general2815 wordsRead on Arc Codex

How to interrogate AI regulations

As artificial intelligence systems grow in their capabilities and reach, governments in the U.S. and abroad are considering a variety of AI regulatory proposals. While there is no national AI regulation in the U.S., several states have passed laws aimed at protecting workers, consumers and others who may use or interact with AI systems, including in Colorado, California, Texas, Utah and other states. Some AI firms and individual employees of AI firms have openly called for government regulation of their industry. But blurred technical distinctions about what constitutes AI, as well as potentially overlapping jurisdictions, make it difficult to evaluate governance proposals. Those initiatives also connect to different organizations, technologies and decisions, so evaluating them requires tracing how requirements are expected to change behavior and reduce risks. Journalists should take note when proposals lack precision about implementation or legal authority. This lack of precision makes their effects harder to assess. Ask: Who, with what power, compels whom, to do what? Those questions are central to assessing a proposal — and there must be a clear path from harm to action. Three questions give reporters a foothold: - What harms do a regulatory proposal target? - Who has the power to require what — and of whom? - Why should it work? As AI agents take wider-ranging action into businesses and institutions, new regulatory mechanisms will need to be designed to align changing incentives, with new standards to better monitor behavior. The range of proposals should be seen as a stack of overlapping coverage across the economy and society. If you cover technology news then you almost certainly cover what’s happening with AI, and AI regulation. Keep reading to inform your reporting. - What is an AI system — and what are the potential harms? - Who can require what of whom? - How to assess proposed regulations - Understanding the different types of harm - Rogue, reckless or reasonable actors - Will regulation work? What is an AI system — and what are the potential harms? The term ‘AI’ captures a range of methods, tools and systems that people use every day. Alongside powerful but narrow algorithms and generative tools, recent AI systems include complex multi-agent systems that can coordinate work across tasks. Each of these comes with its own potential harms and associated regulatory proposals and interventions. Classic consumer-facing artificial intelligence applications include social media algorithms, facial recognition on smartphones, navigation apps, product recommendations, and spam classifiers that sort junk email. These applications use algorithms trained on data to perform particular tasks, and they learn patterns in user behavior. Harms can include errors, racial or ethnic discrimination, and privacy violations affecting users and other firms. AI agents are large language models placed in “harnesses” that allow them to take actions in real environments — digital or physical — on behalf of people or organizations. The shift from chatbots that answer questions to software that takes action has opened new regulatory areas. A major strand of AI governance has focused on algorithms involved in making decisions that can change lives — things like insurance eligibility, bail decisions, allocation of government assistance and hiring. Decision-making algorithms could cause harm at scale, with opacity making some harms harder to detect or contest. A 2019 study in Science, for example, found racial bias in a widely used health-care algorithm because it used health spending as a proxy for health needs. Some state-level legislation, along with international regulations, such as the European Union’s General Data Protection Regulation, has sought to protect people affected by certain automated decisions. AI capabilities depend on hardware and software — including firmware that controls hardware. Technical advances can lead to more competent systems, but systems of the same competence can also be given more access, or a longer leash. For example, an operator could give a model access to tools controlling critical infrastructure, subject to required integration and authorization. Such changes in access can increase a system’s potential impact without improving the underlying model’s performance. Who can require what of whom? This question is central to the nature of policymaking. When is a government justified in intervening? Do we need to weigh costs against benefits? What level of risk is acceptable or unacceptable? Do potential indirect effects, such as some firms losing ground to competitors, count as harms? Suppose an AI system is used to screen applicants for a job. A governance proposal might require an employer to examine its hiring practices, a developer to disclose the algorithms deployed, and the model provider to test systems for certain biases. Audits and mandatory disclosures may support enforcement of standards. For example, a New York City law passed in 2021 mandates that automated employment decision tools pass a bias audit. Each regulatory approach raises different questions about access to evidence and responsibility for correcting problems. Who can impose AI governance? Governance includes a wide range of activities, including laws, organizational policies and private or industry standards. Regulation often refers to action undertaken by governments, but many actors can play a role in governance. Individual firms can impose internal or contractual requirements, and industry bodies can develop standards whose force depends on adoption, contracts or law. Many proposals exist under the banner of ‘governance.’ For reporters communicating with the public, it is important to ask what kind of commitment is being proposed. Research agendas and endorsements are not company commitments or industry standards. Domestic law and international agreements also have varied consequences. Pacing the Frontier, an open letter published in July 2026 and signed by over 1,300 employees of AI companies, requested U.S. government support for an international effort to develop tools to pace, or moderate, automated AI development. This is an example of support for coordination, but it is not an agreement to a governance regime. National and sub-national governments can mandate actions. In the U.S., Congress enacts statutes, courts can issue judgments and orders, and the president can issue executive orders. Federal agencies issue regulations under delegated authority. Executive orders and agency interpretations differ in legal effect and are not a substitute for legislation. Individual firms can also set internal standards through governance practices to limit their risks based on the firm’s incentives. Groups of firms may come together to try and set industry standards. In the U.S., regulatory action is subject to constitutional and statutory limits, procedural requirements and judicial review. Regulating internet-based technologies can also be contentious due to overlapping regulatory authorities and the global nature of the internet. Who is being governed? Any proposed governance should specify whose action is changing — this is the entity being governed. There is also a distinction between the source of risk and the industry or individuals subject to regulation. For example, proposals that aim to reduce misuse by an end user might impose requirements on a technology developer or operator. Similarly, a proposal aimed at curtailing the growth of AI capabilities might try to constrain AI training, or computing infrastructure. Firms are limited in their ability to mandate anything about competitor behavior, but a government may have the authority to impose an obligation, control a resource or induce an industry to change conduct. Authority and control are not the same thing. A government can have the legal power to impose a rule without the practical means to observe compliance or enforce it. Reporters should investigate both. What is being governed? Laws and regulations can target the development, deployment or spread of a technology. A governance intervention can target the computing resources and software used to develop or operate a model. For example, the administration of former President Joe Biden imposed export controls on some advanced computing chips and certain high-bandwidth memory. Energy supply and data-center operations are other potential points of intervention. Software and firmware can be subject to regulation. The model powering an agent can be subject to requirements concerning, for example, training methods. A government can restrict access to certain tools, or say that their use must comply with data-protection rules. For example, health privacy laws may apply when firms or governmental organizations use AI systems that handle protected health information. Monitoring and verification regimes are important because they can provide evidence about whether specified thresholds or requirements are met, even if the technologies and actors being regulated are wide-ranging. Verification can provide evidence that someone has complied with a check, but not what they should be complying with. How to assess proposed regulations Regulatory proposals can be assessed by the harm they are trying to solve. Some proposals use “dangerous capabilities” as a trigger for intervention — a capability is not itself a harmful outcome. Research presented with the July 2026 Pacing the Frontier letter discusses the risks of AI being used to create biological weapons or to commit cybercrime, such as ransomware deployed in healthcare systems. The Pacing the Frontier research also considers AI-assisted research and development accelerating beyond the capacity of human oversight. Translating that potential outcome into specific regulation raises questions: Who could lose control? Over what system? And with what consequences? Illustrating risks is important, but governance regimes need concrete proposals. Such proposals might examine growth in AI capabilities, or misuse of existing capabilities. Or they might focus on overreliance on AI within organizations, or AI contributing to a concentration of economic or political power. An intervention should be assessed by looking at the outcome it’s trying to prevent and the pathway that might produce it. But it is impossible to eradicate all risk. Where possible, governments should set standards for acceptable levels of risk. Journalists, for their part, should interrogate whether governments are meeting or falling short of those standards. Understanding the different types of harm There are several broad types of harm that most governance proposals aim to address. Sometimes a regulation will address several types of harm. But it can be helpful for reporters to categorize a proposal, law or regulation by the primary or overarching type of harm it aims to mitigate. Doing this can help reporters identify the core problem legislators or regulators hope to solve, and can also help the public better understand these efforts. The broad types of AI harm include: Loss of rights. This is one focus of the European Union Artificial Intelligence Act, alongside other objectives, such as public health and safety. The EU AI Act also addresses discrimination, privacy and due process. A system can pass a statistical fairness test and still produce decisions that violate someone’s rights, or that the people affected have no way to contest. Fairness metrics are not a guarantee that fairness is met. Catastrophic and existential risk. Some proposals are concerned with severe misuse or loss of control that may happen when AI systems rapidly gain new capabilities. These concerns feature in parts of proposed regulations centered on AI safety and security, aimed at frontier AI firms at the cutting edge. Reporters should know that an AI system may be able to pass tests showing it does not pose catastrophic risks, but this does not mean it is safe for every deployment context. National security. AI governance is seen as a key axis of U.S. competition with China, where strategic advantage can be won or lost. President Donald Trump’s administration in July 2025 released its AI Action Plan, which emphasizes U.S. leadership and competition. An influential preprint paper, “Superintelligence Strategy: Expert Version,” by Dan Hendrycks, Eric Schmidt and Alexandr Wang, proposes deterrence, competitiveness and nonproliferation in response to strategic competition. Concentration of economic power. Many people are worried about a relatively small number of private firms wielding tremendous economic power. There are issues with dependence, restricted research and limited market entry for competitors. Open models and interoperability are among the approaches proposed to broaden access and competition. According to the AI 2040 governance scenario from the AI Futures Project, proposals can target several harms simultaneously. Its authors propose coordinated limits on superintelligence development alongside public research and broader participation across companies and countries, with transparency arrangements intended to support oversight. Unequal access. Global and regional governmental bodies are concerned about unequal access to computational power, capacities to use and develop AI within firms and governments, and expertise on AI systems. The UN’s AI advisory body and the African Union have proposed measures to strengthen local capacity and broaden access, alongside regulation and accountability. Rogue, reckless or reasonable actors Harms from AI can emerge from actors behaving wholly reasonably. Other harms come from hostile actors. Reporters who want to improve public understanding of proposed AI regulations can group and present those regulations by whether they target rogue, reckless or reasonable actors. The point of the grouping is to ask who a proposal is targeted at, and if its mechanism can reach that actor. Rogue actors are not meaningfully disciplined by ordinary compliance and liability. They are outside governmental authority, or are insulated from reciprocal sanctions. Depending on the jurisdiction and circumstances, this group could include terrorists, adversarial states or rogue AI systems. Depending on the actor and leverage available to the government, responses may include domain-specific deterrence, denial and enforcement. Reckless actors are within a governable regime but show little care for public welfare and safety. This might be because costs are small or externalized, expected enforcement is low, information is asymmetric, or the private payoff to speed or scale dominates the private payoff to caution. This is an incentives problem for policymakers. Standards, audits, and liability regimes can be designed to increase the expected costs of harmful conduct, but their effect depends on detection, enforceability and sanctions. Reasonable actors follow laws, rules and norms. Harms can arise from interactions among actors even when individuals are compliant and non-negligent. For example, mass layoffs may cause social or political harm after an industry or large firm implements cost-saving technologies. Such harms raise coordination and distributional questions addressed by policies around competition, labor, economic policymaking and systemic risk, and no single AI-specific rule is likely to resolve them. Existing governance frameworks can apply to people and organizations deploying AI, although autonomous systems can complicate issues like attribution, proof and allocation of responsibility. AI systems are being empowered with autonomous planning, operations and resource allocation abilities. Regulations — and reporting about those regulations — need to explore the boundary of autonomy: When is a human employee legally responsible for actions delegated to an agent? When is the firm responsible? Does the developer of an AI model, harness or tool bear responsibility? Will regulation work? For any proposed AI governance to work it must have a strong causal logic, where a requirement leads to reduced harm through changed conduct. That logic can fail even when everyone complies. Companies may substitute, move, or restructure their activity to avoid costs while technically complying. Reporters should ask what a rule would change in practice and how firms would adapt to it, not only what it requires on paper. For issues like pacing, which refers to moderating the growth of AI capabilities, it’s important that journalists ask regulators what slowing or pausing technological advancement would accomplish, and what progress might look like. Reporters should also dig into how regulations may affect costs, opportunities and competitive positions differently across companies. Commercial technology firms generally face incentives to earn returns on investment. Depending on their position, they may benefit from expanding the industry, gaining market share or both. Competition and collaboration can serve these aims, but may also create tradeoffs. A firm that publicly supports regulation may be supporting the version that raises its competitors’ costs more than its own. A range of economists and lawyers are interested in publicly supervised but privately assured provisions for regulation. The 2023 “regulatory markets” proposal from Gillian Hadfield and Jack Clark would have governments set outcomes and oversee private regulators, with regulated firms required to buy services from approved regulators. The proposal would build a market for private AI regulators. The public looks to regulation to correct market failures. Measures should address specific problems and should be supported with evidence. But government regulation is not always productive, and the evidence on benefits and costs varies by application and intervention. Established harms can have substantial empirical evidence, while estimates concerning frontier capabilities and extreme outcomes depend more heavily on uncertain assumptions. Many of today’s harms can be handled with regulatory tools that already exist. Some, though, are fundamentally different to the policy problems our institutions were built to handle. Proposals will need to treat AI systems both as instruments that people use and as agents that act on their behalf. The scale of the regulatory challenge means that it will require the work of many agencies and legislators, and an omnibus bill is unlikely to adequately tackle all the challenges outlined here. Reporters have a critical role to play in ensuring that the public understands, in plain language, the benefits and drawbacks of proposed regulatory efforts. Expert Commentary

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.