Global Edition
The Doom Ledger
Est. 2026
AI is not a new church, and people don’t need a new pope.

Who Regulates the Model? Inside the Fight Over Frontier AI Rules

Regulate the model, the deployment, or the company? The answer determines who bears the cost.

A legislative chamber — photo by Ole Neitzel, licensed under CC BY-SA 4.0 via Wikimedia Commons.

There is a genuine technical question at the centre of the regulatory debate, and it is not about whether rules are needed. It is about what layer of the stack the rules should attach to.

Training time, deployment, or the developer

Regulating the model means imposing obligations at training time: compute thresholds, disclosure of training data, pre-deployment testing, incident reporting. It targets the smallest number of actors and the capabilities that cause the most concern, but it requires defining what counts as a frontier model, and that definition ages quickly.

Regulating the deployment means imposing obligations on whoever puts a system in front of users: sector-specific rules, transparency about automated decisions, redress mechanisms. It is closer to how existing law works and easier to enforce, but it multiplies the number of regulated entities enormously.

Regulating the company means imposing duties on the largest developers as institutions: safety programmes, whistleblower protection, reporting to a supervisor. It is administratively simple and mirrors how financial regulation works.

Advertisementin-article · responsiveAfter the opening section of a long article. Never between a heading and its own body.

Every layer has a loser

  • Model-level rules concentrate cost on a handful of labs, which they argue is unfair competition policy.
  • Deployment-level rules spread cost across thousands of businesses, which they argue is a compliance burden.
  • Company-level rules require deciding which firms are large enough to matter.

Capability thresholds now, deployment duties later

Most jurisdictions appear to be assembling a hybrid: capability thresholds at the model layer, obligations at the deployment layer for high-risk uses, and institutional requirements for the largest developers. Each element is weaker than a single-minded approach would be, and each is harder to evade than any one alone.

The unresolved question is what happens when the activity moves faster than the rulemaking. That is not a hypothetical: it is the operating condition of the entire field.

States moved first, industry wants one national rule

The most consequential disagreement in the United States is not between regulators and industry but between levels of government. Several states have moved ahead with their own requirements, and industry has argued for a single national framework on the grounds that a patchwork is unworkable.

Advertisementin-article-2 · responsiveRoughly two thirds down a long article.

Critics of that position reply that federal preemption without a federal standard means less protection rather than more. This is the same debate that has accompanied consumer privacy, data breach notification and autonomous vehicles, with similar stalemates.

Building to the strictest regime on the map

Companies operating across jurisdictions will face the strictest applicable requirement in practice, since maintaining separate systems is usually more expensive than complying everywhere. That gives the most demanding regime a gravitational pull beyond its own borders.

Whether that dynamic produces convergence or fragmentation depends on how divergent the requirements become. Where they concern disclosure, convergence is likely. Where they concern permitted uses, companies will build to the strictest and offer the difference only where it is legal.

Image credit and licence details for every photograph on this site are listed on the credits page. This article is editorial content; it carries no sponsored material.

Related

Advertisementfooter-banner · 970x90End of page, above the site footer. Never inside the footer itself.