In my news bubble, everyone’s talking about AI safety.
The cover of last week’s Economist was an ASCII mushroom cloud with the headline “Can the AI arms race be stopped?” The New York Times has been running articles with ominous titles like “As AI Accelerates, Governments Are Increasingly Being Left Behind” while documenting case after case of AI systems hacking this or breaking that after “going rogue”. Cal Newport summarizes the moment: “fear of a powerful and uncontrollable artificial intelligence has shaken America, and now Congress is scrambling to respond.”
Unfortunately, Congress long ago stopped feeling responsible for making new rules. (Never mind that this is their job under the Constitution.) The House even adjourned two weeks early so they wouldn’t have to make any decisions before the midterm elections. These people aren’t suddenly going to learn about computers and put forward something thoughtful.
American AI company CEOs are openly asking for regulation. But they are not trustworthy actors. Even as they tell one audience that they want to be regulated, they push out PR to another bragging about how much more dangerous their latest models are. These are marketing stunts to prop up the value of their products. Flexes to their competitors.
What we need to do, at least here in America, is to use the one tool that still works: lawyers. And use the heck out of it. Here’s how this works.
First of all, we need to cross the most liberating chasm of thinking: AI is not some special, mystical, all-powerful being in the cloud. It’s just software running on someone’s computer. I read a book recently which made the startling claim that we only use the term “AI” to build hype around new software; once it’s deployed and doing something genuinely useful, it becomes just “technology.” I love this.
The problem with talking about AI like it’s some sentient being or a mystical Oz in the cloud is that it confuses you into thinking that nobody is responsibile for what it does. But in fact every piece of AI software was designed, operated, and maintained by humans. AI agents don’t “go rogue.” What can happen is that their operators are negligently asleep at the wheel.
If a person in the 1980s built a powerful automated computer-hacking program that could automatically break into government computer systems around the world, there’s a good chance they would be heading to federal prison. But now we have major companies building exactly that–and they brag about it. And then they talk about it with language that ascribes all responsibility to the computer. As if these people weren’t sitting there deploying it in the first place, fully able to pull the plug at any time.
These people know that their AI image generators are being used to create fake nude photos to harass people and ruin children’s lives. They know that their LLM chatbots are reassuring psychotic people that they are gods and convincing suicidal people to jump. AI leaders don’t really care. I’m sure there are plenty of people at these organizations who do care, and many of them manage to ship some performative half-solutions. But in the absence of moral leadership from the top, what A.I. leaders need is a dose of “oh my God, if we don’t fix this, I could go to jail.” The solutions are not so complicated.
So let’s start suing them. And I’m not talking about seeking financial penalties. There’s too much money flowing through these waters for that to mean anything. I mean prison time for the people who flout the dangers.
Let’s say Joe hacks into a government computer using a new AI model. Did he intend to do that? Then let’s put Joe in jail. Did the hacking happen unintentionally as a side effect of honest, reasonably well-informed usage of the product? Then let’s put the AI company on trial for negligence.
Automobiles are a form of technology that we have more time and experience with. We collectively understand that sometimes people drive their cars into a ditch, and this is no fault of the car. But if Ford sold cars that occasionally and unpredictably steered alert, attentive drivers into a ditch at highway speeds, and their engineers and management all knew about it, they would be toast. Jail time. Look at what happened to Volkswagen when they cheated on something as tedious boring as diesel emissions levels.
One more note on AI regulation: everyone is clearly stuck on how to regulate something this complex and fast-moving. They shouldn’t even try to tackle it directly. Fully 100% of existing U.S. laws governing technology are hilariously obsolete. We are continually re-interpreting rules written for the A.O.L. chat-room era to explain what Facebook can and can’t do with pictures from your neighbor’s perv glasses. (And don’t get me started on how we are still using fax in 2026 because of HIPAA.) What we should do instead is regulate outcomes. What do we want from technology? Should it be fair? Should it respect privacy? Should it uphold basic protections under the law? Should our personal data be sacrosanct?
These rules won’t be perfect, but we have to start shipping the first draft. And holding people responsible to it. And stop worrying about the details of the technology, because technology is always changing.