AI may need regulation. But before we create new rules, we should understand who is asking for them, why they want them, and who those rules might protect.

I use artificial intelligence regularly. I think it has tremendous potential, and I also think there are legitimate reasons to be concerned about how it develops and how people use it.

What concerns me almost as much as AI itself, though, is the rush to regulate it.

Especially when some of the loudest voices calling for regulation come from the companies developing the technology.

That should make us curious.

Not automatically suspicious. Not conspiratorial.

But curious.

Why would a private company ask the government to restrict the industry in which it operates?

Sometimes regulation helps the companies being regulated

We tend to think of business and government as natural opponents.

Government regulates. Business resists.

That may be how regulation feels to a small business struggling with rules, paperwork and compliance costs. But the relationship can look very different from the top.

Economists have a term for one version of this: regulatory capture.

It happens when the industry being regulated gains significant influence over the rules and the agencies enforcing them. Instead of simply restraining established businesses, regulation can help protect them from new competition.

Think about what happens when compliance becomes expensive.

A technology company worth hundreds of billions of dollars can employ armies of lawyers, lobbyists, compliance specialists and technical experts.

A startup with six employees cannot.

The same regulation applies to both companies. But it does not necessarily burden them equally.

That doesn’t mean every large company asking for regulation is secretly trying to eliminate its competitors.

It does mean we should ask who will be helped—and who might be shut out.

Why can’t AI companies regulate themselves?

This is the question I keep coming back to.

If an AI company believes a certain practice is dangerous, what prevents it from refusing to engage in that practice?

Companies can test their models more extensively. They can establish safety procedures. They can restrict certain uses. They can submit systems to independent evaluations.

In fact, voluntary frameworks already exist. The National Institute of Standards and Technology has developed an AI Risk Management Framework specifically to help organizations manage AI risks, and participation is voluntary.

So why isn’t voluntary action enough?

There is a legitimate answer.

Competition.

If one company slows development to conduct additional safety testing while another races ahead, the cautious company may lose customers, investors and market share.

Government regulation can create a common floor. Everyone has to meet the same minimum standards, so companies aren’t financially punished for behaving responsibly.

That’s a reasonable argument for regulation.

But it also brings us right back to the most important question:

Who gets to decide what those standards are?

If the largest AI companies become government’s primary advisers on how AI should be regulated, those companies could have tremendous influence over the rules their future competitors will have to follow.

I don’t think we should assume bad motives.

I also don’t think we should ignore incentives.

Fear makes bad policy easier

AI presents real dangers.

We’ve already seen how artificial intelligence can make scams, impersonation, fraud, misinformation and cybercrime easier.

We should deal with those problems.

But we’re also hearing much more frightening predictions—that increasingly powerful AI could escape human control or even threaten humanity itself.

Some researchers and industry leaders take those possibilities very seriously. Others argue that the catastrophic predictions are being overstated. There is no consensus about the size of the risk or the best response.

That’s exactly when we need to resist panic.

Fear has a way of shortening the policy discussion.

When people believe disaster is imminent, they become much more willing to say, Just do something.

But “do something” is not a regulatory strategy.

Before creating new government authority, we should identify the specific danger we’re trying to address and determine whether the proposed rule would actually address it.

We aren’t developing AI in isolation

There is another problem that any serious discussion of regulation has to confront.

The United States isn’t the only country developing advanced AI.

China is aggressively developing the technology and already has its own system of AI regulation and safety requirements. Its rules and objectives are not identical to ours, nor can the United States dictate what another country will permit its companies to do.

That matters.

If an American regulation merely requires reasonable safety precautions, perhaps the competitive effect will be small.

But if we impose restrictions that substantially slow American AI development, we have to consider what happens when our international competitors don’t impose equivalent restrictions.

AI isn’t just another consumer technology. It has economic, cybersecurity and national-security implications.

Any regulatory system has to account for that reality.

Start with questions, not rules

I’m not arguing for a regulation-free AI industry.

There may be risks that clearly require government action.

But before creating a massive new regulatory structure around a rapidly changing technology, I want answers to some basic questions:

What specific problem are we trying to solve?

Can existing fraud, privacy, consumer-protection, antitrust or criminal laws address it?

What can AI companies do voluntarily?

Why do the companies themselves believe government intervention is necessary?

Who will write the technical standards?

How much influence will the largest AI companies have over those standards?

Will smaller companies be able to afford compliance?

Could today’s regulations make today’s dominant AI companies even more dominant tomorrow?

And what happens if American companies follow restrictions that foreign competitors do not?

Those questions aren’t arguments against regulation.

They’re part of deciding whether a regulation is wise.

The companies developing AI know things about the technology that policymakers and the rest of us don’t. We should listen when they warn us about potential dangers.

But expertise shouldn’t exempt anyone from scrutiny.

When some of the most powerful companies in the world come to government and say, “Please regulate us,” I don’t think our first response should be yes.

I think our first response should be:

Why?