Commentary. The central question in artificial-intelligence policy is no longer whether governments should regulate powerful systems. It is whether the rules they adopt will be strong, clear and enforceable enough to protect the public without freezing useful innovation.

Recent developments offer reason for both optimism and concern. The European Union’s AI Act has entered its enforcement phase, with transparency obligations applying from August 2026 and additional marking requirements for some generative-AI systems due later this year. [1] In the United States, by contrast, the policy landscape remains more dependent on voluntary commitments and a patchwork of state laws. China is pursuing its own state-directed framework, combining oversight with an insistence that technological development continue at speed. [2]

Our view is straightforward: voluntary promises can be useful, but they cannot be the foundation of public safety. Companies should be encouraged to exceed legal requirements, yet the public should not have to trust that commercial incentives will always align with the public interest.

The case for firm rules

AI systems increasingly influence employment, housing, finance, education and access to public services. A 2026 review of US state legislation found continuing attention to automated decisions in these consequential areas, alongside proposals for independent audits and controls on frontier models. [3] These are not abstract risks. An opaque system that wrongly rejects a loan or filters out a job applicant can affect a person’s life even when no one intended discrimination.

Binding standards can establish minimum protections: documentation, testing, human review, reporting of serious failures and remedies for people harmed by automated decisions. They can also create a level playing field. Responsible companies should not be undercut by competitors that save money by ignoring safety checks.

The EU’s risk-based model reflects this logic. It distinguishes between relatively low-risk applications and systems considered unacceptable, including certain forms of manipulation and social scoring. [2] That approach is imperfect, but it is preferable to pretending that every AI product carries the same stakes.

The case against overreach

Critics are right to warn that regulation can become slow, vague or disproportionate. Small businesses may struggle with compliance costs that large technology companies can absorb. Rules written around today’s systems may become obsolete quickly, while broad restrictions could discourage medical research, accessibility tools and other socially valuable applications.

There is also a legitimate concern about fragmented regulation. The US state-by-state approach may produce conflicting requirements, while different national regimes could raise costs for companies operating across borders. Industry groups argue that flexible standards and voluntary testing can respond faster than legislation.

“It may make sense” to codify some voluntary AI safeguards into law or formal regulations in the future, according to a recent industry-government accord. [4]

That argument deserves serious consideration. Regulators should avoid demanding impossible guarantees or treating every error as proof that a system must be banned. They should consult researchers, workers, civil-society groups and businesses, and build in review mechanisms so rules can change as evidence changes.

What accountability should mean

Flexibility, however, is not the same as self-regulation. The current debate needs a practical baseline: companies deploying high-impact systems should disclose what those systems do, test them for foreseeable harms, preserve records for independent review and provide a meaningful appeal when automated decisions cause damage.

Governments should also identify who is responsible when a system fails. Responsibility cannot disappear into a chain of vendors, datasets and algorithms. Nor should users be asked to accept secrecy as the price of convenience.

International coordination would help. Twenty countries and the EU have called for cooperation to keep AI under human control, including discussion of an oversight body. [4] Such cooperation will be difficult, especially when the US, EU and China favor different political and economic models. But shared principles on testing, incident reporting and human accountability are achievable.

The right policy is neither a blank cheque for industry nor a blanket prohibition on innovation. It is enforceable regulation aimed at the highest risks, paired with room to experiment in lower-risk settings. Governments should move quickly—but not carelessly—and companies should welcome rules that make trust measurable rather than promotional.

AI will not be governed well by pledges alone. The public needs rights, transparency and someone answerable when systems cause harm. Anything less leaves the most consequential decisions to the least accountable actors.

Sources