AI policy is increasingly expressed through sector rules, enforcement theories, procurement conditions, security expectations, and voluntary risk frameworks rather than one comprehensive legal code.