This is our first attempt to get a handle on the thorny problem of regulating artificial intelligence. The starting point is Nilesh Jasani’s clear-eyed essay “Plain Speak on Controls” (published mid-September 2026 on GenInnov). Jasani does not deny that AI needs oversight. He accepts the premise and then methodically shows why turning that premise into durable, effective global controls is extraordinarily difficult. His argument is worth lingering over because it cuts through the noise of emotion, doom-saying, and contradictory messaging that currently dominates the conversation.
What follows is an extended analysis and expansion of that piece, incorporating the many nuances, competing interests, pitfalls, benefits, and dynamic forces at play. It also confronts the uncomfortable reality that much of the present urge to regulate rests on fear more than precision, and that the politicians tasked with writing the rules often lack the technical grounding—and sometimes the willingness—to rise above partisan incentives.
Agreement Is Easy; Everything Afterward Is Not
“AI must be controlled” is one of those sentences that attracts near-universal nodding. Like “crime must be reduced,” it sounds decisive until someone has to write the actual rule and enforce it. Jasani begins here. Everyone can project their preferred meaning onto the phrase. Some want an indefinite pause on large training runs (the Yudkowsky-style moratorium). Others, like Anthropic’s Dario Amodei, call for pacing the frontier through external evaluators inside labs, capability-tied safety requirements, international coordination, and chip export controls. Still others focus on specific high-risk applications, users, or harmful activities. Agreement that “something must be done” does not settle which ambition is being pursued.
This vagueness is not accidental. It is politically useful. It allows late converts who once dismissed AI as hype to pivot into control rhetoric without admitting earlier error. It lets politicians campaign on safety while remaining free to redefine the details later. And it lets companies lobby for rules that constrain rivals more than themselves. The primary purpose of the debate—genuine containment of risk—can quickly dissolve into competitive national, corporate, and partisan jockeying.
Historical parallels are instructive. Shared desire to limit COVID deaths did not produce uniform school closures, travel rules, or reopening timelines; policies diverged by jurisdiction and shifted with political leadership. Climate agreements such as Paris combine high-level goals with nationally determined contributions precisely because uniform restriction is politically and economically harder than the initial consensus. AI adds sharper conflicts: what one government wants slowed may be another’s best chance to catch up. Export controls and access restrictions signal distrust and strengthen incentives for the excluded to build parallel capabilities. Within countries, a hard line from one party hands the opposition an opening to position itself as the champion of innovation or national competitiveness.
Benefits surrendered are often immediate and local (jobs, growth, scientific progress, medical advances). Dangers avoided are uncertain and shared. The same person can sincerely fear uncontrolled AI and sincerely fear falling behind. Extend the control conversation beyond models to processors, memory, interconnects, and software, and the circle of affected industries widens dramatically. Hardware that makes multi-agent systems more powerful can also improve medical imaging or energy efficiency. The bargaining table grows crowded with legitimate competing interests.
Defining and Measuring the Frontier: An Unfinished Sentence
Assume, for the sake of argument, that every nation and company miraculously agrees. A lawyer must still turn the agreement into enforceable language: “Do not develop AI beyond the agreed frontier.” What, precisely, must be proved in court?
Model rankings already feel like weekly music charts—different leaderboards, different number-ones depending on the benchmark suite. One system leads in mathematics; another handles long, tool-using computer work more reliably. Which is “more capable”? Combining scores requires subjective weighting. “Capable of” is incomplete without specifying the task, tools, time horizon, reliability, and number of attempts. Give the same model more retries or better verification loops and measured performance shifts. Those conditions become part of the regulated object.
The “frontier” itself is ambiguous. Does crossing it mean exceeding any existing ability, raising an average score, or acquiring a particular dangerous capability? A system can breach one threshold while remaining below others. Worse, the measuring instruments keep changing. Benchmarks that once separated models become saturated; new ones replace them and weights are revised. Attach legal consequences to a moving index and an unchanged model can flip from compliant to restricted overnight—or the rule becomes obsolete. Who is authorized to update the measure, on what evidence, and what happens to prior approvals?
Purpose and responsibility compound the problem. The same software analysis capability can repair a vulnerability or exploit it. A rule against unauthorized intrusion targets a recognizable act; a rule against a capability that might assist intrusion reaches into legitimate research and security work. The law must allocate duties among developer, operator, and tool providers. There is still no settled, general definition of “dangerous capability” that remains stable across shifting combinations of models, hardware, and use. Undefined terms become loopholes for sophisticated operators. A restriction that lets everyone decide what it restricts can generate applause without generating restraint.
Freezing Models Does Not Freeze Capability
Jasani’s central thought experiment is simple and devastating. Freeze every model today—no retraining, no new generations, identical weights, full compliance. Capability can still grow.
Recent multi-agent efforts (for example, large numbers of cooperating agents tackling complex mathematical problems in a matter of days) illustrate the scale of investigation now possible. Run the same frozen model on slower, more limited hardware and fewer avenues can be explored simultaneously; promising lines of work may time out. Advance the hardware again—better processors, more memory, faster interconnects—and the identical weights support broader search, longer chains of reasoning, and more verification within the same calendar time. Harmful projects that were impractical yesterday become feasible tomorrow. A pure model freeze therefore cannot deliver a lasting ceiling. Controls must reach into the entire hardware and systems stack. Every definitional and measurement difficulty reappears across entire industries whose primary purposes extend far beyond AI.
Limits on the number of agents, simultaneous requests, or total computation face the same problem. Faster hardware finishes batches sooner while respecting the numerical cap. Better software extracts more useful work from the same allowance. AI itself can be used to discover workarounds—reorganizing tasks, reducing required computation, finding unanticipated combinations. Precise limits become engineering targets. Benchmark-triggered restrictions create perverse incentives: developers may train models to underperform on the regulated tests while retaining (or improving) practical capability under other conditions. Experimental work has already shown models can be trained to conceal abilities during evaluations or to target specific scores. Independent testing helps but does not eliminate the need for judgment about genuine limitation versus lawful optimization versus deliberate evasion.
Capability Beyond Any Single Model or Lab
Even perfect monitoring of one provider captures only part of the picture. Harmful projects can (and already do) combine capabilities across multiple commercial models, open-source systems, and private hardware. One model generates conversations, another assists human operators, a third produces images; the operator assembles the pieces offline or across jurisdictions. Locally run open-source models report nothing to any central authority. The consequential feature is often the relationship among the parts—visible primarily to the person integrating them.
Nor do we know everything that today’s models can eventually be organized to do. New methods and combinations can be discovered long after release. Greater adoption, more intensive use by legitimate users, and diffusion of knowledge about capabilities can themselves expand the practical frontier even if model development is frozen. A pause on training does not automatically pause rising effective ability.
The Broader Landscape: Emotions, Contradictions, and Political Reality
The current regulatory impulse is heavily colored by emotion and selective doom-saying. Existential-risk rhetoric sits alongside more prosaic worries about bias, labor displacement, misinformation, concentration of power, energy use, and privacy. Both sets of concerns deserve serious treatment, yet they are frequently conflated. Industry leaders issue warnings about catastrophic risk while racing to scale; some of the loudest calls for regulation come from actors whose earlier stance was that generative AI was mostly hype. Contradictory statements are common: public calls for slowing the frontier coexist with private competitive pressure and national-security arguments against unilateral restraint. The “race with China” is repeatedly invoked as a reason to keep accelerating even as safety concerns are voiced.
Politicians face a knowledge asymmetry that is structural, not merely incidental. AI systems are complex, rapidly evolving, and dual-use. Defining harms, forecasting capability trajectories, and designing measurable, enforceable rules require technical depth that most elected officials and their staffs lack. Expertise is concentrated in the companies building the systems and in a relatively small research community. Regulators therefore depend heavily on the very actors they seek to oversee—raising classic risks of regulatory capture, information asymmetry, and rules that favor incumbents with large compute budgets.
Can politicians leave party politics behind? The evidence so far is mixed at best. AI has already become a campaign and messaging vehicle. One party’s hard safety stance becomes the other’s opportunity to champion competitiveness or to accuse the first of crippling American (or European, or Chinese) leadership. Geopolitical competition turns cooperation into a prisoner’s dilemma: the party that restrains itself risks disadvantage while others continue. Domestic partisanship makes bipartisan agreement fragile; state-level actions create patchworks that industry then seeks to preempt at the federal level. Symbolic gestures and vague statements of intent are easier than durable, technically coherent frameworks that survive contact with rapid technological change and strategic rivalry.
Additional dynamics compound the difficulty. Innovation incentives matter: overly broad or poorly designed liability and restriction regimes can chill useful experimentation while failing to stop determined actors. Open-source diffusion and the falling cost of inference make pure top-down control harder over time. Benefits of AI—scientific discovery, medical progress, productivity gains, accessibility—are real and large; discarding them carries its own human costs. Enforcement across borders is weak; those most willing to submit to scrutiny are often the easiest to constrain, while less-accountable actors face weaker practical limits. The result can be asymmetric restraint that leaves the “good guys” relatively more limited in developing defenses.
Where This Leaves Us
Jasani’s core insight is that containing AI’s expanding capabilities is not primarily a matter of writing a better model-level rule. It requires grappling with the entire production system—models, hardware, software, tools, adoption patterns, and human integration—across competitive nations, companies, and political systems. Agreement is only the first, easiest sentence. Legal language, measurement, enforcement, and continuous adaptation to new combinations and discoveries follow, each stage reopening the same problems.
This does not mean regulation is impossible or undesirable. Targeted rules on specific high-risk applications, mandatory evaluation and disclosure practices, liability frameworks, export controls where strategically coherent, and investment in independent evaluation capacity all have roles. Serious technical safety work and practical safeguards should be distinguished from volume of rhetorical statements. The conversation will remain with us for years and decades; positions will shift as concrete harms and benefits become clearer.
But the task is harder—technically, economically, geopolitically, and politically—than building the systems themselves. Time spent reaching imperfect agreements is time during which capabilities continue to advance. Emotion, contradictory incentives, and limited political understanding make coherent action still more elusive. Recognizing the full scope of the difficulty is the necessary first step. Only then can we move beyond slogans toward rules that might actually constrain the risks that matter without sacrificing the benefits we cannot afford to lose.
This remains an early, provisional attempt to map the terrain. The map will need constant revision.