Through 2025, AI governance frameworks proliferated across standards bodies, national governments, and U.S. states without meaningful harmonization. The International Organization for Standardization's ISO/IEC 42001, the first international standard for AI management systems, published in December 2023, gained adoption momentum through 2025 as companies sought third-party certifiable frameworks to demonstrate responsible AI practices to customers and regulators, while the U.S. National Institute of Standards and Technology continued refining its voluntary AI Risk Management Framework, first published in January 2023.
The mechanism producing fragmentation was political rather than technical: President Trump rescinded President Biden's October 2023 AI executive order within days of taking office in January 2025, replacing the prior administration's emphasis on safety testing and reporting requirements for frontier models with a new 'AI Action Plan' released in July 2025 that prioritized deregulation, domestic AI infrastructure buildout, and competitive posture against China over the safety-testing mandates the Biden order had emphasized. The federal AI Safety Institute, established under Biden, was renamed the Center for AI Standards and Innovation (CAISI) under the new administration, with a correspondingly shifted mission emphasis.
U.S. states moved into the gap federal ambivalence left open: Colorado passed a comprehensive AI Act in 2024 regulating high-risk AI systems in employment and other consequential decisions, then delayed its effective date amid industry lobbying and implementation concerns, while California, Texas, and other states advanced their own, frequently conflicting, AI-specific legislation on deepfakes, algorithmic discrimination, and chatbot disclosure requirements — producing exactly the patchwork compliance landscape federal preemption advocates had warned against.
Large AI labs and enterprise adopters bore the direct cost of fragmentation, maintaining separate compliance programs for EU AI Act obligations, a shifting U.S. federal posture, and a growing list of state-specific requirements, while smaller AI startups without dedicated compliance teams disproportionately struggled to track which rules applied to which product features in which jurisdiction. Civil society and safety-focused researchers argued the rescinded Biden-era reporting requirements had provided the only mechanism forcing frontier labs to disclose safety testing results to the government at all, a gap the AI Action Plan did not directly replace.
Coverage tracked each new framework or executive order largely as a standalone announcement — a new standard here, a rescinded order there — rather than emphasizing the more consequential underweighted story: that AI governance in 2025 had become explicitly partisan and administration-dependent in the U.S. in a way that few other technology regulatory areas were, meaning compliance planning for AI companies now required modeling electoral outcomes as a material business risk, not just technical and legal requirements.
The Paris AI Action Summit in February 2025, a rebranding of the prior year's UK-hosted 'AI Safety Summit' in Bletchley Park, reflected the same shift in emphasis internationally: the U.S. and U.K. both declined to sign the summit's closing declaration on inclusive and sustainable AI, a departure from the more unified safety-focused messaging of the 2023 Bletchley summit, signaling that international coordination on AI governance was fraying along the same lines as domestic U.S. politics.
NIST AI RMF, EU AI Act obligations, executive orders, and corporate AI boards formed a patchwork governance stack. Audits, model cards, and red-teaming professionalized. The risk is checkbox compliance that misses deployment context.
International forums struggle to define compute thresholds and dual-use lines while labs ship weekly. Insurance markets experiment with AI liability products. Governance frameworks are becoming infrastructure: imperfect, necessary, and permanently lagging capability.
Paper frameworks fail when procurement ignores them; living frameworks need auditors with teeth. International alignment stalls on dual-use definitions while capabilities compound. Governance is now a race against deployment habits, not a seminar after the fact.
Boards added AI risk to enterprise risk registers beside cyber and climate. The useful frameworks are the ones tied to kill-switches and procurement gates, not the ones that only produce PDF principles.
The lasting inheritance is a governance landscape best understood as a compliance market rather than a coherent regulatory regime: companies now purchase AI governance software, hire dedicated compliance staff, and pursue voluntary certifications like ISO 42001 not because a single binding law requires it everywhere, but because the fragmented, shifting patchwork of frameworks makes voluntary standardization cheaper than tracking every jurisdiction's requirements individually — governance by certificate rather than by uniform statute.
Century Signals note: NIST AI RMF; EU AI Act; major national AI policy documents; corporate governance reporting. Editorial judgment about what still structures the present — not a comprehensive history.
