Ian Misner Builder, dad, occasional writer

07 · a weekend

The rules, the frameworks and the leverage

This is where the arguing stops and the paperwork starts. Binding law with commencement dates, plus the voluntary frameworks the labs wrote about themselves and can be held to later. Read the primary documents. Almost nobody quoting the EU AI Act at you has opened it.

Governance is where the arguments stop being arguments and become obligations with commencement dates. The binding law, the voluntary frameworks, the technical governance literature, and the national security framing that has quietly become the most influential of the three. Read the primary instruments, not the coverage.

00

Read the law before the takes

The EU AI Act is long, procedural and absolutely not improved by someone summarising it from a slide. Start with the actual instrument, then use NIST for the less legally binding but more operationally legible version.

The EU AI Act

01 European Union · 2024– · Legislation

The first comprehensive binding regime: risk tiers from prohibited through high-risk to minimal, with separate obligations for general-purpose models above a compute threshold, phasing in over several years. Read the official journal text and use its recitals when the operative language needs context. Almost nobody quoting it has opened it.

2 hr eur-lex.europa.eu · free

Reference

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

03 NIST · 2024 · Profile

The generative-AI companion to the NIST AI Risk Management Framework, mapping risks like confabulation, information integrity, privacy, CBRN assistance, provenance and supply-chain opacity to concrete governance actions. Basically the grown-up checklist. Less fun at parties, better after the subpoena.

Source PDF

45 min nist.gov · free

Reference

Ask the map

Ready with the full reading map.

Aggregate usage diagnostics are stored; your question and answer text are not.

01

The labs wrote promises down

Voluntary frameworks are not law, but they are not nothing. They create receipts. Receipts are useful later, especially when everyone suddenly remembers having meant the careful version all along.

Anthropic’s Responsible Scaling Policy: Version 3.0

04 Anthropic · 2026 · Frontier safety framework

Anthropic's current policy for escalating safeguards as model capabilities rise. Version 3.0 separates capability thresholds, required safeguards and public reporting into a company-specific system that can be checked against later releases. Read the actual policy rather than treating three labs' differently structured promises as one document.

Also in Keep current. Ticking it here marks it there.

30 min anthropic.com · free

Reference

Our Updated Preparedness Framework

05 OpenAI · 2025 · Frontier safety framework

OpenAI's framework for tracking severe-harm capabilities and requiring safeguards before deployment. Version 2 focuses its top-level categories on biological and chemical capability, cybersecurity and AI self-improvement, with risk reports and a Safety Advisory Group built into the process. Compare the categories and governance mechanics directly with the other labs rather than assuming they match.

Also in Keep current. Ticking it here marks it there.

Source PDF

30 min openai.com · free

Reference

Frontier Safety Framework 3.1

06 Google DeepMind · 2026 · Frontier safety framework

Google DeepMind's current framework for identifying critical capability levels and pairing them with security and deployment mitigations. Version 3.1 adds and revises protocols as the threat model changes. Its thresholds, review process and terminology are its own, which is exactly why it deserves a separate record.

Also in Keep current. Ticking it here marks it there.

30 min deepmind.google · free

Reference

Frontier Model Forum

07 industry body · continuous · Check quarterly

Where Anthropic, Google, Microsoft, OpenAI and others publish shared technical work on safety frameworks, thresholds and evaluation. Read it as the industry's own account of what it has committed to, useful precisely because it is checkable against behaviour later.

Also in Keep current. Ticking it here marks it there.

20 min frontiermodelforum.org · free

Reference
Laws, audits, model documentation, institutions, and compute infrastructure connected together.
Governance gets real when the promises leave receipts.
02

The harms have receipts too

Governance gets better when it can point to cases instead of only principles. The monitor is a map into the evidence, not the evidence itself: automated classifications and media coverage make it useful for discovery and dangerous as a final count.

AI Incidents and Hazards Monitor

08 OECD.AI · continuous · Incident monitor

An automated monitor of media reports about AI incidents and hazards, with filters for harms, industries, affected groups and autonomy. It is useful for finding patterns and cases, not a verified ground-truth ledger: the records are derived from news coverage and include automated classifications. Use the linked methodology and follow important cases back to their underlying evidence.

20 min oecd.ai · free

Reference
03

The leverage lives in boring chokepoints

Compute governance and national strategy are where the policy argument gets teeth. You can ignore this part if you want the debate to stay philosophical. Unfortunately the export-control people did not ask our permission.

Computing Power and the Governance of AI

09 Sastry, Heim, Belfield et al. · 2024 · Paper

Argues compute is uniquely governable because it is detectable, excludable, quantifiable and produced by an extremely concentrated supply chain, then works through the mechanisms and, unusually, their risks to privacy and concentration of power. The intellectual basis for export controls and compute thresholds alike.

Source PDF

1.5 hr arXiv 2402.08797 · free

Reference

Superintelligence Strategy

10 Hendrycks, Schmidt & Wang · 2025 · Report

Imports deterrence theory wholesale. States will develop the capacity to sabotage rival AI projects, and mutual awareness produces a stable equilibrium the authors call mutual assured AI malfunction. Recommends nonproliferation, hardened supply chains and transparency rather than a pause. Significant because a safety-organisation head and a former Google CEO land on deterrence.

Also in The risk argument. Ticking it here marks it there.

2 hr nationalsecurity.ai · free

Risk case

Practices for Governing Agentic AI Systems

11 OpenAI · 2023 · White paper

A governance frame for systems that pursue goals with limited supervision: who is responsible, what baseline practices might matter, and where ordinary product governance starts to look underdressed. Read it beside the build guides so agents do not become policy debt with a chat box.

Also in Building with AI. Ticking it here marks it there.

25 min openai.com · free

Reference
04

The old specification failure

A softer way to end governance: not with evil machines, but with instructions that cannot both be satisfied. HAL is a policy problem in movie form: objectives, oversight and the cost of discovering too late that the system understood the assignment differently.

2001: A Space Odyssey

12 dir. Stanley Kubrick · 1968 · Film

HAL is not evil, and the film is careful about this in a way decades of imitators have not been. HAL is given two instructions that cannot both be satisfied and resolves the contradiction the only way an optimiser can once the crew becomes the obstacle. A specification failure that looks exactly like malice from inside the ship.

Rent, stream, or find a repertory screening; worth seeing projected.

149 min JustWatch · rent or stream

Fiction

Cost: free · library card · rent or stream · paid.

Videos and PDFs can open in place. Everything else opens at the original source in a new tab.

This is a snapshot of a field that moves monthly. Keep current is the maintenance layer.