How Frontier AI Is Actually Governed — A Layered Map
As of 11 August 2026. Scope: global, weighted toward the US, EU and UK, where frontier developers are headquartered, regulated and sued.
How to read this. Nothing here governs frontier AI on its own. The system is a stack of partially overlapping regimes in which the binding layers borrow their substance from the voluntary ones, and the voluntary ones borrow their credibility from the threat of the binding ones. The Key dependencies column is the important one — it is where the map stops being a list and becomes a system.
Binding force key: HARD = legally enforceable · SOFT-BINDING = legal effect conditional on adoption or self-designation · VOLUNTARY = reputational/contractual only · STRUCTURAL = operates through control of an input, not a rule
Layer 0 — Material & chokepoint governance
Control over the physical inputs to frontier training. The only layer that can constrain a developer that ignores every other layer.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| US export controls (BIS / Commerce) — ECCN 3A090/4A090, FDPR, entity listings | Chip designers, fabs, cloud resellers, ultimately foreign labs | HARD | Licensing of advanced AI accelerators and semicap equipment by destination and end-user | Criminal/civil penalties, denial orders, entity list; extraterritorial via foreign direct product rule | TSMC/ASML concentration; allied alignment (NL, JP); customs enforcement; political will | Loosened. 13 Jan 2026 rule permits H200 / MI325X-class exports to China, codifying the Dec 2025 policy reversal. Commerce moved 31 May 2026 to close the “Chinese firms offshore” loophole. Net: chokepoint intact in form, weakened in substance |
| GAIN AI Act (proposed US domestic-priority allocation) | US chipmakers | — (not law) | Would have required domestic order priority before export | None | Congressional floor time; NVIDIA lobbying | Dropped from the NDAA after industry lobbying; hardliners regrouping around a “Secure and Feasible Exports Act” |
| TSMC / ASML / HBM suppliers | Every frontier developer | STRUCTURAL | De facto sole-source for leading-edge logic, EUV and high-bandwidth memory | Allocation decisions, refusal to supply | Taiwan Strait stability; export-control law they must implement | Load-bearing and single-point-of-failure. The true hard constraint on who can train at frontier scale |
| Hyperscale cloud providers (Microsoft, Google, AWS, Oracle, CoreWeave) | Model developers and downstream deployers | STRUCTURAL + contractual | KYC on large training runs, acceptable-use policies, capacity allocation, security requirements for weights | Contract termination, capacity denial | Their own commercial entanglement with the labs they would police | Conflicted by design — Microsoft/OpenAI, Amazon–Google/Anthropic mean the “regulator” is also the investor |
| Energy & grid regulators / data-centre siting (FERC, state PUCs, national grids) | Compute buildout | HARD (but not AI-specific) | Interconnection queues, siting permits, ratepayer allocation | Permit denial | Local politics; explicitly carved out of US federal preemption efforts | Emerging as the most politically live constraint on scaling; governs pace, not model behaviour |
Layer 1 — Corporate / internal governance
Firm-level structures. Fastest-moving layer; the source of most substantive safety practice; the weakest in accountability.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| Anthropic Responsible Scaling Policy | Anthropic | VOLUNTARY (now partly SOFT-BINDING via CA/NY/IL law and the EU Code) | Capability thresholds (ASL levels) gate deployment and security standards; published Frontier Safety Roadmaps and Risk Reports | Board/LTBT oversight; public commitment; now referenced by statute | Internal eval quality; LTBT independence; competitive parity | v3.0 (24 Feb 2026), amended to v3.1. Replaced the “hard pause” trigger with a tiered ASL-3 security standard plus graded public roadmaps |
| OpenAI Preparedness Framework | OpenAI | VOLUNTARY | Tracked capability categories, High/Critical thresholds, safeguards before deployment | Safety & Security Committee, which sits at the Foundation level and can require mitigations including halting a release | Foundation’s willingness to use its authority against commercial pressure | In force; contains an explicit “adjust if a competitor ships without comparable safeguards” clause — a formalised race-to-the-bottom valve |
| Google DeepMind Frontier Safety Framework | Google DeepMind | VOLUNTARY | Critical Capability Levels with response plans across CBRN, cyber, manipulation, ML R&D | Internal review councils | Alphabet-level product pressure | v3 lineage in force |
| Meta Frontier AI Framework; xAI Risk Management Framework; Microsoft Frontier Governance Framework | Respective firms | VOLUNTARY | Analogous threshold-and-mitigation structures, materially thinner in places | Internal only | Firm leadership commitment | In force; treated by most analysts as the floor of the practice, not the frontier of it |
| Anthropic Long-Term Benefit Trust | Anthropic board composition | STRUCTURAL (corporate law) | Independent, financially disinterested trustees elect a growing share of the board | Board appointment/removal | Delaware PBC law; investor acquiescence; unresolved question of whether stockholders can amend it away | Operative; independence contested in the literature. IPO speculation raises the stakes |
| OpenAI Foundation / OpenAI Group PBC | OpenAI | STRUCTURAL | Nonprofit Foundation holds equity in and appoints/removes directors of the PBC; retains exclusive control of the Safety & Security Committee | Board control; CA and DE AG memoranda of understanding | Foundation board independence; state AG appetite to enforce | Restructuring completed Oct 2025. The AGs are now, in effect, standing supervisors of OpenAI’s mission |
| Internal audit / model welfare / policy functions | All major labs | VOLUNTARY | Second- and third-line assurance inside the firm; incident review | None external | Reporting lines; budget | Emerging; Illinois’ audit mandate (2028) is the first law to force this outward |
| Whistleblower channels | Lab employees | Now HARD in CA / NY / IL | Protected internal and regulator-facing disclosure about catastrophic risk | State AG enforcement; anti-retaliation remedies | Employees knowing the protections exist; NDA/equity-clawback practices | Statutory in three US states; the main mechanism by which internal facts reach external actors |
Layer 2 — Voluntary & collective commitments
The negotiated middle. Where practice is standardised across firms before any legislature codifies it.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| EU GPAI Code of Practice (Safety & Security, Transparency, Copyright chapters) | GPAI model providers in the EU market | SOFT-BINDING — voluntary to sign, but signature is the practical route to presumed compliance | Model documentation, systemic-risk assessment, incident reporting, copyright policy | Non-signatories face heavier RFIs; signature is a mitigating factor in fine-setting; adherence monitored by the AI Office | AI Office capacity; the underlying AI Act Arts. 53/55 | Final text July 2025. Signed by OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral and others; Meta declined; xAI signed only the safety chapter. Becomes materially consequential 2 Aug 2026 when fines switch on |
| Seoul Frontier AI Safety Commitments (2024) | ~20 frontier developers across US, EU, UK, China, UAE | VOLUNTARY | Publish a safety framework with capability thresholds and unacceptable-risk red lines | Reputational; summit-cycle reporting | Summit continuity; a convening state willing to chase compliance | The template that CA SB 53, NY RAISE, IL SB 315 and the EU Code all converged on. Its own follow-up has weakened as the summit agenda shifted |
| New Delhi Frontier AI Commitments (19 Feb 2026) | Frontier developers plus Indian firms | VOLUNTARY | Shared anonymised deployment insights on labour, productivity and economic impact | None | Company participation | New. Notably not a safety instrument — evidence of the agenda shift from risk to diffusion |
| White House Voluntary Commitments (2023) | 15+ US developers | VOLUNTARY | Red-teaming, watermarking, information sharing | None | Executive-branch interest | Largely superseded; retained mainly as precedent |
| Frontier Model Forum | Member labs (Anthropic, Google, Microsoft, OpenAI, Amazon, Meta) | VOLUNTARY | Technical reports on thresholds, third-party assessment, security; a shared vocabulary for the whole stack | None | Member consensus, i.e. lowest-common-denominator risk | Active and quietly load-bearing: its definitions propagate into statutes |
| Partnership on AI, MLCommons (AILuminate), AI Safety Institute Consortium | Broad multistakeholder | VOLUNTARY | Benchmarks, deployment guidance, safe-model practice | None | Funding; member goodwill | Ongoing; benchmark work increasingly cited in procurement |
Layer 3 — Standards, assurance & evaluation
The connective tissue. Turns abstract legal duties into testable claims — and is the current bottleneck.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| CEN-CENELEC JTC 21 | EU AI Act compliance | SOFT-BINDING → HARD on OJEU listing | Harmonised standards conferring presumption of conformity | Presumption of conformity is the legal payoff | Commission standardisation request; expert capacity; consensus among national bodies | The critical path failure. Originally due Aug 2025, slipped repeatedly; exceptional acceleration measures adopted, target Q4 2026. Standards absence was a principal justification for the Digital Omnibus deferrals |
| EN ISO/IEC 42001 (AI management systems) | Any organisation | VOLUNTARY certification | Management-system certification; a governance-process claim, not a model-safety claim | Certification withdrawal | Accredited certification bodies | Adopted by CEN as EN ISO/IEC 42001:2026. Widely used as a procurement proxy; not yet a harmonised standard conferring presumption of conformity |
| NIST AI RMF + Generative AI Profile | Voluntary, US-anchored | VOLUNTARY | Risk-management taxonomy that most corporate programmes are built on | None | NIST/CAISI resourcing and political direction | The de facto US common language; embedded by reference in contracts and state law |
| CAISI (US Center for AI Standards and Innovation) | Participating developers | VOLUNTARY | Pre-deployment evaluation, security testing, standards work | None — evaluation, not authorisation | Voluntary lab access agreements; Commerce leadership | Under the 2 June 2026 EO, runs the 30-day pre-release cyber review. Directed to stop publishing frontier evaluation findings — contested in Congress. A measurement body whose measurements are no longer public |
| UK AI Security Institute | Participating developers | VOLUNTARY | Pre-deployment evals, red-teaming, safeguard testing, foundational research | None — no authorisation power | Voluntary access; DSIT budget | The most technically capable public evaluator; secretariat for the International AI Safety Report; network coordinator |
| Independent evaluators — METR, Apollo Research, SecureBio, FAR.AI | Contracted by labs / AISIs | VOLUNTARY / contractual | Autonomy and scheming evaluations, bio uplift testing, adversarial assessment | Publication; refusal to certify | Model access grants; funding; NDA terms; evaluation-awareness in models degrading validity | Real but structurally fragile: dependent on the goodwill of the entity being evaluated. Illinois’ 2028 audit mandate is the first attempt to make this compulsory |
| Accredited audit market | Frontier developers (IL from 2028) | HARD (IL only) | Annual independent safety audit by conflict-free qualified experts | AG referral | Existence of qualified, independent auditors — which is not yet established | Nascent. The supply of credible auditors is the binding constraint on the whole assurance layer |
Layer 4 — State institutional capacity
Who can actually look inside a frontier model on behalf of the public.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| European AI Office (DG CNECT) | GPAI providers | HARD | Sole supervisor of GPAI models: document requests, model evaluations, mitigation demands, market restriction, fines | Up to 3% global turnover or €15M | Technical staffing; harmonised standards; Member State cooperation | Powers activate 2 Aug 2026. The single most consequential institutional change of the year. Capacity remains widely questioned |
| European AI Board, Scientific Panel of Independent Experts, Advisory Forum | Coordination | Advisory | Member State coordination; qualified alerts on systemic risk to the AI Office | Indirect | Appointments and funding | Operating; the Scientific Panel is the intended technical alarm channel into the AI Office |
| National market surveillance authorities (EU) | AI systems (not GPAI models) | HARD | Enforce system-level obligations | Fines, withdrawal | Member State designation and resourcing | Uneven; several states behind on designation |
| DSIT / UK AISI | UK | Advisory + research | Evaluation, national-security risk assessment, AI Growth Lab regulatory sandboxing | None directly; sector regulators (ICO, Ofcom, FCA, MHRA) hold the powers | Existing sectoral statutes; no AI Act to anchor it | No UK AI Act and none scheduled. AI Growth Lab launched 8 Jun 2026 (legal services first). UK governs frontier AI through capability and access, not law |
| US federal — CAISI, OSTP, OMB, DOJ AI Litigation Task Force | Federal posture | Mixed | Procurement standards (OMB M-memos), voluntary evaluation, and active federal litigation against state AI laws | DOJ can sue states; OMB binds federal buyers | Executive discretion; Article III courts | EO 14257 (11 Dec 2025) directed preemption; DOJ Task Force operational since 9–10 Jan 2026; Commerce review of “burdensome” state laws due 11 Mar 2026 |
| Cal OES, NY DFS AI office, Illinois EMA + AGs | Frontier developers | HARD | Receive incident reports, publish anonymised summaries, enforce | State AG civil penalties | State budgets; survival of state law against preemption | The only functioning mandatory incident-reporting pipeline in the US |
| Cyberspace Administration of China (CAC) | Chinese model providers | HARD | Algorithm and generative-service filing, security assessment, corpus review, mandatory content labelling | Service suspension, market exclusion | Party-state administrative capacity | Fully operational; labelling regime in force since 1 Sep 2025. Application- and content-centric; catastrophic-risk framing largely absent |
| Korea MSIT | AI in Korea | HARD | High-impact AI duties, generative-AI labelling, domestic representative requirement | Fines to KRW 30M | Enforcement decree; capacity | AI Framework Act in force 22 Jan 2026; one-year penalty grace period — guidance-first enforcement |
Layer 5 — Hard law
Binding obligations that attach specifically to frontier model development.
| Actor / Instrument | Who it governs | Binding force | What it actually requires | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| EU AI Act, Arts. 53 & 55 (GPAI + systemic risk) | Providers placing GPAI models on the EU market; systemic-risk tier presumed above 1025 FLOP | HARD | Technical documentation, training-data summary, copyright policy; for systemic risk: model evaluation, adversarial testing, systemic-risk mitigation, serious-incident reporting, cybersecurity of weights | AI Office fines up to 3% / €15M; market restriction | Code of Practice as the compliance route; AI Office capacity; extraterritorial reach via market access | Obligations in force since 2 Aug 2025; enforcement powers live 2 Aug 2026. Untouched by the Digital Omnibus |
| EU Digital Omnibus on AI | AI Act timeline | HARD | Defers Annex III high-risk duties to 2 Dec 2027 and Annex I to 2 Aug 2028; adds prohibited practices; scope clarifications | — | Standards readiness | Published in the OJ 24 Jul 2026, in force 27 Jul 2026. Art. 50 transparency duties still apply from 2 Aug 2026 |
| California TFAIA (SB 53) | “Large frontier developers”: >1026 FLOP models and >$500M revenue | HARD | Publish a frontier AI framework; publish a transparency report before deploying a new or substantially modified model; report critical safety incidents to Cal OES (15 days; 24h where risk is imminent); whistleblower protections | AG civil penalties up to $1M per violation | Survival against DOJ preemption suits; Cal OES capacity; annual CDT threshold review | In force since 1 Jan 2026. The de facto US baseline and the template for NY and IL |
| New York RAISE Act (as amended) | Frontier developers with >$500M revenue; 1026 FLOP / $100M compute | HARD | Safety protocol publication, incident reporting, third-party-aligned transparency | Civil penalties; new DFS oversight office | Preemption litigation; DFS standing up the office | Chapter amendment signed 27 Mar 2026, aligning it closely to California. Effective 1 Jan 2027 |
| Illinois AI Safety Measures Act (SB 315) | Frontier developers | HARD | Frontier AI framework covering catastrophic risk, mitigations, cybersecurity, internal governance, third-party evals and risk from internal model use; 72-hour incident reporting; annual independent third-party audit | AG enforcement | Existence of qualified independent auditors | Signed 6 Jul 2026; effective 1 Jan 2027; audits from 1 Jan 2028. First US mandate for external verification rather than self-attestation |
| US EO 14365 — “Ensuring a National Policy Framework for AI” | States, indirectly | HARD (executive) | Directs DOJ litigation against state AI laws, Commerce review of “burdensome” state laws, FTC policy statement, FCC proceeding; conditions certain federal funds | Federal litigation; funding leverage | Article III courts; dormant Commerce Clause and preemption doctrine | Signed 11 Dec 2025; White House legislative recommendations followed in Mar 2026. Expressly carves out child safety, compute/data-centre infrastructure and state procurement. The central legal conflict in US AI governance right now |
| US EO (2 Jun 2026) — “Promoting Advanced AI Innovation and Security” | Frontier developers (voluntarily) | HARD on agencies, VOLUNTARY for labs | Agencies to design a voluntary pre-release engagement framework by 1 Aug 2026; 30-day CAISI cyber review of volunteered models; classified capability benchmarking by Treasury/NSA/CISA | None on developers — explicitly not a licensing or preclearance regime | Lab participation; agency capacity | In force. The US federal government’s frontier-model posture is now: evaluate voluntarily, publish nothing, preempt the states |
| Great American AI Act (discussion draft) | Large frontier developers >$500M revenue | Not law | Federal transparency, critical-incident reporting, whistleblower protection, independent verification organisations — plus a three-year preemption of state laws governing model development (states keep authority over use) | Would be federal | Committee jurisdiction fights; House–Senate divergence; the preemption bargain | Bipartisan draft released 4 Jun 2026 (Obernolte/Trahan), 269 pages. Referred to committee, no votes. The pivotal open variable for 2027 |
| Council of Europe Framework Convention on AI (CETS 225) | Signatory states’ public-sector and, at each party’s election, private-sector AI | HARD (on states, via implementation) | Human rights, democracy and rule-of-law obligations across the AI lifecycle | State implementation; no supranational court specific to it | National ratification and transposition | In force since 1 Nov 2025 (UK, France, Norway among early ratifiers). EU ratified 15 May 2026; effects for the Union from 1 Sep 2026. First binding international AI treaty; obligations largely restate what the AI Act already does for the EU. The US signed in 2024 but has not ratified |
| China: Generative AI Interim Measures, Deep Synthesis Provisions, Algorithm Filing, AI Labelling Measures | Providers serving the Chinese public | HARD | Pre-launch filing and security assessment, corpus and content controls, mandatory implicit and explicit labelling of synthetic content | Service suspension, penalties | CAC administrative reach | Fully in force; labelling since 1 Sep 2025. A comprehensive national AI Law remains draft |
Layer 6 — Judicial & liability
Fast-moving, retrospective, and increasingly the binding constraint on deployment behaviour — set by courts rather than legislatures.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| Product liability litigation — e.g. In re: ChatGPT Product Liability Cases, JCCP No. 5431 (Cal. Super. Ct., coordinated 3 Feb 2026) | Model deployers | HARD | Tests whether a model is a “product”; defective-design theories aimed at engagement maximisation | Damages, injunctive settlement terms, discovery into internal safety records | Judicial receptiveness; Section 230’s continued erosion in this context | A dozen-plus coordinated wrongful-death and injury cases. Courts have declined to treat chatbots as categorically non-products |
| Wrongful death / minor safety claims (Character.AI, Google, OpenAI) | Consumer-facing deployers | HARD | Duty-of-care claims over self-harm, minors, and manipulation | Damages; settlements | Plaintiff-bar capacity — Edelson and others are now specialised | Character.AI and Google settled multiple suits in Jan 2026. Settlements set de facto product-design standards without any legislature acting |
| Copyright litigation & settlements | Training-data practice | HARD | Fair-use boundaries for training corpora; class certification risk | Statutory damages at ruinous scale — one certified class settled at $1.5B | Circuit splits; class-certification rulings | The largest financial exposure in the sector; drives licensing deals and data provenance practice |
| State AG oversight (CA, DE, and others) | OpenAI’s structure; consumer protection generally | HARD | Charitable-trust supervision of the OpenAI restructuring; UDAP authority over AI claims | Injunctions, structural remedies | AG priorities and resourcing | Standing supervisory relationship — one of the few external checks on a lab’s governance structure rather than its outputs |
| Insurance market | Deployers and, increasingly, developers | STRUCTURAL | Prices and excludes AI risk; ISO GL exclusion forms (CG 40 47/48, CG 35 08) effective Jan 2026 | Coverage denial | Loss data; modelling of correlated failure | End of “silent AI” coverage. Analysts now model foundation-model failure as a systemic, cat-bond-like peril. Uninsurability is becoming a governance signal in its own right |
Layer 7 — International & multilateral
Broad legitimacy, thin obligation. Sets agenda and vocabulary, not conduct.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| UN Independent International Scientific Panel on AI | — | Advisory | 40 experts serving in personal capacity; annual evidence synthesis for the Global Dialogue | None | Member State funding; expert independence | Established Aug 2025; preliminary report published 1 Jul 2026 |
| UN Global Dialogue on AI Governance | — | Advisory | Annual intergovernmental + multistakeholder forum | None | Great-power participation | First session Geneva, 6–7 Jul 2026: 4,200+ participants, ~170 states. Second session New York, 3–4 May 2027 |
| International AI Safety Report (Bengio-chaired, UK AISI secretariat) | — | Evidentiary | Consensus scientific synthesis; names the “evidence dilemma” — act early and entrench weak rules, or wait and absorb the harm | None | Contributor participation; government uptake | 2nd edition Feb 2026: 100+ researchers, 30+ countries. The single most-cited shared evidence base across all layers |
| AI summit series (Bletchley → Seoul → Paris → New Delhi) | — | VOLUNTARY | Produces commitments and declarations; sets the global frame | None | Host state agenda | New Delhi Declaration, Feb 2026: 89 countries/organisations. Seven pillars centred on capacity, access, trustworthiness, energy, science, democratisation and growth. The frame has shifted decisively from safety to impact and diffusion |
| International Network of AI Safety/Security Institutes | Member institutes | VOLUNTARY | Joint testing exercises, shared evaluation methodology, interoperability of reports | None | US participation; institute budgets | Active, UK coordinating; reoriented toward measurement and evaluation science. Weakened by CAISI’s publication restrictions |
| OECD AI Principles, GPAI, G7 Hiroshima Process + HAIP reporting framework | Adhering states and companies | VOLUNTARY | Principles, a company transparency-reporting template, incident monitoring (AIM) | None | Voluntary reporting quality | Operating; HAIP reports are one of the few cross-jurisdiction, like-for-like company disclosures |
| Bilateral / plurilateral chip and compute diplomacy | Allied export-control alignment | Mixed | Aligns Dutch, Japanese, Korean controls with US policy; governs sovereign-AI deals (UAE, KSA) | National law | US policy stability — which has been low | Volatile; the Jan 2026 loosening reduced allied confidence in the durability of any shared line |
Layer 8 — Market, financial & epistemic
Not usually drawn as governance. In practice it decides what gets built and what gets known.
| Actor / Instrument | Who it governs | Binding force | What it actually does | Enforcement teeth | Key dependencies | Status (Aug 2026) |
|---|---|---|---|---|---|---|
| Investors and capital markets | Developer strategy | STRUCTURAL | Set growth expectations; IPO readiness imposes disclosure and control-structure scrutiny | Capital withdrawal; term-sheet governance rights | Return expectations vs mission structures | The dominant force on lab behaviour. Mission-lock structures (LTBT, OpenAI Foundation) exist precisely to resist it, and are being tested |
| Enterprise and government procurement | Deployers, then developers | Contractual → HARD | Security, indemnity, evaluation and provenance requirements flowed down through contracts | Contract loss | Buyer sophistication; standards to point at (ISO 42001, NIST AI RMF) | Frequently faster and more specific than regulation; the main channel by which soft standards acquire real force |
| Academic and independent research (GovAI, IAPS, RAND, CSET, AI Now, Ada Lovelace, arXiv literature) | Agenda | Epistemic | Supplies the concepts — thresholds, evals, structured access, audits — that legislatures then codify | None | Funding independence from labs | High influence and a genuine conflict-of-interest problem: much of the field is lab-funded |
| Journalism, leaks, and employee disclosure | Accountability | Epistemic | Surfaces what no disclosure regime captures | Reputational; triggers regulator action | Whistleblower protections (CA/NY/IL); source protection | Historically the highest-yield accountability mechanism in this sector |
| Open-weight release ecosystem (Meta, Mistral, Qwen, DeepSeek, HF) | Diffusion | STRUCTURAL | Once weights are released, every downstream control in this map becomes unenforceable | None post-release | Release decisions of a handful of firms | The irreversibility problem. Governed almost entirely by unilateral corporate choice |
Dependency analysis — where the load actually sits
1. The binding layers are hollow without the voluntary ones. California SB 53, the NY RAISE Act, Illinois SB 315 and the EU Code of Practice all require developers to publish “a frontier AI framework” — a category invented by the labs themselves (RSP, Preparedness, FSF) and standardised by the Frontier Model Forum. Legislatures codified the shape of the artefact and left the substance — where thresholds sit, what counts as sufficient mitigation — to the regulated firms. The hard law is a disclosure wrapper around private standard-setting.
2. Two chokepoints carry disproportionate load. Harmonised standards (CEN-CENELEC): their absence already forced the Digital Omnibus deferrals, and until they are OJEU-listed there is no presumption of conformity for anyone. Independent auditors: Illinois mandates external audits from 2028, and the Great American AI Act contemplates “independent verification organisations” — but a credible, conflict-free audit profession does not yet exist at the necessary scale. Both are supply-side bottlenecks that no amount of legislative will can shortcut.
3. Evaluation capacity is publicly funded but privately controlled. UK AISI, CAISI, METR and Apollo all depend on voluntary access agreements with the entities they assess. No jurisdiction has legislated a right of pre-deployment access. CAISI’s directive to stop publishing findings severs the last step of the chain: evaluation without publication informs the executive branch and nobody else. Add evaluation-awareness in models degrading test validity, and the measurement layer is weaker in mid-2026 than it was a year ago.
4. The US federal–state conflict is the system’s main instability. The only mandatory frontier incident-reporting pipeline anywhere in the US runs through three state agencies. EO 14257 and the DOJ AI Litigation Task Force exist to dismantle the legal basis for those laws; the Great American AI Act would preempt state authority over model development for three years in exchange for a federal transparency regime. Whether the US has any binding frontier disclosure regime in 2028 turns on that trade landing, or on the courts.
5. Liability is outrunning regulation. Coordinated product-liability proceedings, chatbot wrongful-death settlements, a $1.5B copyright class settlement, and ISO general-liability exclusions effective January 2026 are changing deployment design faster than any statute. Notably, this is the one layer that reaches consumer-facing deployment behaviour, which the frontier-safety statutes — all focused on catastrophic risk — barely touch.
6. Extraterritoriality does the harmonising work. With no binding international instrument that constrains frontier developers directly, EU market access (AI Act), California’s presence as home jurisdiction, and US export controls do the global coordination. The CoE Framework Convention is binding in form but restates existing EU obligations in substance.
7. The frame itself has shifted. Bletchley (2023) was about catastrophic risk. New Delhi (Feb 2026) is about impact, diffusion, energy and access — 89 signatories, and the frontier commitments attached to it concern economic deployment data, not safety. Meanwhile the binding safety instruments (SB 53, RAISE, SB 315, AI Act Art. 55) all landed after the political attention moved on. Implementation is now proceeding in a colder political climate than the one that produced it.
8. Feedback loops worth watching.
- Capability → threshold → obligation: compute thresholds (1025 FLOP EU, 1026 FLOP US states) mechanically expand coverage as training scales, but algorithmic efficiency erodes them from below. California’s annual CDT review is the only built-in recalibration.
- Incident → report → rule: Cal OES / DFS / IEMA reporting is designed to generate the evidence base that justifies the next round of rules. Its output is anonymised and aggregated, which limits how much it can actually prove.
- Race dynamics → framework erosion: OpenAI’s Preparedness Framework contains an explicit competitive-adjustment clause, and Anthropic’s RSP v3.0 replaced a hard pause with graded roadmaps. Voluntary commitments loosen under competitive pressure in exactly the conditions where they would matter most — which is the strongest available argument for statutory floors.
Uncertainty flags
- The International Network of AI Safety Institutes appears to have been renamed/refocused around measurement and evaluation science; the precise current designation is reported inconsistently across sources.
- CAISI’s publication restrictions are recent and contested in Congress (Sen. Budd’s June 2026 letter); the operative scope may change.
- The Great American AI Act is a discussion draft with no votes recorded — treat every provision as provisional.
- Preemption litigation outcomes are unresolved; any row describing a US state obligation is contingent on that litigation.
- Compute thresholds and revenue triggers are subject to statutory review mechanisms and may move.
- Executive order numbering for the 2 Jun 2026 frontier AI / cybersecurity EO is reported inconsistently across firm alerts; the title (“Promoting Advanced Artificial Intelligence Innovation and Security”) is the reliable identifier.
Sources
EU: Digital Omnibus (Freshfields) · Gibson Dunn on the Omnibus · GPAI Code of Practice · Enforcement of Chapter V · How much power does the AI Office have? (Lawfare) · Commission GPAI guidelines
Standards: CEN-CENELEC AI · Standards and the EU AI Act · ISO 42001 and presumption of conformity
US states: California SB 53 (White & Case) · SB 53 compliance guide (Nelson Mullins) · Brookings on California’s AI safety law · NY RAISE Act finalised (Wiley) · NY amendments (MoFo) · Illinois SB 315 (Crowell) · Illinois audits (Latham)
US federal: EO 14365 text (White House) · EO 14365 unpacked (Sidley) · Preemption EO (Lawfare) · Preemption EO (Paul Hastings) · June 2026 frontier AI EO (Skadden) · June 2026 EO (Latham) · Great American AI Act (TechPolicy.Press) · GAAIA vs state laws (FPF) · Budd letter on CAISI publication
Compute & export controls: New AI chip export policy (CFR) · GAIN AI Act (CSIS) · Commerce move on offshore Chinese entities (CNBC)
Corporate: Anthropic RSP · RSP v3.0 analysis (GovAI) · Frontier Safety Roadmap updates · Anthropic Long-Term Benefit Trust · OpenAI restructure explained (Transformer)
Assurance & evaluation: FMF third-party assessments · OpenAI on third-party evaluations · METR frontier risk report · Evaluation awareness (IAPS) · Secure third-party access (RUSI) · OpenAI on CAISI/UK AISI work · International network next steps (CSIS)
International: UN Global Dialogue on AI Governance · Scientific Panel preliminary report · UN News on the Geneva dialogue · India AI Impact Summit outcomes (Brookings) · New Delhi Declaration (PIB) · CoE Framework Convention · EU ratification
Asia: Korea AI Framework Act in force (Library of Congress) · Korea AI Basic Act overview (Cooley) · China AI labelling measures · China AI regulation tracker
UK: UK AI regulation in 2026 (Bratby Law) · AISI blog
Liability & insurance: ChatGPT product liability coordination · AI lawsuits filed (Edelson) · Emerging AI exclusions (Fenwick) · Insurer interest in AI exclusions · The insurability frontier of AI risk