AI Policy Wiki
Dashboard

Regulating Under Uncertainty

high confidence · updated 2026-06-06

The epistemic problem at the heart of AI governance: governments must set rules now for a technology whose trajectory, risks, and capabilities they cannot yet fully characterize — and waiting is itself a regulatory choice.

Regulating under uncertainty refers to the epistemic problem in AI governance whereby governments must design binding rules for a technology whose capabilities, deployment patterns, and long-term impacts are not yet fully understood. Deferring regulation until that uncertainty resolves is itself a substantive regulatory choice carrying its own risks.

The phrase was used and the problem framed comprehensively by G'sell (2024) in the title of her Stanford Cyber Policy Center report. The underlying problem is general across emerging-technology regulation and has been discussed by many other authors under other labels.

The core trade-off

G'sell frames the dilemma facing governments: "If they act aggressively to mitigate all hypothetical risks, they might inhibit the development of the technology. If they act too conservatively at the outset, they might miss the chance to steer the industry toward the safe development of the technology and away from foreseeable harms."

On one end of the trade-off, aggressive early regulation risks stifling innovation and locking in regulatory ossification, but offers better hedging against catastrophic risk. On the other, a wait-and-see posture risks locking in a harmful technological trajectory and regulatory capture by incumbents, but allows policy to be optimized around realized rather than hypothetical harms.

In G'sell's account neither side is established as correct; the trade-off must be made under conditions where neither side can be confidently measured. As she puts it: "Governments cannot wait until they have perfect and complete information before they act, because doing so may be too late."

Why AI amplifies the problem

Emerging-technology regulation always involves uncertainty, but several features of AI compound it:

  1. Capability trajectory unknown. Foundation-model capabilities grow unpredictably with scale, and emergent capabilities surprise developers (see Scaling Laws, Compressed 21st Century).
  2. Deployment patterns unpredictable. GPAI models enable applications their developers did not design for, and sector-specific regulation misses these downstream uses (see General-Purpose AI (GPAI)).
  3. Expertise asymmetry. Detailed technical knowledge resides almost entirely in the private sector, leaving governments without capacity to independently assess claims (see the "enforcement" principle in G'sell Ch. 7).
  4. Irreversibility. Some harms, such as catastrophic misuse of frontier models, loss of human oversight, and widespread infrastructure dependence, may not be recoverable from ex post (see AI Autonomy Risk, Treacherous Turn).
  5. Rapid iteration. Models are replaced faster than legislation can be drafted, negotiated, and implemented. A rule written for GPT-3 may be outdated by GPT-5.

Catalogued responses

Accept the uncertainty; regulate anyway

Minimize the uncertainty first

Build the capacity to regulate later

  • Radical optionality (Winter & Bullock, 2026) is presented as a distinct third answer: neither regulate-now nor wait-and-see, but aggressively building the institutional capacity (information-gathering authorities, whistleblower protections, flexible regulatory definitions, evaluations, lab-security standards, talent) to govern competently once uncertainty resolves, while avoiding substantive overregulation in the interim. The authors explicitly distinguish it from Lindblom-style "muddling through," which preserves flexibility only passively through inaction.

Wait-and-see

  • UK "pro-innovation" posture (pre-2025) relied on existing sector-specific regulators and avoided binding AI-specific legislation.
  • US federal (pre-EO 14110) relied on voluntary commitments and "encouraged self-regulation."
  • Israel and the UAE combined sandboxes with minimal binding rules.

G'sell, and most of the cited sources, express skepticism of pure wait-and-see, on the grounds that delay produces lock-in and cedes norm-setting to jurisdictions that do act (see Brussels Effect).

Pause

  • The FLI March 2023 pause letter proposed halting training of systems more powerful than GPT-4 pending governance mechanisms. It was widely signed but not implemented; G'sell notes it "quickly became clear that a pause was not realistic."
  • The CAIS statement is a shorter, broader statement on extinction-level risks as a priority.

The precautionary-principle debate

A recurring subdebate concerns whether the uncertainty argument favors the precautionary principle (acting to prevent severe harms even without full evidence of their likelihood) or the anti-precautionary principle (declining to regulate speculative harms, given regulation's own costs).

On the precautionary side: the The Coming Wave — Suleyman and Bhaskar (2023) containment framework; the Statement on AI Risk (CAIS); and Bengio's LawZero initiative (see Introducing LawZero (Bengio)). On the anti-precautionary side: Narayanan and Kapoor's "normal technology" frame; pro-innovation camps in the US and UK; and Volokh and other Digitalist Papers essays arguing for user-level rather than developer-level controls.

G'sell's report is agnostic on this debate but operationally favors binding rules over pure self-regulation, placing it closer to the precautionary camp in operational posture while remaining descriptive rather than advocating.

Use of the frame

Positions in AI governance can be read as taking a stance, often implicit, on how to act under uncertainty. Making the frame explicit supports three uses. First, it distinguishes positions by epistemic disposition: a source advocating wait-and-see differs from one advocating binding rules not only in policy prescription but in its underlying disposition toward uncertainty. Second, it helps explain convergence and divergence: jurisdictions that share uncertainty premises, such as soft-law Japan and Singapore, can move faster together than jurisdictions that differ, such as the hands-off US and command-and-control China. Third, it offers a test for new proposals: a regulatory proposal can be assessed not only on whether it works if its risk assumptions are correct, but on how it performs if those assumptions are wrong.

Relationships