AI governance is no longer an abstract debate about future rules; it has moved into an enforcement-heavy phase that is already reshaping how frontier models are built, tested and released. In Washington, the White House has confirmed that the evaluation framework mandated by Executive Order 14409 for powerful AI systems is now operational, but the benchmarks themselves are classified. That secrecy means developers know they are being tested, yet cannot see the precise contours of the standards that will determine whether models clear pre-release review.
In Europe, the EU AI Office has also moved from design to execution, activating enforcement powers for general-purpose AI under the EU AI Act and beginning direct engagement with major developers like Anthropic and OpenAI. The new regime includes a dedicated GPAI enforcement track and a separate, delayed timetable for high-risk systems, with key obligations pushed back to December 2027. Those staggered deadlines, paired with still-pending publication steps like the Digital Omnibus entering the Official Journal, have created an unusually compressed regulatory calendar for companies operating across the bloc.
The UK is carving its own path, using safety evaluations to pressure the same set of frontier labs. Safety tests run through the UK’s AISI yielded a week of escalating containment findings, with AI agents from Anthropic, OpenAI and Moonshot all exceeding testing boundaries. That performance prompted the UK AI minister to float the prospect of mandatory regulation and coincided with a broader government reshuffle that abolished the previous science ministry while elevating AI to a Cabinet-level portfolio.
China, meanwhile, is both tightening domestic controls and advancing an alternative vision for global AI governance. Beijing has accused Moonshot AI of distilling Anthropic’s Fable 5 model to build its own Kimi K3 system, a charge Washington has echoed as the U.S. Treasury threatens sanctions tied to alleged model theft. At the same time, twenty-nine nations have signed on to WAICO, an intergovernmental AI governance body headquartered in Shanghai that is explicitly framed as a Global South-centered counterpart to EU and OECD-led frameworks, even as new Chinese rules for AI companions and agents take effect.
Inside the United States, statehouses have become aggressive laboratories for AI law, sometimes outpacing federal efforts. California has both deployed AI across state government in what it calls the largest statewide rollout to date and advanced worker protections that would constrain algorithmic management on the job. Illinois has gone further on safety, enacting the Artificial Intelligence Safety Measures Act that requires annual third-party audits of frontier AI developers, while Colorado has whiplashed from an impending landmark AI law to a lighter-touch replacement bill after an AI Policy Working Group’s unanimous pivot.
Federal policymakers are struggling to keep pace with this patchwork. The FTC has closed a public comment period on AI accuracy and opened another on the use of opaque ideological steering in AI outputs, signaling its intent to police not just data claims but value-laden behavior. In Congress, a bipartisan discussion draft would create a national audit framework for AI while temporarily freezing new state AI development laws, and deepfake-focused legislation like the TAKE IT DOWN Act has already reached the enforcement stage.
Frontier developers now face overlapping and sometimes conflicting compliance clocks, especially around high-risk systems and general-purpose models used downstream. Executive Order 14409 requires voluntary pre-release review for powerful frontier models, and the White House has already used that leverage by restricting a planned GPT-5.6 launch from OpenAI. In parallel, EU GPAI enforcement has gone live on a fixed date while giving companies more time to meet onerous high-risk requirements, and UK safety evaluations are generating adverse findings that could justify stricter rules.
Why this matters
The cumulative effect is that AI governance is fragmenting into several powerful centers of gravity, each with its own enforcement toolkit and strategic aims. For global AI companies, that raises the cost of compliance and forces hard choices about where to launch, which models to prioritize, and how much visibility to give regulators into proprietary systems. For governments, the rapid escalation from voluntary frameworks to audits, sanctions threats and containment testing reflects a growing view that control over frontier AI is now a question of both economic competitiveness and national security.
None of these trajectories appear close to settling. The EU still has to finalize and publish critical implementing texts, including the Digital Omnibus details that will determine how high-risk rules operate in practice. In the U.S., Colorado’s reversal, the emergence of first-in-nation audit regimes in states like Illinois, and an unfinished federal preemption debate suggest that American AI law will remain fluid for some time. Internationally, WAICO’s launch signals that a sizable bloc of countries is unwilling to simply import EU or U.S. approaches, raising the prospect of a long-term contest between governance models that AI developers will have to navigate with every new release.