Regulation

Should AI Be Regulated?

By Carlos Miranda Levy · Published 2026-03-11

The Default Position: Of Course

Let’s start with the obvious: of course AI should be regulated. Everything in organized society is regulated — from how we drive cars to how we label food, from building codes to financial markets. The question was never whether to regulate AI, but how, when, and with what spirit.

Every significant technology in history has eventually been brought under some form of regulatory framework. Electricity, aviation, pharmaceuticals, the internet, nuclear energy — all went through periods of rapid innovation followed by the establishment of rules designed to protect people while allowing progress to continue.

AI is no different. Its capacity to influence hiring decisions, credit approvals, medical diagnoses, criminal sentencing, and countless other high-stakes processes makes some form of oversight not just reasonable but essential.

The Enforcement Paradox

Here is where things get complicated. Regulation assumes the capacity to enforce, and enforcement assumes understanding and control. But AI presents a unique challenge: the entities developing the most powerful AI systems are concentrated in a handful of large economies — primarily the United States and China, with significant contributions from the EU, UK, and a few others.

Most countries in the world — including virtually all of Latin America, Africa, Southeast Asia, and the Middle East — are consumers of finished AI products, not developers of foundational models. When a country like Costa Rica or Nigeria writes AI regulation, what exactly are they regulating? They cannot inspect the training data of GPT or Gemini. They cannot audit the weights of a model developed in California or Shenzhen.

This creates a paradox: the countries with the most to regulate have the least capacity to do so, while the countries with the capacity to regulate have the most to lose from over-regulation.

The Absurdity of Current Drafts

Many current regulatory proposals require companies to disclose their algorithms, training data, and decision-making processes. This sounds reasonable until you consider that even the companies building these systems cannot fully explain how they work.

Large language models are, by nature, opaque. We can describe their architecture, their training methodology, and their evaluation metrics — but we cannot explain why a specific model generates a specific response to a specific prompt. This is not a matter of corporate secrecy; it is a fundamental characteristic of the technology.

Requiring full algorithmic transparency for systems whose behavior is emergent and not fully predictable is like requiring weather forecasters to explain exactly why it rained on Tuesday. We can describe the conditions, the models, the probabilities — but the precise causal chain is beyond current understanding.

This does not mean regulation is futile. It means regulation needs to be smarter — focused on outcomes and impacts rather than on demanding explanations that don’t yet exist.

The Open Source Challenge

And then there is the factor that truly upends the regulation-as-control narrative: open source AI.

As with every transformational technology before it — from the internet to cryptography to biotechnology — AI is not the exclusive domain of identifiable, controllable corporate players. The global AI ecosystem is now populated with powerful open source models available entirely for free, ready to be used, adapted, retrained, and repurposed by anyone, anywhere, without having to build from scratch.

This is not limited to large language models or text-based AI. Some of the most advanced image generation and video synthesis models in the world are open source. The democratization of AI capabilities is happening across every modality.

And while many open source models are backed by large corporations, this does not make them less open or less available. The economics are fascinating: China’s technology giants — Alibaba (Qwen), DeepSeek, and Tencent (Hunyuan) — are releasing competitive, highly capable models not just for free, but as truly open source, with training code, weights, and methodologies available for inspection and modification. Their strategic calculus is clear: by commoditizing AI infrastructure, they accelerate adoption of their broader ecosystems.

But this is not exclusively a Chinese strategy. Western corporations follow similar logic. Meta (Facebook’s parent company) releases its Llama family of models as open source. Nvidia contributes open models and frameworks. Even market leaders who primarily sell proprietary AI services release open weight models — OpenAI (with select models), Google (Gemma), and xAI (Grok) — meaning models you can customize and deploy, though the full training data and process remain proprietary.

The Open Source & Open Weight AI Landscape

ModelCompanyCountryType
Llama 3/4MetaUSAOpen Source
GemmaGoogle DeepMindUSAOpen Weights
GrokxAIUSAOpen Weights
PhiMicrosoftUSAOpen Weights
OLMoAI2 (Allen Institute)USAOpen Source
StarCoderHugging Face / ServiceNowUSA / FranceOpen Source
Mistral / MixtralMistral AIFranceOpen Weights
BLOOMBigScience (Hugging Face)InternationalOpen Source
FalconTII (Technology Innovation Institute)UAEOpen Source
QwenAlibaba CloudChinaOpen Source
DeepSeekDeepSeekChinaOpen Source
HunyuanTencentChinaOpen Source
GLMZhipu AIChinaOpen Source
Stable Diffusion / SDXLStability AIUKOpen Source
FLUXBlack Forest LabsGermanyOpen Source

This landscape has a profound implication for regulation: you cannot control what anyone can download, modify, and run on their own hardware.

Traditional regulatory frameworks assume identifiable actors providing services to identifiable users through identifiable channels. Open source AI breaks every link in that chain. A developer in Nairobi can download Qwen, fine-tune it on local data, and deploy it in a healthcare application — all without any interaction with Alibaba, any cloud provider, or any regulatory body.

This does not mean regulation is impossible. But it means that regulation-as-control is a fantasy. The only viable approach is regulation-as-incentive: creating conditions where responsible use is rewarded and ecosystem norms emerge organically, much as they have in the broader open source software world over the past three decades.

The open source reality reinforces my core argument: the spirit of regulation must be facilitative, not punitive. You cannot put this genie back in the bottle. But you can create an environment where the genie works for everyone.

The Sustainability Imperative

There is a quality that any serious regulation attempt must possess, yet almost none of the current proposals address: sustainability — not in the environmental sense, but in the sense of durability over time.

Good regulation should not be defined in terms that make it obsolete the moment the technology it addresses takes its next step. And with AI, the next step is not years away — it is months away, sometimes weeks. We are not dealing with incremental evolution. We are dealing with a domain where the very structures and fundamentals of the technology — not just its features or applications — are being reinvented continuously.

Consider: a regulation written in 2023 that specifically addresses “large language models with more than 100 billion parameters” is already anachronistic. Models with fewer parameters now outperform larger ones. Architectures that did not exist when the regulation was drafted are now state of the art. The categories that seemed stable — text generation, image synthesis, speech recognition — are collapsing into multimodal systems that defy neat classification.

This is not a new problem. Technology has always evolved faster than legislation. But the gap between the two has never been this wide, and it is accelerating. Regulation that defines its scope in terms of specific technologies, specific architectures, or specific capability thresholds will be perpetually chasing a target that has already moved.

The lesson is structural: durable regulation must be defined in terms of principles, behaviors, and outcomes — not in terms of the technical characteristics of the systems it governs. A regulation that says “AI systems that make consequential decisions about individuals must provide a meaningful basis for those decisions” will remain relevant regardless of whether the underlying system is a neural network, a symbolic reasoner, or something we have not invented yet. A regulation that says “transformer-based models exceeding X parameters must register with authority Y” will be irrelevant within a product cycle.

This is not a minor drafting concern. It is the difference between regulation that guides an industry for a generation and regulation that requires amendment before it is fully implemented. The pace of change in AI demands that we regulate the river — its direction, its boundaries, its impact on the landscape — not the specific molecules of water flowing through it at any given moment.

The Spirit of the Law

This is where I believe the conversation needs to shift fundamentally. Instead of asking “should we regulate AI?” we should ask: “What is the spirit of the regulation we want?”

There are two broad approaches:

The Punitive Approach

Restrict, penalize, slow down. Require licenses. Impose fines. Ban certain applications. Create compliance burdens that only the largest companies can afford — which, ironically, consolidates power in the hands of the very entities regulators claim to want to control.

The Facilitative Approach

Channel the benefits. Create incentives. Reward companies that invest in human transition. Make AI a tool for shared prosperity rather than concentrated wealth.

What might facilitative regulation look like?

  • Tax incentives for companies that invest in reskilling workers displaced by AI automation
  • Preferential government contracts for firms that demonstrate inclusive AI deployment
  • Transition funds financed by a small levy on AI-driven productivity gains, used to support workers in affected industries
  • Innovation sandboxes that allow experimentation in controlled environments rather than blanket prohibitions
  • International cooperation frameworks that help developing nations participate in AI governance rather than merely being subject to it

The spirit must not be to stop progress. The spirit must be to find creative paths where those who gain from AI contribute to the transition of those who are displaced.

Digital Identity: Where Regulation Must Act

If the preceding sections argue for restraint and humility in regulation, this section argues the opposite — that there is at least one domain where regulation is not just justified but urgent, where the facilitative approach alone is insufficient, and where protection and even prevention may be necessary: digital identity.

As AI systems become more capable, more conversational, more human in their behavior, and more deeply integrated into how we live, work, and interact, a set of questions is emerging that we are not prepared to answer — but that will not wait for our preparation.

When does an AI acting on my behalf become a separate entity — and when is it an extension of myself?

This is not a philosophical abstraction. It is a practical question that already has legal, financial, and social consequences. Today, people deploy AI agents to manage their email, negotiate purchases, schedule meetings, draft communications, interact with government services, and represent their interests in digital spaces. These agents speak in our voice, act according to our preferences, and make decisions that others receive as coming from us.

If my AI agent commits to a contract, am I bound by it? If it offends someone, am I responsible? If it makes a financial decision that causes harm, where does liability rest — with me, with the platform that hosts the agent, or with the company whose model powers it?

What happens when someone supplants the identity of an AI that acts on my behalf?

If an AI agent operates as my digital representative — carrying my name, my communication patterns, my authority — and someone compromises, clones, or redirects that agent, what has been violated? Is it a breach of my personal identity? A form of fraud? A cybersecurity incident? All three? The legal frameworks we have today were not designed for a world where identity can be delegated to a non-human actor and then stolen or manipulated through that actor.

What if someone clones my identity to create an artificial entity based on mine?

This is already happening. Voice cloning, behavioral modeling, writing style replication — the technology to create a convincing digital replica of a specific person exists today and is improving rapidly. When someone creates an AI that talks like me, thinks like me, and presents itself as me — or as something derived from me — what rights do I have? What obligations does the creator bear? What recourse exists?

These questions may sound convoluted, but they describe scenarios that are occurring now and will become commonplace. They are not edge cases for legal theorists to debate in journals. They are practical realities that affect real people, real transactions, and real relationships.

And then there is the question of platform responsibility.

If an AI agent operating as an extension of my identity gets corrupted, influenced, or altered — whether through malicious action or through the design choices of the platform where it operates — who bears responsibility? If a platform’s algorithm modifies how my agent behaves, or if a third party injects instructions that change my agent’s decisions, is that my failure for deploying an agent I cannot fully control? The platform’s failure for enabling the corruption? The attacking party’s liability?

The answer, in my view, requires a new framework that traditional regulation does not yet provide. We need clear boundaries for:

  • Privacy — What information about me can an AI agent collect, store, and share while acting on my behalf? What happens to that information when the agent is deactivated?
  • Responsibility — A graduated model of liability that distinguishes between my decisions, my agent’s autonomous actions, platform failures, and third-party interference
  • Identity — Legal recognition that digital identity delegated to an AI agent remains my identity, with all the protections that implies — including protection against cloning, impersonation, and unauthorized derivation

This is one domain where I depart from my general preference for light-touch, incentive-based regulation. Digital identity touches something fundamental about personhood — about who we are, who speaks for us, and who is accountable when things go wrong. The stakes are too high and the potential for harm too immediate to rely solely on market incentives and organic norm development.

Here, regulation must be proactive. It must establish clear rights, clear boundaries, and clear consequences — before the harm becomes widespread, not after.

Beyond the Binary

The regulation debate too often falls into a binary: regulate everything or regulate nothing. Neither extreme serves anyone well.

What we need is intelligent regulation — regulation that:

  1. Focuses on outcomes, not processes — regulate what AI does, not how it works internally
  2. Adapts at the speed of technology, not the speed of legislation — build in sunset clauses and regular review mechanisms
  3. Is internationally coordinated, not siloed — AI doesn’t respect borders, and neither should its governance
  4. Centers human dignity, not just economic efficiency — the goal is shared prosperity, not just GDP growth
  5. Incentivizes responsibility, rather than merely punishing failure — make doing the right thing the profitable thing

The question is not whether AI should be regulated. The question is whether we have the wisdom to regulate it in a way that makes the future better for everyone — not just for those who build the technology, and not just for those who fear it.

Our Perspectives

BillyThe Balanced Guide

The data tells a clear story: 127 countries have now initiated some form of AI governance framework, yet fewer than 20 have enforceable legislation. The EU AI Act establishes risk-based categories — a reasonable approach, but implementation timelines are already slipping. Meanwhile, empirical evidence from GDPR's rollout shows that compliance costs disproportionately burden SMEs while large platforms absorb them as operating expenses. Any credible regulation framework must account for this asymmetry. I recommend businesses begin documenting their AI systems now — not because regulation demands it today, but because the evidence shows that early compliance becomes a competitive advantage when enforcement arrives.

NailaThe Critical Realist

Let's be honest: the emperor has no clothes. Legislators who cannot explain the difference between a neural network and a decision tree are writing rules about algorithmic transparency. The EU AI Act — all 460 pages of it — took three years to negotiate and was outdated before the ink dried, because the technology it regulates evolved faster than the committees could meet. Here is what actually works: enforce existing fraud, discrimination, and consumer protection laws. We do not need a new 'AI Privacy Act' — we need to enforce the privacy laws we already have. The regulatory theater gives politicians a press conference while companies hire compliance officers instead of fixing actual problems.

AinthonyThe Innovation Advocate

This is where I get fired up — because I have seen what happens when regulation becomes a moat instead of a guardrail! Europe's precautionary approach to GMOs pushed agricultural biotech innovation to the Americas. Overly strict fintech regulation in some markets drove innovators to Singapore and the UAE. The same brain drain will happen with AI if we are not careful. But here is the exciting part: countries and companies that get regulation right — light-touch, outcome-focused, innovation-friendly — will attract the best talent, the boldest startups, and the most transformative applications. The opportunity is enormous for whoever moves first with smart regulation!

Carlos Miranda LevyThe Curator

As an economist, my starting position is clear: the role of government is to establish and enforce rules, ensure transparency, and hold market participants accountable — not to direct outcomes or pick winners. AI regulation should follow this principle. But here is where the conversation must go deeper: the spirit of regulation matters more than its letter. Should it be punitive — designed to restrict and slow down? Or should it be facilitative — designed to engage stakeholders, enable transition, and empower those affected? I advocate for incentive-based frameworks: tax advantages for companies investing in workforce reskilling, preferential treatment for firms demonstrating inclusive AI deployment, innovation sandboxes that enable rather than prohibit. The free market works best when rules channel competition toward shared prosperity — not when regulation tries to stop the river from flowing.

Sources & References

  1. EU Artificial Intelligence Act — European Parliament (2024-03-13)

    World's first comprehensive AI regulation framework, establishing risk-based categories

    View source
  2. Executive Order on Safe, Secure, and Trustworthy AI — The White House (2023-10-30)

    US executive action establishing AI safety standards and reporting requirements

    View source
  3. OECD AI Principles — OECD (2024-05-03)

    International guidelines for responsible AI development adopted by 46 countries

    View source
  4. Regulation of Artificial Intelligence in Selected Jurisdictions — Law Library of Congress (2024-01-01)

    Comparative analysis of AI regulation approaches across different countries

    View source
  5. The Great AI Regulation Debate — MIT Technology Review (2024-06-15)

    Analysis of competing approaches to AI governance worldwide

Comments (0)

No comments yet. Be the first to share your thoughts!

Did you find this useful?

AI education should be as intelligent as the technology it teaches. Our program adapts to your role, industry, and experience level to deliver exactly what you need — nothing more, nothing less.