Commentary. The political argument over artificial intelligence has moved from whether regulation is necessary to what kind of regulation can actually work. That is progress—but also a warning. Governments are now proposing emergency shutdown mechanisms, auditor registries and new duties for developers, while companies continue to promise that voluntary safeguards will keep pace with increasingly capable systems. Our view is that neither slogans nor technical theater will protect the public. AI oversight must be practical, independently testable and backed by consequences.
The case for urgency is strong. Regulators are responding to systems that can make decisions, generate persuasive misinformation and act with growing autonomy. The European Union’s AI Act already requires human oversight for high-risk uses, while other countries are developing distinct controls for autonomous systems and “circuit breakers.” The resulting patchwork is making compliance harder for developers operating across borders.[Source]
That fragmentation is not merely an inconvenience for technology companies. Different definitions of risk can leave citizens with different protections depending on where they live. A bank, hospital or public agency may use comparable systems under sharply different rules. Smaller developers could also be squeezed by compliance costs that large firms can absorb, potentially concentrating power in the companies best positioned to shape the rules.
Yet the answer is not to suspend regulation until every government agrees on a single global framework. The Center for Democracy and Technology reports that U.S. lawmakers are addressing automated decisions in employment, housing, finance and education, as well as chatbot safety and frontier-model risks. It also notes that no federal AI bill has passed during the current U.S. session, while states continue to legislate.[Source] State experimentation can expose weaknesses and produce useful models. It can also create confusion. The goal should be interoperability: common definitions, compatible reporting requirements and mutual recognition of credible audits.
The limits of the “kill switch”
Proposals requiring emergency shutdown buttons sound reassuring because they translate an abstract risk into a familiar physical metaphor. But an AI system is rarely a single machine with one obvious off switch. It may be distributed across cloud infrastructure, connected to external tools and copied into downstream products. A button that stops one service may not stop the model’s outputs, cached data or systems built around it.
That does not make emergency controls useless. They can be valuable for restricting access, disabling dangerous functions and preserving human authority over high-stakes actions. But legislation should demand demonstrated control effectiveness rather than a particular piece of interface design. Regulators should ask developers to show how systems can be paused, rolled back, monitored and isolated—and require independent testing under realistic conditions.
The alternative, favored by some industry leaders, is voluntary responsibility. In the United States, major AI companies have publicly pledged to monitor capabilities, assess whether systems follow human intentions and work with independent evaluators.[Source] Such commitments can move faster than legislation and may help establish technical standards.
But voluntary promises cannot substitute for public accountability. Companies face commercial incentives to release products quickly, and private evaluations may lack transparency. The fact that a firm agrees to an audit does not answer who selects the auditor, what the auditor can inspect or what happens when serious failures are found. Independent testing needs protected access to systems, published methodologies and penalties for concealment—not simply a favorable press release.
Regulate consequences, not headlines
The most defensible approach is targeted regulation. Rules should focus first on uses where errors can deny people housing, work, education, credit, health care or due process. They should require notice, meaningful human review, documentation, incident reporting and a route to challenge automated decisions. Frontier-model obligations should be proportionate to demonstrated capabilities and foreseeable risks, not to a company’s marketing language.
Europe’s experience also shows why implementation matters as much as legislation. The EU has applied rules for general-purpose models and transparency obligations, while a later simplification package delayed some high-risk application timelines.[Source] Delays may give businesses time to prepare, but they can also postpone protections for people exposed to risky systems. Any transition should therefore include clear interim duties and public reporting on enforcement.
Our newsroom does not believe every AI danger can be solved by law, or that every proposed safeguard deserves approval simply because it is called “safety.” But the opposite confidence—that innovation will reliably police itself—is equally unconvincing. The public deserves rules that are technically literate, democratically accountable and capable of changing as evidence improves. That means fewer theatrical promises, more independent testing and cooperation across jurisdictions. The race to build AI may be global; responsibility for its consequences must be, too.
Sources
- TechTarget, “Developers facing a patchwork of competing AI safety regulations”
- Center for Democracy and Technology, “2026 State and Federal AI Legislation Updates”
- NPR, “This is how evaluators test if an AI model is safe”
- American Bar Association, “2026 Artificial Intelligence Rules and Global Data Protection Risks”