The Governance Gap

As artificial intelligence reshapes industries, governments, and daily life, a troubling pattern has emerged: the countries with the most sophisticated AI governance frameworks are the ones that need them least. The EU's AI Act, the UK's AI Safety Institute, and the US executive orders on AI represent serious, well-resourced governance efforts — but they are calibrated for economies with mature regulatory infrastructure, deep technical expertise in government, and large domestic AI industries.

Nepal, like most developing nations, has none of these. And yet AI is arriving in Nepal regardless — in the form of automated loan decisions, algorithmic content moderation affecting Nepali users, AI-powered recruitment tools, and increasingly, government digitisation projects that embed algorithmic decision-making into public services.

The choice is not between "governing AI" and "not governing AI." It is between governing AI intentionally or having AI govern us by default, on terms set by others.

This framework offers a practical, phased approach to AI governance that emerging nations can implement without requiring vast regulatory resources or sacrificing the innovation needed for economic development.


Principles for an Emerging-Nation AI Governance Model

Before prescribing structures, it helps to articulate the principles that should shape them.

Proportionality over perfection. Governance frameworks should be calibrated to actual risk and available capacity. A country of Nepal's size does not need a dedicated AI regulatory authority on day one. It needs clear principles, a designated coordination function, and a risk-tiered approach that reserves heavy oversight for high-stakes applications.

Outcome-focused, not process-focused. Good governance asks: are AI systems causing harm? Are they discriminating unfairly? Are they transparent enough for accountability? These are outcome questions. Prescriptive rules about algorithms and training data — the approach favoured in some Western frameworks — are difficult to audit without significant technical capacity.

Adaptive by design. AI policy needs a defined review mechanism so evidence, technology, and implementation lessons can inform updates.

Inclusive of civil society. The communities most affected by AI — rural citizens accessing digital government services, informal workers using AI-mediated gig platforms, women and minorities subject to automated screening — must have voice in governance design. This is both ethically right and practically important for legitimacy.


A Three-Tier Risk Classification

The cornerstone of an efficient governance model for resource-limited settings is risk classification. Not all AI applications deserve the same level of scrutiny.

Tier 1 — Prohibited Applications These are uses where the risks are so severe that no governance framework can adequately mitigate them. Examples include: AI systems that assign social credit scores affecting citizens' rights, real-time biometric mass surveillance in public spaces, and AI-generated disinformation at scale. These should be prohibited by legislation with meaningful penalties.

Tier 2 — High-Risk Applications Requiring Pre-Deployment Assessment These include AI systems used in: credit and insurance decisions affecting individuals, public sector automated decision-making (welfare, taxation, immigration), healthcare diagnosis tools, and recruitment screening for employment. Organisations deploying Tier 2 systems must conduct and publish impact assessments, maintain human oversight mechanisms, and provide individuals with explanation and appeal rights.

Tier 3 — Standard Applications with Light-Touch Requirements The vast majority of commercial AI — recommendation engines, customer service chatbots, predictive analytics for business operations — falls here. Requirements are minimal: basic transparency (users should know when they're interacting with AI), data protection compliance, and a mechanism for complaints.


Institutional Architecture

Nepal does not need a new AI regulatory agency in the near term. It does need:

A designated AI coordination function within an existing ministry — most logically the Ministry of Communication and Information Technology — with a mandate to develop national AI strategy, coordinate across sectoral regulators, and maintain a living inventory of high-risk AI deployments.

Sectoral regulator capacity building. The bodies that regulate banking, healthcare, and public services need to develop AI literacy. This means training existing regulatory staff, not creating new institutions.

A multi-stakeholder advisory mechanism including technology industry representatives, civil society, academic researchers, and relevant ministry officials, with transparent terms and published deliberations.

International coordination. Nepal should seek observer status or active membership in regional AI governance dialogues — particularly within SAARC and emerging Asia-Pacific frameworks. Much AI governance is cross-border in nature; bilateral and multilateral coordination is essential.


Implementation Sequence

Establish foundations: Designate coordination responsibility, publish principles, inventory higher-risk public-sector uses, and assess regulator capacity.

Develop proportionate rules: Consult on risk classification and sector guidance using the legislative or regulatory process considered lawful and appropriate.

Review implementation: Publish evidence, identify gaps, revise the approach, and coordinate internationally where useful.


The Opportunity Within the Challenge

There is an opportunity within this governance challenge that is easy to miss. Countries that establish credible, proportionate AI governance frameworks early will find it easier to attract responsible AI investment, build trust in digital public services, and position their digital economy as a premium, trustworthy partner in the global market.

Nepal can choose to develop responsible AI governance proactively or respond after problems emerge. The effects of either approach should be evaluated through transparent evidence rather than assumed.

About the author: Laxman Kafle is CEO and Founder of EveMoo Tech Pvt. Ltd. This article expresses the author's analysis and recommendations.