Scaffolding for Whom? Reading the EU-ASEAN Business Council's Responsible AI Blueprint
A balanced look at Building ASEAN's Responsible AI Ecosystem — and a closer reading of its governance layer
In January 2026, the EU-ASEAN Business Council released Building ASEAN's Responsible AI Ecosystem: Towards a Safe, Inclusive and Innovation-Ready Future. It arrives at a deliberate moment. The ASEAN Digital Economy Framework Agreement (DEFA) is nearing completion, the ASEAN Digital Masterplan 2025 is entering its renewal phase, and the region has spent two years assembling a shelf of soft-law instruments — the ASEAN Guide on AI Governance and Ethics (2024), its expanded generative-AI companion (2025), and the recently declared ASEAN AI Safety Network (AI SAFE).
Worth stating at the outset: this is not a neutral policy survey. The EU-ABC is, by its own description, the primary voice of European business in the region — an advocacy body whose stated mission is to shape policy and regulatory environments in ways that ease European investment and trade. That does not disqualify the document. Trade bodies often produce the clearest maps of a regulatory landscape precisely because they have to operate inside it. But it does mean the paper should be read as a position, not a census. Its recommendations answer a specific question: how can the region make responsible AI legible, interoperable, and low-friction for firms deploying across ten different national regimes?
The Stack as a framing device
The paper's organizing device is the "AI Stack" — four interdependent layers running from Data & Infrastructure at the base, through Model & Algorithm Development and Applications & Adoption, up to Governance & Coordination at the top. The layers are used both descriptively (to sort the region's existing initiatives) and prescriptively (to cluster the recommendations).
The device earns its place. Its real analytical merit is the division of labour it proposes: regional bodies set common baselines and mutual recognition; national governments handle implementation through sandboxes, standards bodies, and incentives. For a region as uneven as ASEAN — where Singapore has operational assurance institutions like AI Verify while several members are still drafting roadmaps — that separation is genuinely useful. It lets the report sidestep the trap of demanding harmonized regulation, which no member wants, and argue instead for interoperability — a lower and more achievable bar. If you strip away the branding, the Stack is a competent way of showing that responsible AI is not produced by regulation alone but by a system of enablers: trusted data, skilled people, accountable oversight. That is a reasonable and well-made point.
The governance layer, up close
The top of the Stack is where the report is most candid, and most worth reading closely.
Its diagnosis is honest about the hard problems. It acknowledges that questions of IP ownership, liability, and how training data should be treated remain unresolved across most member states, and that limited local evaluation capacity makes it difficult for firms to validate outputs for accuracy, ethics, or cultural relevance — a difficulty it connects, correctly, to the region's linguistic and cultural diversity. It is refreshingly free of the pretence that principles alone solve anything.
The remedies cluster around a handful of instruments: a voluntary ASEAN AI trust mark built on AI SAFE; a vendor assurance framework in the form of a procurement and due-diligence checklist; alignment to international references such as ISO/IEC 42001 and the NIST AI Risk Management Framework; and bilateral or multilateral mutual-recognition pilots among willing states. The underlying logic is a "passporting" one, borrowed openly from how firms already think about compliance: evaluate once, be recognized across borders, avoid duplicated audits. As a piece of regulatory design aimed at reducing friction, it is coherent and realistic — the repeated insistence on "voluntary" and "willing" is more honest than a call for mandates the region could not enforce.
Three things, though, are worth sitting with.
First, the word "voluntary" does a great deal of work here, and it rewards watching in its trajectory rather than its present tense. A voluntary trust mark that becomes a de facto procurement expectation, and then a practical condition of market entry, is a well-travelled road from soft law to hard requirement. The report is not concealing this — mutual recognition and procurement are precisely the mechanisms it names — but readers should understand "voluntary" as a starting position, not a stable equilibrium. The decisive questions are downstream: who accredits the auditors, and against whose benchmarks? That is where the power actually settles, and the document leaves it open.
Second, the proposal renders trust as a certifiable object. Once trust is something a trust mark confers, it becomes whatever the assurance framework measures — and the framework here is anchored to standards developed largely outside the region. There is nothing wrong with borrowing mature references; there is something worth questioning in a "trust" signal whose underlying metric is defined elsewhere and then recognized locally. For anyone who works on measurement in the cultural field, the move is familiar: the instrument does not so much record trust as produce a particular, auditable version of it, and then presents that version as the thing itself.
Third — and this is where the report matters most for cultural policy — culture and language enter the document almost entirely as risk. The paper flags cultural and linguistic appropriateness as a governance concern and lists "cultural/IP considerations" in its vendor checklist. But diversity appears as something to validate against: a source of shortage (local-language NLP talent), a compliance dimension, a variable to be managed. It does not appear as a body of heritage, language data, and creative work with its own claims. The proposed remedy for unresolved IP and training-data questions is, in the end, a procurement checklist — an instrument that manages enterprise liability, not one that establishes creators' rights or communities' claims over the data used to train systems on their languages and cultural forms.
What the Stack leaves out
It is telling to read the case studies as a set: SAP, Coca-Cola, DHL Supply Chain, DHL Express, L'Oréal. Enterprise transformation, smart manufacturing, logistics sortation, cosmetics formulation. This is a document about industrial and commercial adoption, and it is upfront about that.
But it means the Applications & Adoption layer — the one meant to capture how AI enters sectors like manufacturing, finance, healthcare, and education — has almost nothing to say about the cultural and creative sector, public heritage institutions, or the public-interest data that cultural work depends on. Training-data sovereignty, cultural-heritage data as a shared public asset, the position of artists and archives whose material feeds generative systems — none of it is in frame. For a region whose creative economies are a real engine of soft power and cross-border exchange, that is a meaningful absence, not a footnote to be filled in later.
Why it still matters
None of this is a reason to dismiss the paper. It is a reason to engage it.
The report's own strongest advice — pressed on industry throughout — is to get involved early, while the vocabulary is still being written, rather than inheriting frameworks built entirely around someone else's use cases. That advice applies with at least equal force to cultural institutions, creative-sector bodies, and the public agencies that steward heritage and language data. If "responsible AI" in ASEAN comes to mean only what an enterprise procurement checklist can certify, that will be partly because the people who think about culture, memory, and the politics of the archive were not in the room when trust was being defined.
The instruments proposed here — trust marks, assurance forums, mutual-recognition pilots — are still soft, still voluntary, still being shaped. That is precisely the moment to ask whose ledger they are keeping.
Frequently asked questions
What is the EU-ASEAN Business Council's responsible AI report? Released in January 2026, Building ASEAN's Responsible AI Ecosystem is a policy paper by the EU-ASEAN Business Council — the main advocacy body for European business in the region. It proposes practical, near-term steps for ASEAN and its member states to turn shared principles of responsible AI into working governance mechanisms.
What is the "AI Stack" framework? The report organises AI policy into four interdependent layers: Data & Infrastructure, Model & Algorithm Development, Applications & Adoption, and Governance & Coordination. It uses this "stack" to sort existing initiatives and to argue that regional bodies should set common baselines while national governments handle implementation.
What is the proposed ASEAN AI trust mark? A voluntary regional certification, built on the ASEAN AI Safety Network (AI SAFE), intended to signal that an AI system meets baseline transparency and documentation standards. It would draw on international references such as ISO/IEC 42001 and the NIST AI Risk Management Framework, and support mutual recognition across member states.
What does the report mean for the creative and cultural sector? The report treats intellectual property, content authenticity and cultural-linguistic appropriateness mainly as enterprise compliance and risk issues. For the creative economy, that leaves open questions the paper does not resolve — around creators' rights, training-data provenance, and cultural-heritage data — which is why cultural institutions and creative-sector bodies have a reason to engage while the frameworks are still being written.
Source
EU-ASEAN Business Council, Building ASEAN's Responsible AI Ecosystem: Towards a Safe, Inclusive and Innovation-Ready Future (January 2026). EU-ABC — https://www.eu-asean.eu


