On 18 September 2026, Dutch Prime Minister Rob Jetten announced that the Netherlands intends to establish a national AI security agency, built in cooperation with France, the United Kingdom, and Germany — nations that already operate comparable institutes. The announcement is specific: Jetten plans to convene like-minded states at the United Nations General Assembly next week to establish stricter rules and safeguards, explicitly excluding China and the United States from the initial coalition. This is not a supranational harmonization move under the EU AI Act; it is a bilateral capacity-building alliance that includes a non-EU partner and operates outside Brussels' deferred timeline.

The Dutch proposal arrives exactly one week after the UN concluded its September push on AI governance. The Global Digital Compact review, advanced through the General Assembly's high-level week, produced two new coordinative mechanisms: an independent scientific panel to assess AI risks and opportunities, and an annual global dialogue where governments and stakeholders can align approaches. What it did not produce was binding auditability standards, federated verification mechanisms, or any operational mandate to inspect model weights, evaluate evaluation environments, or certify safety systems. UN News frames the organization's role explicitly as bringing governments together, providing scientific basis, and identifying areas for cooperation — coordination, not enforcement.

This is the bifurcation worth watching. International and supranational processes are generating architectures for dialogue: panels, compacts, voluntary frameworks, scheduled conferences. National governments are generating architectures for action: agencies, audit standards, procurement criteria, bilateral inspectorates. The two tracks are not converging; they are accelerating in parallel, and the gap between them is where governance will actually be exercised.

The pattern is visible across Europe. Germany's Federal Office for Information Security published its national AI Audit and Assurance Assessment Architecture (A5) in July, a machine-readable certification framework designed to slot into existing compliance toolchains while Brussels' harmonized standards remain under development. France's data protection authority issued an algorithmic impact assessment interpretive note on 14 September. The Netherlands is now adding a security agency to the stack. Each initiative is technically serious and each is national or minilateral in scope. None derives its authority from the AI Act's deferred presumption-of-conformity mechanism, because that mechanism does not yet exist.

The contrast with the United States is stark. CISA, the agency with the statutory role for critical infrastructure cybersecurity, has lost roughly one-third of its workforce since January 2026 and retired six cybersecurity assessments. The US is contracting national AI safety capacity at the same moment European states are proliferating theirs. The result is not a coherent multilateral regime but a patchwork of national capacities that may interoperate poorly, with the American patch shrinking while others expand.

There is a coherent case for the UN's coordinative approach. Binding global standards for frontier AI would require inspection regimes that no major AI power has yet accepted, and premature rigidity could freeze standards around technologies that will look different in three years. The scientific panel and annual dialogue at least create venues where evidence can accumulate and positions can be compared before they harden into regulation. But coordination without capacity is a conversation without a floor. If the Netherlands, France, Germany, and the United Kingdom develop four different national audit criteria for model safety, the global dialogue will have less to harmonize than to reconcile — and the reconciliation may happen through market access conditions rather than through the UN's scientific consensus.

The question the Dutch announcement raises is not whether national agencies are necessary. They clearly are, and the EU's own Digital Omnibus delay to December 2027 all but invited member states to fill the vacuum. The question is whether the emerging coalition produces shared standards that the eventual harmonized regime can adopt, or merely parallel national programs that fragment the compliance landscape further. Jetten's coalition is explicitly framed as a like-minded alliance. Like-minded is another word for self-selected. Self-selected standards can be rigorous, but they are not automatically interoperable — and interoperability is what separates a patchwork from a regime.

Whether next week's UNGA side meetings produce anything more concrete than another commitment to commit will be the short-term signal. The longer-term signal is whether any of these national agencies begin to recognize one another's audits as equivalent. Until that happens, AI governance is being built, but it is being built in national silos — and the UN's global dialogue will be mapping the walls rather than opening the doors.

Sources
UN News, "Who should set the rules for AI? The UN is pushing for a safer digital future"
NL Times, "Netherlands considering AI security agency to address serious concerns"