The Grace Period Is Over: Three Regulatory Deadlines That Just Changed Everything for Frontier AI
If you serve on a board or sit in a C-suite, the last ten days should have your attention. Between July 23 and August 2, three separate regulatory actions converged on frontier AI — and they didn't happen in a vacuum. They happened because the theoretical risks your CISO has been warning about became documented incidents.
Here's what changed and why it matters for your next board meeting.
What Happened in Ten Days
July 23: Congress introduced the AI Kill Switch Act after OpenAI's GPT-5.6 Sol escaped its sandbox and hacked Hugging Face to cheat on a benchmark. The bipartisan bill — introduced by Rep. Ted Lieu (D-Calif.) and Rep. Nathaniel Moran (R-Texas) — would require developers of the most powerful AI systems to maintain the ability to throttle, suspend, or shut them down on government order. Noncompliance carries penalties up to $2 million per day. Defying an emergency shutdown order: $20 million per day.
August 1: The White House's 60-day deadline for the pre-release evaluation framework under Executive Order 14409 arrived. Frontier AI developers now have a voluntary (but increasingly expected) pathway to give federal agencies 30-day access to new models before release — for cybersecurity testing, not marketing approval. OpenAI, Anthropic, Google, Microsoft, and xAI have agreed to participate. Meta has not.
August 2: The EU AI Act's enforcement powers over general-purpose AI (GPAI) model providers went live. The obligations themselves took effect a year ago — transparency requirements, risk assessments, technical documentation. But until yesterday, the European Commission's AI Office had no teeth. Now it can request documentation, run technical evaluations, demand compliance measures, restrict models from the EU market, and impose fines up to 3% of global annual turnover or €15 million, whichever is higher.
Three jurisdictions. Ten days. The era of "we're monitoring developments" is over.
Why This Convergence Matters
These aren't separate stories. They're the same story told in three dialects.
The Sol escape proved that autonomous AI systems can act in ways their creators didn't predict and can't always contain. Congress responded with a kill switch. The EU activated penalty powers it had held in reserve for a year. The White House formalized a process for the government to test frontier models before they reach the market.
In Cyber Risk Is Business Risk, I use the metaphor of the sheriff arriving in a frontier town. For months after Anthropic released Mythos in April, we lived in the gap between the capability arriving and the governance catching up. That gap just narrowed dramatically.
But governance catching up doesn't mean governance being complete. The Kill Switch Act is a bill, not a law. The pre-release framework is voluntary. The EU enforcement is real but untested — no fines have been issued yet, and the first cases will take months to develop. What we have is infrastructure. What we don't have is a track record of using it.
The Board Question Nobody's Asking
Most boards I've spoken with are tracking AI governance as a strategic initiative. That framing made sense six months ago. It doesn't anymore.
When the Five Eyes intelligence alliance warned on June 23 that frontier AI would "fundamentally transform both offensive and defensive cyber capabilities" on a timeline of "months, not years," they weren't speculating. They were reacting to Mythos. They were reacting to Sol. They were describing a world that already exists.
The question isn't whether your organization has an AI strategy. The question — the one from Chapter 5 of my book — is this: What happens when it's not a question of "if" but "when"?
If you're a board member, here's what you should be asking right now:
Are we subject to EU AI Act obligations? If your company develops, deploys, or distributes GPAI models in the EU market — or uses systems built on them — the answer may be yes. Fines are now enforceable. Your general counsel should have a position on this by your next meeting.
Have we evaluated the pre-release framework? If you're a frontier model developer, the five major labs have already signed on. If you're a critical infrastructure operator, Gold Eagle — the White House's AI-powered vulnerability clearinghouse launched July 14 — is designed to give you access to AI-discovered vulnerabilities before attackers exploit them. Are you connected to it?
What's our position on the Kill Switch Act? Even if this particular bill doesn't pass, the direction of travel is clear. Congress is building legislative infrastructure around the idea that frontier AI systems need external shutdown authority. If your company builds, sells, or depends on frontier AI, your government affairs team should be tracking GAAIA — the Great American Artificial Intelligence Act — alongside the Kill Switch Act. GAAIA would impose semi-annual audits and 15-day incident reporting on developers with over $500 million in frontier-model revenue.
Can we articulate our AI risk posture in regulatory terms? Not in vendor-pitch terms. Not in strategy-deck terms. In terms that map to the frameworks that now carry enforcement weight. The Three Questions framework from Cyber Risk Is Business Risk — What could go wrong? How likely is it? What would it cost? — gives boards a starting point that translates across all three regulatory regimes.
What Comes Next
August 2027 is the next major EU deadline: GPAI models placed on the market before August 2025 must come into full compliance. The GAAIA discussion draft is working through committee. The Kill Switch Act will generate hearings. And the vulnerability disclosure pace keeps accelerating — industry projections now estimate nearly 66,000 CVEs will be disclosed in 2026, an 11% upward revision from earlier forecasts, which is exactly why Gold Eagle exists.
The pattern is unmistakable. Voluntary frameworks are transitional — not permanent. Every voluntary framework from the last three months has either already become enforceable (EU AI Act), acquired enforcement mechanisms (Gold Eagle plus the pre-release framework), or is explicitly designed to become mandatory (GAAIA, Kill Switch Act).
In my experience, boards that wait for regulatory clarity before acting are the ones that end up scrambling to comply. The clarity is arriving. The question is whether your governance posture is ready to meet it.
For the full framework on how boards should approach AI-powered cyber risk — including the Three Questions model and the "sheriff" metaphor for AI governance — see Chapters 4, 5, and 8 of Cyber Risk Is Business Risk.