
The excuse for not regulating AI is that nobody can agree how. The people who built the internet would find that laughable.
One after another, the people building the most powerful AI in the world have asked to be regulated.
Dario Amodei, who runs Anthropic, published a 3,800-word essay calling for the industry to slow down and submit to outside oversight.
Sam Altman of OpenAI agreed within the day.
So did Elon Musk.
So did Demis Hassabis, who runs Google DeepMind.
Kevin Roose put it bluntly, “The platforms should be absolutely begging Congress to regulate them, because the alternative is they get sued into oblivion by a bunch of law firms.”
Congress, in response, said no.
Speaker Mike Johnson waved it off. His reasoning, that the government cannot really act because the industry itself cannot agree on what the rules should be, is a farce. No consensus, no legislation. The White House went the other way when AI czar David Sacks said the companies should simply “pace the frontier” themselves, and the President told everyone to stop trying to kill the Golden Goose.
The result is that the two positions on the table are “we can’t regulate it because they don’t agree” and “we don’t need to, they’ll regulate themselves.” Both are excuses.

We know they are excuses, because the people who built the internet were handed the same problem thirty years ago, a crowd of brilliant people who profoundly disagreed and a technology moving faster than anyone could govern, and they solved it.
In 1992, at a meeting of the Internet Engineering Task Force, a computer scientist named David Clark stood up and gave the young internet its governing philosophy in a single sentence, “We reject kings, presidents, and voting. We believe in rough consensus and running code.”
He was not speaking in the abstract. He said it in the middle of a war most people have forgotten, one Andrew Russell has spent his career documenting. Through the 1980s and early 1990s, two visions competed for how computers should talk to each other.
One was the internet’s, TCP/IP, built from the bottom up by engineers who shipped working code and standardized whatever survived contact with reality. The other was called OSI, a complete and elegant framework designed top down by international committees, backed by European governments and mandated by the US Commerce Department for federal computer purchases. OSI had the institutions, the process, and the official consensus. The internet had rough consensus and running code.
At that very 1992 meeting, roughly 700 engineers revolted against their own leadership for suggesting they adopt a few OSI protocols, and the leaders, Vint Cerf among them, backed down. They wanted no part of the committee’s grand design. Clark titled his talk “A Cloudy Crystal Ball,” and gave it a second title too, “Apocalypse Now.”
The internet went on to win so completely that OSI collapsed under the weight of its own process. Russell, who wrote the definitive history of the whole fight, put the strangeness of it plainly, saying, “It’s almost alarming that something that recent can be so easily forgotten.”
You have probably never heard of the standard the government spent a decade backing.
Lawrence Lessig later called Clark’s line “a manifesto that will define our generation.” Lessig meant something larger though,how you govern something new and fast-moving that nobody fully understands yet.
That is basically the whole response to Mike Johnson’s reasoning. The consensus-first model already went to war with the ship-and-iterate model, in the actual history of the internet itself, and consensus-first lost. It lost because you cannot govern something new by waiting for everyone to agree on the finished specification first.
I have spent my career building digital products and what Johnson is actually doing, is something every product person will recognize immediately. He is refusing to ship until every stakeholder agrees and the requirements are complete.
That is the single most reliable way to kill a product, and everyone who has ever built one knows it. It is why we abandoned the waterfall process years ago.
You only arrive at certainty by building something, carefully, and learning in the open.
Regulating AI is a product problem, and right now Congress is a bad product owner.
Rough consensus and running code

What should embarrass Congress is that the method already exists. It has existed for more than fifty years, it is thoroughly documented, and it was invented by people solving a harder version of this exact problem.
When the engineers building the early internet needed to agree on how it would work, they did not convene a commission or wait for a finished rulebook. In 1969, a graduate student named Steve Crocker started writing up proposals and circulating them for reaction, and he was so worried about sounding presumptuous that he called them “Requests for Comments.” The name stuck.
The foundational documents of the internet, the specifications that still run the internet, are literally called requests for comments, because they were drafts, never meant to be handed down finished. You published one, people argued with it, you revised, and the parts that worked survived.
That process had rules, and the rules were the opposite of Mike Johnson’s. The IETF made decisions by “rough consensus,” which one of its own documents is careful to define as agreement reached “when all issues are addressed, but not necessarily accommodated.”
It was not unanimity, and it was not majority rule. It meant enough agreement, with the serious objections genuinely engaged, to move forward and ship.
Nobody had to be fully satisfied. Nobody got to stop the whole enterprise by withholding their blessing.
They even had a method for measuring it. Instead of voting, IETF engineers hum. The chair poses a question, the room hums, and the hums are judged by volume and intensity. A loud hum from a few people signals a real objection worth working through. A weak hum all around means you have not reached consensus yet.
It sounds ridiculous, and it is, but it also built the internet, on time, while running circles around a committee with government backing and a formal ballot process.
The genius of it, and the part that matters for AI, is that nothing was ever final. The internet’s standards process moved a proposal through stages, draft, then proposed standard, then full standard, and any of it could be revised as reality taught you something the spec had missed.
This is the thing every product person does for a living.
You ship a version, you watch what it does to real people, you fix what you got wrong, and you keep going. The rules improve because they are allowed to change.
Congress is still writing in waterfall, stuck in a world that is quickly passing them by. It wants one comprehensive, dare I say beautiful, AI bill, fully specified, passed once, ideally after everyone agrees, which is to say never.
The internet’s builders would have found that laughable. They governed a technology that was changing under their feet, and they did it by treating governance the way good teams treat a product, as a living thing you steer, not a monument you unveil.
None of this is foreign to government either, whatever Congress tells you. Prohibition took effect in 1920, written directly into the Constitution, and it failed on contact with reality so completely that thirteen years later a second amendment repealed the first, the only time in American history one amendment has undone another. The founding document itself got a patch.
The closest parallel to this exact moment takes place after the 1929 market crash, when Wall Street insisted the markets were too complex for outsiders to regulate and that the industry should police itself. Congress created the SEC anyway, a standing body with the authority to write and rewrite the rules as the market kept changing under it.
Bob Greifeld, who ran Nasdaq for over a decade, points to exactly that history as the model for AI, noting that “the SEC of 2026 is a faint echo of what was created in 1934.”
Governing by revision is how the country’s hardest rules have always actually been made.
The tools are sitting right there. We wrote them down. We have been using them for generations.
The interface is the loophole

Say Congress surprises everyone and passes a law. It works out what it wants, it gets rough consensus, it ships. There is still one place the whole thing can quietly die, which may not seem completely obvious to most people, but it is arguably the most important.
The interface.
A good product team knows what Congress keeps forgetting, that you are not building for the company that has to comply. You are building for the person the rule is supposed to protect.
Right now the interface gets designed by the party with the least reason to make it honest, which is exactly backwards.
We have watched this happen already with GDPR. Europe’s data-protection law did something genuinely good in principle, giving people a right to control whether they are tracked, requiring that any consent be “freely given, specific, informed, and unambiguous.” Companies now had to ask before dropping cookies on you. A real right, handed to real people.
The trouble showed up immediately. On the very day GDPR took effect in 2018, privacy lawyer Max Schrems, the activist most responsible for putting the law on the books, filed complaints arguing that the consent companies were collecting was a sham. “Forced consent,” he called it, a choice engineered so the only easy answer was yes.
The companies, meanwhile, got to design how you’d exercise it, and you know exactly how that went, because you have clicked through it ten thousand times. “Accept All” is a big glowing button. “Reject” is greyed out, or buried behind “Manage Preferences,” or split across nineteen individual toggles, or simply absent.
The right technically exists. Exercising it was made deliberately miserable. Harry Brignull had already named this years earlier, in 2010, when he coined the term “dark patterns” for interfaces built to trick people into choices they would not otherwise make. His vocabulary was so obviously describing something real that it migrated out of the design world and into actual law, cited now in European regulation and American enforcement.
To be fair, GDPR was not useless. When you measure what it did to actual tracking rather than to your blood pressure, it moved the needle. Guy Aridor, Yeon-Koo Che, and Tobias Salz studied an online travel company and found that GDPR cut the number of tracking cookies by 12.5 percent.
Vincent Lefrere, Logan Warberg, Cristobal Cheyre, Veronica Marotta, and Alessandro Acquisti found the effect reached even US users before any American law required it.
John M. Yun summed up the early verdict plainly, saying, “the evidence in the aftermath of the GDPR is that it worked, in the sense that firms were using less data.”
The win was real but partial. Aridor’s own study found that among the users who stayed trackable, tracking actually intensified.
The law made companies ask before they tracked you, but it didn’t touch what they were allowed to do once you said yes.
Where it failed was the part it left unspecified. It said get consent. It did not say what asking for consent had to look like, and so the companies being regulated designed the asking, and they designed it to fail.
This is the most basic thing a product person knows and a legislator apparently does not.
An underspecified requirement does not get built well. It gets built in whatever way is cheapest and most self-serving for whoever is building it.
Ask the growing graveyard of apps that shipped fast and leaked everything: a sales tool whose founder bragged it was built with “zero hand-written code” and got hacked into oblivion within two days, a platform where anyone could walk into private apps with a single public ID, an AI app-builder that quietly shipped 170 sites exposing users’ personal data.
Iterate on the rule all you want, just don’t leave out what the person actually sees and clicks, because that is where good intentions become dark patterns.
The European Commission has admitted it, conceding in its own memo that the consent banners “might not achieve their aim” and that a fix for “the proliferation of cookie banners is long overdue.” Matt Burgess wrote in Wired that we need to fix GDPR’s biggest failure.
The regulator and the tech press agree that the law was right about the goal and naive about the execution.
The encouraging part is what regulators are doing now, because it looks a lot like running code. They are no longer only writing down outcomes and hoping. They are starting to regulate the design itself.
The EU’s proposed Digital Fairness Act targets deceptive interface design directly, by name. France’s data-protection regulator fined Google €150 million and Meta €60 million for exactly one thing: making it harder to reject cookies than to accept them.
In the US, the FTC’s “click-to-cancel” rule, which would have forced companies to make canceling a subscription as easy as signing up, was vacated by a federal appeals court in 2025 because the agency had skipped a required analysis of the rule’s costs. The FTC then went back and restarted the rulemaking to try again.
The lesson for AI could not be more direct. Nearly every AI rule anyone is proposing is a right exercised through an interface. The right to know you are talking to a machine and not a person. The right to see why an automated system denied your loan or flagged your kid. The right to opt your work out of a training set.
Grant those rights and leave the disclosure notice, the appeal process, the opt-out flow to be designed by the companies the rules are meant to constrain, and you already know what you will get. You will get a checkbox nobody can find and an appeals process that is a search for a phone number that does not exist.
The right will be real. The interface will make it worthless.
Patrick Neeman borrows the language of car crashes when writing about this. The first collision is the model being wrong. The second is what the interface does with that wrong answer on its way to a person, confident prose, no visible uncertainty, a fabricated number pre-filled into the field you were about to send.
Engineers spent decades unable to prevent the first collision, so they padded the interior for the second one.
AI has no padded interior. That is a design job, which means it is not going to get done by waiting for Congress.
If you are going to regulate AI, you cannot stop at what the companies must allow. You have to get specific about what it has to look like when a human being actually tries to use it. That is just knowing where the bodies are buried.
We already ran this experiment

The other position from the opening, the one the White House is pushing, is that we do not need any of this because the companies will regulate themselves.
When the AI companies asked for oversight, JD Vance told them that if they were “building Frankenstein,” the answer was not regulation but to “build the defensive mechanism against Frankenstein.” The people who made the monster should build a bigger net, and leave the government out of it.
We tried that. Not as a thought experiment, as a fifteen-year live trial, and the technology was social media.
Social media grew up almost entirely unregulated, on the motto Facebook famously put on its office walls, “move fast and break things.” That was iteration, technically, but with none of the guardrails. Ship whatever keeps people scrolling, break whatever slows that down, and don’t think too hard about what you’re breaking.
The internet’s founders were iterating toward something real, a network that worked, that anyone could build on. Facebook was iterating toward one number that mattered to them, the time you spent in the app.
Its founding president, Sean Parker, admitted that the design question from the start was “how do we consume as much of your time and conscious attention as possible,” and the answer was to hand you “a little dopamine hit” every time someone liked your post, “a social-validation feedback loop” built by “exploiting a vulnerability in human psychology.”
We know exactly how the self-regulation went, because someone inside brought receipts. In 2021, Facebook product manager Frances Haugen copied tens of thousands of internal documents and handed them to the Wall Street Journal, the SEC, and Congress.
The reporting that followed, the Facebook Files, showed something worse than a company that did not know. It showed a company that knew, in detail, from its own research, and kept the findings quiet.
One internal slide from 2019 put it in the company’s own words, “We make body image issues worse for one in three teen girls.” Facebook’s studies also found that 13.5 percent of teenage girls said Instagram made thoughts of suicide worse.
Jeff Horwitz later wrote a book, Broken Code, on how the company’s own researchers kept finding the harm and executives kept declining to fix it.
It landed in the middle of what the U.S. Surgeon General would soon call a youth mental-health crisis, warning that social media use “is associated with harm to young people’s mental health.”
The company had the data. It ran a research program good enough to find the harm, and then it left the harm in place, because fixing it would have meant slowing down.
To be fair to other side, Zuckerberg pushed back hard, writing that the idea the company prioritized profit over safety was “just not true,” and asking why a company that wanted to ignore research would fund a research program to find it.
What is not in dispute is that the research existed, that it documented real harm, and that the fixes did not come from inside. They did not come at all until an employee smuggled the evidence out.
That is the actual track record of “let them regulate themselves.” The problem was a company that could not be the thing that stopped itself, because everything that would have slowed it down was in tension with the only number that mattered. Haugen’s own request to Congress is the part that should echo right now.
She wasn’t looking for them to punish Facebook, but just asking them to help, because the company, she said, could not fix itself on its own.
Aaron Sorkin made a film about it, The Social Reckoning, about Haugen and the Facebook Files. The AI industry is standing in front of Congress making the identical “trust us” argument, one technology later, a case that movie spends two hours dismantling.
A bad product owner

AI is sitting at two moments in history at the same time.
It is at the internet’s 1992, a new and fast-moving technology that needs rules its own builders can shape before it hardens into something nobody can steer. It is also at social media’s 2010, a technology whose harms are already documented and whose makers are already deciding, quarter by quarter, how much of that harm they are willing to live with.
We are in the brief window where it’s still up to us which of those it becomes.
What makes this moment strange, and genuinely hopeful, is that the builders are asking for the rules. The people with the most to lose from regulation, Amodei, Altman, Musk, Hassabis, looked at what they are making and said out loud that someone should govern it.
Whatever you think of their motives, they have handed the government the rare opportunity of permission and a running start.
A product owner is the person who decides what gets built, sets the priorities, and clears the way so the team can ship. In this analogy that role belongs to Congress, the one body with the actual authority to make the rules everyone else is waiting on.
A bad product owner is the person with the power to decide, refusing to.
The government has answered with the two oldest excuses in the book. Mike Johnson says Congress cannot act because the industry does not agree.
The people who built the internet did not agree either, and they shipped anyway, on rough consensus and running code, and beat the committee that waited for certainty. David Sacks says the companies should govern themselves. We watched them try for fifteen years, and it took a whistleblower with a hard drive to tell us how that went.
The strangest part is that the excuses are not even true anymore, because the regulating is already happening. It is just happening everywhere except the US Congress.
The European Union passed a comprehensive AI Act, risk-tiered and phased in over years, and has already gone back to revise its own timeline as it learns what is workable, which is not failure, that is running code. In the US, with the federal government stalled, the states moved.
By early 2026, lawmakers in forty-five states had introduced more than fifteen hundred AI bills. Colorado passed the first big one, discovered it was too broad, and repealed and replaced it with a narrower version before the first draft ever took effect. That is not dysfunction.
Instead of joining in, the federal government’s response to all that iteration was to stop it. The administration’s December 2025 executive order directed the Justice Department to challenge state AI laws in court and stood up a task force to do it, and when Congress floated a ten-year ban on states regulating AI at all, the Senate killed it ninety-nine to one.
The current federal position goes further than “we cannot write the rules.” It is that nobody else should be allowed to either.
The public is not confused about any of this. Gallup found that 80% of Americans want the government to keep rules on AI safety even if it slows the technology down, a number that holds across both parties.
When Congress floated blocking the states from regulating AI, voters opposed it three to one.
Pod Save America recognized this as well. The hosts spent a segment on September 18, 2026 marveling that public opinion has swung to regulation faster than almost any issue in years, and that the only thing standing in the way is a Congress that, in their words, doesn’t know how to spell AI.
The builders want rules. The states are writing them. Other governments already have. The voters are begging for them. The only party at the table arguing for nothing is the one holding the power.
I have spent a career watching products get built and stall and ship, and this is the most recognizable failure there is. Regulating AI should be a clear product brief.
The goal is simple. Capture what a powerful technology offers while containing what it can wreck.
The constraints are known. Nobody fully understands the system, it cannot be recalled once released, and the interface is where the rules will live or die.
A competent team looks at a brief like that and ships something narrow and honest, watches what it does to real people, and revises. The EU is doing that. The individual states are doing that.
The reason it is not happening in the one place it matters most has nothing to do with the difficulty of the problem and everything to do with the people holding the brief. They are treating a living thing as a monument, refusing to lay the first stone until they can see the whole cathedral, and then trying to stop the crews already building next door.
No product survives an owner like that. Neither will this.
The tools are old, tested, and sitting in plain view. The builders are, for once, asking to be governed. Other governments and half our own states are already shipping and revising. The only thing missing is a federal government willing to act like it has built something before.
We need it to stop being a bad product owner.
References and further reading
The builders asking to be regulated
- Dario Amodei’s essay calling for a slowdown and outside oversight (CNN).
- Elon Musk (PolitiFact) and Demis Hassabis (Irish Times) backing the call.
- David Sacks, “pace the frontier,” and the “Golden Goose” response (CNBC).
- Kevin Roose, on why the platforms should want regulation before the lawsuits come (NYT, Hard Fork).
How the internet was actually governed
- David Clark and “rough consensus and running code” (Computer History Museum).
- Andrew Russell, “OSI: The Internet That Wasn’t,” the definitive history of the standards war (IEEE Spectrum).
- The GOSIP mandate requiring federal agencies to buy OSI (OSTI).
- The 1992 IETF revolt against the IAB’s OSI proposal (APNIC).
- The collapse of OSI (Internet Hall of Fame).
- Lawrence Lessig on Clark’s line as a governing “manifesto” (via Russell, IEEE Annals).
- Steve Crocker and the first Request for Comments, 1969.
- “Rough consensus,” humming, and how the IETF actually decides (RFC 7282).
- The internet’s staged standards process (RFC 1310).
- The downside of the waterfall process.
Government has always governed by revision
- The 21st Amendment repealing the 18th, the only time one amendment has undone another (National Constitution Center).
- The SEC, created after the 1929 crash over Wall Street’s objections (Living New Deal).
- Bob Greifeld, former Nasdaq CEO, on the SEC as the model for AI regulation (CNBC).
The interface is where rules live or die
- GDPR’s consent requirement, “freely given, specific, informed, and unambiguous.”
- Max Schrems, filing “forced consent” complaints the day GDPR took effect (The Register).
- Harry Brignull, who coined “dark patterns” in 2010.
- Guy Aridor, Yeon-Koo Che, and Tobias Salz, on GDPR cutting tracking cookies 12.5% while intensifying tracking of the users who remained.
- Vincent Lefrere, Logan Warberg, Cristobal Cheyre, Veronica Marotta, and Alessandro Acquisti, on GDPR’s spillover to US users.
- John M. Yun, “A Report Card” on GDPR (George Mason Law Review).
- The vibe-coding graveyard: EnrichLead, Base44, and Lovable’s 170 exposed apps.
- The European Commission conceding cookie banners “might not achieve their aim” (ICLE).
- Matt Burgess on fixing GDPR’s biggest failure (WIRED).
- The EU Digital Fairness Act, targeting deceptive interface design.
- France’s CNIL fining Google €150M and Meta €60M over consent design.
- The FTC’s click-to-cancel rule, vacated by the Eighth Circuit and restarted (Crowell & Moring).
- Patrick Neeman, “Altman and Amodei’s ‘Unsafe at Any Prompt’ Moment,” the first-collision/second-collision frame.
The last time we let an industry regulate itself
- “Move fast and break things,” Facebook’s early motto (Snopes).
- Sean Parker on engineering “a social-validation feedback loop” (Axios).
- Frances Haugen’s testimony, the internal research on teen harm, and her request that Congress help (NPR).
- The Facebook Files, the original WSJ reporting (via Al Jazeera).
- Jeff Horwitz, Broken Code, on what Facebook knew and declined to fix.
- The US Surgeon General’s advisory on social media and youth mental health.
- The Social Reckoning, Aaron Sorkin’s Haugen film (Variety).
- JD Vance, telling AI companies that if they are “building Frankenstein,” the answer is not regulation but to “build the defensive mechanism against Frankenstein” (All-In Summit).
Regulation is already happening (everywhere but Congress)
- The EU AI Act and its phased, revised timeline (Cooley).
- US state AI legislation, forty-five states and 1,500+ bills (SIG).
- Colorado’s repeal-and-replace of its AI Act (VerifyWise).
- The December 2025 executive order and the failed federal moratorium (Z Cyber).
- Gallup, finding 80% of Americans want the government to maintain AI safety rules even if it slows the technology, held by 88% of Democrats and 79% of Republicans.
- The Institute for Family Studies / YouGov, finding voters oppose federal preemption of state AI laws three to one.
- Pod Save America, on rising public support for AI regulation and Congress’s failure to act.
The lie we keep telling ourselves about regulating AI was originally published in UX Collective on Medium, where people are continuing the conversation by highlighting and responding to this story.
