Getting AI Innovation Culture Right
Abstract
Policymakers must choose between two policy defaults for algorithmic systems: the precautionary principle, under which innovations are treated as guilty until proven innocent, or permissionless innovation, under which they are innocent until proven guilty. The paper argues the United States should reject the former and extend the Clinton-era internet policy vision to AI, because “the most effective solution to technological problems usually lies in more innovation, not less” — and because a country “will only get as much innovation as it allows.”
Publication details
- R Street Policy Study No. 281, March 2023; dated 30 March 2023 and posted to SSRN on 13 April 2023. 21 pages.
- Author: Adam Thierer, R Street Institute.
Innovation culture and the “innovation cage”
- Nations with a more positive innovation culture — attitudes toward innovation, technology, knowledge exchange, entrepreneurship, and uncertainty — have historically enjoyed greater technological advancement.
- The foundation is a dynamic, open economy encouraging new entry, entrepreneurialism, continuous investment, and free movement of goods, ideas, and talent — all strongly influenced by public policy.
- When new technologies challenge the status quo, opponents use policy to erect barriers that lock in archaic rules benefiting incumbents and special interests: the “innovation cage” problem.
- A positive culture requires freedom to try new things without bureaucratic permission at every juncture.
The analog-era regulatory regime as cautionary tale
- For most of the past century, ICT (newspapers, telephony, broadcasting, cable) was governed by operating licences, line-of-business restrictions, price controls, rate-of-return regulation, device rules, and quality-of-service mandates — all in the name of “the public interest.”
- Consequences: less innovation, fewer choices, higher prices, and lacklustre service. In most instances it was illegal to compete.
- The “public interest” standard shifted with political winds, was invoked to justify censorship and evade the First Amendment, and produced an incoherent speech standard — words protected in print could cost a broadcaster its licence. The FCC’s open-ended authority also enabled “regulation by raised eyebrow.”
- Concrete casualties cited: FCC spectrum and localism policies that blocked DuMont as a fourth national TV network in the 1950s (Fox arrived only in the mid-1980s); regulatory roadblocks against cable and satellite TV; and broadcaster lobbying against satellite radio as recently as the mid-2000s.
- Regulatory accumulation became self-perpetuating — new rules layered on to fix problems created by earlier ones. The FCC now ranks first among independent regulatory agencies in rules promulgated.
”Born in captivity” vs. “born free”
- Cable, satellite, and wireless were “born in regulatory captivity” — immediately subject to existing rules and agencies.
- Data and computing were largely “born free” of sectoral rules, governed instead by common law and general consumer protection law.
- That freedom was a strategic advantage: Steve Jobs and Bill Gates needed no licence or prior approval to launch new computers or software.
The internet policy default
Three developments in the 1990s set the U.S. on course to dominate global ICT:
- The Clinton administration opened the internet to commercialisation and private use, previously restricted to government, universities, and a few large organisations for non-commercial purposes.
- The Telecommunications Act of 1996 largely ignored the internet rather than pigeonholing it into the old regime — with the exception of Section 230, which immunised online intermediaries from liability for third-party content. The author calls it “likely responsible for more economic growth than any provision of law Congress has enacted over the past half century.”
- The Framework for Global Electronic Commerce (July 1997) established a market-oriented vision at a time when skeptics still called the internet a fad — a 1998 prediction by a Nobel laureate held its economic impact would be “no greater than the fax machine’s.”
Framework principles offered as a template for AI policy: treat the medium as a market-driven arena rather than a regulated industry and encourage self-regulation and private-sector leadership; avoid undue restrictions, bureaucratic procedures, and burdens; where government is involved, “support and enforce a predictable, minimalist, consistent and simple legal environment for commerce”; respect the technology’s decentralised nature and bottom-up governance tradition; and keep the legal framework consistent and predictable.
Claimed payoff (Bureau of Economic Analysis, 2021): the U.S. digital economy accounted for $3.70 trillion of gross output, $2.41 trillion of value added (10.3% of GDP), $1.24 trillion of compensation, and 8.0 million jobs.
Two lessons and the case against “regulation by hypothesis”
- Lesson one: preemptive restraints generate costs and unintended consequences; claiming something is “in the public interest” does not make it so. Real-world results matter more than good intentions.
- Lesson two: heavy-handed regulation can make legitimate policy goals harder to achieve. The touchstones of good policy are humility and flexibility.
Illustrations:
- Spectrum: an economist proposing property rights and auctions was “laughed out of the room” at a 1959 FCC hearing; top-down “zoning” of spectrum delayed nationwide wireless markets until 1990s liberalisation. Counterfactual offered: an FCC with authority over computing in the 1950s might have licensed only vacuum-tube mainframes as “in the public interest,” delaying the PC revolution.
- Universal telephone service: a worthy goal pursued through local monopolies and service mandates rather than means-tested vouchers (“phone stamps,” analogous to food stamps) — inefficient for nearly a century, with echoes in today’s broadband access struggles.
- Common themes: mandates over markets, top-down decision-making over bottom-up consumer-driven processes, and rigidity over flexible experimentation.
- The author labels worst-case-driven policymaking “regulation by hypothesis” — policy by hypothetical without regard to the opportunity cost of restrictions. “There is no need to worry about the future if inventors cannot even create it first.”
- On privacy and security problems from the internet era: real, still being worked through, but not solvable preemptively “without fundamentally stunting the development of digital technologies.”
The two visions, contrasted
| Precautionary principle (“innovation cage”) | Permissionless innovation (“innovation culture”) |
|---|---|
| Innovation guilty until proven innocent | Innovation innocent until proven guilty |
| Wisdom via top-down planning and regulation | Wisdom via bottom-up, consumer-centric trial and error |
| Equilibrium and stability as primary goals | Experimentation and resiliency as primary goals |
| Progress must be guided, perhaps limited | Progress freewheeling and open-ended |
| Fear of risk and uncertainty | Embrace of risk and uncertainty |
| Safety through anticipatory regulation | Safety through iterative, flexible governance |
| Ex ante (preemptive) solutions | Ex post (responsive) solutions |
Critique of the Biden AI “Bill of Rights”
- The October 2022 Blueprint for an AI Bill of Rights and accompanying Key Actions are read as a fear-based model foreshadowing a precautionary regime — what pro-regulatory scholars call “unlawfulness by default”, which the author warns could mean technological stagnation by default.
- The Blueprint opens by describing algorithmic systems as “unsafe, ineffective, or biased,” “deeply harmful,” and threatening to public rights, stressing dangers over opportunities throughout.
- Both the Blueprint and the Clinton Framework contain five core principles, but the former imposes affirmative obligations and constraints while the latter emphasises entrepreneurial freedoms.
- Specific obligations flagged as potentially burdensome if converted into rules: public consultation across design through maintenance; extensive pre-deployment testing; proactive and ongoing risk identification and mitigation; independent ethics review before deployment; proactive equity assessments and formal algorithmic impact assessments.
- Important caveat acknowledged: the 73-page Blueprint is explicitly non-binding and does not constitute government policy. As soft law it “might not be as constraining or burdensome in practice.”
- Legislative and institutional proposals viewed as the real risk: the Algorithmic Accountability Act of 2022 (mandatory impact assessments filed with the FTC, plus a new Bureau of Technology), the Protecting Americans from Dangerous Algorithms Act, and academic proposals for an “FDA for Algorithms,” a National Algorithmic Technology Safety Administration, or an AI Control Council.
- NEPA is singled out as a bad model for algorithmic audits: assessments now average 600+ pages with 1,000+ page appendices and take an average of 4.5 years; the law is “effectively a bias towards the status quo” and “easily captured by small groups with strongly held opinions.”
- EU comparison: the data-economy regime is said to have decimated Europe’s IT sector, and the forthcoming AI Act’s conformity assessments and fines will burden SMEs — the European Commission’s own estimate for required quality management systems is roughly $193,000–$330,000 upfront plus $71,400 annually.
Proposed alternative: agile governance
- Soft law — informal, iterative, experimental, collaborative mechanisms: multi-stakeholder processes, regulatory sandboxes, industry codes of conduct, technical standards, private certifications, agency workshops and guidance, informal negotiation, and education. Japan, Singapore, and South Korea are cited as pursuing largely non-regulatory approaches.
- Private standards and best practices — ACM, IEEE, ISO, and UL ethical guidelines and “safety-by-design” standards; AI frameworks from the U.S. Chamber of Commerce, Business Roundtable, BSA, ACT, and CTA; corporate guidelines from IBM, Intel, Google, Microsoft, Salesforce, SAP, and Sony, which the author notes are remarkably consistent with one another. The recommendation is to build on these and supplement with voluntary certification and auditing.
- Multi-stakeholder convening — government’s role should focus on convening toward consensus best practices. The NIST AI Risk Management Framework is held up as addressing many of the Blueprint’s concerns in a more flexible, less fear-based way, being “designed to be responsive to new risks as they emerge” rather than itemising them in advance.
- Product recall authority and consumer protection law — the FTC and state offices act against unfair and deceptive practices; NHTSA, FDA, and CPSC hold broad recall authority applicable to algorithmic or robotic defects.
- Courts and common law — contracts, property rights, nuisance, torts, and products liability. Products liability law is described as “highly adaptive to the many new technologies that have emerged in recent decades.” The author faults the Blueprint for barely mentioning existing regulatory or court-based remedies.
- Reputational incentives and competition — firms have incentives to improve safety to avoid liability, bad press, and lost customers; competition is “the most important pro-consumer policy of all.”
Conclusion
- A policy paradigm that stacks the deck against innovation by default will produce less innovation; innovation culture is a function of incentives.
- Over the past half century “regulation has clobbered the learning curve” in nuclear, nanotech, and advanced aviation, with society losing innovations to foot-dragging and opposition from special interests, activists, and bureaucrats.
- Demonising AI also discourages people from studying or pursuing careers in the field.
- Geopolitical stakes: with China and others competing in advanced IT, the United States needs a positive innovation culture “if it hopes to prosper economically and ensure a safer, more secure technological base.”