AI Legislation
AI Legislation
PublicEU AI Act takes effect; US states enact AI safety laws
Monday, Jul 20, 2026
Both the EU and US are adapting AI governance frameworks in response to the ChatGPT shock and state-level momentum.
The EU AI Act, initially criticized as obsolete, evolved through multiple presidencies to impose layered rules on general-purpose AI, with enforcement beginning August 2025 and a stakeholder-drafted Code of Practice now serving as a compliance tool.
Meanwhile, US states like California, New York, and Illinois are passing frontier safety laws—documented risk assessments, public disclosure, incident reporting, and audits—that OpenAI argues can create a de facto national standard and even a US-led global framework, though the Trump administration is separately developing federal testing oversight.
The tension lies in the EU's centralized, evolving code versus the US's state-driven 'reverse federalism' strategy, with both systems now entering enforcement phases after initial gaps.
Tracking: AI Legislation · AI law · AI regulation
Geography: European Union, United States, China, United Kingdom, Canada
1. EU AI Act Adapts to General-Purpose AI After ChatGPT Shock
Critics argue that ChatGPT exposed the EU AI Act as obsolete, but the law's evolution tells a different story.
The original 2021 proposal focused on regulating AI by use case, leaving general-purpose AI models unaddressed—a gap flagged by stakeholders as early as August 2021.
Over three presidencies, the EU adapted: the Council agreed on obligations for general-purpose systems by late 2022, the Parliament added a tiered regime for foundation models in June 2023, and the final trilogue in December 2023 created layered rules.
Since August 2, 2025, all GPAI providers must supply technical documentation, copyright policies, and training-data summaries, with stricter duties for systemic-risk models.
The AI Act also left flexibility by tasking the AI Office with a Code of Practice, published July 10, 2025, which nearly 1,000 stakeholders helped draft.
The Commission and AI Board confirmed it as an adequate compliance tool, allowing rules to update without reopening the law. Enforcement only began in August 2025, leaving a year-long gap without teeth.
Key facts:
- EU proposed AI Act in April 2021, focused on regulating AI by use case.
- Stakeholders warned in August 2021 the Act lacked rules for general-purpose AI (GPAI).
- Council agreed on GPAI obligations by late 2022; Parliament added foundation model tiers in June 2023.
- Trilogue in December 2023 produced layered GPAI rules: baseline duties, lighter open-source, stricter for systemic risk.
- GPAI obligations applied from August 2, 2025, with enforcement starting a year later.
Why it matters: The AI Act's adaptation shows how regulation can evolve alongside technology, rather than freezing outdated rules.
Providers of general-purpose AI models now face clear obligations on documentation, copyright, and risk testing, leveling the playing field for compliance-heavy firms.
The Code of Practice offers a flexible update path, but its voluntary nature raises questions about enforcement strength. Watch for how the AI Office handles systemic-risk designations and whether the open-source exemption creates loopholes.
2. State AI safety laws in California, New York, Illinois advance US national framework
OpenAI is promoting a “reverse federalism” strategy for AI governance, where states pass similar frontier safety laws to create a de facto national standard.
California, New York, and Illinois have already enacted legislation with core elements: documented safety frameworks with risk assessments, public disclosure of those assessments, reporting of serious incidents, and independent audits.
At the federal level, the Trump administration is developing a framework for government testing of the most capable AI models on cyber threats.
This state-led momentum, OpenAI argues, can lay the groundwork for a US-led global AI safety framework based on democratic values, provided states avoid policy creep and focus on essential safety elements.
Key facts:
- California established the core disclosure framework for frontier AI models.
- New York showed the approach could be adopted across jurisdictions.
- Illinois required independent verification of key AI safety disclosures.
- Trump administration is working on federal AI testing framework for cyber.
- OpenAI advocates for a national standard via reverse federalism from states.
Why it matters: This state-by-state approach could avoid a chaotic patchwork of regulations, creating a uniform baseline for AI safety that benefits large developers and regulators.
However, startups may face compliance burdens, and the risk of mission creep—where states take on national security or technical reviews—could undermine coherence.
The federal testing framework adds a layer of oversight, but the ultimate shape of US AI governance will depend on whether states maintain discipline and whether Congress eventually codifies a national law.
Internationally, a US standard could compete with the EU's AI Act, shaping global norms for democratic AI deployment.
Generated by newsltr · 2026-07-20T13:03:32.161Z
