Tuesday, September 22, 2026

The Next Front In The AI Race Is Institutional Speed – OpEd


Image: ChatGPT


September 10, 2026

By Burak Oktenli


Key Takeaways:

The author says this week’s fights—U.S. accusations of Chinese model “distillation” and OpenAI’s call for mandatory safety rules—show the same gap: models update on a product calendar while governments still move on a legislative one.

Governance is treated as part of the export stack. Buying U.S., Chinese, or EU AI also imports who logs incidents, who can inspect or pause a system, and whose standards travel. Washington sells a full stack; Beijing a Global South standards club; Europe a slow, legal market-access model.

Proposed fix: aviation-style two clocks—parliaments set durable red lines; regulators issue narrow, expiring directives from shared incident reports and pooled tests—so middle powers can demand audit and rollback rights instead of becoming rule-takers.



Washington is exporting an AI technology stack, Beijing is building a governance coalition, and Europe is revising its timetable. Strategic advantage will belong to states that can turn new evidence into legitimate rules before the next model generation arrives.

Within forty-eight hours, the AI race exposed two of its least settled rules. On September 8, Washington accused six Chinese developers of using distillation to extract capabilities from American models; Beijing rejected the charge as an attempt to suppress competition. On September 9, OpenAI said that voluntary commitments were no longer sufficient for increasingly capable systems and called for mandatory, capability-based national rules covering testing, independent assessment, cybersecurity and incident reporting.

One dispute concerns how models learn from rivals; the other concerns how governments learn from models. Together they reveal a strategic constraint. Developers can alter capabilities on a release calendar, while public institutions still respond on a legislative one. Industry proposals warrant scrutiny because incumbents can shape rules to their advantage, but the underlying mismatch is difficult to dismiss. A country may lead in chips, models and data centers yet surrender strategic initiative if it cannot convert new capabilities and new failures into credible rules before the next generation arrives.


Washington already describes artificial intelligence as a geopolitical contest. The official US AI strategy says that the country with the largest ecosystem will set global standards and collect economic and security benefits. A White House order promoting full-stack American AI exports packages hardware, cloud services, data systems, models, cybersecurity and applications for allies and partners and explicitly seeks worldwide adoption of American standards and governance models.

Beijing is building a competing route to influence. At July’s World Artificial Intelligence Conference in Shanghai, participants from more than one hundred countries and international organizations endorsed “agile governance,” faster revision of standards and their mutual recognition. The meeting also marked the signing of an agreement to establish the World Artificial Intelligence Cooperation Organization in Shanghai, with an explicit mission to support development and governance capacity in the Global South.

Europe offers a third model, built around legal obligations and market access. The EU AI Act is now in force, but its rules for many high-risk uses were moved to December 2027, while obligations for systems embedded in regulated products were extended to August 2028 so that standards and other implementation tools could be completed. The European Commission’s current timetable is defensible. It also illustrates the strategic cost of governing a moving target: a law can be comprehensive and still arrive after the systems it was drafted around have changed.

Governance Is Part of the Stack


These approaches are usually compared as regulation: permissive America, rules-first Europe and state-directed China. That comparison misses the harder geopolitical point. Governance is becoming part of the technology stack itself.

When a government, bank, hospital or military imports an AI platform, it also adopts assumptions about what counts as an incident, which logs are retained, who may inspect the system, how a model update is disclosed and when service can be suspended. Those choices become embedded in procurement contracts, professional routines and data architecture. Hardware can sometimes be replaced faster than an institutional workflow can be rebuilt.

For states across Eurasia, the Middle East, Africa and Southeast Asia, the choice is therefore larger than vendor selection. They are choosing an update authority. Who decides that a newly discovered capability requires different safeguards? Whose evidence is accepted? Can a local regulator pause a system, or must it wait for a foreign provider? Will an incident in one country trigger review elsewhere? The answers determine how much sovereignty remains after deployment.

The geopolitical contest will turn partly on whose governance model travels. The United States cannot export confidence if it lacks a trusted way to investigate failures at home. China can use standards cooperation to build influence even where its most advanced hardware is not dominant. Europe’s regulatory pull weakens when compliance dates move or practical guidance lags behind legal ambition. Speed alone does not create legitimacy, but persistent lag erodes both safety and influence.

The Necessary Slow Loop

Two calendars show the problem. A leading developer’s public rulebook for model behavior was revised repeatedly between February 2025 and August 2026 as deployments generated new lessons. Over the same period, Europe’s high-risk implementation schedule moved because the standards needed to apply the law were unfinished. The comparison is not an indictment of Europe or an endorsement of corporate self-regulation. It measures two different responsibilities.

Technical learning has a short loop: deploy, observe, correct and release. Institutional learning has a longer one because it must investigate, hear affected parties, establish facts others will accept, assign authority and preserve avenues for challenge. Those steps are not bureaucratic decoration. They are how a rule acquires the right to bind people who did not write it.

The failure comes when one layer is expected to supply both legitimacy and rapid correction. Statutes then describe systems that no longer exist; companies become the only actors with current knowledge; and private specifications become the operational law because public institutions cannot update theirs in time. A uniform national framework can reduce fragmentation, as the White House legislative framework argues. Without a rapid learning mechanism inside it, however, uniformity merely replaces several slow loops with one.

What Aviation Actually Offers


Aviation offers a useful institutional architecture, not a claim that an AI model is an aircraft. Its learning system combines several tempos. NASA’s Aviation Safety Reporting System gathers protected voluntary reports and uses them to identify system deficiencies. The National Transportation Safety Board conducts investigations under a mandate for institutional independence. The Federal Aviation Administration can issue legally enforceable airworthiness directives to correct specific unsafe conditions, including through emergency procedures.

The slow layer grants authority, protects rights and defines jurisdiction. The fast layer gathers evidence and issues narrow corrections within those boundaries. Neither is asked to perform the other’s job.

AI governance needs the same separation. Legislatures should establish durable red lines, reporting powers, due process and judicial review. Regulators and technical bodies should be able to respond to specified capabilities and failure modes with provisional measures that are evidence-based, appealable and designed to expire. The objective is not permanent emergency rule. It is a lawful route from a new fact to a temporary safeguard while the slower process catches up.

Build an Adaptive Governance Stack

First, create a common incident grammar. Reporting thresholds should be tied to consequences unauthorized system access, circumvention of controls, material deception, physical harm or loss of human override rather than to product names that may disappear. Protected channels should encourage early disclosure, while anonymized findings should travel across borders.


Second, pool independent assessment capacity. Every state will not build a frontier laboratory, and it should not have to. Allies and regional organizations can share technical teams, recognize one another’s findings and maintain common testing environments. This gives middle powers access to credible evidence without making them dependent on a vendor’s account of its own failure.

Third, authorize narrow provisional directives. A regulator should be able to require extra monitoring, restrict a tool connection, suspend a capability or order a rollback when a defined risk is demonstrated. Each measure should state its evidence, scope and expiration date. Sunset clauses force review and prevent yesterday’s emergency from becoming tomorrow’s obsolete rule.

Fourth, export governance with technology. A full-stack offer should include shared incident formats, audit access, disclosure of material model changes, rollback procedures and joint crisis exercises. Recipient states should retain the practical ability to inspect and suspend systems operating in sensitive sectors. A package that exports capability without a correction loop creates dependency; one that exports both can create durable alignment.

Finally, make revision ordinary. High-risk rules and standards should be dated, versioned and tied to review triggers such as new tool use, greater autonomy or deployment in critical infrastructure. Public archives of material changes would allow regulators and researchers to compare what a system was allowed to do with what it later did.

A Strategic Choice for Middle Powers


Middle powers should negotiate these institutional terms as seriously as they negotiate data localization, financing and access to compute. Procurement agreements can require reciprocal incident notification, local audit rights, continuity plans and participation in shared testing. Regional bodies can operate incident clearinghouses and recognize evidence without copying an entire American, Chinese or European regulatory model.

This is a chance to avoid becoming passive rule-takers. A state that cannot build the most powerful model may still shape how models are tested, updated and trusted across a regional market. In a fragmented international system, that capacity is a source of bargaining power.

This week’s policy signals point in the same direction from different starting points. A leading American developer says voluntary commitments are insufficient. Washington wants its technology and governance model adopted abroad. Beijing is organizing a standards coalition around agile governance and the Global South. Europe has adjusted its schedule to align law with the tools needed to enforce it. All are acknowledging that the institutional calendar has become a strategic variable.

The states that govern fastest will not be those that legislate most often or discard deliberation. They will be those that separate durable authority from rapid correction, build trusted evidence loops inside lawful institutions and make those loops interoperable with partners. The next global standard-setter may not be the country with the single most powerful model. It may be the one whose rules can learn quickly enough to remain credible.


About Burak Oktenli
Burak Oktenli holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University. His research addresses the governance of authority in autonomous and AI-enabled systems, and his writing has appeared at the Modern War Institute at West Point, RUSI, RealClearDefense, RealClearMarkets, and Geopolitical Monitor. He is the author of Authority Architectures for Autonomous Systems, a ten-volume series on how authority in autonomous systems is delegated, monitored and recovered, at authority-architecture.me.
View all posts by Burak Oktenli →

No comments: