The Regulatory Dilemma
Governments are being asked to regulate technologies they do not fully understand, developing faster than legislation can be drafted, built by firms whose technical staff earn several times what any regulator can offer, operating across borders that domestic law does not reach.
Err in one direction and harms proliferate, public trust collapses, and the eventual backlash produces an overcorrection that costs more than early regulation would have. Err in the other and development relocates to jurisdictions with weaker protections, which means citizens lose the benefits without being spared the harms.
This chapter is for legislators, regulators, and the people who advise them. It is not a policy manual—jurisdiction, sector, and moment all matter too much for that—but a framework, plus a set of specific recommendations that are available now.
The honest starting point: no adequate regulatory framework for AI exists anywhere. Every government is improvising. Some improvisations are better than others, and the differences are instructive.
Why This Is Genuinely Hard
Speed mismatch. Model capabilities change on a scale of months; primary legislation takes years. Any rule specifying a technical threshold will be obsolete before it is enforced.
Knowledge asymmetry. The people who understand these systems work for the firms being regulated. This is not corruption; it is a labor market. But it means regulators are structurally dependent on the regulated for the information needed to regulate them.
Jurisdiction. The technology is global, the regulation is national, and model weights are files.
Generality. Previous technology regulation targeted specific applications—a drug, a vehicle, a reactor. A foundation model is a general capability whose applications are not enumerable in advance, which defeats the standard regulatory approach of specifying permitted uses.
Dual use. The same capability produces the benefit and the harm, and often within the same system responding to different prompts.
2026 Snapshot — What Exists
The European Union produced the most comprehensive framework in the AI Act, adopted in 2024.¹ It classifies systems by risk: unacceptable uses banned outright (social scoring, certain biometric categorization), high-risk uses subject to conformity assessment and documentation, limited-risk uses subject to transparency obligations, and everything else unregulated. Implementation is phased over several years.
Its strength is coherence. Its weaknesses are the compliance burden on smaller developers, and a definitional problem: the Act was substantially drafted before general-purpose models became the central concern, and the provisions added to address them are the least settled part of it.
The United States has been the most volatile. An October 2023 executive order established reporting requirements for frontier training runs and directed agency action across government; it was rescinded in January 2025 and replaced with a differently oriented order emphasizing deregulation and competitiveness.² The practical consequence is that US federal AI policy currently resets with each administration, which makes it unreliable as a planning basis for anyone.
Substantive US regulation therefore happens through sectoral agencies applying existing authority—FDA for medical devices, FTC for deceptive practices, financial regulators for lending—and through states. California's SB 1047 was passed and vetoed in 2024; a narrower transparency-focused successor was enacted in 2025. Colorado passed comprehensive AI legislation. This produces a patchwork, and the patchwork is currently doing most of the actual work.
The United Kingdom took a principles-based approach with existing regulators applying cross-cutting principles in their own domains, and made its most significant contribution institutionally: the AI Safety Institute, established in 2023, was the first government body conducting independent pre-deployment evaluation of frontier models.³ Other countries have followed. This is the single most replicable governance innovation of the period.
China regulates faster than anyone through the Algorithm Recommendation Regulation (2022), Deep Synthesis Provisions (2023), and Generative AI Measures (2023).⁴ The framework is comprehensive and oriented toward content control and social stability, which limits what democracies can borrow from it—though the synthetic media labeling provisions are a genuine policy innovation that other jurisdictions are copying.
The gaps are consistent everywhere: enforcement capacity, technical capability inside government, and international coordination.
Principles
Regulate by risk, not by technology. The relevant question is what a system decides and what happens when it is wrong—not what architecture it uses. A model determining benefit eligibility warrants oversight that the same model summarizing documents does not. Technology-specific rules also date immediately, while risk-tiered rules survive the next architecture.
Regulate the application, and the frontier separately. Most AI harms occur at the point of use and are already covered by existing law—discrimination in lending is illegal regardless of what performed the discrimination. Enforcing existing law against AI-mediated conduct addresses most real harm without new legislation. A narrow set of concerns specific to frontier development—dangerous capability evaluation, security of model weights—genuinely requires new authority.
Build technical capacity as the precondition for everything else. A regulator that cannot evaluate a system can only accept assurances. AI safety institutes are the proven model. This is cheap relative to any other intervention and gates all of them.
Prefer adaptive instruments. Broad principles in statute, detail in regulation, sunset provisions forcing periodic review, and sandboxes for supervised testing.⁵ Legislatures should set objectives and grant authority; agencies should specify thresholds.
Assign liability clearly. Much regulation becomes unnecessary when responsibility for harm is unambiguous. Liability harnesses the developer's own information advantage—they know their system's failure modes better than any regulator will—and requires no technical capacity to enforce. The EU's proposed liability directive addresses the evidentiary problem by presuming causality in certain circumstances, since a claimant cannot inspect a model they do not have access to.⁷
Policy Tools
Ex ante requirements—testing, certification, disclosure before deployment—suit high-stakes applications and impose costs that fall disproportionately on smaller developers.
Ex post liability suits diffuse or unpredictable harms and requires functioning courts and evidentiary rules adapted to opaque systems.
Procurement is the most underused instrument available. Government is an enormous customer, and purchasing conditions require no legislation, apply immediately, and shape products for the whole market. A government that will only buy systems meeting specified evaluation, documentation, and audit standards moves the market faster than most rulemaking.
Disclosure and labeling obligations—marking synthetic media, disclosing automated decision-making, incident reporting—are low-cost and enable everything downstream, since harms that are not recorded cannot be regulated.
Standards bodies are doing quiet, consequential work through ISO/IEC 42001, IEEE ethics standards, and the NIST AI Risk Management Framework.⁶ Voluntary standards frequently become the de facto compliance baseline and then the legal one.
Export controls on advanced chips and potentially on model weights are the primary security instrument.⁸ They constrain adversary capability, accelerate indigenous development, and fragment the technical ecosystem—all three, simultaneously, and the balance is contested.
Specific Recommendations
Six things governments could do now, ordered by ratio of benefit to difficulty.
Fund an evaluation body. An AI safety institute with the technical staff to independently test frontier systems. Cost: tens of millions. Nothing else in this chapter works without it.
Mandate DNA synthesis screening. Discussed in Chapter 60 and repeated here because it is the highest-value, lowest-cost safety measure available in any domain this book covers, it is currently voluntary, and it could be made mandatory in a single legislative session.
Set procurement standards. Immediate effect, no new legislation, market-wide influence.
Clarify liability. Specify who is responsible when an AI system causes harm—developer, deployer, or both—and adjust evidentiary rules so claimants can meet their burden without access to systems they cannot inspect.
Require incident reporting. Mandatory reporting of significant AI failures, structured like aviation safety reporting rather than punitive enforcement. Aviation became safe largely because failures were reported and analyzed rather than concealed, and the AI sector currently has no equivalent.
Enforce existing law. Most AI harm violates rules already on the books. Anti-discrimination, consumer protection, product safety, and professional licensing all apply. The gap is enforcement capacity, not statutory authority.
Second-Order Impacts
Compliance cost concentrates the market. Every requirement is easier for a large incumbent to absorb than for a startup, which means safety regulation can entrench the firms it regulates. This is not an argument against regulation; it is an argument for tiering obligations by developer scale and for pairing safety rules with antitrust attention.
Fragmentation exports the strictest rule. When compliance regimes conflict, global firms tend to build to the strictest and apply it everywhere, because maintaining variants is expensive. The EU has exercised more influence over global product behavior through this mechanism than through any negotiation.
Regulatory capacity becomes a competitive asset. Jurisdictions that can evaluate systems credibly attract development that wants legitimacy, while jurisdictions that cannot are left choosing between prohibition and trust.
Safety framing can be weaponized. Incumbents advocating for licensing regimes are simultaneously making a genuine safety argument and raising a barrier to entry. Both are true, and regulators should assume both.
The Path Forward
Near-Term (2026–2028)
Build evaluation capacity. Implement and enforce what is already enacted rather than legislating further. Address the harms that are demonstrably occurring—synthetic media fraud, algorithmic discrimination, model security. Harmonize technical standards internationally where the politics permit, which is more often than the headline disagreements suggest.
Medium-Term (2028–2032)
Fill coverage gaps and resolve liability. Build enforcement resourcing to match statutory ambition, which is currently the largest gap between what laws say and what they do. Establish incident reporting infrastructure. Develop mutual recognition so that evaluation in one jurisdiction is accepted in another.
Long-Term (2032+)
Governance for substantially more capable systems, if they arrive. International institutions for genuinely cross-border risks, which so far exist as forums rather than as bodies with authority.⁹ And the constitutional questions—what due process means when a decision is made by a system nobody can fully explain, and what democratic accountability means when the consequential choices are technical.
For Specific Actors
Legislators should write objectives and grant authority rather than specifying technical detail that will be obsolete on enactment, and should fund the agencies they empower. An unfunded mandate to regulate AI is a press release.
Regulators should hire technical staff at whatever it costs, engage industry closely enough to understand the systems while maintaining the independence to act against them, and use sandboxes and pilots to learn before committing to rules.
Local government has more leverage than it exercises. Procurement conditions, deployment decisions in public services, and transparency about municipal AI use all sit at this level, and the systems most likely to affect a citizen's life adversely—benefits eligibility, policing, housing—are frequently operated locally.
Risks and Guardrails
Regulatory capture. The knowledge asymmetry makes it structural rather than occasional. Guardrails: independent technical capacity, diverse and funded public-interest input, transparency in rulemaking, and restrictions on the revolving door.
Innovation displacement. Guardrails: proportionality, evidence-based requirements, scheduled review, and obligations tiered so that compliance cost does not itself become the barrier to entry.
Under-protection. Guardrails: precaution scaled to irreversibility, adequate enforcement resourcing, and liability that makes harm expensive for those positioned to prevent it.
Fragmentation. Guardrails: international standards harmonization, mutual recognition of evaluation, and—within federal systems—preemption only where it raises the floor rather than lowering it.
The Deeper Questions
What is government for, here? Protector, enabler, purchaser, and distributor, in different measures for different technologies. The choice of emphasis is a political question that technical analysis does not answer.
Who decides? Democratic legitimacy requires public input; competent regulation requires expertise most of the public lacks. This tension is not new—it applies to pharmaceuticals and nuclear power—and the workable resolution has been delegated technical judgment inside democratically set constraints. That model requires the delegation to be genuine and the constraints to be real, and both are currently weak in AI.
Whose values? Regulation embeds values, and safety, innovation, equity, and liberty conflict. Making those tradeoffs explicit is better than resolving them silently through technical standards.¹⁰
Conclusion
Governments have regulated transformative technologies before. Pharmaceuticals, aviation, nuclear power, and telecommunications were each, in their moment, moving faster than the law and understood mainly by the people who built them. Each is now governed adequately, and none of those regimes was designed correctly on the first attempt.
What is different about AI is generality, speed, and the fact that the primary artifacts are files rather than facilities. What is not different is the underlying task: build the capacity to evaluate, assign responsibility for harm, and set conditions on the highest-stakes uses.
The most useful thing to notice is how much of the necessary work requires no new theory. Fund an evaluation body. Make synthesis screening mandatory. Set procurement conditions. Clarify liability. Require incident reporting. Enforce the laws already on the books. None of these depends on resolving what AI will become, none requires international agreement, and none is expensive relative to the harms they address.
They are not being done because they are unglamorous, because they require sustained institutional investment rather than announcements, and because the constituency for preventing a harm that has not yet occurred is always smaller than the constituency against the cost of preventing it.
That is the actual governance problem. It is not that the right policies are unknown. It is that the political system rewards responding to visible harm and provides almost nothing for preventing invisible ones—and this technology's most serious harms are precisely the ones that become visible only after they are difficult to reverse.
Endnotes — Chapter 63
- The EU AI Act was adopted in 2024, establishing a risk-based framework that bans certain uses, imposes conformity assessment on high-risk systems, and applies transparency obligations to limited-risk applications, with phased implementation.
- The US Executive Order on AI (October 2023) established reporting requirements for frontier training runs and directed agency action; it was rescinded in January 2025 and replaced with an order emphasizing competitiveness and deregulation. Federal AI policy currently resets with administrations, leaving sectoral agencies and states as the operative regulators.
- The UK AI Safety Institute, established in November 2023, was the first government body conducting independent pre-deployment evaluation of frontier models; equivalents have since been established elsewhere.
- China's AI regulation includes the Algorithm Recommendation Regulation (2022), Deep Synthesis Provisions (2023), and Generative AI Measures (2023)—comprehensive, rapidly implemented, and oriented toward content control.
- Regulatory sandboxes provide controlled environments for testing under reduced requirements with supervision; used in the UK, Singapore, and elsewhere for both financial technology and AI.
- Technical standards work includes ISO/IEC 42001 (AI management systems), IEEE standards for AI ethics, and the NIST AI Risk Management Framework, which is voluntary and widely used as a de facto compliance baseline.
- The EU's proposed AI Liability Directive addresses the evidentiary asymmetry by establishing a presumption of causality in certain circumstances; US practice relies on existing tort law, which was not designed for opaque systems.
- US export controls restrict advanced AI chips to China, with controls on frontier model weights proposed. The measures constrain adversary capability, accelerate indigenous substitution, and fragment the technical ecosystem simultaneously.
- International AI governance efforts include the UN High-Level Advisory Body on AI, the G7 Hiroshima AI Process, and a series of international AI summits, none of which has yet produced binding commitments.
- The tension between technical complexity and democratic accountability in AI governance has produced various proposals for structured citizen engagement, including deliberative assemblies on specific policy questions.
