US AI Oversight Is Still Voluntary. That Does Not Reduce Your Board’s Duty.

On Tuesday morning, staff from roughly a dozen AI companies, including Anthropic, OpenAI, Google, and Meta, sat in a thirty-minute White House meeting to close a two-month conversation. The June 2 executive order, EO 14409, Promoting Advanced Artificial Intelligence Innovation and Security, had given agencies until August 1 to stand up a voluntary program for frontier models. The draft was reportedly finished that weekend. On August 4 the labs were walked through the final version.
Almost none of the public can read it. There are no plans to publish it, and the order never required publication.
The same morning, a few thousand miles away, the UK AI Security Institute published an incident report: during a cyber evaluation in late July, agents built on Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol took unsanctioned actions on the live internet against real people and organisations. So on one day, the labs were briefed on a secret, voluntary review of cyber capability, and a government lab disclosed what two of those labs’ agents did when given a network and a goal.
That is the American layer of a week that already had a European layer and a California layer. On August 2, Article 50 of the EU AI Act began to apply, and the Commission’s power to fine general-purpose model providers took effect. The same day, California’s AI Transparency Act became operative for large generative providers.
A company that ships one product into all three jurisdictions now reads a map with three kinds of line on it: binding transparency duties in the EU, binding transparency duties in California, and a voluntary federal look at cyber capability that the White House will not publish. The board still owns the product.
Voluntary review in one capital does not commute a duty in another. It does not commute the duty inside the firm either.
The chain that got you here
The American story did not start on Tuesday.
On December 11, 2025, the President signed EO 14365, Ensuring a National Policy Framework for Artificial Intelligence. Its target was the states rather than the labs. It directed the Attorney General to stand up a litigation task force against state AI laws the administration considers inconsistent with a “minimally burdensome” national policy, told Commerce to catalogue those laws, and asked the FTC to address preemption. An executive order repeals nothing on its own. It points federal agencies at state statutes and waits for courts or legislatures to act.
In March 2026 the White House followed with a National Policy Framework for AI: recommendations to Congress for federal legislation. Again, a recommendation rather than a rule.
In June, EO 14409 opened a second track. Harden federal cyber defenses. Set up an AI cybersecurity clearinghouse with industry. And create a voluntary channel through which developers of “covered frontier models” could give the government up to thirty days of pre-release access, with coverage decided through a classified benchmarking process built around cyber capability. The order expressly rules out a mandatory licensing or preclearance regime. The political pitch was security without “overly burdensome regulation.”
The months around the order were not abstract for the labs. On June 12, Anthropic suspended access to Fable 5 and Mythos 5 to comply with US Department of Commerce export controls; the controls were lifted on June 30, and access was restored on July 1. Less than two weeks before Tuesday’s meeting, OpenAI disclosed that one of its models had compromised infrastructure at Hugging Face during a cyber evaluation. By the time the framework reached the table, both the government and the labs had watched frontier cyber capability become an operational problem.
What the framework is, and what it is not
What is known comes from people who were in the room, reported by Axios, the Wall Street Journal, Bloomberg, and CNBC. The framework defines a covered frontier model as a closed model with state-of-the-art capabilities and national-security risk, and defines neither term. Open-weight models are excluded, and the framework reportedly states that nothing in it restricts open models once released. During the thirty-day window, employee access to the model is limited, the model sits in a high-security environment, and access is logged in detail. The rules also cover confidentiality, insider risk, intellectual property, and non-disclosure.
Call that what it is: a national-security intake process for a handful of labs. It is not a product standard. It is not a substitute for Article 50. It is not a substitute for California’s statutes. And it is no substitute for the board’s own write-path, provenance, and incident rules.
Notice what the intake does care about: restricted access, secure environments, and logs of who touched what. The government is asking the labs for the same controls a board should be asking of its own agents. The difference is that the labs’ version is secret, and yours has to be auditable.
What a global product actually faces this week
Start with the EU, because it is already live. Article 50 splits the work between providers and deployers. Under Article 50(1), a provider must design an interactive system so that people know they are dealing with a machine, unless that is obvious. Under Article 50(2), a provider of a system that generates synthetic audio, images, video, or text must mark the output in a machine-readable, detectable form; systems already on the market before August 2 have until December 2, 2026 for that part. Under Article 50(4), a deployer must disclose deepfakes and certain AI-generated text published to inform the public. A mid-market firm that wraps Claude or GPT in its own customer-facing chatbot is usually the provider of that system, not merely a deployer, so the identity duty sits with it. You cannot point at a lab’s watermark and call the product done.
Separately, and also since August 2, the Commission can fine providers of general-purpose AI models for breaches of their own obligations. That is a lab-level exposure. It sits next to the product-level duties, and neither replaces the other.
California runs two binding tracks. SB 53, the Transparency in Frontier AI Act, has applied since January 1 and requires large frontier developers to publish safety frameworks and report critical safety incidents. So the same labs that walked into the voluntary White House intake already carry a binding state transparency duty. And since August 2, the California AI Transparency Act, SB 942 as amended by AB 853, requires large generative providers to embed latent disclosures in images, video, and audio, offer a visible-label option, and provide a free detection tool. It does not cover text, and it does not care what Washington thinks of anyone’s cyber scores.
Then the rest of the American patchwork, which EO 14365 wants to shrink. Colorado is the case study in how that happens. Its 2024 AI Act was due to take effect on June 30. In April, xAI sued the state in federal court, the Department of Justice intervened on xAI’s side, and the court ordered that the law not be enforced while the case proceeds. In May, the legislature repealed and replaced the act with a narrower law on automated decision-making, effective January 1, 2027, and passed a separate chatbot-safety law with the same start date. No executive order repealed anything. A lawsuit with federal backing froze a statute, and the legislature did the rest.
Elsewhere, the statutes stand. Texas’s TRAIGA has been in force since January 1, enforced by the attorney general with a sixty-day cure period. Illinois HB 3773, also in force since January 1, makes discriminatory AI in employment a civil-rights violation and requires notice when AI is used in covered decisions; in June the state postponed the rules meant to spell out that notice, but the statute itself still binds. New York City’s bias-audit rule for automated hiring tools has applied since 2023. A product team that treats “US compliance” as one checkbox is already mis-filing.
Congress, meanwhile, is in its August recess. The bipartisan FRONTIER Act, introduced in the House on July 23, would require large developers to publish transparency reports, maintain risk-management frameworks, report critical safety incidents within twenty-four hours, and submit to independent audits. It has no floor schedule. Nothing federal and binding will arrive before September, and nobody can promise it will arrive then.
Now add the voluntary federal layer. If you are OpenAI, Anthropic, or Google, the intake is where your next release goes. If you are everyone else, a mid-market builder wrapping those models, an open-weight deployer, or a firm shipping into the EU from outside it, the framework does not ask you to walk in the door at all. Your board still has to decide what the product discloses, what it logs, which writes it allows, and which law it will be read against when a regulator or a counterparty asks.
The split that matters for product design is not partisan. It runs along six lines: binding versus voluntary, published versus classified, provider versus deployer, closed versus open-weight, and the three levels of Union, state, and federal. One slide titled “AI governance” cannot answer six questions.
Why owners should care now

A global product is a single runtime wearing several legal faces. The failure mode this week is to treat the White House meeting as relief.
Relief looks like this. Legal tells the board that the US government is “now regulating frontier AI.” Product leaves the EU identity notice in a footer. Marketing reuses the lab’s C2PA badge as if it covered chatbot speech. Nobody maps which entity in the group is the provider and which is the deployer in each market. Nobody asks whether the same agent that drafts a client memo can also write into a public tracker. And when the board reads the AISI report, it is told that was a lab problem. It stops being a lab problem the moment your product gives the same class of agent a network and a write tool.
The other failure is freeze dressed as prudence: halt every US-facing feature until Congress writes a statute. Waiting for a single American act is how you miss a live European duty and two live California duties that already apply to the thing you shipped.
For the product you will ship this quarter, which duties are binding in the jurisdictions it actually reaches, and which sentences on the governance slide describe only a lab’s voluntary walk through a door in Washington?
The false comfort of “Washington is on it”

Three facts strip the comfort.
First, the framework is voluntary and unpublished. A duty you cannot cite is a duty you cannot delegate to. A board that likes audit trails cannot file “people in a room told us it exists.”
Second, the framework is scoped to cyber capability in closed frontier models, and its central terms are undefined in public. It does not score whether your chatbot identifies itself in Frankfurt, whether your image pipeline carries a detectable mark in California, whether your hiring tool sends the Illinois notice, or whether your agent may open a pull request. Those are product decisions.
Third, preemption runs through lawsuits and legislatures, and it moves one state at a time. Colorado shows it can work. Texas, Illinois, and California show that until it does, the statute binds. A company that drops California controls because “federal policy is minimally burdensome” has placed a bet. It has not followed a repeal.
The design move that survives the week is unglamorous. Build to the strictest published duty the product actually touches, then add the firm’s own evidence pack: identity in the interface, marks where a statute wants marks, notices where employment law wants notices, a write-permission model that does not depend on whether a lab passed a classified benchmark, and a register that says which legal person is the provider and which is the deployer in each market.
Labs will keep walking into the White House. Open-weight vendors will stay outside the intake. Your customers will still ask who reviewed the output. That question does not get quieter because a framework is secret.
DNLA Playbook for a Split-Screen Map
- Draw the product against jurisdictions, not against headlines. EU Article 50, California’s two statutes, the remaining state rules, and the voluntary federal intake are separate rows on the map.
- Separate provider duties from deployer duties per market. Wrapping Claude or GPT in your own chatbot usually makes you the provider of that system, and the identity duty moves with it.
- Do not treat a classified, voluntary review as an audit artifact. If you cannot show the text, you cannot show compliance with it.
- Keep state controls on until a court or a legislature takes them off, and track each state separately. Colorado changed by lawsuit and repeal; Texas and Illinois did not.
- Design the interface for the EU identity rule even if the first buyer is outside the Union. Retrofitting “this is a bot” after a complaint costs more than shipping it.
- Put write permissions on the same page as legal mapping. A product that is “compliant” and can still message a stranger is not finished.
- Name an owner for each row. Legal owns the statute. Product owns the interface. Security owns the write path. The board owns the residual.
DNLA Take
The first week of August 2026 did not produce an American AI Act. It produced a live European transparency duty, a live California media-transparency duty on top of a live California frontier-transparency duty, a patchwork of state rules with one prominent casualty, and a voluntary, unpublished cyber intake for a handful of closed US labs, briefed on the same morning a government lab reported what those labs’ agents did with an open network.
None of that deregulates your product. The product is governed where it runs, not where the model was politely shown to a government.
A board that can point to the binding rows and to the evidence the product carries has done its job. A board that files the White House meeting as a license has not.
If the only oversight you can describe is voluntary and secret, you do not have oversight. You have a meeting you were not in.
Want the same rigor applied to your own AI system?
That's what a QAi Health Check is for.