Go back

Cindy Parokkil On Bridging AI Policy And Standards

32m 47s

Cindy Parokkil On Bridging AI Policy And Standards

In this episode of *AI Standards Stack*, hosts Michael Minnelli and Adam Smith interview Cindy Paracill, ISO’s AI policy lead. Paracill explains that her career began at the UN, where she saw standards as powerful tools for trade, innovation, and regulatory cooperation. Now at ISO, she emphasizes that standards bridge the gap between AI policy ambitions (e.g., from the OECD or UN) and practical implementation by providing risk management frameworks, terminology, and processes. She highlights the 2024 Seoul Statement, which affirms that international standards organizations must engage with AI governance questions around socio-technical design, human rights, multi-stakeholder collaboration, and capacity building. Paracill notes that this statement has been well received and prompts internal reflection within the standards community. She also describes a capacity-building workshop in Singapore, where 15 countries—including developed and developing nations—sent pairs from national standards bodies and government ministries to learn how standards can support AI policy. This initiative aims to demystify the standards development process and encourage broader participation, particularly from the Global South. Paracill stresses that multi-stakeholder collaboration is essential for AI standards to remain relevant for industry, regulators, and society, even as it adds complexity. Overall, she positions ISO as a key partner in the global AI governance ecosystem, helping turn policy into practice.

Transcription

4898 Words, 28638 Characters

English
Welcome to the AI standards stack with me, Michael Minnelli, director at Ziann Group. And me, Adam Smith, chair of the AIQI consortium. Each episode on AI standards stack, we discuss developments in AI assurance with guests from around the world that are leading the charge on the standards, ethics and regulation of AI. On the show today, we're joined by Cindy Paracill, who leads ISO standards and public policy program and serves as ISO's AI policy lead. She's also vice chair of the AI multimedia authenticity standards working group and was program lead for the 2025 international AI standards summit. In her current role, she leads ISO strategic engagement with the international AI policy ecosystem, collaborating with global organizations and policy forums to ensure coherence between international standards and emerging AI policy frameworks. Well, welcome to the show, Cindy. It's a pleasure to have you on. Before we unpack the stack, it'd be nice if you just maybe gave the audience a flavor about what led you to the exciting world of ISO standards. Thank you so much for having me, Michael and Adam. It's a real pleasure to join you today about a conversation on standards and AI policy. Many roads sort of led to where I am at this point in time with ISO. I started off my career at the UN, working on trade capacity building and development, which is where I first came across quality infrastructure and standards and understood that it is a very important part of, you know, facilitating trade enabling market access. So I wanted to learn more and that's where my journey began and I was first with BSI, the British standards institution. And now I'm here at ISO. Oh, fantastic. Now, you know, career is an economist because you trained at Oxford, is that right? Yes. And then in Africa with Unito and now ISO, you know, how did you actually get into standards, Cindy? So what really drives me is solving real life problems. And through my work, what I quickly realized is that standards are really powerful tools. They're versatile and they can help a wide range of stakeholders solve very concrete problems. But they're also one of our best kept secrets. And I think more people need to know about standards and the value they carry, which is how I, which is how I entered the space and I am doing work with regards to that. So, you know, particularly you mentioned my work in development and in Africa. And through the work I've been doing, what I saw is how powerful standards can be in, in terms of very practical things like facilitating trade, literally moving a product across the market, across the border. How standards can support innovation, regulatory cooperation. And, you know, from a developing country perspective, how it can really help them participate in global markets. So I really see standards at this intersection between policy markets and implementation. And that's what really made me want to go deeper into this world and see how stakeholders such as governments can really leverage standards to help provide clarity and go from, you know, policy ambition to practical implementation. That's great. You know, the kind of the passion here behind the power of standards to do beneficial things. Really, really good. Well, you're at ISO now, which of course is in some quarters, you know, sort of the pinnacle of all of this. And it's best known as a technical standards body. But your role is explicitly about policy engagement. So how do you describe I saw this place in the broader AI governance conversation alongside the bodies you mentioned earlier, you know, regulators, governments, industry, bodies like the OECD or the UN. You know, where do you think ISO's influence is most felt? We're seeing a lot of recognition on the role of standards in global digital conversation, global digital governance conversations, international standards, you know, are reflected in discussions around the global global digital compact. And so on, there is significant awareness on the importance of standards. But when we think about AI governance, I think of it in a very layered manner, it is very much a layered ecosystem. So at the one level, we have international law, soft law, national legislation, regulatory guidance and policy frameworks. And this is very important because that sets out the principles, the expectations, the direction. So what governments and societies expect from AI systems. But organizations still need to understand what those requirements mean in practice. They need the tools, the processes, the terminology, the risk management frameworks, the management systems to help them deploy and use AI safely and responsibility. And standards help fill that gap. So when I describe ISO's place in the AI governance landscape, I would say we help bridge policy ambition with practical implementation. The relationship between regulators, governments and standards is something I find fascinating. And I've seen quite a few different models and this is not an exhaustive list. But one example, I can think of is in medical devices where governments got together and aligned the differences in their regulation in order to enable ISO to come up with a global standard. Another model is of course the European model where the regulators ask for specific standards to be written. But there's also other models. So I'm thinking in AI when the OECD got together and came up with a, I guess, I can't remember what exactly what it was called, but it was a piece of work around incidents. They then brought that to ISO IEC and said, can you finish this off, integrate it with your other standards and publish it as an ISO IEC standard? And then there's also the kind of more implicit model in that courts and regulators will usually defer to a technical document where a group of experts have reached consensus. I'm sure that's not exhaustive, but those different models are really, really interesting to me. Absolutely. And I think that is the value of having governments, international organizations and other stakeholders participate and engage with our system because you know when there is a need in the market and that is being identified, bringing that to ISO or IEC and sort of using that as a backbone to create a solution is how we can help markets. And that is something that we offer and we very much welcome engagement and participation by international organizations and governments and civil society and all the stakeholders that are impacted by AI. Cindy, you last year there was a big accord, a joint statement in Seoul and there were four commitments around AI and they covered socio-technical approaches, human rights, multi-stakeholder collaboration and capacity building for big areas. I was wondering if you could tell us what's the importance of that statement, what does it mean in practice? In a minute maybe we could go briefly through those four areas if you wouldn't mind, but why is that a statement an important one? So the Seoul statement was launched by IEC ISO and ITU at the International AI Standard Summit last year in December and it presents an important reflection based on several years of engagement with the broader AI policy ecosystem. So there's been a lot of momentum in this space. We saw the AI with trust conference in 2022, which helped bring together standards and policy conversation. We've seen the Council of Europe's framework convention on AI adopted in May 2024 and it's non-binding framework called Hedaria. We have seen the global digital compact adopted in September 2024. We've seen a lot of important work by the partnership on AI on transparency and AI and also work by the OHC HR outlining their views on the relationship between technical standards and human rights. So the Seoul statement built on that context. There have been a lot of questions that have been put to the standards community on how standards fit within the AI policy framework. So the statement in a way signals that the standards community is very much engaging with the policy facing AI governance questions such as, you know, are the standards we develop socio-technical in nature? What is the relationship between voluntary standards and human rights and law at large? In our standards development, our all voices heard the multi-state-holder collaboration aspect. And, you know, how do standards work in practice? It's great to say that standards are there. They help solve problems, but how do standards work in practice? So this is some of the rationale why we decided to put out our position, our statement, basically saying we hear these questions. We understand these are important. You know, we don't have the solution, we don't have the answer to all the questions and we are, you know, collectively looking at responding to these needs. I should note that the sole statement has been very well received by UN agencies, international organizations, development banks, policy makers, media. And it's really reinforced or helped reinforce the idea that international standard organizations should be partners at the table when AI governance is discussed. And it was also great to see that the AI standards summit that was organized by BSI and PL, UKAS and the Alan Charing Institute held in Glasgow this year in March also use the sole statement as a common threat throughout the event. And maybe what I can also just say is the sole statement is also being discussed within the technical community. It is important to keep in mind that it is not just an external communication tool. It really invites internal reflection. It asks, you know, are we doing enough to respond to the needs that are raised by our stakeholders, governments, regulators, civil society, industry and users, you know, are our standards responding to those needs. If yes, great. Is there anything that we need to do going further? If so, what and who should we partner with? So these are some of the questions that we're grappling with. Well, we've got a lot of other questions to tend to, but first just over to Adam and then I would like to briefly, briefly walk through those four areas. Yeah, just have to reiterate the importance of this and then you know, confirm that that internal reflection is happening in a technical standards community. Yeah, the inclusive participation and the multi stakeholder collaboration is what makes standards progress faster and makes them gets adopted more widely, so it's crucial human rights and societal concerns have been on our mind since the very first work in the AI committee and I see so. Over the years, we've written about them quite a lot, but of course there are limitations on what we can do in ISO IEC and even in Europe, we did a podcast recently with James Geely, who's been working on integrating fundamental rights, recall them in Europe into technical standards. And while we manage to do some great things, like take the definition of harm from product safety and incorporate not just harm to health and safety, but harm to human rights, we haven't been able to go much further than that in a technical way because it quickly becomes very complex and legal and stuff to rely on case laws and things like that. So let's just have a quick look if we could at those four areas and I know they're quite extensive and exhausted, so we don't need to go through the ball, but I just some of these are quite abstract concepts, you know, sociotechnical approaches. So, you know, what sort of what sort of progress has been made on that. And sometimes of the first commitment on social technical, it really is about the idea that outcomes depend on the interaction between social and technical elements, rather than the technical design alone. Within, you know, as Adam said, ISO and IEC standards have long accounted for these dimensions, but these are questions that we are getting and what this whole statement tries to do is invite this precise reflection on whether the current practices systematically captures the social technical dimension. Then on the second one, the second commitment, which is about understanding the interplay between standards and human rights and the word interplay there is chosen very carefully because it's really about differentiating what voluntary standards can do and what legally binding laws can do and how the two interact, you know, we as STOs, we don't define human rights. And we have a responsibility lies with the legislator courts and the competent public authorities. But our, you know, what are standards do very often say is understand the legal context in which you operate you as an organization operating. So, you know, is that enough, you know, stating that in the standard or or do we need to do anything else so that our standards can help organizations that wish to demonstrate compliance with their human rights obligations should, you know, should they wish to do so. We need to do anything else there so it's really reflecting the it's really calling for reflection on these important topics and understanding how far standards can go and, you know, where they can't offer a solution. Well, I think that was really helpful in kind of just giving people a flavor of what these commitments are. I think we kind of get the multi stake hole that our collaboration as well that's come across strongly, but maybe you just would like to finish with a remark or two on capacity building. So in terms of capacity building, that's a very important commitment to make sure that we deliver standards that meet the needs of the market and the stakeholders that we serve. And in terms of capacity building, there are two signs to it, there's capacity sides to it, there's capacity building internal to our organization. So this is getting, you know, bringing different perspectives to the standards development table, be it, you know, human rights perspective, government perspective, so that that can be. Considered in an effective manner and external to our organizations it's helping the private sector and the public sector understand how standards can really complement legislation policies and assurance mechanism and also explaining to them how they can contribute effectively to standards development. So capacity building has two sides to it now my work and standards hasn't been as exciting as yours because we're about to move from soul to Singapore and I just I just admiring your travel schedule here. Before we do so we're going to have a little rehearsal more for me than for you, I can assure you. I'll say ISO IEC JTC one SC 42 plenary. Could you unpack that please for the audience then we'll move into the question itself. What is the ISO IEC JTC one SC 42? That is definitely a mouthful that is our technical committee that develops standards for AI. So that's where all the AI magic happens. That's great. So we can call it SC 42 right perfect. Okay, so you had a big plenary in Singapore. What what people doing there why were they there why did ISO bring them to Singapore and what did they achieve. So I mean the the plenary meeting and the technical meetings is is where the experts the technical experts come together from all the different countries and you know develop the standards and address the issues that are at hand. So I think from the work that I do that ISO with regards to policy engagement I brought a group of 15 countries. So this is around 30 representatives to the SC 42 plenary with the primary goal of connecting policy and standards the policy and standards community. About 15 countries we deliberately brought a mix of developed and developing countries because AI governance is not only a concern for one region on every country is grappling with how to govern it and each national delegation had two representatives a national standards body representative and a senior government representative responsible for AI so this could be a regulator or someone from the Ministry of ICT. And we brought them together because you know pulling their unique knowledge and skill sets the aim is the aim was to encourage collaboration between these stakeholders at the national level to help government solve policy challenges that they are grappling with. We brought them to Singapore because we wanted them to see how standards can help achieve national policy objectives and how they can also contribute to shaping those standards. So this has been work that we're doing this is part of a wider program that we're running a capacity building journey which started last July at AI for good and the first workshop was held along said AI for good where amand deep single for the under secretary get a general launch the capacity building journey. The second stage was at the international AI standards summit where the delegates you know really engaged with the sole statement and reflected on the role of international standards and AI governance and this last workshop in Singapore was really focused on showing how ISO and I see standards are actually developed and this really matters because. The countries you know see that they can actually shape and influence the development of standards and provide some of that opportunity to understand the system more. Committee 42 because we have the answer to everything if you don't mind me. dropping in at the bus havens. - Absolutely. - Refrigerator there. But one of the interesting things I think about the committee is the growth in the participation from developing countries over the past couple of years. I mean, obviously we don't have everybody. I think there's 86 countries participating in SC42 out of 177 ISO members, but it's been really good to see that growth and start to see more and more particularly global South countries join over the last few years. And I think that's an example of the sort of thing that this capacity building work really, really helps with. - Well, I love the Douglas Adams reference and deep thought, which we've definitely seen deep being used a few times in this sector. Cindy, could you just add just a tiny bit of color? I'm not asking you to do all 15, but could you name some of the larger nations that were there and some of the other nations who were trying to look at capacities off the top of your head? - So as I mentioned, it's a mix of developed and developing countries. So we have the UK. There, Canada, the Netherlands, Brazil, Uganda, South Africa, Malaysia, Indonesia, Saudi Arabia, the Bahamas. So we have a broad mix of countries at different levels of development who are all very interested in how standards can help solve their AI governance challenges. - Great, now just a bit of color there. Thank you. That helps to hear some of them. Now standardization has often been led by industry. In many cases, in fact, in a number of cases, people see that as an enormous benefit. Industry moves at the pace that it needs, or close to it anyway, to deliver a standard that is shaped by a group of stakeholders and all that. But here you are pushing very hard for multi-stakeholder collaboration, government, civil society, human rights. All this sounds very good, and I'm not trying to denigrate it, but on the other hand, one says, oh my gosh, are we trying to boil the ocean? Are we trying to bring all these issues to the table? And therefore not going to move forward. So where do you fall on that, I guess, of a pendulum, really? - No, that's a very good question. And I think, you know, opening up AI standardization is essential because AI standards must be relevant not only for industry, but also for public policy, for society, and the people affected by AI systems. So if standards are going to support AI governance, then they need to be useful for different market actors and governance actors. And, you know, I also want to emphasize that this is not something new. Multi-stakeholder collaboration is something that we really want across the board. The more views we have at the table, the better standards we can create. Yes, it might be more complex, but that makes the standard better at the end of the day. And, you know, governments and regulators, they bring an understanding of the public policy objectives. They can help ensure that standards are relevant to regulatory needs or national strategies can be used in procurement policies. And at the end of the day, we want these standards to be used. Industry brings, you know, practical insights into real-world use cases, implementation constraints, technical feasibility, and so on. Their perspective is also very important. Academia brings, you know, research expertise, civil society brings perspectives on the societal impacts and these perspectives also need to be heard in the standards-making process. And, you know, the more perspectives are represented, the more relevant and legitimate the standards become. And this is also what we really emphasize in the sole statement, just going back to that. We AI or technology takes a social technical approach, and that cannot happen if only technical experts are in the room. So we need these other perspectives to be there, who maybe have a better understanding in the legal context, in the institutional setup, in the social impact, and the human dimension. So it's really having those different perspectives around the table. And there are many, I can give you a few examples of the real-life value of having these various stakeholders as well, but perhaps we can come to that. Go ahead. Let's have one, let it be useful. I think maybe just also starting with the UK. I think the UK AI standards hub is a great initiative in that it tries to really bring together the various stakeholders that are impacted by AI. And it also helps to demystify the standards landscape and supports more informed participation. So it's not just about increased participation, but it's also helping wider stakeholders understand like the value of standards and how standards can help them. Another example I can give is the case of Malaysia. The Malaysian government, as part of the capacity building work that we're running, has been part of the capacity building journey and is very exposed to the value of standards together with the National Standards Body in Malaysia. And as a result of participating in this work, the government launched a whole new initiative on AI standards. And this was an outcome of the collaboration between the government and the National Standards Body. And what it does is position international standards as the operational foundation for AI governance in the country. And this is a good example of what happens when the right actors are connected around a shared goal and what they can do nationally to help achieve AI governance goals. I totally agree. And I think we're certainly at a peak of concern about how technology, especially AI, can impact societies and cause also ethical concerns. I think it's absolutely crucial that trade unions, consumers, and all sorts of other relevant interest groups are enabled to come to the table. That doesn't mean that we should centrally make sure they all come to the table. That means we need to create pathways and tools and enable them. There's also well-documented concerns about the dominance of certain industry groups within international AI standards. So it's really important that we make sure that we're inclusive and create those pathways. For other views, as well as ensure that industrial groups from different countries and sectors enable to join as well. And if I may just come in on that just to add, Adam mentioned our membership, 177 National Standards Buddies. And I really want to highlight how important their role is in making sure that these voices are at the table because at the end of the day, at the national level, all these stakeholders can participate in the international standardization system through the national standards body. And that stakeholder engagement is very important to creating these standards. Now, this is sort of a question for both Cindy and Adam before we move to the final question. I do a lot of work, for example, in the space sector. And the space sector's best model is actually the maritime sector. There are just so many crossovers between the two sectors. It's almost uncanny. When you look at standards-- and SE42 is one of many SEs-- is there a particular-- another SE or another standard sector that you often look at and say, that's actually a pretty good model or a good analog for what we're doing here in SE42? Yes, actually. So I'd say in international standards, often we look at cybersecurity. So you'll see a lot of similarities between IEC 42, 2001 and IEC 27,01 for information security. And I'd say to European level, because it's a completely different approach to regulation, I think the medical device sector is probably the closest. Cindy, any thoughts from you? Nothing more to add to that than what Adam said. Well, time is ever is pressing. So I'm just going to move on to the final question area. IEC has been investing in capacity building for governments and standards bodies on AI. And you've seen-- you've been linking that work with practical training around 42,001 and 42,005. And this is really kind of a question for beginners. You've emphasized in this conversation quite rightly the importance of capacity building across the board. I really see where you're coming from there. I really admire that. But for an organization or a country that's just starting to engage with AI standards, what's the most important first step? What's the biggest barrier you see to uptake? How can ISO or AI quality infrastructure somebody help them? I would say the first step is to really understand the value proposition of standards. I mean, we know standards can help enable market access, enable regulatory cooperation, help with intrapability, build trust, and so on. Standards can help organizations understand what good looks like in practice. But what is equally important to understand is what standards are. standards cannot do. You know, standards are not law. They also don't solve every governance problem by themselves, but standards interact with, you know, other tools. So it's really understanding the context in which the organization operates. I think it's having clarity on what is the governance problem you as an organization or country is trying to solve, and then identifying which standards can help. But that also comes to one of the big barriers that I see often people talk about. They don't really know where to start. The standards landscape can look very complex from the outset. And as you said, you know, we have many acronyms and numbers. That, you know, may not be very intuitive for someone. So it seems often I hear from engagement that someone might be trying to look, trying to solve a very practical problem and look at standards. And they feel like they have to learn a whole new language before they can even begin to address that. And that is that is a barrier. So it's about us as a community trying to provide clarity on how the standards work together. You know, where to start, you know, based on your level of development, what, you know, what can you do. And then it's really practical training. We reference the AI QI 42,001 and 42,005 standards in the capacity building work that we're doing. And the feedback that we got is that the training was very practical and helped stakeholders understand more than, you know, the standard is important, but get into the details and understand how they could use it in within their context. So training is essential, but it's understanding what you're trying to solve. What is the governance challenge? What standards can help? And then really like figuring out the details. And I cannot, I cannot help but interject and remind the listeners that the AI QI training that Cindy just references available on a IQI dot org and is free to all. And that's great. And Cindy, I think you've done a really great job of reminding us, particularly on that answer to the final question. The importance of keeping your eye on the value proposition. Hold on to that. That's probably one of the key things to do. Well, I'm afraid we have sadly outrun out of time, but we really want to thank you, Cindy, for sharing your valuable insights today. I'd like to also thank my co-host, Adam Leon Smith, and most importantly, all of you listening to this program. So join us next time for when we try to cover the full stack of AI standards, ethics and regulation. Thank you very much.

Podcast Summary

Key Points:

  1. Cindy Paracill leads ISO’s AI policy engagement, bridging standards with global governance frameworks like the UN and OECD.
  2. ISO standards translate high-level AI policy principles (e.g., safety, human rights) into practical tools for organizations.
  3. The 2024 Seoul Statement, issued by IEC, ISO, and ITU, signals the standards community’s commitment to socio-technical approaches, human rights, multi-stakeholder collaboration, and capacity building.
  4. ISO’s SC 42 technical committee develops AI standards, with growing participation from developing countries to ensure global relevance.
  5. A capacity-building program in Singapore brought together 15 countries (e.g., UK, Brazil, Uganda) to connect policy officials with standards experts, fostering national-level collaboration.

Summary:

In this episode of *AI Standards Stack*, hosts Michael Minnelli and Adam Smith interview Cindy Paracill, ISO’s AI policy lead. Paracill explains that her career began at the UN, where she saw standards as powerful tools for trade, innovation, and regulatory cooperation. , from the OECD or UN) and practical implementation by providing risk management frameworks, terminology, and processes.

She highlights the 2024 Seoul Statement, which affirms that international standards organizations must engage with AI governance questions around socio-technical design, human rights, multi-stakeholder collaboration, and capacity building. Paracill notes that this statement has been well received and prompts internal reflection within the standards community. She also describes a capacity-building workshop in Singapore, where 15 countries—including developed and developing nations—sent pairs from national standards bodies and government ministries to learn how standards can support AI policy.

This initiative aims to demystify the standards development process and encourage broader participation, particularly from the Global South. Paracill stresses that multi-stakeholder collaboration is essential for AI standards to remain relevant for industry, regulators, and society, even as it adds complexity. Overall, she positions ISO as a key partner in the global AI governance ecosystem, helping turn policy into practice.

FAQs

ISO helps bridge policy ambition with practical implementation by providing tools, processes, and frameworks for safe and responsible AI use.

The Seoul statement, launched by IEC, ISO, and ITU, signals the standards community's engagement with AI governance questions like socio-technical approaches and human rights, reinforcing standards as key partners in AI discussions.

The commitments cover socio-technical approaches, understanding the interplay between standards and human rights, multi-stakeholder collaboration, and capacity building.

SC 42 is the technical committee that develops AI standards, where experts from various countries collaborate to address technical and policy issues.

The workshop aimed to connect policy and standards communities, showing how standards can achieve national policy objectives and how countries can shape their development.

It ensures AI standards are relevant for industry, public policy, and society, incorporating diverse perspectives from governments, civil society, and others.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.