Argument architecture

How this editorial can be challenged

Core question

Who can turn an AI safety finding into a legitimate, enforceable decision when the model, developer, affected public, and regulator sit in different jurisdictions?

Proposed mechanism

Frontier developers generate most safety evidence, private assessors receive negotiated access, national regulators retain legal authority, and international bodies seek common rules. Because those four functions are separated, a serious finding can lose force at every handoff: scope can be narrowed, evidence can be redacted, publication can be delayed, and a regulator elsewhere may lack jurisdiction. The result is an accountability gap between seeing a risk and stopping it.

Strongest counterargument

National governments are accountable to their own citizens and can already use product safety, cybersecurity, competition, consumer-protection, and liability law. A global AI authority could be slow, politically captured, or used to freeze the advantage of dominant states and companies.

Our response

A single global licensor is neither necessary nor presently realistic. The narrower requirement is interoperability: common incident categories, minimum assessor access, protected evidence channels, and reciprocal recognition of urgent findings, while elected governments retain the power to choose remedies. Sovereignty can govern the consequence without making the underlying evidence stop at the border.

Evidence limits

Today's speeches, poll, voluntary banking principles, and assessment proposal do not demonstrate that international oversight would reduce harm or that national enforcement will fail. The public-opinion evidence covers U.S. adults, the Meta concierge is a reported test rather than a public product, and the new private frameworks have not yet produced a visible deployment decision.

What would change our mind

This argument would weaken if national regimes repeatedly obtained full technical evidence, coordinated remedies across borders, and forced meaningful deployment changes without shared standards, or if third-party assessments reliably published adverse findings and triggered corrective action through private contracts alone.

Two speeches exposed one missing institution

The United States used the UN stage to reject any global scheme of AI control. The UN used the same stage to demand binding cooperation, independent oversight, and a multilateral risk framework. This is not a disagreement about whether harm matters. It is a conflict over jurisdiction: which institution has the legitimacy and power to decide when an AI system has crossed a line.

That distinction matters because frontier systems do not stay inside the authority that built them. A model may be trained in one country, served from infrastructure in another, assessed by a private organization elsewhere, and used against people who have no direct relationship with any of them. National sovereignty remains real, but so does transnational exposure.

The public sees the accountability gap

A Reuters/Ipsos poll of 1,277 U.S. adults found that 73 percent believed AI companies were not doing enough to prevent serious societal harm. Fifty-five percent said slower development would be good for the country, while 13 percent said it would be bad. Those results do not settle policy, and the reported credibility interval was about three percentage points. They do show that corporate assurance has not converted into broad confidence.

The Meta Muse test demonstrates why disclosure is part of control. Reuters reported that human contractors quietly handled some calls presented through a personal AI agent, prompting internal concern about whether participants understood who was on the other end. Meta said the test was intended to gather feedback and that proper disclosure would precede wider rollout. The disputed fact is not whether people can help an AI service. It is whether users can exercise meaningful choice when the system's real operator is obscured.

Independent assessment can still depend on permission

OpenAI's new proposal is substantial. It supports deep access across training, evaluation, and deployment; assessment of safety cases and safeguards; review of capability evaluations; and independent investigation of critical misalignment incidents. It also calls for scientific rigor, conflicts disclosure, security, editorial independence, and findings that distinguish evidence from interpretation.

The institutional tension remains inside the design. Scope would be mutually agreed. Some evidence may be inaccessible. Developers could receive time to remediate before publication. Sensitive findings may go only to a board or other oversight body. Each safeguard can be reasonable, yet together they leave the assessed company with influence over the path from discovery to consequence. Independence is not only who writes the report. It is whether an uncomfortable finding survives the handoffs.

Voluntary principles arrive before agents spend money

Six banks have published shared principles for agentic commerce organized around transparency, safety, privacy and data, choice, and interoperability. They correctly identify identity, authorization, fraud prevention, liability, and customer protection as the hard problems. They also say an implementation blueprint will come later.

This is governance in its most common early form: agreement on nouns before agreement on duties. The economic stakes are growing at the same time. The OECD projects global growth of 2.9 percent in 2026 and 3.0 percent in 2027, while warning that AI investment increasingly depends on external financing and could amplify a correction if expected returns do not arrive. Agents are entering payments while the capital behind AI is becoming more systemically connected.

The strongest objection is sovereignty

A global AI authority could be captured by powerful states, dominated by incumbent laboratories, or slowed by governments that do not share political values. Existing national law already provides tools through liability, consumer protection, cybersecurity obligations, procurement, and market access. A new supranational regulator might create delay without creating knowledge.

That objection rules out a simplistic world licensor, not cross-border evidence. Governments can retain democratic authority over remedies while recognizing a common incident taxonomy, minimum assessor access, protected channels for confidential findings, and an obligation to notify other jurisdictions when a failure can propagate. Sovereignty should decide the remedy. It should not make evidence disappear at customs.

A useful assurance system has four handoffs

First, developers must preserve evidence that an external investigator can reconstruct. Second, assessors need rights that do not vanish when a finding becomes commercially inconvenient. Third, a public authority must be able to impose an interim restriction while the evidence is tested. Fourth, other affected jurisdictions need a channel to receive the finding and decide their own response.

The test is observable. Does an adverse assessment delay a release, narrow a capability, change a contract, trigger a notification, or alter liability? If the answer is consistently no, the growing ecosystem of principles, standards, and audits is producing reputational insulation rather than control.

The decision is between interoperable evidence and isolated promises

Today's sources do not prove that a global regime would work or that national enforcement will fail. They show a repeated structural gap. The organizations with the most evidence do not always have independent incentives. The institutions with legal authority may lack technical access. The bodies seeking common rules may lack enforcement. Public skepticism grows in the space between them.

The practical choice is not global government or no governance. It is whether safety evidence becomes portable enough to meet legitimate authority wherever the risk lands. Keep remedies sovereign if that is the political requirement. But make the facts interoperable, the assessor rights durable, and the consequence visible. Otherwise every new promise will end at the same border as the last one.

Evidence behind the argument

Read the reporting

Opinion is ours. The factual record is linked below.

White House — United States rejects global AI control at the UN United Nations — Four tests of power and binding AI cooperation Reuters — U.S. public attitudes toward AI safeguards Reuters — Meta's human concierge test for Muse Bank of America — Shared principles for trusted agentic commerce OpenAI — Priorities and principles for third-party assessments