AI Regulation: Who Controls the Controllers?

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through these links, we may earn a small commission at no extra cost to you. This helps support Outside The Case and allows us to continue producing independent content. We only recommend products and resources we genuinely find valuable.
9 min read

In April 2024, the European Union passed the AI Act — the world’s first comprehensive legal framework for artificial intelligence. It was hailed as historic: a bold attempt by democratic governments to impose accountability on the most consequential technology in a generation.

Eighteen months later, the picture is more complicated.

The largest AI companies — based in the United States, funded by the deepest capital pools in history, operating at a speed that legislative calendars cannot match — have continued building. The models have grown larger. The capabilities have expanded. The deployment has accelerated. The Act’s tiered risk categories and conformity assessment procedures are, by the assessment of most technical observers, already lagging behind what the technology can do.

This is not a failure unique to Europe. It reflects a structural problem that no jurisdiction has solved: AI is developing faster than the institutions designed to govern it. The question of who controls AI is, in practice, the question of who sets the pace — and right now, the answer is not governments.

The Regulatory Landscape

Three distinct regulatory philosophies are currently competing for global influence.

The European approach is precautionary and rights-based. The AI Act classifies systems by risk level — unacceptable (banned outright), high-risk (conformity assessments required), limited risk (transparency obligations), and minimal risk (largely unregulated). Banned systems include social scoring by governments, real-time biometric surveillance in public spaces, and manipulative AI targeting vulnerable groups. High-risk systems — covering employment screening, credit scoring, educational assessment, law enforcement, and critical infrastructure — face pre-market testing, human oversight requirements, and ongoing monitoring obligations. The logic is broadly analogous to pharmaceutical regulation: demonstrate safety before deployment, not after.

The Act’s weaknesses are real. It is technology-neutral in design but application-specific in implementation, which means general-purpose AI systems — the ones causing the most debate — fall into complex jurisdictional grey zones. Its enforcement depends on national authorities that vary enormously in technical capacity. And its territorial scope, while formally applying to any AI system deployed in Europe regardless of origin, faces obvious practical challenges when the developers are headquartered in California and operating globally.

The American approach is market-led and ex-post. The United States has produced executive orders, agency guidance documents, and voluntary commitments from major AI labs, but no comprehensive federal legislation. The dominant philosophy, influential across both parties though argued differently, is that regulation must not slow American innovation at a time when geopolitical competition with China defines the technology stakes. The AI Safety Institute, established under the Biden administration’s 2023 executive order, represents a genuine institutional step — but it operates through voluntary testing agreements with AI companies, not legally binding requirements.

The consequence is a system where the companies developing the most powerful AI systems are substantially self-regulating, with government playing a consultative and occasionally reactive role. This has advantages: American AI development has moved at extraordinary speed, and the country’s AI capabilities currently lead the world. The risks are structural: there is no reliable mechanism to require safety testing before deployment, no mandatory incident reporting system, and no standing authority to pause development of capabilities that regulators determine to be unsafe.

China’s approach is state-centric and targeted. Beijing has moved with unexpected speed in some areas — algorithmic recommendation systems, deepfakes, and generative AI each have specific regulations requiring provider registration, content watermarking, and government approval for public-facing deployments. But these regulations are narrowly focused on political control and social stability, not on the broader safety concerns that preoccupy Western researchers. China’s AI companies operate in a regulatory environment that is simultaneously restrictive (in what content can be generated) and permissive (in deployment speed, data collection, and civilian application).

The Self-Regulation Problem

The case for trusting AI companies to regulate themselves is not entirely without merit. The major AI labs — OpenAI, Anthropic, Google DeepMind, Meta AI — have published extensive safety research, established internal safety teams, and in several cases voluntarily paused or limited deployments they assessed as premature. Some of the best thinking about AI risk comes from people inside these companies.

The case against self-regulation is also not without merit. It rests on a structural observation: companies competing for market share in a winner-take-most technology race have powerful incentives to move quickly and powerful disincentives to create unilateral constraints their competitors will not match. The history of self-regulation in technology — social media’s handling of misinformation, the smartphone industry’s relationship with attention and children, the advertising ecosystem’s privacy practices — does not provide grounds for confidence.

The honest version of the current situation is that AI development is outpacing governance by a margin that is widening, not narrowing. The gap exists not because governments lack intelligence or will, but because the technical complexity of modern AI systems makes meaningful external oversight genuinely difficult. You cannot regulate what you cannot evaluate, and evaluating the capabilities, failure modes, and emergent behaviours of frontier AI systems requires technical expertise that few regulators possess and AI companies have little incentive to share.

The Compute Governance Question

One angle that has gained traction among AI governance researchers involves a different leverage point: not regulating AI systems themselves, but regulating the hardware required to build them.

Training frontier AI models requires extraordinary quantities of specialized computing hardware — primarily Nvidia’s A100 and H100 GPUs, and their successors. This hardware is manufactured by a small number of companies (primarily TSMC in Taiwan), using supply chains that pass through a handful of chokepoints. The US government has already weaponized this chokepoint in its competition with China, imposing export controls that have significantly slowed Chinese AI development.

The same logic could in principle be applied to domestic regulation. If training runs beyond a certain compute threshold required prior notification to a regulatory body — and if cloud providers were required to report large training runs to government — regulators would at least know what was being built before it was deployed. This would not solve the governance problem, but it would close the information gap that makes meaningful oversight nearly impossible.

The AI safety community has discussed compute governance extensively. Governments have moved more slowly. The reasons are partly technical (verification is hard), partly political (the companies most affected are among the most powerful corporate lobbies in Washington and Brussels), and partly conceptual (there is no consensus on what threshold should trigger oversight or what oversight should entail).

The International Dimension

The governance problem has a dimension that no single jurisdiction can solve: AI is developed and deployed globally, and a regulation that restricts one country’s AI companies while leaving others unaffected primarily handicaps the regulated party in a competitive race.

This is not a hypothetical concern. EU officials privately acknowledge that overly restrictive AI regulation risks driving development to more permissive jurisdictions. American policymakers worry that excessive federal regulation creates an opening for Chinese AI systems to fill markets that American systems vacate. The structural dynamic is a regulatory race-to-the-bottom, in which the prospect of competitive disadvantage disciplines governments toward permissiveness even when they would prefer caution.

The analogy to financial regulation after 2008 is instructive. The Basel accords — international agreements on banking capital requirements — emerged from the recognition that national financial regulation in an interconnected global system creates arbitrage opportunities that undermine everyone’s stability. The question of whether something analogous can be built for AI is one of the central governance challenges of the decade.

The G7 Hiroshima AI Process, launched in 2023, represents an attempt at international coordination. The OECD AI Principles, endorsed by 46 countries, represent another. Both are voluntary, non-binding, and light on specifics. The distance between these diplomatic frameworks and binding international governance is vast.

The Accountability Vacuum

At the centre of the AI regulation debate sits a question that is simultaneously legal, philosophical, and practical: when an AI system causes harm, who is responsible?

Current law struggles to answer this. AI systems are not legal persons. They cannot be sued, fined, or imprisoned. The companies that build them, the companies that deploy them, and the individuals who use them all share in the outcome in ways that existing liability frameworks are not designed to apportion.

A medical AI that misdiagnoses a patient — is the developer liable? The hospital that deployed it? The doctor who deferred to its recommendation? A hiring algorithm that systematically discriminates against candidates from a particular demographic — who answers for the outcomes it produced over years of use before the bias was detected?

These are not hypothetical cases. They are happening now, in courts across the US and Europe that are improvising frameworks from consumer protection law, product liability doctrine, and employment discrimination statutes — none of which were designed with AI in mind.

Liability clarity is not a glamorous regulatory intervention. It does not generate headlines or satisfy the appetite for decisive government action. But it is arguably the single most important governance lever available: if the developers and deployers of AI systems face meaningful financial and legal exposure for harms their systems cause, they have immediate and powerful incentives to invest in the safety testing and human oversight that voluntary commitments have not reliably produced.

The Deeper Question

Every governance debate eventually reaches a value question that technical analysis cannot resolve.

The governance debate about AI is no exception. Beneath the arguments about risk categories and compute thresholds and liability frameworks is a dispute about what AI development is for — whether it should be primarily optimized for economic output and competitive advantage, or whether it should be subject to the kind of democratic deliberation we apply, however imperfectly, to other technologies that reshape how people live and work.

That question has not been answered. In most countries, it has barely been asked. The technology has moved too fast, the lobby too effective, the complexity too daunting.

The AI Act is one attempt. Executive orders are another. Both are real things. Neither is an answer.

The gap between what AI can do and what governance can address is not a gap that will close naturally. It closes only if societies decide, deliberately and in the full understanding of what is at stake, that they want to close it. The technology will not wait for that decision. It never has.

Also explore:

AI Ethics: The Complete Guide

The AI Existential Risk Debate

AI Is Changing the Nature of War

Digital Privacy: The Complete Guide


Sources & Further Reading

Related Articles

Stay Ahead of the Curve

Get weekly analysis on geopolitics, global conflicts, and the forces shaping our world. Join thousands of readers who think beyond the headlines.

We don’t spam! Read our privacy policy for more info.

Weekly Geopolitical Briefing

Go Beyond the Headlines

Analysis of the forces shaping the world - delivered every week. No noise, no bias, just depth.

Subscribe Free ?

No spam. Unsubscribe anytime.

António Monteiro

About the Author

António Monteiro

Engineer by profession, geopolitical analyst by conviction. I believe responsibility for the planet's future doesn't belong only to governments and institutions - it belongs to all of us. Knowledge about geopolitics, international conflicts, and the forces shaping the world is the most powerful tool for becoming more conscious, informed citizens. You don't need to be a diplomat to understand what's at stake - you just need to want to go beyond the headlines. At Outside The Case, I analyze conflicts, power dynamics, and global trends with rigor and accessible language, so you can understand what's really happening in the world.

Read more about the author →

Leave a Reply

Discover more from Outside The Case

Subscribe now to keep reading and get access to the full archive.

Continue reading

Enjoyed this analysis? Get more every week → Subscribe Free