Enforcement Is Outrunning Legislation — But Only at the State Level
The contrast this week could not be starker. California's AG issued a legally binding subpoena to OpenAI — with discovery obligations that will surface internal documentation on agent oversight and incident response — while the White House was signing a voluntary 'Super Intelligence' accord that carries no penalty structure, no verification regime, and not even consistent spelling. The accord confirms that the current US federal posture on frontier AI remains self-regulatory, widening the divergence from the EU AI Act's mandatory compliance architecture. Into that vacuum, state attorneys general are functioning as the operative enforcement layer, a pattern consistent with California's historical role on consumer privacy under CCPA.
Internationally, the governance gap is equally visible. Australia's copyright consultation pits Anthropic's opt-out training data proposal against the ABC and SBS — public broadcasters warning of content cannibalisation — forcing the Albanese government to choose between AI industry accommodation and media sector protection. The Gebru-Bender commentary on a near-miss military AI incident with China adds a higher-stakes dimension: the regulatory frameworks most governments have constructed address bias, transparency, and data rights, but not the brittle reliability failures already occurring in live government deployments. The practical implication for policy professionals is that enforceable AI governance is, for now, being written case by case through subpoenas and enforcement actions — not through statute.