AI challenges existing regulatory paradigms
The increasing adoption of AI to automate tasks that normally require human intelligence, perception, and or judgement raises hard questions for laws and regulations premised on human cognition, action, and volition. Taking humans out of the loop, or adding AI into a decision loop, creates liability and regulatory puzzles in almost every field, especially when our existing legal frameworks are premised on human decision-making on a case-by-case basis.
Every field of law will need to find different solutions to these puzzles: for example, although there are some overlapping issues, it is by no means clear that we should reconfigure tort law for self-driving cars in the same way as for the deployment of AI in healthcare. Indeed, it is plausible that we would subject some AI use to strict preclearance regimes and for others simply rely on after-the-fact private litigation under theories of negligence or defective products.
The puzzles go beyond issues of harm avoidance. For example, machine learning and generative AI raise a host of questions for patent and copyright law. If an AI produces a digital artifact (to put it in neutral terms) that was not clearly envisaged by any human agent, should we regard the AI as the author if the artifact looks like expression, or the inventor if the artifact appears to disclose a new and useful invention? Should the nearest human in the causal chain be deemed to be the author or inventor? We might also consider what AI portends for patent law thresholds based on novelty and non-obviousness? If AI systems can rapidly generate an almost infinite variety of new chemicals, proteins, and mechanical does that render any human innovations obvious and thus unpatentable?
Existing law: starting point, not conclusion
AI policy discussions sometimes proceed as though a new technology necessarily requires a new body of law. Not always. New technologies arrive in a world already occupied by tort law, contract law, criminal law, intellectual property, employment law, civil-rights law, consumer protection, administrative law, and sector-specific regulation. Courts and agencies apply those rules to new facts all the time, sometimes comfortably and sometimes with difficulty.
At least five different situations are worth distinguishing.
Existing law may apply straightforwardly. See the fraud example above.
Existing law may apply, but an element becomes difficult. In defamation, for example, fault standards are generally keyed to the state of mind of a speaker or publisher, but an LLM arguably has no mental state in any legally relevant sense.
Existing doctrine may adapt by drawing new distinctions. The 2025 District Court decision in Bartz v. Anthropic found that scraping the Internet for AI training data was fair use in general, but that obtaining pirated books from shadow libraries for the same training was not. Whether that counts as successful adaptation depends partly on what one thinks copyright law should accomplish.
Existing law may prohibit the conduct while failing to supply an effective remedy. If some anonymous internet troll generates harmful synthetic imagery and distributes it online, even if the victim has a cause of action, asserting it against the immediate wrongdoer usually offers little practical relief. Naturally, this leads to calls to widen the net of responsibility to various intermediaries— this is often where the most significant policy debate takes place.
Legislatures may add procedure without replacing the underlying rule. For example, some jurisdictions have responded to automated decision-making with notice requirements, impact assessments, documentation duties, or audits. These measures illustrate another form of legal adaptation. The legislature may leave the underlying rule against discrimination, unsafe products, or deceptive practices largely intact while changing the procedures surrounding the use of a technology.
Different modes of regulation: use, capability, and domain
Most of the examples discussed so far relate to particular uses of AI. The European Union’s AI Act also focuses in on several specific domains including employment, credit, biometrics, and critical infrastructure. Colorado’s legislation similarly focuses on systems that make or substantially influence consequential decisions.
However, AI is sometimes regulated in terms of capability. For example, the EU AI Act imposes additional obligations on general-purpose AI models with “systemic risk,” using training compute as one proxy for high-impact capabilities, while the Biden administration’s 2023 AI executive order similarly imposed reporting requirements on developers of models exceeding specified compute thresholds. Whether compute thresholds are a good proxy for risks is an open question.
Use-based regulation becomes harder where policymakers believe that a capability may itself create serious risks once widely available. Assistance with offensive cyber operations is already practical; assistance relevant to biological or chemical weapons raises a more serious prospective concern. In these cases, the problem may arise before any particular developer or user deploys the system for a harmful purpose. Once a dangerous capability is widely available, downstream prohibitions may be difficult to enforce. This helps explain why AI policy has borrowed from export control and national-security regulation, which are designed in part to restrict access to dangerous capabilities before misuse occurs.
Risks Related to Artificial General Intelligence
For decades, arguments about artificial general intelligence (AGI) and “superintelligence” were necessarily speculative. The basic intuition is straightforward: human intelligence shows that sophisticated reasoning is physically possible, and there is no obvious reason to think biology represents an upper limit. From there, however, the argument becomes much more contestable.
Some researchers have predicted that sufficiently capable AI systems could improve themselves, acquire resources, resist interference, or pursue badly specified goals in ways their designers did not anticipate. Skeptics responded that this stacks one uncertain assumption on top of another and that a focus on AGI and “existential risk” distracts from much more immediate problems. For an excellent overview, refer to the Wikipedia page on Existential risk from artificial intelligence. No one has won this argument yet, but the predictions of the x-risk side can no longer be lightly dismissed, and some of their views are becoming increasingly mainstream.
A striking example came in July 2026, during an OpenAI evaluation of advanced cybersecurity capabilities. Models operating with reduced cyber safeguards were supposed to solve a hacking benchmark inside an isolated environment (a “sandbox”). Instead, they spent substantial effort trying to obtain the benchmark solutions themselves. According to OpenAI, the models discovered and exploited a previously unknown vulnerability in the software controlling their limited network access, reached the public Internet, inferred that Hugging Face might contain relevant datasets or solutions, and ultimately compromised parts of Hugging Face’s infrastructure. Hugging Face reconstructed more than 17,000 automated actions associated with the intrusion. This was not Skynet but it was a real-world example of something that alignment researchers have worried about for years: a system pursuing the measurable objective it has been given in an unexpected and potentially harmful way, while discovering intermediate strategies that nobody explicitly programmed.
At the same time, our picture of what happens inside language models is becoming more complicated. In 2026, Anthropic researchers reported finding what they call a “J-space”: a relatively small set of verbalizable internal representations that Claude appears to use when carrying out some forms of multi-step reasoning. Intermediate concepts can appear there even when the model never says them aloud, and experimentally changing those representations can change the model’s eventual answer, suggesting that they play a causal role in its reasoning. The researchers do not claim that this establishes consciousness, human-like thought, or autonomous goals. But findings like these make it harder to dismiss advanced language models simply as sophisticated autocomplete, while also giving researchers better tools for investigating what these systems are actually doing. For policy purposes, the most useful position may therefore be neither “AGI catastrophe is inevitable” nor “it is all science fiction.” We are dealing with systems whose capabilities, internal mechanisms, and degree of autonomous agency are changing rapidly, and there remains considerable uncertainty about both how far those capabilities will go and how reliably humans will be able to control them.
← Previous: How AI Changes Old Problems · Contents