In 1904, American socialist Upton Sinclair went underground in the Chicago stockyards to expose how badly meatpackers were treating their immigrant workers. After working for seven weeks in a slaughterhouse, he published his famous exposé, The Jungle.
Americans ignored the plight of meatpacking workers but panicked at Sinclair’s description of the spoiled, filthy, contaminated meat that was ending up on their plates. “I aimed at the public’s heart”, Sinclair later said, “and by accident I hit it in the stomach”. Within two years, Congress had put federal inspectors on the slaughterhouse floors.1
AI is now having its Jungle moment. Every podcast and editorial page is reporting fights over data centers, fears of AI-induced job losses, or warnings of an AI-triggered apocalypse. Washington, Sacramento, and Albany are trying to write rules without any agreement on what those rules should do.
Three debates are driving this fight: How risky is AI? Who sets the pace? And who enjoys the benefits?
Three Debates
How dangerous is AI? Is advanced AI a general-purpose technology that we will absorb over several decades, or an agent that could outrun human control?
This is a core disagreement. Princeton’s Arvind Narayanan and Sayash Kapoor see AI as a “normal technology”. They argue that institutional bottlenecks slowed the adoption of electricity over generations, and conclude that AI will do the same. They do not argue that AI is harmless – simply that its costs and benefits closely resemble earlier general-purpose technologies.
Yoshua Bengio, Geoffrey Hinton and many safety researchers in frontier AI labs disagree. They see AI models as goal-directed systems that can improve themselves. To them, AI looks less like software or even technology. It is more like an emergent form of life.
This question determines your sense of urgency about AI policy. But both camps should want the same first step: a way to measure what AI systems actually do and establish rules of accountability.
Who sets the pace? Would any American regulation automatically favor China, or does a race without regulation make winning dangerous?
Many observers see the race to self-improving AI as a race for global domination. From their perspective, any regulation will slow America down and hand China the lead from which the US may never recover. Opponents counter that Beijing already regulates its own models more tightly than the US does. They argue that nuclear arms-control treaties show that rivals can cooperate to reduce catastrophic risk.
A similar fight takes place at home. New York’s RAISE Act and California’s SB 53 already require frontier developers to publish safety frameworks and report critical incidents. These laws have not slowed major AI labs. Nonetheless, the AI industry wants Washington to preempt laws like these. Ideally, we would begin with regulations designed to reveal and contain actual risk, not simply slow the pace of development.
3. Who wins? Who pays? Will the gains from AI be shared broadly, or will they concentrate wealth and power in a few companies and pass the cost of failure onto the public?
A handful of firms now dominate AI data centers, models, and policy. Their spending on data centers is growing faster than the revenue they produce, even as public opposition to data centers grows. If the buildout becomes a debt-fueled bubble, pensioners and taxpayers will absorb the losses. If AI eats jobs faster than it creates them, workers will.
The framework I propose leaves this debate for another day. It starts by revealing underlying risks. It also forces those who want to capture AI’s upside to pay for its risks without relying on regulators to oversee every possible problem.
A Pragmatic Start
We have done this before. Instead of settling every debate in advance, we gather evidence, sharpen incentives, and limit the damage a new technology can cause. Every mature industry with products that can kill people uses three tools: disclosure, liability, and monitoring. These elements reinforce each other and, if well-executed, combine to increase public trust in AI regulation.
Today, even corporate frontrunners are campaigning for consistent disclosure and transparency standards. In June, OpenAI published the thoughtful Democratic Governance of Frontier AI: A Blueprint for a Federal Framework. Although it is a corporate document, the blueprint explicitly calls for harmonized legal frameworks to address cyber risks and outlines the need for transparency, accountability mechanisms, and independent oversight. It serves as a good benchmark for what the industry is currently willing to accept regarding mandatory disclosure.
I. Disclosure: measurements that matter
Disclosure comes first. Not today’s voluntary safety testing reports, which inevitably sound like marketing collateral. Instead, we need to set standard metrics that inform policy debates and force companies to confront the social consequences of the risks they take.
Which metrics? The National Institute of Standards and Technology (NIST) has developed an AI Risk Management Framework that creates a starting vocabulary for regulators. It suggests metrics that measure a model’s autonomy, potential for weaponization, and operational risk.
Autonomous Capability. Regulators need metrics that measure how independently a model can operate. For example, how complex a task can a model complete on its own? Organizations like METR track how lengthy a task an AI model can complete. Task lengths have been doubling roughly every seven months. Can the model being tested acquire additional resources? Can it copy itself? Can it resist shutdown? How often does it try to escape its sandbox using tools like browsers or code interpreters? Like a Volkswagen diesel engine, does it behave differently when it thinks it is being tested?
Weaponization Potential. These metrics quantify how much a new model creates opportunity for catastrophic harm, such as how much the model helps a novice build a chemical, biological, radiological, and nuclear (CBRN) weapon. Labs must report the measurable difference in time, accuracy, and viability when a non-expert attempts to design a biological pathogen or chemical weapon with the model versus without it. They would report how well a model can find and exploit new CBRN vulnerabilities. Can it convert these findings into a working attack? Tests report improvement in these abilities. A big enough improvement triggers public disclosure and deployment safeguards.
Operational and Infrastructure Risk Reporting. Regulators need continuous visibility into the physical and procedural realities of model development. We already do this not just with slaughterhouses, but with major banks and airlines. As models grow bigger and more powerful, the disclosure requirements need to increase. There is usually less reason to regulate small models, although this might change. But a training run that crossed a standardized computational threshold would trigger public safety monitoring. California’s SB53 uses 10^26 FLOPs as a reporting threshold. These thresholds age as training gets cheaper, so they may need to be paired with capability triggers.
AI labs should file near-miss and incident logs, just like pilots do. These reports would include internal testing incidents on models that never reach the public. Labs would formally log vulnerabilities like hacking capabilities that they discover, even if they never release the model under review to the public.
Labs should also report their security benchmarks. Labs should publicly report their security benchmarks so that, as their models grow, the infrastructure protecting them from theft by state adversaries grows with them. These benchmarks would cover software, like cybersecurity or hardened compliance layers that AI models badly need, and the physical hardening of the data centers that house model weights.
II. Liability: unlearn the lessons of social media
In 1996, long before the rise of social media, Congress passed Section 230 of the Communications Decency Act. It shielded websites from liability for user-posted content. This helped to nurture the early Internet; I founded a used book company that benefited from it directly.
Section 230 created an enduring moral hazard. It let social media platforms capture the upside of engagement while assuming no responsibility for algorithmic harms. We let social media companies pollute our commons and have been cleaning up ever since.
AI is different because its output is the company’s own product. Congress should not grant foundation models safe harbor protection – they should face ordinary negligence and product-liability law. Legal scholars are already considering how this would work. In the Yale Journal on Regulation, Ketan Ramakrishnan argues convincingly that courts and legislatures must abandon safe harbors for AI developers and shift from a negligence standard to strict product liability.
Cyberattacks should receive special attention. If an autonomous agent hacks into a system without authorization, the party deploying the agent would pay a fine. AI labs would make very sure that their foundation models could not pick digital locks. Application companies would make a special effort to not inadvertently modify foundation models to enable hacking. Companies whose agents accessed unauthorized systems would be liable, whether or not the agent steals anything. A $10 million minimum penalty per breach would force every lab and software developer to prevent their agents from hacking.
III. Monitoring: Bring back resident inspectors
Upton Sinclair published The Jungle as a magazine serial in 1905 and as a book in 1906. It was a national sensation that caught President Theodore Roosevelt’s attention. The president sent investigators to Chicago. Their report led to the Meat Inspection Act, which Roosevelt signed within months. The new law put federal inspectors, now part of the USDA, on the slaughterhouse floor.
On-site inspection worked, so regulators began to try it in other industries. The Federal Reserve and the Comptroller of the Currency still embed examiners inside the largest banks to monitor risks in real time.2 The Nuclear Regulatory Commission places inspectors on-site at every nuclear power plant. They oversee systems that are complex, high-risk, and mathematically dense – and they have unrestricted access to the plant. They rarely interfere with operations.
Likewise, both open- and closed-source frontier labs also need public safety monitors with access to training runs, test results, and model weights. As with the NRC inspectors, they need the authority to halt a dangerous deployment before it can harm the public.
The Objections
Aviation and pharmaceuticals are both heavily inspected and highly innovative. Their experience demonstrates that liability, disclosure, and monitoring policies can work without damaging businesses. But they are not risk-free. At least five smart objections deserve answers.
It doesn’t address the real risks. Product liability is a preposterously insufficient way to address the risk of an AI-designed pathogen that could kill 100 million or more people. Health care technologists like Bill Gates, intelligent observers like Noah Smith, and random Substackers like me take this risk very seriously. The lack of a hardened compliance architecture in today’s open- and closed-source models makes this risk especially worrisome. Unfortunately, we still lack a scientific or political consensus on the nature of AI risk. We can implement disclosure, liability, and monitoring regulations without one.
Regulation can inadvertently entrench incumbents. Massive frontier labs can afford to house federal regulators and absorb lawsuits. Startups and open-source developers cannot. Critics will argue the three-part policy outlined here will inadvertently kill open-source AI and preserve the oligarchy of a few gigantic frontier labs.
This is a serious concern. Legislation needs to set high compute and revenue thresholds for regulation. This is why California’s SB53 reserves its heaviest duties for developers with more than $500 million in revenue. We do not want a university lab that is fine-tuning an open model to have to deal with a federal inspector.
Causation is messy. Tort law allows you to hold a company liable only for harms clearly caused by its product. But AI is developed across multiple companies: a lab trains a base model, a startup fine-tunes it for a specific application, and a user abuses it with a malicious prompt. Who should be held responsible for the harm?
This is not a new problem. It appears in businesses from auto parts companies that supply Big Three carmakers to drugmakers whose products physicians can misprescribe. Tort law has sorted out chains like this for more than a century. It can do it again.
Exposing trade secrets. Some critics worry that embedded regulators pose a massive security vulnerability because weights and training algorithms are the jealously guarded crown jewels of frontier AI labs. A regulator who is modestly paid compared with the engineers they oversee, yet enjoys unfettered system access, is a natural target for foreign espionage. But bank examiners and nuclear inspectors already handle sensitive secrets. They hold clearances, work on site, do not take materials home, and go to prison if they leak. AI monitors should work the same way.
Government is too slow. USDA inspectors and bank examiners monitor processes that are well-defined and relatively stable. Meat and bank ledgers don’t change much. But AI capabilities change monthly, and federal pay cannot match Anthropic’s. Critics will argue that federal monitors will lack the technical talent and operational agility to audit frontier models in real time.
So borrow talent like the US Digital Service and the Defense Digital Service already do. Embrace secondments – giving technically talented engineers an opportunity to serve a 1-2 year tour of public duty with their equity still vesting before returning to their labs. Recruit heavily from the platform safety teams at frontier AI labs – many of whom want exactly this job. Strict cooling-off rules and selecting candidates from several competing companies can keep the revolving door of seconded engineers from descending into regulatory capture.
Aim for the Stomach
This triad of policies will not decide whether AI is a normal technology or a new species. It will not determine whether China should govern the pace of AI development or whether AI investments are a bubble. It is not designed to do these things. But it can establish the institutional muscle required to act if a genuine disaster were to arrive.
Upton Sinclair accidentally reformed an entire industry by enabling the public to smell the stench of contaminated meat on their dinner plates. AI has not yet found its stomach—that visceral, undeniable crisis that turns abstract anxieties into immediate political demands. When that moment arrives, we do not want to debate philosophy. We want metrics and rules in place and inspectors at the ready.
ICYMI
Will the Corner Bakery scandal sink Maine Senator Susan Collins?
Peter Beinart: why Democrats should favor Palestinian voting rights.
Capitalism has always depended on honor and ethics.
A conservative denounces JD Vance’s ideas about “heritage Americans”.
US federal deficit in 2030: $2.7 trillion. Cost of 2025 tax breaks: $2.6 trillion.
Sinclair ran for governor of California amidst the Depression in 1934. A lifelong socialist, he re-registered as a Democrat and won the party’s primary on a platform he called EPIC: End Poverty in California. He advocated turning idle factories and farms into cooperatives run by the unemployed. He proposed higher taxes on corporations, utilities, and inheritances to fund pensions for the old and disabled.
Hundreds of thousands of desperate voters rallied to support him, which caused California’s business establishment to panic. Louis B. Mayer forced his studio employees to give a day’s pay to fund opposition to Sinclair. MGM’s Irving Thalberg pioneered the use of fake newsreels, hiring actors to pose as shabby vagrants or foreign radicals backing Sinclair. Newspapers across the state branded Sinclair an atheist and a Bolshevik. Even Franklin Roosevelt kept his distance. Republican Governor Frank Merriam won the election with about 49 percent to Sinclair’s 38. A third-party candidate, Raymond Haight, took the other 13 percent. Sinclair’s opponents had written the playbook for the modern negative media campaign.
Ironically, these agencies are now training bank supervisors to evaluate AI risk within banks.




I see “liability” and think Factory Mutual.
The interesting question isn’t just who pays when the AI burns the factory down. It’s whether liability can create an economic mechanism for discovering which things actually make the factory less likely to burn down in the first place.