A Framework for the Private Governance of Frontier Artificial Intelligence
Abstract
Frontier AI governance needs a nomocratic (process-oriented) rather than teleocratic (goal-oriented) structure — “not a solution to any discrete problem, but an articulation of the set of mechanisms, processes, and checks and balances used to solve problems themselves.” The proposal: a legislature authorises a commission to license competing private standards-setting and regulatory bodies; developers opt in to their certification and audits; in exchange they receive safe harbor from tort liability for user misuse of their models.
Publication details
- Preprint by Dean W. Ball — Fellow at Fathom, Research Fellow at the Mercatus Center, Nonresident Senior Fellow at the Foundation for American Innovation.
- The paper directs readers interested only in the mechanism to Section 4; the rest builds context.
- Scope limits stated upfront: the regime targets the gravest harms — loss of personal or digital property (fraud, cyberattacks) and physical harm — which is why the incentive is tort safe harbor rather than protection from civil rights or consumer protection liability. Other harms such as algorithmic bias could be folded in, but only with a matching safe harbor against the analogous liability. It covers software systems, not physical manifestations like self-driving cars, robotics, or drones, for which existing legal frameworks are judged reasonably suited.
Why frontier AI needs qualitatively different governance
Four features distinguish it from past technology waves:
- Systems are intended to match or exceed human intellectual capability, including any cognitive task performable via computer — cyberattacks, fraud, threats — so misuse potential is high.
- Being software, they are infinitely scalable and replicable, so harmful activity can scale rapidly enough to overwhelm societal defences.
- They improve rapidly — algorithmic efficiency gains on the order of 400% per year alongside falling compute costs mean any capability available at high cost now is roughly an order of magnitude cheaper, and available to a wider range of actors, within about twelve months.
- Researchers do not fully understand how they work or how to control them — mechanistic understanding, output prediction, objective alignment, and adversarial robustness are all incomplete. Current models are “more like biological systems in their complexity than… deterministic software systems,” so these are canonical “wicked” problems solved piecemeal, through bricolage, and never “perfectly.”
The consequence: no governance system should aim at absolute control, which is neither achievable nor on the table given the current trajectory. The realistic goal is “a modicum of order.” Governance frequently operates not by banning but by creating incentives through the assignment of accountability (fines, damages) and benefits (legal protections, market access).
Why frontier specifically: it concentrates attention on the most acute emerging risks and gives the state a “preview” of capabilities soon to be widely available; frontier development is done by few enough firms to be legible to law without a massive boost in state capacity; and frontier firms lead their industry in capabilities, market share, and resources, so their practices propagate.
Why centralized government regulation is undesirable
- The analysis is framed through public choice economics — regulators as organisations of individuals with incentives, aiming at “what regulation is likely to achieve rather than what it is intended or desired to achieve.”
- Regulatory capture need not be corrupt; it “arises almost sociologically, through simple patterns of interaction,” and is especially likely where measuring and mitigating risk are high-dimensional tasks creating information asymmetry that makes deference to regulated firms’ expertise hard to avoid.
- But capture by the AI industry is not the main worry — the tech industry “has been remarkably unlikely to lobby for regulatory moats against competition in recent decades.” The greater danger is the many other special interests AI threatens: primary and higher education, healthcare, financial services, lawyers, media, and white-collar professional services — “some of the most powerful interest groups in American politics.”
- A centralized general-purpose regulator becomes a legal chokepoint through which any of these groups can lobby to slow development, degrade product utility (e.g. requiring licensed human review of AI outputs competing with licensed professionals), and impede diffusion.
- Weighing these tradeoffs is “fundamentally political, rather than technocratic or even particularly legal” — properly the function of legislatures, not bureaucracies. A centralized regulator “short circuits this fundamentally political process.”
Alternatives assessed and found wanting
Compute governance
- Spans export controls, on-chip governance (coprocessors tracking location and security status), and more ambitious ideas like a government-backed “Compute Reserve” operating like a central bank for global compute availability.
- Genuine advantages: “There is no frontier AI without frontier compute,” and compute is a physical good, far more legible than infinitely replicable software — the highest-end hardware being “among the most difficult-to-produce goods mankind has ever devised.”
- But: the Biden export controls, while working reasonably well, appear to have redoubled China’s commitment to catching up on semiconductor design and manufacturing, at which point controls on American products stop functioning as intended. Controls on desirable physical goods reliably produce illicit and quasi-illicit movement, and within roughly two years a “small yard, high fence” approach had ratcheted into the Diffusion Framework’s regulation of “the global diffusion of the most advanced artificial intelligence models and large clusters of advanced computing integrated circuits” — requiring regulation of datacenter construction, compute export, and frontier model use “in every country on Earth.”
- Even leading proponents concede controls will not deny adversaries the ability to develop frontier models (as DeepSeek v3 and R1 partly showed), only the economy-wide ecosystem benefits. And additional mechanisms like on-chip governance only strengthen the incentive to build an alternative computing ecosystem, after which compute governance ceases to be viable as a foreign policy tool. Its limits are sharper still for a domestic regime, which is this paper’s object.
Tort liability
- Tort liability “broadly conceived, is America’s current default governance mechanism for frontier AI development” — the most prominent proposed U.S. AI laws have relied on it, negligence in particular.
- Historical framing: U.S. tort law underwent a mid-20th-century transformation from a purely legal mechanism into a tool of economic policymaking, as scholars applied strict liability to products and softened negligence standards to force corporations to internalise externalities. Codified in the Restatement (Second) of Torts in 1964, §402(A) became “the most cited section of any [ALI] Restatement.” So “the system as it exists today was very much the result of a deliberate and top-down effort” — notably, by the American Law Institute, itself a private governance body.
- Consequences are contested: necessary internalisation of harms, or a “lottery” in which companies are held responsible “essentially at random for harms alleged by sympathetic victims.” Near-indisputable is that by the 1980s tort exposure caused an insurance market panic, leaving vaccine and airplane manufacturers, medical practitioners, day care providers, and municipalities unable to afford or obtain coverage.
- A structural limit: the vast majority of tort cases end in dismissal or settlement, so “almost none of the harms contemplated by tort law result in a court-mediated fact-finding procedure,” and almost none generate the precedent that is the common law’s key benefit.
(International governance is likewise reviewed and found insufficient for the transition period.)
The proposal
- A legislature authorises a government commission to license private AI standards-setting and regulatory organizations — granted to bodies with technical and legal credibility and demonstrated independence from industry.
- AI developers opt in to certification from those bodies, which verify that the developer meets the body’s published technical standards for security and safety, with annual audits.
- In exchange, certified developers receive safe harbor from all tort liability related to misuse by others resulting in tortious harm.
- The authorizing body periodically audits and re-licenses each private regulator.
- The safe harbor does not apply to conduct that would legally qualify as reckless, deceitful, or grossly negligent.
- The private body can revoke a developer’s safe harbor for non-compliance.
- The authorizing body can revoke a private regulator’s license for negligence — for example, ignoring developer non-compliance.
Why multiple competing private regulators
- Competition mitigates regulation’s tendency to accrete complexity and compliance cost over time.
- It permits innovation in governance itself — a core thesis is that “advanced AI will itself be a breakthrough governance technology,” enabling automated creation of model evaluations and automated monitoring via tightly bound AI agents.
- It avoids one-size-fits-all technocracy, letting institutional entrepreneurs carve out niches in the “governance marketplace”: dedicated bodies for startups marketing heavily modified agent models, for open-source and open-weight models, and for emerging markets like robotics or biological foundation models, “rather than having to be squeezed into some pre-existing regulatory design.”
- Because most U.S. AI legislation so far has been at state level, the private bodies are designed to operate across state lines — letting states enact frontier governance without creating a compliance patchwork. Federal enactment is nonetheless preferred, for a single nationwide standard and better certification expertise.
The authorizing government body
- A multi-member commission with fixed members from agencies with AI expertise (the Director of NIST or of the US AI Safety Institute, the Director of OSTP) plus members appointed by Congress and the President — or, at state level, the Attorney General, leaders of in-state public research universities, and appointees from academic and research communities outside government.
- Powers: review and approve applications, investigate whether a private body has behaved negligently, and revoke licenses. Review should be narrowly focused on technical capability to conduct the certifications envisioned, with all parties prioritising mitigation of plausible tort-related harm.
- Deliberately narrow: to guard against mission creep and political interference, powers should be “significant and narrow” — an absolute right to certify, decertify, and investigate, but no broad rulemaking authority. All considerations beyond tort harm should be statutorily disallowed unless matching liability protections are added.
- Anti-race-to-the-bottom mechanism: revoking a private regulator’s license strips liability protection from all companies it certified. If Company B’s poorly overseen models cause major harm under lenient Private Regulator C, Company A loses its protection too — so participants have a shared interest in the rigour of their chosen regulator.
Independence and staffing
- A key challenge is recruiting expertise, much of which would come from the frontier AI industry, while preserving independence. Proposed solutions: divestment requirements, a bar on recent industry veterans serving on private governance boards, a statutory maximum ratio of staff with industry experience, and routine audits tailored to monitor this specifically.
Liability protections and adjustable parameters
- Protections apply only in tort and only to harms from user misuse — not to ordinary corporate tort exposure (premises liability, workplace harms), not to statutory liability (civil rights, consumer protection, environmental), and not to first-party use, e.g. an internal deployment that exfiltrates itself and commits tortious acts against third parties.
- Adjustable: the safe harbor could be capped, applying only below an objective threshold (property damage under $500 million, or a death count), above which it becomes a rebuttable presumption of reasonable care or disappears. Alternatively, the whole protection could be a rebuttable presumption against all claims — softer, possibly enough to deter some participation, but preserving the proposal’s spirit especially at federal level.
Institutional-economics advantages
- Lower transaction costs — private transacting bodies can define, monitor, and enforce rules among themselves more cheaply than government regulators.
- Smaller information asymmetries — a private body with tailor-made structure, specialised expertise, and more sophisticated technological tools closes more of the gap than a general regulator.
- Heterogeneity — a flexible private system serves a diverse industry better than one-size-fits-all.
- Reputation mechanisms — a quasi-governmental certification may matter far more to firms marketing knowledge-work automation to regulated-industry customers than a standard government fine.
Conclusion
- The paper claims “no perfect order… but neither perfect control by the state or any other authority” — only “modest order in the form of protection from the most dire conceivable harms,” taking political economy, liberty, and major AI risks all seriously.
- The system includes safeguards against both corruption and over-regulation, and leaves harms outside its scope to existing law or future statutes.
- A secondary priority is incentivising institutional innovation in American governance, with lessons expected to transfer to other domains of statecraft.
- Final caveat: no governance system works “without virtuous leadership and prudent enforcement,” and the proposal could still fall to corruption, undue risk aversion, torpor, or needless complexity — pitfalls that are “a problem of culture, not a problem susceptible to clever technocratic tweaks.”