Three rulebooks in fifteen days
July 2026 was a clarifying month for anyone who builds with AI, although nobody planned it that way.
On July 1, China's new ethics and safety guidelines for AI applications took effect. On July 5, Google published a white paper proposing how America should govern frontier AI. On July 6 and 7, the United Nations convened its Global Dialogue on AI Governance in Geneva, forty scientists and most of the world's governments in one room. On July 15, two more Chinese instruments became binding law. And in the background of the same month, almost unnoticed, the European Union's freshly amended AI Act timetable entered into force.
Fifteen days, three completely different answers to the same question, with a fourth rewriting itself quietly in Brussels. It is worth reading them side by side, because the differences are not details. They are philosophies.
Start with Google's proposal, because every word in it is doing work. The company suggests a "federally overseen, industry-backed organization" to set frontier AI safety standards and run "voluntary audits." Federally overseen: the government watches. Industry-backed: the companies pay for it and staff it. Voluntary: nobody has to come. The newsletter that flagged the paper called it a pragmatic middle path between over-regulation and doing nothing, and noted, almost in passing, that purely voluntary arrangements are losing political support even in Washington.
Here is what that newsletter did not say. America has already run this exact experiment, several times, with the receipts filed in congressional archives.
A federally overseen, industry-staffed body that certifies safety while the regulator watches from a distance is a precise description of how the FAA delegated aircraft certification to Boeing's own employees under the Organization Designation Authorization scheme. That structure certified the 737 MAX. Three hundred forty six people died, and the congressional report afterwards found what such reports always find: the overseer had drifted into trusting the overseen. Before that, the SEC ran a voluntary supervision program for the big investment banks. It was dissolved in September 2008, the same month Lehman Brothers was, and SEC Chairman Christopher Cox performed the rarest act in Washington, an admission: "voluntary regulation does not work."
The British record is, if anything, richer. The banks self-reported the interest rate that half the world's contracts were priced on, until it emerged they had been rigging it for years. The press regulated itself through the Press Complaints Commission, right up until the phone-hacking scandal disbanded it. The water companies were trusted to monitor their own sewage discharges, and anyone who has followed the state of English rivers knows how that ended. In 2023, with this record behind it, the UK government published its AI white paper and chose, once again, no new law. A "pro-innovation approach." Existing regulators would cope. The industry would behave.
Which brings me to the part of this story that actually interests me: how London and Washington behave as a unit whenever they believe they are ahead.
In November 2023, the UK convened the Bletchley Park summit and set the agenda around "frontier AI," a category that at the time meant a handful of American labs plus DeepMind. Twenty eight countries signed the resulting declaration, so the guest list was broad; the framing was not. In April 2024, Michelle Donelan and Gina Raimondo signed a memorandum of understanding wiring the two AI Safety Institutes together, the first bilateral agreement of its kind. And in February 2025, in Paris, when about sixty countries signed the AI Action Summit declaration, two refused, together: the United States and the United Kingdom. JD Vance told the hall that overregulation could kill a transformative industry just as it takes off. Britain cited national security. The pattern is not new, and it is not conspiratorial either. When you are ahead, you champion standards, your standards, voluntarily arrived at, in bodies you convene, with agendas you frame. Rules with teeth are for other people's industries. That is simply what leading looks like from the inside, and both governments would say so openly. What is worth noticing is the choreography: two policies that arrive at the same refusal on the same day, from the two countries with the most to lose from binding rules.
Meanwhile, the country they are trying to hold off skipped the philosophy seminar. China's July rules are not aspirational principles. Anthropomorphic AI services must file their algorithms with the regulator. Services must disclose they are AI. Virtual intimacy services for minors are not discouraged, they are prohibited. Companion apps must interrupt users after two hours. A safety assessment is triggered, mechanically, at one million registered users. Agents in healthcare and transport must be filed and tested before deployment, with recall provisions if they misbehave. I hold no illusions about the motives; a state that requires algorithm filing is also building a lever of control, and the same apparatus that protects minors polices speech. But as regulatory engineering, it is concrete where the Google paper is diplomatic: thresholds instead of principles, effective dates instead of consultations, prohibitions instead of postures.
And in Geneva, the rest of the world sat down at the one table where it gets a chair. The scientific panel's Yoshua Bengio told delegates that science currently cannot guarantee increasingly capable AI will not cause catastrophic harm, which is a remarkable sentence to say out loud while the leading jurisdiction proposes voluntary audits. El Salvador's ambassador, co-chairing, pointed at the divide nobody in San Francisco or London likes to discuss: most countries will never train a frontier model. They will consume systems built elsewhere, under rules written elsewhere, and the Global Dialogue is their only venue for objecting. The Anglosphere's answer to that room has been consistent: warm words, no signatures.
Europe was in that room too, and its month deserves its own paragraph, because it was the strangest of the four. In Geneva, the Commission's Roberto Viola delivered the EU statement: governance rooted in universal human rights, evidence over vibes, and, pointedly, a follow-up mechanism so that principles agreed in Geneva become measurable accountability at home. Of the Western powers, only Europe does both halves: binding law domestically, signature and engagement multilaterally. That is a coherent position, whatever you think of its content. But July also brought the wrinkle. The same month, the EU's Digital Omnibus entered into force and quietly moved the AI Act's high-risk obligations from August 2026 to December 2027, some as far as August 2028. Brussels held the line on transparency, from August 2 an AI system in the EU must tell you it is an AI, but the heavy rules slipped by well over a year, after a lobbying campaign in which the loudest voices were the same companies proposing voluntary audits at home. Even the jurisdiction that chose law over trust turns out to be movable when the trust lobby leans on it. The gravitational pull of the voluntary model reaches Brussels too.
I should say where I sit in all this, because it is not on the sidelines. I run a small AI company in Germany. From August 2, Article 50 applies, and my product must disclose to every customer's customer that they are talking to a machine, which we do anyway, but now with documentation. The heavier obligations I had budgeted my autumn for just moved to the end of 2027, and here is the uncomfortable honesty: I felt relief. The European way costs me personally, every quarter, and there are days I resent it. The self-regulation pitch is seductive to someone like me; I am, after all, the industry that would be doing the self-regulating.
But I keep coming back to the Boeing engineers. They were not villains. They were competent professionals inside a structure that asked them to mark their own homework while their employer's stock price watched over their shoulder. Every self-regulation failure on the list looks like that from inside. Nobody rigging Libor thought of themselves as rigging anything. The industry never believes it needs regulating, and it is always sincere.
The EU AI Act may prove clumsy. The UN dialogue may produce nothing but communiqués. China's filings may serve the filer more than the public. All three are honest attempts to answer the question with something other than trust us. As of this July, the jurisdiction leading the technology is the only one still offering trust as the mechanism, and offering it jointly with the one other country whose regulatory record makes trust the strangest possible ask.
The audits, at least, will be voluntary.