Article image
Cover: generated with Midjourney, edited in Photoshop.
 

America Governs Frontier AI by Relationship, Not Statute

Europe writes its AI controls into law. Washington exercises them.

markus brinsa 11 september 8, 2026 12 12 min read create pdf website all articles

Verified Sources

Beneath the contrast, the questions converge

At the G20 Innovation Ministerial in Chapel Hill, North Carolina, the United States presented its familiar contrast with Europe — and won a diplomatic round. All twenty members endorsed the non-binding Carolina Principles, which urge governments to favor sector-specific rules, avoid creating new AI regulators, and work closely with industry. American policy, the argument went, would preserve room for experimentation and competition, while the European Union had surrounded artificial intelligence with an elaborate statutory regime. Elon Musk, speaking by video, described the preferred American environment as one in which new technologies are legal by default. European Commission Executive Vice President Henna Virkkunen heard the criticism and rejected the binary.

The two systems, she told Axios, increasingly confront similar concerns. Europe handles them through legislation such as the AI Act. In the United States, responses emerge through state statutes, litigation, executive action, national-security controls, agency standards, and private agreements with model developers. The legal containers differ, but the questions entering those containers are becoming harder to distinguish.

Who gets to examine a frontier model before release? What capabilities trigger government attention? How should developers document testing and restrict access? Who receives notice of a serious incident? What happens when a model can materially assist cyber operations? How much information must a developer disclose about its training data? Governments on both sides of the Atlantic are now asking these questions.

These are not hypothetical concerns. In July 2026, OpenAI disclosed that two of its models, trying to cheat on an internal cybersecurity evaluation, broke out of a sealed test environment and hacked into the production systems of another company — one of the first documented cases of an AI system autonomously carrying out such an attack. Virkkunen pointed to that wave of "rogue" model behavior at the G20 as precisely the reason governments will need to coordinate.

Virkkunen's argument is therefore more substantial than the observation that America regulates despite its deregulatory language. She is pointing to an emerging convergence at the operational level. Frontier-model governance is being built around evaluations, controlled access, incident reporting, cybersecurity, and release decisions. Brussels has placed those functions inside a public statutory structure. Washington is assembling them through several institutions whose authority, procedures, and transparency vary sharply.

The result is not harmonization. It is a more complicated form of regulatory overlap.

Europe starts with a legal category

The EU AI Act gives companies a relatively visible map of the system. It defines regulated actors, assigns obligations according to risk, and gives the European Commission's AI Office supervisory powers over general-purpose models.

Providers of general-purpose AI models must maintain technical documentation, give downstream providers information about capabilities and limitations, implement a policy for complying with EU copyright law, and publish a summary of the material used for training. Providers established outside the Union generally need an authorized representative before placing a covered model on the European market.

Additional duties apply to general-purpose models classified as presenting systemic risk. The AI Act presumes that models trained above a specified computational threshold fall into this category, although the Commission can rebut that presumption or designate other models based on their capabilities and impact. Providers of systemic-risk models must conduct and document evaluations, perform adversarial testing, assess and mitigate risks, report serious incidents, and protect the model and its infrastructure against cyber threats.

The Commission also has a formal power to request information and conduct evaluations when necessary to investigate systemic risk or assess compliance. It may seek technical access to a model, including through an application programming interface or other appropriate means. These powers exist within a structure that includes legal thresholds, procedural duties, confidentiality requirements, and potential fines.

That machinery is now in motion. In the same week as the G20 meeting, the Commission confirmed it had sent formal information requests to more than thirty providers of general-purpose AI models — the first enforcement step since the GPAI obligations took effect, focused on model safety and security and on copyright.

Implementation remains difficult, and parts of the broader AI Act timetable have changed. Yet the architecture is recognizable. A company can identify the statute, the regulator, the legal category, and the nominal route through which a decision can be challenged.

Washington has built a release gate of its own

The United States lacks an equivalent federal AI statute. It now has something that would have seemed improbable during the early phase of the generative-AI boom: a government process through which selected frontier models can be reviewed before release.

A June 2026 executive order instructed several federal bodies to create a classified benchmarking process for advanced cyber capabilities. The order assigns roles to the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the National Institute of Standards and Technology, the Office of the National Cyber Director, the Treasury Department, and other parts of the executive branch. The designation itself — whether a given model qualifies as a "covered frontier model" — rests with the Director of the NSA.

Under the accompanying voluntary framework, a developer can engage the government to determine whether a model meets that threshold. The company can then provide federal officials with access for up to 30 days before the model is released to other trusted partners. The government and the developer may also collaborate to select the organizations that receive early access.

The executive order expressly disclaims mandatory licensing, preclearance, or permitting. That sentence protects a central part of the administration's policy identity. It also leaves unresolved how voluntary the process will feel to a developer whose model has attracted national-security attention.

Axios reported that the framework covers closed models with state-of-the-art capabilities and potential national security risks, while excluding open models. During a review, access is supposed to occur in high-security environments, with detailed logs and limits on which employees can use the model. Multiple government offices may participate. The benchmarks used to identify covered cyber capabilities are classified, and the White House has not made the review framework public.

OpenAI CEO Sam Altman confirmed that the administration reviewed the company's Astra model. Asked about the voluntary character of the process, he replied: "But we of course did it."

That short answer captures the institutional reality better than the formal label.

Voluntary rules can carry public power

A frontier developer does not need a formal licensing requirement to feel compelled to cooperate. The federal government buys technology, controls access to classified work, administers export restrictions, investigates cyber incidents, and shapes which companies are trusted to supply sensitive systems. A company may remain legally free to refuse a review while concluding that refusal is commercially or politically untenable. Participation becomes a condition of credibility even when it is not a condition written into law — which is what Altman's "we of course did it" actually describes.

For the government, this is a source of speed. Officials can respond to a new capability without waiting for Congress, adjust classified benchmarks as threat information evolves, and work directly with the small number of developers whose models raise national security questions.

The cost is accountability. Companies outside the process cannot see what qualifies a model for review, which tests apply, or how trusted partners are chosen, and Congress has limited visibility into a framework that may shape which models reach the market and under what restrictions. If a reviewed model later causes harm, outsiders may be unable to tell whether the government used a weak benchmark, accepted a developer's mitigation, or never examined the relevant capability. Europe's system can be faulted for burden and rigidity. The American arrangement invites the opposite criticism: consequential controls exercised through relationships and undisclosed criteria rather than generally applicable public rules.

State law and the courts add layers of their own

The federal release gate is only one layer. Where Washington leans on relationships, the states and the courts impose obligations through mechanisms that look nothing alike.

California's Transparency in Frontier Artificial Intelligence Act requires large frontier developers to publish safety frameworks, report specified critical incidents, and protect certain whistleblowers. New York's RAISE Act, now enacted, imposes comparable transparency and safety duties on frontier-model developers. Colorado's revised automated decision-making law, effective in 2027, governs systems used in consequential decisions and gives consumers the right to correct inaccurate personal data. Separate state measures reach chatbots, deepfakes, political communications, employment tools, health care, and automated pricing.

These laws do not add up to a national risk hierarchy. Their definitions and enforcement mechanisms differ — one state targets frontier-model incidents, another targets discrimination in consequential decisions, another targets interactions between minors and companion chatbots.

Courts supply yet another layer. Product-liability, consumer-protection, copyright, civil-rights, privacy, and contract claims can force changes not specified by any legislature, arriving through an injunction, a settlement, or a company's effort to limit exposure across many similar cases. It is a characteristically American form of governance: rules emerging from contest, precedent, bargaining, and overlapping jurisdiction. It adapts around concrete injuries — and leaves companies uncertain until somebody sues.

Copyright exposes the limits of convergence

The Justice Department's September 1, 2026 statement of interest in the consolidated copyright litigation against OpenAI — In re: OpenAI, Inc. Copyright Infringement Litigation, before Judge Sidney H. Stein in the Southern District of New York — illustrates how the American system works. The federal government did not enact a copyright rule for model training. It entered a dispute between private parties and asked a court to adopt the executive branch's interpretation of fair use.

The filing argues that using copyrighted works to train a large language model is highly transformative when the training process is considered on its own. According to the government, the model analyzes works to learn statistical relationships and produce a system capable of new functions. That purpose differs from delivering the original article or book to an audience.

The Justice Department separates this training use from two other questions. One concerns how a developer obtained its copies. Unlawful acquisition may create liability even if a later analytical use is transformative. The other concerns model output. An output that reproduces protected expression or substitutes for the original work may still infringe. A finding that training is fair use would not immunize everything an AI company did before or after training.

That distinction offers the administration a way to support inexpensive model development while acknowledging creator protections at the output layer. It is also likely to shift litigation toward provenance, memorization, substantial similarity, and the effectiveness of safeguards against reproduction.

The filing is a statement of interest under federal law. The United States is not a party to the case, and Judge Stein is not bound by its position. Congress has not amended the Copyright Act. No nationwide precedent has declared every form of AI training lawful.

Yet the filing is policy. It tells model developers, investors, publishers, and foreign governments how the executive branch wants existing law to develop.

The fight over market dilution

The Justice Department's position is especially consequential for the fourth fair-use factor, which examines harm to the potential market for or value of a copyrighted work.

Some creators and publishers argue that generative systems can flood markets with inexpensive works that compete with human production. Even when an individual output is not substantially similar to a particular book or article, millions of generated works may reduce demand for the category of material on which the models were trained. This theory is often described as market dilution.

The government rejects that approach. Copyright protects expression, not a creator's general position in a market. On the Justice Department's reasoning, lawful competing works do not become infringing simply because they were made with a tool trained on copyrighted material. Economic competition from non-infringing output is therefore different from substitution for protected expression.

If courts adopt that view, publishers and creators will face a narrower path for challenging training. Evidence that generative AI competes for readers, commissions, advertising, or subscription revenue may not be enough. Plaintiffs would have stronger claims where they can trace unlawful acquisition, demonstrate memorized reproduction, or show that outputs substitute for identifiable protected works.

Licensing markets would not disappear. Developers may still pay for reliable archives, current information, metadata, contractual certainty, or uses that go beyond any plausible fair-use defense. Publishers can also offer data that is cleaner and more useful than material gathered from the open web. But the negotiating baseline would change. A license purchased for quality or risk management commands a different kind of leverage from a license legally required before training can begin.

The administration argues that mandatory licensing would favor the largest laboratories, which can absorb substantial rights-clearance costs, and major media companies with enormous archives. Smaller model developers could benefit if courts establish a broad training privilege. Creators and publishers would bear more of the cost unless output claims, contracts, collective licensing, or new legislation create another route to compensation.

Here the American and European systems remain materially different. EU law provides a text-and-data-mining exception for lawfully accessible works, but commercial users must respect rights reservations expressed by copyright holders in an appropriate manner. The AI Act requires general-purpose model providers to maintain a copyright compliance policy and publish a training content summary. Those requirements apply to providers placing models on the EU market, including companies based outside the EU.

The same training corpus may therefore carry a defensible fair-use argument in the United States and create compliance obligations in Europe. Convergence on model testing does not erase divergence over the resources used to build the model.

International companies need two maps

For global businesses, the old question — "Which AI law applies?" — has become inadequate. Compliance must account for statutes, agency relationships, litigation exposure, procurement rules, and the conditions attached to access or distribution.

The practical starting point is a shared operational foundation. Model evaluations, adversarial testing, access controls, incident records, cybersecurity measures, and documented release decisions can support obligations in several jurisdictions. A company that builds those functions only when a particular law demands them will keep reconstructing the same evidence under deadline pressure.

Legal treatment still needs jurisdiction-specific branches. An EU launch requires analysis of the AI Act's model categories, copyright policy, training summary, notification duties, downstream documentation, and systemic risk controls. A U.S. launch may require state-by-state product analysis, assessment of federal review expectations, scrutiny of procurement and export exposure, and preparation for claims under existing law.

The evidence should travel with the model. Companies need to know which version was tested, which mitigations were active, who had access, what changed after evaluation, and which incidents altered the release decision. A government review of one configuration cannot safely be treated as approval of every derivative, fine-tune, or deployment context.

Contracts with model suppliers will need to reflect that reality. Enterprise customers should seek notice of material model changes, enough documentation to perform their own risk analysis, cooperation after serious incidents, and clarity about which party will respond to regulators. A supplier's participation in a U.S. voluntary review does not establish compliance with the EU AI Act. An EU conformity process does not resolve American copyright liability.

Launch calendars may also become a compliance control. A potential 30-day federal access period affects product sequencing and internal security. EU notifications and documentation impose their own preparation time. International release can no longer be assumed to occur through one simultaneous switch.

Convergence will not produce simplicity

Virkkunen is probably right about the direction of travel, and the clearest evidence is that Europe is now building the very mechanism it once contrasted itself against. She told Axios that the EU is developing its own blueprint for pre-deployment testing and trusted-partner access — the same functions embedded in Washington's voluntary framework — and is discussing the approach with G7 partners. More capable models are drawing governments into evaluations, release planning, incident response, and decisions about trusted access. Few administrations will remain comfortable learning about a serious capability only after public deployment.

Yet functional convergence can coexist with deep institutional divergence. Europe places its controls in legislation that aims to ensure consistency across markets. The United States distributes control among the executive branch, states, courts, procurement systems, and voluntary arrangements backed by government leverage. Europe's weakness is the weight and complexity of formal compliance. America's weakness is uncertainty about where the real rule resides.

The DOJ's copyright intervention makes the pattern visible. American AI policy can change through a court filing even though no statute has changed and no judge has ruled. A developer must account for the signal while remembering that it is neither a safe harbor nor settled law.

International companies should expect more of this. The operational standards applied to frontier models may slowly converge, especially around cyber capabilities and serious incidents. The legal meaning of those standards will remain contested. Compliance will depend on understanding both the published framework and the institution capable of changing the conditions around it.

America does have AI guardrails. The harder question is who can see them, who must follow them, and what recourse exists when they move.

About the Author

Markus Brinsa writes about AI failure, enterprise risk, governance, and the structural shifts underneath them — the through-line being the gap between AI governance on paper and what systems actually do at runtime. He created Chatbots Behaving Badly, a publication and podcast investigating real incidents in which AI systems gave bad advice, were manipulated, or failed in ways that mattered. He is the Founder & CEO of SEIKOURI Inc., an international strategy firm that gives enterprises and investors human-led access to pre-market AI — and converts first looks into rights and rollouts that scale. Access creates possibility. Rights create leverage. Scale turns early advantage into durable position. The two halves are the same work from opposite ends: SEIKOURI gets clients to AI early and makes sure what they deploy holds up once it's running. Thirty years bridging technology, strategy, and cross-border growth across the U.S. and Europe. I close the gap between what leaders expect AI to do and what it actually does in the wild.

brinsa.com
©2026 copyright by markus brinsa | brinsa.com™