Policy Is Writing Checks Enforcement Cannot Cash
Three distinct policy domains this week share an identical structural failure: rules exist, or are being designed, with inadequate enforcement infrastructure beneath them. The FINRA-style AI SRO under White House review is a direct response to the recognition that no existing agency can enforce AI standards at scale — but without Congressional mandate, any such body risks being a voluntary arrangement with limited teeth. The IAPS chip export enforcement guide makes the same diagnosis more precisely: U.S. controls on advanced semiconductors are functioning as friction and cost mechanisms rather than capacity-denial tools, with Samsung's 15% price hikes on Chinese customers and Nvidia Jetson modules appearing in Russian missile guidance systems both confirming that adversarial demand is redirected, not eliminated. Meanwhile, AI-generated bills flooding the Office of Legislative Counsel are degrading the quality of the drafting bottleneck at the heart of U.S. lawmaking, with no screening mechanism in place.
The EU AI Act provides a partial counterexample — Anthropic's watermarking implementation in Claude is a confirmed product-level change directly attributable to a named regulatory obligation, making it the clearest signal yet that EU requirements are translating into engineering decisions. But the compliance action arrived ahead of finalised technical standards, and developer communities documented workarounds within hours of the watermark's rollout, confirming that provenance enforcement via content tagging is structurally inadequate. Australia's enacted social media law, now resting on a report with citations to non-existent academic articles, illustrates the downstream consequence: once legislation passes on a defective evidence base, no automatic correction mechanism exists. Senior policy professionals should treat enforcement feasibility as a primary design constraint, not a downstream implementation detail.