned that private companies can become powerful infrastructure providers.
And they had learned that technology regulation requires technical expertise.
AI governance therefore emerged from an existing governance ecosystem.
It did not replace earlier forms of technology governance.
Instead, it began connecting them.
WHY EXISTING GOVERNANCE IS NOT ALWAYS ENOUGH
If these frameworks already existed, why is dedicated AI governance necessary?
Because modern AI introduces several characteristics that create new challenges.
First, AI systems can operate across a very wide range of applications.
Second, increasingly capable foundation models can be adapted for many different purposes.
Third, AI systems can produce outputs that are difficult to predict in advance.
Fourth, AI capabilities are developing rapidly.
Fifth, AI systems can increasingly interact with external tools and digital environments.
Sixth, AI development is highly concentrated among organisations with substantial computing resources and technical expertise.
And finally, AI systems can affect information environments, labour markets, scientific research, public institutions and national security simultaneously.
These characteristics do not make previous governance frameworks irrelevant.
They make their limitations more visible.
THE SHIFT FROM PRODUCT GOVERNANCE TO SYSTEM GOVERNANCE
This is one of the most important changes in the field.
Traditional technology regulation often focused on individual products or services.
AI increasingly requires thinking about systems.
Consider a modern foundation model.
The model itself is only one component.
Around it are training datasets, computing infrastructure, model developers, evaluation systems, application developers, cloud providers, users and downstream organisations.
A governance failure at one point in this ecosystem can create consequences elsewhere.
This means AI governance increasingly requires lifecycle thinking.
How is the system developed?
What data is used?
How is the model evaluated?
How is it deployed?
Who can access it?
How is it monitored?
What happens after deployment?
How are incidents reported?
Who can intervene?
This is a much broader governance challenge than regulating a single software product.
THE LESSON FROM EARLIER GOVERNANCE SYSTEMS
The history of data protection, cybersecurity, internet governance and algorithmic accountability provides a useful lesson.
Technology governance tends to evolve after technology creates new forms of power, risk or dependency.
Institutions then attempt to catch up.
This process is rarely immediate.
It involves experimentation, disagreement, institutional learning and sometimes regulatory failure.
AI governance is now going through a similar process, but the speed of technological development is much faster.
That creates pressure on institutions to learn more quickly.
The question is therefore not whether governments can create a perfect AI governance framework immediately.
The more realistic question is whether governance institutions can develop the capacity to continuously adapt as AI systems evolve.
FROM STATIC RULES TO ADAPTIVE GOVERNANCE
This may become one of the defining characteristics of AI governance.
Traditional regulation often assumes that the regulated technology changes relatively slowly.
AI challenges that assumption.
A model released today may have capabilities that differ substantially from systems available several years earlier.
New applications can emerge quickly.
New risks can appear after deployment.
New technical evaluation methods can become available.
As a result, governance may increasingly require mechanisms for continuous monitoring and adaptation.
This does not necessarily mean constantly changing laws.
It can also involve standards, technical guidance, reporting frameworks, evaluations, regulatory sandboxes and institutional learning.
The goal is to create a governance system that can evolve without becoming unstable.
THE PATH TOWARD MODERN AI GOVERNANCE
The historical path can now be seen more clearly.
Data protection established principles for controlling the use of personal information.
Cybersecurity established practices for protecting digital systems.
Human rights frameworks established protections for individuals.
Internet governance demonstrated the importance of international and multi-stakeholder coordination.
Algorithmic accountability raised questions about automated decision-making.
Digital platform regulation highlighted the challenges created by concentrated technological and economic power.
AI governance brings these strands together while confronting new challenges created by increasingly capable and general-purpose systems.
This explains why modern AI governance is such a broad field.
It is not simply a new branch of technology regulation.
It is increasingly becoming a meeting point between technology policy, human rights, economic policy, security, competition, development and international relations.
WHAT THIS HISTORY MEANS FOR THE FUTURE
Understanding this history changes how we think about the future.
AI governance should not be treated as a completely new experiment.
It is part of a much longer process through which societies attempt to adapt institutions to technological change.
But AI also introduces something different.
The technology is increasingly capable of performing tasks associated with human reasoning, communication, analysis and decision-making.
That creates governance challenges that cannot always be solved by simply applying older frameworks.
The future will therefore likely involve both continuity and change.
Existing principles around privacy, human rights, security and accountability will remain important.
But they will need to be adapted to increasingly capable AI systems.
THE CENTRAL LESSON
The history of technology governance teaches a simple but important lesson:
Technology can change faster than institutions.
When that happens, governance gaps emerge.
Those gaps can create uncertainty for governments, companies and citizens.
The challenge is therefore not to stop technological change.
It is to build institutions capable of understanding and responding to it.
AI governance represents the latest stage of that process.
Its foundations were built through decades of experience with data, privacy, cybersecurity, internet governance, human rights and algorithmic accountability.
The next challenge is to determine whether these foundations are sufficient for the age of foundation models, frontier AI and increasingly autonomous systems.
CONCLUSION
AI governance did not begin with the first AI regulation.
It emerged from a much longer history.
Societies had already spent decades learning how to govern information, protect privacy, secure digital infrastructure, protect fundamental rights and hold automated systems accountable.
Those experiences created the foundations upon which modern AI governance is being built.
But today’s AI systems are testing those foundations in new ways.
The technology is increasingly general-purpose.
Its capabilities are advancing rapidly.
Its infrastructure is becoming strategically important.
Its applications are spreading across sectors.
And its effects can cross borders almost instantly.
This means the next generation of AI governance will have to combine lessons from the past with institutions capable of responding to technologies that are changing at unprecedented speed.
The question is no longer simply how to regulate a new technology.
It is how to build governance systems that can evolve alongside it.
ATLAS AI GOVERNANCE SERIES
This article is Part 2 of the Atlas AI Governance Series:
“From Principles to Power: The Evolution of AI Governance.”
Part 1 examined what AI governance is and why it has become increasingly important.
Part 2 traced the historical foundations of AI governance through data protection, cybersecurity, internet governance, human rights and algorithmic accountability.
The next article will examine a major turning point:
Why did AI governance become an international policy priority during the 2010s—and what changed when artificial intelligence moved from specialised applications toward increasingly capable general-purpose systems?