Drafting laws while the ground moved (2020–2023)
Lesson 3 of 5 in From Asimov to the AI Act: A History of AI Governance.
By 2020, the principles were written; governments started converting them into draft law. The European Commission proposed the AI Act in April 2021 — a product-safety-style, risk-based regulation that would dominate the global conversation for the next five years. UNESCO’s Recommendation was adopted by 193 states (November 2021). China moved first to binding rules with its Algorithm Recommendation Provisions (in force March 2022) and Deep Synthesis Provisions (January 2023) — narrow, enforceable, and fast. New York City passed Local Law 144 (2021, enforced July 2023), the first mandate for independent bias audits of hiring tools. The White House published the Blueprint for an AI Bill of Rights (October 2022) — principles again, but with unusually concrete technical companion notes — while NIST built its Risk Management Framework in public workshops.
Then the ground moved. ChatGPT launched on 30 November 2022 and reached an estimated hundred million users within two months — the fastest consumer-technology adoption ever recorded at the time. Every legislative draft in progress had been written for predictive AI: scoring, ranking, classifying. Suddenly the fastest-growing AI systems generated — and could be repurposed for nearly anything. The EU’s nearly finished text had no meaningful answer to general-purpose models; the final trilogue negotiations of 2023 bolted on the entire GPAI chapter, compute thresholds and all. Remember this when you read the AI Act’s slightly awkward two-track structure: it is geology — you are looking at the ChatGPT shock preserved in statutory rock.
2023 became the most crowded single year in this history:
- January — NIST releases AI RMF 1.0, the voluntary framework that now anchors US practice.
- March–May — the “pause letter” (calling for a six-month halt on training beyond GPT-4) and a one-sentence statement that AI extinction risk belongs beside pandemics and nuclear war put existential risk into mainstream politics; OpenAI’s CEO testifies to the US Senate asking for regulation.
- July — the White House extracts voluntary commitments from seven leading labs (red-teaming, watermarking research, security).
- August — China’s Interim Measures for Generative AI take effect: the first binding national rules aimed squarely at generative services.
- October — the G7 adopts the Hiroshima Code of Conduct for advanced-AI developers; President Biden signs Executive Order 14110, the longest EO in US history, invoking the Defense Production Act to require safety-test reporting for models above 10²⁶ FLOPs.
- November — the UK convenes the first AI Safety Summit at Bletchley Park: 28 countries and the EU and China sign the Bletchley Declaration acknowledging frontier-AI risk, and the first AI safety institutes (UK, US) are announced.
- December — EU trilogue agreement on the AI Act; ISO/IEC 42001, the AI management-system standard, is published.
In thirteen months, AI governance went from a specialist Brussels negotiation to head-of-state business on three continents.
The generative shock, month by month
- 2019-02-11 — EO 13859 — American AI Initiative:
The first US executive order on AI: R&D investment and NIST tasked with technical standards — the seed of the AI RMF.
- 2021-04-21 — European Commission proposes the AI Act:
The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.
- 2022-11-30 — ChatGPT launches:
100 million users in two months. Generative AI becomes a household reality and every AI bill on Earth gets rewritten to cope.
- 2022-03-15 — NIST SP 1270 on AI bias:
Names three bias families — systemic, computational, and human-cognitive — reframing bias as a socio-technical problem, not just a dataset defect.
- 2023-01-26 — NIST AI RMF 1.0 released:
Govern, Map, Measure, Manage — the voluntary framework that becomes the de facto grammar of US AI risk management and a safe-harbor hook in state laws.
- 2024-07-26 — NIST Generative AI Profile (AI 600-1):
Twelve generative-AI risk categories with hundreds of suggested actions — the RMF operationalized for the ChatGPT era.
- 2025-02-01 — Frontier safety frameworks become table stakes:
Following the Seoul commitments, major labs publish or update frontier safety policies (capability thresholds, evaluation gates, deployment mitigations) ahead of the Paris summit.
- 2023-05-22 — Commission issues the AI Act standardisation request:
CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.
- 2023-07-21 — White House voluntary AI commitments:
Seven frontier labs commit to red-teaming, watermarking research, and security — the voluntary-first US pattern in one document.
- 2023-08-15 — China’s Interim GenAI Measures take effect:
The first binding national generative-AI regulation: content controls, labeling, security assessments for public-facing services.
- 2023-10-30 — EO 14110 on Safe, Secure, and Trustworthy AI:
The most sweeping US federal AI action to date: compute-threshold reporting, agency mandates, NIST tasked with GenAI guidance. Revoked fifteen months later.
- 2023-11-01 — Bletchley Park AI Safety Summit:
28 countries + the EU — including the US and China — sign the Bletchley Declaration on frontier-AI risk. The summit series begins.
- 2023-12-08 — AI Act trilogue deal:
After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.
- 2024-05-21 — Seoul AI Summit:
Frontier labs sign safety commitments — publish risk frameworks or explain why not. The summit series turns from declarations to developer promises.
- 2024-08-01 — EU AI Act enters into force:
Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.
- 2025-02-02 — AI Act prohibitions + AI literacy apply:
The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.
- 2025-02-10 — Paris AI Action Summit:
The series pivots from safety to action and investment; the US and UK decline to sign the final declaration — the divergence made visible.
- 2025-07-10 — EU GPAI Code of Practice published:
Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.
- 2025-08-02 — AI Act GPAI rules, governance, and penalties apply:
Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.
- 2025-11-19 — Digital Omnibus proposes AI Act simplification:
The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.
- 2026-02-19 — AI Impact Summit, New Delhi:
The summit series lands in the Global South, centering development and inclusion; Geneva planned as the next stop (2027).
- 2026-07-06 — First UN Global Dialogue on AI Governance:
The Global Digital Compact’s forum convenes in Geneva — every state at one AI governance table for the first time.
- 2026-08-02 — AI Act general application:
The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.
- 2026-12-02 — Synthetic-content marking compliance deadline:
Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).
- 2027-12-02 — High-risk rules apply — Annex III systems:
The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.
- 2027-08-02 — Legacy GPAI models must comply:
Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.
- 2028-08-02 — High-risk rules apply — Annex I products:
AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.
Key terms: general-purpose AI, pacing problem, voluntary commitments, risk-based regulation
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.