Within 48 hours, policymakers on both sides of the Atlantic reached a remarkably similar conclusion about the future of frontier AI governance.
On June 1, the European Union activated its new Scientific Panel under the EU AI Act, bringing together independent experts to support systemic-risk assessments of General-Purpose AI (GPAI) models.
One day later, the United States issued a new AI Executive Order establishing a framework for government-led security reviews of frontier AI systems before public release.
The details differ significantly. The EU focuses on systemic risks, regulatory oversight, and provider accountability. The US frames the issue primarily through national security and cybersecurity concerns.
Yet both initiatives point to the same underlying shift.
For years, AI governance has relied heavily on policies, documentation, transparency commitments, and provider assurances. Today, regulators increasingly recognize that these mechanisms alone are insufficient for understanding the real-world behavior and risks of the most capable AI systems.
Instead, governance is moving toward independent technical evaluation.
This represents an important evolution for organizations developing, deploying, and governing AI. The central question is no longer whether AI systems should be assessed, but how those assessments are conducted, what evidence they generate, and who can rely on the results.
The EU and US have chosen different paths, but both signal the emergence of a new principle for frontier AI oversight: trust must be supported by evidence.
Why Frontier AI Has Changed the Governance Conversation
The latest generation of frontier AI models has introduced capabilities that extend far beyond traditional software risks.
These systems can generate code, automate complex workflows, interact autonomously with external tools, and operate at scales that make failures difficult to predict and contain. As capabilities advance, concerns about cybersecurity, misuse, critical infrastructure impacts, misinformation, and systemic failures have moved from theoretical discussions into practical governance challenges.
The result is a growing recognition that the organizations building these models should not be the sole entities responsible for assessing their risks.
Independent evaluation is emerging as a mechanism to provide more objective evidence about model behavior, limitations, and potential impacts before those systems are deployed at scale.
The EU Approach: Systemic-Risk Governance
The EU's Scientific Panel is designed to support oversight of GPAI models under the EU AI Act.
The panel can advise the AI Office on model classification, systemic-risk assessments, evaluation methodologies, and emerging risks. It can also raise concerns about specific models and support market surveillance activities across member states.
The approach reflects the EU's broader philosophy toward AI governance: establish governance structures early, define responsibilities clearly, and create mechanisms to assess and manage risks before significant incidents occur.
At its core, the EU framework seeks to answer a governance question: how should systemic risks from the most capable AI systems be identified, measured, and controlled?
The US Approach: National Security Oversight
The new US AI Executive Order addresses a similar challenge through a different lens.
Rather than focusing on broad systemic-risk governance, it concentrates on the national security implications of frontier AI capabilities. Under the framework, developers can provide advanced models for government-led security reviews before public release.
The rationale is straightforward. Certain frontier AI capabilities may introduce cybersecurity and national security risks significant enough to warrant specialized evaluation infrastructure and government oversight.
While the mechanisms differ from those established under the EU AI Act, the underlying assumption is remarkably similar: advanced AI systems may require independent assessment beyond provider-led testing and assurances.
The Emerging Consensus: Governance Requires Technical Evidence
The most significant takeaway from both developments is not where they differ. It is where they converge.
Both the EU and the US are moving toward a model of AI governance that depends increasingly on technical evidence rather than documentation alone.
For years, AI governance programs have emphasized policies, risk frameworks, transparency reports, and compliance processes. These remain important. But they are increasingly being complemented by technical assessments designed to measure how AI systems actually behave under real-world conditions.
This reflects the broader emergence of technical AI governance: translating governance requirements into measurable controls, evaluations, and evidence.
The debate is no longer whether AI systems should be evaluated. The debate is how evaluations should be conducted, who should perform them, and what evidence should be considered sufficient.
What This Means for Enterprise AI Teams
Both the EU Scientific Panel and the new US Executive Order focus on frontier AI models.
Most enterprises, however, face a more immediate challenge. Organizations are already deploying AI copilots, customer-facing assistants, agentic workflows, decision-support applications, and retrieval-augmented generation systems into production environments. The risks associated with these systems, such as security vulnerabilities, reliability failures, compliance gaps, performance degradation, and misuse, exist today.
Yet many organizations still rely primarily on policies, documentation, vendor questionnaires, and provider assurances when assessing AI risk.
As expectations around AI oversight mature, organizations will likely need stronger evidence that their systems are performing as intended and that risks are being actively measured, validated, and controlled.
The lesson from both sides of the Atlantic is that AI governance can no longer rely solely on paperwork.
As AI systems become more capable and more deeply embedded in business operations, organizations will increasingly need measurable evidence that those systems are secure, reliable, compliant, and operating as intended.
The future of AI governance is not more documentation. It is better evidence.