Commentary. Artificial-intelligence policy is entering the most consequential phase of its short political life. Governments are no longer debating whether AI should be governed; they are arguing over how, by whom and at what cost. Our view is that the next generation of rules should focus less on dramatic promises of control and more on measurable duties: testing, transparency, human accountability and remedies for people harmed by automated decisions.

The case for urgency is straightforward. In 2026, lawmakers continued to address AI in employment, housing, finance and education, while also considering safeguards for frontier models and independent audits. The Center for Democracy & Technology describes a legislative landscape moving toward oversight of “consequential” automated decisions, even as comprehensive federal legislation in the United States remains absent.[1] That gap leaves people exposed to systems that can influence their lives without giving them a meaningful way to challenge an error.

Europe has taken a different route. The EU AI Act’s obligations are now entering enforcement, with requirements that include human oversight for high-risk systems.[2] The European model offers a valuable principle: where an algorithm can materially affect someone’s rights or prospects, responsibility cannot be outsourced to software. A person or institution must remain answerable for the outcome.

The argument for restraint

But regulation can fail when it mistakes a compelling slogan for a workable safety mechanism. Proposals for mandatory “kill switches” and similar emergency controls are spreading across jurisdictions. Critics argue that such measures may not match the technical and operational realities of complex AI systems, particularly when models are integrated into wider software, business and infrastructure networks.[3] A switch that sounds reassuring in a hearing may be difficult to define, test or use without causing disruption.

Industry also has a legitimate concern about fragmentation. Developers now face differing requirements across countries and, in the United States, a growing patchwork of state initiatives. Compliance costs may be manageable for the largest firms but prohibitive for smaller companies, universities and public-interest laboratories. Poorly designed rules could therefore entrench dominant platforms—the opposite of what competition policy should seek.

Those objections should shape policy, not end the discussion. The answer is not voluntary self-regulation alone. The record of technology governance is full of assurances that became less persuasive after systems were deployed at scale. Voluntary commitments can be useful, but they need independent verification and consequences when companies mislead regulators or users.

What responsible oversight looks like

First, governments should regulate uses and risks rather than rely on vague labels such as “AI.” A spellchecker, a medical triage system and an autonomous weapon do not present the same stakes. Rules should be proportionate, with the heaviest obligations reserved for systems capable of affecting safety, liberty, access to essential services or democratic participation.

Second, audits should be genuinely independent. A company’s internal safety report may provide important technical information, but it cannot substitute for scrutiny by bodies that can inspect evidence, reproduce tests and publish meaningful findings. Regulators should also require incident reporting, so the public can see whether safeguards work outside controlled demonstrations.

Third, people need rights that operate in practice. Notice is not enough if it is buried in legal language. Individuals should be told when an automated system materially shaped a decision, receive an understandable explanation and have access to a qualified human review. These protections should apply whether the system is supplied by a technology company or built inside a government agency.

Finally, policymakers should resist the temptation to legislate through panic. AI can amplify fraud, discrimination, cyber risks and misinformation, but it can also improve accessibility, research and public services. Rules that prohibit useful experimentation without reducing serious risks will lose legitimacy—and may push development into less transparent environments.

Our position is therefore neither “regulate everything” nor “let innovation decide.” It is that powerful systems should earn trust through evidence. The public should not have to choose between unchecked automation and impossible promises of perfect control. Governments can demand safety while leaving room for innovation, provided that accountability is clear, oversight is independent and the people affected retain a voice.

The current policy race will produce many headlines. The durable test will be quieter: whether an ordinary person denied a job, loan or service by an automated system can find out why, challenge the decision and obtain a remedy. That is where AI governance should begin—and where it should ultimately be judged.

Sources