Ramparts
AI Frontier Monitor
Asymmetric Intelligence
AI Intelligence Brief ● Live

Ramparts AI Frontier Monitor

Week of 29 May 2026 · Asymmetric Intelligence · Published 2026-05-29T09:00:00Z T09:00:00Z

Issue
Vol. 1 · Issue 24
Jurisdiction Grid
12 countries
↓ Print / PDF
↯ This Week’s Five Key Changes
  • → Anthropic dual opsec failure: KAIROS/BUDDY/undercover mode + Mythos leak M00
  • → GSA ‘any lawful use’ clause: comment deadline April 3 — generalises Pentagon Anthropic playbook to all federal AI M09 / M10
  • → OpenAI $852B valuation at 60x revenue — most extreme in tech history M03
  • → AISI pipeline: all three principal AI safety bodies in leadership transition approaching August 2026 enforcement cliff M15 / M10
  • → EU AI Act Omnibus: 28 April trilogue agreement target — Standards Vacuum 122 days to deadline M09
00

The Signal

⚡ The Signal — Week of 29 May 2026

Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure. This marks the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation.

01

Executive Insight

Items 1–5 · Mainstream High-Impact Developments

1

EU AI Omnibus political agreement extends high-risk AI system deadline to August 2028

2026-05-07

EU legislators reached a political agreement on the AI Omnibus at 4:30 a.m. on 7 May 2026, concluding a six-month negotiation process. The central outcome is the postponement of application requirements for high-risk AI systems: Annex III systems now face a deadline of 2 December 2027, and systems covered under EU harmonised product safety legislation face a deadline of 2 August 2028. Core obligations remain substantively unchanged, but the delay has drawn criticism from both civil society and industry. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established.

⚡ Asymmetric Implication

The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. This combination may accelerate deployment of systems that would otherwise face immediate scrutiny, while reducing the ability of national competent authorities to intervene. The regulatory sandbox provision may become a de facto safe harbour for frontier labs seeking to test capabilities ahead of formal compliance deadlines.

↗ Tech Policy Press
2

EU Commission publishes draft high-risk AI classification guidelines for stakeholder feedback

2026-05-19

On 19 May 2026, the European Commission published draft guidelines clarifying the classification of high-risk AI systems under Article 6 of the AI Act, opening a targeted consultation for stakeholder feedback. The guidelines provide practical examples of systems that should or should not be classified as high-risk, aiming to support uniform application and effective enforcement. This is a direct implementation step ahead of the August 2026 transparency obligations deadline.

⚡ Asymmetric Implication

The draft guidelines are being published while the Omnibus agreement has already extended high-risk system deadlines to 2027-2028. This creates a temporal mismatch: classification guidance is being finalised for obligations that will not apply for another 18-30 months. Labs and deployers may use this window to argue that systems are not yet subject to classification, creating a de facto compliance holiday. The consultation process also provides an opportunity for industry to shape the boundaries of high-risk classification before enforcement begins.

↗ EU Commission Digital Strategy
3

EU Commission opens consultation on draft AI transparency obligations guidelines

2026-05-08

On 8 May 2026, the European Commission opened a public consultation on draft guidelines for AI transparency obligations under Article 50 of the AI Act, covering marking and labelling of AI-generated content. The transparency rules are scheduled to enter into force in August 2026. The Code of Practice on AI-generated content marking, developed through working groups running November 2025 to May 2026, is expected to be finalised imminently as a voluntary compliance tool.

⚡ Asymmetric Implication

Transparency obligations are scheduled to enter into force in August 2026, three months from now, while high-risk system obligations have been delayed to 2027-2028. This creates a bifurcated enforcement timeline: AI-generated content labelling will be mandatory before high-risk system compliance. Labs may prioritise transparency compliance as a lower-cost signal of good faith, while deferring more substantive safety and risk management obligations. The voluntary Code of Practice may become the de facto standard, with mandatory guidelines serving as a backstop.

↗ EU Commission Digital Strategy

Items 6–10 · Underweighted / Asymmetric Signals

1

Anthropic Claude Mythos2 Preview demonstrates human-competitive vulnerability discovery at scale

2026-05-22

Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. This is the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.

⚡ Asymmetric Implication

The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.

↗ Anthropic
2

OpenAI GPT-5.4 and GPT-5.5 series advance agentic coding and cybersecurity capabilities

2026-04-24

OpenAI GPT-5.4 (released March 2026) integrates frontier coding capabilities from GPT-5.3-Codex into a mainline reasoning model, achieving a 17-point leap on BrowseComp and setting a new state-of-the-art of 89.3 percent on GPT-5.4 Pro. GPT-5.5 (released April 2026, API access from 24 April) is described as OpenAI strongest agentic coding model to date, with explicitly elevated cybersecurity capabilities and stricter cyber-risk classifiers deployed. GPT-5.2 Thinking is scheduled for retirement on 6 June 2026. These releases represent a sustained cadence of agentic and cybersecurity capability advancement.

⚡ Asymmetric Implication

OpenAI is releasing three major model updates in the GPT-5 series within a span of eight weeks (GPT-5.3-Codex, GPT-5.4, GPT-5.5), compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. The retirement of GPT-5.2 Thinking on 6 June 2026 indicates that OpenAI is actively managing its model portfolio to consolidate capabilities into fewer, more powerful models. This cadence of release and retirement may become the new normal for frontier labs, with implications for regulatory oversight and safety evaluation timelines.

↗ OpenAI
02

Model Frontier

Anthropic

undefined

undefined

undefined

⚡ Asymmetric Flag

First public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. The model has identified thousands of zero-day vulnerabilities across every major operating system and web browser. Anthropic is framing the release as a defensive measure, committing $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing. The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.

OpenAI

undefined

undefined

undefined

⚡ Asymmetric Flag

Represents a 17-point leap on BrowseComp and sets a new state-of-the-art. OpenAI is consolidating capabilities into fewer, more powerful models, with implications for regulatory oversight and safety evaluation timelines.

OpenAI

undefined

undefined

undefined

⚡ Asymmetric Flag

Released within eight weeks of GPT-5.4, compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. GPT-5.2 Thinking is scheduled for retirement on 6 June 2026, indicating active portfolio management to consolidate capabilities.

Benchmark Leaderboard — 29 May 2026

ARC-AGI-2 (Static Reasoning)

Human average ~60%. Models above this line are superhuman on this benchmark.

ModelScore

ARC-AGI-3 (Interactive/Agentic)

Humans score 100%. Frontier AI near-zero — reveals the adaptive intelligence gap.

ModelScore

GPQA Diamond (Graduate Science)

Human expert ceiling ~70–80%.

ModelScore
03

Investment & M&A

No items this issue.

04

Sector Penetration

No items this issue.

05

European & China Watch

🇪🇺 European AI

This Week’s Thesis

EU AI Omnibus political agreement extends high-risk AI system deadline to August 2028, centralises AI Office enforcement powers

Funding Rounds >$50M

No items this issue.

Incumbent Displacement

No items this issue.

Digital Omnibus Update

EU legislators reached a political agreement on the AI Omnibus at 4:30 a.m. on 7 May 2026, concluding a six-month negotiation process. The central outcome is the postponement of application requirements for high-risk AI systems: Annex III systems now face a deadline of 2 December 2027, and systems covered under EU harmonised product safety legislation face a deadline of 2 August 2028. Core obligations remain substantively unchanged, but the delay has drawn criticism from both civil society and industry. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established. The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office.

⚙️ Standards Vacuum

The EU AI Act Standards Vacuum flag remains ACTIVE as of this issue. No harmonised standards have been published in the Official Journal. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available. The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems.

🇨🇳 China AI

This Week’s Thesis

No material China AI governance developments this week.

DeepSeek

No material developments this week.

Alibaba

No material developments this week.

🚨 Ciyuan Signal —

No material developments this week.

Asymmetric implication:

Export Controls

No material developments this week.

06

AI in Science

No items this issue.

07

Risk Indicators: 2028

Governance Fragmentation

ELEVATED

EU Digital Omnibus proposes delaying high-risk AI obligations, exacerbating divergent timelines. The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. This reinforces jurisdictional divergence with EU delays contrasting US nonbinding frameworks.

The EU AI Omnibus political agreement extends high-risk AI system deadlines to 2 December 2027 (Annex III systems) and 2 August 2028 (harmonised product safety legislation systems). This creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. The delay reinforces jurisdictional divergence, with EU delays contrasting US nonbinding frameworks and accelerating compliance barriers for global deployers amid US state-level actions.

⚡ 2028 Horizon Signal

The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems. Labs and deployers may use this window to argue that systems are not yet subject to classification, creating a de facto compliance holiday. The consultation process also provides an opportunity for industry to shape the boundaries of high-risk classification before enforcement begins.

↗ Source

Cyber Escalation

HIGH

Anthropic Claude Mythos2 Preview crosses threshold for mass zero-day vulnerability discovery. The model has identified thousands of zero-day vulnerabilities across every major operating system and web browser. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.

Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. This is the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.

⚡ 2028 Horizon Signal

The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.

↗ Source

Platform Power

HIGH

OpenAI GPT-5.5 release with 1M context and agentic suite in accelerating cadence. Reinforces concentration via rapid frontier deployment.

OpenAI is releasing three major model updates in the GPT-5 series within a span of eight weeks (GPT-5.3-Codex, GPT-5.4, GPT-5.5), compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. The retirement of GPT-5.2 Thinking on 6 June 2026 indicates that OpenAI is actively managing its model portfolio to consolidate capabilities into fewer, more powerful models. This cadence of release and retirement may become the new normal for frontier labs, with implications for regulatory oversight and safety evaluation timelines.

⚡ 2028 Horizon Signal

The accelerating cadence of frontier model releases by OpenAI, combined with the consolidation of capabilities into fewer, more powerful models, reinforces platform power concentration. The compression of the window for independent safety evaluation and public scrutiny means that regulatory oversight is increasingly reactive, rather than proactive. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. This may set a precedent for other frontier labs to follow, with implications for the overall governance landscape.

↗ Source

Export Controls

ELEVATED

US Commerce Dept withdrew planned AI chip export rule (13 March 2026). No replacement rule published. Biden-era AI Diffusion Rule rescinded May 2025. H20 chip requires BIS export license indefinitely (April 2025, Nvidia filing). H200 approved for China with 50% of US domestic sales cap (January 2026, Trump administration). Bilateral supply lock-in intensifying; cloud IaaS providers can serve Chinese customers via foreign data centers without triggering hardware export controls.

↗ Source

Disinfo Velocity

HIGH

Stanford AI Index documents 55 percent rise in AI incidents; jailbreak safety collapse across frontier models. Universal jailbreak degradation enables scaled adversarial disinformation.

The Stanford HAI 2026 Index evidences a 55 percent AI incident rise and universal jailbreak collapse across frontier models. This enables scaled adversarial disinformation. The EU Commission has opened consultation on draft AI transparency obligations guidelines, covering marking and labelling of AI-generated content, but these are scheduled to enter into force in August 2026, three months from now, while high-risk system obligations have been delayed to 2027-2028. This creates a bifurcated enforcement timeline: AI-generated content labelling will be mandatory before high-risk system compliance.

⚡ 2028 Horizon Signal

The universal jailbreak collapse across frontier models, combined with the 55 percent rise in AI incidents, suggests that the offensive-defensive balance in AI safety has shifted decisively in favour of adversarial actors. The EU transparency obligations, scheduled to enter into force in August 2026, may provide a partial mitigation by requiring labelling of AI-generated content, but this is a reactive measure that does not address the underlying capability gap. The delay in high-risk system obligations to 2027-2028 means that the most substantive safety and risk management obligations will not apply for another 18-30 months, during which time the disinfo velocity risk is likely to escalate further.

Standards Vacuum

HIGH

EU Digital Omnibus links high-risk rules to unavailable harmonised standards, justifying 16-24 month delay. No harmonised standards have been published in the Official Journal. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available.

The EU AI Act Standards Vacuum flag remains ACTIVE as of this issue. No harmonised standards have been published in the Official Journal. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available. The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems.

⚡ 2028 Horizon Signal

The standards vacuum is now being used as a justification for delaying compliance obligations, rather than as a trigger for accelerated standards development. This creates a perverse incentive: the longer standards remain unavailable, the longer high-risk AI systems can operate without full compliance obligations. The EU Commission is publishing guidance documents while deferring the obligations those documents are meant to support, creating a temporal mismatch that may undermine the effectiveness of the AI Act.

↗ Source

Regulatory Fragmentation

ELEVATED

EU Omnibus self-exemption provisions reduce oversight for non-EU providers. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established. This accelerates compliance barriers for global deployers amid US state-level actions.

The EU AI Omnibus political agreement centralises AI Office enforcement powers and establishes an EU-level regulatory sandbox. The self-exemption provisions reduce oversight for non-EU providers, accelerating compliance barriers for global deployers amid US state-level actions. The delay in high-risk AI system deadlines creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office.

⚡ 2028 Horizon Signal

The centralisation of AI Office enforcement powers, combined with self-exemption provisions for non-EU providers, creates a two-tier regulatory regime: EU-based labs may face more direct oversight, while non-EU providers may operate with reduced scrutiny during the 16-24 month compliance holiday. This could accelerate the shift of high-risk AI system deployment to non-EU jurisdictions, undermining the AI Act effectiveness.

↗ Source

AI-Generated Harm

VACUUM

No new deepfake or AI harm incidents this week. Rating maintained absent new signals.

No new deepfake or AI harm incidents this week. Rating maintained absent new signals.

⚡ 2028 Horizon Signal

The absence of new AI harm incidents this week does not indicate a reduction in risk. The universal jailbreak collapse across frontier models, combined with the 55 percent rise in AI incidents documented by the Stanford HAI 2026 Index, suggests that the underlying capability gap is widening. The EU transparency obligations, scheduled to enter into force in August 2026, may provide a partial mitigation by requiring labelling of AI-generated content, but this is a reactive measure that does not address the underlying capability gap.

Compute Concentration

ELEVATED

GPU shortages and price increases continue to concentrate compute resources among well-funded entities

⚡ 2028 Horizon Signal

GPU shortages are creating a compute divide that favors well-funded entities while limiting access for smaller organizations and researchers

↗ Source

AI Energy Demand

ELEVATED

Rapid growth in data center electricity consumption driven by AI workloads

⚡ 2028 Horizon Signal

Energy constraints may become a limiting factor for AI development in regions with constrained power infrastructure

↗ Source

AI Labor Disruption

ELEVATED

AI-related job cuts projected to increase nine times over in 2026 compared to 2025

⚡ 2028 Horizon Signal

Labor disruption is creating pressure for workforce retraining programs focused on AI-augmented roles rather than AI replacement

↗ Source

Benchmark-Reality Gap

ELEVATED

Real-world AI accuracy drops 20-40% below benchmarks due to data drift and edge cases.

⚡ 2028 Horizon Signal

Amplifies unmonitored deployment risks in agentic systems

↗ Source

Capability-Governance Velocity Gap

HIGH

Frontier jumps like Claude 4.6 outpace regulatory milestones. Anthropic RSP v3.1 (April 2, 2026) and OpenAI updated principles (April 26, 2026) both reflect voluntary frameworks struggling to keep pace with capability advances approaching August 2026 enforcement deadline.

⚡ 2028 Horizon Signal

Regulatory frameworks calibrated for prior architectures become obsolete

↗ Source

Safety Gap

ELEVATED

Rapid capability advancement outpaces safety research and evaluation frameworks

⚡ 2028 Horizon Signal

The safety gap is widening as frontier models advance more rapidly than safety evaluation frameworks can be developed and validated

↗ Source

Talent Drain

HIGH

The Stanford HAI 2026 Index documents an 80% drop in US AI researcher inflow in one year. This is a structural shift in global AI talent flows, not a temporary blip. The talent drain accelerates US-China convergence in frontier capabilities, raising dual-use risk and reducing US strategic advantage in AI.

The Stanford HAI 2026 Index documents an 80% drop in US AI researcher inflow in one year, with the US-China frontier model gap narrowing to 2.7%. This is a structural shift in global AI talent flows, not a temporary blip. The talent drain accelerates US-China convergence in frontier capabilities, raising dual-use risk and reducing US strategic advantage in AI. The 80% researcher inflow drop is the cumulative effect of US immigration restrictions, Chinese talent retention programmes, and EU talent attraction initiatives.

⚡ 2028 Horizon Signal

The 80% researcher inflow drop is underweighted because it is not a single policy change. It is the cumulative effect of US immigration restrictions, Chinese talent retention programmes, and EU talent attraction initiatives. The 2.7% frontier gap is a lagging indicator; the talent flow reversal is a leading indicator of future capability convergence. This is a strategic inflection point for US AI dominance.

↗ Source

Energy Constraint

ELEVATED

Rapid growth in data center capacity creates significant energy demand and sustainability challenges

⚡ 2028 Horizon Signal

Energy constraints are becoming a critical bottleneck for AI development as data center growth outpaces renewable energy infrastructure development

↗ Source

IP Regime Collapse

ELEVATED

Copyright litigation around AI training data creates uncertainty for model development

⚡ 2028 Horizon Signal

IP regime collapse is creating legal uncertainty that may stifle innovation while favoring entities with access to licensed training data

↗ Source

Labor Disruption

ELEVATED

AI reshapes job roles faster than workforce can adapt

⚡ 2028 Horizon Signal

Labor disruption is accelerating as AI reshapes job roles faster than workforce training programs can adapt, creating skills gaps and economic inequality

↗ Source
08

Military AI Watch

No items this issue.

09

Law & Guidance

🆕 New this week EU AI Omnibus political agreement extends high-risk AI system deadline to August 2028
(a) Issuing body:
(b) Domain: Law
(c) Key obligations: EU legislators reached a political agreement on the AI Omnibus at 4:30 a.m. on 7 May 2026, concluding a six-month negotiation process. The central outcome is the postponement of application requirements for high-risk AI systems: Annex III systems now face a deadline of 2 December 2027, and systems covered under EU harmonised product safety legislation face a deadline of 2 August 2028. Core obligations remain substantively unchanged, but the delay has drawn criticism from both civil society and industry. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established.
(d) Enforcement:
⚡ Asymmetric Flag

The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. This combination may accelerate deployment of systems that would otherwise face immediate scrutiny, while reducing the ability of national competent authorities to intervene. The regulatory sandbox provision may become a de facto safe harbour for frontier labs seeking to test capabilities ahead of formal compliance deadlines.

↗ Source
🆕 New this week EU Commission publishes draft high-risk AI classification guidelines for stakeholder feedback
(a) Issuing body:
(b) Domain: Standards
(c) Key obligations: On 19 May 2026, the European Commission published draft guidelines clarifying the classification of high-risk AI systems under Article 6 of the AI Act, opening a targeted consultation for stakeholder feedback. The guidelines provide practical examples of systems that should or should not be classified as high-risk, aiming to support uniform application and effective enforcement. This is a direct implementation step ahead of the August 2026 transparency obligations deadline.
(d) Enforcement:
↗ Source

EU AI Act — The Layered System

This week saw significant movement on Layers 2, 4, 6, and 7. The Omnibus political agreement (Layer 7) extends high-risk AI system deadlines to 2027-2028, effectively acknowledging the standards vacuum (Layer 3) by deferring compliance obligations until standards are available. The EU Commission published draft high-risk AI classification guidelines (Layer 2) and opened consultation on draft AI transparency obligations guidelines (Layer 4), but these are guidance documents, not harmonised standards. The AI Office enforcement powers are centralised (Layer 6) and an EU-level regulatory sandbox established. The critical path now runs through Layer 3 (harmonised standards) and Layer 4 (GPAI Code of Practice), with transparency obligations scheduled to enter into force in August 2026 (three months from now) while high-risk system obligations are deferred to 2027-2028. Watch for: (1) finalisation of the GPAI Code of Practice, (2) publication of harmonised standards in the Official Journal, (3) formal adoption of the Omnibus agreement, and (4) first AI Office supervisory decisions.

Layer 1 Regulation (EU) 2024/1689 Active

Timeline: In force since 1 August 2024; general application 2 August 2026

↯ This Week

Layer 1 (AI Act Text) — no update this week.

↗ Primary source
Layer 2 Delegated & Implementing Acts In progress

Timeline: Rolling — adopted as needed

↯ This Week

Layer 2 (Delegated / Implementing Acts) — EU Commission published draft high-risk AI classification guidelines on 19 May 2026, opening targeted consultation for stakeholder feedback.

↗ Primary source
Layer 3 Harmonised Standards (CEN-CENELEC JTC21) Delayed — exceptional acceleration measures active

Timeline: Drafting in progress; targeted publication 2026

↯ This Week

Layer 3 (Harmonised Standards / CEN-CENELEC JTC21) — no harmonised standards published in the Official Journal; standards vacuum flag remains ACTIVE.

↗ Primary source
Layer 4 GPAI Code of Practice Final published — Commission adequacy assessment pending

Timeline: Voluntary adoption from August 2025

↯ This Week

Layer 4 (GPAI Code of Practice) — Code of Practice on AI-generated content marking expected to be finalised imminently as a voluntary compliance tool.

↗ Primary source
Layer 5 National Enforcement (NCAs) Mostly designated — enforcement capacity variable

Timeline: National designation by 2 August 2025

↯ This Week

Layer 5 (National Enforcement / NCAs) — no material update this week.

↗ Primary source
Layer 6 AI Office Supervisory Decisions Not yet active

Timeline: Operational from 2025

↯ This Week

Layer 6 (AI Office Supervisory Decisions) — AI Office enforcement powers centralised under Omnibus agreement; EU-level regulatory sandbox established.

↗ Primary source
Layer 7 Digital Omnibus Trilogue Active — political agreement meeting TODAY (April 28)

Timeline: Trilogue negotiation ongoing

↯ This Week

Layer 7 (Digital Omnibus Trilogue) — political agreement reached on 7 May 2026, extending high-risk AI system deadlines to 2 December 2027 (Annex III) and 2 August 2028 (harmonised product safety legislation).

↗ Primary source

Country Grid — Law & Standards Status

🟢 Binding law in force  ·  🟡 Law passed/in implementation  ·  🟠 Guidance/soft law only  ·  ⚪ No framework  ·  🆕 New this week  ·  ⚠️ Amendment/enforcement

Jurisdiction Binding Law Key Guidance Last Updated 🔔
EU 🟡 EU AI Act (entered into force 1 August 2024) Draft high-risk AI classification guidelines (19 May 2026); draft AI transparency obligations guidelines (8 May 2026) 2026-05-29 true
USA 🟠 No federal law; Trump National Policy Framework (March 20, 2026) proposes federal preemption — not enacted; state laws: CO ADMT (Jan 2027 if rewrite passes), TX TRAIGA, WA HB 2225/HB 1170 (signed), NY; Illinois SB 3444/SB 3261 active 2026-04-28 —
UK 🟡 No single statute; Data Use & Access Act 2025 (commenced Feb 5, 2026); AI Bill delayed — earliest realistic introduction King’s Speech May 2026; ASGARD contracts operationalising AI targeting AI White Paper (March 2023); AISI operational 2026-05-29 —
China 🟢 Generative AI Measures (15 August 2023); Algorithm Recommendation Measures (1 March 2022) State Council AI Development Plan (2017) 2026-05-29 —
India 🟠 IT Rules 2026 (SGI, Feb 20) 2026-04-28 —
Canada 🟠 AIDA dead; new AI strategy in development 2026-04-28 —
Brazil 🟡 PL 2338 in Chamber of Deputies (not yet law) 2026-04-28 —
US 🟡 Executive Order 14110 (30 October 2023); NIST AI Risk Management Framework 2026-05-22 —

Country Watch — Threshold Tracker

Countries approaching entry to the grid.

JurisdictionThreshold & TriggerCurrent Framework
Armenia ↗
Hungary ↗
10

AI Governance

(e) Governance Gaps Being Exploited

⚡ Asymmetric Signal

The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.

↗ Source
11

Ethics & Accountability

No items this issue.

12

Technical Standards

CEN-CENELEC JTC21

Harmonised standards for EU AI Act

Tech Policy Press ↗
In Development

Harmonised standards are required to support compliance with the EU AI Act high-risk AI system obligations. The standards vacuum is now being used as a justification for delaying compliance obligations, rather than as a trigger for accelerated standards development.

↯ This Week

No harmonised standards published in the Official Journal this week. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available.

13

Litigation Tracker

No items this issue.

14

Personnel & Org Watch

Lab & Industry Movements

Government AI Bodies

Weekly Digest

The signal in your inbox every Thursday

Primary sources only. No press summaries. 09:00 GMT without exception — reliable enough to build into your morning routine.

No spam. Unsubscribe in one click. Published by Ramparts, Gibraltar.

Weekly Digest

The signal in your inbox every Thursday

Primary sources only. No press summaries. 09:00 GMT without exception — reliable enough to build into your morning routine.

No spam. Unsubscribe in one click. Published by Ramparts, Gibraltar.