Abstract

Frontier AI should be governed through a hybrid public-private system in which government-authorised private bodies certify, on an opt-in basis, that developers meet a heightened standard of care — with certified developers receiving safe harbour from tort liability for customer misuse of their models. Authorising multiple competing private regulators puts different governance approaches into trial against each other and against the legal status quo.

Framing: the meta-problem

  • Beyond addressing discrete foreseeable risks, there is a meta-problem: designing a governance structure — the mechanisms, processes and checks and balances used to solve problems themselves.
  • Hayek’s distinction is invoked: a nomocratic (process-oriented) rather than teleocratic (goal-oriented) structure, more akin to constitutional design than to any specific policy.
  • Scope: the proposal covers development of software systems, not physical manifestations like self-driving cars, robotics or drones, which the author tentatively judges adequately covered by existing law.

1.1 Why frontier AI is different

  1. Systems are intended to match or exceed human intellectual capability, including any cognitive task performable with a computer — cyberattacks, fraud, intimidation. Misuse potential is high.
  2. Being software, they are infinitely scalable and replicable, so harmful activity can be scaled rapidly enough to overwhelm societal defences.
  3. They improve rapidly — algorithmic efficiency improvements of roughly 400% per year alongside falling compute costs, so any capability available at high cost now should be an order of magnitude cheaper within about 12 months.
  4. Researchers do not fully understand how they work or how to control them — mechanistically, predictively, or in terms of alignment and adversarial robustness. Current models resemble biological systems more than deterministic software, so these are likely never to be solved “perfectly”: canonical wicked problems solved piecemeal, through bricolage.

Consequently, governance should not aim at absolute control — which is neither achievable nor obviously desirable — but at “a modicum of order.” Governance frequently operates through incentives: assigning accountability (fines, liability damages) and benefits (legal protections, easier market access).

1.2 Why frontier AI governance

  • It concentrates policymakers on the most acute emerging risks, giving the state a “preview” of capabilities soon to reach a much wider range of actors.
  • Frontier development involves a small number of firms, making it legible to law without a massive boost in state capacity.
  • Frontier firms lead their industry in capabilities, market share and resources, so their adoption of best practices propagates.

1.3 The limits of use-based regulation

  • The paper does not argue against use-based regulation, but holds that it can easily become onerous and that even a well-designed regime is insufficient.
  • It also distinguishes governance during the transition to advanced AI from governance after it, arguing the former faces meaningfully distinct constraints.

2. Why centralised government regulation is undesirable

2.1 Political economy

  • Public choice lens: regulatory bodies are composed of individuals — bureaucrats, lobbyists, politicians — with their own incentives; the question is what regulation is likely to achieve, not what it is intended to achieve.
  • Rent-seeking and regulatory capture need not be corrupt; they often arise sociologically through patterns of interaction between regulators and regulated entities, and are especially likely in complex technical fields where risk measurement and mitigation are high-dimensional.
  • Frontier AI firms themselves could wield large amounts of power over the political and regulatory system.

2.2 Practical barriers

  • The technology evolves rapidly and is difficult to define precisely, even at the frontier.
  • Frontier AI regulation requires answering questions that currently have no good answers and may never.
  • Hiring the necessary human experts is difficult, plausibly more so in the public sector given fixed pay scales and lengthy hiring timelines — though the UK and US AI Safety Institutes are acknowledged as having staffed themselves ably.
  • Effective governance will require aggressive and creative adoption of emerging technologies, including frontier AI systems themselves: “How could one effectively govern, for example, the internet, without also using the internet themselves?“

3. Alternatives assessed

3.1 Compute governance

  • Spans export controls, on-chip governance (co-processors tracking location and security status), and more ambitious ideas such as a government-backed “Compute Reserve” operating like a central bank, adjusting compute available to the global market.
  • Strengths: there is no frontier AI without frontier compute; compute is physical and therefore far more legible than infinitely replicable software.
  • Weaknesses:
    • Export controls have worked reasonably well but may backfire long-term by causing China to redouble semiconductor investment; once a rival ecosystem exists, controls on American products stop functioning as intended.
    • Controls created path dependency: illicit and quasi-illicit movement of hardware pushed the US from “small yard, high fence” to the Biden Diffusion Framework regulating global diffusion of advanced models and large compute clusters — i.e. regulating data centre construction, compute export and frontier model use in every country on Earth.
    • Even leading proponents concede controls won’t deny China the ability to develop frontier models (as DeepSeek v3 and r1 partly demonstrated); the argument is about denying ecosystems. Sensible, but it means controls won’t stop adversaries if frontier AI is a weapon.
    • Additional mechanisms like on-chip governance only add incentive for adversaries to build alternative computing ecosystems — after which compute governance ceases to be viable as a foreign policy tool.
  • Compute governance has so far been used to limit or deny capabilities to adversaries; its limitations are even more apparent for building a domestic governance regime.

3.2 Tort liability and insurance

  • A tort (from tortum, “twisted”) is a wrongful act causing injury — physical harm, property loss, or both. In the US it is primarily state law, varying considerably by state, with bodies like the American Law Institute harmonising standards.
  • Tort liability already applies to frontier developers for at least some harms, and the most prominent proposed US AI laws rely on negligence as their enforcement mechanism — meaning tort liability is America’s current default governance mechanism for frontier AI.
  • Historical note: US tort law transformed in the mid-20th century from a purely legal mechanism into a tool of economic policymaking, as society contended with the managerial corporation, mass-produced goods, automobiles and modern pharmaceuticals.

3.3 International governance

  • Advocated by figures from Geoffrey Hinton to Sam Altman, but “there is currently no path to achieving it”: global affairs are characterised by increasing strife and the fraying of international institutions, with the US and China in protracted conflict including over technical and governance standards.
  • Any international regime must grapple with the tension between controlling advanced AI and respecting sovereignty. AI will be a general-purpose civilisational fundament, and it is each country’s right to choose how to use it within very wide bounds — policing narrower bounds without a global surveillance system over all AI use remains unexplained.
  • The paper does not dispute the prudence of AI diplomacy but argues American effort is best channelled domestically, designed to be exportable later. Narrow future windows for cooperation are most likely to be seized if the US already has demonstrably functional governance practices — and because private governance organisations operate more readily across international lines than governments, private governance is argued to be the approach most likely to facilitate long-term international collaboration.

4. The proposal

4.1 Structure

  1. A legislature authorises a government commission to license private AI standards-setting and regulatory organisations, granted to bodies with technical and legal credibility and demonstrated independence from industry.
  2. Developers opt in to certification from those bodies, which verify compliance with published technical safety and security standards, with annual audits.
  3. Certified developers receive safe harbour from all tort liability related to misuse by others.
  4. The government body periodically audits and re-licenses each private regulator.
  5. Safe harbour does not apply to conduct that is reckless, deceitful or grossly negligent.
  6. Private bodies can revoke a developer’s safe harbour for non-compliance.
  7. The government body can revoke a private regulator’s licence for negligence — e.g. ignoring non-compliance.

Why multiple private regulators

  • Competition mitigates the tendency of regulation to accrete complexity and compliance cost.
  • Innovation and experimentation in governance design — a core thesis being that advanced AI will itself be a breakthrough governance technology (automated creation of model evaluations, automated monitoring via tightly bound AI agents).
  • Avoiding one-size-fits-all technocracy: institutional entrepreneurs can carve out niches — a body for startups marketing heavily modified foundation-model agents, distinct standards for open-source and open-weight models, dedicated bodies for robotics or biological foundation models.
  • Designed to accommodate state or federal implementation, with private bodies operating across state lines so states can act without creating a compliance patchwork — though federal enactment is preferred for a single nationwide standard.

4.2 The authorizing government body

  • A multi-member commission with fixed members from agencies with AI expertise (Director of NIST or the US AI Safety Institute, OSTP Director) plus members appointed by Congress and the President — or, in a state implementation, the Attorney General, leaders of public research universities, and appointees from outside government representing academic and research communities.
  • Powers should be significant but narrow to prevent mission creep: an absolute right to certify and decertify private bodies and to investigate them and the firms they certify, but no broad rulemaking authority. Considerations beyond tort-related harm should be statutorily disallowed unless matched by analogous liability protections (e.g. adding algorithmic bias would require adding civil rights liability protection).
  • Anti-race-to-the-bottom mechanism: revoking a private regulator’s licence eliminates liability protections for all companies it covers. If Company B’s poorly overseen models cause major harm under lenient Regulator C, Company A also loses protection — giving both firms an incentive to avoid piling into a knowingly lax regulator. A blunt instrument, designed so licences are revoked only for serious misconduct.

4.3 The private governance bodies

  • They develop technical standards, model evaluations, auditing and monitoring mechanisms to ensure an elevated standard of care, with minimal prescription as to how — by design, since advanced AI is expected to transform the task of governance itself and radically increase the cognitive capabilities of small teams.
  • Explicitly inspired by Gillian Hadfield and Jack Clark’s “Regulatory Markets” paper: private regulators may develop new, data-intensive, AI-based regulatory technologies, and targets choose and can switch between competing licensed regulators on cost and efficiency. (The paper notes Clark co-founded Anthropic, which would be a covered entity.)
  • The regime is preemptive, aiming to protect against tort harms before they occur; over time lawmakers could set performance targets for private regulators, such as incident counts involving property damage or physical injury.
  • Two levels of competition: within the regulatory market, and between the regulatory market as a whole and the legal status quo — allowing the contention that plain tort liability is lighter-touch and more effective to be put to a market test.
  • Independence challenge: much of the needed expertise will come from the frontier AI industry, with attendant financial exposure. Possible solutions: divestment requirements, barring recent industry veterans from private governance boards, a statutory cap on the ratio of staff with industry experience, and tailored routine audits.

4.4 Liability protections

  • Protections apply only to tort liability, and only to harms arising from user misuse. They do not cover standard corporate tort exposure (premises, workplace), statutory liability (civil rights, consumer protection, environmental), or harms from first-party use — e.g. an internal deployment that exfiltrates itself and commits tortious acts.
  • Adjustable parameters: the safe harbour could apply only below an objective threshold (e.g. property damage under $500 million, or deaths below a threshold), above which it shifts to a rebuttable presumption of reasonable care or disappears entirely. Alternatively the whole protection could take the form of a rebuttable presumption against all tort claims — softer, possibly deterring some participation, but preserving the spirit especially at federal level.

4.5 Institutional-economics advantages

  1. Lower transaction costs — private transacting bodies can define, monitor and enforce rules among themselves more cheaply than government regulators.
  2. Smaller information asymmetries — a private body with tailor-made structure, specialised expertise and sophisticated use of technology closes more of the gap than a government regulator can.
  3. Heterogeneity — a flexible private system serves a diverse industry better than one-size-fits-all regulation.
  4. Reputation mechanisms — quasi-government certification may be far more valuable to firms marketing large-scale knowledge-work automation to regulated-industry customers than a standard government fine.