Binding law arrives — then the world diverges (2024–2025)
Lesson 4 of 5 in From Asimov to the AI Act: A History of AI Governance.
2024 is the year the word “shall” finally outweighed the word “should”. The EU AI Act entered into force on 1 August 2024 — the first comprehensive, horizontal AI statute anywhere. A month later (5 September 2024) the Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law opened for signature: the first binding international AI treaty, and notably open to non-European states — the US, UK, and Israel signed early. The UN General Assembly had already passed its first AI resolution by consensus (March 2024), followed by the Global Digital Compact (September 2024). The summit train rolled on: Seoul (May 2024) produced the Frontier AI Safety Commitments — sixteen companies pledging published safety frameworks — and launched the international network of AI safety institutes. Domestically, Colorado signed the first comprehensive US state AI act (May 2024), Korea passed its AI Basic Act (December 2024), and the OECD updated its principles and absorbed GPAI — the Global Partnership on AI — into its structure.
Feel the pattern of the year: every layer of the stack moved at once — treaty, statute, state law, summit pledge, standard. That simultaneity, not any single instrument, is what “the binding-law era” means.
Then 2025 broke the convergence story. In Washington, the new administration revoked EO 14110 in January 2025 (EO 14148), issued EO 14179 — “Removing Barriers to American Leadership in AI”, and published America’s AI Action Plan (July 2025): the frame shifted from safety-first to innovation-and-dominance-first, and the US AI Safety Institute became the Center for AI Standards and Innovation (CAISI). Congress fought over whether to preempt state AI laws — a proposed ten-year moratorium on state AI regulation was stripped from the 2025 tax bill by a 99–1 Senate vote, but the pressure continued via EO 14365 (December 2025) pushing a national AI policy framework. Meanwhile California signed SB 53, the first US frontier-model transparency statute, and New York followed with the RAISE Act (signed December 2025).
Across the Atlantic, the EU stayed the course but felt the wind: the AI Act’s prohibitions and AI-literacy duties applied 2 February 2025, and the GPAI obligations on 2 August 2025, supported by a General-Purpose AI Code of Practice (published July 2025). The Paris AI Action Summit (February 2025) renamed the summit series itself — from AI Safety to AI Action — and the US and UK declined to sign its declaration; the International AI Safety Report (January 2025, led by Yoshua Bengio) gave the field its first IPCC-style evidence synthesis. China issued AI content-labeling measures in 2025, and the UN established its Independent International Scientific Panel on AI and Global Dialogue on AI Governance (August 2025). One planet, two directions: Brussels operationalising, Washington deregulating — and everyone else triangulating.
The binding-law era and the 2025 divergence
- 2019-02-11 — EO 13859 — American AI Initiative:
The first US executive order on AI: R&D investment and NIST tasked with technical standards — the seed of the AI RMF.
- 2019-05-14 — San Francisco bans government facial recognition:
The first big-city ban — the beginning of the US municipal wave against biometric surveillance.
- 2021-04-21 — European Commission proposes the AI Act:
The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.
- 2021-12-11 — NYC enacts Local Law 144:
The first mandated bias audits for automated employment decision tools — enforcement begins July 2023. Impact ratios become a legal requirement, not a research metric.
- 2022-10-04 — White House Blueprint for an AI Bill of Rights:
Five principles for automated systems — non-binding, but the clearest US federal statement of the rights-based framing.
- 2022-10-07 — US advanced-chip export controls on China:
Sweeping controls on advanced semiconductors and manufacturing equipment — compute becomes an explicit instrument of AI policy.
- 2023-01-26 — NIST AI RMF 1.0 released:
Govern, Map, Measure, Manage — the voluntary framework that becomes the de facto grammar of US AI risk management and a safe-harbor hook in state laws.
- 2023-10-17 — US tightens chip export controls:
The 2022 rules are extended to close performance-density loopholes and cover more countries — the compute-control net widens.
- 2025-01-13 — AI Diffusion Rule issued — then rescinded:
A three-tier global framework for AI chip and model-weight exports, issued in the administration’s final week and rescinded by its successor in May 2025 — export policy whiplash.
- 2025-02-01 — Frontier safety frameworks become table stakes:
Following the Seoul commitments, major labs publish or update frontier safety policies (capability thresholds, evaluation gates, deployment mitigations) ahead of the Paris summit.
- 2023-07-21 — White House voluntary AI commitments:
Seven frontier labs commit to red-teaming, watermarking research, and security — the voluntary-first US pattern in one document.
- 2023-10-30 — EO 14110 on Safe, Secure, and Trustworthy AI:
The most sweeping US federal AI action to date: compute-threshold reporting, agency mandates, NIST tasked with GenAI guidance. Revoked fifteen months later.
- 2023-11-01 — Bletchley Park AI Safety Summit:
28 countries + the EU — including the US and China — sign the Bletchley Declaration on frontier-AI risk. The summit series begins.
- 2023-12-08 — AI Act trilogue deal:
After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.
- 2024-03-21 — First UN General Assembly resolution on AI:
Adopted by consensus, US-led, China co-sponsoring — “safe, secure and trustworthy” AI enters UN language.
- 2024-05-17 — Council of Europe Framework Convention on AI adopted:
The first binding international AI treaty — human rights, democracy, rule of law — opened for signature 5 Sep 2024. Entry into force pending ratifications; check current status.
- 2024-05-17 — Colorado AI Act signed (SB 24-205):
The first comprehensive US state AI law: algorithmic-discrimination duties for developers and deployers of high-risk systems. Later delayed, then repealed and replaced in 2026.
- 2024-05-21 — Seoul AI Summit:
Frontier labs sign safety commitments — publish risk frameworks or explain why not. The summit series turns from declarations to developer promises.
- 2024-08-01 — EU AI Act enters into force:
Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.
- 2024-08-09 — Illinois amends its Human Rights Act for AI (HB 3773):
AI-driven employment discrimination becomes a civil-rights violation, effective 2026 — states legislating through existing rights law.
- 2024-09-22 — UN Global Digital Compact adopted:
Commits the UN to an Independent International Scientific Panel on AI and a Global Dialogue on AI governance — the closest thing to a universal AI forum.
- 2025-01-20 — EO 14110 revoked (EO 14148):
The incoming administration revokes the 2023 AI order on day one — the sharpest one-day regime flip in AI policy history.
- 2025-01-23 — EO 14179 — Removing Barriers to American Leadership in AI:
The new posture: dominance through deregulation. Agencies ordered to review and unwind “burdensome” AI requirements.
- 2025-02-02 — AI Act prohibitions + AI literacy apply:
The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.
- 2025-02-10 — Paris AI Action Summit:
The series pivots from safety to action and investment; the US and UK decline to sign the final declaration — the divergence made visible.
- 2025-07-10 — EU GPAI Code of Practice published:
Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.
- 2025-07-01 — Senate strips the state-AI-law moratorium, 99–1:
A proposed 10-year federal preemption of state AI laws dies in the Senate — states keep the pen, and keep writing.
- 2025-07-23 — America’s AI Action Plan:
90+ federal actions: exports, permitting, “ideological neutrality” in procurement — the deregulatory posture becomes a program.
- 2025-08-02 — AI Act GPAI rules, governance, and penalties apply:
Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.
- 2025-08-26 — UN establishes the Scientific Panel and Global Dialogue on AI:
Resolution A/RES/79/325 creates the IPCC-style panel and the universal governance forum promised by the Global Digital Compact.
- 2025-11-19 — Digital Omnibus proposes AI Act simplification:
The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.
- 2025-12-01 — New York signs the RAISE Act:
Frontier-model safety duties — protocols, incident reporting — arrive at state level, effective early 2027.
- 2025-12-01 — EO 14365 pushes a national AI framework:
The administration moves toward federal preemption of the state patchwork — litigation and legislation follow. Check current status.
- 2026-01-01 — Texas TRAIGA takes effect:
Prohibited-uses framing (behavioural manipulation, social scoring, certain biometric uses) with a regulatory sandbox — the red-state model of AI law.
- 2026-01-01 — California SB 53 takes effect:
Frontier AI transparency: published safety frameworks and critical-incident reporting for large developers — the first binding US frontier-model law.
- 2026-02-19 — AI Impact Summit, New Delhi:
The summit series lands in the Global South, centering development and inclusion; Geneva planned as the next stop (2027).
- 2026-05-01 — Colorado repeals and replaces its AI Act (SB 26-189):
After two delays, the pioneering duty-based law gives way to a disclosure-based regime — a live lesson in how hard first-mover state regulation is.
- 2026-06-01 — EO 14409 on frontier-model cybersecurity:
Federal attention narrows to security of frontier models — weights, infrastructure, adversarial threats. Check current status for implementing rules.
- 2026-07-06 — First UN Global Dialogue on AI Governance:
The Global Digital Compact’s forum convenes in Geneva — every state at one AI governance table for the first time.
- 2026-08-02 — AI Act general application:
The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.
- 2026-12-02 — Synthetic-content marking compliance deadline:
Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).
- 2027-12-02 — High-risk rules apply — Annex III systems:
The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.
- 2027-08-02 — Legacy GPAI models must comply:
Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.
- 2028-08-02 — High-risk rules apply — Annex I products:
AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.
EU: operationalise
The AI Act’s clock started ticking in phases: prohibitions + AI literacy, 2 Feb 2025; GPAI, governance bodies, penalties, 2 Aug 2025. The bet: first-mover rules become the global default (the Brussels effect, as with the GDPR). The risk: compliance cost pushes development elsewhere while the rules chase a moving frontier.
US: deregulate federally, legislate state by state
EO 14110 revoked (Jan 2025); EO 14179 and the AI Action Plan (Jul 2025) reframed policy around winning the AI race; CAISI replaced the safety institute branding. But federal deregulation met state legislation: Colorado, then Texas’s TRAIGA, California’s SB 53, New York’s RAISE Act — and the preemption war (moratorium stripped 99–1; EO 14365, Dec 2025) became the defining US governance fight.
The middle powers: choose and blend
Korea passed the first comprehensive AI law in Asia (AI Basic Act, Dec 2024). China kept layering targeted rules (labeling measures, 2025). UK stayed statute-free, betting on existing regulators and its security institute. The UN built evidence machinery (Scientific Panel, Global Dialogue) rather than rules — the realistic ambition for a body of 193 members.
Key terms: Brussels effect, preemption, framework convention, code of practice, frontier model
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.