Back to Insights
AI Governance · Published July 2026 · 8 min read

The Regulatory Blind Spot in Mining AI.

Why no jurisdiction names it, and why that changes nothing about your exposure.

LOMexcel undertook a comprehensive review of the primary instruments that govern artificial intelligence globally — statutes, regulations, standards, and mine-safety codes across more than a dozen jurisdictions — to establish what actually governs AI deployment in mining, as distinct from what is commonly assumed to govern it.

The distinction matters. Most commentary on AI governance in mining defaults to the EU AI Act or to generic "responsible AI" principles, without establishing whether, or how, those instruments actually reach a mining operation's specific use cases.

The central finding is a structural absence rather than a rule: no jurisdiction reviewed in this research — including the European Union, the United States, and China — has enacted AI legislation that names mining, or mining-adjacent activities such as autonomous haulage or resource estimation, as a defined use case. This is a notable gap given the pace at which the sector has adopted AI: machine-learning-driven geological and grade-estimation models, autonomous haul fleets operating unsupervised across open pits, predictive-maintenance systems monitoring plant and mobile equipment, and workforce-analytics tools informing hiring, scheduling, and performance decisions.

Three channels of exposure

Employment and workforce AI

Employment and workforce AI is the most consistently regulated mining AI use case globally. It is explicitly classified as high-risk under Annex III of the EU AI Act, which covers AI systems used in recruitment, task allocation, and performance evaluation. It is the direct target of Colorado's amended AI Act, effective January 2027, which mandates pre-use notice and a right to meaningful human review for covered automated decision-making technology in employment contexts. It underlies Quebec's Law 25, in force since September 2023, which requires disclosure and a right to human review for exclusively automated decisions affecting individuals — a provision that extends directly to workforce-analytics tools many mining operators have deployed without classifying them as regulated AI.

The governing principle for operators: any AI system that informs hiring, scheduling, performance evaluation, or termination should be treated as high-risk by default, in every jurisdiction of operation, irrespective of whether local AI-specific legislation has been enacted.

Data-protection law as the universal backstop

Where AI-specific legislation remains pending — the position in most jurisdictions at present — general data-protection frameworks already impose binding obligations. South Africa's POPIA requires human oversight of automated decisions affecting individuals well ahead of its still-draft national AI policy. Indonesia's UU PDP performs the equivalent function while its AI Presidential Regulation remains unsigned. In China, the Personal Information Protection Law and data-security regime govern internal mining AI applications more directly than the public-facing algorithm-registration regime typically associated with Chinese AI policy.

The pattern is consistent across jurisdictions: the operative constraint is rarely the AI-specific statute. It is the data-protection law already in force.

Autonomous equipment and mine-safety codes

Autonomous equipment is governed through mine-safety codes rather than AI statutes. Western Australia's Safe Mobile Autonomous Mining Code of Practice is the most developed regulatory instrument of its kind globally, developed in direct response to operational incidents, including a documented collision between an autonomous haul truck and other mobile equipment that produced a formal Significant Incident Report. ISO 17757 establishes the corresponding international safety standard for autonomous and semi-autonomous machine systems across their full operating lifecycle, not solely at commissioning.

In substance, this body of safety regulation constitutes AI governance, notwithstanding that it is not labelled as such.

The industry has the governance infrastructure

The gap is specificity, not maturity

Mining is not starting from a position of governance immaturity. The sector already operates under some of the most rigorous safety, disclosure, and technical-standards regimes of any industry: ISO 17757 for autonomous machinery, the Global Industry Standard on Tailings Management, IEC 62443 for operational-technology cybersecurity, and the resource-disclosure codes — NI 43-101, JORC, SK-1300 — that govern every public mining company's technical reporting. The gap is that almost none of these instruments yet contain an explicit AI provision.

GISTM does not currently include an AI-specific requirement, but the applied research on AI in tailings monitoring converges on principles consistent with mature governance frameworks generally: the Engineer of Record retains final decision authority, AI is positioned to support technical judgment rather than substitute for it, and models trained predominantly on large, well-documented facilities require explicit validation before being relied upon at smaller or atypical sites.

Resource estimation carries the same principle with more immediate consequence. Current disclosure codes contain no AI-specific exemption from Qualified Person or Competent Person accountability: where a machine-learning tool informs a resource estimate, the QP or CP remains fully responsible for understanding, validating, and documenting that output. The 2022 Gatos Silver matter illustrates the magnitude of what estimation-governance failure can produce, independent of the tooling involved: a technical-report error triggered a reserve restatement and a single-day equity decline of approximately 69%.

Beneath jurisdiction-specific rules, a common methodological layer is consolidating quickly. NIST's AI Risk Management Framework — organized around the four functions of Govern, Map, Measure, and Manage — is emerging as the default reference point, reinforced by a forthcoming Critical Infrastructure Profile whose concept note addresses physics-informed AI and autonomous vehicles with fail-safe controllers directly. ISO/IEC 42001 is now the first certifiable international standard for AI management systems, and is increasingly appearing in enterprise procurement and RFP language. Lenders, insurers, and joint-venture partners are beginning to reference both.

A regulatory landscape moving at uneven speed

Trajectory matters as much as current state

For operators with cross-border footprints, the trajectory of regulation matters as much as its current state. The European Union has delayed enforcement of Annex III high-risk obligations to December 2027 under the Digital Omnibus process. The United States federal government is pursuing deregulation and state-law preemption, while individual states — Colorado and Texas among them — continue to legislate independently. Canada's federal AI bill lapsed with the prorogation of Parliament in January 2025, leaving the country to operate from a broader national strategy rather than a binding statute. Chile, Brazil, Peru, and South Africa are each developing EU-style, risk-tiered regimes, at differing stages of enactment.

This divergence is not a rationale for deferring governance work. It is a rationale for structuring a governance program around actual AI use cases and their associated risk level, rather than around the legislative calendar of any single jurisdiction.

Three priorities for the current quarter

Where governance maturity clusters — and what closes the gap

Across the operators LOMexcel has engaged with, governance maturity clusters in a narrow band: most have no formal AI inventory, or have governed only the one or two systems that are self-evidently significant — typically the autonomous haulage fleet or a major enterprise platform. The recurring gaps are consistent: no documented human-oversight process for AI-assisted resource estimation, no vendor due-diligence process specific to AI procurement despite the majority of mining AI being vendor-supplied, and no executive formally accountable for AI risk.

01

Complete an AI inventory

Include informally adopted generative-AI tools, not only sanctioned enterprise systems.

02

Designate an accountable executive

A named executive with board-level accountability for AI risk across the organization.

03

Document override authority

In writing, the individual with authority — and training — to override the highest-consequence AI system: autonomous haulage, tailings monitoring, or resource estimation.

These three steps establish the foundation from which the remainder of a governance program can be built.

The Checklist

The Global AI Governance Checklist for Mining Operators

LOMexcel has consolidated the research underlying this analysis — every jurisdiction, every standard, and every mining-specific technical requirement, supported by more than seventy primary-source citations — into a single working document. It is designed for direct use by leadership teams, technical leads, and HSE or legal counsel: a structured basis for assessing current governance posture and prioritizing remediation, rather than a document to be filed away.

Strategic Engagement

Move from reading about AI governance to operating it.

A complimentary 30-minute AI discovery call to discuss your organization's current position — risk assessment, vendor due diligence, board-level policy, or a jurisdiction-specific roadmap.