Why AI regulation is already obsolete before it's written
Every parliament on earth is racing to regulate AI. The problem isn't the urgency — it's that legislation is the wrong instrument entirely.
Every major parliament on earth is currently racing to regulate artificial intelligence. The European Union has its AI Act. The United States Congress is drafting frameworks. Australia's ministers have announced consultations and formed taskforces. The energy is genuine, the concern legitimate, and the legislative process entirely the wrong tool for the job.
Parliament runs on years; AI runs on months
The core problem is not that governments lack the will to act. It is a structural mismatch between two clocks running at entirely different speeds. Parliaments operate on cycles of years. AI development operates on cycles of months. The last time the United States Congress passed major technology regulation was 1996, when most Americans were still connecting to the internet through a telephone line. The technology transformed beyond recognition multiple times in the three decades that followed. The law, for practical purposes, did not. There is no obvious reason to expect the next attempt will be different.
Australia faces the same constraint. The parliamentary process that produces legislation, consultation periods, committee hearings, amendments, Senate crossbenchers, and eventual royal assent, is not designed for speed. It is designed for deliberation and accountability, which are genuine virtues. But those virtues come at a cost when the subject matter is evolving faster than the deliberation can conclude.
The instinct to legislate is understandable. There are real harms to address. Algorithmic bias in lending decisions, liability for autonomous systems, deepfake-enabled fraud, surveillance tools that outpace civil liberties protections. These are not invented concerns. But the relevant question is not whether to address them; it is whether a dedicated AI statute is the right instrument.
Most AI harms already have a legal home
In many cases, the problem already has a legal home. A bank using an AI model to decide who gets a loan is already subject to responsible lending obligations, anti-discrimination law, and APRA oversight. The algorithm does not create a legal vacuum; it introduces a new mechanism inside an existing framework. The regulatory task is to make sure that framework is applied to the new mechanism, not to write a new framework from scratch. This is a harder enforcement problem than a drafting problem, and more legislation does not solve it.
Where genuinely new powers are needed, the more agile instrument is the independent agency. Pharmaceuticals, aviation, financial services, and telecommunications are all regulated not primarily through Acts of Parliament but through expert agencies empowered to set and revise technical standards as conditions change. The Therapeutic Goods Administration does not wait for parliament to amend the Therapeutic Goods Act every time a new drug class emerges. ASIC does not ask a Senate committee whether a new financial product category needs a licence condition. These agencies operate within a legislative mandate, but they update the substance of regulation continuously. Parliament sets the boundaries; the agency manages what happens inside them.
Agency capture is a real risk, not a hypothetical
There is a governance risk in the agency model, and it is worth naming honestly. Regulatory agencies can be captured by the industries they oversee. Allowing companies to write the rules that govern their own behaviour is precisely how the social media era went sideways, as Senator Richard Blumenthal put it when warning the US Congress not to repeat the same mistake with AI. An agency empowered to regulate AI needs structural independence, genuine expertise, and transparency obligations strong enough to resist that pressure. None of that is automatic.
A fixed technical standard written into law today will be calibrated to the systems that exist today. In five years those definitions will be simultaneously over-inclusive in some dimensions and entirely silent on risks that do not yet exist.
But the alternative, leaving the field to slow-moving legislation, is not neutral. It is a choice with consequences. A fixed technical standard written into law today, defining, say, what counts as a "high-risk" AI system, will be calibrated to the systems that exist today. In five years those definitions will be simultaneously over-inclusive in some dimensions and entirely silent on risks that do not yet exist. The EU's AI Act, for all its ambition, may well face exactly this problem before its enforcement mechanisms are fully operational.
No single tool is sufficient — but legislation is the least sufficient
The more honest frame is that no single governance tool is sufficient. Existing sectoral regulation, properly enforced, handles most of what is already happening. An independent agency, modelled on what works in pharmaceuticals or finance, handles the pace problem that parliament cannot. International coordination handles the jurisdictional problem that neither can solve alone. And legislation, used sparingly, sets the mandate that gives all of it authority.
The governments currently racing to write AI legislation are not wrong to be worried. They are wrong about the instrument. Writing a comprehensive AI statute is the kind of response that looks decisive at a press conference and arrives, gilt-edged and already outdated, to a technology that has long since moved on.
Sources
Time — What an American Approach to AI Regulation Should Look Like
Brookings Institution — The three challenges of AI regulation
Harvard Law Review — Co-Governance and the Future of AI Regulation
UK Parliament Lords Library — Artificial intelligence: Development, risks and regulation
YouTube — How (Not) To Regulate AI: Challenges and Opportunities
Frequently Asked Questions
Why is AI regulation so hard to get right?
The core problem is a speed mismatch: parliaments work on cycles of years while AI development moves on cycles of months. By the time legislation passes, the technology it was written to govern has already changed substantially, leaving rules either over-broad or blind to new risks.
Does Australia already have laws that cover AI harms?
For most current AI applications, yes. A bank using AI in lending decisions is already subject to responsible lending obligations, anti-discrimination law, and APRA oversight. The regulatory gap is largely an enforcement problem — applying existing frameworks to new mechanisms — not a drafting problem requiring new statutes.
What is the alternative to dedicated AI legislation?
The most durable model combines sector-by-sector enforcement of existing law with independent expert agencies empowered to update technical standards continuously — similar to how the TGA regulates pharmaceuticals or ASIC regulates financial products. Parliament sets the mandate; the agency manages what happens inside it.
What is wrong with the EU's AI Act as a model?
A statute that hard-codes definitions — such as what counts as a 'high-risk' AI system — is calibrated to the technology that existed when it was drafted. Within a few years those definitions risk being simultaneously over-inclusive in some areas and entirely silent on risks that did not yet exist when the law was written.
Can independent regulators be trusted to oversee AI without being captured by industry?
Capture is a genuine risk and one the agency model does not automatically solve. An AI regulator would need structural independence, deep technical expertise, and strong transparency obligations — none of which emerge by default from simply creating the agency.