World News

The US, the EU and the UK are Reshaping AI Governance

Companies can adapt to strict regulations or light-touch oversight, but uncertainty becomes a major barrier to long-term innovation. Photo by Richard Baker / Images via Getty Images Images

In the first week of June 2026, Anthropic released its most capable AI models, Claude Mythos and Claude Fable, to a small group of organizations under a new security program called Project Glasswing. Within days, the US Department of Commerce suspended access to both models to comply with export controls. Three weeks later, the Department removed those controls, and access was restored. For most of June, the world’s most advanced AI systems were governed under written law rather than the agency’s judgment call, which was made and amended during the same month.

That arrangement is important because it reveals something the AI ​​industry has been slow to recognize: the United States is relying less on a unified regulatory regime and more on a set of high-speed tools. Export controls, national security reviews and executive memoranda can open or close access to the border model without new legislation. What is needed is an agency that decides, in a given week, that something warrants action.

That instability has not been reflected within the industry. In mid-July, Demis Hassabis, the London-based CEO of Google DeepMind, published a proposal by a US standards body modeled on FINRA, an industry-sponsored group that oversees Wall Street under the supervision of the SEC. Hassabis said the improved management of the Mythos and Fable suspensions last month convinced him that Washington needed a permanent structure, not a one-off fix. His plan begins modestly: labs submit boundary models for voluntary review before release, with the plan to be hardened into a market requirement once the process proves itself. Hassabis runs one of three labs running hard towards the border, and he makes the case from London, a city that regulates AI through existing industry regulators instead of a dedicated law of its own. His proposal is a predictive vote.

Now consider what was happening in Brussels at that time. The EU AI law, which was passed in 2024, spent most of 2026 pushing back its start date. High-risk obligations under the AI ​​Act, which was scheduled to take effect on Aug. 2, delayed until December 2027 following months of negotiations between the Council, the Parliament and the Commission regarding the Digital Omnibus package. The requirement for member states to set up national AI regulatory sandboxes dropped by a full year, until August 2027. The EU drafted the world’s most comprehensive AI law, then spent two years finding it unable to meet its implementation timeline.

In London, there is no AI legislation at all. I The UK did not pass the AI ​​bill there are rumors from the first AI Safety Summit in 2023. Instead, AI is regulated the way British regulators tend to regulate most things: sector by sector, by whatever existing body has authority. The Financial Conduct Authority oversees finances. The Information Commissioner’s Office collects personal information. Ofcom folds AI risks into telecoms’ security obligations. There is no single system we can point to, and the government’s current response to the need to exist is a supervised sandbox, the AI ​​Growth Lab, which allows companies to test products under temporary, case-by-case exemptions instead of fixed rules.

Three governments, with three very different ideas on how to manage technology that changes almost daily.

The American approach treats AI primarily as a question of security policy and industrial policy, controlled by smart management tools that move at the speed of a memo. That gives Washington a lot of flexibility: it can act on Tuesday in response to a threat that no one had written into law on Monday. But the rules under which a company operates can change as management learns at the time, and the same tools that limit access to one company can, in fact, be used in another.

The European approach treats AI primarily as a risk to the rights of individuals and public bodies, regulated by a comprehensive, unified law that tries to determine in advance what counts as a serious risk and what happens when a company does something wrong. That gives companies something the American system can’t: a document that a lawyer can read and interpret. But defining the future in the law means amending it every time the truth overtakes the legislature, which is many times. The Digital Omnibus shows the challenge of applying comprehensive legislation to changing technologies on an eighteen-month cycle. The AI ​​Act provides a clear legal framework, but keeping that framework in line with rapid technological change requires constant revision.

The British approach treats AI as a general set of problems to put on a new coat of arms, better handled by regulators who already understand the financial harm, misuse of data and telecommunications risks than by new administrations specific to AI. That is safer, and cheaper to use than any other method. But a company’s responsibilities end in terms of which controller has a valid claim in a given use case, and that boundary remains unfixed. No one in London can say yet where the agent’s systems are not equal to the existing administrator’s money.

None of these methods are wrong; they answer different questions. Washington is asking who controls the world’s most powerful technology and how quickly it can act if that control slips. Brussels is asking how to keep technology from reproducing discrimination and harm at scale, and how to write it so that courts can enforce it. London questions whether existing tools are sufficient, and whether it’s worth building an expensive new regulator before knowing it’s needed.

A company selling AI to governments must answer all three questions at once, even if the answers don’t add up to everything. A system that clears the criteria-based assessment of the UK regulator would still cripple the EU’s dangerous fragmentation. Partnerships that pass every company-driven security review can still be put on hold by an export control decision driven by geopolitics rather than model performance. There is no unified compliance objective, because there is no unified theory of what is protected.

This has an impact on where innovation is going, and is not an impact on each side of the more-or-less regulation debate that is often predicted. Strong regimes do not simply repel companies, and weak regimes do not simply attract them. Prediction itself has become a competitive input, different from any rigid rule. An inventor can create a system of compliance with a fixed, even arbitrary, rule. It’s hard to build one around a discretionary power that’s been dormant for years and then used overnight, or near the edge of an industry no one has released yet. Companies decide for themselves what kind of uncertainty they can tolerate, not which country has the friendliest rules on paper.

No single philosophy of AI governance provides a definitive answer, because no such answer exists. What matters is whether companies can understand the system well enough to make long-term decisions, whether that system is selective and fast, broad and slow, or industry-based and advanced. In AI, clarity has become a competitive advantage in itself. Countries that offer the most credibility may shape the next decade of innovation more than countries that promise the tightest controls or the lightest touch.

Why Clarity, Not Control, Will Define the Global Race to Dominate AI



Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button