By Steven Cohen, Ph.D., Director of the M.S. in Sustainability Management program, School of Professional Studies
While Artificial Intelligence is a new technology that I am still learning about, I have been studying and publishing on regulatory strategy for over three decades. I have always approached regulation pragmatically, with the goal of maximizing the market’s power to innovate while seeking to understand, measure, and minimize risk. The goal of regulation is to influence behavior, and there are many ways to achieve that goal. It has become clear that the United States must develop and implement regulations to govern this powerful and important new technology. The free market cannot ensure safety, and the need for AI regulation is urgent.
AI is a powerful production technology, like energy, chemicals, transportation, finance, or biotechnology. It should be encouraged where it improves human welfare but governed where it creates measurable risk. An AI regulatory strategy should include these seven key elements:
- Define and measure harms clearly.
Regulation should focus on observable and potential risks: AI acting without human control, privacy violations, fraud, safety failures, misinformation, labor displacement, national security threats, including disruptions of energy and water systems, and environmental impacts from biohazards, as well as data centers. These potential harms must be objectively observed, measured, and analyzed. - Use risk-based regulation.
Low-risk AI tools should face minimal rules. High-risk uses in medicine, finance, employment, policing, education, infrastructure, elections, and weapons should face strict testing, documentation, audit, and accountability requirements. All AI is not created or used in the same way. Both the production and use of AI need to be understood. Whenever possible, government should stay out of the way of private sector innovation, but when risks are high, rules are needed. - Build government competence and organizational capacity.
Rules are meaningless without capable agencies. Governments need technical staff, audit capacity, procurement expertise, data science capacity, and the ability to update standards quickly. We need an AI regulatory agency that includes scientists who have worked to develop this technology. This is the most critical element of the strategy. While I do not see this happening in this anti-regulatory Trump era, we need to develop independent AI expertise as soon as possible. In the short run, this capacity might need to be built by foundation-funded nonprofits or universities with the goal of migrating this capacity into government when the ideological antipathy to all regulation fades, or the crisis becomes so obvious that even a Trump-style government would act. The President’s announcement last week of the creation of an “AI Force” and appointment of a “AI Czar” should not be confused with a serious effort at understanding and regulating AI. While true regulation and enforcement of rules is not yet politically feasible, an expert and independent nonprofit could analyze and monitor AI and educate the public when risks are detected. This could hopefully compel voluntary risk reduction by the AI developer or user. This voluntary approach is a good place to start, but it is far from sufficient. - Require transparency and accountability, not total disclosure of trade secrets.
When government finally decides to regulate AI, it should ensure that firms document training data sources, testing results, known limitations, safety incidents, model capabilities, and risk controls. I assume firms are making mistakes with these new models, but my hope is they learn from the mistakes and are someday soon required by law to report both the problem and the solution to the government and to the public. If there is no solution yet in place, Artificial Intelligence developers should be required to request help. But regulation should protect legitimate intellectual property while giving regulators enough information to verify safety. This will be difficult to accomplish, and if we err, it should be on the side of disclosure—even if government must purchase the intellectual property, it needs to be disclosed. - Invest in public AI infrastructure.
We need public investment in AI to maximize its benefits: AI literacy, public-interest AI research, cybersecurity capacity, worker retraining, enhanced broadband, clean energy for data centers, and government use of AI to improve public services. Our goal should be to maximize the benefits of Artificial Intelligence. The danger now is that fear of this technology and its unregulated negative impact will impair its development and discourage its use. I see AI as roughly analogous to the invention of the internet and search engines: Search engines on steroids. We live in a complex, interconnected world. AI provides a tool for understanding and managing that complexity, so we can benefit from the technologies that enhance productivity and human well-being. - Use incentives as well as command-and-control regulation.
Tax credits, grants, liability rules, public procurement standards, insurance requirements, and certification systems could push firms toward safer systems without freezing innovation. I have always seen command and control as the last resort. Rules and punishment for their violation are not always and not often the best way to motivate behavior. Tax incentives could be used to reward successful technologies that help humans maintain control of AI and impair the ability of AI models to act on their own. Requiring insurance of risks enlists private insurance companies to the battle against the risks of Artificial Intelligence and motivates companies to be serious about risk reduction. Insurance companies charge less for safe automobile drivers and more for drivers with accidents and traffic violations. AI risk insurance could be required, and companies better at reducing risk would pay less for insurance. An insurance requirement could provide a powerful tool in the effort of controlling risks from AI. - Global coordination and national enforcement.
While global AI rules are needed, most real enforcement will remain national. International agreements can set standards for safety testing, cyber misuse, military use, privacy, deepfakes, and model evaluation. National governments must implement and enforce them. This will need to begin with an agreement with China to coordinate and share technological development rather than add AI to the long list of areas we compete in. If aliens invaded the Earth, we’d work alongside all national governments, including China, to resist subjugation. Consider AI a form of potential alien invasion. But remember we live in a world where sovereignty remains with the nation-state and therefore serious rules must rely on national enforcement.
Regulatory strategy for Artificial Intelligence should be multi-dimensional. One size does not fit all, and rules alone are insufficient. We need a system of incentives and disincentives and the technical capacity to inspect and understand the rapidly evolving AI models under development. Our goal is to influence the behavior of those who produce and use Artificial Intelligence. Behaviors will vary, as will the AI models they are based on. The idea that this technology can be shut off or banned is extremely unrealistic. The notion that AI poses no threat is naïve.
The tech bros managing the development of AI have a history, albeit a short one, of disdain for government and rules. They are also a group that can be both arrogant and disingenuous. In Peggy Noonan’s excellent column in last week’s Wall Street Journal, she took a close look at the language used by AI companies to discuss the problems they face and observed that:
“We must take a moment here to discuss the language of AI, which those who cover it are increasingly, inevitably using. It is uniquely dishonest and misleading. AI companies should be pressed on this point and greater clarity demanded… This summer it occurred to me that my understanding of alignment might be wrong. I understood nonaligned to mean “the system is acting in a way not in line with our values.” I asked an expert, who said no, it has nothing to do with values; an AI system that is in nonalignment simply isn’t doing what it’s told. It’s disobeying orders. Not in alignment means the machine is pursuing its own goals… When AI agents escape containment, they say it left “the sandbox.” Oh those frolicking bots tripping through the local playground. Sometimes they say it “slipped the leash” like a puppy… “Recursive self-improvement”… is an awfully benign linguistic formulation for something that means “The machines are in charge and no longer paying attention to the humans.” A less benign name for RSI might be Escaping Human Control or Machine Takes Over.”
There is also the suspicion that the large AI companies are now confessing fear because they believe that regulation will prevent the entry of start-ups into the business they now dominate.
All of this means that regulating Artificial Intelligence will be both difficult and complicated. The leadership of AI companies tends to think they are smarter than everyone else. They assume they can control any effort to govern their businesses, and that may be why some are advocating regulation. Effective regulation of AI will require a serious, pragmatic, and nonideological approach that helps build the business while protecting the public interest. Typical of American politics in the polarized era, the issue has rapidly jumped on the political agenda, with politicos appealing to the public’s fear of the impact of AI’s use and stoking a “Not in my Backyard” response to the data centers AI requires to function. These are real concerns that need to be approached with care and sensitivity. I don’t see either industry or government approaching this issue with care; instead it’s being used to gain and wield power. Trump’s proposed AI Czar is likely an effort to dominate rather than regulate this growing industry. We need a competent and well-led federal government to meet this challenge. Functioning regulation will not be built on the dysfunction that now characterizes all three branches of our federal government. The capacity to govern Artificial Intelligence will need to be built, hopefully before we endure an AI-induced catastrophe.
Views and opinions expressed here are those of the authors, and do not necessarily reflect the official position of Columbia School of Professional Studies or Columbia University.
About the Program
The Columbia University M.S. in Sustainability Management program offered by the School of Professional Studies in partnership with the Climate School provides students cutting-edge policy and management tools they can use to help public and private organizations and governments address environmental impacts and risks, pollution control, and remediation to achieve sustainability. The program is customized for working professionals and is offered as both a full- and part-time course of study.