Abstract

A lot of valuable time for AI governance was lost in 2025, so comprehensive policy is no longer achievable on the timeline AI capabilities demand. The realistic remaining goal is to “80/20” AI policy — mitigating most of the worst-case risks with a fraction of the effort a slower-progress world would have allowed — which requires prioritising the bare minimum on safety, security, and concentration of power, and acting in 2026 rather than waiting for a better political moment.

Starting point

  • Follows up on a late-2024 post arguing AI exceeding human performance in nearly every cognitive domain was almost certain within a few years, and that comprehensive US AI regulation was needed by the end of 2025 at the latest.
  • That goal was missed. The work remaining requires focus and acceptance that AI policy will not be “nailed.”

80/20ing as the only realistic goal

  • Best case: mitigating roughly 80% of risks with 20% of the effort that would have been applied given slower AI progress and an earlier start. Even this is not assured.
  • Rapid progress relative to governance means, at best, barely avoiding some worst-case scenarios: an AI-enabled biological weapon killing billions, a rogue AI takeover, or stable global totalitarianism.
  • Very bad but not worst-case outcomes probably cannot be avoided entirely: an unjust economic transition causing widespread suffering, AI psychosis and addiction, a rushed transformation of education, smaller-scale AI-enabled terror attacks killing thousands or millions, and stable AI-enabled totalitarianism in a few countries for a few decades.
  • The rapid timeline also means a lot of low-hanging societal benefits will go unpicked, since they were not pursued actively.

Why 80/20 is not equivalent to being doomed

  • Most people do not want to kill everyone, which leaves some margin in how good safeguards must be.
  • Minimal safety caution is in AI companies’ basic self-interest.
  • AI safety is not as hard as some claim.
  • Many people will do beneficial things with AI without being compelled to, because it advances their existing goals.
  • AI will help with its own governance to some extent, e.g. by speeding up societal defences and safety research.

Why more effort is still needed

  • Incentives to cut corners are common, and safety is not trivial either.
  • History shows that even when something could be done safely, people in a hurry find ways to get it wrong — and AI companies admit to cutting corners to avoid being left behind.
  • Illustrative analogies cited: the Bhopal disaster and the Volkswagen “Dieselgate” emissions scandal.
  • The focus is on the bare minimum precisely because it is not clear even that will be achieved.

Ships that sailed in 2025

  • Timely strong regulation. The regulations that emerged all have fatal flaws — watered down by industry lobbying (SB 53, the RAISE Act), counterproductive or focused on less urgent risks (many other state laws), or not durable (the EU AI Act, whose enforcement is vulnerable to US political pressure). 2025 also saw the rise of super PACs focused on stopping meaningful AI regulation. Consequently there is no real requirement for frontier companies to have a good safety and security policy: SB 53 only requires publishing some policy, and the RAISE Act will require it to be “detailed.” No one must share their AI’s constitution or how well behaviour aligns with it, and no external party must check whether a company is following its own policy.
  • Robust misuse prevention. Public health investments were gutted in the US and elsewhere, leaving less pandemic preparedness. No major investments to drive down Far-UVC costs or pre-commit to vaccine purchases. On cyber, little progress on proactively patching open-source code and hardening critical infrastructure, though companies began pushing harder on AI cyberdefence in early 2026.
  • Large-scale safety and security research. Good research exists but is “mom and pop” and underfunded relative to capabilities research, and is often stymied by lack of access to non-public company information. Funding efforts exist, but societal urgency is low and many 2025 proposals for scaling risk-mitigation work have not been followed up.
  • Large-scale AI auditing. A growing third-party audit ecosystem exists, and frontier AI auditing is described as urgently needed, doable, and helpful against extreme concentration of power by introducing external oversight. But there are not enough qualified auditors to rigorously audit hundreds of companies across a full range of risks, forcing triage onto the top few dozen companies and a narrow set of risks. Building demand earlier could have scaled the ecosystem in time.

What people can do

  • Deploy relevant skills now rather than planning for impact years out.
  • Policymakers and those with influence over them: advance state-level policies building on SB 53 and the RAISE Act, and improve the quality and likelihood of a near-term federal compromise passing before the elections.
  • Donors: support organisations working on AI safety, security, and policy (the author plugs his own organisation, AVERI).
  • AI company employees: be more vocal about what the company is doing on lobbying, engage with the policy team on details, and volunteer to brief policymakers. Employees likely have more influence than they think.
  • Everyone: be more engaged on AI policy in everyday life and on social media — most people do not know or care about these issues, which must change for policymakers to feel pressure rather than caving to industry lobbyists.

Why now

  • A common view among “AI policy elites” at companies and in government holds that Congress is broken, nothing happens in an election year, and things are too polarised — with the upshot that the can must be kicked another year.
  • The author understands the perspective but treats it as a self-fulfilling prophecy that burns scarce time.
  • Given uncertain but rapid AI progress that is “not even close to hitting any walls,” the time for 80/20ing is now.