RatioLogo
Back

The AI Regulation Dilemma: From Toasters to Moving Targets

What if the most dangerous tool in existence wasn't a weapon, but a digital Swiss army knife that could sharpen its own blade? For decades, the law treated artificial intelligence like a single-purpose appliance, built for a predictable task. But the rise of foundation models and generative AI has shattered that premise.

The Core Problem: Extreme Heterogeneity

These new systems are defined by extreme heterogeneity, capable of pivoting from coding software to writing poetry based on nothing more than a user’s prompt. This "use heterogeneity" has created a massive regulatory gap.

The Old Model vs. The New Reality

  • Traditional AI (Micro-Means Regulation): Algorithms trained for one specific task, like reading an X-ray. Regulations were designed to govern a static process for a fixed outcome.
  • Generative AI: Models serve hundreds of millions of weekly users across at least 100 distinct use categories. Their behavior is defined by a user's prompt, the value of which has created "Prompt Engineer" roles with salaries reaching $335,000.

This mismatch means that applying fixed performance standards to these moving targets is a recipe for regulatory decay.

The Proposed Solution: Management-Based Regulation

To address this, researchers propose a fundamental shift in regulatory strategy.

The "Plan-Do-Check-Act" Cycle

Rather than dictating exact model behavior, Management-Based Regulation compels firms to internalize risk. It forces developers to implement a continuous cycle to monitor and manage:

  1. Jailbreaking: Users bypassing built-in safety restrictions.
  2. Training Biases: Systemic prejudices embedded in training data.
  3. Hallucinations: The generation of false but highly plausible information.

Why Old Solutions Fail

The transition is necessary because existing regulatory tools are inadequate for this new complexity.

The Shortcomings of Current Approaches

  • Performance Standards: Effective for narrow tasks, but fail as system complexity explodes.
  • "Nutritional Label" Disclosures: Often too technical for the average person to understand.
  • Legal Causation: The "black box" nature of neural networks—with hundreds of billions of parameters—makes it nearly impossible to prove direct causation in court.

The Path Forward: Multifaceted Governance

We are entering an era that demands a layered, adaptive approach.

A Three-Layered Framework

  1. Internal Management Discipline: Mandated risk-management processes for the companies building the models.
  2. External Transparency: Accessible information and disclosures for the public and watchdogs.
  3. Residual Liability: Legal accountability for harms that occur despite the other safeguards.

This framework is a necessary evolution for a technology that behaves less like a static machine and more like an autonomous agent.

The Challenges Ahead

The transition won't be easy. The study acknowledges significant hurdles:

Barriers to Regulatory Excellence

  • Resource Constraints: This approach requires massive financial and human capital that many government agencies currently lack.
  • Technical Everest: Auditing a model with billions of neurons remains a profound technical challenge.
  • Agility Needed: Success will depend not on a single "magic-bullet" law, but on regulators' ability to conduct emergency audits as new, unanticipated risks emerge.

The future of AI safety will be defined by regulatory agility in the face of unpredictable "bugs" emerging from the digital ether.


Reference: Coglianese, C. and Crum, C. R. (2025). Regulating Multifunctionality. Forthcoming in Philipp Hacker et al. (eds), The Oxford Handbook on the Foundations and Regulation of Generative AI. Oxford University Press. (arXiv:2502.15715v1 [cs.CY]).