Two regimes for the same companies - Washington, Brussels and the regulation of frontier models
At the turn of August 2026, three consecutive days displayed two opposing ways of governing the same five companies. On 1 August, the deadline set by US Executive Order 14409 expired without any public deliverable. On 2 August, the European AI Office acquired its full powers of sanction over providers of general-purpose AI models. On 4 August, the White House convened Meta, OpenAI, Google and Anthropic around a voluntary review framework. This contribution compares the two trajectories along three axes — the criterion that designates the companies concerned, the legal form of the constraint, and the level at which it is exercised — and argues that they are not answering the same question.
Introduction: three days, five companies, two logics
The calendar sometimes composes juxtapositions that no intention designed. The week of 2 August 2026 offers one that is useful to comparative analysis, because it sets two legal systems side by side, acting within hours of one another on exactly the same addressees.
On Saturday 1 August, the sixty-day deadline set by US Executive Order 14409 expired — the deadline for defining what constitutes a “covered frontier model”, for establishing a voluntary disclosure framework, and for producing a plan to strengthen the federal cybersecurity workforce. According to available reporting, none of these three deliverables was made public by that date1.
On Sunday 2 August, Regulation (EU) 2024/1689 crossed its most significant threshold for providers of general-purpose artificial intelligence models: the AI Office came into possession of the full range of its investigative and sanctioning powers over them2.
On Tuesday 4 August, the White House convened executives from Meta, OpenAI, Google and Anthropic to review a framework for assessing the cyber capabilities of the most advanced models — a framework whose primary legal characteristic is that it is voluntary, and whose founding executive order expressly forbids its use as the basis for any prior-authorisation regime3.
A point of vocabulary must be settled before any comparison, because it conditions the validity of the exercise. There is at present no US federal statute regulating frontier models. There is an executive order, a voluntary framework under development, and a draft bill — the Great American Artificial Intelligence Act of 2026 — released on 4 June 2026 as a discussion document which, two months later, has not been formally introduced in Congress4. Comparing a regulation in force and enforceable with a text that does not yet have a bill number would be methodologically unsound if the aim were to measure relative stringency. The exercise nonetheless retains its full interest if one compares what each system chooses to do: the criteria by which it designates those it intends to reach, the legal form it gives to constraint, and the level at which it places the decision.
That is the object of this contribution. We shall examine in turn the facts of the period (I), the criterion for selecting addressees (II), the form of the constraint (III) and the vertical allocation of competence (IV), before assessing what the comparison permits us to conclude (V). The thesis defended is that the two systems converge on their target — a restricted and largely identical set of companies — but diverge on the three axes examined, to such a degree that the common phrase “regulating artificial intelligence” covers two distinct operations answering two different questions.
I. The state of the law as at 5 August 2026
A. The American arrangement
Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, was signed on 2 June 2026 and published in the Federal Register on 5 June5. Its general economy deserves accurate description, since it is frequently summarised inaccurately.
The order establishes a coordination framework for national security and cybersecurity. It tasks the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology with developing a classified process for assessing a system’s advanced cyber capabilities and determining whether it constitutes a “covered frontier model”. It invites developers to give the federal government access to such models for up to thirty days before release. And it states, in terms that leave no room for doubt, that nothing in it shall be construed to authorise the creation of a mandatory governmental licensing, preclearance or permitting requirement for the development, publication or distribution of a model6.
The voluntary character is therefore neither a drafting accident nor a transitional stage: it is a claimed feature of the arrangement. The framework announced on 3 August and reviewed with the companies the following day belongs to that economy. As at the time of writing, neither the testing methodology nor the metrics adopted have been published, and the order itself provided that certain benchmarks would remain classified7.
B. The European arrangement
On the European side, the 2 August 2026 milestone creates no new obligations: it renders enforceable those that already existed. Obligations on providers of general-purpose AI models have applied since 2 August 2025; it is the power to sanction them that opens a year later. The AI Office may now require information, conduct model evaluations, demand corrective measures and impose fines.
One figure circulating in this connection must be corrected, as it distorts the comparison. The ceiling of thirty-five million euros or seven per cent of worldwide turnover, frequently cited, corresponds to Article 99(3) and sanctions the practices prohibited by Article 5 — manipulation, exploitation of vulnerabilities, social scoring. Fines applicable to providers of general-purpose AI models fall under Article 101, and their ceiling is three per cent of total annual worldwide turnover or fifteen million euros, whichever is higher. They may be imposed where the provider has, intentionally or negligently, failed to comply with its obligations, refused to supply information, provided inaccurate information, or refused access to the model for the purposes of evaluation8.
It should finally be noted what Regulation (EU) 2026/1744 of 8 July 2026 — the “Digital Omnibus on AI” package, published in the Official Journal on 24 July and in force since 27 July — has amended and what it has left untouched. It defers to 2 December 2027 the obligations relating to standalone high-risk systems under Annex III, and to 2 August 2028 those relating to systems embedded in regulated products. It shortens, by contrast, the transition period for marking synthetic content, brought forward from 2 February 2027 to 2 December 2026. And it does not touch the obligations of providers of general-purpose AI models9. The deferral, often presented as a wholesale weakening, therefore spared precisely the segment with which this comparison is concerned — and tightened, on another point, the original timetable.
II. The selection criterion: computing power or revenue
The question of who is covered precedes the question of what is required. The two systems answer it with criteria of a different nature, and that difference is not technical: it engages a conception of what regulation claims to grasp.
A. The European threshold: a property of the model
The European regulation distinguishes general-purpose AI models and, among them, those presenting systemic risk. Article 51 establishes a presumption: a model is deemed to have high-impact capabilities where the cumulative amount of computation used for its training, measured in floating-point operations, exceeds 10²⁵. The Commission may in addition classify a model in that category on the basis of the criteria in Annex XIII10.
Obligations are arranged in two tiers. Article 53 applies to every provider of a general-purpose model: technical documentation, information for downstream providers, a copyright compliance policy, and a summary of the content used for training. Article 55 adds, for systemic-risk models, model evaluation in accordance with state-of-the-art protocols — including documented adversarial testing — assessment and mitigation of systemic risks, notification of serious incidents to the AI Office, and an adequate level of cybersecurity11.
The criterion adopted therefore bears on a property of the artefact. It considers neither the size of the undertaking, nor its revenue, nor its legal form. A university laboratory or a heavily capitalised young company crossing the threshold would be subject to the same obligations as a listed group.
B. The projected American threshold: a property of the company
The American draft combines two criteria. A frontier model is defined there by a computing threshold above 10²⁶ operations — an order of magnitude above the European threshold. But the text adds a condition attaching to the developer: qualifying as a frontier developer presupposes gross revenue above fifty million dollars, and as a large frontier developer, to which the heaviest obligations attach, revenue of at least five hundred million12.
Those obligations are substantial. They include the annual publication of a risk-management framework, transparency reports published before or concurrently with each release or substantial modification, semi-annual audits conducted by independent verification organisations with access to documents, personnel and systems, notification of critical incidents within fifteen days — reduced to twenty-four hours where risk is imminent — and whistleblower protections. Enforcement would rest with the federal Attorney General and with state attorneys general. The text would also raise the annual funding of the Center for AI Standards and Innovation from fifteen to one hundred million dollars13.
C. What each criterion produces
The comparison of the two criteria lends itself to dispassionate examination, since each has identifiable merits and blind spots.
The computing threshold captures a capability independently of market position. It is verifiable, at least in principle, and it does not reward small size. Its weakness is known and documented: it ages badly. Gains in algorithmic efficiency make it possible to obtain, with fewer operations, capabilities that previously required more, so that a fixed threshold shifts in practice towards greater relative stringency for some and less for others. It is an indicator, not a measurement.
The revenue threshold captures something else: the capacity to bear the cost of compliance, and incidentally market position. It avoids imposing semi-annual audits on a structure that could neither finance nor organise them. But it produces a structural consequence that must be stated without judgment: an equally capable model escapes the obligations if it is produced by an entity that does not reach the commercial threshold — an open-weight developer, an academic laboratory, a non-commercial entity, or the subsidiary of a foreign actor without consolidated domestic revenue. The arrangement then regulates the company rather than the object.
Two non-overlapping perimeters result. The European arrangement, with a threshold ten times lower and no revenue condition, mechanically reaches a wider set. The projected American arrangement targets, by the admission of the analyses accompanying it, a restricted and nameable group — OpenAI, Anthropic, Google, Meta, xAI14. That regulation should implicitly designate its addressees by name is not in itself a criticism; it is a feature with effects on competition, on the incentive to cross or not cross the threshold, and on the perceived legitimacy of the arrangement.
III. The form of the constraint: obligation and undertaking
A. American voluntarism and its condition of existence
The framework arising from Executive Order 14409 rests on the assent of the companies concerned. This feature calls for two observations, one favourable, the other less so.
A voluntary arrangement has real advantages in a field where information asymmetry is extreme. It secures technical cooperation — access to models before release, sharing of evaluation methodologies — that a contentious obligation would take years to produce. It adjusts to the evolution of the regulated object faster than a statute. And it does not require settling, before the necessary knowledge is available, definitional questions that have been shown to resist settlement.
Its condition of existence, however, is that the companies consent, and its content is negotiated with them. Several analyses have noted that the thresholds determining which models will be subject to prior review are developed with the participation of the companies that will be subject to them, and hence that future competitors will have to clear a threshold they did not help to write15. This mechanism is well documented in the sociology of law: organisations subject to an indeterminate obligation construct its operational meaning themselves, and that construction is frequently ratified thereafter by the authority16. The observation implies no imputation of intent; it describes an observable institutional dynamic, and it is worth stating because it is foreseeable.
The episode of 1 August provides, moreover, factual evidence about the robustness of the method. A deadline set by executive order passed without public output, and developers remain, at that date, unable to determine whether their architectures will fall within the category of covered models, for want of that category having been defined. An arrangement whose trigger is not yet established produces, in the meantime, no verifiable effect.
B. European constraint and its condition of effectiveness
The European arrangement does not warrant a symmetrically favourable assessment, and it would be dishonest to present it as the solution the other failed to find.
Its strength is clear: the obligations are enforceable, breach of them is sanctionable, and the level of fines is fixed in advance. A provider who refuses access to its model for evaluation purposes incurs a sanction; that is a difference in kind from a framework whose participation is a matter of decision.
Its condition of effectiveness is nonetheless demanding and not assured. To sanction presupposes finding a breach, and finding a breach presupposes evaluating models the authority does not hold, against criteria — the adequacy of technical documentation, the “sufficiently detailed” character of the training-data summary, an adequate level of cybersecurity — that are open standards. The evaluation capacity of the AI Office, its staffing and its access to technical expertise constitute the major unknown of the arrangement, and no provision resolves it in itself.
It should be added, for the accuracy of the picture, that Europe has not abstained from co-regulation either. The code of practice for general-purpose AI models and the template for the training-content summary were drawn up under the aegis of the AI Office with the actors concerned. The difference from the American method is therefore not the absence of co-production, but its placement: in Europe it sits within a binding framework whose execution it specifies; in the United States it stands in place of a framework. The distinction is one of degree as much as of kind, and it is more accurate to present it so.
IV. The level: harmonising upwards, preempting downwards
The third axis of divergence concerns the vertical allocation of competence, and it produces the most instructive juxtaposition.
The European Union chose the form of a regulation, directly and uniformly applicable, precisely to prevent twenty-seven divergent national regimes from fragmenting the internal market. Harmonisation is presented there, and generally received, as an instrument of protection: a single normative tier, more demanding than the average of what it replaces.
The American draft performs a structurally analogous and politically inverse operation. It would prohibit states from establishing, continuing in effect or enforcing any rule specifically regulating the development of an artificial intelligence model, for three years, with a sunset in December 2029. Laws of general applicability — data protection, consumer law, anti-discrimination — would be preserved, as would state competence over post-deployment stages and over uses17.
Three state laws are directly concerned. California adopted the Transparency in Frontier Artificial Intelligence Act, signed on 29 September 2025 and applicable since 1 January 2026, which defines a frontier model by a threshold of 10²⁶ operations and imposes enhanced obligations on developers whose annual revenue, including affiliates, exceeded five hundred million dollars in the preceding year. New York State adopted the RAISE Act, Illinois SB 315; both adopt the same computing threshold and require incident notification within seventy-two hours, shorter than the fifteen days adopted in California and in the federal draft18.
One particularity deserves noting, without necessarily reading a contradiction into it: the federal draft borrows from the state laws it would displace both the computing threshold and the five-hundred-million-dollar revenue threshold. The federal text therefore does not invent the criteria; it federalises their use while removing from the states the competence to develop them on the development segment. Its promoters see in this the substitution of a coherent national regime for a costly patchwork; its opponents — Public Citizen, Public Knowledge and the AFL-CIO have taken that position — see the neutralisation of a tier that legislated faster than Congress. Both readings describe the same mechanism and differ on its assessment19.
The juxtaposition with Europe is then as follows. In both polities, the operation consists in substituting a single normative tier for a plurality of possible tiers. What distinguishes the two cases is not centralisation, which is common to both, but the level of stringency of the tier retained relative to what it replaces, and the fact that one is in force while the other remains a draft.
V. What the comparison permits us to conclude
It is tempting to present these trajectories as the respective positions of two competitors on a single road, one further along than the other. The description would be convenient and inaccurate.
The two systems are not asking the same question. The European regulation asks what a provider must document, evaluate, mitigate and declare: this is a question of market regulation, addressed to an economic operator and sanctioned as such. The American executive order asks what cyber capabilities a model possesses and whether the state may examine it before release: this is a question of national security, addressed to a technical object and handled by intelligence and cybersecurity agencies by means of partly classified benchmarks. That both approaches reach the same companies does not make them comparable term for term; they do not address the same risk and do not mobilise the same authorities.
Three real convergences nonetheless remain, and they are more instructive than the overall opposition.
The first is the target. Both systems, by different routes, arrive at a restricted and largely identical set of companies. The regulation of frontier models is, in fact, nominative regulation, whatever drafting precautions are employed to avoid writing it down.
The second is the recourse to a quantitative threshold. Both need an objectifiable trigger, and both have adopted one whose informational value is contested. The computing threshold is a convenient and ageing entry indicator; the revenue threshold measures a capacity to contribute rather than a risk. Neither measures what is claimed to be regulated.
The third is dependence on evaluation capacity. Whether access to the model is obtained by constraint or by consent, one must then know what to do with it. Both systems come up against the same limit: the expertise required to appraise a frontier model resides principally with those who produce it. That is the central problem, and neither the regulation nor the executive order resolves it — they organise it differently.
Three observation points will make it possible, in the coming months, to measure what each arrangement actually produces: whether or not the definition of the covered frontier model and the methodology of the American voluntary framework are published; whether or not the draft is formally introduced and what becomes of its preemption clause; and whether or not the AI Office opens a first procedure under Articles 91 to 93 of the European regulation. So long as these three unknowns persist, any comparative assessment of stringency is anticipation rather than observation.
Conclusion
The phrase “regulating artificial intelligence” designates, on either side of the Atlantic, two operations that have nothing in common but their addressees. One subjects an economic operator to enforceable documentary obligations, under the supervision of a market administration and under the threat of capped fines. The other organises the access of security agencies to a technical object, on a consented basis and according to benchmarks that will in part not be published.
From that difference one cannot infer that one system protects better than the other: they do not protect against the same thing. One can, however, infer a difference that is not technical in nature. A regime of written obligations produces, by construction, a trace: published thresholds, capped sanctions, decisions open to challenge. A regime of negotiated undertakings produces cooperation, and leaves to the discretion of its parties what will be made public.
That difference is verifiable today, without waiting for the first litigation. It determines what researchers, courts and citizens will be able to know about the models that concern them — and, consequently, what it will be possible to debate.
Bibliography
Normative and institutional sources — European Union
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L, 2024/1689, 12 July 2024 (Articles 51, 53, 55, 91 to 93, 99 and 101; Annexes XI, XII and XIII).
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (“Digital Omnibus on AI”), OJ of 24 July 2026, in force 27 July 2026.
- European Commission, General-Purpose AI Models in the AI Act — Questions & Answers, Directorate-General for Communications Networks, Content and Technology.
- AI Office, code of practice for general-purpose AI models, 2025; public template for the summary of content used for training, 2025.
Normative and institutional sources — United States
- Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, 2 June 2026, Federal Register, vol. 91, no. 108, 5 June 2026, p. 34565.
- Great American Artificial Intelligence Act of 2026, discussion draft released on 4 June 2026 by Representatives Jay Obernolte (R-California) and Lori Trahan (D-Massachusetts), 269 pages. Not introduced as at the date of publication.
- California, Transparency in Frontier Artificial Intelligence Act (SB 53), signed 29 September 2025, applicable since 1 January 2026.
- New York State, Responsible AI Safety and Education Act (RAISE Act); Illinois, SB 315.
- Congressional Research Service, Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained, IF13268, 9 July 2026.
Legal and policy analyses
- Cato Institute, “A Primer on the Great American Artificial Intelligence Act”, 2026.
- DLA Piper, “Unpacking the Great American AI Act”, June 2026.
- Future of Privacy Forum, “Frontier AI Goes Federal: How the Great American AI Act Compares to State Laws”, 2026.
- Norton Rose Fulbright, “Executive Order Establishes Voluntary Early Access Framework to Frontier AI Models”, 2026.
- Tech Policy Press, “Unpacking the Great American Artificial Intelligence Act of 2026”, June 2026.
- WilmerHale, “Transparency in Frontier Artificial Intelligence Act (SB 53): California Requires New Standardized AI Safety Disclosures”, 1 October 2025.
- Public Citizen, “Obernolte-Trahan Bill Strips States Authority to Protect Consumers, Workers, and Children”, 2026.
Academic literature
- EDELMAN L. B., Working Law. Courts, Corporations, and Symbolic Civil Rights, Chicago, University of Chicago Press, 2016.
- FUNG A., GRAHAM M. and WEIL D., Full Disclosure. The Perils and Promise of Transparency, Cambridge, Cambridge University Press, 2007.
- HILDEBRANDT M., Law for Computer Scientists and Other Folk, Oxford, Oxford University Press, 2020.
Notes
- Executive Order 14409 set a sixty-day deadline, expiring on 1 August 2026, for three deliverables: a classified benchmarking process involving the NSA, CISA and NIST, a voluntary disclosure framework, and a plan to strengthen the federal cybersecurity workforce. Several specialist press reports note that none was made public by that date. Absent official communication, this observation rests on those reports and not on a primary source.
- Regulation (EU) 2024/1689, Articles 91 to 93 and 101. Obligations on providers of general-purpose AI models have applied since 2 August 2025; the Commission’s powers to sanction them open on 2 August 2026.
- Meeting announced on 3 August 2026 and held the following day, with executives from Meta, OpenAI, Google and Anthropic. Neither the methodology nor the metrics of the framework had been published at the time of writing.
- Great American Artificial Intelligence Act of 2026, discussion draft of 4 June 2026. Besides its two authors, the text is supported by Representatives Scott Franklin (R-Florida), Suhas Subramanyam (D-Virginia), Erin Houchin (R-Indiana) and Scott Peters (D-California). No bill number has been assigned to date.
- Federal Register, vol. 91, no. 108, 5 June 2026, p. 34565.
- Executive Order 14409, provisions on the classified assessment process and early access; clause expressly excluding the creation of any licensing, preclearance or permitting regime.
- See note 3; the order provided that certain evaluation benchmarks would remain classified.
- Regulation (EU) 2024/1689, Art. 101: fines not exceeding 3% of total annual worldwide turnover in the preceding financial year or EUR 15,000,000, whichever is higher. To be compared with Art. 99(3), applicable to the prohibited practices of Art. 5, whose ceiling is EUR 35,000,000 or 7%.
- Regulation (EU) 2026/1744 of 8 July 2026. Besides the deferrals to 2 December 2027 and 2 August 2028, the text brings forward from 2 February 2027 to 2 December 2026 the deadline relating to the marking of AI-generated content.
- Regulation (EU) 2024/1689, Art. 51(2): presumption of high-impact capabilities above 10²⁵ cumulative floating-point operations for training; Art. 51(1)(b) and Annex XIII for classification by Commission decision.
- Ibid., Art. 53 (general obligations) and Art. 55 (additional obligations for systemic-risk models).
- Great American Artificial Intelligence Act of 2026, op. cit. The thresholds reported here — 10²⁶ operations for the model, USD 50 million in revenue for a frontier developer and USD 500 million for a large frontier developer — are drawn from the analyses listed in the bibliography, the text having no consolidated official version. They will need to be verified against the version as introduced.
- Ibid.; on the obligations, notification deadlines and the role of Independent Verification Organizations, see the analyses by the Future of Privacy Forum, DLA Piper and the Cato Institute.
- This enumeration is the one adopted by the cited analyses to illustrate the reach of the threshold; it has no legal force, and actual application will depend on recorded revenues.
- Several specialist press reports have noted the participation of the leading companies in developing the threshold that will determine which models are subject to review. The author has not had access to the corresponding working documents; the information is reported as such.
- EDELMAN L. B., Working Law, Chicago, University of Chicago Press, 2016. The transposition of this analytical framework to the European AI regulation was proposed in an earlier contribution published on this site.
- Great American Artificial Intelligence Act of 2026, op. cit., preemption clause: prohibition on states specifically regulating the development of a model, for three years, with a sunset in December 2029; carve-outs for laws of general applicability, common-law remedies and post-deployment stages.
- On the comparative thresholds and obligations of California, New York State and Illinois, see Future of Privacy Forum, art. cited, and WilmerHale, art. cited.
- Organisations supporting the text include the Business Software Alliance and the Information Technology Industry Council; those opposing it include Public Citizen, Public Knowledge and the AFL-CIO. The co-chairs of the House commission on artificial intelligence, for their part, considered that the discussion draft could not serve as the basis for productive dialogue.