AI Regulatory Design
When the legislature handed Secretary Robert Asante the job of writing his state's first rules for how private companies could use AI in hiring, lending, and tenant screening, he assumed the hard part was the technology. It was not. The moment he drafted a rule specific enough to bite, the technology shifted underneath it, and the moment he drafted a rule broad enough to last, it was too vague to enforce. His first attempt banned "automated decision systems that produce discriminatory outcomes." A year later no enforcement action had been brought, because nobody, not the regulated companies and not his own staff, could agree on what those words meant. He had written a rule that felt strong and did nothing.
That is the central tension of AI regulatory design. You are aiming a slow instrument, law, at a fast target, technology, without freezing innovation or leaving people unprotected. This lesson treats regulation as a design exercise rather than a statement of intent. Good design requires a clear problem definition, an actual grant of authority, an administrative process you can survive, and an accountability architecture that someone can operate. Bad design produces rules that are litigated, disapproved, or quietly ignored, and the difference is usually visible within months of adoption.
The regulator's dilemma and the two failure modes
Every AI rule fails in one of two directions. Regulate too early or too rigidly and you ban approaches that turn out to be safe, push companies and talent elsewhere, and lock in yesterday's technology. Regulate too late or too loosely and people are harmed, denied loans, screened out of housing, misjudged by a model, before the law catches up. This is the pacing problem: technology runs and law walks. Robert's banned-discrimination rule failed the second way. A rule mandating one specific, soon obsolete fairness algorithm would have failed the first, and both failures are expensive.
The way out is not to pick a speed. It is to regulate the outcome and the obligation rather than the technology. A durable rule says what must be true, that the system must not discriminate and that the deployer must be able to show it looked, and who bears the duty, while staying silent on which technique achieves it. Outcomes age slowly and techniques age fast. That single choice is what lets a rule written this year still mean something against a model architecture nobody has built yet.
Authority comes before instrument
Before a leader argues about substance, the design question is which instrument is available and under what authority. In the United States, Congress enacts authorizing statutes that delegate detailed rulemaking to executive-branch agencies with sector expertise. Agencies then issue most binding rules through notice-and-comment rulemaking under the Administrative Procedure Act, at 5 U.S.C. 551 and following, with the rulemaking process itself set out at section 553. A rule issued without statutory authority is not a strong rule that lost in court later. It is a rule that was never available to you.
The process imposes its own discipline. Under the reasoned decision-making standard associated with Motor Vehicle Manufacturers Association versus State Farm, an agency must consider the relevant factors, avoid clear errors of judgment, explain the rule it chose, and respond to significant comments it received. Executive Order 12866 routes significant regulatory actions through centralized review by the Office of Information and Regulatory Affairs at the Office of Management and Budget, with heavier analysis for the economically significant category. The Unified Agenda and Regulatory Plan make the pipeline visible to everyone who intends to fight you.
Three further constraints shape what is realistic. The Regulatory Flexibility Act requires analysis of effects on small entities, which is exactly where an AI compliance obligation lands hardest. The Paperwork Reduction Act governs the information collections your rule creates, and an impact-assessment filing requirement is an information collection. The Congressional Review Act lets Congress disapprove a recently promulgated rule by joint resolution under fast-track procedures. For most rules that is not a live threat, but it is a design discipline: a rule that stretches its authority or lacks political support carries disapproval risk you should price in early.
Executive policy is not the same lever as a rule
Leaders routinely confuse two instruments that look similar and behave differently. Executive-branch policy instruments direct how agencies themselves buy, build, and govern AI without going through rulemaking. Executive Order 14110 on the safe, secure, and trustworthy development and use of artificial intelligence, and OMB Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Agencies' Use of Artificial Intelligence, issued in 2024, are the leading recent examples. Both were addressed to the executive branch. Neither is a substitute for a rule that reaches a private company.
The limits matter in both directions. Executive policy moves fast, needs no comment period, and can be revised or withdrawn by a later administration just as fast, which is why durable change in the private economy still runs through sector rulemaking or through legislation. Because executive instruments turn over with administrations, confirm the current status of any executive order or memorandum before you build a compliance argument on it. Both instruments above are stated here historically, as examples of the form, not as a claim about what is in force on the day you read this.
Risk-based tiering: not all AI deserves the same rule
The most consequential design choice is to match the weight of the rule to the weight of the risk. A model that recommends which park to mow first does not deserve the scrutiny you apply to a model that informs a bail decision. Both the European Union's AI Act and United States federal practice organize around this idea, sorting uses by how much they can hurt people and applying heavier obligations only near the top. Robert rebuilt his framework around the four tiers below, adopting the vocabulary his legislature would recognize.
| Tier | Definition | Example use | Obligation |
|---|---|---|---|
| Prohibited | Unacceptable harm | Social scoring of residents | Banned outright |
| High-risk | Affects rights, safety, access | Hiring, lending, tenant screening | Impact assessment, audit, human appeal, transparency |
| Limited-risk | Interacts with people but lower stakes | Customer service chatbot | Disclosure that it is AI |
| Minimal-risk | Little potential for harm | Inventory forecasting | None beyond existing law |
Tiering addresses the proportionality problem rather than solving it outright. The large majority of AI uses fall in the bottom two tiers and need almost nothing new, which frees a small enforcement staff to concentrate on the tier where real harm lives. It also answers the innovation objection directly, because a startup building inventory software faces no new burden at all. The federal vocabulary in M-24-10 runs in parallel rather than identically, distinguishing general uses from rights-impacting and safety-impacting ones without a centralized classification authority behind it.
The sector-regulator map you are actually drafting into
The United States chose a sector-based, delegated-rulemaking approach rather than one comprehensive AI statute, and that choice is not an accident. It follows the constitutional architecture and long practice: expert agencies write detailed rules under their own authorizing statutes, OMB reviews the significant ones, courts review for arbitrary and capricious error, Congress retains disapproval and appropriations leverage, and states operate in parallel under their own authorities. The result is expertise-driven but uneven, slower than a single statute, and better covered in mature sectors than in the gaps between them.
Any rule you draft lands somewhere on this map, usually next to a regulator that got there first. Finance is covered by the Securities and Exchange Commission, the Consumer Financial Protection Bureau, the Federal Trade Commission, the Office of the Comptroller of the Currency and the prudential regulators. Health runs through the Food and Drug Administration, the Department of Health and Human Services Office for Civil Rights, and the Centers for Medicare and Medicaid Services. Employment sits with the Equal Employment Opportunity Commission and the Department of Labor, transportation with the Federal Aviation Administration and the National Highway Traffic Safety Administration, communications with the Federal Communications Commission, and education with the Department of Education.
The substance those regulators have already produced is your best available precedent. The Food and Drug Administration has issued guidance on software as a medical device and on predetermined change control plans, which address the specific problem of a device that keeps learning after clearance, and it runs a Digital Health Center of Excellence. The Securities and Exchange Commission has issued staff statements on AI use by investment advisers and broker-dealers. The Consumer Financial Protection Bureau, in Circular 2023-03, addressed adverse-action notices under the Equal Credit Opportunity Act, clarifying that a notice must be specific enough to be useful even when a complex algorithm produced the decision.
The pattern continues across the map. The Federal Trade Commission has emphasized that its unfair and deceptive acts and practices authority applies fully to AI claims and AI conduct, which reaches marketing exaggeration as readily as it reaches the model. The Federal Aviation Administration works through its airworthiness and certification framework, and the National Highway Traffic Safety Administration through voluntary guidance and its standing general order for automated vehicles. The Equal Employment Opportunity Commission has issued guidance on algorithmic selection procedures, the Department of Labor on AI in workplace contexts, and the Department of Health and Human Services applies Section 1557 and Section 504 obligations to AI-informed health decisions.
The state layer moves faster than you do
States reach specific harms years before the federal system does, and a leader drafting at either level has to account for the other. Illinois enacted the Artificial Intelligence Video Interview Act, which imposes notice and retention requirements on employers using AI video analysis. Colorado's AI Act, Senate Bill 24-205, addresses consequential decisions by both developers and deployers. New York City's Local Law 144 requires bias audits for automated employment decision tools. Several other states have proposals in various stages, and effective dates in this area move, so confirm the current status of any state instrument before you rely on it.
Enforcement at the state level does not wait for new statutes either. State attorneys general have reached AI conduct using long-standing unfair and deceptive practices statutes and existing civil-rights law, neither of which mentions AI and both of which apply anyway. That is a useful reminder for any drafter: the question is rarely whether conduct is regulated, but which existing authority already covers it. The cost of this layered system is fragmentation, which creates real compliance complexity for interstate actors and generates recurring pressure for federal preemption or harmonization that a leader in Robert's chair will be asked to take a position on.
Comparative frameworks: reference, not template
The European Union's AI Act entered into force in 2024 with phased application and adopts a formal risk-based architecture: unacceptable risk is prohibited, high risk triggers conformity assessment and continuing obligations, limited risk triggers transparency duties, and minimal risk is largely unregulated. Providers and deployers of high-risk systems face obligations on risk management, data governance, transparency, human oversight, accuracy, robustness, and cybersecurity, with conformity assessment tied to notified bodies and technical documentation. It also interacts with the General Data Protection Regulation rather than replacing it.
For a United States regulator the EU Act is a reference to understand, not a template to copy, because the enforcement architecture that carries it does not exist here. What is striking is the convergence on substance without convergence on structure. Many American sector regulators are arriving at the same substantive requirements, risk management, data governance, transparency, oversight, accuracy and security, through their own authorizing statutes and without any centralized classification body. Copying the EU's classification scheme into a system that lacks its institutions produces a rule with no one to run it.
The wider international layer is worth knowing because stakeholders will cite it at you. The Council of Europe Framework Convention on artificial intelligence, the OECD AI Principles, the G7 Hiroshima AI process, and the Bletchley Declaration and the summits that followed it all shape expectations and vocabulary. None of them is a binding rule in your jurisdiction. The OECD principles in particular are non-binding commitments, and treating a non-binding instrument as a legal requirement in a preamble is an unforced error that opponents will find. Cite them for what they are: evidence of an emerging international baseline.
Adaptive regulation: rules that can be wrong cheaply
Even a well-tiered rule ages. Adaptive regulation builds in mechanisms to update without a full legislative do-over each time, and three tools do most of the work. Each of them buys flexibility at a cost you should name openly, because the flexibility is what critics will attack. Good AI regulation does not predict the future. It builds in the ability to be wrong cheaply and to correct quickly, which is a design property rather than a slogan.
- Regulatory sandboxes. A supervised space where firms test novel AI under temporary, relaxed conditions while the regulator observes. The United Kingdom's financial regulator pioneered the form. A sandbox produces observation of real behavior before you write permanent rules; it does not produce a safety finding, and nothing that leaves a sandbox has been certified as safe by anyone.
- Delegated standards. The law states the obligation, that high-risk systems must be assessed for bias, and delegates the technical method to an updatable standard maintained by your agency or by a body such as the National Institute of Standards and Technology, whose AI Risk Management Framework is voluntary and non-binding unless a rule or a contract makes it a requirement. You revise the standard as the field moves without reopening the statute.
- Sunset and review clauses. The rule expires or must be formally re-justified after a set period, which forces a deliberate look at whether it still fits. Periodic review provisions are the cheapest protection against a rule that quietly stops matching the technology it governs.
Impact assessment as the enforcement engine
For the high-risk tier, the workhorse obligation is the algorithmic impact assessment: a required document in which the deployer states what the system does, who it affects, how it was tested for disparate error rates, what those rates are across groups, and how a person can contest a decision. Federal practice has required something similar of agencies themselves for rights-affecting uses. Requiring it of regulated firms does three things at once. It forces someone to look before deployment, it creates the paper trail an enforcer needs, and it gives the public a specific document to point at.
Be precise about what the document proves. A filed assessment establishes that the deployer examined the system and made representations about it. It does not establish that the system is fair, and a complete, well-formatted assessment has never once made a discriminatory model lawful. Its enforcement value is that it converts an unprovable claim, that a company was careless, into two provable ones: either the required document does not exist, or it exists and its representations are false. That is precisely the leverage Robert's original vague ban never gave him.
The rulemaking design test
Before drafting any AI rule, a leader should be able to answer each of the questions below. A blank answer is a warning, not a detail to fill in later. The first several come from the standard rulemaking design test and go to whether the rule survives contact with a court; the rest go to whether it survives contact with reality.
- Rationale. Is there a market failure or a clear public-interest reason for intervening? Without one, the rule is likely unjustified, and saying so early is cheaper than hearing it later.
- Authority. Which statute authorizes this rule? Rules without authority are vulnerable on review, whatever their merits.
- Proportionality. Is the obligation matched to the harm and to the risk tier? Over-broad rules chill legitimate use; under-inclusive rules leave the harm in place.
- Scope. Is the covered conduct clearly defined? Ambiguous scope invites litigation and inconsistent application, which is exactly how Robert's first rule died.
- Costs and benefits. What are they, and who bears them? Significant rules face centralized review, and small entities get their own analysis.
- Enforcement. How will this be enforced, by whom, using what evidence? Paper obligations without enforcement produce paper compliance.
- Review. How and when will the rule be revisited? Sunset and review provisions are what prevent obsolescence.
- Outcome not technique. Does the rule state what must be true and leave the method to an updatable standard?
- Accountable party. Who exactly bears the obligation, the developer, the deployer, or both, and can an enforcer tell which?
- Appeal. How does an affected person learn a decision was automated, and how do they contest it?
Designing backward from the enforcement you have
The most common failure in AI regulatory design is writing rules your agency cannot enforce. A sophisticated high-risk regime is worthless if you have three staff and none of them can read a model audit. So design backward from capacity. Robert phases his rollout, taking the prohibited-use and disclosure rules first because they are cheap to enforce, then bringing the high-risk impact-assessment requirement into force once he has hired technical auditors. Sequencing is a legitimate design tool, not an admission of weakness, and it is easier to defend than a regime that collapses on first contact.
Third-party audits extend reach without extending payroll, by requiring regulated firms to obtain independent assessments your staff then spot-checks. That leverage is real but it is not free: an independent audit is only as good as the auditor's competence and independence, and a regime that never verifies its verifiers has simply moved the trust problem one step away from itself. Build in the ability to review auditors, and be honest with your legislature about the enforcement capacity a new regime requires, before rather than after you promise the protection.
Communicating and defending the rule
Regulatory design does not end at the drafting table. Leaders brief members of Congress and their staff, engage the regulated community early, coordinate with the other agencies whose authority touches the same conduct, and respect legislative prerogatives on major rules. Good-faith engagement produces better rules and fewer surprises; bad-faith engagement is expensive, because the people you dismissed during drafting become the people funding the litigation. Anticipating disapproval risk under the Congressional Review Act is part of the same discipline, not a separate political exercise.
Robert learned the communication lesson the same way he learned the drafting one. His first rule was announced rather than negotiated, and the trade associations who could have told him which definitions were unworkable found out when the press did. His second attempt used a public comment process seriously, published the tiering logic in plain language, and named which obligations would phase in with which enforcement hires. The rule that resulted was narrower than his first draft and enormously more effective, because it described conduct that a company could actually recognize as its own.
Anti-Patterns to Avoid
- The rule that feels strong and does nothing. Prohibiting "discriminatory automated decision systems" reads well in a press release and gives an enforcer nothing to prove. If you cannot describe the document, test, or record that establishes a breach, you have written a statement of values, not a rule.
- Regulating the technique. Mandating a named fairness algorithm or model architecture writes an expiration date into your statute and forces a legislative reopening every time the field moves. Regulate what must be true and delegate how.
- Treating the sandbox as a safety certificate. Firms will describe a sandbox exit as regulatory clearance and some of your own staff will start to believe it. A sandbox is a controlled observation, not a finding. Say in the authorizing text that participation confers no approval and no defense.
- The assessment as absolution. A filed impact assessment proves a document exists, not that a system is fair. When a complete filing starts functioning as a shield in your own enforcement conversations, the obligation has inverted and you are now regulating paperwork.
- Skipping the authority question. Substance arguments are more interesting than jurisdiction, which is exactly why teams spend months on the former and discover the latter in litigation. Locate the statute before the substance debate starts.
- Importing an architecture without its institutions. Copying a foreign classification scheme without the enforcement body, technical documentation regime, and assessment infrastructure that carries it produces a rule with no one to operate it.
- Promising protection you cannot staff. A regime that requires audits nobody in the agency can read is theater, and the public learns it is theater at the worst possible moment. Phase to capacity and say so publicly.
- Citing a non-binding instrument as a requirement. International principles and voluntary frameworks describe an emerging baseline. Presenting one as a legal obligation in a preamble hands opponents an easy attack on the whole rule.
Practice Prompts
- Two-directional failure audit. Take a draft AI rule from your jurisdiction and write two paragraphs: one describing the legitimate activity it would chill if it is too rigid, and one describing the harm it would fail to reach if it is too loose. If either paragraph is hard to write, you do not yet understand your own rule.
- Authority trace. For a rule you want to issue, write the chain from the authorizing statute to the specific obligation, in plain sentences. Mark every link where you are relying on an argument rather than on text, and get a lawyer to price each one.
- Tier your own portfolio. List the AI uses currently operating in your sector and assign each to a risk tier with a one-sentence justification. Note which assignments were contested internally, because those are the definitions your rule will litigate.
- Enforcement dry run. Pick a hypothetical violating company and script how your staff would prove the violation: which document is demanded, which test is run, who reads the result. If the script needs skills you do not have, you have found your phasing plan.
- Design test on a real draft. Run the design-test questions above against an actual proposed rule, yours or another jurisdiction's, and write the blank answers on a single page. Bring that page to your next drafting meeting instead of the full text.
Reflection
Think about the last rule your organization issued or advised on that touched automated decisions. Which of the two failure modes was it closer to, and who inside your process was arguing for the other side? Consider whether the obligations you imposed were matched to the risk tier of the covered uses or applied uniformly because uniformity was easier to draft. Ask yourself honestly what evidence an enforcer would need to bring a case under it, whether your agency can obtain that evidence today, and if not, what you told the public about the protection you had created.
Glossary
- Pacing problem. The structural mismatch between the speed at which technology changes and the speed at which law can be written, reviewed, and amended.
- Notice-and-comment rulemaking. The Administrative Procedure Act process by which an agency proposes a rule, takes public comment, and issues a final rule with responses to significant comments.
- Reasoned decision-making. The standard requiring an agency to consider relevant factors, avoid clear errors of judgment, and explain the rule it adopted, associated with the State Farm decision.
- Significant regulatory action. The category of rule that triggers centralized executive review, with additional analysis required for economically significant actions.
- Congressional Review Act. The mechanism allowing Congress to disapprove a recently issued rule by joint resolution under fast-track procedures.
- Risk tier. A classification of an AI use by its potential to harm people, used to set the weight of the obligations that attach to it.
- Conformity assessment. A procedure for demonstrating that a system meets specified requirements before it is placed on a market, used in the European risk-based architecture.
- Algorithmic impact assessment. A required document in which a deployer states what a system does, who it affects, how it was tested, and how a decision can be contested.
- Regulatory sandbox. A supervised arrangement in which firms test novel products under temporary, relaxed conditions while the regulator observes. It confers observation, not approval.
- Delegated standard. A technical specification maintained outside the statute that supplies the method for meeting an obligation the statute states in general terms.
- Preemption. The displacement of state law by federal law, a recurring question wherever states regulate faster than the federal system.
Related Lessons
- Legislative Framework Development covers the statutory side of this work, for the cases where no existing authority reaches the conduct you need to regulate.
- Multi-Level Government AI Governance takes up the federal, state, and local layering that makes fragmentation and preemption live questions for any drafter.
- AI Policy Monitoring and Enforcement continues from the point where a rule exists and someone has to detect violations and act on them.
- OMB M-24-10 Deep Dive: Full Implementation works through the executive-branch instrument in detail, including how its obligations differ from a rule that binds private parties.
- International Standards: EU AI Act and OECD goes further into the comparative frameworks summarized here and what they do and do not require.
- AI Sandbox and Experimentation Frameworks covers the design and supervision of sandboxes as an adaptive-regulation tool.
- AI Policy Impact Assessment examines how to evaluate whether a policy achieved what it claimed once it is in force.
Closing
Robert's second rule was shorter than his first, more specific about who owed what, and considerably less satisfying to announce. It named the harms, sorted uses into tiers, required an assessment document for the tier where people get hurt, guaranteed notice and a path to contest, delegated the technical method to a standard he could update, and phased its hardest obligation to arrive with the auditors who would enforce it. None of that is dramatic. It is what the difference between a rule that works and a rule that decorates the statute book usually looks like, and it is available to anyone willing to design rather than declare.
Key Takeaways
- Regulate outcomes and obligations, not techniques. Specifying what must be true survives technology change; specifying a method becomes obsolete and unenforceable.
- Find the authority before you argue the substance. A rule without a statute behind it is not a strong rule that lost later, it is a rule you never had.
- Executive policy and rulemaking are different levers. Executive orders and OMB memoranda direct agencies, move fast, and can be withdrawn just as fast; durable obligations on private parties run through rules or legislation.
- Tier by risk. Sort uses into prohibited, high, limited, and minimal risk and concentrate heavy obligations where real harm lives, which also answers the innovation objection honestly.
- Know the sector map you are drafting into. A regulator with existing authority has usually reached the conduct already, and its guidance is your best available precedent.
- Build in adaptation. Sandboxes, delegated standards, and sunset clauses let rules update without reopening the statute, provided you never describe a sandbox exit as an approval.
- Make impact assessment the engine, and be precise about what it proves. It converts carelessness into a provable claim about a document; it does not establish that a system is fair.
- Design backward from enforcement capacity. Phase obligations to arrive with the staff who can enforce them, use independent audits to extend reach, and verify the verifiers.
- Treat international instruments as reference, not requirement. Comparative frameworks shape expectations and vocabulary; citing a non-binding instrument as binding weakens the whole rule.
Frequently Asked Questions
Is a comprehensive AI statute better than the sector approach? Each buys something different. A single statute gives uniform coverage and a clear classification architecture but moves slowly and centralizes judgment away from people who understand a sector. The sector approach gives you expert regulators applying mature authorities, at the cost of uneven coverage and gaps between sectors. The practical answer for a leader is that you inherit whichever system you work in, so design for its actual failure mode rather than for the one you would prefer to have.
Can we simply adopt the European risk tiers? You can adopt the vocabulary, and many jurisdictions have, but the architecture depends on institutions that may not exist in your system: a centralized classification authority, conformity assessment bodies, and a technical documentation regime. Borrowing the tiers without those institutions produces categories nobody administers. Borrow the design logic, that obligations should scale with potential harm, and then build the classification and enforcement machinery your own authority actually supports.
Do regulatory sandboxes weaken protection? They can, if they are described dishonestly. A sandbox trades temporary relaxation of specific conditions for supervision and visibility, which is a reasonable exchange when you genuinely do not yet know how a technology behaves. It becomes a loophole when participation is treated as approval, when the relaxed conditions are never restored, or when the observations never turn into rules. Write the exit conditions and the no-approval language into the authorizing text at the start.
What should a rule require for a person affected by an automated decision? At minimum, that the person can learn an automated system was involved, can get a plain-language account of what it did, and has a usable path to contest the outcome that does not require a lawyer or an unreasonable wait. Notice and contestability are what make the rest of the regime real to the person it exists to protect, and they are also the obligations most likely to be quietly weakened during drafting negotiations.
How do we keep a rule from going obsolete quickly? State obligations as outcomes, delegate technical methods to a standard you can revise without reopening the statute, and attach a review or sunset provision that forces a deliberate look. None of that prevents obsolescence; it lowers the cost of correcting it. The goal is not a rule that is right forever but a rule that can be wrong cheaply and fixed quickly, which is a different and much more achievable design target.
How much should we worry about disapproval or litigation risk? Enough to change your process, not enough to stop you. Rules that stay within clear statutory authority, respond seriously to significant comments, and carry defensible cost analysis are the ones that survive review. Engaging the regulated community and legislators during drafting rather than after publication is the single cheapest risk reduction available, and it usually improves the rule on the merits at the same time.
Skill.re