Artificial intelligence is now used in at least one area of government in 35 of the 36 OECD countries, which makes the real question for the next decade less about whether states adopt AI and more about who writes the rules that govern it. In 2026, three answers are on the table: Washington's voluntary security-first approach, Brussels' risk-based law, and a small Baltic country that just decided to give AI agents their own identity cards (OECD, 2026).
The American model: voluntary and security-first
On 2 June 2026, President Donald Trump signed Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security. The order directs agencies to harden federal systems against AI-enabled cyber threats, creates an AI cybersecurity clearinghouse, and asks the NSA to run a classified benchmarking process to decide when a model is powerful enough to qualify as a covered frontier model (White House, 2026).
The crucial detail is in the verbs: nothing in the order is mandatory. Participation by AI developers is voluntary, the pre-release review window lasts only 30 days, and the order explicitly states it does not authorize licensing, preclearance or permitting for AI models. The stated policy is that America leads in AI because it refuses to burden the industry with regulation (Executive Order 14409, 2026).
What Washington is building instead is a security relationship: voluntary benchmarks, early government access to frontier models for trusted partners, and criminal enforcement against people who misuse AI to break into systems. Congress's own research service frames EO 14409 as a shift from AI safety concerns under the rescinded EO 14110 toward AI security concerns, protecting models from external threats rather than from their own outputs (Congressional Research Service, 2026).
The European model: risk categories and deadlines
Brussels took the opposite route. The EU AI Act entered into force on 1 August 2024, banned unacceptable-risk AI from February 2025, and begins applying its obligations for high-risk systems in August 2026, with the full set of rules binding on all high-risk systems by August 2027 (EU AI Act, 2024).
Where Washington asks companies to volunteer, Brussels writes a risk ladder: unacceptable, high, limited and minimal, with progressively heavier obligations for the riskier tiers. The model is built for accountability rather than speed, and it is exactly why the EU and the US keep talking past each other. American companies see European compliance costs as a brake on innovation; European regulators see American voluntarism as a bet that nothing goes badly wrong.
The AI Act's deadlines are staggered on purpose. Unacceptable risk was banned first because those uses were already considered indefensible, high-risk obligations then phase in to give deployers time, and the system-wide obligations land last. For Estonia, as a member state, the act is the legal floor: national rules sit on top of it, and that is exactly where its most interesting experiment began.
The Estonian model: agents with ID codes
The most original governance experiment is not a superpower at all. On 17 June 2026, Estonia's Eesti.ai advisory board agreed the country would create digital identities for AI agents, AI ID codes, a world first. The idea is that an agent acting for a person or company gets limited, verifiable, auditable powers: it might view data, prepare a document or draw up a payment, but only within a defined financial limit, and always with a named human behind it (Estonian Government, 2026).
Now that we find ourselves in the age of AI agents, we are faced with the same question: how can we use that technology in a way that makes life easier but without losing control and accountability? - Prime Minister Kristen Michal (June 2026)
The mechanism matters more than the novelty. Estonia is applying the same infrastructure that made its digital state work, X-Road, digital signatures and personal ID codes, to machines. The policy rationale is direct: without limited and revocable authority for agents, a citizen granting an AI assistant access to their account is effectively handing it every right, service and piece of data they hold. ID codes turn that all-or-nothing grant into a granular, controllable one.
Estonia's numbers are the real story
The ID-code decision sits on top of a decade of accumulated practice. Estonia counts more than 220 public-sector AI use cases and estimates close to 60 million euros in annual impact from them, from procurement-document generation to legislative-drafting tools that cross-check Estonian law against EU law and catch citation errors early (e-Governance Academy, 2026).
The same survey-driven method that picked those first use cases shows why adoption sticks. Briefing notes alone consumed over 33,000 hours a year across just two ministries, and the country plans to save roughly 97 million euros worth of work over the next two years by automating the tasks civil servants hate most. More than half of all Estonians already use AI daily, and government employees use it more than private-sector workers, 37 percent against 25 percent, a reversal of the usual pattern (e-Governance Academy, 2026).
What the OECD audit found about everyone
The OECD's Digital Government Outlook 2026 measured how well governments actually govern AI, and the findings are uncomfortable for every model. Only about 11 percent of OECD countries report any financial or non-financial impact measurement of their AI use cases, even though half say adoption decisions draw on evidence of potential savings. Only 22 percent have citizen complaint or feedback mechanisms for AI services, and few governments run formal standards or open algorithm registers (OECD, 2026).
- Only 11% of OECD countries measure the impact of their AI use cases.
- Only 22% have citizen complaint or feedback mechanisms for AI services.
- Algorithm transparency is committed to more than it is implemented.
- Procurement support for AI lags far behind strategy and funding announcements.
- Estonia is one of only three countries with a mandatory AI use-case repository.
The same report ranks Estonia, France, Korea and the UK as consistent high performers, driven by consolidated oversight bodies and transparency mechanisms. But even the leaders score poorly on the questions that matter most: does the AI actually save money, and can citizens challenge what it decided? The gap between adoption and accountability is the shared failure across every governance model in 2026.
The unresolved questions for 2032
The three models are not competing for the same prize, which is why none will simply win. The US approach is built to keep frontier companies unregulated and inside national-security loops; the EU approach is built to force accountability onto every deployer; the Estonian approach is built to make AI agents legible inside an existing digital state. A country can run all three at once, and most governments probably will.
What 2032 will actually test is which model survives real failure. The US bet holds if no frontier-model catastrophe forces licensing; the EU bet holds if high-risk compliance does not strangle deployment; the Estonian bet holds if AI ID codes make agents trustworthy enough for people to actually use them. The rulers of AI in 2032 will be the governments that guessed the failure mode correctly, and right now, none of the three knows which one that is.
Key takeaways
- The US governs AI through voluntary security benchmarks, not licensing, under Executive Order 14409.
- The EU regulates by risk category through the AI Act, binding on high-risk systems from August 2027.
- Estonia is the first country to issue AI ID codes, giving agents limited, auditable powers.
- Only a handful of governments measure whether their AI use cases actually deliver results.
- The winners by 2032 will be the models that survive real failure, not the best-looking philosophy.
Frequently asked questions
Who regulates AI in the United States?
There is no comprehensive AI law. The federal approach, led by Executive Order 14409, is voluntary security benchmarking, an AI cybersecurity clearinghouse and criminal enforcement against AI misuse.
What does the EU AI Act actually ban?
Unacceptable-risk AI, banned since February 2025, plus obligations on high-risk systems, binding on new systems from August 2026 and on all high-risk systems by August 2027.
Why is Estonia giving AI agents ID codes?
So an AI agent can act for a person within clearly defined limits that are verifiable and auditable, preventing agents from inheriting full access to rights, services and data.
How many governments use AI?
AI is used in at least one area of government in 35 of the 36 OECD countries, about 97 percent, according to the OECD Digital Government Outlook 2026.
Which AI governance model is working?
None has been proven yet. Few governments measure the impact of their AI use cases, so the field is still in the pilot phase with very little evidence.
- The EU AI Act rules that took effect
- The US ban on Chinese AI models, explained
- Kimi K3: why China's open-weights push matters
- White House: Executive Order 14409
- Estonian Government: digital identities for AI agents
- OECD Digital Government Outlook 2026
Bottom line
What 2032 will actually test is which model survives real failure. The US bet holds if no frontier-model catastrophe forces licensing; the EU bet holds if high-risk compliance does not strangle deployment; the Estonian bet holds if AI ID codes make agents trustworthy enough for people to actually use them. The rulers of AI in 2032 will be the governments that guessed the failure mode correctly, and right now, none of the three knows which one that is.
What we still don't know
This is a fast-moving story. We update the post as new facts land — and we'll flag it when we do.
Enjoyed this? Pay it forward
A sharp story is worth passing on. Share it with the people who read tech like it matters.
