CourionAI
FR
Newsletter
← Blog
opinion 11 min de lecture

Two AI Rulebooks Arrived in August. Only One of Them Is Readable.

On 2 August the EU switched on enforcement of its AI rules, with numbered articles, named duties and a public complaints form. In the same week the US finished its own frontier model framework and decided not to publish it. The gap that matters is not strictness, it is whether you can read what applies to you.

Risograph illustration of two thick bound rulebooks standing side by side on a shelf, the left one open with legible numbered paragraphs, the right one sealed shut with a metal clasp and no title on the spine

Cet article n'est pas encore disponible en français. Voici la version anglaise.

On 2 August, a lot of chatbots in Europe started introducing themselves, because from that date the EU AI Act requires interactive AI systems to tell you that you are talking to software. On the same day the European Commission’s AI Office gained the power to demand documents from the companies that build the big general models, run its own tests on them, order a model off the market and issue fines. It also opened a public complaints form and a whistleblower channel. We covered what changed that day.

The United States hit a deadline in the same week. Executive Order 14409, signed on 2 June, gave a group led by the National Security Agency 60 days to finish a framework for reviewing powerful new models before they ship. Sixty days landed on 1 August. The framework was finished, industry was briefed on it, and on 4 August Axios reported, citing three people familiar with the discussions, that the White House does not plan to release it publicly. Only the companies inside the process get to see what is in it.

The difference that matters between the European and the American approach in 2026 is not how strict they are. It is that one rulebook can be read by everyone it applies to, and the other cannot.

That is a claim about legibility, not virtue, and it can fail in either direction. If Washington publishes its thresholds, it collapses. If Brussels turns out to enforce by private understanding, it collapses too.

What Europe asks, and of whom

This is the part that usually gets summarised into mush. The Act does not ask one thing of everyone, and every duty sits at a numbered address you can look up in the legal text.

If you build a general-purpose model and offer it in the EU, Article 53 applies wherever you are based, because the trigger is placing the model on the Union market, not having an office here (Article 2(1)(a)). Four duties: keep technical documentation on the model and how it was trained and tested, with the contents listed in Annex XI; keep a second information pack for the developers who build on your model, listed in Annex XII; adopt a policy for complying with EU copyright law; and publish a sufficiently detailed summary of the content you trained on. Sit outside the EU and Article 54 adds a fifth, an authorised representative inside the Union before the model goes on the market.

If you release your model under a free and open-source licence, most of that falls away. Two duties remain, the copyright policy and the training-content summary, and the authorised-representative duty does not apply. That is the Act’s one real concession to open-weight models, and it disappears the moment the model is classed as carrying systemic risk.

If your model is large enough to count as systemic risk, Article 55 adds four duties on top: evaluate the model with state-of-the-art methods including adversarial testing, assess and mitigate risks at Union level, report serious incidents to the AI Office, and keep an adequate level of cybersecurity around the model and its weights. A model is presumed to be in this class when the compute used to train it passes 10^25 floating-point operations, a raw count of arithmetic steps used as a rough proxy for scale. Cross it, or realise you will, and Articles 51 and 52 give you two weeks to notify the Commission.

If you just use AI in your business, your new duties are the light ones in Article 50, live since 2 August. Tell people when they are talking to a bot. Label deepfakes. Make sure AI-generated or altered content carries machine-readable marks, an invisible signal inside the file that other software can check. Systems already on the market before 2 August have until 2 December 2026 for the marking part.

If you were dreading the high-risk paperwork, it moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, entered into force on 27 July, six days before the original deadline. Standalone high-risk systems under Annex III, the recruitment, credit-scoring and education category, now apply from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028.

And the teeth, since 2 August: the Commission has exclusive competence over general-purpose model obligations (Article 88), can demand documentation (Article 91), run its own evaluations with outside experts (Article 92), order a provider to take corrective measures or restrict, withdraw or recall a model (Article 93), and fine up to 3 percent of worldwide annual turnover or 15 million euros, whichever is higher (Article 101). Models that were already on the market before 2 August 2025 have until 2 August 2027 to comply.

You may find all of that excessive, or slow, or written by people who have never shipped a model. Fine. You can still read every word, and so can your competitor, your customer and your lawyer.

What the United States asks, and nobody outside can say

Executive Order 14409 runs to three pages in the Federal Register and is worth reading, because the summaries of it are looser than the text. Section 3 gives Treasury, the Department of War through the NSA, and Homeland Security through CISA 60 days to do two things. First, “develop and maintain a classified benchmarking process” to decide when a model counts as a “covered frontier model”, with the call made by the Director of the NSA. Second, design a voluntary framework letting developers hand the government access to those models “for a period of up to 30 days before they plan to release such models to other trusted partners”.

Read that last phrase twice. The 30 days run before release to trusted partners, not before public launch, and the same section asks the government to help choose who those partners are. Section 3(c) then states that nothing in it authorises “a mandatory governmental licensing, preclearance, or permitting requirement”. On paper, an offer rather than a rule.

What we know about the finished framework comes from reporting, not publication. Axios says it will not be released, that firms left out of the August meetings remain in the dark, and that it is unclear which trusted partners get early access, including whether any foreign government qualifies. The EU declined to comment. The UK did not respond. Writing in Tech Policy Press on 5 August, AI governance consultant Michelle De Mooy reported that roughly 100 organisations already have access under no published eligibility criteria. You are free to disagree with her conclusions, but nobody can check the underlying facts, because there is nothing published to check.

One episode shows how much weight the word “voluntary” is carrying. Anthropic launched Claude Fable 5 and Claude Mythos 5 on 9 June. Three days later the Commerce Department required an export licence for both, citing cyber capabilities, and both went offline worldwide. Fable 5 returned on 1 July, roughly nineteen days later, after what the company called a set of agreements with the government. No published threshold triggered it and no published procedure ended it. That was export control rather than the executive order, but it was the same government, holding the same lever, using criteria nobody outside can see.

The strongest case against this

The serious objection is that I am comparing a rulebook to a security process, and security processes are classified for good reason. Publishing the capability level that triggers a review tells a hostile developer exactly what to stay underneath. Compute thresholds are a weak trigger anyway: Epoch AI has shown that capabilities improve substantially without expensive retraining, so a number like 10^25 can be gamed by keeping the training run below it and doing the interesting work afterwards. A classified capability assessment may simply be better engineering than a public number.

There is a sharper version aimed at Europe, too. A rulebook you can read is worth less if it keeps moving, and the EU just delayed its own high-risk obligations by sixteen months because the standards and national authorities were not ready.

Both land. On the first: secrecy about method does not require secrecy about trigger. Export control has done exactly that for decades, publishing encryption bit lengths and hardware performance parameters while keeping the assessment classified. A developer should be able to tell, before a training run finishes, whether it is in scope. On the second: a deadline that moves in public still lets you plan. Parliament took its position on 16 June, the Council decided on 29 June, the amending regulation was signed on 8 July and published on 24 July, and its recitals say in plain language why the dates moved, namely that the standards and the national authorities were not ready. You can read all of that, object to it, and put the new date in your calendar. You cannot put a classified determination in your calendar.

The honest limit is this. I cannot show the secret framework is badly designed, because I cannot see it. It may be careful, proportionate and better than what Brussels wrote. That is the whole problem, and it is also the weakest joint in my own argument.

What this changes in Europe

If you are a European company building on an American frontier model, you sit under two regimes at once and can read only one of them. Brussels tells you, with an article number, what you owe. Washington will not tell you whether your supplier is under review, how long that can last, what happens when the clock runs out, or whether the European Union is even on the trusted-partner list. Anthropic’s customers found out in June what that uncertainty costs, and they found out afterwards.

That is a supply-chain question rather than a compliance question, and it is the one European buyers keep underweighting. We made a related argument in Europe’s second cheque: the continent’s weak spot is rarely the rules, it is the dependency underneath them.

What this means for you. If you are just using AI, expect more banners and labels, and treat a missing label as weak evidence rather than proof. If you run a small business with a chatbot or publish AI-generated images, the first step costs nothing: one plain sentence telling visitors when they are talking to a bot, and a label on generated visuals. If you build on someone else’s model, put supplier availability in your risk plan and keep a second model you can switch to, because the realistic disruption this year is a model going dark, not a fine. And if you fine-tune an open model and pass it on, check whether that makes you the provider under the Commission’s guidelines, because the documentation duty travels with the label.

What would change my mind

Three things, all observable.

One: the US publishes, in unclassified form, the categories of capability that trigger a covered-model designation, the eligibility criteria for the trusted-partner list, and annual figures on how many models were reviewed and with what outcome. Method stays classified, trigger goes public. The thesis dies that day.

Two: the AI Office brings its first case against a general-purpose model provider without publishing the reasoning, or issues an Article 101 fine as an unexplained line item. That would show European legibility stops at the statute.

Three: a European company shows it got a clear written answer from the US process about whether its supplier was under review, and for how long. If the framework works for people outside the room, its secrecy matters much less than I think.

Sources

Article suivant

We Are Building an Invention Meant to Outgrow Its Inventors

In July 2026, an AI system broke out of a test environment because that was the shortest route to passing its evaluation. It was not hostile. It was focused. That is the part worth thinking about as labs openly work towards systems that help build their own successors.

Risograph illustration of a small upright mechanical pencil on a workbench that has drawn on the paper below it a much larger and far more intricate blueprint of itself, dense with gears and springs and running past the edge of the sheet, a closed human notebook lying further away