Years ago, I won an argument with a sentence I knew was incomplete.
I wrote briefing notes for people with no time to read the documents underneath them. That week it was a regulator's report — long, careful, thick with the word may. I needed one line, and page thirty-four had a good one. I quoted it exactly, in full, with the page number, because I am not a monster.
Three pages later, the same report qualified that line almost out of existence. I read that paragraph. I did not include it. Nobody asked, because nobody else in the room had opened the file, and my note went up with the strong half in it while the qualifier stayed on page thirty-seven.
Every word I wrote was true. That is what made it a small dishonesty rather than a large one, and it is why I still think about it at inconvenient hours. You do not have to lie to mislead a room. You only have to be the one person who read the whole thing.
I bring it up because the international AI policy conversation spent 2026 doing this at scale, in public, to the same document.
The rarest object in AI policy actually exists now
For a decade the argument about artificial intelligence has run without a shared set of facts — every side with its own studies, its own worst case, its own definition of risk. Then, published on February 3, 2026, the second International AI Safety Report landed: two hundred and twenty-one pages, over a hundred contributing experts, chaired by Yoshua Bengio, who won a Turing Award for building the techniques he now spends his time worrying about.
It was commissioned by the UK government, with a secretariat inside the UK AI Security Institute, and its expert advisory panel has a precise composition: 29 nations, the UN, the OECD, and the EU each nominated one representative. Not "thirty-odd countries" — the number in most coverage folds three international organizations in with the nation states. That shape matters later.
The findings are hedged with real care. Capabilities improve fast but remain, in the report's word, "jagged" — leading systems ace hard problems and fail easy ones. AI agents (systems that take actions rather than just produce text) raise the stakes because they act autonomously, making it harder for humans to intervene before failures cause harm. Safeguards have improved, and yet attackers still succeed at a moderately high rate.
On the risk everyone wants a headline about — losing control of these systems — the report is scrupulous in a way almost nobody reproduced: "Current systems lack the capabilities to pose such risks, but they are improving in relevant areas such as autonomous operation." Two halves pointing opposite ways. Notice how easy it would be to use either one alone.
It also names the trap it was written for — an "evidence dilemma": act too early and you entrench a bad rule, wait for conclusive data and the harm has already happened.
A hundred experts, a negotiated map of what is known and unknown, and — deliberately — no policy recommendations attached. In a field this loud, that is close to a miracle. Now watch what people did with it.
Before anyone else picked a half, the report picked one
Start with the uncomfortable part, since it is the one I would want pointed out to me.
The 2026 edition made its own scope narrower than that of the 2025 Report, setting aside bias, environmental impacts, privacy and copyright to concentrate on "emerging risks" at the frontier of capability. The stated reason is defensible — it complements other assessments, including the UN's scientific panel. But the definition of "AI risk" in the world's flagship AI risk document got smaller, and the topics that fell out are the ones affecting the most people today.
Then read the three forewords in the same PDF, the most instructive ninety seconds available on this subject. The UK minister reads the evidence as an adoption story: a shared understanding will "build trust, enable adoption and pave the way for AI to deliver prosperity for all." India's minister reads the identical document as a warning about capacity: "Our global risk management frameworks are still immature, with limited quantitative benchmarks and significant evidence gaps." Bengio hedges at the door, hoping to improve our understanding of "what may be the most significant technological transformation of our time."
Three forewords, one report, three different halves — on consecutive pages, inside the covers, before a single outside reader gets near it.
The year everybody took their half and went home
The report landed sixteen days before governments met in Delhi.
Washington took the strongest half and rejected the frame entirely. On February 20, 2026, from the summit podium, White House science director Michael Kratsios said the United States would "totally reject global governance of AI", and that too many international forums maintain "a general atmosphere of fear" and "ideological, risk-focused obsessions." That is not a quibble with the findings — it is a rejection of the whole category the report belongs to.
That posture was already policy. A December 2025 executive order directed the Attorney General to stand up an AI Litigation Task Force whose sole responsibility shall be to challenge State AI laws, and told Commerce to publish a list of "onerous" state laws due by March 11, 2026. The states, unimpressed, passed more than 100 new AI laws this term anyway — 109 by one count as of July 1, 2026, across 29 states.
London commissioned the report and then legislated nothing. The government that paid for this document, whose own chief scientific adviser sits on its panel, held its State Opening of Parliament on May 13, 2026 — and an AI bill was conspicuously absent from this year's King's Speech, despite a 2024 manifesto pledge to introduce binding regulation on the most powerful models.
Brussels used the year to defer. In May 2026 the EU institutions agreed politically to postpone the AI Act's high-risk obligations — deferred to December 2, 2027 for standalone systems, to August 2, 2028 for AI embedded in regulated products. Precision matters here, because much of the coverage lacked it: those changes take legal effect only on formal adoption and publication. The agreement to defer is real; the deferral is not yet law.
And the labs quoted their own half. The Future of Life Institute's summer 2026 index — FLI's own assessment and grading, not an audited finding — reports that Anthropic, OpenAI, Google DeepMind and Meta have weakened or voided pledges to pause unilaterally if red lines are approached. In FLI's scoring, existential safety is the industry's worst domain: no company exceeds a C-.
Notice what is not on that list: anyone engaging with the whole of it. The same document was on every desk, and each of them took the part that fit what they already meant to do. That is the whole problem.
The strongest argument against everything I have just said
My framing has three soft spots, so let me press on them.
A shared baseline is not automatically a neutral one. Writing in Tech Policy Press in October 2025, Eryk Salvaggio argued that in this field peer review of claims by corporations building these products "is considered optional," and that skepticism about capability claims gets treated as impolite, even political. If that is right, a consensus document is not correcting for industry framing — it may be laundering it into something that looks like neutral science.
Risk language cuts both ways. The AI Now Institute argued in April 2025 that an unsubstantiated arms-race narrative and speculative existential-risk claims were being used to justify the accelerated rollout of military AI systems. Which inverts my assumption neatly: more risk evidence does not reliably produce more caution. Sometimes it produces more urgency to get there first.
And the experts never fully agreed anyway. Reporting on the series' interim edition in May 2024 noted the lack of universal agreement among AI experts on current capabilities, and the 2026 edition says as much about itself: researchers cannot reliably predict when specific capabilities will emerge, and experts disagree about whether exponential increases in inputs will continue.
So the honest version of my thesis is narrower than the one I started with. The baseline is not a set of agreed conclusions. It is an agreed map of the uncertainty — rarer and more useful, and far easier to quote selectively, because such a map has a strong half and a weak half on every question.
Watch it happen with biological weapons. Developers, the report says, "could not exclude the possibility that these models could assist novices." One camp turns that into AI now helps amateurs build bioweapons. The other turns it into no evidence of uplift was found. Both misquote a sentence saying, precisely, that a specific danger could not be ruled out.
The country on the panel list that went home and wrote rules
Here is the part that rearranged my thinking, and it starts with a list of names. Read the report's published expert advisory panel membership table and you find twenty-nine countries plus the EU, the OECD and the UN. China is on it, represented by Yi Zeng of the Institute of Automation at the Chinese Academy of Sciences, who also sits on the UN's high-level advisory body on AI. The United States does not appear on that page at all. Separately, TIME reported that, unlike the previous year, the United States declined to throw its weight behind it, which Bengio confirmed.
Two facts, kept apart on purpose: the published table does not list the United States, and the US declined to back the report. Nobody was thrown out of anything — Washington endorsed the summit's non-binding declaration even while opposing formal global AI governance. But the shape of the room is not what most people assume.
So what has Beijing done with its copy? Rather a lot.
Guidance first. In September 2025 China released its AI Safety Governance Framework (Version 2.0), a national-standards document prescribing explainability, adversarial training, watermarking and kill switches across the whole lifecycle — over thirty measures, and emphatically not a statute. The fairest description is an instruction manual.
The binding layer is older. The Interim Measures for the Management of Generative AI Services took effect on August 15, 2023, issued by the Cyberspace Administration of China with six other regulators, requiring security assessments and algorithm filing for services with public opinion influence. Carnegie's Matt Sheehan put it bluntly in July 2026: China has rolled out the world's most extensive and detailed regulations on AI, including mandatory registration and testing of models — while cautioning that watching a government regulate "is not a guarantee that they will take action."
The institutional layer is stranger: China's answer to the UK and US safety institutes, launched in February 2025, is more of a coalition than an agency.
Then 2026 happened. Concordia AI's July 2026 review found China's approach moving beyond controlling what AI says to governing what AI does: senior officials referencing "risks of technological loss of control," agent safety climbing from 8% of new Chinese papers in early 2025 to 27% in the first quarter of 2026, and dedicated guidance on agentic AI from the CAC in May 2026 — four months after the report warned about agents.
Then the institution. In July 2026 the Shanghai conference's Chair's Statement recorded the agreement establishing the World Artificial Intelligence Cooperation Organization, headquartered in Shanghai, committing signatories to ensure that AI always remains under human control and to hold AI agents to clearly defined decision-making authority and behavioral boundaries. Twenty-nine countries signed the agreement on July 16 — the same number sitting on the report's panel, and largely not the same countries. Viewed from Delhi, one analyst called it a permanent institutional vehicle for turning technical cooperation into diplomatic influence.
Savor the timing. Beijing's communiqué commits its signatories to keeping AI under human control — five months after Washington called that exact framing, from a summit podium, an atmosphere of fear.
Now the caveat, because China is not the responsible adult here either. Carnegie's October 2025 assessment is that China weighs development opportunities more heavily than risk in both rhetoric and practice, and that its evaluation system for frontier AI risks lags behind the United States'. Concordia's numbers agree domestically: only five of ten leading Chinese foundation-model developers reported safety evaluation results when releasing models this past year, and none did so consistently. The Diplomat hedges too — the new organization "may prove to be China's most ambitious effort yet," and "It remains more aspirational."
So China did not read the whole report either. It took a half — control, agents, institutional standing — and built with it. That half happens to be the one Washington threw away.
Now imagine the 2028 edition, and the seventy-two hours after it lands
Picture the fourth report, its scope narrowed again. Somewhere in chapter four sits a sentence that took eleven experts three weeks to negotiate:
We can no longer exclude the possibility that autonomous agents deployed at scale will pursue sub-goals their operators did not specify, though observed instances remain rare and confined to evaluation settings.
Watch the next three days. Within hours, a communiqué quotes the second clause — rare and confined to evaluation settings. A capital on the other side of the world quotes the first — can no longer exclude. A frontier lab's system card quotes neither, only the footnote on methodology, to explain why its own testing already exceeds the standard. A state attorney general pastes the whole paragraph into a complaint; a federal task force replies that the paragraph is preempted. By day three a fifteen-second clip of the chair being asked "so is it dangerous or not?" is doing well on video platforms, cut at the comma. Somebody builds an agent to summarize the report for citizens, and the summary keeps the strong half, because engagement rewards it.
None of that requires bad faith. It requires exactly what I did with page thirty-four: a strong sentence, a busy audience, and no cost attached to leaving the qualifier where you found it.
What the people who study this actually say
The striking thing is the shape of the disagreement. It is barely about the science.
On the American preemption fight, the ACLU's Cody Venzke called the executive order not just dangerous, it's unconstitutional, arguing a president cannot unilaterally and retroactively rewrite the conditions on federal grants to states. From the free-market side, R Street's Adam Thierer and Logan Kolas argued in February 2026 that most states trend toward over-regulation and that freedom and opportunity should be the default. Same evidence base, opposite instruction — and neither is arguing about what the models can actually do.
And Bengio is realistic about his own leverage. "The pace of advances is still much greater than the pace of [progress in] how we can manage those risks and mitigate them," he said — which he thinks puts the ball in the hands of the policymakers. He does not expect treaties, only informal coordination. The report's own diagnosis is sharper: AI development outpaces traditional governance cycles, because capabilities improve month to month while major legislation takes years to draft, negotiate and implement.
That is the finding everybody agreed on. It is also the one nobody acted on.
What does this mean for you?
You are not going to read two hundred and twenty-one pages, and neither is your representative. The useful skill is not reading everything — it is knowing how halves get taken.
When anyone cites a scientific report at you, ask which sentence. Not which study — which sentence, and then what the sentence after it said. In this document the qualifier is almost always the very next clause. That question is free to ask and expensive to dodge.
Learn to read the direction of a hedge. "Could not exclude the possibility" means a danger was not ruled out; it does not mean one was demonstrated. "Current systems lack the capabilities" is a claim about today, immediately followed by one about the trend. Both halves are the finding.
Check what got scoped out, not just what is in. This year's edition set aside bias, environmental impact, privacy and copyright. If the thing that affects you was scoped out, no amount of consensus inside the scope will help.
Watch your state capital, not only the national one. More than a hundred state AI laws passed this term against active federal pressure to preempt them. That is where the rules touching your job, your rent application and your kid's school get written.
Treat "backed by thirty countries" as a claim to check, not a credential. Ask who nominated whom, who declined, and who is on the published list.
The lesson, as I see it
I have never quite let myself off the hook for page thirty-four. Not because the harm was large — it wasn't — but because of how ordinary it felt. I was summarizing. I was being efficient. Every institution in this story would describe its own behavior in those words, and mean it.
We spent years assuming the obstacle to sane AI policy was the absence of agreed facts. Well: here are the agreed facts — negotiated by more than a hundred experts, backed by twenty-nine countries and three international organizations, published free, hedged with unusual honesty, demanding nothing of anyone. And 2026 answered the question we were all quietly asking. Evidence, by itself, changes very little. It becomes ammunition, sorted by clause.
That is not a reason to stop producing it. You cannot catch someone quoting half of something that does not exist, and this year we could. The report is why we can name what Washington skipped, what London postponed, what Brussels deferred, what the labs quietly relaxed, and what Beijing built with the piece it kept. That is the beginning of accountability, not the end of it.
The next edition will land, and within a day the halves will be distributed to their usual owners. So my suggestion is small, and it is the thing I wish someone had asked me all those years ago. When the quote arrives, ask what came next.
The HAIA Foundation works on keeping AI accountable to the people it gets used on — which starts, unglamorously, with reading the whole paragraph. Subscribe here if you would like the rest of the document and not just the quotable half.




