
Realistically, Where Can and Can’t You Regulate AI?
The title of this column may be misleading because realistic and thoughtful are typically not the two words that drive most legislation and policy (there’s only one phrase that matters 99% of the time — politically advantageous). However, for the first time since I’ve worked in politics, we have something that is societally, technologically and economically transformational, has the ability to solve existential problems and also the ability to destroy humanity itself.
Clearly, thoughtful regulation is needed. But because AI is also so new and is developing so quickly, exactly what you even could regulate right now in a way that makes sense and does more than propel a tweet and a press release is unclear at best. The list below is my first attempt to categorize what seems feasible and worth pursuing right now.
(1). Consumer Protection
Some forms of AI only involve internal business operations, but many touch consumers one way or another. Basic consumer protection, regardless of the sector, is one of the first principles and responsibilities of government at all levels and also probably the easiest form of AI to regulate since it fits into the pre-existing approach well. So far, most of the legislation that has advanced centers around three topics: chatbots, data centers and employment regulations.
Chatbots: Legislation that governs how chatbots must work and what type of work they can do typically focuses on informing humans that they’re talking to AI and not another person. Some require age verification, some block sexually explicit content for minors, some require providing resources to users who demonstrate the tendency towards self-harm, some focus on banning misleading statements, some focus on what types of work AI can perform.
Bills have already passed in California, New York, Washington, Oregon and Idaho. Bills are awaiting signatures from the governor in Georgia and Nebraska. Others are moving in Oklahoma, Maryland, Hawaii, Missouri, Tennessee, New Jersey, Connecticut, South Carolina, Pennsylvania, Minnesota and Arizona. Note that this issue crosses party lines.1 Expect regulation of mental health chatbots especially to dominate over the next few legislative sessions.
Data Centers: Legislation that limits the costs that data centers can impose on utility ratepayers in the form of higher energy and water bills has been introduced in dozens of states, again, from leaders in both parties. No politician wants to lose their next election because they sat by when AI data centers consumed so much energy that their constituents’ electric bills jumped 30 or 40%.
That’s why ratepayer protection laws have already passed in Oregon, Maine, South Carolina, Maryland, Minnesota, California and Ohio. Bills are moving through the process in New York, Virginia, Oklahoma and Florida with many more underway. It’s also worth noting that in states where energy regulators are independently elected, incumbents have lost in Georgia and Arizona because of voter anger over having to subsidize companies like OpenAI or Nvidia (from a venture standpoint, it’s why we’re investing in and working with companies that are creating more energy efficient chips and ways to provide onsite power for data centers). If I had to guess, every state will eventually pass legislation and enact regulations protecting ratepayers.
Employment regulations: Cities and states have been working on the use of AI in hiring decisions for several years (we ran the bill in the New York City Council around AI tools in hiring back in 2023 for our portfolio company pymetrics). California, Illinois, Texas, Colorado all have laws on the books as well, with new legislation advancing in Connecticut, Minnesota and New Jersey. Unlike chatbots and data centers, these regulations are more partisan with GOP states tending to provide more protections to employers and Democratic states siding more with applicants (also, there will be times that legislators overreact to “AI” and legislate things that are really already covered by the underlying statutes for that issue).
(2). Catastrophic harm prevention
Only two states — New York and California — have enacted frontier AI safety laws. But because those two states tend to be the trendsetters for legislation and regulation for other states across the country, these models are likely to be adopted in multiple states in the future. With Anthropic’s announcement last week that its new frontier model, Mythos, is so powerful — and potentially so dangerous in its ability to identify undiscovered software vulnerabilities and weaponize them — that they are limiting access to just forty organizations, legislation to regulate frontier models to prevent catastrophic harm will likely accelerate.
The two existing legislative models both attempt to define catastrophic risk and prevent it. California’s Transparency in Frontier AI Act (SB 53) targets large frontier developers (gross revenue exceeding $500 million) and defines the risk as a cyberattack or another attack using a chemical, biological, radiological or nuclear weapon that kills more than 50 people or causes more than $1 billion in damage. It requires developers to publish their plans to mitigate risk, report incidents and enact kill switch mechanisms, and it creates new whistleblower protections. New York’s RAISE Act was signed in December and amended a few weeks ago, largely mirroring the California bill but requires faster disclosure of critical safety incidents. Neither bill bans frontier models.
Both bills are, in my view, good starts but neither really can be seen as the final answer to preventing catastrophic harm. The best way to incentivize the frontier model developers to not risk catastrophic harm is by holding them liable, but OpenAI was able to kill that provision in the California bill and it will probably take years of jurisprudence to ultimately determine who should be held responsible for that (perhaps way too late to actually prevent catastrophic harm).
Because the power of new AI models will continue to grow and grow, ongoing regulation is going to be essential, especially at the federal level. And while the hyperscalers will almost certainly argue that regulation will deter innovation and cause us to fall behind China, you could use that argument to justify virtually anything. We don’t let anyone just build a nuclear power plant and we shouldn’t just allow any form of AI to be made commercially available if the risks outweigh the rewards.
(3). Jobs
This is less about regulating the use of AI and more about what will happen if AI leads to major job displacement across the economy. Economists are taking the risk more and more seriously as more companies start reducing headcount because tasks that were performed by humans can now be performed far better instead by AI tools. The natural inclination of politicians when faced with the question of job loss is to offer more job training. That’s not a bad idea, except no one really knows what to train people in. Not everyone can become a plumber and even as an early stage venture capitalist, I don’t know what industries are going to emerge because of AI (and from what I can tell, none of my colleagues do either).
I had lunch the other day with Daniel Schrieber, the co-founder and CEO of Lemonade, an AI-powered insurance company that we invested in and helped legalize. Daniel has funded economic studies looking at the potential impact of AI job displacement in Israel and came up with a very innovative solution based on creating a new type of negative income tax where the higher profits companies realize from using AI are then taxed as a VAT and distributed to people who lost their jobs. The study, which can be found here, offers an entirely novel approach to the problem where the more that profits grow from reduced headcount, the more tax revenue becomes available to then support those who lost their jobs.
(4). Where AI can be used now to add societal value
Yes, AI brings tremendous risk, as Anthropic most recently showed us with the release of Mythos. And yes, AI has the potential to solve massive problems like climate change and disease treatment. AI will, I believe, help climate scientists figure out how to efficiently and safely capture and store carbon from the atmosphere, allowing us to focus on attacking the problem directly rather than trying to limit further temperature increases. AI will, I believe, help doctors and researchers figure out how to develop cures for every type of disease, identify exactly how to isolate and treat every type of mental illness, and create drugs that can attack all of the underlying causes of mortality. However, it can’t do that yet. But just in taking two companies from our portfolio, here are two examples of what AI can do to help today.
Doctronic is an AI medical advisor that helps people quickly diagnose ailments and medical issues and then, when a doctor is needed, immediately connects them to one via telemedicine. It is one of the fastest growing digital health companies around and in January, we received permission from the State of Utah to begin issuing prescription refills via AI for about 200 different types of medications. The logic is simple: having to chase down your doctor to get a refill is just a waste of everyone’s time. It’s a hassle for the patient, the doctor and the doctor’s staff. And the more that doctors are spending time on paperwork, the less time they’re treating patients. That drives up the overall cost of health care. We’re now working on similar approvals in other states. This is the type of safe innovation that can take the world’s most expensive and confusing healthcare systems and make it far more accessible and affordable.
Hazel is an AI startup that radically improves the procurement process for governments. Right now, let’s say you run a school system. You always need pencils. When supply runs low, someone has to notice, then tell the procurement and legal teams that they need more pencils. People then start writing an RFP that goes around and around internally. Eventually, it gets issued and sent to the half a dozen pencil vendors they always deal with. Those vendors send back written responses which are then reviewed by the RFP committee. The committee is made up of human beings who, at best, have their own set of biases, preferences, relationships, ambitions, emotions and everything else that comes with being human. At worst, they’re outright corrupt and are taking bribes to fix the outcome.
In the normal scenario, the school system — and therefore the taxpayers — is getting relatively few bids and then evaluating them in a suboptimal way. Hazel instead uses AI to write the RFP, distribute it to hundreds of pencil vendors, evaluate and score the responses, do so without any bias or corruption, and then provide its recommendations to the relevant person in the school district, who can decide how to proceed. It gets the taxpayers a better price, the school system better quality and saves a lot of staff time and money. Imagine if we did all procurement this way. The $2 trillion currently spent across all levels of government every year would be so much more efficient, cost-effective and trustworthy.
Those are just two examples of companies we work with directly, but there are hundreds more that can be used to make our government better, our schools better, our hospitals better, our energy systems better, our law enforcement better and help virtually every component of the public, private and non-profit sectors.
(5). So what do we do next?
A lot and a little at the same time. Just passing laws and creating regulations to say you did something is often harmful. Just sitting around and letting the world pass you by could be even worse — Congress tried this with social media and look where it got us. What we need are lawmakers and regulators in both the executive and legislative branches in city, state and federal government actively seeing where there’s true risk to their constituents that merits new regulation now, where there are opportunities to use AI to do their jobs better and make life easier for their constituents, and to anticipate the significant increase in unemployment and figure out now what to do about it.
Overall, this is going to be a very iterative process. Problems and risks will emerge and legislators and regulators will play whack-a-mole to try to solve them (or at least not be blamed for them). In a perfect world, governors and legislative leaders (and in an even more perfect world, the President and Congress) would break the different areas around AI into categories like those above and then thoughtfully determine where they can and should engage in each.
That seems very unlikely but I do think that, as crazy as this sounds, you could see a bipartisan federal deal on some of the issues above next year — not necessarily because the House Democrats, Senate Republicans or Democrats and Trump truly want to solve these problems but because they’re terrified that 2028 will be the AI election and if they do nothing, they’ll be punished for it. So even though elections as the driver of what government chooses to do in almost all cases is usually not the best way to tackle and solve problems, perhaps this time, it may actually help.
Doing nothing is not an option. Trying to anticipate everything and regulate it before it happens also won’t work. If there was ever a time and an issue for true leadership, it’s now — lawmakers who are engaged, thoughtful, not putting politics first and genuinely trying to use good judgment to address each risk and opportunity as soon as it’s feasible. And if we fail, the fact that the previous sentence sounds like a fantasy may be exactly why.
In December, Trump issued an Executive Order trying to ban states from regulating AI. Governors across the board have ignored it and the order itself is completely unenforceable in court.
Next Post
Unpacking an OpenAI IPO
Venture investing and retail stock investing are two very different things.
