Executive judgment

The central AI-policy choice is frequently presented as a contest between innovation and safety. That framing is analytically weak. Innovation is not valuable only to technology firms: it can increase worker capability, accelerate scientific discovery, improve public services, lower the cost of expertise and expand access to education, health and markets. Safety is not achieved by slowing a general-purpose technology indiscriminately: rules can entrench the largest firms, drive activity into less accountable settings and delay beneficial systems alongside harmful ones.

There are real risks. An automated eligibility system can unlawfully deny a person a benefit. A medical model can produce unsafe advice. Synthetic media can facilitate fraud or political manipulation. Model-assisted cyber operations can increase the scale of attack. Dominant infrastructure providers can shape downstream markets. Training and deployment may implicate privacy, intellectual property and confidentiality. These problems deserve law and institutional capacity, not reassurance.

The regulatory question is therefore one of fit. Which actor controls the relevant risk? At what stage can it most effectively be reduced? Does existing law already prohibit the harm? What additional information, testing or accountability is necessary? And will the proposed duty improve outcomes enough to justify its cost, delay and effect on entry?

Zwarte Peper’s position: governments should affirmatively support rapid AI development and adoption. Regulation should target demonstrated or reasonably foreseeable harms, rely on existing and sector-specific law where it works, allocate duties to actors able to control the risk, and prefer measurable outcomes over permissions to innovate. General-purpose development should not require a licence merely because future uses are uncertain.

This is not deregulation by slogan. It is a more legally disciplined model. High-impact deployers should document the intended decision, test performance in context, monitor incidents, preserve contestability and bear responsibility for negligent use. Frontier developers should support evaluation and disclose information necessary for downstream risk management, subject to security and legitimate commercial confidentiality. Regulators should have access to technical expertise, evidence and enforcement tools. But compliance should scale with risk, and obligations should expire or change when evidence does.

1. The public-interest case for speed

AI is best understood as a general-purpose technology that changes the cost of prediction, language, pattern recognition, software production and increasingly complex reasoning. Its value does not arise only at the research frontier. It arises when organisations redesign work, products and public services around new capabilities. Policy that concentrates on model development while neglecting diffusion can protect society from hypothetical innovation by ensuring that only the best-capitalised institutions can afford to use it.

Early productivity evidence is meaningful, not conclusive

In a study of 5,179 customer-support agents, access to a generative-AI assistant increased issues resolved per hour by 14 per cent on average and by 34 per cent for novice and lower-skilled workers. The evidence suggested that the tool helped diffuse the practices of more effective workers.1 Other studies have found gains in writing, coding and consulting tasks, although effects vary with task, user skill, workflow and measurement. Laboratory success does not guarantee economy-wide productivity; organisations must invest in complementary process, data, management and skills.

That qualification strengthens rather than weakens the case for experimentation. Policymakers cannot learn where AI produces durable value through abstract debate alone. They need many deployments, different institutional settings, transparent evaluation and rapid diffusion of what works. A regulatory system that makes pilots slow or legally perilous reduces the evidence on which better regulation depends.

The distributional implication is equally important. If AI disproportionately helps less-experienced workers in some tasks, it can broaden access to capability. If compute, data, liability and compliance costs reserve deployment for incumbents, the opposite may occur. Competition and diffusion are therefore safety issues as well as growth issues. A market with more users, evaluators and providers can expose failure and generate alternatives; a market organised around a few licensed firms creates concentrated operational and political risk.

Delay has a risk profile

Regulatory analysis often counts harms caused by a technology but treats foregone benefits as ethically neutral. They are not. Delayed diagnostic support, slower drug discovery, inaccessible education, administrative backlogs and productivity forgone in a low-growth economy all affect human welfare. The comparison should be between realistic states of the world, not between an imperfect AI system and an imaginary error-free status quo.

This does not mean that every deployment should proceed. It means a regulator should articulate both sides of the counterfactual. In a benefits system, for example, the relevant comparison is not automated error versus perfect human judgment. It is automated or assisted administration versus the actual human process, including delay, inconsistency, unrecorded discretion and existing bias. The right design may be AI assistance with audit and appeal, not autonomous denial and not a ban.

2. What current frameworks get right—and where caution is warranted

The European Union: comprehensive, risk-based and operationally demanding

The EU Artificial Intelligence Act establishes a horizontal framework built around prohibited practices, high-risk systems, transparency obligations and rules for general-purpose AI models. Certain prohibitions and general provisions have applied since February 2025; general-purpose-model duties since August 2025; and the Regulation is due to apply generally from 2 August 2026, subject to its transitional provisions.2 It also requires national regulatory sandboxes and contains measures intended to support innovation.

The Act’s strongest contribution is differentiation. It rejects the proposition that all AI is equally risky and imposes more extensive obligations where systems affect specified high-stakes domains. It creates an EU-wide legal vocabulary and makes organisational responsibility difficult to ignore. Its limitations arise from the same ambition. Classification, documentation, conformity assessment and interactions with data protection, product safety, consumer, employment and sectoral law can generate substantial fixed costs. Ambiguous boundaries may be resolved conservatively by smaller firms that cannot finance legal uncertainty.

The policy test is not whether compliance is burdensome; effective safety obligations often are. It is whether each burden is causally connected to risk and proportionate to the actor’s control. European implementation should prioritise simple guidance, harmonised standards, reusable compliance artefacts, fast classification support and evidence on market entry. If obligations increase concentration without improving incident outcomes, the framework should be revised rather than defended as a completed constitutional settlement.

India: innovation over restraint, with sectoral accountability

India’s AI Governance Guidelines, released in November 2025, expressly adopt a principle-based, evidence-led and proportionate approach. Their seven “sutras” include “Innovation over Restraint”, alongside trust, people-first development, fairness, accountability, understandable design, and safety, resilience and sustainability. The Guidelines favour a techno-legal framework, voluntary measures and existing or sector-specific law rather than a new horizontal AI statute at this stage.3

This is an attractive starting architecture for a rapidly developing economy. It avoids freezing technical assumptions into legislation, recognises that sectoral regulators understand context and preserves room for adoption. It also creates a serious implementation obligation. “Light touch” cannot mean that no institution owns cross-sector risks, incidents are invisible or affected persons lack remedy. India’s proposed AI Governance Group, Technology and Policy Expert Committee and AI Safety Institute will need clear mandates, technical independence and public measures of performance.

India also contributes an important corrective to global AI debate. Governance models developed around wealthy economies may overvalue risks salient to incumbent institutions and undervalue access, language, administrative capacity and development. Systems working in low-resource settings, across many Indian languages or through digital public infrastructure expose different error modes and opportunities. Global standards will be technically better when this evidence shapes them at inception rather than being added as an “inclusion” annex.

The NIST model: adaptable risk management

The US National Institute of Standards and Technology’s AI Risk Management Framework is voluntary and organised around four functions: govern, map, measure and manage. Its Generative AI Profile identifies risks and suggested actions that organisations can tailor to context.4 This architecture is useful because it treats risk management as a continuous operating process rather than a one-time approval. Its voluntary character facilitates experimentation and cross-sector use, but high-impact contexts still require enforceable legal duties and remedies through sectoral or general law.

3. The regulatory error to avoid: treating capability as culpability

A general-purpose model may support translation, coding, research, fraud, tutoring or cyber defence. Regulating the model solely by reference to broad capability can be attractive because developers are visible and fewer in number than users. But upstream control is poorly fitted to many downstream harms. A model developer may not know the deployment data, interface, human reliance, sectoral context or decision consequence. The deployer often controls those facts.

This does not eliminate upstream duties. A developer controls training, security, evaluation, model access and information disclosed to customers. For sufficiently capable systems, it may be the only actor able to conduct certain evaluations. Duties should therefore follow control:

ActorPrincipal controlProportionate duty
Model developerTraining process, core evaluation, security, release design and technical documentation.Evaluate material capabilities and vulnerabilities; secure model assets; communicate limitations and incident-relevant information.
Application providerFine-tuning, retrieval, interface, tools, defaults and user instructions.Test the integrated system for its intended function; prevent foreseeable misuse; maintain logs and update paths.
DeployerUse case, affected population, data, workflow, reliance and human authority.Establish lawful purpose; validate in context; train users; monitor outcomes; provide contestability where decisions materially affect people.
Professional userJudgment about whether and how to rely on output.Meet existing professional standards; verify consequential output; preserve confidentiality and disclose AI use where material.
Infrastructure providerCompute, hosting, access security and service resilience.Apply proportionate cybersecurity and lawful-process controls without becoming a general monitor of user purpose.

Licensing general-purpose development should face a high threshold. A licensing system creates delay, administrative discretion and a barrier to entry. It risks converting today’s technical leaders into legally protected incumbents. The state would need reliable criteria for safe capability, competence to update those criteria, capacity to decide quickly and evidence that less restrictive instruments cannot manage the risk. That case has not been established for ordinary general-purpose development.

Compute thresholds and model size can be useful triggers for information or focused evaluation when they correlate with a specific concern. They are poor substitutes for risk by themselves. Efficiency changes can produce greater capability with less compute; small specialised models can be dangerous in context; and large models can be deployed for benign uses. The trigger should be reviewed frequently and linked to an articulated purpose, not treated as a permanent scientific boundary.

4. A six-layer pro-innovation governance framework

Layer 1: enforce technology-neutral law

Fraud remains fraud when synthetic content is used. Discrimination, negligent professional service, unsafe products, anticompetitive conduct, unlawful surveillance, breach of confidence and data-protection violations do not become lawful because AI is involved. Governments should first identify enforcement gaps under existing law. New AI-specific rules are justified where the technology changes scale, attribution, evidence or the distribution of control in a way current doctrine cannot handle.

This approach reduces duplication and preserves doctrinal coherence. It also avoids a perverse defence: a firm should not escape ordinary responsibility by categorising conduct as an AI issue subject only to softer principles. Regulators need technical capacity, joint protocols and access to evidence so existing powers are usable in practice.

Layer 2: impose sector-specific duties for consequential use

Risk depends on context. An AI-generated restaurant suggestion and an AI-supported cancer-treatment recommendation should not share a compliance path. Health, finance, employment, critical infrastructure, policing, education and public benefits have different evidentiary standards, affected rights and professional institutions. Sectoral rules should define the acceptable role of automation, validation requirements and allocation of human responsibility.

For material decisions about individuals, minimum safeguards should ordinarily include notice that AI materially informed the process, records sufficient to reconstruct the decision, testing relevant to the affected population, a responsible decision owner and an effective route to human reconsideration. “Human in the loop” is not enough if the person lacks time, expertise or authority to disagree.

Layer 3: use safe harbours to make good practice investable

Uncertain liability can deter both reckless and responsible actors. A safe harbour can reward specified conduct—credible pre-deployment testing, documented risk assessment, incident response, participation in a recognised sandbox or conformance with an open standard—without immunising fraud, gross negligence or rights violations. Safe harbours should be rebuttable and outcome-aware. A checklist completed in bad faith should not defeat evidence of avoidable harm.

Layer 4: require incident learning, not public theatre

High-impact deployers and developers should report defined serious incidents to an appropriate authority under protected conditions. The purpose is to identify recurring failure, coordinate response and improve standards. Public summaries should disclose patterns and corrective actions while protecting personal data, security and genuinely sensitive commercial information. Overbroad reporting produces noise and defensive bureaucracy; narrow definitions, thresholds and feedback loops produce learning.

Layer 5: protect competition and open research

AI governance must consider market structure. Control of compute, cloud, chips, data, distribution and talent can create durable bottlenecks. Competition authorities should scrutinise exclusionary conduct, discriminatory access, anticompetitive tying and acquisitions that remove emerging constraints. Procurement should avoid unnecessary vendor lock-in and require portability where feasible.

Open-source and open-weight models complicate risk control but also support research, local adaptation, language access, verification and competition. Liability should reflect actual control after release. Imposing continuing responsibility on a developer for every third-party modification would deter openness while failing to reach the actor making the harmful deployment. Restrictions should be tied to specific, severe and evidenced risks, with research and security-testing protections.

Layer 6: build regulation that can learn

Every major AI rule should state its objective, theory of harm, compliance cost, success metric and review date. Sandboxes should answer a defined regulatory question, not operate as promotional programmes. Regulators should publish decisions and anonymised incident learning, coordinate internationally and revise guidance on a faster cycle than primary legislation. The OECD’s updated AI principles recommend agile, outcome-based and interoperable policy environments that support experimentation and competition.5

5. Government should be an intelligent lead adopter

The public sector cannot regulate AI competently while remaining operationally unfamiliar with it. Government should deploy AI in research, drafting support, translation, fraud detection, case triage, citizen service, procurement analysis and administrative workflow—first where errors are detectable and reversible, then in more consequential settings as evaluation capacity matures.

Public adoption serves three purposes. It improves services and productivity. It creates informed buyers capable of challenging vendors. And it generates evidence about governance in real institutions. But state deployment also carries distinct risks because government can determine rights, impose coercion and operate at population scale.

A public-sector AI deployment should have a compact decision file:

  1. the statutory authority and public objective;
  2. the baseline process, including current error, cost and delay;
  3. the role assigned to AI and the decisions reserved to officials;
  4. validation data, performance thresholds and subgroup analysis relevant to the context;
  5. data-protection, cybersecurity, records and procurement controls;
  6. the responsible senior owner and escalation route;
  7. notice, explanation and reconsideration for affected persons where appropriate; and
  8. a scale, pause and retirement rule based on measured outcomes.

Procurement should buy outcomes and evaluation access, not a promise of “responsible AI”. Contracts should secure necessary documentation, audit cooperation, incident notification, service continuity, portability and exit. Intellectual-property terms should permit the public authority to understand and operate the system without demanding vendor assets unrelated to accountability. Small firms should be able to compete through modular pilots and common assurance artefacts rather than bespoke compliance for every authority.

AI-native government is not government by chatbot. It is an administration able to turn law into testable process, use machines for scale and preserve human accountability for public power. Automation should remove clerical discretion and delay while making substantive judgment more legible, not create an automated shield behind which no official owns the result.

6. Global governance must not become regulatory protectionism

Rules developed in large wealthy markets can become global through market access, procurement and technical standards. This can raise protection where domestic institutions are weak. It can also export compliance costs and policy preferences that other societies did not meaningfully shape. A nominally universal safety framework may privilege large firms able to maintain documentation teams and countries able to finance compute, testing and certification.

The alternative is not fragmented law or a race to the bottom. It is interoperable governance organised around common outcomes with multiple compliant methods. International cooperation should support shared incident taxonomy, evaluation science, secure research, standards mapping and mutual recognition where protections are equivalent. Lower-capacity regulators and researchers should participate in setting priorities, not merely receive implementation assistance after standards are settled.

India’s emphasis on innovation, digital public infrastructure, linguistic diversity and sectoral governance is especially valuable. African experience with mobile services and low-resource deployment, Southeast Asian platform economies, Latin American digital-government systems and expertise distributed across other regions should shape global evaluation. Safety depends on knowing how systems fail across languages, institutions and material conditions. Western experience is important evidence; it is not the whole dataset.

Trade policy also matters. Restrictions on chips, cloud, models, data or digital services may be justified by narrow security concerns, but broad controls can freeze global capability gaps and slow beneficial adoption. States should identify the precise threat, assess circumvention and downstream development costs, and choose the least restrictive effective measure. “AI sovereignty” should not become a general permission for protectionism that raises domestic costs and excludes foreign knowledge.

7. A decision scorecard for AI regulation

QuestionEvidence of sound regulationWarning sign
What harm is being addressed?Defined affected interest, causal pathway, likelihood and severity.“AI risk” used as an undifferentiated category.
Who controls the risk?Duty allocated to the developer, provider, deployer or user able to reduce it.Obligation imposed on the most visible actor rather than the responsible one.
Does existing law work?Documented enforcement gap before creating a new horizontal duty.Duplicate regimes with inconsistent definitions and regulators.
Is the intervention proportionate?Outcome standard, safe harbour or targeted duty before licensing or prohibition.Permission to develop required because future use is uncertain.
Can new entrants comply?Clear guidance, common standards, reusable evidence and low fixed cost for low-risk use.Bespoke legal process affordable only to incumbents.
Will the rule improve safety?Incident, error, remedy and market-structure metrics with a baseline.Success measured by forms filed or entities registered.
Can the rule learn?Regulatory data access, sandbox question, review date and revision mechanism.Technical threshold embedded indefinitely in primary law.
Is the framework globally legitimate?Meaningful participation, interoperability and accommodation of different capacities.One market’s compliance model exported as universal technical truth.

8. A practical policy programme

In the first six months

Create a cross-government inventory of AI-relevant law, regulators and enforcement gaps. Select high-value public-sector pilots with measurable baselines. Establish a protected serious-incident channel. Publish procurement clauses and a common lightweight impact record. Fund evaluation capability, red-teaming, local-language benchmarks and regulatory technical teams. Avoid a new omnibus statute until this evidence reveals problems that existing and sectoral law cannot solve.

Within twelve months

Issue sector-specific guidance for the most consequential uses. Define notice and reconsideration rights for material public decisions. Launch regulatory experiments with explicit questions and time limits. Create safe harbours for recognised testing and incident practices. Map domestic requirements to NIST, OECD, EU and other relevant frameworks so firms can reuse evidence. Publish aggregate incident and adoption data.

Within twenty-four months

Evaluate whether harm, entry, adoption and public-service metrics support enforceable additional duties. Legislate narrowly where evidence shows a persistent gap. Build international mutual-learning arrangements and invest in technical public goods—benchmarks, provenance tools, privacy-enhancing technology, security evaluation and open datasets. Review rules annually for obsolescence and competitive effect.

This programme is intentionally sequenced. Capacity and evidence precede broad prescription. That does not delay protection: ordinary law, sectoral powers, procurement controls and targeted interim guidance apply immediately. It avoids the more consequential delay created when legislation establishes categories that regulators and firms spend years interpreting while technology and risk move elsewhere.

Conclusion: acceleration with responsibility

AI policy should start from confidence in society’s capacity to learn and adapt. Rapid development will produce mistakes as well as breakthroughs. The relevant institutional goal is not zero failure, which no complex human or technical system can deliver. It is faster discovery of error, clear responsibility, effective remedy and continuous improvement—while preserving the freedom to build and adopt systems whose benefits cannot be fully predicted in advance.

A rules-based order is compatible with technological acceleration when rules discipline harm and power rather than requiring permission for change. The state should be strong where rights, safety, security and competition are genuinely at stake; restrained where risks are speculative or already addressed; and ambitious in using AI to improve its own performance.

The jurisdictions that govern AI best will not be those with the longest statute or the least regulation. They will be those that expand access to capability, keep markets contestable, make high-impact deployment accountable and revise policy in response to evidence. That is not a compromise between innovation and safety. It is the institutional design through which both become possible.

Authorities and selected research

  1. Erik Brynjolfsson, Danielle Li and Lindsey R. Raymond, “Generative AI at Work”, NBER Working Paper 31161.
  2. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, especially Articles 57 and 113 and the transitional provisions.
  3. Government of India, India AI Governance Guidelines, November 2025; Rajya Sabha response on the Guidelines, 19 December 2025.
  4. US National Institute of Standards and Technology, AI Risk Management Framework; NIST AI 600-1, Generative Artificial Intelligence Profile.
  5. OECD AI Principles, adopted 2019 and updated 2024.
  6. OECD Recommendation of the Council on Artificial Intelligence.
  7. OECD, “Regulation and innovation”.
  8. International Monetary Fund, “How Europe Can Capture the AI Growth Dividend”, 20 November 2025.
  9. Office of the Principal Scientific Adviser to the Government of India, Artificial Intelligence mission and governance materials.
  10. Office of the Principal Scientific Adviser, “Strengthening AI Governance Through Techno-Legal Framework”, 23 January 2026.
  11. OECD, Smart Regulations, Strong Business, 2026, section on adaptive regulation.
  12. OECD, The OECD.AI Index, 2026.

Editorial note. This article is general policy research and does not constitute legal advice. Regulatory status and sources were last checked on 27 July 2026.