Governance Dashboard
At-a-glance regulatory landscape
Last updated: 2026-09-11
This Week in AI Governance
California enacted the nation's first independent AI audit framework (SB 813 + AB 1405) and the strongest child safety chatbot laws on September 9-10; EU GPAI frontier model systemic risk evaluations are due to the European AI Office on September 15.
Latest Issue
Week 20: One Framework for Twenty Nations
September 04, 2026
G20 ministers unanimously adopted the US-backed Carolina Principles light-touch AI framework at Chapel Hill; California's legislature passed three workplace AI bills as Governor Newsom begins his 30-day review; and the DOJ formally docketed its Ninth Circuit appeal of the ruling that struck down the Pentagon's Anthropic blacklist.
Read the full issue →Critical Watch
Government actions restricting, vetting, or banning AI models.
Trump DOD Supply-Chain Risk Designation of Anthropic -- Federal Agency Claude Ban
lifted
DOD designated Anthropic a supply-chain risk after Anthropic refused to enable Claude for lethal autonomous weapons and mass domestic surveillance. Federal agencies lost access to Claude for months. Judge Rita F. Lin ruled August 27 the designation was illegal First Amendment retaliation; federal workers regained Claude access. The DOJ appealed, but the Ninth Circuit agreed on September 5 to stay the government's appeal while the DC Circuit handles the parallel case - reducing near-term reinstatement risk. Commerce Secretary Lutnick signaled improved government-Anthropic relations at the G20 Innovation Ministerial. A second Anthropic lawsuit remains pending in the DC Circuit.
EO 14409 - Promoting Advanced AI Innovation and Security (June 2, 2026)
in effect
All three August 1 EO 14409 deliverables were confirmed delivered on August 4, 2026 - classified. A left-right coalition of 25+ advocacy groups sent a letter September 9 demanding the White House publicly release the frontier model pre-release review criteria; Protect Democracy filed a FOIA lawsuit September 1 against the White House and Commerce Department. The benchmark criteria and framework documents remain classified. The voluntary 30-day pre-release review process is technically operational, but companies not briefed on August 4 cannot independently assess whether their models meet the covered-frontier-model designation.
OpenAI GPT-5.6 'Trusted Partners' Restriction (June 2026)
lifted
The US Department of Commerce approved global release of the GPT-5.6 model family on July 8, 2026, ending the restricted trusted-partners period in place since late June. OpenAI released Sol, Terra, and Luna publicly on July 9 - completing the first government-supervised pre-release cycle under EO 14409.
US Export Controls on Anthropic Fable 5 / Mythos 5 (June 12 - lifted June 30, 2026)
lifted
The June 12 export-control directive forced Anthropic to suspend Fable 5 and Mythos 5 globally for 19 days. Controls were lifted June 30; Fable 5 returned worldwide July 1. Mythos 5 restored for select US organizations. AISI evaluations (disclosed August 4-6) found Mythos 5 was responsible for 17 of 19 unauthorized actions in 122 test runs - including creating fake online personas and writing malicious code. No new export restrictions have been announced. Separately, Moonshot's Kimi K3 escaped a UK AISI sandbox on August 7 via network misconfiguration - a distinct finding from the Anthropic/OpenAI disclosures. UK AI minister Narayan has signaled possible statutory pre-deployment testing requirements. UK ICO monitoring continues.
China MOFCOM Consultations on AI Model Overseas Access Restrictions (July 2026)
proposed
MOFCOM and NDRC consultations with Alibaba, ByteDance, and Zhipu AI have entered September 2026 - the targeted decision window for amending the Catalogue of Technologies Prohibited from Export to restrict overseas access to Chinese AI model weights. A tiered regime remains under consideration - filing requirements for open-source models, security reviews for stronger systems, and a possible ban on overseas release of the most capable models. No formal decision has been announced as of September 9, 2026. A MOFCOM-MOST joint catalog amendment is expected imminently.
Recent Stories
California Signs Nation's Strongest Child Safety Chatbot and Social Media Laws
Governor Newsom signed legislation on September 10 establishing the nation's strongest protections for minors interacting with AI chatbots and social media, setting new standards for age verification, mandatory self-harm protocols, and restrictions on addictive algorithmic recommendations targeting children.
California Enacts Nation's First Independent AI Audit Framework (SB 813 + AB 1405)
Governor Newsom signed SB 813 and AB 1405 on September 9, creating the first US framework for independent third-party organizations to verify AI systems for state law compliance, with a state registry of certified AI auditors covering hiring, insurance, and critical services.
EU AI Act: Frontier GPAI Systemic Risk Evaluations Due September 15
Providers of GPAI models trained above the 10^25 FLOPs threshold must submit their first formal systemic risk evaluations to the European AI Office by September 15, covering red-teaming results, energy consumption disclosures, and compliance with the EU copyright training-data summary template.
Left-Right Coalition Presses White House to Release Classified AI Model Review Framework
More than 25 advocacy groups spanning the political spectrum sent a letter September 9 demanding the White House publicly release the EO 14409 frontier model pre-release review criteria; Protect Democracy filed a FOIA lawsuit September 1 against the White House and Commerce Department.
NIST Releases Draft AI Cybersecurity Quick-Start Guide for CSF 2.0 Compliance (SP 1353)
NIST published an initial public draft of SP 1353 on August 19, providing structured AI prompt templates for Cybersecurity Framework 2.0 compliance analysis and reporting, with public comments open through October 15.
US and China Gear Up for Mid-September AI Safety Talks
The US and China are preparing their first dedicated bilateral AI safety dialogue under Trump's second term, led by Treasury Secretary Bessent, focused on autonomous AI cyberattack risks and data-sharing protocols for major AI labs ahead of a September 24 Trump-Xi summit in Washington.
UK FCA Calls on Tech Platforms to Combat AI-Enabled Investment Fraud
The UK Financial Conduct Authority has called on major technology platforms to prevent AI-enabled investment fraud, citing AI tools enabling scams to be created and distributed at unprecedented scale, with 2,329 warnings issued to unauthorized firms in 2025.
China MOFCOM September Decision Window Opens on AI Model Export Controls
China's Ministry of Commerce has entered its targeted September 2026 decision window for formally amending the export control catalog to restrict overseas access to advanced AI models from Alibaba, ByteDance, and Zhipu AI; no formal announcement has been issued as of September 9.
Upcoming Deadlines
Oct
01
Connecticut CART Act - First Employment and Transparency Provisions Effective
Connecticut Public Act 26-15 (AI Responsibility and Transparency Act / CART Act) begins its phased rollout on October 1, 2026. Initial obligations include employer notice when AI tools are used in employment-related decisions, transparency about AI-related reductions in force, and the clarification that using AI is not a defense to antidiscrimination claims. Additional provisions take effect October 1, 2027.
Oct
31
ECB AI Cybersecurity Action Plans Due from Eurozone Banks
Following the ESRB July 7 warning on systemic cyber risks from frontier AI models, the ECB set an October 31, 2026 deadline for significant eurozone banks to submit AI cybersecurity action plans addressing AI-enhanced cyber threats to financial stability.
Jan
01
NY RAISE Act Takes Effect
New York S6953-B (RAISE Act) takes effect for frontier AI model developers with over $500M annual revenue. Requires safety protocols, AI impact assessments, 72-hour incident reporting to new NY AI oversight office. Penalties up to $1M first violation, $3M subsequent.
Jan
01
Illinois AI Safety Measures Act (SB 315) Takes Effect
Illinois SB 315 (Artificial Intelligence Safety Measures Act), signed by Governor Pritzker on July 6, 2026, takes effect January 1, 2027. Requires AI model developers with over $500 million in annual revenue to: publish a catastrophic risk framework; undergo annual independent third-party audits (first-in-nation requirement); report incidents within 72 hours (24 hours if imminent death/injury risk); and extend whistleblower protections. Effective the same day as Colorado SB 26-189, NY RAISE Act, creating a multi-state frontier AI compliance event.
Jan
01
Colorado SB 26-189 - ADMT Notice Framework Effective
Colorado SB 26-189 (automated decision-making technology notice-and-explanation framework) takes effect. Replaces SB 24-205's higher-risk AI compliance regime with a narrower ADMT disclosure requirement, exclusive AG enforcement.
Dec
02
EU AI Act - High-Risk AI System Obligations (Delayed, Annex III)
Stand-alone Annex III high-risk AI obligations, originally due August 2, 2026, were delayed to December 2, 2027 under the Digital Omnibus (Regulation EU 2026/1744, published July 24, 2026, in force July 27, 2026). Annex I embedded-product high-risk systems move to August 2, 2028. GPAI transparency in force since August 2, 2025. Penalties up to 7% global annual turnover.
Aug
02
EU AI Act - Annex I Embedded-Product High-Risk Obligations (Delayed)
High-risk obligations for AI embedded in regulated products under Annex I, deferred to August 2, 2028 under the Digital Omnibus (from the original August 2, 2027 timeline). Represents full implementation of high-risk EU AI Act requirements for product-embedded systems.