← Back to list

AI Releases a New Model Every Few Weeks.

On March 5, 2026, OpenAI released GPT-5.4. On April 23, 2026, forty-nine days later, they released GPT-5.5. In the seven weeks between…

Firuz Alimov · 2026-06-10 04:24 · 0 claps · 23.2 min read
#long-form-thinking #ai-governance #ai-regulation #systems-thinking #digital-policy
Open on Medium ↗
Wiki topics: LLM · Large Language Models

AI Releases a New Model Every Few Weeks. The World’s Governments Are Debating How to Regulate the One From Eighteen Months Ago.

On March 5, 2026, OpenAI released GPT-5.4. On April 23, 2026, forty-nine days later, they released GPT-5.5. In the seven weeks between those two releases, the European Parliament was still in the process of formally adopting the Digital Omnibus on AI that provisionally agreed in May to extend the EU AI Act’s key deadlines, pushing the high-risk standalone AI obligations back to December 2027 and the embedded AI obligations back to August 2028.

The EU AI Act was first proposed by the European Commission in April 2021. The technology it was designed to govern in 2021 bears approximately the same relationship to the technology currently shipping as a Nokia 3310 bears to the device in your pocket.

This is the central absurdity of global AI governance in 2026: the gap between the speed at which the technology is developing and the speed at which institutions are producing the rules to govern it is not narrowing. It is widening. The models are releasing on timelines measured in weeks. The regulations are operating on timelines measured in years. The decision-makers who are writing the rules are, in many cases, writing rules for capabilities that no longer represent the frontier, that are being superseded while the consultation period is still open, and that will be archaically narrow by the time they are enforced, if they are enforced, which in many jurisdictions requires several additional steps that are also running on multi-year timelines.

The specific quality of this problem varies significantly by jurisdiction, and the variation is instructive in ways that the standard narrative, which treats AI regulation as a binary choice between the EU’s precautionary approach and the US’s innovation-first approach, does not capture. The reality is that there are roughly as many approaches to AI governance as there are jurisdictions attempting it, most of them internally incoherent, most of them operating on timelines that bear no relationship to the pace of development they are trying to govern, and most of them produced by people who, with some honourable exceptions, understand the technology they are regulating the way a Victorian physician understood germ theory: they have heard of it, they have strong opinions about it, and the specific content of those opinions is going to age very poorly.

What follows is a tour of what global AI governance actually looks like from the outside, by region, with the specific quality of satirical precision that the situation warrants.

The United States. Or, Fifty Governments Disagreeing About Something One Government Is Trying to Freeze.

The American approach to AI governance is, as of May 2026, best described as an argument taking place at several institutional levels simultaneously, at sufficient volume that the argument itself has become the policy. The states have been acting because the federal government has been debating. The federal government is now trying to stop the states from acting, using a draft bill that would freeze state AI regulations for three years, which is itself an act of governance so specific about its intentions that it inadvertently reveals how the federal government has assessed the situation: the statehouses are moving faster than Washington, which is a development that Washington finds deeply inconvenient.

The Great American AI Act, the 269-page draft from Representatives Jay Obernolte and Lori Trahan, would preempt state rules on how frontier AI models are trained for three years, override safety laws in California, New York, and Illinois, require labs with over $500 million in annual revenue to publish safety frameworks and submit to semi-annual third-party audits, and flag any model posing a catastrophic risk, which the draft defines as a foreseeable threat of fifty or more deaths or one billion dollars in damage. It would write the Center for AI Standards and Innovation into law inside the Commerce Department, fund it at $100 million annually through 2029, and carry civil penalties up to one million dollars a day.

The industry groups welcomed it. The AFL-CIO called it a giveaway to the AI industry. Brad Carson of Americans for Responsible Innovation called preemption a generational mistake. The Colorado AI Act, the first law in the queue to be sidelined and set to take effect June 30, became the immediate test of whether Washington can produce legislation faster than a state legislature whose June 30 deadline is a fixed calendar fact rather than a legislative aspiration.

The White House executive order from December 2025 marked a shift toward a unified national AI policy framework with broad implications for technology companies and state governments. What it did not do was produce a law. The executive order is a direction of travel. The Great American AI Act is a bill in draft. The Colorado AI Act is a law with a date.

These three things operate on different legal authorities, different timelines, and different degrees of enforceability, and their interaction in the next few months will be the most consequential test of American AI governance architecture since the question became serious.

What the American situation reveals, beyond the specific mechanics of federal preemption, is the specific problem that plagues every democratic governance system trying to regulate a technology that moves faster than a legislative session: the accountability lag. The representatives drafting the Great American AI Act are working from a model of the risk landscape that was accurate in late 2025, based on briefings they received in early 2025 about models that were released in 2024. GPT-5.5 shipped in April 2026. The draft bill’s catastrophic risk threshold, fifty deaths or one billion in damage, was calibrated for a risk profile that GPT-5.5 has already superseded, and GPT-5.6, or whatever comes next on the five-to-seven week release cycle that has become the industry norm, will supersede it further before the bill is introduced, let alone passed.

The representatives drafting the Great American AI Act are working from a risk model calibrated for technology that was frontier in 2024. GPT-5.5 shipped in April 2026. The bill has not been introduced. The gap between those two facts is the specific problem that no legislative calendar can solve.

The one thousand plus state-level AI bills that have been introduced across American statehouses in the past three years are the evidence that the states understand something the federal government is still debating: that waiting for a national consensus produces a vacuum, and vacuums get filled by whatever is growing fastest. The states that have acted are imperfect. Colorado’s law has been criticised by AI researchers, civil liberties advocates, and industry simultaneously, which is usually the sign of a piece of legislation that tried to do too much too quickly with too little technical input and managed to annoy everyone in the process. It is also a law. The federal equivalent is still in draft.

The European Union. Or, How to Spend Five Years Regulating Something and Then Extend All the Deadlines.

The EU AI Act is the most ambitious attempt to regulate artificial intelligence anywhere on earth. It was proposed in April 2021, negotiated through three years of intense trilogue debates between the European Commission, Parliament, and Council, formally adopted in 2024, and entered into force on August 1 of that year. It establishes a risk-tiered framework that categorises AI systems into prohibited practices, high-risk systems, limited-risk systems, and minimal-risk systems, with requirements escalating from transparency disclosures for limited-risk to full conformity assessments, quality management systems, and database registration for high-risk. Penalties reach thirty-five million euros or seven percent of global annual turnover for prohibited practices violations, which is a number large enough to concentrate the attention of even the largest technology companies.

The implementation timeline has been adjusted several times, which is the diplomatic way of describing a process that has been extended to accommodate the reality that building a compliance infrastructure for a technology that keeps changing is considerably harder than building the regulation that describes what the compliance infrastructure should contain. The prohibitions on unacceptable risk practices took effect in February 2025. The general-purpose AI obligations took effect in August 2025. The high-risk system obligations were originally scheduled for August 2026 and have now, under the Digital Omnibus provisional agreement reached on May 7, 2026, been pushed back to December 2027 for standalone high-risk AI and August 2028 for high-risk AI embedded in products.

The extension is not malicious. It is the honest acknowledgement that the compliance ecosystem, the conformity assessment bodies, the notified bodies, the EU AI Office staff, the legal frameworks within member states for enforcement, does not exist at the scale the Act requires and will not exist at that scale by August 2026. The EU is extending the deadlines because the alternative is having deadlines that produce no compliance activity because the infrastructure for compliance activity does not exist.

This is rational. It is also the specific quality of governance that produces the observation, which is accurate, that the EU spent five years producing a regulation for 2024-era AI that will not be enforced in its most consequential provisions until December 2027, by which time the technology landscape will have changed in ways that the 2021 proposal could not have anticipated and that the 2024 final text did not fully capture.

The specific genius and the specific problem of the EU AI Act are the same thing: it is comprehensive. The breadth that makes it the most serious attempt at AI governance in the world is also the breadth that makes it structurally incapable of keeping pace with the technology. A risk-based framework that categorises AI systems requires defining what an AI system is, what risk means in the context of each category, what compliance looks like for each risk level, and how enforcement works for each violation type. These are not small definitional tasks. They are exercises in regulatory philosophy that the technology keeps making harder by continuing to develop while the exercises are in progress.

The European AI Office, established to oversee the general-purpose AI provisions, began its work in 2025 as a small team inside the European Commission tasked with overseeing the most technically complex aspects of AI regulation in the world. The ambition is genuine. The resources are limited. The technology is not waiting for the staffing plan.

Meanwhile, European companies and the international companies serving European customers are operating under layered compliance obligations that compound the EU AI Act with GDPR, the Digital Services Act, the Digital Markets Act, the AI Liability Directive still in progress, the Product Liability Directive updated for AI, and sector-specific requirements from financial services, healthcare, and employment regulators, all of which are simultaneously moving and not always moving in the same direction.

The compliance lawyer who specialises in EU AI obligations is the fastest-appreciating professional asset in Europe right now, which is either a commentary on the career opportunities created by regulatory complexity or on the specific cost that regulatory complexity imposes on the companies that have to navigate it.

The United Kingdom. Or, Pro-Innovation, Which Is What You Say When You Have Decided Not to Have a Law.

The UK left the European Union in 2020, which meant leaving the regulatory framework that would have produced the EU AI Act as directly applicable UK law. The UK government’s response to this was to announce a pro-innovation approach to AI governance, which is the phrase that means the government has decided that not regulating is itself a regulatory choice and would like credit for the decision.

The pro-innovation framing is not incoherent. The argument that binding rules for a technology in its early development phase impose compliance costs that impede the innovation that would produce the societal benefits justifying the rules is a serious argument with serious proponents. It is also an argument that the industry being regulated finds very compelling, which is either because the argument is correct or because the industry prefers to be unregulated and has articulated an argument for why this is in everyone’s interest.

The UK approach assigns AI governance responsibilities to existing sectoral regulators: the FCA for financial services, the CMA for competition, the ICO for data, the MHRA for medical devices. Each regulator is supposed to develop guidance for AI in their domain using their existing powers and their existing staff, who have varying levels of AI technical expertise and resources. The advantage of this approach is speed and flexibility: the existing regulators can move at their own pace without waiting for new legislation. The disadvantage is that horizontally applicable AI risks that cross sector boundaries fall between the existing regulatory mandates, that the pace and depth of guidance varies enormously across regulators, and that the companies building AI products with applications across multiple sectors face a different regulatory question for each sector with no single authoritative framework.

The AI Governance and Safety Institute, established in 2023 and rebranded the AI Security Institute in 2024, conducts pre-deployment safety evaluations of frontier models in collaboration with labs that participate voluntarily. The key word in that sentence is voluntarily.

The Institute has published interesting safety research. It has no enforcement powers. The labs participate because the reputational benefit of participating is currently higher than the cost of the evaluations. When that calculus changes, the voluntary nature of the arrangement is the mechanism through which the Institute’s influence changes with it.

Singapore. Or, The World’s Most Thoughtful Voluntary Framework.

Singapore has been building AI governance infrastructure longer than almost any other jurisdiction, and with a specific quality of practical pragmatism that reflects the city-state’s approach to most policy challenges: identify the problem clearly, consult widely, produce guidance that is technically coherent and operationally usable, and implement it through industry partnership rather than enforcement action. The Model AI Governance Framework, the world’s first, was published in 2019. It has been updated multiple times.

In January 2026, Singapore launched the world’s first governance framework specifically for agentic AI, acknowledging that the move from AI systems that answer questions to AI agents that take actions in the world represents a qualitative shift in the risk profile that existing frameworks did not adequately address.

The Singapore framework is thoughtful, well-structured, and explicitly acknowledges that organisations remain legally accountable for the behaviours of their AI agents even when those behaviours are autonomous. It provides practical guidance on human oversight, accountability structures, and risk assessment for agentic systems. It is also, in its enforcement dimension, essentially voluntary. Singapore’s approach to AI governance reflects the broader ASEAN philosophy of non-interference, which produces frameworks that are reference documents rather than enforcement regimes. The company operating AI agents in Singapore that ignores the January 2026 framework faces no formal legal consequences from doing so, because the framework does not currently create any.

This is not a criticism of Singapore specifically. It is a description of the structural challenge that every jurisdiction faces when trying to govern a technology that is commercially important to its economy and legally difficult to define precisely enough for enforcement.

Singapore’s voluntary approach has produced genuine industry engagement and a level of practical AI governance thinking that many binding regulatory regimes have not achieved. Whether voluntary engagement produces safe AI deployment, or whether safe AI deployment requires the specific incentive of enforcement risk, is a question that Singapore, along with every other jurisdiction operating in this space, is discovering the answer to in real time.

Southeast Asia. Or, The Fastest-Growing AI Infrastructure Region With the Loosest Governance Framework.

Southeast Asia presents the most instructive tension in global AI governance: the region is simultaneously becoming a critical node in global AI infrastructure and operating with the least binding governance framework of any major economic region. Malaysia and Thailand have become significant data centre hubs as hyperscalers expand their Asian capacity, with Microsoft, Google, and Amazon all announcing multi-billion-dollar investments in regional infrastructure in 2024 and 2025. The rules governing how those data centres manage AI workloads, handle the data flowing through them, and respond to AI-related incidents are still, in both countries, being drafted.

The ASEAN AI Guide, updated in 2025 to include generative AI, establishes seven principles for AI governance across member states: transparency, fairness, security, reliability, human-centricity, privacy, and accountability. These are correct principles. They are also entirely voluntary. The ASEAN approach reflects the bloc’s foundational non-interference doctrine, which prevents binding regional standards in the same way that it prevents binding regional action on most things. Each of the ten ASEAN member states is developing its own approach, at its own pace, with its own technical capacity, which produces an archipelago of governance frameworks that range from Singapore’s globally-referenced voluntary leadership to the meaningful absence of any framework in several smaller economies.

Thailand’s Electronic Transactions Development Agency (ETDA) has been revising its consolidated draft AI principles after a public consultation in 2025, but the timeline for the law remains unclear. Indonesia was expected to sign off on AI regulations as Presidential regulations in early 2026, a process that reflects the country’s approach to technology governance through executive action rather than legislative process. Vietnam enacted an AI law in 2026, making it one of the first Southeast Asian countries with binding obligations. The Philippines is still in the early stages of AI governance framework development. Each of these is moving at a pace that is faster than it was two years ago and slower than the AI deployment it is attempting to govern.

The specific risk of the Southeast Asian governance gap is not primarily about sophisticated AI systems making problematic decisions in the region. It is about the region’s role as infrastructure. The data centres in Malaysia and Thailand are processing AI workloads for companies globally. The AI systems deployed through that infrastructure serve customers in jurisdictions with stronger governance requirements.

The regulatory arbitrage opportunity, the possibility of routing AI processing through jurisdictions with minimal oversight to avoid the compliance obligations of jurisdictions with more, is already visible in how some companies are thinking about their AI infrastructure geography. The gap between the governance of AI deployment locations and the governance of AI impact locations is the specific problem that no purely national regulatory approach can solve.

West Asia and the Gulf. Or, When You Declare a Year of AI and Mean It.

Saudi Arabia declared 2026 the Year of AI. This is not a metaphor. It is a national policy commitment backed by the resources of an economy with significant sovereign wealth, a young and digitally engaged population, and the specific quality of institutional urgency that comes from a national leadership that has decided AI is the primary mechanism of economic diversification from hydrocarbon dependence and is treating the deadline accordingly. The Saudi Data and AI Authority, SDAIA | سدايا , issued forty-eight decisions under the Personal Data Protection Law in 2025, the enforcement activity of a regulator that has decided that governing data and governing AI are the same problem and that both require active enforcement rather than guidelines.

The Gulf approach to AI governance is in some ways the inverse of the European approach. Where the EU built a comprehensive regulatory framework first and is now building the enforcement capacity, the Gulf states are building enforcement capacity and practical infrastructure first and developing the comprehensive framework as the deployment matures.

The UAE’s AI strategy, its AI regulation framework, and its specific investments in AI research institutions and deployment projects have made it the most AI-forward government in the region and one of the most AI-forward governments globally. The challenge for the Gulf regulatory approach is not ambition. It is the specific tension between a governance culture that operates through executive direction rather than parliamentary process and a technology that requires the kind of distributed, adaptive, multi-stakeholder governance that executive direction struggles to produce at scale.

The West Asian approach also reflects a different risk prioritisation than the European or American one. Where EU and US AI governance is primarily oriented around protecting individuals from AI-related harms, the Gulf state approach is more explicitly oriented around enabling AI-related growth. These are not incompatible goals, but they produce different regulatory reflexes, and the regulatory reflex that prioritises growth over protection tends to discover the protection cases it missed through enforcement activity after the fact rather than through precautionary framework design before the deployment.

Oceania. Or, Firming Up the Guardrails, Which Is Happening, Apparently.

Australia’s AI governance journey is the journey of a country that has watched what happened to the early movers in AI regulation, observed the compliance costs and the innovation concerns and the extension of the deadlines, and concluded that ‘firming up guardrails’ is the appropriate pace for a mid-sized economy that is neither a frontier AI developer nor, yet, a major AI deployment scale. The Australian government has been developing a voluntary AI Ethics Framework since 2019. It has been consulting on a mandatory guardrails proposal since 2024. The expected firm-up-by-2026 that appears in every analysis of Australian AI governance reflects genuine forward movement and a realistic assessment that the guardrails are still being installed when the cars are already driving.

New Zealand has been even quieter about AI governance, which is either sensible restraint or the specific quality of governance gap that becomes visible only when the first significant AI-related incident occurs and the affected party discovers there is no regulatory framework they can invoke. The Algorithmic Charter for Aotearoa New Zealand commits government agencies to transparency and human oversight in their algorithmic decision-making. It covers government, not the private sector. It is also, like almost every other voluntary commitment in this space, a document rather than an enforcement mechanism.

The Pacific island states present the starkest version of the global governance gap: small administrations with minimal technical capacity, growing exposure to AI systems deployed by companies headquartered in jurisdictions whose regulations do not extend to the Pacific, and no realistic prospect of building the domestic regulatory capacity that the EU AI Act’s model assumes.

The AI governance discussion in the Pacific happens, to the extent it happens, through regional bodies and development organisations that produce voluntary guidance. The AI systems affecting Pacific communities are governed, in practice, by the terms of service of the companies that built them.

Japan and South Korea. Or, The Countries That Regulated AI With More Seriousness Than Most and Less Drama Than Anyone.

Japan enacted its AI Promotion Act in May 2025, which establishes a non-binding framework focused on strategic coordination across government agencies, transparency goals, and research and development promotion. This is weaker than what the name suggests, but it reflects Japan’s consistent approach to technology governance: voluntary industry cooperation, international coordination through the G7 Hiroshima AI Process that Japan shaped during its 2023 presidency, and the specific cultural preference for building consensus before writing rules that makes Japanese regulatory development slower than the European model but considerably more likely to achieve genuine industry alignment when it arrives. Japan’s AI Safety Institute, modelled after the UK’s, focuses on pre-deployment testing of frontier models with an emphasis on voluntary cooperation and international coordination.

South Korea is the most quietly consequential AI governance story of 2025 and 2026. The AI Basic Act took effect on January 22, 2026, making South Korea the second country globally, after the EU, to have comprehensive AI legislation in force. The Act establishes a risk-based classification system broadly similar to the EU approach but with lighter compliance requirements and a stronger explicit emphasis on promoting AI innovation alongside managing its risks. South Korea’s approach reflects the specific situation of a country whose national champions, Samsung, LG, Hyundai, Kakao, are both deployers of AI at scale and, in some cases, developers of AI capabilities, and whose regulatory instincts therefore have to balance the protection concerns of a regulator with the competitiveness concerns of an industrial policy maker.

The combination of Japan’s voluntary coordination approach and South Korea’s binding but innovation-oriented framework is, in some ways, the most honest attempt in the world to produce AI governance that reflects the actual state of the technology rather than the state of governance theory. Neither country pretends that the rules they are writing will keep up with the development they are governing. Both countries have decided that imperfect governance that is actually implementable is better than perfect governance that is not.

China. Or, Regulation Through Architecture, Which Is the Most Efficient Form of Governance and the Most Concerning.

China’s approach to AI governance is fundamentally different from every other approach described in this essay, and the difference is not primarily about authoritarianism, though that dimension exists and matters. The difference is that China has chosen to embed governance requirements directly into system architecture rather than relying on post-deployment enforcement. Carnegie Endowment researchers have characterised this as ‘regulation through technical control,’ which is a precise description of a system in which the compliance obligation is built into the infrastructure itself rather than appended to it through legal requirements that companies may or may not meet.

The Measures for Labelling AI-Generated and Synthetic Content, effective September 2025, require platforms to implement specific detection mechanisms including audio Morse codes, encrypted metadata, and VR-based watermarking systems. The amended Cybersecurity Law that became enforceable on January 1, 2026 explicitly references AI and adds requirements for security reviews and data localisation. A draft AI Law proposed in 2024 may formalise binding requirements for high-risk systems, potentially creating a comprehensive AI law equivalent to the EU AI Act but with enforcement characteristics that the EU model does not have.

The Chinese regulatory approach is fast, technically specific, and operates with an enforcement capacity that European regulators would find difficult to match. It also reflects the specific governance values of a system in which the primary risk that regulation is designed to address is not individual harm but state stability, and in which the most significant AI governance decisions are made by people whose primary accountability is to a party rather than a parliament.

The efficiency of Chinese AI governance and its specific orientation away from individual rights protections are not separable features. They are the same feature viewed from different perspectives.

The Velocity Problem. Which Is the Only Problem That All of These Have in Common.

The global AI governance landscape in May 2026 can be summarised as follows: over seventy-two countries have launched more than a thousand AI policy initiatives. The EU AI Act is the most comprehensive framework and is extending its deadlines. South Korea has the most recent comprehensive law and is already watching the technology it regulates develop beyond the capabilities the law anticipated. Singapore has the most thoughtful voluntary framework and no enforcement mechanism. China has the most efficient enforcement and the most specific values embedded in its framework. The United States has a draft preemption bill, a thousand state laws, an executive order, and a June 30 deadline that will answer whether Washington can outrun a statehouse. Australia is firming up its guardrails. The Pacific islands are reading the terms of service.

The one thing that connects all of these approaches is the velocity problem: the speed at which frontier AI capabilities are developing is not connected to the speed at which any governance system on earth is capable of responding. GPT-4.5 was released in February 2025. GPT-4.1 in April 2025. GPT-5 in August 2025. GPT-5.2 in December 2025. GPT-5.4 on March 5, 2026. GPT-5.5 on April 23, 2026. These are the publicly visible releases of a single company.

The aggregate development activity across OpenAI , Anthropic , Google DeepMind , Meta , Mistral , XAI , Baidu, Inc. , and dozens of other frontier labs is happening at a pace that the phrase ‘moving quickly’ does not adequately describe.

The EU AI Act was designed for the risk profile of GPT-3 era AI, updated through the negotiations to address GPT-4 era capabilities, and will be enforced in its most consequential provisions in December 2027 against AI capabilities that nobody in the 2021 drafting room could have anticipated.

The Great American AI Act’s catastrophic risk threshold, fifty deaths or a billion dollars in damage, is a threshold that was calibrated for the risk models of late 2025 and that will be evaluated against the capabilities of whatever frontier model ships in late 2027. The ASEAN voluntary principles, written in 2019 and updated in 2025, describe desirable properties of AI systems at a level of abstraction that is genuinely applicable to every generation of AI and genuinely insufficient to govern any particular generation.

The EU AI Act was designed for GPT-3, updated for GPT-4, and will be enforced in December 2027 against capabilities that nobody in the 2021 drafting room could have anticipated. This is not a failure of the people writing the rules. It is a structural feature of the gap between legislative timelines and development velocity.

The velocity problem is not a failure of the people writing the rules. Most of them are working in good faith with the best information available to them. The structural problem is that legislation requires consensus, and consensus requires time, and time is the resource that the technology is not waiting for. The legislative process that produced the Colorado AI Act took years. The technology that Colorado’s law is trying to govern released three new major versions during those years. The congressional process for the Great American AI Act will take months at minimum, years at realistic estimate, during which the technology will continue releasing on its five to seven week cadence, each release changing the risk landscape that the draft bill’s definitions were written for.

The decision-makers drafting these rules are not ignorant. Many of them have received briefings from technical experts, held hearings with industry representatives, consulted with civil society organisations, and read the research that is available. What they are is temporally misaligned. Their process operates on a timeline that is structurally incapable of keeping pace with the subject matter of their decisions, and the subject matter is not going to slow down to accommodate the process. This is not a solvable problem in the framework of existing legislative and regulatory institutions. It is a permanent feature of trying to govern exponential technology with linear institutions.

What Would Actually Help. A Short Section, Because the Options Are Limited.

The governance approaches that have the best chance of remaining useful as the technology develops are not the comprehensive binding frameworks with precise definitions, because the precise definitions become inaccurate faster than they can be updated. They are the approaches that govern outcomes rather than technologies, that create accountability for consequences rather than compliance with capability classifications, and that build update mechanisms directly into the regulatory architecture rather than requiring new legislation every time the technology changes.

The EU AI Act’s risk-tier classification, which defines high-risk AI by the domain of application rather than the technical capability, is more durable than a classification based on model size or compute threshold, because the domain of application changes more slowly than the technical capability. Employment decisions, credit scoring, law enforcement, medical devices: these are high-risk regardless of whether the AI making the decisions is a 2024 model or a 2028 model. The capability classification elements of the Act, the general-purpose AI obligations triggered by compute thresholds, are the elements that will require the most frequent updating because the compute frontier moves fastest.

Singapore’s approach of rapid guidance cycles, which can update voluntary frameworks faster than binding legislation, is better suited to a fast-moving technology than the EU’s comprehensive legislation approach, with the specific limitation that voluntary guidance without enforcement creates guidance that is followed when convenient and ignored when inconvenient. The combination that no jurisdiction has fully achieved is binding accountability for outcomes with flexible guidance on how to achieve compliance, updated on cycles that match the development pace rather than the legislative calendar.

AI Safety Institutes, the pre-deployment evaluation bodies that the UK, US, and Japan have established, are the closest thing to a velocity-matched governance mechanism: they can evaluate models as they are released rather than on a legislative cycle. Their current limitation is enforcement authority. A Safety Institute that can tell the world what a model does but cannot require changes to a model that poses unacceptable risks is an observatory, not a regulator.

The next phase of AI governance development is the transition from Safety Institutes that observe to Safety Institutes that act, and the political will to make that transition is the question that the next significant AI-related incident will answer.

The Cynical Conclusion. Which Also Happens to Be the Accurate One.

The global governance of AI is simultaneously more serious and more inadequate than it has ever been. More serious because there are now binding laws in multiple jurisdictions, enforcement actions being taken, and institutional capacity being built at a pace that would have seemed implausible three years ago. More inadequate because the technology it is trying to govern is developing faster than at any point in the history of attempts to govern it, and the most consequential capabilities of 2026 AI are being deployed, at scale, into the decisions that affect employment, credit, healthcare, law enforcement, and democratic participation, under governance frameworks that range from thoughtful but voluntary to technically serious but not yet in force.

The specific irony of the Great American AI Act is that it is trying to solve the wrong version of the problem. The problem it is solving is the proliferation of incompatible state laws that create compliance complexity for companies building AI across state lines. This is a real problem. The problem it is not solving, because no legislative process can solve it, is the velocity gap between AI development and AI governance. A three-year federal preemption creates a regulatory space in which the largest labs answer to one federal rulebook instead of fifty, which reduces compliance complexity for the largest labs and reduces the speed at which the regulatory environment can respond to AI developments that require a response faster than the federal rulemaking process allows.

The EU’s extension of its high-risk obligations to December 2027 is, beneath the diplomatic language of allowing the compliance ecosystem to mature, an acknowledgement that the most ambitious AI governance framework in the world is not ready to be enforced on its original schedule, which was itself a schedule that everyone involved knew was optimistic when it was set. The extension is honest. It is also the admission that the gap between regulatory ambition and regulatory capacity is real, and that capacity is the binding constraint on governance, not ambition.

In Southeast Asia, the AI infrastructure is being built faster than the governance frameworks that should accompany it. In the Gulf, the deployment ambition outpaces the protection framework. In the Pacific, the communities most exposed to the downstream effects of AI governance decisions made in other jurisdictions have the least input into those decisions. In Washington, a three-year freeze is being proposed for a technology that will look fundamentally different in three months. In Brussels, a digital omnibus is extending deadlines that were already extended. In Tokyo, a voluntary framework is generating international goodwill and uncertain domestic compliance. In Seoul, a binding law is in force for technology that is already a generation ahead of what the law describes.

The technology is not waiting. It shipped GPT-5.5 while the committee was still reviewing GPT-5.4. It will ship something else before this essay finds its audience, and the governance framework that was supposed to catch up will be another few weeks behind.

The committee will reconvene after lunch. The technology will have released a new model by then. The minutes from the last meeting will note that the situation was evolving rapidly and that further consultation was required. The minutes will be accurate. The situation will be worse.

AIRegulation #AIGovernance #GlobalPolicy #EUAIAct #TechPolicy #ArtificialIntelligence #DigitalPolicy #FederalPreemption #SystemsThinking #LongFormThinking #GeoTech #Regulation #Innovation #PolicyDesign #NoBS


메타데이터
post_id
3eeacfb019f5
slug
ai-releases-a-new-model-every-few-weeks-3eeacfb019f5
url
https://medium.com/@firalim/ai-releases-a-new-model-every-few-weeks-3eeacfb019f5
canonical_url
https://medium.com/@firalim/ai-releases-a-new-model-every-few-weeks-3eeacfb019f5
author_url
https://medium.com/@firalim
status
ok
fetched_at
2026-06-13 16:00:06