← All posts

The Regulatory Net Is Closing: What's Mandatory, What's Voluntary, and What's Coming for Frontier AI

On July 14, the White House launched Gold Eagle — a government-run clearinghouse that coordinates AI-powered vulnerability scanning across critical infrastructure. A week before that, the European Commission published its Cybersecurity and AI Action Plan, announcing that the EU will build its own capacity to evaluate frontier AI models before they hit the market. Six weeks before that, Congress released the first comprehensive federal AI governance bill — the 269-page Great American Artificial Intelligence Act.

If you are a board member or executive, you may be hearing from your compliance team that frontier AI regulation is still "voluntary" or "early stage." That was true in May. It is not true anymore.

The United States: From Voluntary Framework to Operational Reality

On June 2, President Trump signed an executive order establishing a voluntary framework for early government access to frontier AI models. I wrote at the time that "voluntary" in Washington has a short shelf life. Six weeks later, that prediction is playing out faster than I expected.

Gold Eagle is not a policy proposal. It is an operational program, already processing vulnerability reports through Carnegie Mellon's VINCE platform, coordinating scanning assignments across private-sector partners, and triaging the flood of AI-discovered vulnerabilities for remediation. The Cybersecurity Information Sharing Act — whose liability protections underpin Gold Eagle's information-sharing model — is set to expire in September unless Congress reauthorizes it. The administration has asked for a ten-year extension, signaling that this infrastructure is meant to be permanent.

Meanwhile, the GAAIA discussion draft — released June 4 by Reps. Obernolte (R-CA) and Trahan (D-MA) — would convert much of the EO's voluntary architecture into binding law. Large frontier developers (companies with over $500 million in annual revenue that have trained a frontier model) would be required to publish risk-mitigation frameworks, submit to semi-annual audits by federally licensed Independent Verification Organizations, and report critical safety incidents to the new Center for AI Standards and Innovation within 15 days — or within 24 hours if the incident poses imminent risk of death or serious injury. The bill includes whistleblower protections with double back pay and compensatory damages.

Is the GAAIA likely to pass as drafted? No. Is it a reliable signal of where federal regulation is heading? Absolutely. The discussion draft has bipartisan support from six co-sponsors across both parties. Even the provisions that get watered down will establish a floor.

The EU: Already Mandatory, Getting Stricter

While U.S. executives debate whether frontier AI regulation is voluntary, their European counterparts are already operating under binding obligations.

The EU AI Act's rules for general-purpose AI models became legally applicable on August 2, 2025. Enforcement powers — fines of up to 3% of global annual turnover or €15 million (whichever is higher), model recalls, mandatory information requests — activate on August 2, 2026. That is twelve days from now. Frontier models (initially defined as those trained with computational resources exceeding 10^25 FLOPs) face additional requirements: detailed technical documentation, risk evaluations, adversarial testing, and serious incident reporting.

NIS2, the EU's updated cybersecurity directive, hit its first compliance audit deadline on June 30, 2026. Essential entities face fines up to €10 million or 2% of global turnover. NIS2 explicitly covers AI systems as information systems — meaning organizations must include AI agents in their risk assessments and map data sources, models, and interfaces with other systems.

And on July 7, the European Commission went further. Its new Cybersecurity and AI Action Plan establishes a dedicated EU evaluation capacity for frontier AI models, targeted to be operational by 2027. By Q4 2026, the Commission and ENISA will publish a "European Blueprint" for structured access to advanced AI models for cybersecurity purposes. A secure testing platform, built by ENISA and the Joint Research Centre, is due by year-end.

The EU is building the evaluation infrastructure that the U.S. executive order only describes in concept.

The U.K.: Funded, Staffed, and Testing Everything

The U.K.'s AI Security Institute has tested more than 30 frontier systems over the past two years — including models from Anthropic, Google, and OpenAI. Their findings should give every executive pause: they have discovered universal jailbreaks for every system tested, and found that AI models can now complete expert-level cybersecurity tasks that typically require over ten years of experience. AISI is backed by £360 million (roughly $480 million), dwarfing the U.S. Center for AI Standards and Innovation's approximately $10 million budget for 2026.

When the U.K.'s testing body has nearly 50 times the budget of its American counterpart, and the EU is building mandatory pre-market evaluation capacity, the assumption that U.S. regulation will remain lighter is a bet, not a strategy.

The Convergence Problem

Here is what boards are missing: these regulatory tracks are converging. The June 4 Congressional hearing on frontier AI — chaired by Rep. Ogles — heard testimony from the Frontier Model Forum, Google Threat Intelligence, the Electronic Frontier Foundation, and a former CISA official. The through-line was unmistakable: voluntary frameworks are transitional, not permanent. The witnesses discussed Chinese open-weight model dependence, supply chain risks from AI agent frameworks, and the collapse of timelines between vulnerability discovery and exploitation. The hearing took place two days after the EO was signed and the same day the GAAIA draft dropped. That is not coincidence — it is coordinated legislative infrastructure.

In the regulatory appendix of Cyber Risk Is Business Risk, I argue that the distinction between "compliance" and "security" is a trap. Companies that treat regulation as a checkbox exercise — doing only what is currently mandated — consistently lag behind companies that treat regulatory signals as early warnings. The companies participating in Glasswing and Gold Eagle right now are not doing it because they have to. They are doing it because they read the direction of travel.

What Your Compliance Team Should Be Preparing Now

If your organization develops, deploys, or depends on frontier AI models — and most enterprises now fall into that third category through their vendors — here is what you need on your board agenda:

Map your regulatory exposure across jurisdictions. If you operate in the EU, AI Act obligations for frontier models are already binding and enforcement starts August 2. NIS2 audit requirements are live. If you operate in the U.S., the EO's voluntary frameworks are operational through Gold Eagle. If the GAAIA passes in any form, you will need a documented AI risk framework, third-party audit capability, and an incident-reporting process. If you operate in the U.K., AISI may request pre-deployment access to test your AI systems. Running a multinational business without mapping these overlapping requirements is like flying without instruments.

Audit your AI supply chain now. Gold Eagle's VINCE platform is designed to receive vulnerability reports from anyone. That means vulnerabilities found in software your organization depends on may be disclosed through a new channel your security team is not yet monitoring. Ask your CISO: Are we plugged into Gold Eagle? Are we tracking VINCE disclosures?

Establish your incident-reporting timeline. The GAAIA proposes 15 days for critical safety incidents and 24 hours for imminent threats. The EU requires reporting without undue delay. Your current breach-notification playbook almost certainly was not built for AI-specific incidents — model weight exfiltration, agent permission escalation, training data compromise. Update it.

Budget for third-party AI audits. The GAAIA's Independent Verification Organization model and the EU's pre-market evaluation capacity both point in the same direction: external AI audits will become a cost of doing business. Start building that line item now, when you can negotiate terms, rather than later, when demand outstrips supply.

For the full framework on navigating the compliance-vs.-security tension and turning regulatory signals into board-level strategy, see the regulatory appendix and Chapter 8 of Cyber Risk Is Business Risk.