
Guest Opinion
Building a regulatory framework for an emerging technology is a massive undertaking because it involves thinking across agencies and departments, all with different cultures and missions, and identifying gaps that may exist for a future that is partly speculative. In 2006-07, as Chief Counsel of the Research and Innovative Technology Administration of the U.S. Department of Transportation, I led the development of the Hydrogen Regulatory Framework for a Hydrogen Economy across nine federal departments and agencies, which was published in the Federal Register in 2007. We developed a federal framework of existing laws that could be applicable to and regulate all aspects of the use of hydrogen as an energy source. Regulation gave predictability to investors who might want to invest in a hydrogen economy. The next administration had other priorities, but that is how the executive branch works for either party in power. Fortunately, federal regulations are not rescinded without a process, so the regulatory framework is still a federal regulation.
At the beginning of the third millennium, a newly emerging nanotechnology was threatening our way of life, or so they said. These were elements that, at the atomic scale, took on new properties compared with their larger compounds. They could be inhaled and perhaps even pass the blood-brain barrier, causing contamination. There was fear and concern about the effects nanoparticles might have on humans and the environment. They could be toxic if ingested, and because they were unseen, that posed a threat as well. A new phobia was even adopted to describe the fear—nanophobia. It turned out that existing regulations had sufficient scope to regulate all of these threats, with some adjustments to toxic substances regulation under TSCA and a few other laws.
I also became a legal expert in the regulation of biological materials that were dual-use, meaning they could be developed into biological weapons. I served as an expert to the United Nations Convention on Biological Weapons. A regulatory framework was developed and enhanced after the anthrax attacks of 2001. It included safety and security regulations focused on the handling of the agents, the training and background of researchers, laboratory containment facilities, and perimeter security. These were all elements of a safety and security regulatory framework.
The regulatory framework for nuclear energy for national security purposes was used as a model for developing the biological agents regulatory framework, and it was not a good fit. For just one aspect, it is worth noting that nuclear materials sit in their inventory space, and when you come back in a couple of weeks, the inventory should be the same. With biological agents, the very nature of them is that they propagate and increase. So, if you come back in a couple of weeks and you do not have an increase in your biological agent inventory, it is likely dead.
Therefore, biological materials could be stolen or misplaced, and it would be nearly impossible to determine that based on this system. Changes in inventory were uncertain, but the regulation included civil penalties and even laboratory-wide closure if inventories could not be accounted for. This is what happens when lawyers do not ask scientists how to develop safety and security regulations around the materials about which they are experts.
In the evolution of the adoption of emerging technologies into our society, there is a typical pattern that is followed. The pacing theory suggests that, in the beginning, we do not know enough about the risks and threats to regulate them. Often, we have to wait for individual cases that the tort system can remedy, such as product liability and negligence. Once the threats are assessed, a statute and regulation can be developed to control them.
The pacing problem is how to get this right and not regulate so early that the technology never develops and investors lose interest in it. Larry Downes described the pacing problem by saying that “technology changes exponentially, but social, economic, and legal systems change incrementally,” and that this law was becoming “a simple but unavoidable principle of modern life.” Add to that Collingridge’s Dilemma, which says that emerging technologies create disparities between those who can afford the new technology and those who cannot.
As early as 2021, there was a first attempt to develop a global regulatory framework for artificial intelligence by the European Commission. It was based on restricting only “high-risk” uses that would alter legal protections such as privacy and biometric data privacy. A year and a half later, in October 2022, the Office of Science and Technology Policy, the White House science office, proposed guidance with five criteria for guarding against AI risks, all related to legal protections such as privacy and nondiscriminatory algorithms.
In May 2023, the private sector decided to take the lead and proposed an international nuclear-agency-type organization run by the United Nations, and the secretary-general of the United Nations endorsed the plan. A few months later, a bipartisan bill was introduced in the U.S. Senate to create an oversight agency for licensing modeled after the Nuclear Regulatory Commission. Given that the NRC has an average time of three to four years, it was clear that slowing down the technology was part of the plan. Senators who author such legislation can expect to be lobbied by the AI industry and, of course, receive campaign contributions from them, so this is a lucrative opportunity.
Then, in October 2023, President Biden signed Executive Order 14110, which required notice to the federal government for any AI system that exceeded a certain size and required the sharing of safety-testing results. That executive order was rescinded by President Trump on January 20, 2025, with Executive Order 14179, issued January 21, 2025, which directed the removal of barriers to the commercialization of AI.

The next phase followed, with states seeking to introduce legislation to address AI. California’s bill was vetoed by Gov. Newsom, but he later signed legislation to create verification organizations for AI. Colorado passed a statute that would have been the first risk-based AI statute, SB 24-205, passed by a state, but it was rescinded in light of the federal preemption policy to prevent state laws from burdening the commerce of artificial intelligence.
Why Not Use the Nuclear Energy Regulatory Model?
As you saw from above, it is not a good fit when it has been used in the past as a regulatory model, for example, with biological agents.
The fuel for nuclear reactors, uranium, requires an infrastructure for enrichment. AI relies on hardware such as specialized chips, code, datasets, and algorithmic code. These are easily duplicated and easily transmitted anywhere in the world through the internet.
The dual-use nature of AI is difficult to regulate because the same processes and datasets can be used destructively as well as constructively. Nuclear energy and nuclear weapons production have large distinctions, and uranium enrichment is relatively easy to evaluate. The same inspection regimes will not work for AI as they do for nuclear security. The dual uses of AI are endless.
The physical infrastructure to build a nuclear reactor station can take years, whereas AI models are trained in weeks and distributed just as fast. This is a major mismatch with a federal agency such as the NRC, which works on very slow timelines, even with its current reform underway.
Time to Regulate?
It is too early to decide on a regulatory model for AI. The federal preemption policy is a good move to prevent barriers to the development of AI across states and to monitor its risks and successes.
Existing safeguards preventing the exportation of code with national security risks are the best control we have, and even that can be thwarted in a basement with an internet connection.
The first risks are emerging with litigation against AI companies over the manipulation of children vulnerable to suicide and its properties of creating addictive social media feedback. The reaction from AI companies was to seek legislation that would likely protect them from liability in such lawsuits, which would be counterproductive to the evolving nature of regulating emerging technologies.
This time next year, we will find that AI did not kill us all, and instead, we will have a much better idea of how it should be regulated.
To read more articles by Professor Sutton go to: https://profvictoria.substack.com/
Professor Victoria Sutton (Lumbee) is a law professor on the faculty of Texas Tech University. In 2005, Sutton became a founding member of the National Congress of American Indians, Policy Advisory Board to the NCAI Policy Center, positioning the Native American community to act and lead on policy issues affecting Indigenous communities in the United States.
The post Hype and Harangue in the Age of AI appeared first on Native News Online.