On 23 September 2026 the UN Security Council held its first high-level briefing devoted to the security risks of AI, with the chief executives of OpenAI and Anthropic among those who addressed it. After AI chief executives brief the Council, which rules actually bind how AI gets used? Not the Council, but the law already in force where you operate — the EU AI Act, or a US state framework.
01The Council debates AI; it does not legislate it
France, holding the presidency in September, convened the meeting. It was the first high-level briefing in which the Council took up AI security risks head-on. No binding resolution was on the programme.
This was not the Council's first pass at the subject. Counting formal and informal sessions, it has met on AI six times before. None of those produced a rule.
This piece checks three things, in order. Whether anyone inside the UN holds rulemaking authority. If not, what prevents it. And where countable deadlines actually exist. For anyone publishing material, the practical answer is plain: the document you need sits outside the United Nations.
02The UN science panel states plainly that it makes no rules
If the Council issues no resolutions, the next place to look is elsewhere in the UN system.
The Independent International Scientific Panel, established under resolution A/RES/79/325, produces evidence-based scientific assessments in an annual report. The Panel describes itself as not a regulatory body. It will not set rules, enforce standards, or prescribe policy — its own explanatory material says so.
The limit is not hidden. The body that gathers and presents evidence and the body that decides and enforces were kept separate from the start.
Follow the diagram to its last box. Sessions accumulate without resolutions, and the body that collects the evidence disclaims regulatory power. Neither of these two UN mechanisms holds the authority to make rules.
03Material review is bound by the domestic law in force today
On one side stands an organisation that has written down that it is not a regulator. On the other, review teams make decisions every day under some law or other.
Whether a piece of material drafted with AI can go out is not settled by a UN document. It is settled by domestic advertising rules, and by the law of the country the material is published into. The file a reviewer should open sits within their own jurisdiction.
The difference is not one of prestige. It is a difference in what each instrument carries. The table below puts that on the same rows.
| Test | The two UN mechanisms | EU AI Act and US state frameworks |
|---|---|---|
| Output | An annual assessment report and a forum for dialogue | Enforceable obligations and administrative frameworks |
| Deadlines in figures | None | Article 73: 15 days, two for critical infrastructure |
| If you fail to comply | No means of enforcement | Administrative supervision and penalties |
The blank in the second row carries most of the argument. A document that carries neither a number of days nor a means of enforcement does not change the deadlines in a working procedure. What changes them is the document that also states what happens when you fall short.
None of this makes the UN mechanisms worthless. An annual assessment is material for understanding what is happening across the field, and that material is needed. Its job is simply not the job of the document you open when deciding whether a piece of material can go out.
04Nothing is settled there because an item that resists agreement sits before a body that requires it
No rulemaking authority inside the UN. To see why, go back to how the Council reaches a binding decision at all.
A binding Council decision requires agreement among the permanent members. Yet AI development and export are also a field in which those same states compete. At the meeting, positions among member states remained split — on whether regulation should be tightened, and on what role the Council itself should take.
This is not a procedural defect. It is what happens when an item that resists agreement is placed before a body that requires it.
I cannot write past what I have verified about who argued what in the chamber. What is verifiable is the single point that positions were split, both on how far regulation should go and on the Council's own role. A split left standing carries into the next session under the same conditions.
What matters is that all three branches remain open. Close any one of them and a resolution comes closer; the meeting gave no indication that any of them is closing.
05Article 73 sets 15 days, and two US states moved in September
If nothing is settled where unanimity is required, the faster move is to count the places where numbers have already been fixed.
Article 73 of the EU AI Act requires reporting of serious incidents involving high-risk AI systems immediately on establishing a causal link, and no later than 15 days after. For events touching critical infrastructure, the limit is two days. In the United States, individual states moved at their own pace.
European Union
Article 73 of the AI Act fixes reporting deadlines for serious incidents in days.
Illinois
In September the governor established an AI cabinet to assess risks to residents and critical infrastructure.
Maryland
On 22 September the governor set out a framework and pledged to work with the legislature on regulation.
The second and third cards are not enacted law. One is an advisory body, the other a framework announcement. Even so, the fact stands: what moved toward regulation in September was two state governments, not the Security Council.
Article 73's obligation is aimed at providers of high-risk AI systems, not at every user of every tool. So the first thing to establish is whether you sit inside that obligation at all — and that, again, is a question for your own jurisdiction.
06Authority, speed and jurisdiction decide which rules apply to you
Fifteen days and two days on one side; split positions in the chamber on the other. Set those beside each other and what the meeting yields separates into three.
The authority to make rules does not sit with the UN
Neither the Council nor the science panel makes rules, and the panel has written down that it is not a regulator. So the fact that something was said at the United Nations cannot serve as justification for your own internal standard.
What it can serve as is material — the panel's annual assessment read as evidence. Material and justification are different things.
The day a document is finished is not the day it starts to bind
The effect of the UN framework is judged to depend less on its design than on how much resource and political will governments put behind it. So a finished document starts to bind only once governments put resource and political will behind it.
That rules out one posture: holding back a decision on adoption until the rules mature. While you wait, material drafted with AI keeps arriving on the desk.
Only the law of your own jurisdiction actually binds you
Article 73 carries numbers. US states are each building something different. The same piece of material can meet a different judgment and a different deadline depending on where it is published.
Authority
A UN statement cannot justify your internal standard.
Speed
You cannot suspend adoption decisions until rules mature.
Jurisdiction
The same material meets different judgments and deadlines in different countries.
Turn the three cards over and an order of work appears. Decide where you are publishing, find the law that reaches there, and put that law's deadline into your own procedure.
07The test ahead is whether states can verify each other's pledges
A mechanism that has written down that it is not a regulator leaves a space behind. The space is the absence of any way to check what states tell one another.
Both UN mechanisms are places to share evidence and talk. Neither carries a means of enforcement. Their effect is judged to rest on what each government carries forward. With no means of enforcement, whether anything is carried forward can rest nowhere but with the governments themselves.
When one state says it has taken a safety measure, no method has been set out by which another state could confirm it. Nor has any date for setting one out. I have no proposal to fill that space, and I could not find a document that does.
The four steps in the diagram turn without waiting for any international agreement. Add a country and you add a law; the numbers in your procedure change with it. Whether once a year is often enough depends on how many countries you publish into.
One caveat belongs here. That no binding outcome was planned for 23 September was a forecast written before the meeting. It does not close off a later resolution. If one comes, obligations fall on member states from that day; whether a means of making them stick comes with it depends on what the resolution says.
Until then, whether material drafted with AI goes out is decided by domestic advertising rules and by the law of the country receiving it. That was still the position the day after the briefing.
- The Council held its first high-level AI briefing on 23 September with no binding resolution planned, as in its six earlier sessions. A forum for debate and a body that makes rules are not the same thing.
- The panel created by resolution A/RES/79/325 states that it is not a regulatory body and will not set rules or enforce standards. Producing evidence and deciding sit apart by design.
- Article 73 of the EU AI Act carries the numbers — 15 days, two days. US states moved separately in September. Only the law of your own jurisdiction actually binds you.
Chief executives briefing the Security Council does not produce rules. What it produces is assessment and dialogue, and neither carries a deadline.
What binds you is the law of the country you publish into, and the obligations and day counts written there. The document you need is closer to hand than the feed from the chamber.
- Security Council Report. Artificial Intelligence: High-level Briefing. 22 September 2026. (The 23 September meeting, convened by France as president; six earlier meetings; no binding outcome planned.)
- United Nations. Independent International Scientific Panel on AI — FAQ. 26 August 2025. (The Panel is not a regulatory body and will not set rules, enforce standards or prescribe policy; it produces an annual report.)
- Tech Policy Press. UN Reaches Consensus on AI. Now Comes the Hard Part. 5 September 2025. (The resolution's impact depends less on design than on how governments carry it forward.)
- EU Artificial Intelligence Act. Article 73: Reporting of Serious Incidents. 12 July 2024. (Fifteen days for serious incidents; two days where critical infrastructure is involved.)
- NPR Illinois. Pritzker establishes AI cabinet amid calls for greater regulation. 22 September 2026. (An AI cabinet to assess risks to residents and critical infrastructure.)
- HR Dive. Maryland governor's AI framework focuses on regulation and reskilling. 22 September 2026. (A framework announced on 22 September, working with the legislature to regulate.)
