The global contest over artificial intelligence is often described as a race for supremacy among states, among AI companies, and even between states and those companies. But it is also increasingly a competition among governance models. Three now dominate the democratic world: the European Union’s rights-centered regulatory state, the United States’ innovation-first market approach, and a middle way first reflected in Japan’s adaptive response and, most recently, the Canadian AI strategy unveiled in June 2026.
It is tempting to arrange these models along a single axis, from heavy regulation to light-touch innovation, with Canada and Japan near the midpoint. That is how the comparison is ordinarily drawn, and we reproduce it below for the sake of later contrast. But that scheme measures the wrong thing. Whether a jurisdiction has a comprehensive statute, and how heavy its compliance burden looks, is a poor guide to how and to what extent AI is actually governed.
The more revealing question is not how much each state formally regulates AI, but rather how it exercises power over AI—in particular, whether that regulatory power is itself constrained by law. Is government control of AI rule-bound, transparent, and open to review; or is it discretionary, informal, and exercised at executive speed? Drawn on that basis, the axis looks quite different, and Canada’s contribution looks more interesting than the language of “balance” suggests.
A second, related question concerns risk. Each governance model reflects which specific AI risks they perceive to be of greatest concern, be they threats to individual rights, national security, or public trust. But, in so doing, they all reveal a considerable blindness to the many other significant risks posed by AI, not least of which is the potentially existential risk posed by the development of artificial general intelligence (AGI).
What makes Canada’s experiment significant is not where it sits on the regulatory spectrum, but that it gestures toward the principle that ought to be at the center of AI governance, which is the rule of law. The state power exercised to govern AI must itself be governed by law. That principle matters most where both the risks and the stakes are highest, such as with the governance related to the development of AGI. While all the models fail to address many of the more serious risks posed by AI, and the most extreme risk posed by AGI in particular (middle powers have little control over that risk in any event), the new Canadian strategy nonetheless points to the principle that should be adopted globally for AI governance: responsible, rule-of-law driven regulatory frameworks. We explain why the risk posed by AGI should be central to all governance models, and why a rule-of-law approach is best suited for addressing that risk. Ultimately, managing that risk will require the development of a comprehensive, treaty-based regulatory framework, but that prospect remains highly challenging for a variety of reasons—until then, more states ought to model themselves on the Canadian approach to AI governance.
The Emerging AI Governance Spectrum
The three major democratic approaches, represented here by four countries, are conventionally visualized as a continuum, represented in the following table:
| Governance Dimension | European Union | Canada | Japan | United States |
|---|---|---|---|---|
| Core Philosophy | Rights protection | Balanced innovation and fostering public trust | Innovation-first “trustworthy AI” | Innovation and competition |
| Primary Goal | Prevent societal harms and protect individual rights | Build trust while accelerating adoption of AI | National revitalization through AI | Maintain technological leadership |
| Primary Risk Sensitivity | Harm to individual rights | Erosion of public trust in AI and AI governance; dependence on foreign AI technology | Stagnation; falling behind in AI development | Loss of national-security primacy |
| Regulatory Style | Comprehensive statutory framework | Targeted legislation plus non-binding policy instruments | Framework statute plus soft law | Sectoral and fragmented – between state and federal, and among executive agencies |
| AI-Specific Law | Comprehensive AI Act (with enforcement mechanisms) | No comprehensive law; target legislation planned, but uncertain | Framework AI Promotion Act (no penalties) | No comprehensive federal AI law |
| Enforcement Mechanisms | Legal obligations and fines | Selective regulation and oversight bodies | Guidance and “name and shame” | Executive and procurement leverage |
This table captures real and meaningful policy differences. But it is better read as the map we mean to complicate than a settled taxonomy, for it foregrounds the variable we think matters least — regulatory intensity — and obscures the one that matters most: the quality of the power behind the rules, and whether that power is itself bound by law. We flesh out these approaches, and then offer an alternative map, below.
The European Model: Rights Before Innovation
The European Union’s Comprehensive AI Act — Regulation (EU) 2024/1689, a binding statute that took effect in 2024 and applies directly across every member state — is the most ambitious attempt yet to regulate artificial intelligence comprehensively. Primarily focused on protecting individual rights against risks posed by AI, it sorts AI systems into prohibited, high-risk, limited-risk, and minimal-risk tiers, with obligations on the AI developer rising as the threat to health, safety, and fundamental rights rises. As such, it aims to protect against harms to privacy, equality, democratic integrity, labor rights, intellectual property, and the like. Protection of fundamental rights is the organizing principle.
The clarity provided by such a legislative scheme has the advantage of creating (relative) legal certainty for firms, regulators, and citizens, and accountability before harm occurs, through mandatory risk management, transparency, and human oversight. Its reach extends past Europe’s borders through what Anu Bradford termed the “Brussels Effect”—firms adopting EU standards worldwide rather than running multiple compliance regimes. But it also imposes costs in the form of heavy compliance burdens and a drag on innovation such that Europe has become a rule-maker without becoming a maker of the systems it rules. Nor is the system as fixed as it purports to be. Under pressure for regulating too much and too quickly, as well as a delay in the establishment of common standards, the Commission has turned to industrial policy and, through its Digital Omnibus, begun to soften and delay parts of the Act even before they take full effect.
The American Model: Innovation, Security, and Primacy
The United States is usually placed at the opposite pole, given that it has no comprehensive AI statute, and its federal posture, expressed mainly through executive orders, prizes private-sector innovation and removal of regulatory friction. But the portrait of a market “free from safeguards” is misleading in two respects.
First, Washington does impose constraints, though more systematically on the government itself rather than on the market. Where the federal government builds, buys, or uses AI, the Office of Management and Budget (OMB) directives require risk management for “high-impact” systems and the abandonment of deployments whose risks cannot be mitigated. What is missing is a law or policy framework governing private actors, though even here the field is contested. In the vacuum left by Congress, states have enacted rules, such as Colorado’s anti-discrimination statute and California’s frontier-model transparency law. Indeed, the federal executive, unable to persuade Congress to pre-empt these state laws, has established a Justice Department task force to try to challenge them in other ways.
Second, the United States is not indifferent to AI’s risks, rather it is focused on different risks. Its principal concern is AI primacy, animated by anxiety that a rival, above all China, will seize the commanding heights of the technology. This was reflected in both the White House’s AI Action Plan and its related Executive Orders of summer 2025 (which we wrote about late last year), and the more recent Executive Order 14409 issued in June 2026, which focuses on the balance between innovation and national security. Nearly every distinctive feature of the American approach, from export controls on advanced chips and models to the framing of AI policy as a contest for “global dominance,” follows from that fear of losing primacy to China.
The Trump administration’s recent confrontation with Anthropic captures both the risk-sensitivity and the nature of Washington’s exercise of control. When the company declined to let its models be used for autonomous weapons or domestic mass surveillance, the government directed federal agencies to stop using its technology and moved to brand it a national-security “supply-chain risk.” Similarly, when the administration determined that Anthropic’s Mythos model would be too dangerous in the wrong hands, a separate export-control directive ordered Anthropic to block the model from foreign users. The United States was hardly powerless for want of a statute. It wielded enormous coercive power through procurement and export levers, at executive speed and discretion. This, rather than the presence or absence of legislation, is the feature that ought to organize the comparison.
Similarly, the recent Executive Order 14409 creates a review process whereby the government is to be provided advance access to AI models designated as “covered frontier models,” primarily for review for purposes of safeguarding against risks to the cybersecurity of critical infrastructure. While ostensibly voluntary, it is once again the deployment of executive power to exercise control over elements of AI development that relate to U.S. concerns. For AI risks that do not come within the scope of these primacy and national security concerns, the government does tend to rely on voluntary governance structures, such as the National Institute of Standards and Technology’s AI Risk Management Framework.
Canada’s New Strategy: Building the Bridge
Canada’s “AI for All” strategy, issued in June 2026 following a failed effort to pass comprehensive AI legislation, is a deliberate attempt to avoid the perceived excesses of both poles. It has a number of thoughtful features, and is implicitly grounded in a principle that we think makes the approach truly significant. Namely, it reflects a good grounding in rule-of-law, with clear criteria and mechanisms for reviewability. It remains vulnerable, however, to limited enforcement mechanisms and insufficient application to the private sector.
Canada’s hybrid strategy consists of a variety of mechanisms, including targeted legislation, public investment, safety institutions, and voluntary codes. These are organized around three principles: building trust, creating opportunity, and reinforcing sovereignty.
The emphasis on sovereignty is common to every jurisdiction here, but what differs is its inflection. For the United States, sovereignty means primacy; for the European Union, it means strategic autonomy from American platforms; for Canada and Japan, it seems to mean something more defensive—the avoidance of dependence, the refusal, as Carney put it at Davos, to be “forced to choose between hegemons and hyperscalers.” Canada’s investments in domestic compute and Canadian-owned intellectual property are the middle-power version of a preoccupation all four share.
More distinctive is Canada’s concern with the erosion of public trust and democratic legitimacy. Ottawa’s strategy returns repeatedly to public confidence in institutions that increasingly use AI, to the integrity of democratic processes against synthetic media, and to the danger that Canadians might come to regard the technology as being used against them rather than for them. That sensitivity explains both the rhetoric of trust and the targeted interventions against specific harms such as non-consensual deepfakes.
It would be wrong to conclude that the demise of the AI legislation left Canada without binding governance. For the government’s own operations, for instance, the Treasury Board’s Directive on Automated Decision-Making (which applies across the federal government) is anchored by a mandatory Algorithmic Impact Assessment, which governs the government’s automated administrative decisions affecting individuals and requires transparency, recourse, and human oversight. But as with the United States, this binds the state’s own use of AI, not the private market, leaving the European Union as the outlier in regulating the market ex ante.
That said, the Treasury Board’s Directive matters most for another reason: namely, that it is a rule-bound instrument, built on transparently published criteria and reviewable procedures. These include requirements that the government must meet when conducting and implementing algorithmic assessments, mandatory notice before any AI-generated decisions, as well as explanations and reasons for such decisions, and establishing and implementing various quality assurance metrics. These are the hallmarks of a rule-of-law grounded framework for regulating AI, and it is a strong start. Such rigorous governance needs to be extended also to the AI industry and the private entities employing AI.
The strategy’s advantages are modest but real, and it seems capable of adapting faster than the EU’s approach, and spares its private AI firms the EU’s heavier compliance costs. But its vulnerabilities are just as real, and enforcement is the central one. Canada’s framework currently has not designated a clear oversight authority and has established no specific enforcement mechanisms for the private sector. Rather, its enforcement relies on voluntary compliance. Where Europe’s obligations carry penalties and America’s preferences ride on strong market mechanisms and executive power, Canada’s softer obligations sit atop a smaller industrial base. Consequently, voluntary mechanisms may hold for the moment while under government and public scrutiny, but may give way when commercial and market pressures rise. As Canadian scholars have argued, transparency does not guarantee meaningful accountability, in the sense that there can be increasing disclosure requirements regarding AI operations without anyone having the capacity to question, challenge, or control the increasingly automated decisions affecting society. What is more, as we return to below, for certain forms of AI-related risk, soft-law voluntary measures are simply inadequate. Nonetheless, Canada appears to be taking steps towards advancing a framework that is centered in rule-of-law principles.
The Japanese Model: Innovation Without Prohibition
Japan reached a position close to Canada’s on the traditional spectrum depicted above, but from the opposite direction, and in ways that distinguish it from Canada on our revised spectrum. In 2022, it published an AI Strategy, and in May 2025 it enacted its first AI statute, the Act on Promotion of Research and Development and Utilization of AI-Related Technologies. This statutory approach might seem to place it near the European end of the spectrum. But in substance it is a framework law which states principles, creates an AI Strategic Headquarters chaired by the Prime Minister, and mandates an AI Basic Plan, adopted in December 2025 under the banner “Japan Rebooted through Trustworthy AI.” It imposes no prohibitions and no penalties, relying instead on non-binding guidance, advice, and the public naming of laggards. Binding enforcement is left to existing law on data and copyright. Its stated ambition is to facilitate local AI development, to assist Japan in becoming the friendliest country in the world in which to build and use AI.
The risk the Act is explicitly focused on is not really about AI at all. It is the fear of decline resulting from an aging society, two stagnant decades, and the prospect of missing out on the one general-purpose technology that might reverse the trend. Tokyo’s dominant fear is not the danger of AI but the danger of failing to adopt it, and its statute is built to facilitate the development and deployment of AI rather than to restrain it.
Here again, therefore, the conventional categories are misleading. Japan has the comprehensive legislation the United States lacks yet exerts lighter pressure on private actors than the American executive mechanisms. Nor can “soft law” like this be the primary feature that links Canada and Japan into a category of their own, since the United States leans on soft law too, most prominently the National Institute of Standards and Technology’s voluntary risk-management framework. And, indeed, as reflected in our reformulated spectrum below, Canada and Japan diverge, as Japan has not adopted the kind of rule-of-law approach that Canada has—with transparency, accountability, and quality assurance metrics established in law that constrain government action. Their real kinship is that both are capable middle powers that have made AI adoption and domestic capacity a high priority, reaching for coordination and investment rather than outright prohibition. Japan’s norm-entrepreneurship abroad, through the G7 Hiroshima process, echoes the bridge-builder role Ottawa now claims.
The Differing Responses to the Risks of AI
Each approach, as we have seen, answers to the particular AI risk its jurisdiction most fears, and each of these fears, however reasonable, is somewhat parochial. It is a response to the danger that seems most legible to that polity or is most salient in the moment, while leaving many of the more serious risks entirely unaddressed, some of which pose societal-level threats.
Most striking is the complete failure, not only of the four approaches discussed here but indeed most AI governance models more generally, to address the one risk that arguably should be central to all governance models—namely, the enormous risk posed by the prospect of AGI being developed in conditions that do not ensure its complete containment and control. That is, the danger posed by the emergence of an entity that is more intelligent than us, connected to the world’s infrastructure, capable of directing agents in the real world, and possessed of objectives that differ from ours. As we have explained in more detail elsewhere, many of the leading researchers building frontier systems increasingly warn of the catastrophic, even existential, risk such systems could pose for humanity.
One may think that this danger is remote, but given the magnitude of what is at stake, the precautionary principle argues for taking it seriously. Yet none of the four AI governance models purports to govern the development of frontier AGI. The European Act gestures at it, through extra obligations for “systemic-risk” models, but those provisions are thin and are now being pared back in any event under AI arms race pressures. The United States treats frontier capability as a question of who controls it, not whether it should be constrained—though the fact that the recent Executive Order 14409 calls for the establishment of metrics for designating frontier models, and government review of such models, is a step in the right direction. But even here, the concern is more with cybersecurity than the prospect of corporate entities developing AGI in insufficiently secure environments. Canada’s safety institute nods toward advanced-AI risk, but its strategy’s center of gravity is trust and adoption. Japan, by design, is least concerned of all.
Part of the problem, in our view, is the tendency to separate the risk posed by AGI from all other AI-related risks, and to think of it as both a speculative and distant-future threat. But as Yudkowsky and Soares (among many others) warn us, the risk is inherent in the current and largely unregulated efforts to develop so-called frontier models, and the emergence of a general intelligence model that we simply cannot control. There remain many questions about the recent reporting about an OpenAI experimental model escaping a sandbox and hacking into a Hugging Face system (among others), but the basic facts are undisputed. Less than two weeks later, Anthropic reported that it too had an experimental model escape a sandbox and hack into external systems. These events should be an enormous wake-up call. All work on frontier models that pose any risk of developing emergent qualities should be conducted in the most secure facilities, and ideally be formally regulated. Yet the debate these events (along with the release of the Chinese open-source model Kimi) have prompted in Silicon valley is over whether there should be less regulation of open systems.
In our view, the approach to frontier models and the risk of AGI is somewhat analogous to how we treat the study and handling of dangerous biological agents in designated secure laboratories. While there is no binding international treaty (excluding the biological weapons convention, which is focused on a different set of issues than those we reference here), the WHO has set standards that have received broad buy-in among states, and those standards have been widely implemented at national levels through both law, regulation, and soft-law instruments, which together ensure that work on the most dangerous pathogens is conducted in designated laboratories that meet specified safety standards, with increasing levels of security depending on the estimated risk posed by the pathogen in question.
The features that make each of the four governance models discussed here effective against the risk they fear do little against a danger that respects no jurisdiction and arrives, if it arrives, all at once and with catastrophic consequences. The United States is the most important actor in addressing this risk, yet its approach so far does not reflect a serious consideration of this risk. In both its response to the Anthropic conflict with the Department of Defense, and in Executive Order 14409, the Trump Administration has been more focused on the potential risk frontier models pose to cybersecurity than other serious risks, and again reached for executive branch mechanisms to establish voluntary guidelines that can be enforced through the manipulation of market mechanisms, rather than hard law constraints enacted by the legislature. With American companies being most likely to cross the Rubicon of developing AGI, and the United States under Trump being the actor most willing to wield decisive executive power, the fact that the American governance approach almost entirely ignores this risk should be cause for particular alarm. Even AI companies are sounding the alarm—at the end of July leading scientists from Anthropic, OpenAI, Google, and Deep Mind, joined by 1,300 others, issued a statement calling upon the U.S. government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.”
A Principled Governance Model for Middle Powers
At Davos in January 2026, Carney urged the world’s “middle powers” to combine their weight against the return of great-power rivalry and the erosion of the so-called international rules-based order. Canada’s AI strategy belongs to that project, and Japan’s approach also shares in this resistance to hegemonic control of the technology, even if Tokyo would likely not characterize it as such. Most states are neither regulatory nor technological superpowers, but they need to protect their citizens from certain AI harms without smothering innovation, and to encourage AI innovation without surrendering accountability. Canada and Japan are examples of middle powers developing two diverging paths to thread this needle. These two are not the only middle powers charting a new course: the United Kingdom and Australia have each declined a comprehensive statute in favor of principles applied through existing regulators, and emphasized the facilitation of innovation, which places them closer to the United States on the axis of intensity while leaving open the more telling question of where they fall on ours (though, in late-breaking news, the Australian government announced a shift to a more regulatory model in mid-July).
Returning to Canada and Japan, neither country has expressly articulated a unifying principle that might ground this middle way and give it normative authority. We think there is one, though Japan’s approach does not yet embody it and the Canadian strategy states it only obliquely: that is, it provides an AI governance model grounded in the rule of law. This deserves to be highlighted, as the rule of law ought to be central to all AI governance everywhere.
Recall the governance spectrum we outlined above. The conventional scheme asks how much each model regulates, and answers with reference to statutes and compliance burdens. But that is misleading. What separates these systems is not the quantity of regulation but the quality of the power behind it — whether the state acts through rules that are public, prospective, and reviewable, or through discretionary power exercised at will and contested only after the fact. On that measure a different map emerges:
| Dimension of Lawful Governance | European Union | Canada | Japan | United States |
|---|---|---|---|---|
| How state power is exercised | Binding ex ante rules | Procedural rules (public sector) | Administrative guidance | Executive/procurement discretion |
| Transparency of criteria | High (published obligations) | High (published criteria) | Moderate | Low (ad hoc directives) |
| Reviewability and recourse | Built in, before deployment | Built in (recourse, oversight) | Limited | After the fact, via litigation |
| Position on the axis | Rule-bound | Rule-bound (where it governs) | Soft/coordination | Discretionary |
On this map, it is the United States that sits at the troubling end of the spectrum, and Canada that keeps company with the rule-bound regimes. Not only that, but it is rule-bound as a matter of expressed principle and commitment to the rule of law. That, and not “balance,” is what makes the Canadian experiment significant. Indeed, its promise is not that it splits the difference between regulation and innovation, but that it points toward a way of governing AI that remains lawful — transparent, accountable, and constrained — even as the technology’s power grows.
Conclusion
This grounding in the rule of law and all the principles that accompany it are ultimately what may mitigate AGI concerns. Why? Because the governance of catastrophic risk demands credible ex ante binding commitments. The AGI race gives every actor, including state governments, reason to discount precaution and safety. Governance based on discretion and fiat, or voluntary industry guidelines, cannot bind against the risks thus created, for discretion and guidelines are revised or sidelined precisely when the stakes are highest. Only public, prospective, independently enforced rules can hold an actor to restraint against its own interest. The rule of law is the one well-established and trusted democratic principle designed to constrain the most powerful, including the sovereign itself. A rule-of-law model is no guarantee against catastrophe — none of these regimes yet governs frontier risk seriously — but it is one that is not only consistent with democratic values but is most likely to successfully contain such risks.
Canada and other middle powers cannot regulate the laboratories where AGI and other frontier systems will be built, because those companies are neither registered in or based in their territories. Thus, their rule-bound instruments cannot meaningfully address the risks posed by such models. But the significance of Canada’s new strategy lies instead in being an approach that can and should be emulated, particularly in terms of its reliance upon the rule of law as a central principle of AI governance. Europe could realistically develop a governance regime that addresses the AGI risk seriously and in a transparent rule-bound fashion—and as the “Brussels effect” has played out in other digital domains, this could impact the adoption of such models in the states that count. As we have argued elsewhere, and echoed in the recent statement by AI engineers, effective governance of this risk must ultimately take the form of an international treaty or of global institutions — and it is rule-of-law models, not discretionary ones, on which such instruments can be built. But until then, if more countries were to emulate the Canadian approach, and if Canada itself were to regulate the right risks, it would be a step in the right direction.






