Doble Lectura #10

Governing AI in the state is a problem of institutional design, not technology

A technology director in the Brazilian public sector proposes leaving static compliance behind and governing frontier AI with adaptive risk management. His thesis: since no one knows how fast the technology will advance through 2030, fixed rules age badly, and the state needs to monitor capabilities, scale controls according to signals, and redesign organizations.

Generated automatically · sources linked · no prior human review

At a glance

  • What it is: Governing frontier general-purpose AI in the public sector, an article that does not report an experiment but instead organizes others’ evidence and proposes a framework for the state to govern frontier AI when it does not know how it will evolve.
  • Who: Fábio Correa Xavier, sole author, director of the technology department of the São Paulo State Court of Accounts (TCE-SP), in Brazil (LinkedIn).
  • Where: preprint on arXiv, 2026. arxiv.org/abs/2604.06215
  • Type: conceptual article, a synthesis of reports and literature that culminates in a governance framework. There is no new data and no empirical test of the model.

First reading: what it does and what it finds

It helps to start with what kind of text this is, because it frames the rest. It is not an empirical study: the author himself describes it as an exercise in synthesis and framework-building, based on recent institutional reports and peer-reviewed literature, that does not put the model it proposes to the test. So when we talk about “findings,” strictly speaking we are talking about a diagnosis built with other people’s evidence and an original proposal built on that diagnosis.

The diagnosis starts from what the International AI Safety Report 2026 calls the “evidence dilemma”: AI capabilities are advancing faster than knowledge about their harms and safeguards. That leaves the state in an uncomfortable position. Acting too soon can lock in poorly calibrated rules; waiting for complete evidence can leave society exposed. On top of this, according to the OECD’s scenario work, there is no single trajectory of progress toward 2030: plausible futures range from stagnation to acceleration, and current evidence does not allow ruling any of them out.

On that foundation, the author brings together three ideas he takes from the reports and that serve as scaffolding. The first: capabilities grow in a “jagged” way, shining at difficult tasks like programming or scientific reasoning while failing at things that seem simple, so a good benchmark score does not equal institutional reliability. The second: the risks are not a single thing, and it is useful to separate them into malicious use (scams, fraud, abuse), malfunctions (unreliable results in operation), and systemic risks (labor disruption, concentration of power, accumulated institutional dependence). The third, which comes from the digital government literature: adopting AI in the state is not buying software; it is a sociotechnical phenomenon that only pays off if the organization’s routines, structures, governance, and culture change.

From there comes his own contribution, which is the core of the article: an adaptive governance framework for public institutions, with six layers that work in a cycle. Capability intelligence, to closely monitor what AI is starting to be able to do. Risk classification by type and by sector sensitivity, distinguishing justice, health, tax collection, or procurement. Conditional controls, “if this happens, then that is triggered” rules, for when uncertainty is high. Defense in depth, where no safeguard is enough on its own and access controls, logs, auditing, and red-teaming are combined. Sociotechnical implementation, which requires every high-impact project to have an organizational redesign plan with responsibilities and override mechanisms. And a fixed learning and review cycle, quarterly or semiannual, that forces a look at incidents and near misses instead of certifying just once.

The thread that connects everything is a critique of static regulation. When capabilities change along several paths at once, a set of rules written only once quickly falls out of date. The author concludes that governing AI well in the state calls for more public policy capacity, a clearer allocation of responsibilities, and mechanisms that keep working whichever of its possible paths the technological future takes. The sentence that sums up his position is in the first line of the abstract: governing this is a problem of institutional design, not of the model’s technical performance.

Second reading: from Latin America

The first thing worth emphasizing is where the text comes from. It is not a Global North report handed down to the region: it is written by a technology director at a Brazilian oversight body, someone who governs public systems every day. That gives the diagnosis a welcome closeness to practice, and at the same time leaves an interesting paradox. Although the author is Latin American, the framework is conceived in universal terms and relies almost entirely on global sources, such as the international safety report and several OECD papers. The region appears as the audience for the framework, not as the subject of study. It is a proposal made from the region more than about the region.

That distinction matters when it comes to putting it into practice. The framework assumes considerable institutional capacity: units that monitor models, quarterly review cycles, red-teaming, mature data management, maps of responsibility among developers, integrators, and legal departments. In states with a solid civil service, that is already ambitious; where political turnover is high and technical teams are thin, it is an outright uphill battle. That last point is my own reading, not the paper’s, which does not study specific countries or measure state capacity. But it connects with something Xavier himself names: when no one is assigned responsibility for deciding and for stopping, adoption swings between underuse and uncontrolled experimentation.

There is one point where the framework becomes especially relevant for the region. The text insists that AI governance depends on the maturity of data governance: without organized, interoperable data with clear rules of use, there is no auditable or explainable AI worth the name. For many Latin American states, that is the infrastructure work still pending, and the article helps show that it is not an agenda separate from AI, but its precondition.

The question it leaves is the one the author himself poses at the end: at this point, the problem is no longer whether uncertainty exists about where AI is headed, but whether public institutions can govern responsibly while that uncertainty persists. For the region, with less margin and less installed capacity, the question hits harder.

The fine print

  • It is a conceptual article, not an empirical study. Its value lies in organizing a debate and proposing an actionable framework, not in demonstrating that the framework works: the author himself makes clear there is no empirical test of the model. It is best read as a well-built working hypothesis, not as an evaluation.
  • Almost all of its evidence is secondhand and comes from a few sources: the International AI Safety Report 2026 and several OECD documents. These are serious syntheses, but the article inherits their limits, including that data on the prevalence and severity of harms remain incomplete.
  • It is written by a public-sector practitioner, not an external evaluator. That brings institutional realism and, at the same time, is worth keeping in mind: it is the view of someone who designs and operates these systems, not an independent audit of the framework it proposes.
  • The warnings about the speed of the models and the impossibility of predicting the trajectory through 2030 are the author’s and those of the reports he cites. The specific application to state capacity weaknesses in Latin America is mine, not the paper’s.

Paper keywords: artificial intelligence governance, digital government, public sector transformation, AI safety, adaptive regulation

Automated reading. This text was generated by Claude, an Anthropic model, from the original source, without line-by-line human review. It may contain errors or debatable interpretations; to check any point, see the original source.
Spotted an error? Report it

Tell us what's wrong, quoting the sentence if you can and, if you have it, the source that corrects it. An automated process reviews reports every night: if the error is verified, the page is corrected and a correction note is added at the bottom.

Your email is optional: we only use it if we need more context about the report. It doesn't subscribe you to the newsletter.