Trump Rules Out US-China AI Joint Venture Over Technology-Sharing Concerns
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
Explore what Latin America’s AI summit means for AI governance, cloud infrastructure, data, regulation, risk management, skills and digital development.
Latin America’s AI debate is entering a more consequential phase. The central question is no longer simply whether businesses and governments will adopt artificial intelligence. It is whether the region can build the infrastructure, institutions, data systems, skills and controls needed to use AI at scale.
That broader challenge was visible on September 21, 2026, when the Inter-American Development Bank Group convened heads of state and government officials from 12 Latin American and Caribbean countries alongside senior executives from Google, Anthropic, Microsoft and Nvidia. The meeting, held on the sidelines of the United Nations General Assembly, focused on a shared roadmap for broad and safe AI adoption. According to the IDB's official announcement, discussions covered institutions and regulation, talent and skills, digital infrastructure, data systems, technology diffusion and AI risks. Participants also called for work on a regional mechanism incorporating a common strategy and joint investment guidelines.
The economic opportunity could be significant, but it should be treated as a scenario rather than a promise. The IDB estimates that broad AI adoption combined with large labor-productivity effects could leave Latin American and Caribbean GDP 5.1% higher after a decade. Under a scenario involving limited adoption and smaller productivity effects, the estimated increase is only 0.3%. The same analysis indicates that labor mobility could materially affect wage outcomes. These are modeled estimates, not guaranteed economic results.
This is why AI governance in Latin America cannot be separated from cloud infrastructure, data centers, connectivity, energy, data governance or skills. Successful AI adoption depends on the entire system around the technology.
The September meeting matters less as a one-day event than as a signal of how the regional AI agenda is expanding.
The discussion connected AI adoption with productivity, investment, skills, infrastructure, regulation and risk. That framing is important because access to advanced models does not automatically create economic value. Organizations still need reliable digital infrastructure, high-quality data, people capable of redesigning work around AI, and governance systems that determine where AI can be used safely.
The IDB also reported that AI is already producing measurable results in areas such as social protection, public safety and worker productivity. The larger development question is whether those gains can be expanded without creating unmanaged risks or widening existing digital and institutional gaps.
AI may appear to operate in an intangible "cloud", but the infrastructure is physical.
The IDB's 2026 study on the development and use of AI infrastructure in Latin America and the Caribbean identifies five core infrastructure pillars: data generation, storage, processing, transport and development environments. It also highlights financing, cybersecurity, data governance, environmental sustainability and human capital as enabling factors.
In practice, that means AI capacity depends on data centers, processors, storage systems, cloud platforms, broadband and fiber networks, reliable electricity, cybersecurity and technical expertise.
Infrastructure therefore becomes a strategic issue. A government may want AI-enabled public services, or a company may want to deploy generative AI across its operations, but those ambitions depend on the availability, cost, security and resilience of the underlying computing environment.
AI can affect productivity, public administration, healthcare, education, finance, customer service and business competitiveness. It can also alter job tasks, demand new skills and influence how public or private decisions are made.
That makes AI adoption a development issue.
The relevant question is not simply whether a country has access to a particular model. It is whether firms can integrate AI into productive processes, whether public institutions can procure and supervise it responsibly, whether workers can adapt, and whether the infrastructure and governance needed to support deployment are available.
Infrastructure determines what organizations are technically capable of doing. Governance helps determine what they are authorized to do, which risks must be addressed, who is accountable and how systems are monitored after deployment.
As AI infrastructure expands, the consequences of weak governance can expand with it.
Several concepts are often treated as interchangeable even though they serve different purposes.
AI governance is the system of accountability, policies, decision processes and controls through which an organization directs and oversees AI.
AI regulation refers to legally applicable requirements created by legislatures, governments and regulators.
AI risk management concerns identifying, assessing, treating and monitoring risks created or amplified by AI systems.
Responsible AI describes the broader objective of developing and using AI consistently with principles such as safety, fairness, accountability, privacy and appropriate human oversight.
AI management is the operational discipline that turns these requirements and objectives into repeatable organizational processes.
This distinction matters. Monitoring new legislation is not the same as having an AI governance program. An organization can comply with a specific law and still lack a reliable AI inventory, approval process, vendor controls or incident-management procedure.
Scaling AI can introduce or amplify risks involving privacy, cybersecurity, data misuse, discrimination, unreliable outputs, intellectual property, vendor dependency and operational resilience.
Governance provides the mechanisms for deciding which controls are proportionate to those risks.
Human oversight is one example. A requirement for a person to review an AI decision provides limited protection if that reviewer lacks the information, authority, competence or time needed to challenge the system.
The same principle applies to third-party AI. Purchasing an AI service from a major cloud or software provider may transfer technical responsibilities, but it does not necessarily transfer responsibility for how the organization uses the system.
AI workloads require computing power, storage and high-capacity networking. As demand grows, data centers become a more visible part of regional digital-development strategy.
The IDB's 2025 report on the data-center opportunity in Latin America and the Caribbean describes cloud computing, AI and the Internet of Things as important drivers of infrastructure demand. It argues that successful data-center development also depends on infrastructure, talent, regulation, sustainability and public-private cooperation.
This is an important distinction. The number of data centers is not, by itself, a measure of AI readiness.
A resilient AI ecosystem also needs adequate grid capacity, network connectivity, cybersecurity, skilled operators, predictable operating conditions and continuity planning. Governments considering infrastructure incentives therefore need to examine the wider environment around the facility, not simply the initial investment.
Computing capacity provides limited value if businesses, public agencies or communities cannot connect to it reliably.
Cloud-based AI depends on broadband availability, network capacity and acceptable latency. Connectivity gaps can therefore become AI-adoption gaps.
The Latin American Artificial Intelligence Index 2025, produced by Chile's CENIA and ECLAC, evaluates 19 countries across enabling factors, research, development and adoption, and governance. Its regional analysis identifies significant differences in AI ecosystem maturity and provides a reminder that infrastructure, skills, adoption and governance do not develop uniformly across the region.
Digital-development policy therefore needs to consider both advanced computing and broad access. Expanding high-end AI infrastructure while leaving persistent connectivity gaps would produce an uneven foundation for adoption.
AI infrastructure also has an energy dimension.
The International Energy Agency estimates that global data-center electricity consumption reached around 485 TWh in 2025 and projects roughly 950 TWh in 2030 in its central outlook. AI-focused data-center electricity consumption is projected to grow even faster. These are global projections rather than forecasts for individual Latin American countries, but they illustrate why AI infrastructure and energy planning increasingly intersect. The IEA's latest Energy and AI analysis discusses both the projected growth and the physical bottlenecks that could constrain it.
For Latin America, the practical issues include electricity reliability, grid connections, efficiency, cooling, resilience and environmental impact. Renewable resources may create opportunities in some locations, but sustainability still has to be assessed at project level.
Compute receives much of the attention surrounding AI investment, but AI systems are also dependent on data.
Data quality influences system reliability. Provenance helps organizations establish where information came from and whether it can legitimately be used. Interoperability affects whether different systems can exchange information effectively. Access controls determine who can see or change data.
For organizations, data governance therefore includes quality, ownership, security, lineage, retention, accessibility and permitted use.
The IDB's 2026 infrastructure study explicitly places data generation alongside storage, processing and transport, and identifies data governance as one of the enabling conditions for trustworthy AI ecosystems.
AI projects also operate within existing privacy and data-protection frameworks.
Brazil's General Data Protection Law, the LGPD regulates the processing of personal data by public and private actors and provides specific protections for sensitive personal data. Peru's Personal Data Protection Law, Law No. 29733 likewise establishes protections governing personal-data processing.
For an AI project, privacy questions can arise around training data, prompts, retrieval systems, logs, outputs and data shared with external providers.
Organizations using cross-border cloud services also need to determine which legal requirements apply to the movement and processing of data. The relevant rules vary by jurisdiction, so regional businesses should not rely on a single privacy model for all Latin American operations.
Data sovereignty is sometimes discussed as though it simply means keeping every dataset within national borders. The governance issue is broader.
Organizations need to understand where important data is stored and processed, who can access it, which legal jurisdictions may apply and how easily data can be transferred between systems.
Cloud-provider dependency is part of the same discussion. Foreign technology providers are not inherently problematic. The risk arises when an organization becomes dependent on a provider without understanding service continuity, contractual rights, technical interoperability or exit options.
Good governance therefore focuses on control, visibility and resilience rather than assuming that any particular ownership model is automatically safe or unsafe.
Latin America does not have a single AI regulatory model. Countries are combining legislation, strategies, public policies and existing sector-specific rules in different ways.
The distinction between those instruments is essential.
Peru has enacted national AI legislation. Law No. 31814, published on July 5, 2023, promotes the use of AI for economic and social development and includes a risk-based principle. The government subsequently adopted implementing regulations through Supreme Decree No. 115-2025-PCM on September 9, 2025. The official Peruvian government publication is available through the Presidency of the Council of Ministers.
Colombia approved the CONPES 4144 National Artificial Intelligence Policy in February 2025. This is a national public-policy instrument, not a general AI statute. The Colombian National Planning Department's explanation of CONPES 4144 identifies six policy areas, including governance and ethics, data and technological infrastructure, research and innovation, talent, risk mitigation, and AI adoption.
Chile has an existing National Artificial Intelligence Policy and is separately considering AI legislation. Bill 16821-19, introduced in May 2024, remained in its second constitutional stage according to the official Chilean Chamber of Deputies legislative record. As of September 23, 2026, it should therefore be described as a bill under consideration, not an enacted AI law.
Brazil is also considering comprehensive legislation. The Senate approved PL 2338/2023 in December 2024 and transmitted it to the Chamber of Deputies. As of September 23, 2026, the official Chamber legislative record lists the proposal as awaiting the rapporteur's opinion in the special committee examining it. It remains a bill rather than an enacted comprehensive AI statute.
The practical lesson is straightforward: businesses cannot treat "AI regulation in Latin America" as one compliance regime.
A legal framework is only one layer of an effective governance system.
The implementation chain looks more like this:
Law → institutions → implementation → monitoring → enforcement → continuous improvement
A sophisticated law will have limited impact if regulators or public institutions lack expertise, resources or effective implementation mechanisms.
The same principle applies to companies. An AI policy is not a governance system unless people know who is responsible, what documentation is required, how systems are approved and what happens when risk exceeds an acceptable threshold.
Governments are trying to support innovation and investment while protecting rights and maintaining confidence in AI-enabled systems.
Risk-based approaches can help because they allow controls to reflect the possible consequences of a use case. An internal productivity tool and an AI system influencing access to essential services do not necessarily justify identical governance requirements.
For organizations, that reinforces the case for risk classification before deployment rather than attempting to apply the same controls to every AI system.
AI risk is multidimensional. Organizations may encounter privacy and cybersecurity risks, bias and discrimination, inaccurate or fabricated outputs, intellectual-property concerns, model-performance problems, vendor dependencies, operational failures, regulatory exposure and reputational damage.
The severity depends heavily on context.
A generative AI assistant used to brainstorm internal marketing ideas creates a different risk profile from a model influencing hiring, credit, medical treatment or public benefits. Governance should reflect that difference.
A structured program begins with visibility.
Organizations need to identify which AI systems are being used, why they are used, who owns them, what data they process and which external providers are involved. They can then assess risk, define controls, test systems, document decisions and establish monitoring.
Post-deployment monitoring matters because AI systems and their operating environments can change. Vendors update models, prompts change, data shifts and new integrations are introduced.
Incident-management processes should therefore cover AI-specific failures as well as conventional security incidents.
Established frameworks can help organizations structure these controls.
The NIST AI Risk Management Framework is a voluntary framework for managing AI risks. Its core functions are Govern, Map, Measure and Manage. NIST states that AI RMF 1.0 is currently being revised, while the existing framework and Playbook remain available.
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. ISO/IEC 23894:2023 provides guidance on AI-specific risk management.
These frameworks can support internal governance, but they are not universally mandatory across Latin America. Their legal significance depends on applicable law, sector requirements, contracts and organizational commitments.
For professionals who need to turn such frameworks into practical policies, responsibilities and controls, structured AI governance training can help connect regulatory concepts with day-to-day governance implementation.
Data centers and cloud platforms do not automatically create effective AI adoption.
Organizations also need technical specialists, business leaders, privacy and security professionals, lawyers, risk teams, procurement staff and people capable of evaluating AI outputs critically.
The ILIA 2025 research places human capital within the broader enabling environment for AI and highlights differences in regional preparedness.
AI literacy is therefore becoming relevant far beyond technical teams. Employees need to understand when AI is appropriate, what information can be entered into systems, how outputs should be checked and when human judgment must take priority.
The IDB's 2026 economic analysis illustrates why workforce adaptation matters.
Its scenarios estimate that wages could increase by 2.3% to 5.3% over a decade when workers can move into expanding areas of employment. Without that mobility, the model estimates wage reductions of 13.5% to 20.9%. These are scenario-based estimates, not predictions of what will inevitably occur.
The policy implication is that investment in AI infrastructure needs to be accompanied by investment in skills and pathways for workers to adapt.
AI governance increasingly sits at the intersection of technology, law, risk, data, cybersecurity and organizational management.
Responsibilities may include maintaining AI inventories, carrying out impact or risk assessments, interpreting regulatory developments, overseeing vendors, defining human-review requirements and monitoring systems after deployment.
That combination of responsibilities explains why AI governance is becoming a distinct professional capability rather than simply an additional task for IT teams.
Governments need clear responsibility for AI policy and for AI systems used within the public sector.
Institutional capacity includes expertise, accountability, coordination across agencies, procurement controls and monitoring. Procurement is particularly important because governments may acquire AI indirectly through cloud platforms and enterprise software rather than commissioning standalone systems.
Public-sector policies can establish requirements for use-case assessment, risk classification, procurement, transparency, security, human oversight and monitoring.
Higher-consequence applications require particular attention. Where AI can affect eligibility for public services, public safety or other significant interests, institutions need clear evidence about system limitations and meaningful routes for review or intervention.
Agentic AI adds another governance layer because software may be able to interact with external tools, access data and execute actions.
NIST launched its AI Agent Standards Initiative in February 2026, with work focused on interoperability, security, identity and related standards. NIST has separately examined identity, authorization, logging and accountability for software and AI agents.
For governments and businesses, practical controls may include limiting an agent's permissions, recording actions, separating low-risk automation from activities requiring approval and maintaining mechanisms for human intervention.
Every organization adopting AI needs clear ownership.
Governance can build on existing technology, compliance, risk, cybersecurity, legal and audit structures. A new committee is not always necessary. Clear responsibilities are.
Businesses should know who approves AI systems, who owns the business outcome, who evaluates risk and who can suspend a system if its behavior becomes unacceptable.
Organizations cannot govern systems they do not know exist.
An AI inventory should record the system, its purpose, business owner, users, vendor, relevant data, important integrations and risk classification.
The inventory should include purchased AI features as well as internally developed systems. Generative AI embedded inside productivity, customer-service or analytics platforms can create governance issues even when an organization has not formally commissioned an "AI project."
Vendor due diligence should examine data processing, cybersecurity, contractual responsibility, service availability, transparency, model changes, incident notification and subcontractors where relevant.
Exit strategies deserve attention too.
If a critical business process becomes dependent on one provider, the organization should understand whether data can be retrieved, whether another service could replace the system and how operations would continue during a major outage or contractual dispute.
AI supply chains and cloud architectures cross borders.
A company may operate in several Latin American jurisdictions, process data through international infrastructure and use AI services supplied by companies based elsewhere.
National laws remain important, but organizations benefit when terminology, technical standards and assurance practices are interoperable.
The September 2026 IDB meeting called for the development of a regional mechanism incorporating a common strategy and joint investment guidelines. That does not mean countries need identical laws. It does show growing interest in coordination.
International standards can support comparable organizational practices across jurisdictions even where legal obligations differ.
A multinational company, for example, may use a common AI inventory, risk-classification methodology or vendor-assessment process while applying additional controls to satisfy particular national requirements.
AI development involves governments, cloud and technology companies, universities, development institutions, startups and civil society.
Each has a different role.
Governments establish public policy and legal requirements. Businesses supply infrastructure and applications. Universities develop research and talent. Development institutions can provide financing and technical expertise. Civil-society organizations contribute perspectives on rights, inclusion and accountability.
Effective collaboration requires those roles to be clear rather than allowing accountability to become diluted.
The September 2026 meeting does not guarantee particular investments, growth rates or regulatory outcomes. It does, however, point to several potential implications.
Attention to AI infrastructure could increase as governments connect productivity strategies with computing capacity, connectivity and data systems. Demand for cloud and data-center capacity could grow as more organizations deploy AI workloads. Expansion of AI use could increase the need for governance, risk management and compliance capability. Workforce policy may place more emphasis on AI literacy and professional skills. Environmental and energy considerations could also become more prominent as infrastructure expands.
None of these outcomes is automatic.
The central lesson is that the pieces are interconnected. Compute without connectivity limits access. AI without trustworthy data reduces reliability. Infrastructure without skills limits productive adoption. Deployment without governance can expand risk faster than organizations can control it.
The following 10-step framework is a practical synthesis for organizations. It is not an official IDB framework or a government-mandated regional standard.
Identify AI use cases. Determine where AI is already being used and where new deployments are planned.
Create an AI system inventory. Record each system's purpose, owner, users, vendor, data and significant integrations.
Classify AI risks. Assess potential effects on people, privacy, security, operations, rights and regulatory obligations.
Establish governance responsibilities. Define business ownership, approval authority, review responsibilities and escalation routes.
Assess data and privacy requirements. Examine data quality, provenance, access, sensitive information, retention and applicable legal requirements.
Evaluate vendors and cloud providers. Review contracts, cybersecurity, data processing, transparency, resilience, dependencies and exit options.
Implement human oversight. Specify when human review is required, what authority reviewers have and when a system must stop or escalate.
Document AI systems and decisions. Keep evidence of assessments, approvals, testing, limitations, changes and accepted risks.
Monitor performance and incidents. Track reliability, model behavior, security events, complaints, failures and material changes.
Review and update governance controls. Reassess systems as laws, models, vendors, data, business processes and risks change.
The value of this approach comes from treating governance as a lifecycle. A one-time approval is insufficient for systems that continue to change after deployment.
The September 2026 AI dialogue highlights a broader change in Latin America's digital agenda. Cloud computing, data centers and advanced models matter, but they are only part of the capability required for responsible AI adoption.
The region's AI opportunity also depends on trustworthy data, reliable infrastructure, capable institutions, skilled people, appropriate regulation, risk controls and meaningful oversight.
That is the central challenge for AI governance in Latin America. Success will not simply be a question of how much AI governments and businesses can deploy. It will depend on whether they can build the institutional and technical systems needed to use AI productively, responsibly and sustainably.
Professionals responsible for those systems can continue developing practical governance, risk and oversight capabilities through AI Governance Courses as AI adoption and regulatory expectations continue to develop.
AI governance in Latin America is the system of responsibilities, policies, controls and oversight used to manage how organizations and governments develop, procure and use AI. It includes legal compliance but extends further into risk assessment, data governance, cybersecurity, human oversight, vendor management, documentation and monitoring.
AI depends on computing capacity, storage, data centers, cloud platforms, connectivity and reliable electricity. Better infrastructure can expand access to advanced AI capabilities, but infrastructure alone does not guarantee productive adoption. Data quality, skills, institutional capacity and governance also determine whether AI investments create sustainable value.
Approaches differ by country. Peru has enacted an AI law and implementing regulation. Colombia has a national AI policy through CONPES 4144. Chile and Brazil are considering significant AI legislation that, as of September 23, 2026, has not completed the legislative process. Existing privacy, cybersecurity, consumer and sector-specific rules may also apply to AI systems.
Cloud infrastructure gives organizations scalable access to computing, storage, AI models and supporting services without requiring them to build their own data centers. It can accelerate AI adoption, but it also creates governance questions involving security, data processing, provider dependency, service resilience, contractual terms and exit planning.
Key risks include privacy violations, cybersecurity incidents, inaccurate AI outputs, bias and discrimination, intellectual-property exposure, regulatory breaches, vendor dependency, model-performance problems and operational disruption. The significance of each risk depends on the use case and the consequences of an incorrect or unsafe outcome.
Data centers provide much of the computing, networking and storage infrastructure required to train, host and operate AI systems. Their development can expand cloud and AI capacity, but viable data-center ecosystems also require reliable electricity, connectivity, cybersecurity, cooling, skilled workers and appropriate regulatory conditions.
AI governance requires a combination of AI literacy, risk management, privacy, cybersecurity, compliance, data governance, legal understanding, procurement and organizational leadership. Governance professionals do not necessarily need to be machine-learning engineers, but they need enough technical understanding to assess AI use cases, question assumptions and translate risks into controls.
Businesses can create an AI inventory, assign system ownership, assess risk, identify applicable privacy and sector requirements, strengthen procurement controls, document important decisions, evaluate vendors and establish monitoring and human-oversight processes. These actions improve governance today while creating a stronger foundation for adapting to future regulation.
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
AI Law
Compare AI laws around the world in 2026, including binding laws, proposed rules, regulatory frameworks, effective dates and business implications...
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...