One month after the EU AI Act's high-risk obligations took effect and NHTSA opened its engineering analysis into Tesla's Full Self-Driving system, the most telling signal from both jurisdictions is silence.

In Europe, the silence is structural. CEN-CENELEC Joint Technical Committee 21 has published only EN 18286:2026, a quality management framework, while the substantive risk-management harmonized European standards remain 18 to 36 months from publication. Member States began enforcing Articles 9 and 40 on August 2 against operators who must self-assess what "adequate" risk management means without a shared technical baseline. Historical precedent from the Machinery Directive and Medical Devices Regulation suggests that Germany and France will impose divergent national criteria within the next quarter if draft hENs do not appear.

In the United States, the silence is procedural. NHTSA's engineering analysis, opened August 20, can extend 12 to 18 months for complex systems. The Labor Day pause is normal. But the agency's focus on camera-only performance in poor visibility—fog, glare, low light—signals a coming sensor-redundancy threshold that does not yet exist in any federal regulation. The investigation is functionally writing a standard through enforcement, testing whether a camera-only architecture can meet a safety threshold that NHTSA has not yet formally defined.

These two silences reveal the same institutional mechanism: regulatory bodies pace innovation not by preemptive specification but by post-hoc enforcement. The EU's framework is proactive and architecture-neutral, yet its pre-market conformity assessment requires standards that do not exist. The US framework is reactive and incident-driven, yet its post-market recall authority allows it to target specific design choices—like camera-only perception—without waiting for rulemaking or standards development.

The paradox is that the reactive regime may currently offer clearer compliance targets. US operators adapt to discrete mandates as they drop. EU operators must navigate self-assessed "state of the art" risk management, interpreted by national authorities with no guarantee of consistency. Waymo's planned 2027 Germany launch illustrates the tension: a lidar-backed architecture with bounded operational design domains and third-party safety submissions faces no presumption of conformity in Europe because no harmonized standards exist to measure it against.

Regulatory legitimacy requires that enforcement precede harm. Technical legitimacy requires that standards precede enforcement. Both jurisdictions are currently satisfying the first condition while violating the second. The risk is not unregulated autonomous vehicles. It is arbitrary regulation that fragments the global market along national enforcement styles rather than harmonized safety thresholds. One month in, that fragmentation is not a forecast. It is the operating environment.

Sources