AI governance did not happen.
(not what you think)
In 2025, the most consequential AI governance did not come from regulators, CEOs, or safety summits.
Across UN General Assembly side events, AI safety summits, and global forums, what was presented as “AI governance” was largely procedural alignment: shared language, voluntary commitments, principles without enforcement.
These spaces produced coordination, not constraint.
If governance is defined as the capacity to impose real limits on power, then what we currently label as AI governance is, in practice, not governance at all.
Governance should be evaluated by whether systems were actually constrained, delayed, altered, or made costly to deploy.
By that standard, most institutional governance over the past year failed.
Where AI systems were actually constrained, it was never because of summit-level governance. What emerged instead was a pattern that cuts across geographies and sectors: governance did not disappear, it moved. Core governance functions migrated away from institutions with mandate and resources onto people and communities with the least protection.
It is displaced AI governance: governance functions pushed to the margins because institutions failed to act. Or in other words, institutions outsourcing governance downward, while retaining legitimacy upward.
Where AI governance actually happened in 2025
Accountability under grief
Bereaved parents and families confronting recommender systems, addictive engagement design, AI-mediated chat companions, after documented harm and deaths.
Litigation, disclosure demands, public pressure substituting for absent regulation in cases of youth self-harm and algorithmic amplification (US, UK, EU)
→ Governance function: enforcement and liability creation without mandate.

2. Legal pressure without protection
Strategic litigation targeting AI deployment (e.g. ICCL GDPR complaint against Microsoft Ireland alleging processing linked to civilian harm in Gaza, mass surveillance, and apartheid conditions) and platform responsibility, without institutional or political backing, and high personal and financial risk for plaintiffs.
→ Governance function: jurisprudence creation in advance of regulation.
3. Labor as a governance brake
Tech worker unions and collectives refusing participation in AI used for warfare, surveillance, and occupation
Internal disruption of deployment pipelines, including No Tech for Apartheid campaigns
Upstream labor organizing by data workers, including the Data Labelers Association of Kenya, exposing conditions embedded in AI supply chains
→ Governance function: operational veto power inside institutions
4. Refusal as regulation
Community opposition to data centers and compute infrastructure over water, land, and energy extraction
Indigenous and local resistance re-framing AI expansion as environmental and territorial governance (e.g. The Anacé Indigenous community is going to court to stop a planned TikTok data center they say is being built on their land)
Arizona community organizing halting a large data center project over water concerns
→ Governance function: consent, scarcity, and boundary-setting where law fails

5. Counter-documentation and harm mapping
Digital rights organizations documenting surveillance, censorship, and data exploitation where legal recourse blocked, eg. 7amleh’s documentation of digital repression affecting Palestinians under occupation
Investigative journalism exposing AI-enabled military and surveillance infrastructure, including Microsoft cloud services used by the Israeli military
→ Governance function: truth-production and record-keeping under conditions of impunity
6. Norm-setting ahead of law
Artists’ collectives and cultural workers asserting limits on data use, training, and authorship
Collective refusal and legal action preceding enforceable copyright reform
AI Creator Coalition and related initiatives establishing consent and attribution norms before regulatory adaptation
→ Governance function: social constraint before legal constraint
7. Prefigurative governance experiments
Trans-disciplinary collectives operating outside institutional mandates, Spaces such as the Ethical AI Alliance bringing technologists, lawyers, artists, and affected communities into shared governance experimentation
Ethical boundary-setting and accountability mechanisms tested through practice rather than policy or formal authority
→ Governance function: model-building for future institutionalization

8. Moral injury absorption
Communities, activists, and workers carrying psychological, legal, and safety costs of doing governance work the state refuses to do.
→ Governance function: risk absorption displaced downward
9. Cultural refusal and revaluation
Beyond courts, unions, and rights organizations, a quieter form of governance is emerging as public withdraws legitimacy from AI systems that intrude on intimacy, creativity, and care
Growing rejection of AI-mediated intimacy, creativity, and care
Resurgence of human-only spaces, analog practices, embodied experiences
Public resistance to algorithmic substitution of meaning
→ Governance function: legitimacy withdrawal
A consistent pattern:
This is not an exhaustive account.
It does not need to be.
The actors doing the most consequential AI governance in 2025 were the least protected, least funded, and least recognized.
Bereaved families, workers, artists, communities under occupation, and under-resourced NGOs absorbed legal risk, financial strain, political retaliation, and moral injury.
Meanwhile, institutions with formal authority largely produced symbolic outputs.
We are relying on grief, precarity, and exposure to compensate for institutional failure.
A different way to measure governance
If we continue to measure AI governance by summits convened, frameworks published, or stakeholders consulted, we will keep misreading reality.
Governance should be assessed by outcomes:
Did deployment slow, halt, or change?
Did system design alter in response to harm?
Did deployers absorb real cost?
Did affected communities gain leverage they previously lacked?
Did legitimacy withdraw in ways that mattered?
Did constraints persist beyond the controversy?
If none of this occurred, governance did not happen.
What 2025 actually tells us
If AI governance is defined as the ability to impose real constraints on power, then most of what we labeled AI governance in 2025 was not governance at all.
Most real governance occurred outside the institutions designed to perform it.
If AI governance did not alter deployment, design, or power, it did not happen.
Funding followed those producing alignment, not those imposing constraint.
The rest was alignment.
This will matter more in 2026.
~Asma


This lands because it restores the correct test for governance. Governance is not language alignment or principle formation. Governance exists only when power encounters friction. If AI systems are not slowed, gated, altered, or made more expensive to deploy, then governance has not occurred. By that standard, most institutional activity labeled “AI governance” in 2025 is coordination theater, not control.
What you surface clearly is a structural failure mode. When institutions avoid constraint, governance does not vanish. It displaces. Enforcement, liability creation, consent withdrawal, and legitimacy challenges migrate downward to those with the least protection and the highest personal cost. Grief, labor refusal, litigation, and community resistance become substitute braking systems inside an ungoverned deployment engine.
From a governance architecture perspective, this is not resilience. It is leakage. These actors are performing governance functions without authority, budget, or safety nets. That creates real friction, but it also externalizes cost and moral injury. Sustainable governance cannot rely on sacrifice. It must be engineered.
The missing layer is institutionalized checkpoint governance. Bottom-up constraint signals must be translated into mandatory deployment gates, human arbitration points, and measurable cost internalization upstream. Until friction is codified inside systems and organizations, governance remains episodic and extractive rather than durable.
This piece matters because it forces a reset in how governance success is measured. If legitimacy is not withdrawn, deployment is not altered, and deployers do not absorb cost, governance did not happen. Everything else is alignment.
Great rundown, and it’s honestly such a tragedy that so much responsibility (and preventable harm) has been pushed down to the end user and humanity in general. It’s going to be interesting to see how 2026 plays out. I’m tagging 2026 as the year of the AI hangover. I guess the positive is that AI accelerated the process. Rather than having to wait decades to start to see the fallout it took less than a couple years.