US executive order on AI security
System security requirements move into enforcement.
Governments started writing laws about what AI may and may not do and who answers for mistakes. It is both a brake on the industry and the condition for market access.
AI governance moved from declarations into operating mode: requirements, audits, reporting, fines. Deadlines and boundaries keep shifting.
System security requirements move into enforcement.
High-risk requirements and transparency obligations take effect. Fines reach €35M or 7% of global turnover.
Access to advanced accelerators remains an export-control instrument: the geography of compute is not set by the market.
Systems generating intimate imagery of an identifiable person without consent join the prohibited list.
Stand-alone high-risk systems — hiring, scoring, biometrics, justice, borders — moved from August 2026 to December 2027.
Europe plans its own pre-market model evaluation capacity, expected to be operational around 2027.
The equivalent of non-proliferation treaties for systems above a capability threshold. Neither a body nor a verification mechanism exists.