Four claims about who ends up deciding

This series opened by asking what a rule can actually get hold of when the system it regulates changes weekly — and found five attachment points in circulation (the model, the role, the use case, the compute spent, the service as served), each administrable in a different degree and each failing in a different direction. It closed on a narrower, sharper problem: a served system can be altered after assessment with no external mark that anything changed, and every review cycle in force is slower than the systems it names. That piece stopped in the present, with four dated predictions running to August 2029 about whether compute thresholds would be supplemented rather than abandoned, whether enforcement would shift from pre-market paperwork to post-market monitoring, whether version identity would become a regulated object in its own right, and whether third-party AI audit would still lack a licensure regime at scale.

This article picks up where that one stopped counting and asks a different kind of question: not what a single rule can bind this year, but what the whole apparatus around AI — statutes, standards bodies, export controls, liability regimes, international coordination mechanisms — plausibly looks like by 2035. That is not one forecast. It depends on at least four things that do not have to move together: whether the major jurisdictions’ technical requirements converge or keep diverging, whether third-party verification infrastructure matures into something credible, and whether institutional capacity to write and enforce rules keeps pace with the systems it is trying to govern at all. This article names four scenarios built from those axes, gives each a horizon, states what it assumes, names indicators a reader could check without waiting for 2035, and states in advance what would prove it wrong.

Five kinds of statement are kept separate throughout, exactly as elsewhere in this series. A fact is something disclosed in a statute, an executive order, a court filing, or an institution’s own documentation. A vendor or government claim is a body’s statement about its own action, reported as a claim because the body has a stake in the answer. Analysis works out a consequence of stated facts. A scenario is one internally consistent way the future could go, presented beside its alternatives rather than as the likely one. A prediction commits to a horizon, states its assumptions, names an observable indicator, and states in advance what would disconfirm it. None of the four scenarios below is this article’s forecast, and they are not mutually exclusive by construction: a plausible 2035 has real convergence in the scientific evaluation layer at the same moment it has real fragmentation in export control, because those are different fights being fought by different institutions for different reasons.

ADVERTISEMENT

The documented present, mid-2026

The evidence base for the next decade is unusually well populated for a policy area barely three years into binding law, and four kinds of source — statutes and executive actions, standards-body and UN documentation, litigation and legislative tracking, and peer-reviewed policy analysis — converge on a picture that is neither steadily converging nor steadily fragmenting. It is doing both, in different places, at the same time.

Start with the framework this series has treated as the furthest along. The EU AI Act’s general-purpose model obligations became applicable in August 2025, and the Commission’s full enforcement powers over those obligations — fines up to 3% of global annual turnover or fifteen million euro, whichever is higher — activate on 2 August 2026 [7]. The accompanying Code of Practice, published by the AI Office on 10 July 2025, remains voluntary; its signatories formed a Signatory Taskforce, chaired by the AI Office, that convenes at least yearly to coordinate a common application of the code [7]. But the Act’s own compliance calendar for high-risk systems has already moved once, and moved late. The Commission’s Digital Omnibus, proposed 19 November 2025, reached provisional political agreement on 6 May 2026 and entered into force on 27 July 2026, deferring the standalone high-risk (Annex III) compliance deadline from 2 August 2026 to 2 December 2027, and the deadline for AI embedded in already-regulated products (Annex I) to 2 August 2028 — alongside a narrowed definition of which embedded systems count as high-risk at all and new exemptions for small mid-cap firms [4]. The framework most often cited as the model other jurisdictions might converge toward deferred its own flagship deadline before that deadline ever took effect.

Article 43’s default conformity route remains internal control — self-assessment against harmonised standards — with third-party notified-body assessment triggered chiefly where standards do not yet exist or have not been fully applied [5], and Article 51’s presumption of systemic risk still rests on a cumulative training-compute figure of 102510^{25} floating-point operations, a number the Commission can revise by delegated act as the technology moves [6]. Both are the same load-bearing design choices this series examined in its opening piece; nothing about the Omnibus changes their shape, only their start date.

The United States shows the same pattern of motion without a settled direction, but at the level of which government gets to decide at all. On 11 December 2025, the President signed Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence,” directing the Attorney General to stand up an AI Litigation Task Force within the Department of Justice to challenge state AI laws on grounds of interstate-commerce burden, federal preemption, or other unlawfulness, and instructing agencies to work toward a single, “minimally burdensome” federal framework — while expressly declining to preempt state laws on child safety, AI compute and data-center infrastructure, and state government procurement [1]. That order is itself the third reversal of US federal AI policy inside three years, after one executive order requiring frontier-model reporting and a second revoking it — a whiplash distinct from any question of technical pacing. Meanwhile the vacuum the federal government left kept filling from below: state legislatures had enacted 109 AI-specific laws by 1 July 2026, though that figure is itself a small decline from the 121 enacted by the same date in 2025 — the first year-over-year slowdown a tracking count of this kind has recorded [2]. Colorado supplies the clearest single case of a state changing its mind: its 2024 risk-tiered statute, built on a developer–deployer split closer to the EU’s structure, was repealed and reenacted on 14 May 2026 as SB26-189, recasting the regime around a disclosure-and-rights framework for automated decision-making technology, with primary implementation from 1 January 2027 [3].

Liability law shows a third pattern again: not convergence, not fragmentation, but abandonment. The European Commission formally withdrew its proposed AI Liability Directive, with a withdrawal notice published in the Official Journal on 6 October 2025, citing the lack of a foreseeable agreement among the EU’s own institutions and committing to no specific replacement or timeline [9]. What fills the gap instead is broader and less AI-specific: the revised Product Liability Directive, adopted 23 October 2024, extends strict, no-fault product liability to software and AI systems as such, applying to products placed on the market after 9 December 2026 [8]. A dedicated AI liability instrument failed to survive the EU’s own legislative process; a general-purpose one absorbed part of its territory instead.

ADVERTISEMENT

Compute governance, meanwhile, is being run almost entirely as trade and security policy rather than as a shared technical problem. The Bureau of Industry and Security’s rule effective 15 January 2026 replaced a presumption of denial with case-by-case review for advanced AI chips — the H200/MI325X performance class — destined for China and Macau, conditioned on domestic-supply certification, third-party testing, a fifty percent cap on the exporting firm’s US market allocation going to that review pathway, and know-your-customer and remote-access safeguards [10]. That is compute treated as a controllable, allocable physical good crossing a border, not a governable property of a training run. The research proposing hardware-level alternatives — chips that could cryptographically verify their own location or report compute usage to a governing authority — remains, in the words of the researchers themselves, a set of open feasibility questions rather than a deployed capability [11].

Set against all of that friction, the coordination layer above individual statutes has grown busier, not quieter. The UN General Assembly’s Resolution A/RES/79/325, adopted 26 August 2025, established both an Independent International Scientific Panel on AI — forty members, a term running February 2026 to February 2029, tasked with annual evidence-based assessments — and a Global Dialogue on AI Governance, whose first session convened in Geneva on 6–7 July 2026 [14]. The International AI Safety Report 2026, chaired by Yoshua Bengio and mandated by the nations at the Bletchley AI Safety Summit, published 6 February 2026 with an Expert Advisory Panel nominated by twenty-nine countries plus the UN, OECD, and EU, and more than a hundred contributing experts [17]. At the India-AI Impact Summit in New Delhi that same February, UN organizers explicitly framed the Global Dialogue’s purpose as becoming “a convergence point for existing global and regional AI governance efforts… interoperability of approaches,” rather than a competing forum [15]. The OECD’s Hiroshima AI Process Reporting Framework, launched at the G7’s request in February 2025 with early commitments from Amazon, Anthropic, Google, Microsoft, and OpenAI to report against a shared schema, was built to interoperate with other jurisdictions’ risk-management systems rather than replace them [13]. And on the technical-evaluation layer specifically, NIST’s Center for AI Standards and Innovation had, by 5 May 2026, expanded pre-deployment testing agreements to five major labs — OpenAI, Anthropic, Google DeepMind, Microsoft, and xAI — completed more than forty evaluations, and conducted joint assessments with the UK’s AI Security Institute, a functioning bilateral evaluation capacity that exists without being written into any statute at all [16].

Even China, the jurisdiction most often placed at the opposite pole from the EU’s binding, risk-tiered model, shows an unexpected structural echo. Its own amended Cybersecurity Law, approved 28 October 2025 and effective 1 January 2026, folds AI oversight into existing cyber law through a new Article 20 rather than a freestanding statute, directing state support for foundational research, algorithms, infrastructure, ethical norms, and risk monitoring [18]. But a separate, still-pending proposal for a comprehensive Chinese AI Law, put before the National People’s Congress in June 2025, recommends categorizing AI applications into prohibited practices, high-risk systems, transparency-risk systems, and low-risk systems — a four-tier taxonomy that maps remarkably closely onto the EU Act’s own structure, arrived at, as far as the public record shows, independently rather than through negotiation [19].

Four scenarios, not one forecast

That evidence supports more than one storyline continuing at once, which is exactly why a single forecast is the wrong shape for this question. What follows are four scenarios, each a claim about which regime plausibly defines how AI is actually governed by the early 2030s. Two of them are, in effect, direct tests of predictions this series already made about the audit gap: Enforcement Maturity asks whether that gap closes; Governance Obsolescence asks whether it becomes permanent.

Scenario one: Regulatory Convergence

The claim. By 2035, the EU, US, and China have not merged their AI laws into one instrument, but have converged enough at the technical layer — shared risk taxonomies, portable documentation formats, at least one working mutual-recognition or equivalence arrangement — that a provider building to one major framework’s technical file needs incremental adaptation, not a full rebuild, to satisfy the others.

Why this is plausible rather than wishful. The clearest evidence is that convergence is already happening in places nobody had to negotiate it. China’s own pending AI Law proposal recommends a four-tier risk taxonomy — prohibited, high-risk, transparency-risk, low-risk — that echoes the EU Act’s structure without any public sign of coordination between the two processes [19]; independent arrival at a similar answer is different evidence than a negotiated one, and arguably sturdier, because it does not depend on either side conceding anything. On the coordination side, the UN’s own framing of the Global Dialogue is explicitly convergence-oriented — a “convergence point for existing global and regional AI governance efforts… interoperability of approaches,” in the organizers’ own words [15] — and the OECD’s Hiroshima Process Reporting Framework was purpose-built to let a single company’s disclosure satisfy more than one jurisdiction’s expectations at once, with major labs already reporting against it [13]. On the technical-evaluation layer, NIST’s CAISI and the UK’s AI Security Institute are already running joint assessments of the same frontier systems without any treaty requiring them to [16] — bilateral convergence in practice, ahead of any formal instrument. And the International AI Safety Report gives thirty-plus countries a shared, re-usable scientific baseline about what these systems can actually do, which is a precondition for any two regulators agreeing on what “high-impact capability” even means [17].

ADVERTISEMENT
A crosswalk pinboard in the mutual-recognition office with rows of jurisdiction clause cards linked by cord, one final length caught mid-span short of its pin
Figure 1. Regulatory Convergence: enough of these links pinned that a technical file built for one jurisdiction needs only adjustment, not a rebuild, to satisfy another.

Assumptions. This scenario assumes that terms like “systemic risk,” “high-impact,” and “high-risk” keep meaning something close enough across jurisdictions that a finding under one framework is informative under another — an assumption this series’ opening piece already complicated by showing how unstable a single jurisdiction’s own compute-threshold proxy is under algorithmic-efficiency drift. It also assumes continued diplomatic bandwidth for coordination even where compute and export policy remain openly adversarial, and that voluntary instruments like the Code of Practice and the Hiroshima framework eventually acquire either binding force or wide enough voluntary uptake that they function as a de facto shared standard regardless.

Indicators. A first formal mutual-recognition or substantial-equivalence arrangement between the conformity-assessment regimes of any two of the EU, US, and China; a regulator anywhere formally accepting a certification built to another jurisdiction’s standard, or to a shared standard like ISO/IEC 42001, as partial or complete evidence of its own compliance requirement; the Global Dialogue on AI Governance producing a substantive joint output beyond the Scientific Panel’s own reports by its second or third session; continued growth in the number of jurisdictions whose statutory risk tiers are traceably modeled on a shared taxonomy, whether coordinated or independently arrived at.

Horizon and disconfirmation. Horizon: end of 2032. Disconfirmed if no formal equivalence or mutual-recognition instrument exists between any two of the three major blocs by then, or if the Global Dialogue’s first three sessions produce no output beyond restating the Scientific Panel’s annual findings.

Scenario two: Fragmented Blocs

The claim. By 2035, the EU, US, and China’s approaches have diverged further rather than converged, and providers serving all three markets maintain functionally separate technical files, model variants, and — for compute-adjacent hardware specifically — separate physical product configurations, extending the export-control bifurcation already visible today into a general feature of the market.

Why this is plausible against the same evidence. Executive Order 14365 treats EU-style binding, risk-tiered obligations as exactly the kind of “undue burden” the US government should litigate against domestically, not converge toward internationally [1]. Fragmentation is visible even before crossing a border: Colorado rewrote its own statute from something closer to the EU’s model to something structurally different within two years [3], and the wider count of state AI laws — 109 by mid-2026, still more than double what existed two years earlier even after the recent slowdown — shows that a single country has not settled on one template, let alone three countries settling on a shared one [2]. The compute layer shows literal physical bifurcation rather than a shared standard: BIS’s case-by-case licensing regime for advanced chips to China and Macau bakes a hard fifty-percent US-market allocation cap directly into the export-approval conditions, which is market segmentation by design [10]. The academic literature does not resolve cleanly toward convergence either: Cihon, Maas, and Kemp’s comparative analysis of environmental, trade, and security governance regimes weighs centralization’s efficiency gains against the risk of a slow, brittle institution, and concludes that fragmented, self-organizing governance is a live, defensible near-term outcome, not merely a failure state to be converged away from [20].

A hardware compliance module on a sliding carrier tray caught mid-transit between two region-labelled parts bins at a fragmented-compliance configuration desk, technical-file binders behind
Figure 2. Fragmented Blocs: this desk building two, three, or four versions of the same product because no jurisdiction accepts another's technical file.

Assumptions. This scenario assumes continued strategic rivalry, especially between the US and China, keeps frontier-model and compute governance framed as national-security policy rather than a shared technical question amenable to standards-body convergence. It also assumes that the cost of maintaining separate jurisdiction-specific variants stays low enough, relative to market size in each bloc, that providers keep absorbing it rather than lobbying hard enough for harmonization to actually get one.

Indicators. Continued or deepening export-control tiering rather than any relaxation; growth, not shrinkage, in the number of distinct jurisdiction-specific technical files or hardware configurations large multinational providers report maintaining; no equivalence or mutual-recognition arrangement signed between any two major blocs; state-level AI law counts resuming growth after 2026’s slowdown rather than states converging on a shared template.

Horizon and disconfirmation. Horizon: end of 2032. Disconfirmed if a binding mutual-recognition or substantial-equivalence agreement is signed between any two of the EU, US, and China blocs before the horizon, or if the number of jurisdiction-specific compliance variants reported by large multinational AI providers shrinks rather than grows over the period.

Scenario three: Enforcement Maturity

The claim. By 2035, third-party conformity assessment and independent evaluation have closed the audit gap this series identified in its opening piece: accredited bodies operate with defined scope, access requirements, and materiality standards; routine third-party testing, not overwhelming reliance on self-assessment, is the norm for the highest-risk systems; and evaluation findings carry real regulatory consequence rather than functioning as a one-time paper record.

Why this is plausible rather than merely hoped for. The clearest evidence that this can happen without waiting for statute is that it is already happening outside any statute. NIST’s CAISI grew its pre-deployment testing agreements from two labs to five between its founding and 5 May 2026, completed more than forty evaluations covering cybersecurity, biosecurity, and other risk categories, and conducts joint assessments with the UK’s AI Security Institute — a working, binational, non-statutory evaluation capacity operating today, not a proposal [16]. Inside the EU framework, the notified-body designation process for AI Act conformity assessment, though still described as thin as of early 2026, is at least an active pipeline rather than a hypothetical one [5], and the GPAI Code of Practice’s Signatory Taskforce gives voluntary compliance a standing coordination body, chaired by the AI Office and meeting at least annually, rather than a one-time pledge with no institutional follow-through [7]. A certifiable, cross-jurisdictional reference standard for how an organization should manage AI risk already exists in ISO/IEC 42001, and a real certifier market — naming firms that conduct independent third-party audits against it — has begun to form around it [12].

A tamper-evident seal press caught mid-descent onto a system under test on an accredited audit-lab bench, an accreditation-wall certificate half-slid into its display slot, a queue of racked systems behind
Figure 3. Enforcement Maturity: the audit gap this series named earlier — a self-assessed default with no settled third-party method — actually closed at a bench like this one.

Assumptions. This scenario assumes accreditation bodies can scale examiner capacity fast enough to matter at the volume of systems now nominally covered by high-risk or systemic-risk categories, which is a genuinely open operational question this article cannot resolve from the current evidence. It also assumes regulators route enforcement resources toward funding and staffing third-party oversight rather than only toward headline fines, and that evaluation methodology converges enough — which is really Scenario One’s claim, borrowed here as a precondition — that a finding from one accredited body is treated as informative by a regulator in a different jurisdiction.

Indicators. A rising count of completed third-party, rather than self-assessed, conformity assessments, and of notified or accredited bodies actually issuing certificates rather than merely being designated; enforcement actions that turn on substantive evaluation findings rather than on documentation or disclosure completeness — precisely the shift this series’ opening piece named as its second prediction, tested here at a later date; an accreditation or licensure scheme for AI auditors, with defined access levels and materiality standards, operating at meaningful scale — the same absence that piece’s fourth prediction expected to persist through 2029, tested here for whether it is still absent by the early 2030s.

Horizon and disconfirmation. Horizon: end of 2033. Disconfirmed if self-assessment remains the pathway used by the overwhelming majority of nominally high-risk or systemic-risk systems, or if no accreditation or licensure scheme with defined access and materiality requirements exists at meaningful scale by the horizon.

Scenario four: Governance Obsolescence

The claim. By 2035, the gap between the pace of AI deployment and the pace at which binding rules are written, funded, and enforced has not closed — it has become the normal operating condition, and most formal AI governance functions as a slow-moving, largely symbolic backdrop to a market that has already moved past whatever a given rule addressed by the time that rule takes effect.

Why this is not merely the pacing complaint everyone already makes. The pacing-problem literature treats this as a structural feature of the regulatory paradigm itself, not a temporary lag faster legislating would fix: Currie, Schlagwein, Leimeister, and Willcocks argue that AI’s opacity, autonomy, and systemic risk expose the inadequacy of general legal principles and require a risk-informed, technology-specific governance approach current institutions are not yet built to deliver [21]. The strongest concrete evidence is already visible inside the framework held up as furthest along. The EU AI Act’s own flagship high-risk compliance deadline was deferred by the Digital Omnibus before it ever took effect, moving standalone systems from August 2026 to December 2027 and embedded systems to August 2028 [4] — a legislated deadline slipping under its own institutional weight, not a hypothetical one. A dedicated liability instrument, the AI Liability Directive, was withdrawn outright in October 2025 for lack of institutional consensus, with no replacement or timeline committed [9]. US federal AI policy has reversed direction three times inside three years — a reporting requirement, its revocation, and a third order aimed at preempting the state laws that filled the resulting vacuum [1] — institutional incapacity distinct from any question of keeping pace with the technology itself. And the hardware-level mechanisms that would make some obligations mechanically enforceable remain, in the researchers’ own framing, open feasibility questions rather than a deployed capability [11].

A rubber date-stamp caught mid-press over an open statute-amendment folder's schedule page in a governance-capacity research office, a timeline pinboard with two unequal cords behind, a shelf of withdrawn proposal folders to one side
Figure 4. Governance Obsolescence: the schedule keeps moving before the rule under it takes effect, and a shelf of withdrawn folders nearby is where an abandoned rule ends up instead.

Assumptions. This scenario assumes AI deployment cadence keeps outpacing legislative and judicial review cycles rather than plateauing long enough for institutions to catch up — a continuation of current conditions rather than a discontinuity, consistent with the excluded-discontinuity assumption this series’ opening piece already stated for its own predictions. It also assumes political incentives keep favoring deferral and simplification, driven by competitiveness pressure, over building durable enforcement capacity, and that no single dramatic, publicly attributed harm event forces an emergency acceleration of binding rulemaking; this article does not model that possibility, the same way its predecessor did not.

Indicators. Further deferral or narrowing of already-legislated compliance deadlines, beyond the Digital Omnibus precedent; additional proposed accountability instruments withdrawn or left to lapse for lack of consensus, echoing the AI Liability Directive; enforcement-action counts remaining low relative to the number of nominally covered systems; voluntary frameworks such as the GPAI Code of Practice or the Hiroshima reporting schema remaining voluntary past their originally anticipated transition points rather than converting into binding requirements.

Horizon and disconfirmation. Horizon: end of 2031. Disconfirmed if the EU’s own deferred deadlines hold without further postponement and produce a documented volume of substantive, non-disclosure enforcement actions by that date, or if a binding EU-level AI liability instrument is adopted to replace the one withdrawn in 2025.

What the four scenarios share, and where they can coexist

A wide corridor in the coordination centre with doorways onto the mutual-recognition office, the audit lab, the configuration desk, and the capacity research office, each caught in a different state of openness
Figure 5. By 2035 these four rooms may not resolve into one; the honest picture is several still open for business down the same corridor at once.

Read against each other, the four scenarios are not a menu from which 2035 picks exactly one. A plausible 2035 has meaningful convergence in the scientific-evaluation layer — a shared empirical baseline from bodies like the Scientific Panel and the International AI Safety Report, informing how different regulators define capability thresholds — at the same time it has hardening fragmentation in export control and compute policy, because those are governed by different institutions answering to different incentives. It is equally possible for enforcement infrastructure to mature substantially inside one framework, most likely the EU’s given its head start, while liability law stays symbolic across all three blocs because no jurisdiction has managed to legislate a workable fault standard for a system nobody fully observes. Enforcement Maturity and Governance Obsolescence, in particular, are not opposites so much as different layers of the same framework: the EU AI Act could plausibly build real notified-body capacity for conformity assessment — Scenario Three’s claim — while its liability regime stays exactly as unresolved as the withdrawn directive left it — Scenario Four’s claim — inside the same statute, at the same time.

What ties all four together is the naming problem this series opened with. Whichever scenario or combination turns out to describe 2035, the object a rule attaches to — the model, the role, the use, the compute, the service — still determines what can actually be verified once the rule exists. Scenario One is, underneath its optimism, a claim that different jurisdictions’ naming choices turn out to be translatable into each other. Scenario Three is a claim that the verification problem the opening piece named gets solved at the infrastructure layer, through accredited bodies with real access. Scenario Four is a claim that it does not, and that the gap between a stable name and a moving system simply becomes permanent furniture rather than a problem anyone fixes.

What to take away

None of these four scenarios is a forecast this article is making. Each is a self-contained, falsifiable claim, deliberately built so that a reader checking back over the next several years has something concrete to look for rather than a narrative to take on faith — a signed equivalence agreement or its absence, a rising or flat count of third-party conformity assessments, a further deferred deadline or a held one, a replaced liability directive or a permanently vacant slot where one used to be.

The discipline this article asks of that reader is the same one this series asked in its opening piece, extended one level up. There, the question was whether the thing running now is the thing that was checked. Here, it is whether the checking regime itself — the notified body, the equivalence arrangement, the reporting framework, the liability rule — still exists, still has resources behind it, and still binds anything by the time a reader goes looking for it. A framework that exists only as a name on a compliance page, the way this series has already shown a served model can exist only as a name on an invoice, is not evidence that AI is governed. It is a record that governance was once proposed, at a moment now behind us, and it takes checking whether anything followed.