Advertisement

In 2023, the European Union passed the AI Act, the world's first comprehensive legal framework for artificial intelligence. In 2024, the United Kingdom published a white paper outlining its own approach. The United States issued executive orders on AI safety and began drafting federal legislation. China, which had already been issuing AI regulations since 2021, added new requirements around generative AI. Over 60 countries have now published some form of national AI strategy or regulatory framework.

The speed of this legislative activity is historically unusual. Governments rarely agree on technology policy at this pace, across this many jurisdictions simultaneously. Something is genuinely alarming them. Understanding what that is requires separating the rhetoric from the substance.

The three things governments are actually worried about

Strip away the speeches and position papers, and the regulatory concern about AI clusters around three core issues: economic disruption, information integrity, and catastrophic risk.

Economic disruption is the most immediate. As detailed elsewhere, AI is set to displace a significant proportion of the white-collar workforce within a decade. This is not a scenario governments can simply manage after the fact, the tax base, the social safety net, and the political stability of most democratic societies are built on an assumption of broad employment. A rapid, AI-driven hollowing out of the middle-income workforce is a destabilising event of a kind that few modern governments have contingency plans for.

Information integrity is arguably more urgent in the short term. AI systems can now generate synthetic video, audio, and text indistinguishable from genuine human output. Deep-fake videos of political leaders saying things they never said are trivially easy to produce. AI-generated disinformation campaigns can now operate at scale and speed that human fact-checkers cannot match. The 2024 election cycles in the United States, India, and the United Kingdom all featured AI-generated disinformation as a significant documented factor. Governments that depend on public trust to function have every reason to be alarmed.

"The problem is not that governments are moving too fast on AI regulation. The problem is that the technology is moving faster than any regulatory system can follow."

Catastrophic risk: the argument that changed everything

The third concern, catastrophic or existential risk from advanced AI systems, was, until recently, largely confined to academic papers and technology conferences. It entered mainstream policy discourse in 2023, when a letter signed by over 1,000 AI researchers and technology leaders called for a pause on advanced AI development. Shortly after, the heads of several leading AI companies testified before the US Senate that the technology they were building posed potential civilisation-scale risks.

This is the part of the AI debate that most people find difficult to assess. The risks being described, AI systems that pursue goals misaligned with human values, or that could be used to design biological weapons, are speculative in the sense that they have not happened. But the researchers making these arguments are not fringe figures. They include people who built the systems in question. Governments have decided, on balance, that the arguments are serious enough to warrant regulatory attention.

Advertisement

Why regulation is so difficult

The challenge facing regulators is not motivation. It is the fundamental difficulty of writing rules for a technology that evolves faster than the legislative process. By the time a law passes through a parliament or congress, the AI systems it was written to govern may have been superseded by systems two or three generations more capable. The EU AI Act, for example, was written primarily with 2021-era AI systems in mind. By the time it came into force in 2024, the systems it was designed to regulate had already been dramatically outpaced by GPT-4, Gemini, and their successors.

The jurisdictional problem is equally severe. AI development is global. A company developing a potentially dangerous AI system can, in principle, simply operate from the jurisdiction with the lightest regulatory touch. Without international coordination, which is slow, difficult, and politically complicated, national regulation can simply push activity offshore without reducing the actual risk.

What is actually being done

Several approaches are showing promise. The EU's risk-based framework, which applies heavier oversight to AI used in high-stakes contexts like criminal justice, healthcare, and critical infrastructure, while leaving low-risk AI largely unregulated, has become a template other jurisdictions are adapting. Mandatory safety evaluations for the most powerful AI models, before they are released, are gaining traction in multiple countries.

International coordination is also advancing, if slowly. The Bletchley AI Safety Summit in 2023, which brought together governments including the US, UK, EU, China, and others, produced a shared declaration acknowledging catastrophic AI risk. A series of follow-up summits have been held since. None of this constitutes binding international law, but it represents a level of multilateral engagement on the issue that did not exist two years ago.

The honest assessment is that regulation is running behind the technology, and will probably continue to do so. The goal, for most thoughtful regulators, is not to catch up but to establish principles and institutions that can adapt quickly as the technology evolves. Whether that will be enough remains one of the genuinely open questions of the coming decade.

Advertisement