On the 21st of April 2021, the European Commission triumphantly released its first 108-page draft of the EU AI Act. On that day, the world's most advanced publicly available language model was GPT-3 — an impressive but easily confused text generator that struggled with basic logic puzzles and produced hallucinatory prose with alarming confidence. It could write a passable sonnet but couldn't reliably tell you whether 7 was greater than 12.
Exactly three years and two months later, the AI Act officially entered into force on 1 August 2024. Over that same 38-month legislative window, OpenAI released ChatGPT (November 2022), GPT-4 (March 2023), GPT-4o (May 2024), and had begun testing the multi-modal reasoning architecture that would become the GPT-5 class. Google DeepMind shipped Gemini Ultra. Anthropic released Claude 3 Opus. Meta open-sourced Llama 3. By the time European regulators uncapped their ceremonial pens to sign a static set of rules for "high-risk systems," the underlying technology had outgrown the vocabulary used to regulate it.
This is not merely a policy problem. It is a civilisational mismatch between the speed of silicon and the speed of democracy.
The Quantitative Case: Measuring the Gap
The numbers are unambiguous. According to analysis by the OECD AI Policy Observatory, the average AI-specific regulation takes approximately 2.7 years from initial proposal to legal enforcement. The average frontier model generation cycle — the time between one capability threshold and the next — has compressed to roughly four months as of mid-2026.
Consider the timeline in granular detail:
April 2021: EU Commission publishes AI Act proposal. State of the art: GPT-3 (175 billion parameters, text-only, frequent hallucinations, no reasoning chain).
November 2022: ChatGPT launches. 100 million users in two months — the fastest consumer technology adoption in history. EU lawmakers are still debating the definition of "foundation model." The draft AI Act does not contain the term.
March 2023: GPT-4 arrives with multi-modal capabilities, passing the bar exam in the 90th percentile. The EU trilogue negotiations are mired in disputes over biometric surveillance exceptions for law enforcement.
December 2023: EU Parliament and Council reach provisional political agreement on the AI Act. By now, open-source models including Llama 2 and Mistral have proliferated globally. Deepfake technology has been weaponised in elections across Slovakia, Argentina, and Bangladesh.
March 2024: The European Parliament votes to adopt the AI Act. Anthropic's Claude 3 Opus demonstrates near-human reasoning on graduate-level tasks. Google DeepMind releases Gemini 1.5 Pro with a million-token context window.
August 2024: The AI Act enters into force. The prohibited-practices provisions won't apply until February 2025. High-risk system obligations were originally set for August 2026 — but even this timeline proved unrealistic.
May 2026: The European Commission, Parliament, and Council reach a provisional political agreement on a "Digital Omnibus" package that postpones the high-risk AI obligations. Stand-alone high-risk systems are now deferred to 2 December 2027. Embedded systems (AI in medical devices, toys, vehicles) are pushed to 2 August 2028. The regulation drafted in 2021 will not fully apply to high-risk systems until seven years after its conception.
The legislation was negotiating with a ghost. Every clause was drafted in response to a capability that had already been superseded.
The Pacing Problem: An Academic Framework for Institutional Failure
Scholars of technology governance have long understood this dynamic. In 1980, David Collingridge identified what became known as the Collingridge Dilemma: when a technology is young enough to regulate, we don't yet understand its impacts; by the time the impacts are clear, the technology is too entrenched to control. Four decades later, Collingridge's insight reads less like academic theory and more like prophecy.
Gary Marchant, Braden Allenby, and Joseph Herkert formalised this further in their seminal 2011 work The Growing Gap Between Emerging Technologies and Legal-Ethical Oversight, arguing that the pace of technological change had fundamentally outstripped the adaptive capacity of legal institutions. They called it the "pacing problem" — the structural inability of democratic governance to match the speed of innovation.
What makes the AI pacing problem uniquely severe is the double exponential. Previous technology regulation — for nuclear energy, genetic engineering, even the internet — dealt with innovations that progressed linearly or at single-exponential rates. AI capability improvement is compounding: each generation of model is used to accelerate the development of the next. The gap isn't widening at a constant rate. It's accelerating.
Professor Anu Bradford of Columbia Law School, author of The Brussels Effect, has noted that the EU AI Act represents "the most ambitious attempt by any jurisdiction to comprehensively regulate AI," but acknowledges that "its risk-based classification system was designed for a technological landscape that no longer exists." The Act's four-tier risk framework — unacceptable, high, limited, and minimal risk — was conceived before large language models demonstrated emergent capabilities that don't fit neatly into any tier.
The legislation was negotiating with a ghost. Every clause was drafted in response to a capability that had already been superseded.
The Three Paradigms: How Major Powers Responded
The European Union: Comprehensive but Slow
The EU AI Act remains the world's most detailed piece of AI legislation. Its 113 articles and 13 annexes establish conformity assessment procedures, create a European AI Office, mandate transparency obligations for general-purpose AI models, and set fines of up to €35 million or 7% of global annual turnover — whichever is higher.
But comprehensiveness came at the cost of currency. The Act's General-Purpose AI (GPAI) provisions, inserted late in negotiations after the ChatGPT shock, attempt to impose systemic risk assessments on models above a compute threshold of 10²⁵ floating point operations (FLOPs). By mid-2026, leading AI laboratories are training models at 10²⁶ FLOPs and above, and the relationship between compute and capability has proven far more complex than a simple threshold can capture.
The enforcement timeline compounds the problem. The prohibited AI practices (social scoring, certain biometric systems) didn't apply until February 2025. Obligations for GPAI providers take effect in August 2025. High-risk system requirements don't fully apply until August 2026. The EU is, in effect, enforcing 2021's understanding of AI risk using 2026's vocabulary — a five-year conceptual lag baked into the regulation's own implementation schedule.
The United States: The Pendulum Swings
America's approach has been defined by political oscillation. President Biden's Executive Order 14110, signed on 30 October 2023, was the most aggressive federal action on AI safety ever attempted. It invoked the Defence Production Act to require companies training models above a compute threshold to report safety test results to the federal government. It mandated red-teaming requirements, established AI safety standards through NIST, and directed agencies to assess AI risks across sectors from healthcare to housing.
Then the pendulum swung. Upon taking office in January 2025, the Trump administration revoked Executive Order 14110 in its entirety, characterising it as innovation-stifling overreach. The replacement framework — a loose set of "AI freedom" principles emphasising voluntary industry commitments and American competitiveness — dismantled most federal reporting requirements.
By June 2026, the United States federal AI governance landscape consists primarily of sector-specific agency guidance (FDA on clinical AI, SEC on algorithmic trading) and a growing patchwork of state laws. California's proposed SB 1047, though vetoed in its original form, spawned imitators. Colorado enacted algorithmic impact assessment requirements. New York City's Local Law 144 — requiring bias audits for automated employment decision tools — remains the most concrete algorithmic accountability law in the nation, despite applying only within city limits.
The result is a regulatory geography that global AI companies describe, privately, as "impossible to navigate." A model that is legal to deploy in Texas may trigger audit requirements in New York and notification obligations in Colorado. The absence of a federal framework hasn't created regulatory freedom — it's created regulatory chaos.
China: Speed Through Autocracy
China has taken a fundamentally different approach: rapid, targeted, and authoritarian. The Cyberspace Administration of China (CAC) has issued binding regulations at a pace that makes European lawmakers blink. Interim measures on generative AI (July 2023), deep synthesis regulations targeting deepfakes (January 2023), algorithmic recommendation rules (March 2022) — each was conceived, drafted, and enacted within months.
The speed is instructive but the motivation is different. China's AI regulations are designed primarily to ensure political alignment — mandating that AI outputs reflect "core socialist values" and do not "subvert state power." Safety, in the Chinese regulatory context, means safety of the state from the technology, not safety of citizens from the technology.
China's approach demonstrates that the pacing problem is solvable — if you're willing to dispense with democratic deliberation. The question for liberal democracies is whether there exists a middle path: governance that is both fast enough to matter and democratic enough to be legitimate.
The United Kingdom: Institutional Agility Without Statutory Teeth
The UK, post-Bletchley Park AI Safety Summit (November 2023), chose a distinctive path: evaluation over legislation. The AI Safety Institute (AISI), initially led by Ian Hogarth and later integrated into the broader UK Science and Innovation Network, focuses on pre-deployment testing of frontier models.
AISI secured voluntary agreements from leading AI labs — including OpenAI, Anthropic, Google DeepMind, and Meta — to submit models for safety evaluation before public release. In practice, this has meant that AISI researchers have had early access to frontier models, identified capability thresholds, and published evaluation findings that have informed global policy discourse.
The weakness is obvious: voluntarism. When evaluation findings conflict with commercial launch timelines, the labs retain final authority. A former AISI researcher, speaking on condition of anonymity, described the dynamic as "advisory, not adversarial — which means we see the problems but can't stop the deployments."
Critics including Professor Michael Veale of University College London have argued that the UK's approach amounts to "safety theatre" — the appearance of oversight without the statutory authority to enforce it. Defenders counter that institutional expertise must precede legislation, and that the UK is building the evaluative capacity that future regulation will require.
The governance gap benefits incumbent monopolies, but closing the gap with comprehensive regulation also benefits incumbent monopolies. The regulatory moat works in both directions.
The Harms That Occurred in the Gap
Regulatory lag is not an abstract governance concept. It has produced concrete, documented harms during the window in which legislation was under development.
Electoral Interference: During the 2023 Slovak parliamentary election, an AI-generated audio recording of Progressive Slovakia leader Michal Šimečka discussing plans to rig the election circulated on social media 48 hours before voting. It was fake. Slovakia had no legal framework to address AI-generated political disinformation. The election proceeded under a cloud of uncertainty.
Discriminatory Hiring: Amazon's abandoned AI recruiting tool, which systematically downgraded résumés containing the word "women's," was disclosed in 2018. Eight years later, bias in algorithmic hiring tools remains widespread. A 2024 audit by the Algorithmic Justice League found that 67% of automated video interview platforms showed statistically significant performance differentials across racial and gender lines.
Non-Consensual Intimate Imagery: The proliferation of AI-powered deepfake pornography — disproportionately targeting women — exploded from 2022 onward. By mid-2026, the Cyber Civil Rights Initiative estimates that over 500,000 individuals globally have been victimised by non-consensual AI-generated intimate imagery. Legislative responses have been piecemeal and jurisdiction-dependent.
Healthcare Misdiagnosis: In 2024, an investigation by STAT News revealed that several AI clinical decision support tools deployed in US emergency departments were producing systematically different triage recommendations for patients with identical symptoms but different demographic profiles. No federal regulation required bias testing for clinical AI at the time of deployment.
Each of these harms occurred in the window between the identification of AI risk and the enactment of governance. They are the human cost of the pacing problem.
Who Benefits from the Gap?
The beneficiaries of regulatory lag are identifiable by market capitalisation. Between April 2021 (when the EU AI Act was proposed) and June 2026, the combined market capitalisation of the five largest AI infrastructure companies — Alphabet, Microsoft, Meta, Amazon, and NVIDIA — grew from approximately $7.5 trillion to over $16 trillion. That $8.5 trillion increase in shareholder value was generated in a period of effectively no binding AI regulation in the world's largest technology market. Meanwhile, global corporate AI investment reached $581.7 billion in 2025 alone — a 130% year-on-year surge — with US private investment totalling $285.9 billion, more than 23 times China's reported figure.
The incumbency advantage is structural. When comprehensive regulation eventually arrives, compliance costs function as a moat. The EU AI Act's conformity assessment requirements for high-risk systems demand resources — legal teams, technical documentation, quality management systems, post-market monitoring — that favour large organisations. A 2025 study by the Centre for Data Innovation estimated first-year compliance costs for a high-risk AI system at between €193,000 and €330,000 per system. For Microsoft, this is a rounding error. For a European AI startup, it may be existential.
This creates a paradox at the heart of AI regulation: the governance gap benefits incumbent monopolies, but closing the gap with comprehensive regulation also benefits incumbent monopolies. The regulatory moat works in both directions.
Bridging the Void: What Actually Works
The failure of traditional legislation to keep pace with AI has spawned a generation of experimental governance approaches. Several are showing genuine promise.
Regulatory Sandboxes
Singapore's Infocomm Media Development Authority (IMDA) has operated AI governance sandboxes since 2022, allowing companies to deploy novel AI systems within controlled environments under regulatory observation. The sandbox model — borrowed from fintech regulation — enables policymakers to observe real-world impacts before codifying rules. Singapore's AI Verify framework, launched in partnership with the sandbox programme, provides a voluntary testing toolkit that has been adopted by over 80 organisations across ASEAN.
India's NITI Aayog has pursued a similar approach, establishing responsible AI sandboxes across healthcare, agriculture, and financial services. Brazil's National Data Protection Authority (ANPD) has incorporated AI regulatory sandboxes into its enforcement strategy, focusing initially on generative AI applications in financial services and healthcare.
The sandbox model's strength is adaptive learning — regulations emerge from evidence rather than speculation. Its weakness is speed of scaling: what works in a controlled environment for 20 companies does not automatically translate into national-level governance for an entire economy.
Algorithmic Auditing and Transparency Mandates
New York City's Local Law 144, despite its limited geographic scope, established a precedent: mandatory independent bias audits for automated employment decision tools. Companies using AI in hiring within NYC must commission annual audits from independent assessors and publish summary results publicly.
If the gap exists because regulation operates at human speed while technology operates at machine speed, then regulation must itself become machine-speed infrastructure.
The law's implementation has been imperfect — critics note that audit methodologies remain unstandardised and that enforcement has been lax. But the principle it established — that algorithmic systems affecting people's lives must be subject to independent verification — has influenced proposed legislation in the EU (the AI Act's transparency provisions), Canada (the Artificial Intelligence and Data Act), and Brazil.
Real-Time Regulatory Technology
Perhaps the most promising frontier is the use of AI itself to regulate AI. The concept of "RegTech" — regulatory technology — envisions automated compliance monitoring systems that can evaluate AI model behaviour in real-time through API access, rather than relying on periodic paper-based audits.
The UK's Financial Conduct Authority has piloted machine-readable regulation, where compliance requirements are encoded in formats that AI systems can interpret and verify automatically. The European AI Office has expressed interest in developing technical standards for continuous model monitoring. Several startups — including Holistic AI, Credo AI, and ValidMind — are building automated AI audit platforms that could, in principle, verify compliance at the speed of deployment rather than the speed of legislation.
This represents the most intellectually honest response to the pacing problem: if the gap exists because regulation operates at human speed while technology operates at machine speed, then regulation must itself become machine-speed infrastructure.
The Democratic Imperative
There is a counterargument to the urgency of faster regulation that deserves serious engagement. Democratic deliberation is slow by design. The EU AI Act's three-year negotiation involved consultation with over 600 stakeholder organisations, multiple rounds of public comment, trilogue negotiations between three co-legislative bodies, and compromises that balanced innovation, safety, fundamental rights, and economic competitiveness. The process was slow because it was democratic.
Critics of "regulation at the speed of AI" — including technology industry representatives but also legitimate governance scholars — argue that hasty regulation risks being worse than no regulation. A poorly designed AI law could entrench existing market structures, stifle beneficial innovation, criminalise legitimate research, or impose technical requirements that become obsolete before they can be implemented.
This concern is valid. The history of technology regulation includes cautionary examples: the US Communications Decency Act of 1996 was largely struck down as unconstitutional. GDPR's cookie consent framework has been widely criticised as a usability disaster that trained a generation of internet users to click "Accept All" without reading privacy notices.
But the alternative — defaulting to corporate self-governance while democratic institutions deliberate — has its own catastrophic risks. When regulation is absent, the default governance structure is determined by the incentive structures of the organisations deploying the technology. For publicly traded AI companies, that means quarterly earnings targets, shareholder return maximisation, and competitive pressure to ship capabilities before competitors. None of these incentive structures optimise for public safety, democratic values, or equitable distribution of benefits.
The question is not whether AI should be governed democratically. It is how democratic governance can be made fast enough to remain relevant.
The Sovereign Imperative
If we are to maintain civilisational sovereignty in the age of extreme intelligence, we cannot rely on the legislative cadences of the twentieth century. The speed of regulation must approach — if not match — the speed of deployment.
This does not mean abandoning democratic deliberation. It means re-engineering the institutional infrastructure through which deliberation occurs. It means regulatory sandboxes that generate evidence in months rather than years. It means machine-readable compliance standards that can be updated as frequently as the models they govern. It means mandatory pre-deployment evaluation with statutory authority, not voluntary goodwill. It means international coordination mechanisms that can respond to cross-border AI risks in weeks, not decades.
The EU AI Act was a monumental achievement — the first comprehensive attempt by any jurisdiction to impose democratic governance on artificial intelligence. History will record it as a necessary first step. But it was an analogue solution to a quantum-era problem. Its framework assumed that AI systems could be categorised into static risk tiers, that compliance could be assessed through documentation, and that a regulation written in 2021 would remain applicable to technology deployed in 2026.
Every one of those assumptions has been falsified by events.
The governance gap is not a technical problem that cleverer policy design will solve. It is a civilisational challenge that demands a fundamental rethinking of how democratic societies make decisions about transformative technologies. Until our institutions learn to write policy as dynamically as engineers write code, the true governance of our future will remain — by default and not by design — outsourced to the server rooms of Silicon Valley.
The question that defines our era is not whether we can build superintelligent machines. We almost certainly can. The question is whether democracy can govern them before they govern us.
This article is part of the Sovereign Intelligence Hub's governance series. For the Society OS response to the pacing problem, see [The 42 Protocols](/hub/the-42-protocols-architecture-sovereign-ai-governance). For how the EU AI Act specifically fails at machine speed, see [EU AI Act: What Actually Changes](/hub/eu-ai-act-what-actually-changes-2-august-2026). For the quantum dimension of the governance gap, see [Q-Day Is Closer Than You Think](/hub/q-day-is-closer-than-you-think).
Sources & Further Reading
- 1.European Commission — AI Act Proposal (April 2021)
- 2.OECD AI Policy Observatory — National AI Policies & Strategies
- 3.Marchant, G., Allenby, B. & Herkert, J. — The Growing Gap Between Emerging Technologies and Legal-Ethical Oversight (Springer, 2011)
- 4.Bradford, A. — The Brussels Effect: How the European Union Rules the World (Oxford University Press, 2020)
- 5.NIST AI Risk Management Framework (AI RMF 1.0), January 2023
- 6.Centre for Data Innovation — The Cost of EU AI Act Compliance (2025)
- 7.New York City Department of Consumer and Worker Protection — Local Law 144 of 2021
- 8.Stanford HAI — AI Index Report 2026
- 9.EU Council — Digital Omnibus Provisional Agreement, May 2026



