AI Governance in 2025: a year in review
70+ defining milestones of 2025 | Edition #37
Hey 👋
I’m Oliver Patel, author and creator of Enterprise AI Governance.
Happy new year! I hope that everyone who celebrates enjoyed a peaceful, relaxing, and pleasant festive season. 2026 is inevitably going to be a busy and intense year for AI governance professionals. But before looking ahead, we are going to look back on 2025, which was a landmark year for our field.
This week’s newsletter provides a comprehensive review of AI law, policy, and governance in 2025. It features:
✅ 8 key themes that defined 2025
✅ Visual timeline: AI Governance in 2025 (free pdf download)
✅ The ultimate AI governance timeline: 70+ key milestones in 2025 (all hyperlinks provided)
Note: due to the length of this article, it is best viewed on your browser or the Substack app.
Sign up to secure a 25% discount for my forthcoming book, Fundamentals of AI Governance (2026). It provides a detailed, comprehensive, and visual overview of Global AI Law and Policy, including U.S., China, and EU comparison charts, as well as practical strategies for cross-jurisdictional compliance.
8 key themes which defined 2025
EU AI Act compliance becomes a reality. 2025 was the year that EU AI Act compliance became a reality for many organisations worldwide. The first set of provisions, on prohibited AI practices and AI literacy, became applicable on 2 February 2025. And on 2 August 2025, the obligations for providers of general-purpose AI (GPAI) models became applicable. The GPAI Code of Practice was approved just in time for this deadline, and the European Commission also published guidelines on prohibited AI practices, the AI system definition, and GPAI model provider obligations. However, as covered previously in Enterprise AI Governance, there is now uncertainty regarding what the compliance deadline for high-risk AI systems will be, following the Commission’s proposal to delay the 2 August 2026 date, as part of the AI Act “simplification” changes.
But the Brussels effect remains limited. The EU’s comprehensive, horizontal AI law remains an outlier. Despite the immense global policy focus on AI in recent years, other jurisdictions have not opted to follow the EU’s approach. Simply put, there is no other AI law globally that is comparable to the EU’s in terms of its comprehensiveness, stringency, and enforcement teeth. China has enacted several AI-specific regulations, but these are more narrowly focused on the way in which AI is used to recommend, amplify, and generate content and information. Japan and South Korea have also enacted more sweeping AI laws, but these are much lighter touch than the EU’s from a compliance perspective. Across major economies like the UK, Canada, Australia, Singapore, and India, no comprehensive AI law is on the horizon. And in the U.S., it’s a non-starter.
Divergent approaches at the U.S. federal and state level. One of the first things President Trump did upon assuming office was to revoke President Biden’s landmark Executive Order on AI Safety. Since then, not only has the Trump administration pivoted away from the prior focus on AI governance and safety, it has repeatedly stated that its overriding AI policy objective is to strengthen U.S. leadership and dominance in AI, in order to seize the economic and national security advantages. Regulations that impede or restrict private sector AI activities—and the patchwork of hundreds of state AI laws—have been framed as a blocker to U.S. global AI dominance that could undermine U.S. competitiveness. Because of this, the Trump administration has attempted to deter and block U.S. states from passing and enforcing state level AI laws. However, its 10-year moratorium on state AI law enforcement was rejected by the Senate in July. A recent Executive Order outlines plans to challenge state AI laws via litigation and funding restrictions instead. Despite this, meaningful state AI laws have been enacted across the U.S. in 2025, including in California, New York, and Texas.
Foundation models remain the target of AI regulations and standards. The most advanced frontier models continue to receive significant regulatory attention, with various laws and standards worldwide specifically focused on foundation models. For example, California’s Transparency in Frontier AI Act (SB53) requires major AI developers to report certain safety incidents and to publish information about their frontier AI risk management frameworks. Similarly, New York’s RAISE Act requires “frontier AI model” developers to implement mitigations to reduce the risk of “critical harm”. And the EU’s regime for GPAI model providers, and the accompanying GPAI Code of Practice, outlines detailed rules for model and training data transparency, copyright compliance, and systemic risk mitigation. Finally, the safety risks of foundation models with frontier capabilities remains a major focus of policy and research efforts, as evidenced by the inaugural International AI Safety Report, published in January.
Increasing focus on how to implement labelling and marking of AI-generated content. Perhaps the most significant regulatory development in China was the Measures for Labelling of AI-Generated Synthetic Content, a regulation which took effect in September. The Measures require “implicit labels” for all AI-generated content (i.e., information embedded within file metadata to enable detectability of AI content), as well as “explicit labels”, such as text or audio notifications, for AI-generated content that might “confuse or mislead the public” (e.g., deepfake videos and AI-generated music). The Measures were accompanied by a mandatory national standard on AI Content Labelling Methods, which provides detailed requirements. Similarly, work is underway to develop the EU Code of Practice on marking and labelling of AI-generated content, with the first draft published in December. According to Merriam-Webster, “slop” was the word of the year, which perhaps highlights the collective fatigue for low-quality, AI-generated content and the inreasing importance of transparency.
Soft law, technical standards, and public-private sector collaboration prevail. The lack of comprehensive, EU AI Act-inspired laws does not mean there has been a lack of domestic AI policy activity. Many jurisdictions continue to prioritise soft law measures, such as producing guidelines and non-binding frameworks for organisations to leverage. For example, the UK Government published a Code of Practice on Cyber Security and continues to support the growth of the AI Assurance sector. Similarly, Singapore’s regulators published guidelines on agentic AI security and launched a Global AI Assurance Pilot and Sandbox, to enable industry generative AI testing. Finally, China released version 2.0 of its non-binding AI Safety Governance Framework. At the international level, industry and policy stakeholders worked together to produce various technical standards, such as the IEEE 3119 Standard on AI Procurement and the ISO 42005 Standard on AI System Impact Assessment. These efforts highlight that organisations have plenty of practical resources at their disposal which they can use to inform their AI governance work.
Lots of discussion, but less tangible action on the international stage. Topics relating to AI policy and governance continued to receive significant airtime on the international stage. However, it is difficult to pinpoint major developments that go beyond well-intentioned discussion and dialogue. The AI Action Summit, hosted by France in February, was broader in focus than its 2023 and 2024 predecessor events, the AI Safety Summit and the AI Seoul Summit. Also, the UN establishing a Global Dialogue on AI Governance ensures a permanent home for such discussions. And China publishing its Global AI Governance Action Plan, and proposing a World AI Cooperation Organisation, highlights the leading role it seeks to play. Perhaps the most concrete development was the entry into force of the Council of Europe’s AI Treaty, which opened for signature in 2024. However, organisations hoping for greater regulatory convergence globally in 2026 are likely to be disappointed.
The U.S.-China “AI race” and the shifting sands of AI export controls. The release of DeepSeek-R1 in January 2025 was a defining moment, as it highlighted the strength and disruptive potential of China’s AI ecosystem, despite the AI chip export controls already in place. DeepSeek, as well as Alibaba’s Qwen model family, demonstrate that China can innovate around hardware constraints through algorithmic efficiency, while reinforcing the Chinese government’s support for open-source AI as a strategic advantage. However, despite China’s strengths in AI talent, research, patents, and open-source AI, the U.S. retains significant leads in private investment, frontier model performance, and global diffusion. The U.S. export control regime continues to evolve. President Biden’s January 2025 Framework for AI Diffusion hardened AI chip export controls and expanded the regime to include model weights. President Trump rescinded it in May, calling it “burdensome”. In December, the Trump Administration permitted Nvidia to export its H200 chips to China, in exchange for a 25% cut of the sales revenue. This pivot from strategic containment to transactional commerce represents a meaningful policy shift.
Global AI Governance in 2025 (free pdf download)
The ultimate AI governance timeline: 70 key milestones in 2025
In scope: AI-related policy, legislation, regulations, official guidance, international agreements and declarations, and technical standards shaping AI governance across major jurisdictions.
Not in scope: Corporate policies, industry standards, AI model releases, technology developments, litigation, enforcement actions, and solely academic or civil society research and advocacy.
January
🇬🇧 UK Government publishes AI Opportunities Action Plan.
🇺🇸 U.S. Department of Commerce publishes Framework for AI Diffusion, tightening AI export controls.
🇰🇷 South Korea formally enacts the Framework Act on the Development of Artificial Intelligence and Establishment of Trust Foundation (AI Basic Act).
🇺🇸 President Trump signs Executive Order 14179: Removing Barriers to American Leadership in AI, directing development of a new AI action plan.
🇺🇸 President Trump revokes Executive Order 14110 on AI safety, signed by President Biden in October 2023.
🌐 The inaugural International AI Safety Report is published, led by Yoshua Bengio and authored by 100+ AI experts.
🇬🇧 UK publishes AI Cyber Security Code of Practice.
February
🇪🇺 EU AI Act provisions on AI literacy and prohibited AI become applicable from 2 February, marking the first compliance deadline.
🇳🇿 New Zealand Government publishes Responsible AI Guidance for the Public Service, covering generative AI use.
🇪🇺 European Commission publishes guidelines on prohibited AI practices under the EU AI Act.
🇪🇺 European Commission publishes guidelines on AI system definition to clarify scope of the EU AI Act.
🌐 Statement on Inclusive and Sustainable AI for People and the Planet signed by world leaders at the AI Action Summit in France.
🇸🇬 Singapore launches Global AI Assurance Pilot, focused on technical generative AI testing.
🇪🇺 European Commission withdraws the AI Liability Directive proposal.
🇬🇧 UK AI Safety Institute becomes the AI Security Institute and shifts focus.
March
🌐 ASEAN publishes Responsible AI Roadmap (2025-2030), setting regional AI governance priorities.
🇺🇸 NIST publishes updated report on Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations.
🇧🇷 Brazil’s AI Bill (2338/2023) forwarded to Chamber of Deputies following Senate approval.
🇯🇵 Japan publishes updated AI Guidelines for Business (Version 1.1).
April
🇺🇸 OMB issues Memoranda on federal agency use and acquisition of AI.
🇪🇺 European Commission publishes AI Continent Action Plan.
🇺🇸 President Trump signs Executive Order 14277: Advancing AI Education for American Youth.
May
🌐 Singapore Consensus on Global AI Safety Research Priorities published following international summit.
🇺🇸 Framework for AI Diffusion rescinded by Trump Administration.
🇨🇳 China State Council deprioritises Draft AI Law, removing it from 2025 legislative plan.
🌍 African Union officially declares the Africa AI Strategy a top priority for the continent.
🇺🇸 TAKE IT DOWN Act signed into U.S. federal law, criminalising non-consensual intimate imagery.
🇺🇸 U.S. House of Representatives votes to pass 10-year state AI law moratorium.
🌐 ISO/IEC 42005:2025 Standard on AI System Impact Assessment published.
June
🇺🇸 Texas enacts Responsible AI Governance Act (HB 149), regulating AI use in the state.
July
🇺🇸 U.S. Senate votes to reject 10-year state AI law moratorium.
🌐 ISO/IEC 42006:2025 Standard published, outlining requirements for bodies providing audit and certification of AI management systems.
🇸🇬 Singapore launches Global AI Assurance Sandbox.
🇳🇿 New Zealand Government publishes Responsible AI Guidance for Business.
🇪🇺 European Commission publishes guidelines for providers of general-purpose AI models.
🇺🇸 White House releases America’s AI Action Plan, outlining 90+ federal policy actions across three pillars.
🇺🇸 President Trump signs Executive Order 14320: Promoting the Export of the American AI Technology Stack.
🇺🇸 President Trump signs Executive Order 14319: Preventing Woke AI in the Federal Government.
🇺🇸 President Trump signs Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure.
🇪🇺 EU publishes General-Purpose AI Model Training Data Public Summary template.
🇨🇳 China proposes World AI Cooperation Organisation at international forum.
🇨🇳 China publishes Global AI Governance Action Plan.
August
🇪🇺 EU formally approves General-Purpose AI Code of Practice.
🇪🇺 Obligations for GPAI model providers become applicable under the EU AI Act from 2 August.
🇺🇸 Trump Administration negotiates deal with Nvidia and AMD over China AI chip exports.
🇨🇳 China releases national AI Plus Plan to accelerate AI integration across industries.
🌐 UN General Assembly adopts Resolution A/RES/79/325, establishing the Global Dialogue on AI Governance and Independent International Scientific Panel on AI.
September
🇨🇳 China’s Measures for Labelling of AI-Generated Synthetic Content take effect.
🇨🇳 China’s mandatory national standard on Labelling Method for Content Generated by AI (GB 45438-2025) takes effect.
🇯🇵 Japan AI Promotion Act takes effect in full.
🇬🇧 UK publishes Trusted Third Party AI Assurance Roadmap.
🇨🇳 China releases AI Safety Governance Framework 2.0.
🇺🇸 California enacts Transparency in Frontier Artificial Intelligence Act (SB53).
🇺🇸 CAISI publishes Evaluation of DeepSeek AI Models.
October
🇸🇬 Singapore publishes Draft Addendum on Securing Agentic AI.
November
🌐 Council of Europe Framework Convention on AI enters into force.
🇨🇳 China updates National Cybersecurity Law with AI-specific provisions.
🇮🇳 India publishes AI Governance Guidelines.
🇪🇺 European Commission announces proposed changes to EU AI Act as part of Digital Package simplification proposal.
🇪🇺 EU AI Act whistleblower tool launched by European Commission.
🇦🇺 Australia establishes AI Safety Institute.
December
🇦🇺 Australia publishes National AI Plan.
🇺🇸 Trump Administration allows NVIDIA to export H200 AI chips to China.
🇦🇺 Australia passes social media age restrictions law, with AI verification implications.
🇺🇸 President Trump signs Executive Order on Ensuring a National Policy Framework for AI, establishing AI Litigation Task Force to challenge state AI laws.
🇺🇸 OMB publishes Memorandum M-26-04: Increasing Public Trust in AI Through Unbiased AI Principles.
🇬🇧 UK publishes progress report on Copyright and AI consultation.
🇪🇺 European Commission publishes first draft of Code of Practice on marking and labelling of AI-generated content.
🇬🇧 UK AI Security Institute publishes Frontier AI Trends Report.
🇺🇸 New York enacts RAISE Act (S6953B/A6453B) mandating transparency for frontier AI models.
🇨🇳 China releases draft regulations for AI-powered anthropomorphic interaction services.






Oliver, superb retrospective. One area I think deserves more attention in 2026: the mathematical infrastructure underneath AI governance.
Most governance frameworks today, including for high-risk AI under the EU AI Act, still rely on periodic assessments and static risk classifications. But if the systems being governed are probabilistic and continuously evolving, the governance itself must become probabilistic and continuous.
I've been exploring this in the context of pharmaceutical auditing, where we face the same challenge: how do you govern a system (a drug manufacturing line, a clinical data pipeline, an AI-powered decision tool) when the underlying risk landscape warps continuously? The answer I'm converging on borrows from differential geometry and Bayesian statistics, treating organizational risk not as a number on a dashboard, but as a shape (a manifold) that deforms over time, and using topological data analysis to detect structural fragility before crises manifest.
The implications for EU AI Act high-risk compliance (August 2026 deadline) are significant: organizations that only do point-in-time conformity assessments will miss exactly the kind of emergent, non-linear risks that the Act was designed to prevent. Continuous Bayesian monitoring may become a regulatory expectation.