Fragen Sie Ihre Compliance-Daten alles. Sienna Insights, demnächst verfügbar.
Treten Sie der Warteliste bei

Beyond rules and tools: AI governance's three-body problem

A look at how the EU's AI Act delays, America's federal-state clash over AI regulation, and China's new WAICO coalition are reshaping the global AI governance landscape in 2026.

Robert Greco
August 17, 2026
5 min. Lesezeit

Ten months ago, this space described a two-way race: Europe's rules-first model against America's tools-first model, each betting that its own logic would set the global standard. That framing still explains a lot… but as always, I am struck by how it's never quite "that simple".

In the time since, i) regulators and lawmakers on both sides of the Atlantic divide have backed away from the positions I argued defined them, and ii) a third player has emerged, complicating what once appeared to be a two-sided contest.

A brief update on the landscape today:

1. Europe's quiet retreat

The EU has built its reputation on legal certainty: one binding law, one enforcement body, one timeline. However, the timeline in the context of AI governance is now shifting.

The Digital AI Omnibus (the "Omnibus"), agreed upon in May 2026, pushes back the high-risk obligations that were supposed to anchor the AI Act's credibility. Standalone high-risk systems now have until December 2027 to comply, a year later than originally planned. Beyond this, AI embedded in regulated products will experience an even greater lag before compliance is mandated, pushing the original timeline for compliance back to August 2028.

The Omnibus also softened several duties along the way: AI literacy shifted from a guarantee to a "support" obligation, and machinery-embedded AI picked up broad exemptions.

But why?

Brussels didn't delay because the technology proved safer than expected. It delayed because European AI investment has fallen visibly behind that in the US, and industry pressure has made the original timeline politically unsustainable.

Having built its identity on precaution, the arbiter of the "rules-first approach" has signaled that precaution has an economic and innovation cost it isn't fully prepared to bear.

However, under no circumstances can this be seen as a degradation of European lawmaking into a "wild west" of profit or bust. The broader framework governing general-purpose AI, including the General-Purpose AI Code of Practice and the transparency obligations for foundation models, has remained largely on schedule, but we find ourselves with a bit of a dual-track system: i) Track A for foundation models, which is moving ahead as planned, and ii) Track B for high-risk systems, which is moving slower than promised.

2. America's fight with itself

The US side of the story also shifted, but not in the direction most people expected. Somewhat strangely, the development here isn't further deregulation, but rather a fight over who gets to regulate at all.

Congress stripped a proposed moratorium on state AI laws from the 2026 defense authorization bill, the second time that approach has failed there. In its place, reporting points to a "ONE RULE" executive order aimed at preempting state AI law directly: a litigation task force to challenge state statutes, and federal funding conditioned on states not enforcing their own rules. Support for this isn't breaking along the lines you'd expect. Senator Ted Cruz backs it, while Florida Governor Ron DeSantis has called it a subsidy to big tech.

As posited in my original piece: the above fragmentation isn't background noise, it's the very landscape that lobbyists and lawmakers alike will have to battle through to get something (anything?) done.

Viewed through this lens, the US doesn't have a settled innovation-first philosophy so much as an unresolved argument about whether Washington or the states get to write the rules, with the White House trying to settle it by executive order rather than legislation (what could go wrong?).

Where does this leave us?

The EU, with regulatory models traditionally built on certainty, is focused on buying itself time, while the US, with regulatory models traditionally built on flexibility, is trying to impose a single federal answer by force.

3. Enter body three: China's bid for the rest of the world

In mid-2026, China launched the World AI Cooperation Organization ("WAICO"), a permanent intergovernmental body headquartered in Shanghai, with 29 founding member nations and a mandate covering capacity-building, technical interoperability, and open-source ecosystems. China doesn't pitch it as a rival to the AI Act or to US export controls. It pitches WAICO as an alternative to both: wide access, infrastructure support, and formal participation, aimed squarely at countries the EU and US aren't actively courting.

Arguably, Brussels and Washington have been focused on competing for legitimacy with each other and with large enterprises operating in both markets, while Beijing appears to be competing for adoption in the parts of the world that can't afford to run three separate compliance regimes and will default to whichever framework arrives with the infrastructure attached.

Are we seeing the emergence of a tri-polar AI governance framework, complete with overlapping ecosystems in which countries and companies are forced to mix compliance regimes depending on which market they're selling into and which infrastructure they're building on?

Conclusion: is there one logic to rule them all?

Ten months ago, the closing question was whether the EU's rules-before-tools approach and America's tools-before-rules approach could ever converge to create a super-framework which would serve both individuals and corporations in a way that brings prosperity and protection to all.

The straying of each model from its respective suggested "framework" indicates early signs of a convergence in approach, but not to the extent that a unified philosophy will be adopted in the near term.

What was once evolving as a relatively straightforward conflict of "values" and "ethics" may now be shifting into a fight over a simpler issue: infrastructure and access thereto.

Instead, a third model has entered the field, ostensibly competing on reach rather than stringency, and introducing a complexity to the governance landscape few had anticipated.

However, we know that signature ceremonies and photo opportunities are inexpensive marketing tools. At this juncture, it's challenging to forecast whether WAICO can develop into something formidable on the global scene, or if it is simply a vehicle for China to build further soft power in Asia, Africa, and Latin America. Converting these first steps into cross-jurisdictional projects with secured funding in the near to medium term will require significant investment and the collective will of disparate nations.

Count me among those excited to learn whether this new model can be woven together with one of the now shifting EU or US philosophies (or both), to produce a balanced governance philosophy aimed at promoting human centricity without overtly sacrificing shareholder value.

While the primary question remains of which philosophy is best suited to deliver AI in the most trustworthy, competitive, and human-centric manner, a corollary question has arisen for consideration: which of the above approaches will win adoption when a limited number of entities have the resources to comply with all three?

Sources

Inhaltsverzeichniss

Teilen
Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share