Applying the enforceability test to the nine AI governance frameworks everyone is sharing, and the tenth nobody charted.
I. The chart everyone is sharing
A chart has been doing the rounds this month, credited to Hari Kota: nine AI governance frameworks, one blunt tagline underneath. Only two of the nine can actually fine you.
It is a good chart. It sorts EU AI Act, Colorado’s law, Japan’s law, ISO/IEC 42001, the IEEE 7000 series, NIST AI RMF, Singapore’s Model AI Governance Framework, Saudi Arabia’s SDAIA framework, and OECD Principles plus the UNESCO Recommendation into three buckets: mandatory law, certifiable standard, and voluntary or intergovernmental guidance. That sorting is exactly the discipline I call the enforceability test in TrustOS work: before you spend a governance budget, ask what actually binds you, what merely certifies a management system, and what is simply a shared vocabulary everyone has agreed to nod along to.
The chart is directionally right. It is also, on several rows, already out of date, because 2026 has been the year every one of these frameworks moved. Below is the same nine, run through the enforceability test again with what has actually happened since the ink dried on that graphic, plus a tenth governance layer nobody puts on charts like this at all.
II. The enforceability test, applied
Here is the same nine frameworks, reapplied against what changed in 2026. The category is the chart’s own. The reality check is what the enforceability test surfaces once you look past the label.
| Framework | Category | Can it fine you? | 2026 reality check |
|---|---|---|---|
| EU AI Act | Mandatory law | Yes, up to €35m or 7% of global turnover | The Digital Omnibus pushed the Annex III high-risk deadline from 2 August 2026 to 2 December 2027, and Annex I embedded systems to August 2028. Article 50 transparency was not touched and has applied since 2 August 2026, with its own €15m or 3% tier. The Commission’s own FAQ also confirms AI agents are not exempt just because the Act never names them as a category. Source |
| Colorado SB 26-189 | Mandatory law | Yes, from 1 January 2027, once rules exist | The original Colorado AI Act (SB 24-205) never took effect. A federal court stayed it in April 2026, and Governor Polis signed a full repeal-and-replace on 14 May 2026. The narrower Automated Decision-Making Technology law that replaced it also dropped the affirmative defence for aligning to NIST AI RMF or ISO 42001. Rules are still pending from the Attorney General. Source |
| Japan AI Promotion Act | Mandatory law, no fines | No monetary penalty, ever, by design | Genuinely has no penalty clause. Its only lever is administrative guidance and public naming. It got its first live test in January 2026, when Japan’s Cabinet Office summoned X Corp’s local subsidiary over Grok-generated non-consensual sexual imagery. No fine followed, because none is possible under this law. Source |
| ISO/IEC 42001 | Certifiable standard | No direct fine, but a real certificate | Anthropic, AWS, Microsoft and IBM are now certified. CEN adopted it without changes as EN ISO/IEC 42001:2026 in March 2026, and 34 countries must give it national-standard status by September 2026. A companion standard, ISO/IEC 42006, now sets the bar for the auditors themselves. None of this changes the chart’s own warning: you set the scope of what gets certified. |
| IEEE 7000 series | Certifiable standard | No | Still what it has always been, a design-process standard. It verifies that ethical requirements were built into a system’s design, not that the finished output behaves. Certifying the process is not certifying the outcome. |
| NIST AI RMF | Voluntary framework | No, but that may not hold forever | Still voluntary, still no penalty. But NIST’s Center for AI Standards and Innovation launched an AI Agent Standards Initiative in February 2026, working toward a certifiable AI Agent Interoperability Profile due in Q4 2026. “No external proof of conformity” is this year’s answer, not next year’s. Source |
| Singapore MGF (GenAI and Agentic AI) | Voluntary framework | No | Version 1.0 for agentic AI launched at Davos on 22 January 2026, the world’s first governance framework written specifically for agents. IMDA updated it to v1.5 on 20 May and again 5 June 2026, adding multi-agent risk and case studies from more than sixty companies. IMDA also published a discussion paper on legal responsibility for AI agents the same month, which is the sound of a voluntary framework testing whether it needs a harder edge. Still voluntary. Organisations remain legally accountable regardless. Source |
| Saudi SDAIA frameworks | Voluntary framework | Not yet | The 2023 Ethics Principles and 2024 Generative AI Guidelines are still advisory. But SDAIA opened public consultation in April 2026 on a draft Responsible AI Policy that introduces four risk tiers, system registration, ethics labelling and audit obligations for high-risk systems. “Bindings sit in other laws, not here” is an accurate read of where SDAIA stands today, and a shrinking one. Source |
| OECD Principles and UNESCO Recommendation | Intergovernmental principle | No | Still non-binding. But the OECD published Due Diligence Guidance for Responsible AI in February 2026, and UNESCO released new ethics-review and documentation tools at its Global Forum on the Ethics of AI in Riyadh on 9 September 2026, three weeks before this was written. No enforcement, but a thickening shared vocabulary that binding regimes increasingly borrow from. Source |

Of the nine, the chart’s core claim holds. Two can genuinely fine you. But three others (Colorado, Singapore, Saudi Arabia) are actively moving, and the direction of travel is the same in each case: toward more teeth, not fewer.
III. The tenth tower the chart missed
None of the nine boxes on that chart cover the layer that, in practical terms, decides whether the next generation of frontier models even ships. That is each lab’s own self-governance policy: Anthropic’s Responsible Scaling Policy, Google DeepMind’s Frontier Safety Framework, OpenAI’s Preparedness Framework.
These are not law. Nobody voted on them. Anthropic rewrote its RSP into version 3.0 on 24 February 2026, then revised it again to version 3.1 in March and version 3.4 by July, introducing Frontier Safety Roadmaps and recurring Risk Reports along the way. DeepMind’s Frontier Safety Framework reached version 3.0 in April 2026. Twelve labs now publish something in this genre, including Meta, Microsoft, Amazon and xAI.

Here is the detail worth sitting with. Anthropic’s own policy states plainly that the better long-run answer is third-party governance of every relevant frontier developer, not each lab marking its own homework indefinitely. That is a frontier lab arguing, in its own binding-on-itself document, for its own eventual regulation. Nothing on the nine-box chart captures that kind of self-aware unenforceability, and it may be the single most consequential governance document in the entire stack, because it is the one that actually gates what gets built before any regulator sees it.
IV. What Stanford, Mila and the WEF are actually measuring
Step back from any single framework and three research bodies are independently measuring the same gap.
Stanford HAI’s 2026 AI Index Report, published 13 April, put a number on it. Documented AI incidents rose to 362 in 2025, up from 233 the year before. The Foundation Model Transparency Index, which scores how much leading developers disclose about their own systems, fell from 58 to 40 points. Only 31 percent of Americans surveyed trust their own government to regulate AI well. Enterprise adoption sits at 88 percent, but agentic deployment inside those organisations stays shallow. The report’s own framing is a straight line: capability is accelerating faster than governance can follow.
Mila’s contribution runs deeper than a data point. Yoshua Bengio chairs the International AI Safety Report 2026, published in February with more than a hundred contributing experts and a secretariat split between the UK AI Security Institute and Mila. Its central finding for anyone building agentic systems is specific: agent autonomy shrinks the window in which a human can actually intervene before harm occurs. The report calls the policy problem an evidence dilemma. Capabilities move in months, evidence of real-world harm takes years, and regulators are asked to legislate into that gap.
The World Economic Forum’s AI Governance Alliance closes the loop between research and regulation directly. Its paper, AI Agents in Action, is cited in the annex of Singapore’s own Model AI Governance Framework for Agentic AI, the same document I helped shape with IMDA. That is not three separate institutions publishing in parallel. It is one shared vocabulary, assembled in public, that the binding regimes keep borrowing from even when they never cite each other by name.
V. TrustOS as the answer key
This is the exact churn TrustOS was built to survive. Its seven layers already map to MAS FEAT and AIRG, the EU AI Act, NIST AI RMF, ISO 42001, IMDA’s Model AI Governance Framework, the OWASP Agentic Top 10, GDPR and the Colorado AI Act, eight named regimes across one architecture.
Look at what happened to three of those eight in 2026 alone. The EU AI Act’s own deadlines moved twice. Colorado’s law was repealed and rewritten from the ground up, losing its affirmative defence in the process. IMDA rewrote its own MGF twice in five months. A programme built to satisfy any one of those regimes by name would have needed rework each time the wording underneath it changed. A programme built on TrustOS did not, because it never bet on the wording. It abstracted the control objective, human oversight, risk tiering, logging, accountability allocation, that every one of these regimes is independently converging on, and let each regime’s specific language sit on top as a thin translation layer.
That is the actual test of a governance framework in a year like this one: not whether it maps cleanly to nine boxes on a chart, but whether it still stands after two of those boxes get rewritten under it.
VI. The Fork, revisited
Run the same nine through the Fork and they sort into the two futures I keep coming back to: Star Trek or Mad Max.
The Star Trek pole is procedural and evidentiary. It runs on conformity assessments, documentation trails, certificates a third party actually signs. The EU AI Act sits here, and so does ISO/IEC 42001 once you have the audit in hand. Colorado’s ADMT law is trying to join this pole, once the Attorney General finishes rulemaking.
The Mad Max pole runs on reputation and cooperation instead. Nobody polices it directly, so it survives only as long as the actors inside it keep choosing to cooperate. Japan’s AI Promotion Act is the purest example on the chart, no penalty clause at all by design. Singapore’s MGF, Saudi Arabia’s ethics principles, the OECD Principles, the UNESCO Recommendation, and every frontier lab’s self-written safety policy all sit here too, whatever their pedigree.
January 2026 gave the Mad Max pole its live stress test. Japan’s Cabinet Office summoned X Corp’s Japan subsidiary over Grok-generated non-consensual imagery and had exactly one lever to pull: a stern conversation and the threat of being named publicly. No fine was possible, because the law was written to make sure none ever would be. Whether that holds as a real deterrent, or reveals itself as theatre the moment a large enough operator decides reputation is a cost worth paying, is the open question the entire Mad Max pole is quietly betting on.
VII. Prompts, loops, loop governance
Every one of the nine frameworks on that chart was drafted, in its original text, to answer a single question: is this output safe? One prompt in, one answer out, one moment to check.
Agentic AI broke that question quietly, and 2026 has been the year every framework on the chart admitted it. NIST’s draft Agentic Profile extends GOVERN, MAP, MEASURE and MANAGE to cover autonomy-tier classification, tool-use risk mapping, and delegation-chain monitoring across a multi-step loop, not a single turn. IMDA rewrote its MGF specifically to add multi-agent risk and safety components between versions 1.0 and 1.5. Even the EU AI Act, whose text never mentions agents at all, gets stretched to cover them through the Commission’s own reading of Article 3, on the logic that an agent is still an AI system whatever it calls itself.
That is the tell. None of these bodies rebuilt their frameworks from scratch for agentic AI. They patched the prompt-era version to reach further into the loop. Patched governance answers where an agent’s output changed. It rarely answers what the agent decided to try next, why it chose that action over another, or who was accountable for the fifteenth step in a chain nobody watched in real time. That gap, prompt governance stretched thin over loop-shaped risk, is exactly where TrustOS’s loop-governance layer sits, and exactly why patching an old framework is not the same work as designing for one.
VIII. My usual panel weighs in
I put this chart in front of the voices I track most closely. Here is where their own published positions, not mine, land on it.
Yoshua Bengio, Mila. His International AI Safety Report is the clearest institutional statement that the nine-box framing undersells the actual risk. A framework can bind an organisation on paper while the thing it is meant to govern, an autonomous agent mid-loop, has already closed the window for a human to step in. Enforceability and interveneability are two different properties, and this chart only measures the first.
Anthropic, on its own Responsible Scaling Policy. The company that owns the tenth tower is on record saying self-governance is a stopgap, not a destination. Its RSP explicitly frames third-party oversight of every frontier developer as the better long-run design. That is a rare admission from inside the system: the most consequential governance layer in this whole piece knows it should eventually be replaced by something with actual teeth.
Stanford HAI. The Index team is not in the business of recommending policy, only measuring it, and their own number tells the story better than a recommendation would. A transparency score falling from 58 to 40 in one year, while incidents rise from 233 to 362, is a governance system losing ground in real time, whatever the charts of frameworks suggest about coverage.
April Chin, Resaro, on Singapore’s own launch. Speaking when the MGF for Agentic AI first launched, she called it the first authoritative resource addressing agentic AI’s specific risks, closing a real gap in policy guidance by giving organisations a way to define agent boundaries and build in the right mitigations. That is the practitioner’s read from inside the framework I helped build, and it is a fair one. It just does not, by her own account, make the framework binding.
IX. Ghost GDP, AI Atlantis, and the governance theatre problem
Hold all of this together and it is the same story I have been telling under Ghost GDP and AI Atlantis, just with a chart attached this time. Enterprises are running agentic loops today, generating real economic value and real economic risk, inside a governance perimeter that a chart like this one flatters into looking more solid than it is.
Only two of nine frameworks can actually fine anyone. A third of the remaining seven are visibly moving toward teeth this year. The tallest tower, the one that actually gates what capability ships, is entirely self-authored and self-policed. Meanwhile the body counting the damage, Stanford’s own incident tracker, says the gap between what AI can do and what anyone is holding it to is widening, not closing.
A board that points to a certificate, or a chart, and calls that governance is buying theatre. The enforceability test exists precisely to stop that purchase: not to dismiss the nine frameworks, every one of them is doing real work, but to be honest with a board about which of them is a wall and which is a poster of a wall.
X. The working checklist for boards
Five questions worth asking this quarter, in order of how much they will actually change your risk exposure.
- Name every AI system your organisation runs that is governed only by a framework in the voluntary or intergovernmental column. If nobody can name them without checking, that is the answer.
- For any multi-step or agentic system specifically, identify which of your governing frameworks was written for loops rather than for single prompts. Most of your stack was not.
- Ask which version of which frontier lab’s safety policy you are currently operating under, RSP, FSF, Preparedness Framework, and whether anyone tracks version changes the way you would track a vendor’s SLA.
- Assume at least one regime underneath your compliance programme gets rewritten again next quarter, because three of nine did this year alone. Test how much of your documentation survives that rewrite untouched.
- Stop asking which framework you are compliant with, and start asking which control objectives you actually satisfy, independent of whose name is on the document. That question is what TrustOS was built to answer, and it is the only one of the five that does not go stale the next time a regulator changes their mind.


Leave a comment