Three governments looked at the same danger: an autonomous agent that acts, at machine speed, in the world. Singapore built a rail and a running engine to stop it. China is drafting a law to require part of one. And the United States, in the single binding rule its financial agents would otherwise sit under, wrote agentic AI out of scope. Same threat, three desks, three answers. The one that prides itself most on the rule of law wrote itself the exemption.
I. The Same Danger, Three Faces
In the first part of this series I argued something that surprised me: that China’s own safety establishment draws the deterministic runtime gate, the control that can refuse an agent’s action at the moment it acts, and that China is the first government moving to require even a piece of it. That essay was about one country. This one is about three, because the interesting thing is not that any single jurisdiction draws the gate. It is that the three most developed AI-governance stacks on earth, Singapore, China and the United States, are all staring at the identical problem and answering it in three completely different registers of seriousness.
I read all three the way I read everything, against one test. Can the control refuse a specific action, at the moment of that action, by a rule that does not run on the model it is meant to restrain? A control that can is a gate. A control that only watches, or scores, or files a report, or asks nicely before deployment, is not. I built a company on that distinction, so discount me for it, and I will come back to how much. But hold the ruler still for a moment and lay it against the three, because the pattern it reveals is not flattering to the people who talk most about good governance.
Put the three stacks side by side and the difference is not of will. All three see the danger. The difference is of nerve.
II. Singapore Built the Rail
Singapore is the one that treated this as infrastructure. Its financial regulator has spent the better part of a decade turning trust into shared plumbing: fairness principles in 2018, the Veritas initiative after that, Project MindForge for generative and then agentic risk, and now a stack of instruments that name the gate directly. Its media regulator, in its agentic-AI framework, states a preference most Western documents never quite manage: enforce approval through ‘system-level controls where possible, vs prompt-layer guardrails’. That is a regulator saying, in its own hand, that a control in the infrastructure beats an instruction to the model. It is the whole enforceability argument in one clause.
And Singapore did not stop at preferring the gate. Its central bank convened the financial industry and helped specify one: SAFR, a runtime layer whose engine evaluates every proposed action deterministically and returns an enforcing disposition for every one of them, deny, escalate or proceed among the outcomes, before the action executes. That is not a dashboard. That is the kernel, built, with a central bank’s fingerprints on it. I should be careful with the word binding here, because I will lean on it later: SAFR’s disposition is binding in the engineering sense, it actually stops the action, but SAFR itself is a reference model, not something a supervisor compels. The MAS supervisory guidelines now in consultation would reach further, binding financial institutions, once in force, to expectations that explicitly cover autonomous agents.
So Singapore wins on nerve, and I want to be fair about the limit of that win, because it matters for the ranking. Even here, the binding bites on the process, not the gate. The guidelines mandate that a firm run the risk management, keep the human oversight, test the kill switch. SAFR itself is a reference model, disclaimed as anything a supervisor requires. Singapore drew the gate, built a working one, and bound the discipline around it. It stopped just short of requiring the gate itself. That is the closest any liberal jurisdiction comes, and it is still one step short.
Singapore treated trust as infrastructure and built the rail. It bound everything except the one thing that does the stopping.
III. China Is Drafting the Law
China I covered at length last time, so here I will only place it in the row. Its Frontier AI Risk Management Framework, written by a national laboratory, specifies an emergency stop that must be reliable enough that it ‘cannot be circumvented by a malfunctioning or adversarial system’. Read that against the ruler and it is the model-independence the test demands, written down as a design requirement. Around it sits a chorus: a national standards framework reaching openly for circuit breakers and stop-switches, a Turing laureate describing a model that reached into a person’s emails to avoid being shut down, an academician who briefed the Politburo warning about self-improving systems, industry shipping operating-system-level containment.
And then the part that should unsettle anyone who assumed the free world leads here: China is drafting a mandatory national standard for the security of agent applications. I was careful in part one to say what that standard is and is not. It binds baseline agent-security, access limits, logging, human confirmation for the riskiest operations. It is the scaffolding of the gate, not yet the gate itself. But it is binding, and it is the first of its kind anywhere. The lab drew the gate; the state is reaching to require part of it. Whatever you think Beijing’s motives are, and I will question them before the end, the direction of travel is unambiguous.
China’s lab drew the gate hardest, and China’s state is the only one reaching to make any of it law.
IV. America Wrote the Exemption
Now the United States, which builds, with China, the overwhelming majority of the models that matter, and which has, of the three, done the least to govern what those models do.
Start with the flagship, because it is the tell. The National Institute of Standards and Technology published the AI Risk Management Framework, the document every American AI-governance conversation points to. It is a serious piece of work and it is, in its own first pages, ‘intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic’. Voluntary. Its four functions, govern, map, measure, manage, organise how a company thinks about risk. The strongest decision it describes is a pre-deployment go/no-go made by the company itself. There is no gate in it, and there was never meant to be. It governs the meeting, not the action.
Above that sits the industry’s own answer: the frontier-lab safety frameworks. The International AI Safety Report records that in 2025 alone, ’12 companies published or updated Frontier AI Safety Frameworks’. I have read them. They are genuine, and they are voluntary, self-set and self-graded, and their structure is if-then: if a model crosses a capability threshold in testing, then the developer promises enhanced security and monitoring. Those are pre-deployment capability gates and a promise to watch harder. They are not a control that refuses a specific action at runtime, and no one outside the company enforces them.
Which leaves the one place American law actually binds an AI system: federal model-risk guidance for banks. In April 2026 the Federal Reserve, the OCC and the FDIC issued revised guidance, SR 26-2, superseding the rule that had governed model risk since 2011. It is binding, examined, enforced. And in a footnote on its fifth page it says the quiet part in regulator’s prose. Generative and agentic AI models, it explains, are novel and still moving too fast to pin down, and ‘they are not within the scope of this guidance’. Read that twice. The one binding federal instrument that a financial-services agent would otherwise sit under looked directly at agentic AI and wrote it out. No successor instrument named, no deadline set, no lighter rules put in its place. For now, excluded, and handed back to the institution’s own judgement.
The states do not fill the hole. Colorado passed a high-risk AI act, then delayed its start before it ever took effect. Texas passed a narrower, intent-based law aimed at a short list of prohibited uses. California, in its Transparency in Frontier Artificial Intelligence Act, requires frontier developers to disclose and be transparent. Every one of these is worth something, and, as best I can find, not one of them mandates a control that refuses an AI agent’s action at runtime. They ask for disclosure, or impact assessments, or a banned-use list, enforced after the fact by an attorney general. The gate appears in none of them.
So here is the American stack in full. A voluntary federal framework that governs process. Voluntary corporate frameworks that gate on capability before release. A patchwork of state disclosure laws. And the single binding federal rule that would reach an agent, exempting agents by name. I want to be precise about the claim, because the sweeping version is false. American law does force runtime stops all the time, on an infusion pump, on a weapon, on a plant that can explode; medicine and aviation and heavy industry are full of mandated, model-independent, execution-time refusals. What American law has not yet done is carry that instinct across to the AI agent as such, and name it, in binding law, as a thing that must be stoppable at runtime. In the one financial rule that came closest, it wrote the agent out.
America did not fail to require the gate. It looked at the agent, in its one binding rule, and wrote the agent an exemption.
V. The Scoreboard
Lay the three in a row and score them by the only question that matters, whether the control can refuse the action.
Does the stack draw the gate? All three do. Singapore prefers it in writing and built one. China specifies its properties and ships instances. Even America’s labs describe deployment controls, and the international report’s scientists treat the capacity to regain control, to shut a system down and keep it down, as central to averting a loss of control. Nobody is confused about what the answer looks like. On the description, the field is unanimous.
Does the stack require the gate? Here I have to slow down, because require has a legal meaning and an engineering one, and sliding between them is how you cheat the reader. Take require in the strict sense, enacted law in force today. On that test none of the three requires a model-independent runtime refusal of an agent’s action. Not one. Singapore’s engine is disclaimed, China’s mandate is still a draft, America’s binding rule excludes the agent. The honest enacted score is zero to zero to zero.
So the interesting axis is not who has arrived but who is moving, and in which direction. Singapore built a runtime engine and bound the process around it, while stopping short of compelling the engine itself. China specified the gate’s properties in a lab framework and is now drafting, though not yet enacting, a mandatory standard that would bind the scaffolding around it. America had an in-force federal rule that could have reached the agent, and used it to write the agent out. Line those up by declared direction of travel and the order is plain: China reaching furthest, Singapore next, and the United States the only one of the three moving the other way.
I do not enjoy that finding, so let me put my full weight behind the reading that most threatens it. A mandatory Chinese standard for agent security is at least as much the instrument of a state that wants its own hand on every switch as it is a safety measure. Read it that way, and China reaching furthest is a fact about how much control Beijing intends to keep, not evidence that China governs AI better, or more safely, or more freely. It does not, on any of those. The scoreboard measures one narrow thing: which government is willing to move toward writing the word must into law over an autonomous agent. On that one axis, the democracies are the ones still declining to write it. That is a matter of reading the documents, not of admiring the regime that has reached the furthest toward the mandate.
Measured by who is reaching hardest to make an agent stoppable by law, the order runs China, Singapore, then the free world. Measured by who has enacted it, no one has, yet.
VI. The Case Against This Essay
A polemic that concedes nothing is just a press release, so here is where I hand the prosecution its own cross-examination.
Start with me, and with my commercial interest, which I will state in the body rather than bury in a footer. I sell the gate. The kernel this whole series says the world should require is the thing my firm builds, and the enforceability test by which I have just ranked three governments is my own instrument, not theirs. An essay that grades every jurisdiction against the author’s product and finds the author’s product missing is a sales funnel with footnotes, and you should read it knowing that. My only defence is the one I offered last time. The load-bearing words are not mine. The preference for system-level control is Singapore’s regulator’s. The model-independent stop is the Shanghai lab’s. The exemption is the American agencies’, in their own footnote. I did not write those. I only lined them up.
Next, the comparison is not clean, and an honest critic will say so first. I have set three different kinds of instrument beside each other as if they were the same race. Singapore’s is a financial supervisor’s rail. China’s is a national laboratory’s framework plus a standards body’s roadmap. America’s headline exhibit, SR 26-2, is bank model-risk guidance, not the whole of American AI policy, and it is unfair to let one footnote in one financial rule stand for a continental government. That is a real objection, and it did real work on this essay: it is the reason the scoreboard above ranks direction of travel and not enacted law, and the reason I will not tell you China has enacted anything, because it has not. What I will say is that I went looking, across the federal framework, the state laws, and the corporate commitments, for a single American instrument that mandates a runtime refusal of an AI agent’s action, as such, and I did not find one. Outside AI, as I said, the law mandates runtime stops all the time. It has simply not yet carried that across to the agent. The footnote is not the whole indictment. It is the sharpest line in an indictment the rest of the American stack already writes.
Then the strongest defence of the American position, which is not stupidity but a real argument. Perhaps the voluntary, market-led approach is not weakness but speed. A frozen mandate locks in this year’s answer; a dozen labs iterating their own frameworks may reach a better control faster than any regulator could draft one, and the American bet is that competition and disclosure beat compulsion. I take that seriously. I even think it is half right, in the way I argued last time that a good gate is an allowlist and not a rulebook. But speed is a defence of staying voluntary for now. It is not a defence of writing agentic AI out of the one binding rule you already have. You do not exempt a thing because you are moving fast on it. You exempt it because you have decided not to move.
There is a stronger version of that defence, though, and I owe it a hearing. Maybe scoping agentic AI out of SR 26-2 is not abdication but craft. A rule written for static statistical models genuinely may be the wrong instrument for an agent, and a regulator who knows it might reasonably wait for a purpose-built rule rather than freeze a bad control into examinable law. I grant that reading. It is a good one, and it may well be the true one. What I cannot yet grant it is evidence, because an exclusion that names no successor instrument and sets no deadline is, from the outside, indistinguishable from an exclusion that means to do nothing. The day a purpose-built rule appears, I will read the deferral as craft. Until it does, it reads as a gap.
And then the concession that costs me most, so I will say it plainly. The enforceability test is mine. I chose runtime refusal as the thing that counts because it is the thing my firm builds, and a different judge with a different ruler need not reach my ranking. Grade these three stacks by realised harm reduction, or by how many firms have actually put a control into production, or by the maturity of their audit trails, and the American stack, thick with institutional practice, would not sit last. It sits last on my axis, the narrow question of whether the law will compel a machine to stop. I happen to think that axis is the one that will matter most as agents come to act faster than any human can supervise. But it is a choice of ruler, not a law of nature, and you are entitled to weigh it against the others.
And a caveat on freshness, because this is a snapshot of a moving target. American state law is in flux; California’s transparency regime is new, Colorado’s delayed act may yet take effect or be rewritten, and a federal posture can turn in a single administration. If, six months from now, a US instrument mandates an execution-time refusal of an agent’s action, this essay’s ranking is wrong and I will say so in public. That is the test I have set myself, printed at the top of the file.
Distrust the man who sells the gate and drew the ruler. Then read the American footnote he did not write, and see if it says anything other than what he says it says.
VII. Coda: The Word ‘Must’
To require a gate is to accept, in advance, that you might one day have to stop your own most valuable machine. That is an uncomfortable thing for any government to write down, and you can see each of the three flinching from it in its own way. Singapore bound everything it could bear to bind and left the last inch voluntary. China reached for the word must and, being China, reached for it in a form that also happens to put the switch in the state’s hand. America looked at the sentence and decided not to write it at all, and dressed the decision up as a philosophy of innovation.
I keep coming back to the shape of that. The jurisdiction with the least constrained state is reaching hardest for the binding rule, and the jurisdictions that constrain their states most carefully are reaching least. There is a comfortable story where that is a coincidence, or where voluntary is really just wiser, and I have given that story its fair hearing. But strip the comfort away and a plainer reading is left. It is easy to describe a safeguard. It is easy to prefer it, to build a demonstrator, to publish a framework, to convene a forum. All of that is the drawing. The law is the deciding, and on the deciding, over the agent itself, the free world has so far held back.
The gate is drawn in three languages. It is not yet the law in any of them. Two governments are reaching for it, and one is backing away from the one place it had already been within reach. That last move is ours.


Leave a comment