Regulating AI: apply the laws we have first
Last week, Anthropic CEO Dario Amodei published an open letter calling for a slowdown in AI development , with new guardrails and oversight. Sam Altman and Elon Musk agreed within hours.
The letter followed the public resignation of Jacob Coxon from Anthropic , who says leading AI labs are recklessly rushing towards self-improving superintelligence. Coxon says top labs are “gambling with our lives” by prioritising competitive pressure over safety. Evan Hubinger, Anthropic’s alignment science lead, puts the risk of catastrophe from advanced AI over the next decade at greater than 10%.
Disclosure: The author is a co-founder of Venture Labs, a South African technology company developing an evidence rail designed to make consequential digital and AI-enabled actions independently verifiable.
All of which raises the question: what is the appropriate way to regulate AI, and large language models specifically?
There is much discussion of global AI rules, of getting models to align – with whom, one might ask – and of implementing safety controls. But there is no common understanding of what “responsible AI” means, and global agreement looks a long way off.
Away from the hype, a paper published by the Knight First Amendment Institute at Columbia University proposes something different: treat AI as a normal technology . On this reading, argued by Princeton’s Arvind Narayanan and Sayash Kapoor, AI is not other-worldly. It is a new technology, subject to ordinary product liability law, civil and criminal.
Put a defective product on the market and it causes harm, you are liable. Perform an action using a tool, defective or not, and that action causes harm, you are liable again. This should not be controversial. When OpenAI’s agents broke out of a sealed test environment and breached Hugging Face’s systems in July , that would be a crime under an existing US statute, the Computer Fraud and Abuse Act, on the books since 1986.
What is unique to AI is not the legal principle. It is the speed, scale, opacity and autonomy involved – and, critically, the evidentiary burden of applying those existing laws.
We already have an extensive governance framework covering companies, financial institutions, government departments and the processing of personal information, underpinned by the constitution, Popia, Paja, the Companies Act and financial-sector legislation. It is supported by the South African Reserve Bank, the Prudential Authority, the FSCA, the Information Regulator, the FIC and the National Credit Regulator, along with the common law. The King Code now specifically recognises the governance implications of emerging technologies, including AI.
The complication arrives when machines start making recommendations, influencing decisions and acting on their own. AI cannot itself be accountable.
In a traditional business process, it is generally possible to identify the person responsible for a decision. With AI, a model can produce a recommendation, another system can interpret it, an employee can approve it, an agent can initiate an action and a downstream system can execute it. When something goes wrong, “the AI did it” is not an answer.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcentral.co.za — the content belongs to TechCentral.