That is the topic of my latest Free Press column. Excerpt:
The key is to create some basic safeguards, but without stifling broader AI progress. To do so, we must defy the conventional wisdom about public oversight and instead trust the AI labs to be their own primary regulators.
My version of the proposal starts with defining a private not-for-profit body for AI regulation. An ideal body would draw some features from FINRA (the Financial Industry Regulatory Authority): a consortium of financial firms that examines the trade practices of each and makes recommendations, helping the federal Securities and Exchange Commission with oversight and regulation. The AI version would include the major labs and would be authorized and overseen by Washington, perhaps through the now-fledgling Center for AI Standards and Innovation.
This body would periodically audit major AI companies and their models, judging their conduct and safety. In the short run at least, much of this would be focused on issues of cybersecurity, and whether the new models created more cyber risk than they help to solve. If a company passed the audit, it would be exempted from standard liability law, at least provided that it had shown basic, reasonable care, as opposed to extreme or deliberate negligence. That would free the AI labs from the fear that courts might derail their business by granting huge awards to plaintiffs for ill-defined harms that could not reasonably have been prevented. And it would give the labs a strong incentive to meet the safety standards of this body.
It is reasonable to wonder whether such a body, composed of industry players, would issue fair and equitable judgments of safety. Maybe not. Yet there are many upsides and no better alternative.
For one thing, each company knows that a dangerous model from another company could cause a harmful incident and damage the prospects for the entire industry. Consider the Three Mile Island meltdown in 1979, which contributed significantly to the mothballing of the entire U.S. nuclear industry. Few people can name the company (Metropolitan Edison) behind the malfunctioning plant; the reputational penalty attached to the industry as a whole.
Another incentive for safety is that the top companies do not want too much competition from lower-price, lower-quality upstarts. That too will induce those companies to support fairly tough standards, perhaps excessively tough in some cases. Still, we are choosing from imperfect alternatives. The concrete truth, whether we like it or not, is that there is far more expertise within the companies for judging AI safety than we can expect to find in the federal government anytime soon.
I am indebted to some ideas from Dean Ball, noting that his proposal is somewhat different. And here are some comments from Brendan McCord.
Facts Only
* A private, not-for-profit body for AI regulation is proposed.
* The ideal body would feature a consortium of financial firms, similar to FINRA.
* This body would examine the trade practices of major AI labs and make recommendations to the federal Securities and Exchange Commission.
* The body would periodically audit major AI companies and their models to judge conduct and safety.
* Initial audits would focus on cybersecurity and the risk posed by new models.
* Companies passing an audit would be exempted from standard liability law, provided they showed basic, reasonable care.
* This mechanism intends to free labs from liability concerns related to ill-defined harms.
* Incentives for safety include avoiding industry-wide risks similar to the Three Mile Island event.
* Top companies seek standards against lower-quality competitors.
Executive Summary
A proposal is put forward to regulate Artificial Intelligence by establishing a private, not-for-profit body for AI oversight. This proposed body would draw on structures similar to FINRA, consisting of industry members who examine trade practices and make recommendations to federal oversight bodies like the Securities and Exchange Commission. The structure would involve major AI labs being audited periodically regarding their conduct and safety, focusing initially on cybersecurity risks. Companies that pass these audits would be exempted from standard liability law, provided they demonstrate basic, reasonable care. This framework aims to incentivize safety by providing a mechanism for accountability and protecting companies from potentially devastating litigation over ill-defined harms.
The rationale presented suggests this industry-led approach is justified because internal expertise within the AI sector may surpass that of current federal regulators in assessing AI safety. Further incentives for safety come from systemic concerns, such as the risk posed by one company's dangerous model impacting the entire industry, and the desire among top companies to maintain standards against lower-quality competitors. The author acknowledges potential challenges regarding the fairness of judgments made by an industry-composed body but argues that alternatives are currently insufficient.
Full Take
The proposal advocates for shifting regulatory authority from purely external government oversight to a self-regulating, expert-driven system managed by industry players. This move is predicated on the argument that the technical expertise necessary to judge AI safety resides within the companies themselves, suggesting that federal intervention would be ill-equipped or too slow to react. The proposed structure attempts to leverage the existing systemic pressure—the fear of reputational damage affecting the entire sector—as a primary driver for voluntary compliance, drawing an analogy from historical industrial accidents like Three Mile Island.
A key tension lies in trusting industry players with regulatory judgment. While this approach offers potential speed and specialized knowledge, it inherently raises concerns about the impartiality of a body composed of competing entities who also stand to benefit from favorable rulings. The argument that companies will self-regulate because of market pressure must be weighed against the possibility that this pressure might lead to "excessively tough standards" or biased outcomes favoring incumbents. The inherent challenge is balancing the practical need for safeguards with the philosophical requirement for equitable and objective safety judgments, especially when dealing with novel risks that lack established legal precedent.
Bridge Questions: If an industry-led body fails to establish universally accepted safety benchmarks, what mechanisms exist to enforce remediation against a defiant entity? How can regulatory bodies effectively audit the internal workings of complex AI models without access being entirely ceded to private entities? What specific metrics would guarantee that financial or competitive incentives do not override genuine safety imperatives?
Sentinel — Human
The text reads like a thoughtful, opinion-driven column blending regulatory proposal with historical analogy to build an argument for industry self-regulation in AI safety.
