The Agentic AI Security Series: Who Will Actually Follow the Rules? (Part 5B)
FranklyTECH
The Agentic AI Security Series (Part 5B of 6)
AI Regulation: Who Will Actually Follow the Rules?
Last week, I published Part 5 of the Agentic AI Security Series, Should or Can Artificial Intelligence Be Regulated? In that article, I argued that Artificial Intelligence cannot be effectively regulated and that oversight may ultimately have a greater impact than restriction.
Since publishing that article, I have continued thinking about the issue, and my view has evolved slightly. I now believe limited (keyword: limited) regulation may have a role, particularly for public and private organizations developing or deploying powerful AI systems. However, that belief comes with an important concern. Regulation often begins with good intentions and legitimate reasons, but over time, regulations have a tendency to grow. One requirement can lead to another, additional reporting requirements can be added, new approval processes can develop, and eventually a regulatory structure designed to protect people can become so large that it begins slowing the very innovation it was intended to make safer.
That is one of my greatest concerns about regulating Artificial Intelligence. AI is moving at an extraordinary pace, while governments and regulatory processes typically move much more slowly. I also do not believe doing nothing is the answer. There are areas where limited regulation may be both appropriate and necessary. Organizations developing or deploying AI should have responsibilities related to privacy, security, transparency, accountability, and high risk uses. Public companies, private companies, government contractors, technology providers, and organizations using AI to make consequential decisions should operate within reasonable boundaries.
The important word for me is limited. Those boundaries should be understandable, enforceable, and carefully focused on legitimate risks. Government may have a role in establishing minimum guardrails, but we should be extremely cautious about creating an ever expanding regulatory structure that attempts to control every direction in which this technology may develop.
Set the guardrails, but do not try to drive the car.
There is another problem with regulation that I believe deserves considerably more attention: Who will actually follow the rules?
Even within the United States, regulations will primarily affect visible, legitimate, law abiding organizations that are willing to follow them. Public companies, established private companies, universities, government contractors, and responsible developers will invest time, money, and resources complying with whatever rules are established. Meanwhile, individuals, organizations, and bad actors who are already willing to break the law may simply ignore those same regulations.
That creates an uncomfortable possibility. The organizations trying to develop Artificial Intelligence responsibly could become slower, more restricted, and more expensive to operate, while those willing to ignore the rules continue moving forward without those same limitations. In other words, regulation may restrain the responsible without necessarily stopping the irresponsible.
That does not mean regulation has no value. Reasonable laws can establish minimum expectations, assign responsibility, create consequences, and give society a legal framework for responding when violations occur. But we should be honest about what regulation can and cannot accomplish. Passing a law does not mean everyone will follow it, particularly when the technology involved is increasingly accessible to individuals and organizations throughout the world.
And that leads to what I believe is an even larger problem with relying primarily on regulation: Artificial Intelligence has no borders.
The United States can establish rules for companies and organizations operating within its jurisdiction. We can create requirements for public companies, private companies, government contractors, technology providers, and others subject to our laws. What we cannot do is regulate the entire world.
We cannot assume that every other nation will adopt our rules, follow our standards, share our priorities, or have our best interests in mind. We also cannot assume that nations competing with the United States economically, technologically, militarily, or strategically will voluntarily slow their own AI development simply because we decide to place additional restrictions on ours. They wont.
That raises what I believe is one of the most important questions in this entire debate: If we place increasing restrictions on responsible American companies while competitors elsewhere continue advancing without those same restrictions, have we made Artificial Intelligence safer, or have we simply made ourselves less competitive and substantially less secure?
This is where I continue to come back to oversight. And when I talk about oversight, I am not talking about oversight limited to the United States. I believe meaningful AI oversight must ultimately be global. I am sure this is happing already in some capacity.
Global oversight does not mean creating a single international organization with the authority to control Artificial Intelligence around the world. In fact, I would have significant concerns about concentrating that much authority in any one government or organization. What I envision is a layered approach to oversight involving governments, technology companies, independent auditors, researchers, universities, corporate boards, security professionals, employees, users, and other organizations with a stake in how Artificial Intelligence develops and is used.
No single layer will be enough. A government may identify one problem. A technology provider may recognize another. Security researchers may discover threats that neither saw coming. Organizations deploying AI may recognize risks unique to their industries. Researchers may identify emerging problems before they become widespread. Effective oversight should allow information, responsibility, and accountability to exist at multiple levels rather than assuming that one regulatory authority can possibly anticipate everything.
Interestingly, some of the world's largest AI companies are already beginning to move in this direction. In September 2026, leaders from Google, Anthropic, Meta, OpenAI, Nvidia, and SpaceX signed a voluntary White House AI safety accord. The participating companies agreed to measures including internal controls, dedicated teams overseeing those controls, independent external assessments, board level oversight, and regular meetings to establish safety standards and best practices. These commitments are voluntary rather than legally binding. [CBS News], [NPR]
I find that development encouraging, but I would not describe it as technology companies regulating themselves. I believe a better description is structured oversight. Internal monitoring represents one layer. Independent evaluation provides another. Board involvement adds accountability, and continuous review allows safeguards to evolve along with the technology instead of remaining static while Artificial Intelligence continues advancing.
That distinction is important because voluntary industry oversight cannot be the entire answer either. Once again, it will be most effective with visible, established, law abiding organizations willing to participate. A company, developer, organization, foreign actor, or individual prepared to ignore accepted standards or violate the law is unlikely to suddenly change direction simply because responsible technology companies agree on voluntary safeguards.
This brings us right back to the fundamental weakness of relying exclusively on regulation or voluntary standards: rules work best with the people and organizations willing to follow them.
That is why my thinking has evolved toward what I believe is a more practical approach: limited regulation combined with strong, layered, global oversight. Regulation can establish certain boundaries and consequences, while oversight continually examines what is actually happening both within and outside those boundaries to help support the enforcement of the laws put in place.
That oversight could include internal corporate controls, independent audits, board accountability, government monitoring of especially high risk activities, security controls, employee education, transparency, continuous review, clear accountability, and yes, intelligence gathering when necessary to identify those deliberately operating outside established safeguards. Some of these mechanisms can exist within individual companies, while others can span companies, industries, governments, and international borders.
This also brings us back to the Human In The Loop principle that I discussed earlier in this series. As Artificial Intelligence becomes more capable, people must remain involved in oversight, governance, accountability, and consequential decision making. The objective should not be to remove people from oversight. The objective should be to give people better tools to oversee systems that may eventually operate at speeds and scales humans alone cannot effectively monitor.
Ironically, one of the most effective tools for overseeing Artificial Intelligence may ultimately be Artificial Intelligence itself. AI systems potentially can assist people in monitoring other AI systems, identifying unusual activity, recognizing emerging risks, detecting attempts to circumvent safeguards, and bringing questionable activity to human attention.
I do not see that as replacing the Human In The Loop. I see it as strengthening it. Artificial Intelligence may monitor, analyze, recognize patterns, and raise warnings, while people remain responsible for interpreting that information, applying judgment, and determining what happens next.
My position has changed slightly since Part 5, but my central concern has not. I now believe there can be limited regulation, particularly when Artificial Intelligence affects security, privacy, healthcare, financial systems, critical infrastructure, public safety, national security, or other high risk areas. But those regulations should remain focused on legitimate risks rather than becoming an ever expanding system that attempts to control the development of the technology itself.
There is another unintended consequence of excessive regulation that I believe deserves consideration. The world's largest technology companies can hire attorneys, compliance professionals, consultants, security teams, lobbyists, and entire departments dedicated to satisfying regulatory requirements. A startup operating from a spare bedroom cannot. A student experimenting with a new idea may not be able to. A researcher or small business may not have the financial resources necessary to navigate an increasingly complicated regulatory environment.
We could inadvertently create a system intended to restrain the world's largest technology companies that actually strengthens their position by creating regulatory barriers their smallest competitors cannot afford to cross. The rules designed to make Artificial Intelligence safer could eventually help determine who is allowed to build it.
That concerns me because some of the greatest breakthroughs in Artificial Intelligence may not come from the organizations we expect. They may come from a researcher, student, entrepreneur, small business owner, or someone experimenting with an idea that nobody else has considered. We should absolutely protect society from legitimate risks, but we should be extremely careful that in doing so we do not begin protecting ourselves from innovation itself.
This is why I continue to believe oversight will ultimately have a greater impact than regulation. Regulation establishes boundaries and consequences. Oversight examines what is actually happening, identifies risks as they emerge, and creates opportunities to intervene when necessary. Most importantly, oversight does not have to begin and end with one government. It can exist across companies, industries, technology platforms, independent organizations, research institutions, security communities, governments, individuals, and potentially AI systems monitoring other AI systems.
No regulatory system will eliminate every risk. No law will make every bad actor obey it. No international agreement can guarantee that every nation will act in our best interests, and no oversight system will ever be perfect. I do not believe perfection should be the goal.
The goal should be to create enough protection to reduce legitimate risks while preserving enough freedom for Artificial Intelligence to continue creating opportunities we cannot yet imagine.
In many ways, we are living through the Wild West of the AI boom. The technology is advancing faster than the rules, standards, and safeguards surrounding it. History has taught us that complete freedom without reasonable boundaries can eventually create chaos, but too many restrictions can be just as damaging to progress. I believe Artificial Intelligence needs reasonable guardrails, consequences for those who intentionally misuse the technology, and strong oversight. The challenge is putting those protections in place without allowing them to grow to the point where they begin strangling responsible innovation.
If regulation primarily controls those willing to follow it while those willing to ignore it continue advancing, are we making Artificial Intelligence safer, or are we simply making responsible innovation less competitive and the United States less secure?
I'd love to hear your thoughts.
FranklyTECH
Technology Examined Frankly.
By Frank Pannacchione
President
Metropolitan Computer Services, Inc.
Next in The Agentic AI Security Series: Part 6 of 6
Who Is Accountable When AI Gets It Wrong?
When an AI Agent makes a mistake, who ultimately bears responsibility? In the final article of the Agentic AI Security Series, we'll examine accountability and what happens when Artificial Intelligence gets it wrong.