Regulate the Use, Not the Idea: An AI White Paper, Round Two
In my first AI White Paper, Theoretical AI Exists, Applied AI Is Now in Play: A TASCFORM Test Case and the Argument for Transparent Models, I concluded with this statement:
“My research point is very simple: Theoretical AI exists, and Applied AI — for good, for ill, or simply unhelpful — is now in play. Trying to legislate into such an evolving new world of research is a very, very bad idea.”
I made that statement, and this is round two, defending it. My core argument is that Theoretical AI is an evolving research domain. Its uses, and even its limitations, are uncertain. Trying to legislate such an open-ended research space will freeze technologies, methods, and ideas before their consequences are understood. With Applied AI, look for concrete outcomes rather than prejudging its potential use.
Arrayed against my argument are three significant forces: an unbridled fear of AI being stoked to destroy humanity; a number of state and centrally-controlled political figures, both in the U.S. and globally, tapping into that fear to gain political advantage; and, perhaps the third, and so far the most perniciously effective, in my opinion (cue my First Amendment touchstone rights), the incredibly wealthy AI moguls who stand to gain from both fear-mongering and controlling the marketplace.
At the Naval Academy, we often called this the “I am aboard, pull up the ladder!!” command.
So I asked AI, in all fairness, to list the most important thinkers, researchers, and policymakers who are essentially all in on significant AI regulation, right now.
Major figures
- Dario Amodei — CEO, Anthropic
- Has advocated substantial government oversight of frontier AI.
- His proposals include an AI regulatory agency with authority to evaluate frontier models and potentially prevent deployment when they present unacceptable risks.
- A 2026 comparison of the major frontier-AI CEOs describes Amodei’s proposal as analogous to an “FAA for AI.”
- Sam Altman — CEO, OpenAI
- Has repeatedly supported government regulation of advanced AI, including licensing and certification mechanisms and international coordination.
- His preferred model has included an international institution with some similarities to the IAEA, particularly for very powerful frontier systems.
- Importantly, Altman generally argues for regulation focused on the most capable systems rather than regulating every AI application identically.
- Demis Hassabis — CEO, Google DeepMind
- Supports government involvement in regulating frontier AI and independent testing.
- His proposed approach has been compared to a FINRA-like system: standards, testing, and oversight initially involving industry but operating under government supervision, with the possibility of mandatory requirements.
- Geoffrey Hinton — AI researcher and Nobel/Turing-recognized figure
- Has been one of the most prominent public advocates for governments taking AI risks seriously.
- Has called for stronger government intervention and international coordination concerning highly capable AI, particularly because he believes companies have incentives that may not align completely with public safety.
- Yoshua Bengio — AI researcher
- Has advocated substantially stronger public governance of advanced AI, including independent safety evaluation and institutions capable of overseeing powerful systems.
- Has been particularly prominent in advocating international mechanisms for managing frontier AI risks.
- Ian Hogarth — British technology investor and former chair of the UK AI Safety Institute
- Has been an important advocate of state-backed evaluation of frontier AI.
- The UK’s model is explicitly built around government developing its own technical ability to test advanced AI, rather than relying exclusively on companies’ own safety claims.
- Stuart Russell — AI researcher, UC Berkeley
- Advocates stronger governmental and international governance of increasingly capable AI.
- His position is particularly focused on ensuring that AI systems remain aligned with human objectives, and that deployment of highly capable systems isn’t left solely to private companies.
Politicians and government policymakers
There is also a large political and government camp favoring legally enforceable AI regulation.
- Chuck Schumer (U.S. Senator)
- Organized the Senate’s AI policy effort and has advocated federal legislation establishing rules and safeguards for AI.
- Richard Blumenthal (U.S. Senator)
- Has supported legislation establishing federal requirements for advanced AI, and has been involved in proposals for licensing highly capable frontier AI developers.
- Congressional testimony has specifically discussed licensing regimes for highly capable frontier models, rather than relying on voluntary industry standards (Congress.gov).
- Josh Hawley (U.S. Senator)
- Has supported federal restrictions and accountability requirements for AI companies, including proposals involving frontier-model licensing.
- Elizabeth Warren (U.S. Senator)
- Has advocated federal oversight of AI companies, particularly concerning consumer protection, competition, employment, privacy, and corporate accountability.
- Ursula von der Leyen — President of the European Commission
- Under the European Commission, the EU AI Act established a comprehensive, legally binding regulatory framework.
- The framework includes prohibited uses, requirements for high-risk systems, obligations for general-purpose AI, and government supervision and enforcement powers.
- Margrethe Vestager — former European Commission Executive Vice-President
- Was a prominent political figure behind Europe’s technology-regulation agenda, including the development and implementation of the EU’s AI regulatory framework.
That said, I did earn money as a Cornell graduate teaching assistant (graduated in 1977), helping students understand computers and decision-making, so I have some lifelong experience in this field. I also understand the power of legislation, having served as professional staff on the House Committee on Rules, known as “the Speaker’s Committee.” And yes, I also bombed the Khmer Rouge, so I know “death from above.”
Consequently, in just one emerging field of AI-assisted research, which I highlighted in my first white paper, the focus is on mathematical techniques: a model architecture or algorithm does not inherently determine how it will ultimately be used. The same underlying AI capability can have benign, beneficial, or harmful applications. Therefore, regulation can be more precisely targeted once the technology is actually incorporated into a consequential application. that is, Applied AI.
My strongest argument is:
Separate all theoretical research from regulation. Do not regulate Applied AI simply because it might someday be dangerous; regulate identifiable conduct and consequences when AI is actually being used. Applied AI can be evaluated by its creators according to the actual context in which it is proposed and deployed:
- What decision is it making?
- Who is affected?
- How consequential is the decision?
- What data does it use?
- Can a human review or override it?
- What happens when it is wrong?
- What legal protections already apply?
This avoids imposing identical requirements on fundamentally different applications.
Rather than demanding that every underlying AI technology be legislatively controlled, an applied system could be required to provide sufficient transparency for external oversight: what the system is being used for, what data or inputs matter, what its limitations are, who is accountable, and how decisions can be challenged. See my TASCFORM paper, linked above.
The key point in stopping top-down regulatory dictates is simple: existing law can regulate the application without creating an entirely new AI regime.
For example, if an AI system commits fraud, violates privacy, discriminates unlawfully, causes a defective product, or makes an impermissible employment decision, the relevant legal regime can address the conduct regardless of whether AI was involved.
Regulation imposed at the research stage carries a tremendous opportunity cost, discouraging experimentation and slowing beneficial discoveries. The argument isn’t that every AI application should be unregulated; rather, regulation should occur where there is enough information about the actual risk to justify intervention.
I again asked AI to identify the vulnerability in my position, and the caution it raised is worth noting:
The vulnerability of Timperlake’s position is that waiting until application can sometimes be too late. A general-purpose model can be distributed widely and subsequently used for harmful purposes, while some risks may arise from capabilities that are difficult to contain after deployment. Critics therefore argue that at least some pre-deployment testing, reporting, or security requirements may be necessary. Current debates include proposals for mandatory reporting of AI failures and risk-tiered oversight, precisely because application-level enforcement may not catch every systemic risk.
However, my counterargument is that existing safeguards can still support a minimalist approach:
- First Amendment protections. In the U.S., scientific research, publication, software development, and communication can implicate First Amendment protections. That creates a constitutional reason to be cautious about broad government restrictions on research or dissemination merely because a technology might eventually be dangerous. This doesn’t mean AI is categorically protected from regulation, conduct, commercial activity, fraud, unlawful discrimination, and other legally regulable harms can still be addressed.
- Bring on the legal profession. Civil litigation cuts both ways, fear-mongering, tit for tat, against the AI oligarchs included. If an AI-enabled product or service causes legally cognizable injury, ordinary mechanisms such as negligence, product liability, contract, and other civil claims may provide avenues for compensation or injunctions, depending on the facts and applicable law. This makes actual deployment an important regulatory point: there is a defendant, an application, an injury, evidence, and a legal claim — and the potential for enormous damages.
- Existing sector-specific regulation. AI does not operate in a legal vacuum. Employment, financial services, healthcare, consumer protection, privacy, civil rights, transportation, and other sectors already have laws that can apply to AI-mediated conduct.
- NIST’s AI Risk Management Framework explicitly directs organizations to understand and document applicable legal and regulatory requirements, including those involving nondiscrimination, privacy, security, documentation, and disclosure. This is excellent work:
Consequently, through existing administrative enforcement, government agencies can investigate and enforce existing laws when AI is used in ways that fall within their statutory authority. That creates another layer between purely voluntary oversight and blanket regulation of the underlying technology.
My core argument is this: don’t regulate the existence of a technology simply because it has hypothetical, future, draconian capabilities. Regulate identifiable conduct and consequential applications when there is sufficient information to determine the risk, the responsible parties, and the appropriate remedy. AI should enter the legal system through the same mechanisms that have historically governed other technologies, with new rules added only when an identifiable gap is demonstrated.
The burden should fall on proponents of new AI-specific regulation to demonstrate a specific gap in existing constitutional, statutory, regulatory, and civil-liability safeguards. Where such a gap exists, regulation should target the identifiable application or harmful conduct, not theoretical AI research itself.
Finally, on AI in a life-and-death environment: armed conflict has produced great tragedies since long before AI existed.
One horrific example of the complexity of using AI was the tragic targeting mistake that hit an Iranian school. Bloomberg published an excellent article putting AI in context, showing a targeting system shaped by significant flawed human judgment, not just AI: bloomberg.com/graphics/2026-iran-school-attack
A good example of collateral damage and human error in military strikes that predates AI is the case in which the Chair of the Joint Chiefs of Staff called the mistaken killing of innocents a “righteous strike”, even though AI had nothing to do with it. Regulating AI with the best of intentions will not mitigate military arrogance and stupidity.
Three days after a U.S. drone obliterated a car in a Kabul street, General Mark Milley shrugged off reports of civilian casualties, insisting it was a “righteous strike.” On Friday that word came back to haunt America’s top general when the Pentagon was forced to admit that all 10 dead had been civilians, seven of them children. The drone had hit the wrong white Toyota Corolla.
Neither tragedy needed a new AI statute to be wrong, and neither will be fixed by one. Milley’s Toyota Corolla and the flawed Iranian targeting sequence share the same root cause: human judgment under pressure, not a rogue algorithm that regulators failed to license in time.
If we let the fear of what AI might become dictate what AI may research, we will have traded a hard problem — holding people and institutions accountable for what they actually do — for an easy one: pretending a permission slip from Washington or Brussels makes the next mistake impossible.
It won’t.
Regulate the strike, the diagnosis, the hiring decision, the denied loan. In other words, regulate the use. Leave the idea alone.
Postscript: As mentioned AI was used to defend AI and critique AI. As many users of AI have found out AI can be profoundly assertive yet dogmatically wrong. This is no small point in law. Ask and FBI Special Agent or DOJ Prosecutor to engage in making a case one of the most important data points in their investigation. It is simple; was there “criminal intent”? AI in is strengths and weakness brings a new dimension to existing law and order. Legislating AI as if it all knowing and all powerful is a fools errand because it can easily be challenged on being not so trustworthy.
The 2022 Naval Academy Michelson Lecture: Delivered in a Time of Strategic Warning
