In Making Governments Care About AI Regulation, my argument was that politicians move when inaction gets costly — not when they finally grasp existential risk. This piece asks a messier question: what was actually happening on the ground in the years before a big regulatory shift?
I used to believe the clean story — Chernobyl and nuclear rules appear overnight; an AI catastrophe and a global treaty lands next week. These cases are dirtier: stalemate, draft bills in drawers, a scandal on the front page, someone pushing text through an open window. Sometimes it works. Sometimes it doesn’t. Sometimes someone else signs while you’re still fighting.
Thalidomide: a bill stalled in Congress for two years, shoved through by European birth-defect headlines
Thalidomide was a sedative widely used in Europe in the 1950s, including for morning sickness. By 1961, Europe saw babies born with severely shortened limbs. The US regulator was the FDA; the law required safety but not efficacy, and companies could market after 60 days of silence.
Tennessee Senator Kefauver had been fighting since 1959: pharma price-gouging and bogus claims, drugs should prove safe and effective. Lobbying was strong; the bill stalled for two years — but the draft stayed on the table. FDA reviewer Frances Kelsey kept asking for data on the US thalidomide application and refused approval under pressure. America had roughly 17 related cases, not Europe’s mass tragedy.
European headlines dominated in 1961–62. Kennedy honored Kelsey; the public asked why US drug law was so weak. Congress passed the Kefauver-Harris Amendments nearly unanimously in October 1962. Media peak to signature: months — because the bill already existed.
Oil spills and a burning river: Jackson already had NEPA drafted before the EPA existed
1960s America industrialized fast — dirty rivers, smog, highways bulldozing neighborhoods. The EPA did not exist yet.
Carson’s Silent Spring (1962) put pesticides on the map. Anti-freeway movements spread. Washington Senator Henry Jackson wanted a National Environmental Policy Act — major federal projects would need environmental impact statements. His bill hit the Senate in February 1969, before the disasters below.
January 1969: Santa Barbara oil spill, oil on California beaches, days of TV footage. June: Cuyahoga River fire in Cleveland — oily debris burning on the water, Time cover. Pollution became visible in every living room.
Nixon signed NEPA in January 1970; EPA was created that December. Santa Barbara to signature: about eleven months. The myth is the river magically created environmental law — the bill predated the fire; the spill floored the accelerator.
Tobacco: belief shifted in 1964; behavior shifted in the 1990s
Mid-century America: ~40% of adults smoked. Ads sometimes claimed health benefits.
Decades of epidemiology pointed to lung cancer, but industry manufactured doubt from 1953. January 1964: the Surgeon General stated smoking causes lung cancer — front pages nationwide. Smoking rates fell slowly anyway; industry traded weak warning labels for stronger ad limits.
The real turn was secondhand smoke. Flight attendants lobbied from 1969: smoke in sealed cabins was occupational harm. Frame shifted from “you hurt yourself” to “you hurt me” — victims in the room, identifiable. All US passenger flights smoke-free by 2000; bar and restaurant bans spread in the 1990s–2000s. First shock changed belief; second changed behavior — thirty years apart.
2008: voluntary Basel failed first; Lehman made it binding
Basel accords set international bank-capital standards. Basel I (1988) was voluntary; Basel II (2004) let banks use internal risk models — criticized pre-crisis as procyclical and gameable.
Greenspan-era shadow banking ran loose. Working groups met continuously; academics warned — voluntary standards failed under stress.
Bear Stearns, Lehman, ~$700B TARP. July 2010: US Dodd-Frank; near-simultaneous Basel III internationally. Lehman to signature: ~22 months; capital rules fully binding took ~7 more years.
EU AI Act: seven years of legislation; ChatGPT rewrote the foundation-model chapter mid-flight
The EU is a 27-country union, not one government. The Commission drafts; the directly elected Parliament can heavily amend; the Council represents member governments; trilogue negotiates final text behind closed doors — not a US House/Senate fight.
The Act tiers risk: social scoring and similar practices banned; hiring, credit, and similar high-risk uses need conformity assessment and human oversight; GPT-class foundation models got a dedicated chapter after 2022. Fines up to 7% of global turnover or €35M.
GDPR (2018) already showed Brussels can set global standards when the market is big enough. The April 2021 proposal had no “general-purpose model” chapter — ChatGPT didn’t exist. November 2022 ChatGPT arrived; legislators found large models didn’t fit product categories; 2023 negotiations rewrote the foundation-model chapter. Like Snowden 2013 hardening GDPR mid-negotiation: the bill was moving; the shock changed direction and bite.
Parliament passed 523–46–49 in March 2024; law entered force August 2024; August 2026 is the main enforcement cliff for most high-risk obligations. Text on paper ≠ immediate pain — proposal to real enforcement: roughly five to seven years.
FTX: ~$8B gone; US federal crypto law still zero
Crypto exchanges looked like unlicensed stock markets. SEC said many tokens are securities; CFTC said some are commodities; jurisdictional war; years of congressional gridlock.
2020–2022 bull market; FTX ads and political donations everywhere. Drafts existed in Congress — but SEC and CFTC each pushed their lane; nobody threaded a deal.
November 2022 FTX collapse; ~$8B+ shortfall; hearings nonstop. Result: US federal crypto statute = zero. No floor vote. Agency fights, competing bills, SBF’s donations poisoned “now we must regulate” coalitions.
Meanwhile EU MiCA was proposed in 2020; trilogue framework reached October 2022; Parliament passed April 2023 post-FTX. Same industry shock; EU had text ready to sign; US had nobody willing to.
Y2K and Terra/LUNA: two ways shock fails to produce law
Y2K: hundreds of billions spent fixing systems; US law was liability limitation, not comprehensive software regulation. January 1, 2000 — no catastrophe — public narrative: hoax, money wasted; industry pressed down on further duty of care.
Terra/LUNA: May 2022 algorithmic stablecoin collapse, ~$40B gone; huge inside crypto, framed as in-crowd fraud unlike FTX’s depositor narrative. Shock too narrow, no consensus on the table; FTX five months later still produced no federal law.
Mapped to today: do these patterns show up in US and global channels?
Several tracks run in parallel, each mapping to a different historical case.
EU AI Act + Council of Europe AI Convention — closest to the MiCA success path: years of drafting, ChatGPT shock rewrote direction, real signatures at the end. US firms operating in Europe comply anyway. This is today’s only comprehensive, enforceable hard-law track.
US domestic — closer to FTX than thalidomide. No federal comprehensive AI safety law. California SB 53 and New York RAISE require frontier labs to publish safety frameworks, report incidents, protect whistleblowers; federal GAAIA drafts bundle mandatory audits with three-year federal preemption over state law. Cruz tried a ten-year state-law ban in 2025; the Senate killed it 99–1 — state law has political roots, but federal government and industry are fighting who preempts whom. SEC-vs-CFTC agency war here is “federal GAAIA vs California,” plus ~$8.5M Q1 2026 industry lobbying on preemption.
Bletchley → Seoul → Paris → New Delhi summit chain — diplomatic sign-ons, not legislation. Bletchley (2023) and Seoul (2024) on frontier catastrophic risk: like tobacco 1964 — shifts discourse, barely shifts behavior. Paris (2025) pivoted to investment and deployment; China signed the declaration, US and UK did not. New Delhi (2026) leaned Global South and sovereign AI. Output: declarations and voluntary company pledges, not binding law.
AISI network + NIST CAISI — post-Seoul coordination among ~10 countries plus EU on model evals; May 2026 CAISI voluntary testing agreements with DeepMind, Microsoft, xAI, etc. Maps to Basel I/II voluntary layers plus technical annexes to a draft bill: something on the table, some blocking power, no Kefauver-Harris signature.
G7 Hiroshima Process + OECD — voluntary corporate disclosure framework hosted by OECD; GPAI merged into OECD in 2024, 44+ country soft-law hub. Like Basel committees meeting continuously: standards written, adoption voluntary.
UN track — Global Digital Compact, independent scientific panel (40 experts, advisory only), first Global Dialogue on AI Governance July 2026 in Geneva. Maps to research and draft accumulation before NEPA — no binding enforcement yet. Centers Global South and development; diverges from G7 frontier-model safety framing.
APEC, REAIM, etc. — APEC’s first digital/AI ministerial (2025) on regional connectivity and digital divides; REAIM handles military AI separately — US and ~60 countries backed a blueprint; China attended but did not endorse. Military and civilian split tracks, matching UN’s non-military scope.
| Historical pattern | Closest today | Fit |
|---|---|---|
| EU MiCA / AI Act (draft ready, shock, sign) | EU AI Act, Brussels effect | High |
| US FTX (big shock, federal law zero) | No federal US AI safety law; Paris sign-on split | High |
| Basel voluntary → post-crisis coercion | G7/OECD/CAISI/RSP voluntary layer | Medium — voluntary yes, coercion not yet |
| Thalidomide (draft + gatekeeper) | State bills + AISI evals/whistleblowers | Medium — gatekeeping, much weaker |
| Tobacco two waves | Summit discourse vs deepfakes/bills/child harm | Low — politics still in wave one |
| NEPA (bill before disaster) | UN panel, Global Dialogue, procurement-assessment drafts | Low — research yes, binding enforcement no |
| Y2K (nothing broke → “unnecessary”) | Industry pushback if voluntary governance works | Watch |
| Terra (shock too narrow) | In-crowd AI incidents without voters | Depends on next shock’s breadth |
International talk is mostly voluntary standards, eval coordination, and sign-on politics; real legislation today is mainly Brussels and Sacramento. US federal layer still looks pre-FTX: drafts, summits, agency fights, no floor vote — Basel I on the table, Dodd-Frank not in sight.
Implications for AI safety governance today
State transparency law, GAAIA drafts, METR-style eval language for statutes, incident-reporting formats — today’s Kefauver bills. Public eval failures, whistleblowers, regulators slowing risky deployments — Kelsey-style blocks. “Assess before federal subsidy/procurement” needs text before the first blackout headline.
RSP, CAISI, and G7 corporate disclosure are already running — Basel I. Often insufficient under pressure, but with templates Lehman-to-Dodd-Frank can compress to ~22 months; without templates you get Terra plus FTX.
Summits and open letters shift belief, not behavior (1964 Surgeon General). Election deepfakes, child harm, and power bills are secondhand smoke — voter-facing. Existential-risk argument alone won’t carry a state-law coalition.
Federal law can still fail to arrive — FTX already showed that. Brussels and California legislate first; global firms align; Washington copies or preempts with something weaker. “Harmonization” bundled with liability caps is the Y2K playbook.
If governance works, someone will say it was never needed. Record the counterfactual — what would have happened without evals and disclosure — or “nothing broke” becomes “it was never going to break.”