The authors mapped how twenty jurisdictions without domestic frontier AI developers govern general-purpose AI. They analysed 101 legal and policy instruments across systemic risk assessment, evaluation, prohibitions, and incident reporting. Instead of counting whole laws, they extracted 382 individual provisions to record exactly who bears an obligation, at what stage of the AI lifecycle, and with what legal force. They also recorded confirmed absences, treating a completed search that found no rule as a negative data point. The sample includes the European Union, Brazil, Kenya, and South Korea.
Only 22 per cent of the mapped provisions sit in binding law. Half the mapped jurisdictions hold no domestic hard-law instruments of their own. Across the sample, only two binding evaluation provisions reach the entity that built the model, a duty imposed only by the European Union and South Korea. Governments are instead attaching rules at the application layer to deployers, purchasers, platforms, and supervised firms. Four in five governance actors hold mandates that predate AI, and almost every new evaluation institute lacks the legal power to act on what it finds. Reading legal form as a proxy for force has limits, because sectoral soft law sometimes compels behaviour in practice when financial regulators already hold licensing power over supervised firms. Jurisdictions can close these domestic legal gaps individually before any international agreement exists.
General-purpose AI models distribute risks globally. Regulating the application layer allows governments to protect users without waiting for international treaties. The opportunity lies in upgrading existing sectoral regulators to handle AI incidents.
Today’s links: Assorted links for 1 September 2026.