AI Governance Tracker
The governance ratchet in real time — EU AI Act rollout, compute export controls, the open-weight fights, C2PA adoption, and the spreading AI Safety Institutes. Updated as the clicks land.
Every row auto-classifies by keyword match — the LED and left edge carry its state. Chips filter across all seven instruments at once.
Every AI safety announcement is also a procurement document.
The instruments below — the EU AI Act, the US compute export controls, the national AI Safety Institutes, the C2PA watermarking standard — were all sold as guardrails against existential-tier risk from frontier models. They are also, simultaneously, an implementation calendar for who-gets-to-build-what, who-gets-to-import-what, who-gets-audit-rights-into-whose-stack. Both readings are correct. The instruments do not care which one motivates you.
Each row sources to the regulation text, an agency notice, or a real-time tracker. The argument these instruments converge on — who operates the grid, and what held versus what reversed in 2025–26 — is laid out in The AI Governance Ratchet. Update triggers: regulation enters into force, enforcement action announced, executive order signed or rescinded, AI Safety Institute report dropped.
Where it appears in print: Evil Robots (Book 1) Convergence chapter (regulation as backdrop) and The Ratchet (Book 2) Chapter 20 (“The Blueprint”) (regulation as control infrastructure). The page consolidates both books’ tracking.
EU AI Act Timeline
| Date | Provision | Status | Primary Source |
|---|---|---|---|
| Aug 1, 2024 | Entry into force — Regulation (EU) 2024/1689 | Active | Official Journal |
| Feb 2, 2025 | Prohibited practices ban (Article 5) | Active | European Commission AI Act overview |
| Aug 2, 2025 | GPAI model obligations (Chapter V, Articles 51-56) | Active | Code of Practice for GPAI providers (European Commission) |
| Dec 2, 2027 | High-risk AI requirements (Annex III) — moved from Aug 2, 2026 | Future | Regulation (EU) 2026/1744 (Digital Omnibus on AI); Annex III text |
| Aug 2, 2028 | Safety component products (Annex I) — moved from Aug 2, 2027 | Future | Regulation (EU) 2026/1744; Annex I text |
Enforcement signals to watch: European AI Office staffing and guidance; national Market Surveillance Authorities; complaints to data protection authorities under the Article-5-overlapping prohibitions.
Standing tracker: artificialintelligenceact.eu (FLI / Future of Life Institute) — most comprehensive non-official monitor of EU AI Act implementation.
US Compute Export Controls
| Date | Action | Scope | Primary Source |
|---|---|---|---|
| Oct 7, 2022 | Initial advanced computing rule | China — advanced chips & SME | BIS final rule 87 FR 62186 |
| Oct 17, 2023 | Update — closed loopholes, added A800/H800 | China + 22 other countries | BIS final rule 88 FR 73424 |
| Jan 13, 2025 | Tiered global “Framework for AI Diffusion” | Three tiers globally | BIS Framework rule 90 FR 4544 |
Status under Trump II: Executive Order 14110 (Biden EO of October 2023) was revoked by Executive Order 14148 of January 20, 2025. The AI Diffusion Framework was rescinded by BIS announcement of May 13, 2025 — enforcement officials were instructed not to enforce it ahead of its May 15, 2025 compliance date. The formalizing Federal Register rule was never published, so the framework’s text remains in the CFR; GAO held in May 2026 (B-337935) that the press-release rescission was itself a rule subject to the Congressional Review Act.
DeepSeek-R1 / V3 impact: Released January 20, 2025 (R1) on the same day as the Trump EO revocation. Demonstrated frontier reasoning on training compute roughly an order of magnitude below US lab estimates (DeepSeek-V3 technical report). Triggered the policy question whether export controls accelerate Chinese architectural innovation; track CSIS, RAND, and CNAS for analysis updates.
C2PA Content Provenance
Coalition for Content Provenance and Authenticity — cryptographic content credentials.
| Platform | Status | Source |
|---|---|---|
| Adobe | Implemented across Creative Cloud | Adobe Content Credentials |
| Microsoft | Bing Image Creator, Designer | Microsoft on C2PA adoption |
| SynthID + C2PA metadata | DeepMind SynthID | |
| Meta | Labeling AI-generated images (2024) | Meta AI labeling announcement |
| X / Twitter | Not adopted | — |
| TikTok | Limited adoption | TikTok on AI labeling |
| Camera hardware | Leica M11-P, Sony Alpha 9 III, Nikon Z9, Canon CR-N700 firmware support | C2PA member list |
Government mandates:
- China Deep Synthesis Provisions (effective Jan 10, 2023) — labeling required for synthetic media
- EU AI Act Article 50 — disclosure for AI-generated content (Aug 2026)
- No US federal mandate. California AB 3211 vetoed Sep 2024. California SB 942 (AI Transparency Act) signed Sep 2024.
Standing source: C2PA technical specifications — the actual standard.
Open Source / Open Weight Frontier Releases
| Model | Date | Significance | Source |
|---|---|---|---|
| Llama 3.1 405B | Jul 23, 2024 | Meta frontier open-weight, GPT-4-class on benchmarks | Meta release, Llama 3 paper |
| Mistral Large 2 | Jul 2024 | European frontier open weights | Mistral release |
| DeepSeek-V3 | Dec 26, 2024 | 671B MoE, claimed ~$5.6M training cost | DeepSeek-V3 paper |
| DeepSeek-R1 | Jan 20, 2025 | Reasoning model, open-weight, broke compute thesis | DeepSeek-R1 paper, HF model card |
| Qwen 2.5 | Sep 2024 | Alibaba open-weight competitive series | Qwen release |
| Llama 4 | Apr 2025 | Multimodal frontier open weights | Llama 4 release |
Jurisdiction restrictions on open-weight releases: No outright bans.
- California SB 1047 vetoed by Governor Newsom Sep 29, 2024
- EU AI Act Article 53(2) — exempts free-and-open-source providers from most documentation obligations, except for systemic-risk GPAI models (10^25 FLOPs threshold)
- Compute threshold mirrored in Biden EO 14110 (10^26 FLOPs reporting requirement) — now revoked
AI Safety Institutes
| Country | Status | Source |
|---|---|---|
| UK AISI — AI Security Institute (renamed from AI Safety Institute, Feb 2025) | Operational (Nov 2023) | aisi.gov.uk; rename announcement |
| US AISI (NIST) → CAISI | Renamed Center for AI Standards and Innovation; access MOUs with Anthropic/OpenAI persist | CAISI; MOU announcement |
| Japan AISI | Established Feb 2024 | Japan AISI announcement |
| Canada AISI | Established Nov 2024 | Canada AISI announcement |
| France INESIA | Established Jan 2025 | INESIA announcement |
| Singapore AI Verify | Operational (testing framework) | AI Verify Foundation |
| South Korea AISI | Established Nov 2024 | South Korea AISI announcement |
International cooperation:
- Bletchley Declaration (Nov 2023)
- Seoul Declaration (May 2024)
- International AI Safety Report 2025 (Bengio et al.) — first inter-government scientific assessment
Who Governs the Governors (the capture read)
Every instrument above has an author, and the authors are not neutral. Run the same test on the AI-safety apparatus that this project runs on any other captured institution — who funds it, who staffs it, who writes its standard — and the answer, at each layer, is the industry it governs. The finding is structural; it alleges no bad faith by any safety researcher.
| Layer | Who controls it | Source |
|---|---|---|
| The standard-setter | The Frontier Model Forum — founded, funded, and governed by Anthropic, Google, Microsoft, and OpenAI — writes the “safety best practices” for frontier models | Launch announcement |
| The evaluator | The US AI Safety Institute (NIST; now the Center for AI Standards and Innovation) evaluates models only by the labs’ permission — pre-deployment access MOUs with Anthropic and OpenAI — and staffed from the lab-tied evaluation shops (METR, Apollo) the labs fund via Open Philanthropy | NIST MOU announcement |
| The rulebook | The EU AI Act’s General-Purpose-AI Code of Practice was drafted with the model-makers given privileged access while civil society was sidelined (per Corporate Europe Observatory) | Corporate Europe Observatory |
| The board | Paul Nakasone — until 2024 the director of the NSA and commander of US Cyber Command — joined OpenAI’s board and its Safety and Security Committee | OpenAI announcement |
The counter-case (kept, per present-all-sides): the least-captured artifact in the apparatus is NIST’s AI Risk Management Framework, assembled from 240+ organizations across industry, academia, and civil society through open public comment — and it is the one that persists across the administration change. The picture is not that every safety body is a front; it is that the closer you get to the money, the access, and the board seats, the more the safety of the machines is defined by the people who own them.
Principal dossiers (Watching the Watchers): Nakasone, Kratsios, Prabhakar, Cuéllar, Buchanan, Kelly, Chowdhury, Brundage, Krishnan, Sankar. Full research: IGO capture / the F3 finding. The Record’s AI policy-council view renders the same people as a graph.
State-Level US AI Legislation (Tracking)
| State | Law | Status | Source |
|---|---|---|---|
| Colorado | AI Act (SB24-205) — delayed, then repealed and replaced by the ADMT law (SB26-189) before it ever took effect | Effective Jan 2027 | SB26-189; delay via SB25B-004; original SB24-205 |
| Utah | AI Policy Act (consumer disclosure) | Effective May 2024 | SB149 |
| Illinois | Predictive Hiring Act (HB 3773) | Effective Jan 2026 | Illinois HB 3773 |
| Texas | TRAIGA (HB 149) | Effective Jan 2026 | Texas HB 149 |
| California | AB 2013 (training data disclosure) | Effective Jan 2026 | California AB 2013 |
Standing tracker: IAPP US State AI Governance Legislation Tracker — comprehensive monthly-updated state-by-state.
Bridges
- convergence-table — AI governance situated inside the broader infrastructure stack
- the-record — click 18 (“The Blueprint”) points here
- the-record — AI Industry → Government → AI Industry pipeline
- economic-statecraft-tracker — compute export controls as one instrument in the wider economic-warfare set
Sources
Inline above. Standing trackers:
- artificialintelligenceact.eu — FLI EU AI Act tracker
- BIS Federal Register feed — official US export controls
- C2PA specifications — content provenance standard
- IAPP US State AI Governance Legislation Tracker — US state law
- EPIC AI Policy — rights-focused commentary and primary-source archive
- Stanford HAI AI Index — annual cross-cutting governance + capability data
Companion research: The AI Governance Ratchet.