Pacific Design/ artificial intelligence

Policy & Regulation · entry 01/05

The regulatory problem

AI regulation is hard for structural reasons — pacing, definition, opacity, dual use — and most loud disagreements trace back to one of four honest difficulties.

What's actually new here

Regulators have governed dangerous technologies for a century; planes, drugs and derivatives all have rulebooks. Four properties make AI awkward for the standard playbook. Pacing: capabilities turn over in months, legislation in years, and a rule scoped to today's systems is obsolete at signature. Opacity: a model's behavior emerges from training rather than following inspectable design documents — you can audit outputs, not read intentions. Dual use: one model writes marketing copy and phishing with equal competence; capability and misuse are the same artifact. Diffusion: software crosses borders at zero cost, and open weights can't be recalled. None of these excuses inaction; each one breaks a familiar regulatory tool.

The definition trap

Every AI law needs a scope clause, and every scope clause suffers. Define "AI" broadly and the spreadsheet's regression line needs a conformity assessment; define it narrowly by technique and next year's architecture walks around the statute. Thresholds inherit the problem: laws keyed to training compute pick numbers that efficiency gains quietly devalue — a fixed FLOP line captures less capability every year it stands. The workable pattern so far: regulate by use and risk rather than technique, accept fuzzy edges, and delegate detail to bodies that can revise faster than parliaments.

Uses or models?

The field's central design argument. Use-based regulation attaches rules where harm lands — hiring, credit, medical devices — reusing sector expertise and staying technology-neutral. Its blind spot: general-purpose models sit upstream of a thousand uses, and some risks (a model that meaningfully assists weapons development) exist before any deployment. Model-based rules target the upstream artifact — training disclosures, evaluations, safeguards — at the cost of regulating an ingredient rather than a harm. Serious regimes now do both, which is why compliance teams read two rulebooks.

Who's actually in the room

Effective regimes borrow enforcement structures that exist: consumer-protection and competition agencies, sector supervisors, standards bodies (NIST's risk framework became a de facto shared vocabulary), and the newer AI safety institutes doing technical evaluation work governments couldn't previously perform in-house. The quiet truth: most near-term AI enforcement is existing law — fraud is fraud with a model in the loop, discrimination is discrimination — applied by agencies that got a new caseload before any new statute passed.

Failure mode

Arguing "regulation: yes or no" instead of "which rule, for which risk, enforced by whom." The binary framing produces theater on both sides — sweeping bills that collapse under definitional weight, and lobbying that treats any obligation as apocalypse. The productive questions are boring and specific: what evidence must exist before deployment, who verifies it, what happens when it's missing, and does the assigned enforcer have the technical staff to check. Laws that answer those work; laws that don't, don't.