Two bets on AI safety: the EU wrote binding rules, the US is asking nicely
This month both big Western regulators hit milestones that point in opposite directions. The EU AI Act started enforcing; the US leaned on a voluntary, cyber-framed framework that essentially asks frontier labs to police themselves. This week's OpenAI pause is the American bet in action — strengths and weakness on show at once.

The two biggest regulators in the Western world both reached AI milestones this month, and they could hardly be pointing in more opposite directions. In Europe, the EU AI Act started actually enforcing — binding rules, real fines, mandatory disclosures. In Washington, the deadline passed for a very different kind of instrument: a voluntary framework that mostly asks frontier AI labs to cooperate. Two governments, two philosophies, and this is the month you can watch both run in the wild.
What the American approach actually is
On 2 June, President Trump signed an executive order — "Promoting Advanced Artificial Intelligence Innovation and Security" — that set the tone: light-touch, and framed around cybersecurity rather than broad AI harm. It has three main strands. It pushes federal agencies to harden their own and critical-infrastructure cybersecurity. It directs prosecutors to go after AI-enabled cybercrime. And, the centrepiece, it tasks agencies with building a voluntary framework — due by 1 August — for the developers of the most capable models to engage with the government before release.
The mechanics are telling. Under the framework, a developer of a "covered frontier model" would give the federal government access to the model for up to 30 days before it ships, and the two would collaborate on which trusted partners also get early access. Agencies including the NSA, CISA and NIST were tasked with building a classified benchmarking process to measure a model's cyber capabilities and decide what counts as "covered" in the first place.
Read that back and notice the load-bearing word: voluntary. There is no mandate, no fine, no compulsion. The government gets an early look and a seat at the table; it does not get to say no. The whole design assumes the labs will show up in good faith.
The opposite bet, across the Atlantic
The EU made the other wager entirely. Its AI Act is binding law, with penalties that reach tens of millions of euros or a slice of global turnover, and disclosure obligations that apply whether a company likes them or not. Europe is betting that rules, audits and the threat of a fine are what keep a fast-moving industry honest. Washington is betting that cooperation, framed as national security, gets you further than confrontation — and that heavy rules would just push AI development offshore. (We laid out the general menu — hard law, soft law and self-governance — in an earlier explainer; this month is that abstract choice becoming concrete.)
This week handed the American bet a live test
Here is what makes the timing worth writing about. This week, OpenAI paused its largest planned training run and tightened its safety monitoring after judging that an upcoming model might cross a "Critical" cybersecurity threshold. That is almost exactly the behaviour the US framework is designed to encourage — a lab self-assessing a frontier model's cyber capability and acting on it, voluntarily. OpenAI's internal language ("covered" capability thresholds, cyber-capability benchmarks) even rhymes with the executive order's.
So the good news for the voluntary model is real: a lab looked at its own roadmap and slowed down without anyone forcing it. But the same episode exposes the approach's soft spot. OpenAI published the decision and withheld the evidence — no technical postmortem, no data behind the classification. Voluntary governance only works if the labs self-report honestly and in enough detail to be checked, and this week they published a headline, not their workings. That is precisely the gap a binding regime with audit powers is built to close.
The open question
Neither bet is obviously right. Binding rules can lag a technology that reinvents itself every few weeks, and can indeed drive work to friendlier jurisdictions. Voluntary cooperation is nimble and keeps the labs onside — but it is only ever as good as the labs' willingness to be transparent, and it hands the public a lot of trust to extend. This month you don't have to argue it in the abstract: the EU's rulebook and America's handshake are both live, and this week gave us an early real glimpse of what the handshake looks like when a lab actually has to decide something. Encouraging, and incomplete — which is a fair summary of the whole American bet.
Ask Relay — he reads every question himself and replies personally by email.
