AI Policy Wiki
Dashboard

Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation

high confidence · updated 2026-06-06

The three-mode analytical frame for comparing AI-governance approaches across jurisdictions, popularized in G'sell's 'Regulating Under Uncertainty' report and used in cross-country comparisons.

A three-mode analytical framework for classifying how jurisdictions govern AI, or any emerging technology, used in comparative regulatory scholarship. It distinguishes self-regulation, co-regulation, and traditional government regulation. In the AI-governance context it was popularized by Florence G'sell's 2024 Stanford report, and it is compatible with Bradford's three-empires frame while operating at a different level of abstraction.

The three modes

Self-regulation

Under self-regulation, firms within the industry adhere to rules or principles they develop themselves. There is no binding legal framework; oversight, where it exists, is voluntary and internal.

Jurisdiction-level examples include the US before EO 14110 (the Biden administration's voluntary commitments of July and September 2023); the UK's "pro-innovation" or wait-and-see stance, though the UK has an AI Safety Institute; and Israel's tech-promotion posture. Industry instances include Responsible Scaling Policies (Anthropic, OpenAI's Preparedness Framework, Google DeepMind's Frontier Safety Framework, Meta's Frontier AI Framework) and coordination through the Frontier Model Forum.

G'sell characterizes self-regulation as fast, responsive to technical reality, informed by industry expertise, and compatible with innovation. The drawbacks she identifies are that it is voluntary, with no enforcement against firms that defect; that commercial incentives conflict with safety; and that practices are asymmetric across firms. G'sell adds that industry safety work is "not always driven by a desire to prioritize a responsible or ethical approach" (G'sell, Ch. 4), noting that red teaming and RLHF primarily advance model quality rather than safety per se.

Co-regulation

Under co-regulation, regulators and state agencies collaborate with private actors to develop and implement standards and best practices. The government sets objectives but delegates rule-making, and often enforcement, to industry-government working groups.

Examples include the EU AI Act's Code of Practice mechanism and standards development, with the EU AI Office working with AI firms and independent experts on the GPAI Code of Practice; Singapore's Model AI Governance Framework; Saudi Arabia's AI Ethics Principles; and Canada's Voluntary Code of Conduct on Advanced Generative AI Systems, which preceded AIDA's full effect. In the US, NIST's AI RMF is a co-regulatory instrument: non-binding, and developed through joint government-industry-civil-society collaboration.

G'sell describes co-regulation as combining state legitimacy with industry expertise, adapting faster than pure legislation, and able to specify technical details legislators cannot. The limitations she identifies are the risk of regulatory capture, uneven application across firms with different resources, and a lack of democratic accountability for technical standards.

Traditional government regulation

Under traditional government regulation, the government enacts binding laws or legal frameworks. Compliance is legally required, and enforcement uses administrative or judicial mechanisms.

Examples include the EU AI Act (risk-based and binding), Chinese AI regulations (command-and-control), the Colorado AI Act, California SB 53, and Brazil's pending AI Act.

G'sell describes this mode as binding, enforceable, democratically legitimate, and applying equal treatment across firms. Its limitations are that it is slow to update, risks ossifying rules for a fast-moving technology, and requires regulators to have technical expertise they often lack. She concludes that "legislation alone cannot adequately specify rules in advance to govern AI development and applications, even in the near future" (G'sell, Ch. 7).

Jurisdictions on the spectrum

Jurisdictions can be arrayed from self-regulation through co-regulation to traditional regulation:

Self-regulation  ←————————————  Co-regulation  ————————————→  Traditional regulation
     UK (pre-2025)                 EU (AI Act + Codes)                     China
     US (pre-EO 14110)             Singapore (MGF)                   EU (high-risk)
     Israel                        Canada (Voluntary Code)           Brazil (pending)
     UAE                           Japan (shifting rightward)    Korea (AI Basic Act)

G'sell observes that most jurisdictions in practice mix all three modes: "in practice, they are often mixed." The US combines self-regulation, co-regulation through NIST, and traditional regulation through state laws, sectoral federal laws, and now EO 14365's preemption. The EU combines co-regulation through its Codes of Practice within a traditional-regulation shell, the AI Act. China's command-and-control model still coexists with industry ethics committees.

Soft-law to binding-law drift

G'sell documents that jurisdictions initially favoring self- or co-regulation are gradually moving toward binding frameworks, particularly for high-risk or frontier AI. Japan began with non-binding guidelines and is now considering a binding framework for large-scale foundation models (Japan AI Promotion Act — Source Summary). South Korea moved from voluntary strategies and ethics standards to its enacted AI Basic Act. At the US state level, voluntary commitments judged insufficient gave way to California SB 53, the Colorado AI Act, Texas TRAIGA, Virginia HB 2094, and others. Brazil and India are drafting risk-based comprehensive laws explicitly modeled on the EU approach.

G'sell attributes the drift to the limits of voluntary self-regulation when firms defect, public demand for accountability, and the Brussels Effect — the EU AI Act becoming a de facto template.

Relationship to Bradford's three-empires frame

Anu Bradford's three-empires model (US market-driven, EU rights-driven, China state-driven) and G'sell's regulatory typology are compatible but operate at different levels. Bradford's model frames the political economy: what interests a jurisdiction's regulatory model serves. G'sell's typology frames the institutional mode: how the jurisdiction operationalizes regulation.

The two align reasonably well, with US market-driven approximating a self-regulation lean, EU rights-driven approximating co-regulation plus traditional regulation, and China state-driven approximating traditional command-and-control regulation. The typology adds granularity that Bradford's model flattens: it distinguishes the EU's co-regulatory approach from pure command-and-control, and it captures the soft-law to binding-law drift across the middle of the spectrum.

Application

When a source covers AI regulation in a specific jurisdiction, the frame can classify the jurisdiction's posture at the source date and place it against the modes above. It also helps identify which jurisdiction's experience is most relevant to a given policy proposal: a traditional-regulation proposal has different lessons from China than from the EU, and a co-regulation proposal has different lessons from Singapore than from Canada.

Relationships