Every member of the G20 has endorsed the Carolina Principles for Emerging Technologies, a US-backed framework that steers governments away from creating dedicated artificial intelligence regulators and toward applying existing sector-specific law instead. The non-binding principles were adopted in a consensus statement released on 2 September 2026, following the G20 Innovation Ministerial held in Chapel Hill, North Carolina — and reporting indicates China signed on alongside the United States and the European Union.
The ministerial was co-hosted by White House Office of Science and Technology Policy Director Michael Kratsios and Commerce Secretary Howard Lutnick, convening ministers, technology executives and AI policy advisers from 1 September.
What the Principles Say
The framework's organising idea is restraint by default. Countries agree to reserve new regulation for genuinely novel considerations rather than treating each new AI capability as a distinct policy problem requiring bespoke rules.
In practice, the ministers committed to a set of positions that will shape national legislation over the coming years:
- Focus new regulation on novel issues that existing legal frameworks cannot address, rather than duplicating protections already on the books.
- Scope any new rules narrowly to identified gaps.
- Invest in foundational research and strengthen commercialisation pathways from laboratory to market.
- Enable trusted technology adoption and deployment rather than restricting it pre-emptively.
The broader Innovation Ministerial Statement spans six pillars: pro-innovation policy frameworks; technology for opportunity and prosperity; skilled technical workforce development; intellectual property policies for AI; AI for standards and standards for AI; and industrial innovation and supply-chain investment.
A White House official said the United States would press members not to establish new regulatory organisations to oversee AI development — the sharpest edge of the American position and the point on which the framework most directly diverges from the European approach. The proposal was also backed by video appearances from technology executives including Mark Zuckerberg and Elon Musk.
The Institutional Argument
The dispute at the heart of the Carolina Principles is not really about whether AI should be regulated. It is about who regulates it.
The US position holds that AI is a general-purpose technology applied within domains that already have regulators — medicine, aviation, finance, employment, consumer protection — and that those bodies possess the sectoral expertise to evaluate AI systems in context. Creating a horizontal AI authority, on this view, duplicates capacity, invites jurisdictional conflict and produces rules that fit no sector well.
The counterargument, which underpins the EU's approach, is that certain risks are properties of the technology itself rather than of any single application, and that no sectoral regulator has a mandate to examine frontier model development, systemic capability jumps or cross-domain misuse. The EU has been building institutional capacity precisely to enforce the AI Act, and the Carolina Principles run against that grain.
Why It Matters
A non-binding framework with 20 signatures is more consequential than it sounds. Nothing in the Carolina Principles compels any government to do anything. But international consensus statements function as legislative cover. A minister facing domestic pressure to establish an AI authority can now point to a G20 position — endorsed unanimously, including by China — recommending against exactly that. The framework's real force is in the arguments it makes available to legislators who were already inclined to wait.
The unanimity is genuinely notable. AI governance has been one of the more fractured areas of international technology policy, with the EU, US and China pursuing visibly different philosophies. That all three could sign the same text says something about how the document is constructed: broad enough in its language that each can read its own approach into it, and non-binding enough that signing costs nothing.
That flexibility is also the framework's principal weakness as an instrument of actual coordination. "Reserve new regulation for novel considerations" is a principle every regulator would claim to follow already. The disagreement has always been over which considerations count as novel — and the Carolina Principles do not resolve it.
The Timing Question
The endorsement lands in an awkward week. Days before the statement, OpenAI disclosed that its forthcoming Astra model had crossed the Critical cybersecurity capability threshold in the company's own internal framework — the first time a leading laboratory has judged one of its models capable of autonomously discovering and exploiting security flaws in hardened systems. That judgement was made internally, evaluated internally, and mitigated internally, with no binding external review.
Whatever one's view on standing AI regulators, that sequence is a fair illustration of the gap the Carolina Principles leave open. Financial regulators do not defer to banks on capital adequacy self-assessment. Under a purely sectoral model, it is unclear which existing authority is equipped to independently verify a frontier capability claim of that kind, or would have standing to act on it.
For businesses, the near-term implication is a widening regulatory divergence rather than a narrowing one. The EU AI Act's obligations remain in force regardless of what was agreed in Chapel Hill, and multinational deployments will continue to be governed by the strictest applicable regime. Compliance teams should treat the Carolina Principles as a signal about the direction of US and allied policy, not as a relaxation of any obligation currently on the books.
