How Frontier AI Is Actually Governed — A Layered Map

As of 11 August 2026. Scope: global, weighted toward the US, EU and UK, where frontier developers are headquartered, regulated and sued.

How to read this. Nothing here governs frontier AI on its own. The system is a stack of partially overlapping regimes in which the binding layers borrow their substance from the voluntary ones, and the voluntary ones borrow their credibility from the threat of the binding ones. The Key dependencies column is the important one — it is where the map stops being a list and becomes a system.

Binding force key: HARD = legally enforceable · SOFT-BINDING = legal effect conditional on adoption or self-designation · VOLUNTARY = reputational/contractual only · STRUCTURAL = operates through control of an input, not a rule


Layer 0 — Material & chokepoint governance

Control over the physical inputs to frontier training. The only layer that can constrain a developer that ignores every other layer.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
US export controls (BIS / Commerce) — ECCN 3A090/4A090, FDPR, entity listingsChip designers, fabs, cloud resellers, ultimately foreign labsHARDLicensing of advanced AI accelerators and semicap equipment by destination and end-userCriminal/civil penalties, denial orders, entity list; extraterritorial via foreign direct product ruleTSMC/ASML concentration; allied alignment (NL, JP); customs enforcement; political willLoosened. 13 Jan 2026 rule permits H200 / MI325X-class exports to China, codifying the Dec 2025 policy reversal. Commerce moved 31 May 2026 to close the “Chinese firms offshore” loophole. Net: chokepoint intact in form, weakened in substance
GAIN AI Act (proposed US domestic-priority allocation)US chipmakers— (not law)Would have required domestic order priority before exportNoneCongressional floor time; NVIDIA lobbyingDropped from the NDAA after industry lobbying; hardliners regrouping around a “Secure and Feasible Exports Act”
TSMC / ASML / HBM suppliersEvery frontier developerSTRUCTURALDe facto sole-source for leading-edge logic, EUV and high-bandwidth memoryAllocation decisions, refusal to supplyTaiwan Strait stability; export-control law they must implementLoad-bearing and single-point-of-failure. The true hard constraint on who can train at frontier scale
Hyperscale cloud providers (Microsoft, Google, AWS, Oracle, CoreWeave)Model developers and downstream deployersSTRUCTURAL + contractualKYC on large training runs, acceptable-use policies, capacity allocation, security requirements for weightsContract termination, capacity denialTheir own commercial entanglement with the labs they would policeConflicted by design — Microsoft/OpenAI, Amazon–Google/Anthropic mean the “regulator” is also the investor
Energy & grid regulators / data-centre siting (FERC, state PUCs, national grids)Compute buildoutHARD (but not AI-specific)Interconnection queues, siting permits, ratepayer allocationPermit denialLocal politics; explicitly carved out of US federal preemption effortsEmerging as the most politically live constraint on scaling; governs pace, not model behaviour

Layer 1 — Corporate / internal governance

Firm-level structures. Fastest-moving layer; the source of most substantive safety practice; the weakest in accountability.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
Anthropic Responsible Scaling PolicyAnthropicVOLUNTARY (now partly SOFT-BINDING via CA/NY/IL law and the EU Code)Capability thresholds (ASL levels) gate deployment and security standards; published Frontier Safety Roadmaps and Risk ReportsBoard/LTBT oversight; public commitment; now referenced by statuteInternal eval quality; LTBT independence; competitive parityv3.0 (24 Feb 2026), amended to v3.1. Replaced the “hard pause” trigger with a tiered ASL-3 security standard plus graded public roadmaps
OpenAI Preparedness FrameworkOpenAIVOLUNTARYTracked capability categories, High/Critical thresholds, safeguards before deploymentSafety & Security Committee, which sits at the Foundation level and can require mitigations including halting a releaseFoundation’s willingness to use its authority against commercial pressureIn force; contains an explicit “adjust if a competitor ships without comparable safeguards” clause — a formalised race-to-the-bottom valve
Google DeepMind Frontier Safety FrameworkGoogle DeepMindVOLUNTARYCritical Capability Levels with response plans across CBRN, cyber, manipulation, ML R&DInternal review councilsAlphabet-level product pressurev3 lineage in force
Meta Frontier AI Framework; xAI Risk Management Framework; Microsoft Frontier Governance FrameworkRespective firmsVOLUNTARYAnalogous threshold-and-mitigation structures, materially thinner in placesInternal onlyFirm leadership commitmentIn force; treated by most analysts as the floor of the practice, not the frontier of it
Anthropic Long-Term Benefit TrustAnthropic board compositionSTRUCTURAL (corporate law)Independent, financially disinterested trustees elect a growing share of the boardBoard appointment/removalDelaware PBC law; investor acquiescence; unresolved question of whether stockholders can amend it awayOperative; independence contested in the literature. IPO speculation raises the stakes
OpenAI Foundation / OpenAI Group PBCOpenAISTRUCTURALNonprofit Foundation holds equity in and appoints/removes directors of the PBC; retains exclusive control of the Safety & Security CommitteeBoard control; CA and DE AG memoranda of understandingFoundation board independence; state AG appetite to enforceRestructuring completed Oct 2025. The AGs are now, in effect, standing supervisors of OpenAI’s mission
Internal audit / model welfare / policy functionsAll major labsVOLUNTARYSecond- and third-line assurance inside the firm; incident reviewNone externalReporting lines; budgetEmerging; Illinois’ audit mandate (2028) is the first law to force this outward
Whistleblower channelsLab employeesNow HARD in CA / NY / ILProtected internal and regulator-facing disclosure about catastrophic riskState AG enforcement; anti-retaliation remediesEmployees knowing the protections exist; NDA/equity-clawback practicesStatutory in three US states; the main mechanism by which internal facts reach external actors

Layer 2 — Voluntary & collective commitments

The negotiated middle. Where practice is standardised across firms before any legislature codifies it.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
EU GPAI Code of Practice (Safety & Security, Transparency, Copyright chapters)GPAI model providers in the EU marketSOFT-BINDING — voluntary to sign, but signature is the practical route to presumed complianceModel documentation, systemic-risk assessment, incident reporting, copyright policyNon-signatories face heavier RFIs; signature is a mitigating factor in fine-setting; adherence monitored by the AI OfficeAI Office capacity; the underlying AI Act Arts. 53/55Final text July 2025. Signed by OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral and others; Meta declined; xAI signed only the safety chapter. Becomes materially consequential 2 Aug 2026 when fines switch on
Seoul Frontier AI Safety Commitments (2024)~20 frontier developers across US, EU, UK, China, UAEVOLUNTARYPublish a safety framework with capability thresholds and unacceptable-risk red linesReputational; summit-cycle reportingSummit continuity; a convening state willing to chase complianceThe template that CA SB 53, NY RAISE, IL SB 315 and the EU Code all converged on. Its own follow-up has weakened as the summit agenda shifted
New Delhi Frontier AI Commitments (19 Feb 2026)Frontier developers plus Indian firmsVOLUNTARYShared anonymised deployment insights on labour, productivity and economic impactNoneCompany participationNew. Notably not a safety instrument — evidence of the agenda shift from risk to diffusion
White House Voluntary Commitments (2023)15+ US developersVOLUNTARYRed-teaming, watermarking, information sharingNoneExecutive-branch interestLargely superseded; retained mainly as precedent
Frontier Model ForumMember labs (Anthropic, Google, Microsoft, OpenAI, Amazon, Meta)VOLUNTARYTechnical reports on thresholds, third-party assessment, security; a shared vocabulary for the whole stackNoneMember consensus, i.e. lowest-common-denominator riskActive and quietly load-bearing: its definitions propagate into statutes
Partnership on AI, MLCommons (AILuminate), AI Safety Institute ConsortiumBroad multistakeholderVOLUNTARYBenchmarks, deployment guidance, safe-model practiceNoneFunding; member goodwillOngoing; benchmark work increasingly cited in procurement

Layer 3 — Standards, assurance & evaluation

The connective tissue. Turns abstract legal duties into testable claims — and is the current bottleneck.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
CEN-CENELEC JTC 21EU AI Act complianceSOFT-BINDING → HARD on OJEU listingHarmonised standards conferring presumption of conformityPresumption of conformity is the legal payoffCommission standardisation request; expert capacity; consensus among national bodiesThe critical path failure. Originally due Aug 2025, slipped repeatedly; exceptional acceleration measures adopted, target Q4 2026. Standards absence was a principal justification for the Digital Omnibus deferrals
EN ISO/IEC 42001 (AI management systems)Any organisationVOLUNTARY certificationManagement-system certification; a governance-process claim, not a model-safety claimCertification withdrawalAccredited certification bodiesAdopted by CEN as EN ISO/IEC 42001:2026. Widely used as a procurement proxy; not yet a harmonised standard conferring presumption of conformity
NIST AI RMF + Generative AI ProfileVoluntary, US-anchoredVOLUNTARYRisk-management taxonomy that most corporate programmes are built onNoneNIST/CAISI resourcing and political directionThe de facto US common language; embedded by reference in contracts and state law
CAISI (US Center for AI Standards and Innovation)Participating developersVOLUNTARYPre-deployment evaluation, security testing, standards workNone — evaluation, not authorisationVoluntary lab access agreements; Commerce leadershipUnder the 2 June 2026 EO, runs the 30-day pre-release cyber review. Directed to stop publishing frontier evaluation findings — contested in Congress. A measurement body whose measurements are no longer public
UK AI Security InstituteParticipating developersVOLUNTARYPre-deployment evals, red-teaming, safeguard testing, foundational researchNone — no authorisation powerVoluntary access; DSIT budgetThe most technically capable public evaluator; secretariat for the International AI Safety Report; network coordinator
Independent evaluators — METR, Apollo Research, SecureBio, FAR.AIContracted by labs / AISIsVOLUNTARY / contractualAutonomy and scheming evaluations, bio uplift testing, adversarial assessmentPublication; refusal to certifyModel access grants; funding; NDA terms; evaluation-awareness in models degrading validityReal but structurally fragile: dependent on the goodwill of the entity being evaluated. Illinois’ 2028 audit mandate is the first attempt to make this compulsory
Accredited audit marketFrontier developers (IL from 2028)HARD (IL only)Annual independent safety audit by conflict-free qualified expertsAG referralExistence of qualified, independent auditors — which is not yet establishedNascent. The supply of credible auditors is the binding constraint on the whole assurance layer

Layer 4 — State institutional capacity

Who can actually look inside a frontier model on behalf of the public.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
European AI Office (DG CNECT)GPAI providersHARDSole supervisor of GPAI models: document requests, model evaluations, mitigation demands, market restriction, finesUp to 3% global turnover or €15MTechnical staffing; harmonised standards; Member State cooperationPowers activate 2 Aug 2026. The single most consequential institutional change of the year. Capacity remains widely questioned
European AI Board, Scientific Panel of Independent Experts, Advisory ForumCoordinationAdvisoryMember State coordination; qualified alerts on systemic risk to the AI OfficeIndirectAppointments and fundingOperating; the Scientific Panel is the intended technical alarm channel into the AI Office
National market surveillance authorities (EU)AI systems (not GPAI models)HARDEnforce system-level obligationsFines, withdrawalMember State designation and resourcingUneven; several states behind on designation
DSIT / UK AISIUKAdvisory + researchEvaluation, national-security risk assessment, AI Growth Lab regulatory sandboxingNone directly; sector regulators (ICO, Ofcom, FCA, MHRA) hold the powersExisting sectoral statutes; no AI Act to anchor itNo UK AI Act and none scheduled. AI Growth Lab launched 8 Jun 2026 (legal services first). UK governs frontier AI through capability and access, not law
US federal — CAISI, OSTP, OMB, DOJ AI Litigation Task ForceFederal postureMixedProcurement standards (OMB M-memos), voluntary evaluation, and active federal litigation against state AI lawsDOJ can sue states; OMB binds federal buyersExecutive discretion; Article III courtsEO 14257 (11 Dec 2025) directed preemption; DOJ Task Force operational since 9–10 Jan 2026; Commerce review of “burdensome” state laws due 11 Mar 2026
Cal OES, NY DFS AI office, Illinois EMA + AGsFrontier developersHARDReceive incident reports, publish anonymised summaries, enforceState AG civil penaltiesState budgets; survival of state law against preemptionThe only functioning mandatory incident-reporting pipeline in the US
Cyberspace Administration of China (CAC)Chinese model providersHARDAlgorithm and generative-service filing, security assessment, corpus review, mandatory content labellingService suspension, market exclusionParty-state administrative capacityFully operational; labelling regime in force since 1 Sep 2025. Application- and content-centric; catastrophic-risk framing largely absent
Korea MSITAI in KoreaHARDHigh-impact AI duties, generative-AI labelling, domestic representative requirementFines to KRW 30MEnforcement decree; capacityAI Framework Act in force 22 Jan 2026; one-year penalty grace period — guidance-first enforcement

Layer 5 — Hard law

Binding obligations that attach specifically to frontier model development.

Actor / InstrumentWho it governsBinding forceWhat it actually requiresEnforcement teethKey dependenciesStatus (Aug 2026)
EU AI Act, Arts. 53 & 55 (GPAI + systemic risk)Providers placing GPAI models on the EU market; systemic-risk tier presumed above 1025 FLOPHARDTechnical documentation, training-data summary, copyright policy; for systemic risk: model evaluation, adversarial testing, systemic-risk mitigation, serious-incident reporting, cybersecurity of weightsAI Office fines up to 3% / €15M; market restrictionCode of Practice as the compliance route; AI Office capacity; extraterritorial reach via market accessObligations in force since 2 Aug 2025; enforcement powers live 2 Aug 2026. Untouched by the Digital Omnibus
EU Digital Omnibus on AIAI Act timelineHARDDefers Annex III high-risk duties to 2 Dec 2027 and Annex I to 2 Aug 2028; adds prohibited practices; scope clarificationsStandards readinessPublished in the OJ 24 Jul 2026, in force 27 Jul 2026. Art. 50 transparency duties still apply from 2 Aug 2026
California TFAIA (SB 53)“Large frontier developers”: >1026 FLOP models and >$500M revenueHARDPublish a frontier AI framework; publish a transparency report before deploying a new or substantially modified model; report critical safety incidents to Cal OES (15 days; 24h where risk is imminent); whistleblower protectionsAG civil penalties up to $1M per violationSurvival against DOJ preemption suits; Cal OES capacity; annual CDT threshold reviewIn force since 1 Jan 2026. The de facto US baseline and the template for NY and IL
New York RAISE Act (as amended)Frontier developers with >$500M revenue; 1026 FLOP / $100M computeHARDSafety protocol publication, incident reporting, third-party-aligned transparencyCivil penalties; new DFS oversight officePreemption litigation; DFS standing up the officeChapter amendment signed 27 Mar 2026, aligning it closely to California. Effective 1 Jan 2027
Illinois AI Safety Measures Act (SB 315)Frontier developersHARDFrontier AI framework covering catastrophic risk, mitigations, cybersecurity, internal governance, third-party evals and risk from internal model use; 72-hour incident reporting; annual independent third-party auditAG enforcementExistence of qualified independent auditorsSigned 6 Jul 2026; effective 1 Jan 2027; audits from 1 Jan 2028. First US mandate for external verification rather than self-attestation
US EO 14365 — “Ensuring a National Policy Framework for AI”States, indirectlyHARD (executive)Directs DOJ litigation against state AI laws, Commerce review of “burdensome” state laws, FTC policy statement, FCC proceeding; conditions certain federal fundsFederal litigation; funding leverageArticle III courts; dormant Commerce Clause and preemption doctrineSigned 11 Dec 2025; White House legislative recommendations followed in Mar 2026. Expressly carves out child safety, compute/data-centre infrastructure and state procurement. The central legal conflict in US AI governance right now
US EO (2 Jun 2026) — “Promoting Advanced AI Innovation and Security”Frontier developers (voluntarily)HARD on agencies, VOLUNTARY for labsAgencies to design a voluntary pre-release engagement framework by 1 Aug 2026; 30-day CAISI cyber review of volunteered models; classified capability benchmarking by Treasury/NSA/CISANone on developers — explicitly not a licensing or preclearance regimeLab participation; agency capacityIn force. The US federal government’s frontier-model posture is now: evaluate voluntarily, publish nothing, preempt the states
Great American AI Act (discussion draft)Large frontier developers >$500M revenueNot lawFederal transparency, critical-incident reporting, whistleblower protection, independent verification organisations — plus a three-year preemption of state laws governing model development (states keep authority over use)Would be federalCommittee jurisdiction fights; House–Senate divergence; the preemption bargainBipartisan draft released 4 Jun 2026 (Obernolte/Trahan), 269 pages. Referred to committee, no votes. The pivotal open variable for 2027
Council of Europe Framework Convention on AI (CETS 225)Signatory states’ public-sector and, at each party’s election, private-sector AIHARD (on states, via implementation)Human rights, democracy and rule-of-law obligations across the AI lifecycleState implementation; no supranational court specific to itNational ratification and transpositionIn force since 1 Nov 2025 (UK, France, Norway among early ratifiers). EU ratified 15 May 2026; effects for the Union from 1 Sep 2026. First binding international AI treaty; obligations largely restate what the AI Act already does for the EU. The US signed in 2024 but has not ratified
China: Generative AI Interim Measures, Deep Synthesis Provisions, Algorithm Filing, AI Labelling MeasuresProviders serving the Chinese publicHARDPre-launch filing and security assessment, corpus and content controls, mandatory implicit and explicit labelling of synthetic contentService suspension, penaltiesCAC administrative reachFully in force; labelling since 1 Sep 2025. A comprehensive national AI Law remains draft

Layer 6 — Judicial & liability

Fast-moving, retrospective, and increasingly the binding constraint on deployment behaviour — set by courts rather than legislatures.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
Product liability litigation — e.g. In re: ChatGPT Product Liability Cases, JCCP No. 5431 (Cal. Super. Ct., coordinated 3 Feb 2026)Model deployersHARDTests whether a model is a “product”; defective-design theories aimed at engagement maximisationDamages, injunctive settlement terms, discovery into internal safety recordsJudicial receptiveness; Section 230’s continued erosion in this contextA dozen-plus coordinated wrongful-death and injury cases. Courts have declined to treat chatbots as categorically non-products
Wrongful death / minor safety claims (Character.AI, Google, OpenAI)Consumer-facing deployersHARDDuty-of-care claims over self-harm, minors, and manipulationDamages; settlementsPlaintiff-bar capacity — Edelson and others are now specialisedCharacter.AI and Google settled multiple suits in Jan 2026. Settlements set de facto product-design standards without any legislature acting
Copyright litigation & settlementsTraining-data practiceHARDFair-use boundaries for training corpora; class certification riskStatutory damages at ruinous scale — one certified class settled at $1.5BCircuit splits; class-certification rulingsThe largest financial exposure in the sector; drives licensing deals and data provenance practice
State AG oversight (CA, DE, and others)OpenAI’s structure; consumer protection generallyHARDCharitable-trust supervision of the OpenAI restructuring; UDAP authority over AI claimsInjunctions, structural remediesAG priorities and resourcingStanding supervisory relationship — one of the few external checks on a lab’s governance structure rather than its outputs
Insurance marketDeployers and, increasingly, developersSTRUCTURALPrices and excludes AI risk; ISO GL exclusion forms (CG 40 47/48, CG 35 08) effective Jan 2026Coverage denialLoss data; modelling of correlated failureEnd of “silent AI” coverage. Analysts now model foundation-model failure as a systemic, cat-bond-like peril. Uninsurability is becoming a governance signal in its own right

Layer 7 — International & multilateral

Broad legitimacy, thin obligation. Sets agenda and vocabulary, not conduct.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
UN Independent International Scientific Panel on AIAdvisory40 experts serving in personal capacity; annual evidence synthesis for the Global DialogueNoneMember State funding; expert independenceEstablished Aug 2025; preliminary report published 1 Jul 2026
UN Global Dialogue on AI GovernanceAdvisoryAnnual intergovernmental + multistakeholder forumNoneGreat-power participationFirst session Geneva, 6–7 Jul 2026: 4,200+ participants, ~170 states. Second session New York, 3–4 May 2027
International AI Safety Report (Bengio-chaired, UK AISI secretariat)EvidentiaryConsensus scientific synthesis; names the “evidence dilemma” — act early and entrench weak rules, or wait and absorb the harmNoneContributor participation; government uptake2nd edition Feb 2026: 100+ researchers, 30+ countries. The single most-cited shared evidence base across all layers
AI summit series (Bletchley → Seoul → Paris → New Delhi)VOLUNTARYProduces commitments and declarations; sets the global frameNoneHost state agendaNew Delhi Declaration, Feb 2026: 89 countries/organisations. Seven pillars centred on capacity, access, trustworthiness, energy, science, democratisation and growth. The frame has shifted decisively from safety to impact and diffusion
International Network of AI Safety/Security InstitutesMember institutesVOLUNTARYJoint testing exercises, shared evaluation methodology, interoperability of reportsNoneUS participation; institute budgetsActive, UK coordinating; reoriented toward measurement and evaluation science. Weakened by CAISI’s publication restrictions
OECD AI Principles, GPAI, G7 Hiroshima Process + HAIP reporting frameworkAdhering states and companiesVOLUNTARYPrinciples, a company transparency-reporting template, incident monitoring (AIM)NoneVoluntary reporting qualityOperating; HAIP reports are one of the few cross-jurisdiction, like-for-like company disclosures
Bilateral / plurilateral chip and compute diplomacyAllied export-control alignmentMixedAligns Dutch, Japanese, Korean controls with US policy; governs sovereign-AI deals (UAE, KSA)National lawUS policy stability — which has been lowVolatile; the Jan 2026 loosening reduced allied confidence in the durability of any shared line

Layer 8 — Market, financial & epistemic

Not usually drawn as governance. In practice it decides what gets built and what gets known.

Actor / InstrumentWho it governsBinding forceWhat it actually doesEnforcement teethKey dependenciesStatus (Aug 2026)
Investors and capital marketsDeveloper strategySTRUCTURALSet growth expectations; IPO readiness imposes disclosure and control-structure scrutinyCapital withdrawal; term-sheet governance rightsReturn expectations vs mission structuresThe dominant force on lab behaviour. Mission-lock structures (LTBT, OpenAI Foundation) exist precisely to resist it, and are being tested
Enterprise and government procurementDeployers, then developersContractual → HARDSecurity, indemnity, evaluation and provenance requirements flowed down through contractsContract lossBuyer sophistication; standards to point at (ISO 42001, NIST AI RMF)Frequently faster and more specific than regulation; the main channel by which soft standards acquire real force
Academic and independent research (GovAI, IAPS, RAND, CSET, AI Now, Ada Lovelace, arXiv literature)AgendaEpistemicSupplies the concepts — thresholds, evals, structured access, audits — that legislatures then codifyNoneFunding independence from labsHigh influence and a genuine conflict-of-interest problem: much of the field is lab-funded
Journalism, leaks, and employee disclosureAccountabilityEpistemicSurfaces what no disclosure regime capturesReputational; triggers regulator actionWhistleblower protections (CA/NY/IL); source protectionHistorically the highest-yield accountability mechanism in this sector
Open-weight release ecosystem (Meta, Mistral, Qwen, DeepSeek, HF)DiffusionSTRUCTURALOnce weights are released, every downstream control in this map becomes unenforceableNone post-releaseRelease decisions of a handful of firmsThe irreversibility problem. Governed almost entirely by unilateral corporate choice

Dependency analysis — where the load actually sits

1. The binding layers are hollow without the voluntary ones. California SB 53, the NY RAISE Act, Illinois SB 315 and the EU Code of Practice all require developers to publish “a frontier AI framework” — a category invented by the labs themselves (RSP, Preparedness, FSF) and standardised by the Frontier Model Forum. Legislatures codified the shape of the artefact and left the substance — where thresholds sit, what counts as sufficient mitigation — to the regulated firms. The hard law is a disclosure wrapper around private standard-setting.

2. Two chokepoints carry disproportionate load. Harmonised standards (CEN-CENELEC): their absence already forced the Digital Omnibus deferrals, and until they are OJEU-listed there is no presumption of conformity for anyone. Independent auditors: Illinois mandates external audits from 2028, and the Great American AI Act contemplates “independent verification organisations” — but a credible, conflict-free audit profession does not yet exist at the necessary scale. Both are supply-side bottlenecks that no amount of legislative will can shortcut.

3. Evaluation capacity is publicly funded but privately controlled. UK AISI, CAISI, METR and Apollo all depend on voluntary access agreements with the entities they assess. No jurisdiction has legislated a right of pre-deployment access. CAISI’s directive to stop publishing findings severs the last step of the chain: evaluation without publication informs the executive branch and nobody else. Add evaluation-awareness in models degrading test validity, and the measurement layer is weaker in mid-2026 than it was a year ago.

4. The US federal–state conflict is the system’s main instability. The only mandatory frontier incident-reporting pipeline anywhere in the US runs through three state agencies. EO 14257 and the DOJ AI Litigation Task Force exist to dismantle the legal basis for those laws; the Great American AI Act would preempt state authority over model development for three years in exchange for a federal transparency regime. Whether the US has any binding frontier disclosure regime in 2028 turns on that trade landing, or on the courts.

5. Liability is outrunning regulation. Coordinated product-liability proceedings, chatbot wrongful-death settlements, a $1.5B copyright class settlement, and ISO general-liability exclusions effective January 2026 are changing deployment design faster than any statute. Notably, this is the one layer that reaches consumer-facing deployment behaviour, which the frontier-safety statutes — all focused on catastrophic risk — barely touch.

6. Extraterritoriality does the harmonising work. With no binding international instrument that constrains frontier developers directly, EU market access (AI Act), California’s presence as home jurisdiction, and US export controls do the global coordination. The CoE Framework Convention is binding in form but restates existing EU obligations in substance.

7. The frame itself has shifted. Bletchley (2023) was about catastrophic risk. New Delhi (Feb 2026) is about impact, diffusion, energy and access — 89 signatories, and the frontier commitments attached to it concern economic deployment data, not safety. Meanwhile the binding safety instruments (SB 53, RAISE, SB 315, AI Act Art. 55) all landed after the political attention moved on. Implementation is now proceeding in a colder political climate than the one that produced it.

8. Feedback loops worth watching.

  • Capability → threshold → obligation: compute thresholds (1025 FLOP EU, 1026 FLOP US states) mechanically expand coverage as training scales, but algorithmic efficiency erodes them from below. California’s annual CDT review is the only built-in recalibration.
  • Incident → report → rule: Cal OES / DFS / IEMA reporting is designed to generate the evidence base that justifies the next round of rules. Its output is anonymised and aggregated, which limits how much it can actually prove.
  • Race dynamics → framework erosion: OpenAI’s Preparedness Framework contains an explicit competitive-adjustment clause, and Anthropic’s RSP v3.0 replaced a hard pause with graded roadmaps. Voluntary commitments loosen under competitive pressure in exactly the conditions where they would matter most — which is the strongest available argument for statutory floors.

Uncertainty flags

  • The International Network of AI Safety Institutes appears to have been renamed/refocused around measurement and evaluation science; the precise current designation is reported inconsistently across sources.
  • CAISI’s publication restrictions are recent and contested in Congress (Sen. Budd’s June 2026 letter); the operative scope may change.
  • The Great American AI Act is a discussion draft with no votes recorded — treat every provision as provisional.
  • Preemption litigation outcomes are unresolved; any row describing a US state obligation is contingent on that litigation.
  • Compute thresholds and revenue triggers are subject to statutory review mechanisms and may move.
  • Executive order numbering for the 2 Jun 2026 frontier AI / cybersecurity EO is reported inconsistently across firm alerts; the title (“Promoting Advanced Artificial Intelligence Innovation and Security”) is the reliable identifier.

Sources

EU: Digital Omnibus (Freshfields) · Gibson Dunn on the Omnibus · GPAI Code of Practice · Enforcement of Chapter V · How much power does the AI Office have? (Lawfare) · Commission GPAI guidelines

Standards: CEN-CENELEC AI · Standards and the EU AI Act · ISO 42001 and presumption of conformity

US states: California SB 53 (White & Case) · SB 53 compliance guide (Nelson Mullins) · Brookings on California’s AI safety law · NY RAISE Act finalised (Wiley) · NY amendments (MoFo) · Illinois SB 315 (Crowell) · Illinois audits (Latham)

US federal: EO 14365 text (White House) · EO 14365 unpacked (Sidley) · Preemption EO (Lawfare) · Preemption EO (Paul Hastings) · June 2026 frontier AI EO (Skadden) · June 2026 EO (Latham) · Great American AI Act (TechPolicy.Press) · GAAIA vs state laws (FPF) · Budd letter on CAISI publication

Compute & export controls: New AI chip export policy (CFR) · GAIN AI Act (CSIS) · Commerce move on offshore Chinese entities (CNBC)

Corporate: Anthropic RSP · RSP v3.0 analysis (GovAI) · Frontier Safety Roadmap updates · Anthropic Long-Term Benefit Trust · OpenAI restructure explained (Transformer)

Assurance & evaluation: FMF third-party assessments · OpenAI on third-party evaluations · METR frontier risk report · Evaluation awareness (IAPS) · Secure third-party access (RUSI) · OpenAI on CAISI/UK AISI work · International network next steps (CSIS)

International: UN Global Dialogue on AI Governance · Scientific Panel preliminary report · UN News on the Geneva dialogue · India AI Impact Summit outcomes (Brookings) · New Delhi Declaration (PIB) · CoE Framework Convention · EU ratification

Asia: Korea AI Framework Act in force (Library of Congress) · Korea AI Basic Act overview (Cooley) · China AI labelling measures · China AI regulation tracker

UK: UK AI regulation in 2026 (Bratby Law) · AISI blog

Liability & insurance: ChatGPT product liability coordination · AI lawsuits filed (Edelson) · Emerging AI exclusions (Fenwick) · Insurer interest in AI exclusions · The insurability frontier of AI risk