← All articles Blog

Who's In Charge of AI? (An Honest Map of Almost Nobody)

By Dr. Mahmoud Alminawi · SEP 18, 2026 · 7 min read

Every post in this series has ended up pointing at the same hole. The datacenter deals negotiated in secret. The biased models deployed with no testing requirement. The deepfake scams with no disclosure rules to slow them down. Different problems, one common feature: nobody was required to prevent any of it.

So this post answers the question directly: who actually governs AI right now? I'll warn you upfront that the answer is messy, and I'm going to resist making it sound tidier than it is. But messy is worth understanding, because this is the layer where everything else in this series either gets fixed or doesn't.

First, what "governing" would even mean

When I say AI is barely governed, I don't mean anything exotic. For every other technology that can hurt people who never chose to use it, we eventually built the same boring machinery: testing before release, disclosure of known limits, someone liable when it fails, and a way to report incidents so the same failure doesn't repeat. Cars, drugs, airplanes, even your microwave. None of this stopped those industries. It's why you trust them.

Hold that boring standard in your head as we tour what actually exists.

The United States: regulation by tug-of-war

Start with the simplest fact: the US has no comprehensive federal AI law. None. In the country where most of this technology is built, there is no statute that says what an AI system must do, disclose, or avoid before being deployed on the public.

What exists instead is regulation by executive order, which means the rules swing with each administration. One White House issued AI safety requirements in 2023; the next revoked them in January 2025 and replaced them with an explicitly deregulatory approach built around accelerating the industry. Whatever you think of either policy, notice the structural problem: rules that reverse every four years aren't really rules. No serious industry can be governed by whiplash.

Into that void stepped the states. California passed a frontier-AI transparency law. Colorado passed the country's most comprehensive AI accountability act, then delayed it under pressure before it ever took effect. Texas, Illinois, Utah and others passed their own targeted laws. The result is a patchwork, and here's where 2026 got genuinely strange: in December 2025, the White House issued an executive order directing the Justice Department to establish a task force to challenge state AI laws in court, and leveraging federal funding against states with AI rules deemed too burdensome. Whether that holds up legally is an open question, since preemption normally requires Congress to act, and Congress hasn't.

Step back and look at the picture. The federal government has no AI law, and is actively litigating against the states that wrote their own. The referees are suing each other while the game runs at full speed. That's the current American answer to "who's in charge."

Europe: the strictest law in the world, now on pause

The European Union did what the US hasn't: it passed an actual comprehensive law. The AI Act, adopted in 2024, bans certain uses outright (like social scoring), requires labeling of AI-generated content and deepfakes, imposes duties on the companies building the biggest models, and reserves its heaviest requirements — testing, documentation, human oversight — for "high-risk" systems: AI making decisions about your job application, your loan, your education. Fines run up to 7% of global revenue. On paper, it's everything the boring standard asks for.

Here's what happened next, and I'd be lying by omission if I skipped it. As the high-risk rules approached their August 2026 start date, the compliance tools and technical standards companies needed weren't ready, industry pressure mounted, and the EU amended its own law, pushing the high-risk obligations to the end of 2027, and to 2028 for AI embedded in products like medical devices. Some parts did take effect on schedule: the bans, the model-provider duties, and as of August 2026, the requirement to label AI-generated content. But the core of the thing — the part that would govern AI deciding whether you get hired or get a loan — is deferred.

I want to be fair about what that means. It is not evidence that regulation failed; you can't comply with standards that don't exist yet, and a delayed good law beats a punctual bad one. But it is evidence of something uncomfortable: even the world's most determined regulator, with a signed law in hand, could not hold its timeline against the speed and pressure of this industry. If the EU blinked, what exactly is doing the governing in the meantime?

What fills the vacuum: promises

The honest answer: self-regulation. Voluntary commitments, published safety frameworks, internal ethics teams. Some of it is sincere, and I know people doing that work in good faith.

But look at the structure instead of the sincerity. These companies are locked in a race where the perceived prize is dominance of the most important technology in decades. In a race, the company that unilaterally slows down for safety loses to the one that doesn't. Voluntary commitments carry no penalty when abandoned, and internal safety teams can be reorganized away the moment they're inconvenient — and sometimes have been. This isn't because tech executives are villains. It's because we've never, in any industry, successfully relied on competitors to restrain themselves mid-race. It's why speed limits aren't voluntary.

There's a name for what our system currently does with AI's downsides: it externalizes them. The gains from moving fast go to the builder. The costs — the biased screening, the cloned voice, the strained water system — land on people who never signed up. Post 4 showed you that pattern case by case. This post is telling you it isn't an accident. It's what happens, every time, in the gap before rules exist.

What good rules would look like (and what they wouldn't)

Because I promised you I'm not here to scare you, let me end with the fixable part — and it's genuinely fixable. Good AI governance isn't a mystery and doesn't require slowing science to a crawl. It looks like the boring machinery we already know: disclosure requirements, so you know when AI made a decision about you and what it's known to get wrong. Testing proportionate to stakes — more scrutiny for the system denying loans than the one recommending movies. Liability that lands on whoever deployed the system, so "the algorithm did it" stops being a defense. And incident reporting, aviation-style, so failures teach the whole field instead of getting buried in settlements.

Reasonable people will argue about the details, and should. Bad regulation is real too; rules written clumsily can entrench the biggest players and strangle the small ones. But notice that every item on that list already exists in some industry you trust your life to. We're not inventing anything. We're just deciding whether AI gets the same treatment as every other technology powerful enough to hurt bystanders — and right now, on both sides of the Atlantic, the honest status is: not yet.

Which leaves one question hanging, the biggest one. If we're struggling this badly to govern AI's ordinary harms, what about the extraordinary ones?

Next in the series: the finale — taking the "will this destroy us?" question seriously.


Sources worth your time: the European Commission's AI Act overview and White & Case's analysis of the December 2025 US executive order on state AI laws.

Next step

Dealing with something like this?

Tell me what you're facing and I'll tell you honestly whether you need help — or don't.

Get in touch