"AI as Normal Technology" is an essay by Arvind Narayanan and Sayash Kapoor, published April 15, 2025 by the Knight First Amendment Institute at Columbia University (Source: https://knightcolumbia.org/content/ai-as-normal-technology). It argues that AI should be understood as normal technology — comparable to electricity or the internet — rather than as a separate, potentially superintelligent species, and that its broad societal effects will unfold over decades rather than years. The authors describe the piece as an articulation of a worldview rather than a point-by-point defense of a proposition, and say they intend to elaborate it in follow-up work.
Summary of argument
The essay frames the statement "AI is normal technology" as simultaneously a description of current AI, a prediction about its foreseeable future, and a prescription about how it should be treated. The authors present it not to understate AI's impact — they note that electricity and the internet are also "normal" in their conception — but to reject both utopian and dystopian visions that treat AI as a separate species, a highly autonomous and potentially superintelligent entity. The frame is said to be about the relationship between technology and society: it rejects technological determinism, draws on lessons from past technological revolutions, and emphasizes continuity and the role of institutions in shaping AI's trajectory.
The essay is organized in four parts. Part I argues that transformative economic and societal impacts will be slow, on the timescale of decades. Part II describes a possible division of labor between humans and AI in a world with advanced — but not "superintelligent" — AI. Part III reconsiders AI risks (accidents, arms races, misuse, misalignment, and systemic risks) through the normal-technology lens. Part IV draws out policy implications, centered on reducing uncertainty and building resilience. The authors state they aim to describe a median outcome rather than to quantify probabilities, and that they reject "fast takeoff" scenarios, which is why they decline to forecast beyond the world described in Part II.
Part I: The speed of progress
A central organizing claim distinguishes stages that occur at different timescales. The essay defines invention as the development of new AI methods (such as large language models), innovation as the development of products and applications built on those methods, adoption as the decision by an individual, team, or firm to use a technology, and diffusion as the broader social process by which adoption spreads, which for disruptive technologies requires changes to firms, organizations, social norms, and laws. The argument that AI impact will be slow rests on the innovation–diffusion feedback loop and is said to hold even if progress in methods can be sped up arbitrarily, because the authors locate both benefits and risks primarily in deployment rather than development.
Diffusion in safety-critical areas is slow. Drawing on their earlier paper Against Predictive Optimization, the authors cite a compiled list of roughly 50 predictive-optimization applications (such as criminal risk, insurance risk, and child-maltreatment prediction). In most, decades-old statistical techniques — simple, interpretable regression models with small handcrafted feature sets — are used; random forests are rare and transformers absent. On this evidence AI diffusion lags innovation by decades, largely for safety reasons. They cite Epic's sepsis-prediction tool, which appeared accurate on internal validation but in hospitals missed about two-thirds of sepsis cases and generated many false alerts, in part because a training feature (whether antibiotics had been prescribed) was causally downstream of the outcome and unavailable at deployment. Generative-AI failures including the early Bing "Sydney" chatbot (untested over long conversations) and the Gemini image generator (apparently never tested on historical figures) are offered as further examples of failures not caught in testing. The authors note these speed limits are often enforced by regulation (the FDA's oversight of medical devices, the EU AI Act's high-risk requirements) and cite concern that high-risk-AI regulation may be onerous enough to cause "runaway bureaucracy." They cite the 2010 Flash Crash, and the trading curbs and circuit breakers that followed, as a model for regulating newly consequential uses as they arise.
Diffusion is limited by the speed of human, organizational, and institutional change. The essay argues adoption is slower than popular accounts suggest even outside safety-critical areas. A study reporting that 40% of U.S. adults used generative AI in August 2024 is noted to translate to only 0.5%–3.5% of work hours and a 0.125–0.875 percentage-point productivity increase, because most use was infrequent. The same study's claim that generative-AI adoption outpaced personal-computer adoption (40% within two years versus 20% within three for PCs) is qualified on the grounds that it ignores intensity of use and the high cost of a PC; by some measures generative-AI adoption may have been slower. Adoption concerns software use, not availability: even free, instantly available products require people to change workflows and habits. Paul A. David's analysis of electrification is cited, in which electric dynamos were "everywhere but in the productivity statistics" for nearly 40 years after Edison's first central station, with gains realized only after factories were redesigned around production lines and workplace organization, process control, and hiring and training practices changed.
The external world puts a speed limit on AI innovation. The authors conceptualize methods progress as a "ladder of generality," where each rung reduces the programmer effort needed for new tasks and increases the set of tasks achievable for a given effort (machine learning, for example, replaces hand-written logic with training examples). In some domains — language translation via large language models, or game-playing via AlphaZero's self-play — application-development effort has fallen accordingly. But in consequential real-world applications that cannot be cheaply simulated and where errors are costly, this has not held. Self-driving cars followed a feedback loop similar to AlphaZero's but took more than two decades rather than hours, because safety limited how far each iteration could scale. This "capability–reliability gap" is described as a recurring barrier to useful AI agents. Other limits include tacit organizational knowledge that cannot be learned passively (requiring sector-by-sector and sometimes organization-by-organization learning), privacy and data-sharing constraints, and the social costs that bound experimentation when AI must push beyond existing human knowledge (for example drug testing or economic policy). The "bitter lesson" — that general, compute-leveraging methods eventually beat human-domain-knowledge approaches — is described as valid for methods but routinely misapplied to application development, where, for example, recommender systems still require large amounts of manually coded business logic, frontend, and other components.
Benchmarks do not measure real-world utility. The essay argues benchmarks track progress in methods but are misread as tracking applications, which it identifies as a driver of hype about imminent economic transformation. GPT-4's reported top-10% bar-exam performance is said to tell us "remarkably little about AI's ability to practice law," because the exam rewards retrieval and application of memorized information rather than the creative, judgment-laden tasks (such as preparing filings) whose automation would most change the profession. The same pattern is noted for the gap between self-contained coding problems, where AI excels, and real-world software engineering, where its impact appears modest. The authors frame this as a "construct validity" problem — whether a test measures what it intends to — and argue the only reliable measure of real-world usefulness is to build an application and test it with professionals in realistic scenarios. Such "uplift" studies, they note, generally show modest benefits oriented toward augmentation rather than substitution, with a few occupations such as copywriters and translators seeing substantial job losses. Construct-validity problems are said to afflict forecasting as well: the Metaculus "human–machine intelligence parity" question, defined via exam performance in math, physics, and computer science, yields a 95% forecast for 2040, which the authors regard as too watered-down to indicate real-world impact.
Economic impacts are likely to be gradual. Against the argument that increasing generality could make a wide swath of tasks automatable at once (one definition of AGI), the authors hold that sudden method improvements do not directly produce economic impact, which requires innovation and diffusion through a feedback loop that has historically unfolded over decades for electricity, computers, and the internet. They add that automation tends to lower the cost and value of a task over time, so humans shift to not-yet-automated or newly created tasks — meaning the "goalpost" of AGI continually recedes and human labor need not become superfluous, with impacts felt on different timescales across sectors.
Speed limits to methods progress. Although the slowness argument does not depend on it, the essay also discusses limits on methods development. The volume of AI/ML papers on arXiv has a doubling time under two years, but the authors question how volume translates to progress, citing the field's history of herding around popular ideas (such as the decades-long sidelining of neural networks) and the transformer's decade-long dominance despite known limitations. They cite Johan S.G. Chu and James A. Evans's analysis of over a billion citations across 241 fields, which found that higher publication volume makes it harder for new ideas to break through — an "ossification of canon." Hardware constraints (historically GPUs), inference-time-scaling costs, and a possible shift away from open knowledge-sharing are noted as further limits. On recursive self-improvement, the authors note AI development already relies heavily on AI and expect a gradual increase in automation rather than a discontinuous moment. They use a mountaineering analogy — each solved benchmark reveals a "false summit" and prompts a new one — to explain "moving the goalposts," and cite the 1956 Dartmouth conference's hope for significant progress from a "2-month, 10-man" effort as a caution against assuming a single remaining step (such as scaling, agents, or sample-efficient learning).
Part II: A world with advanced AI
The authors argue that the concepts of "intelligence" and "superintelligence" have clouded reasoning about advanced AI, and propose unpacking intelligence into capability and power.
Human ability is not constrained by biology. The common depiction of intelligence as a one-dimensional spectrum across species is rejected as conceptually ill-defined. What matters for analyzing AI's impact, the authors argue, is power — the ability to modify one's environment — not intelligence as such. By this measure modern humans are already "superintelligent" relative to pre-technological humans, through knowledge, tools, and technology rather than biology, and AI is the latest such tool. Recasting the concern without the word "intelligence," they describe the worry as a causal chain from increasing capability to acquisition of power to loss of control; whereas the superintelligence view focuses on alignment to stop powerful systems from acting against human interests, the authors focus on the earlier step — preventing capable systems from acquiring catastrophic power.
Games provide misleading intuitions. The authors argue there is no useful sense in which AI is more intelligent than people acting with AI, because human intelligence includes the ability to use tools and subsume other intelligences. Machines outperform humans where speed dominates (chess, where a human in a human+AI team can do little but defer), but speed is irrelevant to most real-world tasks, and where superhuman speed is required (such as nuclear-reactor control) tightly scoped automated tools handle it while humans retain overall control. They predict there are relatively few real-world cognitive tasks where AI can "blow past" human performance as it does in chess, because many tasks have high "irreducible error." They offer two concrete predictions: that AI will not meaningfully outperform trained humans (especially teams, with simple automated tools) at (1) forecasting geopolitical events such as elections, nor at (2) persuading people to act against their own self-interest. The self-interest condition is emphasized: they note that the "Evaluating Frontier Models for Dangerous Capabilities" study tested persuasion with no or low cost to subjects (for example forfeiting a £20 charity bonus), so its results say little about persuading people toward genuinely costly actions.
Control comes in many flavors. If AI systems are not meaningfully more capable than humans using AI, the control problem becomes more tractable. The authors argue discussion over-focuses on two extremes — full model alignment and a human-in-the-loop reviewing every action — and that human-in-the-loop control, which they distinguish from human oversight generally, tends to devolve into rubber-stamping or be outcompeted. They point to intermediate forms: auditing (pre-deployment and periodic assessment), monitoring (real-time oversight), and system-safety techniques such as fail-safes, circuit breakers, redundancy, and verification. From cybersecurity they cite least privilege and access controls; from formal verification, checking AI-generated code against specifications; from human-computer interaction, designing state-changing actions to be reversible. They list newer safety ideas including language models as automated judges of proposed actions, systems that learn when to escalate to humans, legible agent activity, and hierarchical control in which simpler reliable systems oversee more capable ones. They predict that as automation spreads, an increasing share of human jobs will consist of AI control — drawing a parallel to how industrialization redefined factory work toward monitoring, programming, and quality control — and that task specification will likewise grow as a part of work. Karen Levy's account of truck drivers is quoted to illustrate that much of a job (inspections, securing freight, repairs, paperwork, customer interaction, yard moves) is harder to automate than its most visible component. The authors predict this transformation will be driven primarily by market forces, since poorly controlled AI is too error-prone to make business sense, with regulation bolstering the incentive to keep humans in control.
Part III: Risks
The essay considers five categories of risk: accidents, arms races, misuse, misalignment, and non-catastrophic systemic risks.
Accidents. As with other technologies, the authors argue deployers and developers should bear primary responsibility for mitigating accidents, with market forces providing incentives and safety regulation filling gaps. They flag three reasons this optimism might fail: arms races, deployers so large that their failure could "take down civilization" (which they treat as a concentration-of-power problem better addressed by resilience and decentralization), and control failures by inconspicuous deployers (treated as a misalignment risk).
Arms races are an old problem. An AI arms race is defined as competitors deploying increasingly powerful AI with inadequate oversight, risking safer actors being outcompeted by riskier ones. Military AI is explicitly excluded as out of scope. The authors argue races to the bottom on safety are common and well-studied across industries — citing fire safety in the garment industry, food and worker safety in meatpacking, steamboats, mining, and aviation — and arise when firms externalize safety costs amid information asymmetries, but recede once regulation forces internalization (through process standards, liability, or labeling and certification). Self-driving cars are offered as a case study: Waymo, with a conservative, transparent safety culture, leads on safety outcomes; Cruise (set to shut down in 2025) and Tesla were more aggressive; Uber's unit had a lax culture and was sold off. Market success has correlated with safety, which the authors regard as causal, with light-touch, polycentric regulation and the threat of license revocation playing a supporting role, as in aviation. Social media is presented as a contrasting case where market forces and regulators failed to align algorithmic recommendation with societal benefit, attributed partly to the difficulty of attributing harms and to the longer history of transportation-safety norms. The authors conclude arms races are sector-specific and best handled by sector-specific regulation, emphasizing proactive evidence-gathering, transparency, and "anticipatory AI ethics." On international competition, they argue the innovation-versus-regulation tradeoff is a recurring dilemma, that despite U.S.–China arms-race rhetoric regulation has not clearly slowed in either country (700 AI-related bills were introduced in U.S. state legislatures in 2024), and that the right analogy is nuclear power (no arms race, local harms, public backlash) rather than nuclear weapons, because accident costs from benign applications are felt locally.
Misuse defenses must be located downstream of models. The authors argue model alignment is a brittle and inherently limited defense against misuse, because whether a capability is harmful depends on context the model often lacks. A phishing example illustrates that individually benign steps (scanning social media, crafting messages, exploiting credentials) become harmful only through an attacker's orchestration, which exists outside the model. Trying to build a model that cannot be misused is compared to building a computer that cannot be used for harm; model-level controls will be either too restrictive or ineffective. Giving a model enough personal context to judge intent is said to violate least-privilege and create new exfiltration risks. The authors state they are not against alignment — it reduces harmful outputs, aids commercial deployment, and adds friction against casual actors — but argue defenses must focus on downstream attack surfaces (email filtering, browser and OS protections, security training, vulnerability detection, and biosecurity screening at procurement), adapting decades of existing defenses against human attackers.
AI is useful for defense. Rather than treating AI capability solely as risk, the authors emphasize defensive potential, arguing access to powerful AI often shifts the offense–defense balance toward defenders, who can probe their own systems. Google's integration of language models into fuzzing for open-source software is cited. They argue restricting AI development could backfire, since adversaries can train their own tools while defenders lose access, and propose measuring risk by the offense–defense balance in each domain rather than by offensive capability alone.
Catastrophic misalignment is a speculative risk. Misalignment is defined as a system acting against its developer's or user's intent because objectives were incompletely specified, with the focus here on catastrophic or existential rather than everyday cases. The authors distinguish epistemic uncertainty (which further observation can resolve, as when asteroid 2024 YR4's ~2% impact probability in early 2025 was later resolved) from stochastic uncertainty (as in a 10% estimate of nuclear war in a decade), and classify catastrophic misalignment as speculative — subject to epistemic uncertainty about whether the true risk is even nonzero. They argue the "paperclip maximizer" thought experiment relies on dubious assumptions, because systems that interpret commands over-literally would fail earlier, less consequential tests before being granted consequential access. Deceptive alignment — a system appearing aligned during evaluation then defecting once powerful — is acknowledged as having some early empirical signs, but is framed as an engineering problem to be addressed in development and deployment rather than a "ticking time bomb," noting that AI also aids deception detection and that defenders have advantages including access to system internals and downstream defense in depth. They note that reinforcement learning optimizing a single misspecified objective over a long horizon is especially prone to specification gaming (citing game agents such as a boat-racing agent that loops to score points), but argue such agents are more likely to be ineffective than dangerous in open-ended settings, and call research on less-gameable design paradigms important.
Systemic risks. The authors identify a long list of below-catastrophic but large-scale risks: entrenchment of bias and discrimination, occupational job losses, worsening labor conditions, inequality, concentration of power, erosion of social trust, pollution of the information ecosystem, decline of the free press, democratic backsliding, mass surveillance, and enabling authoritarianism. On the normal-technology view, these become more important than the catastrophic risks, because they arise from people and organizations using AI to advance their interests, with AI amplifying existing instabilities. The Industrial Revolution's urbanization, exploitation, and inequality — and the rise of both industrial capitalism and socialism in response — are cited as precedent. The authors map their shift in focus onto Atoosa Kasirzadeh's distinction between decisive existential risk (an overt AI-takeover pathway) and accumulative existential risk (gradual erosion of econopolitical structures), while distinguishing their own concern as rooted in the path of capitalism rather than threat actors, and as serious but unlikely to be existential.
Part IV: Policy
The essay frames the divergence between the normal-technology and superintelligence futures as a dilemma, because defenses against one set of risks can worsen the other. Its recommendations center on reducing uncertainty and building resilience rather than presenting a comprehensive governance framework.
Policymaking under uncertainty. The authors argue the AI-safety and "normalist" worldviews are entrenched and unlikely to be resolved empirically, so expert consensus is unlikely; they note the skeptics of catastrophic risk coalesced especially during the 2024 debate over California's AI-safety bill. They argue compromise often fails because some interventions (such as nonproliferation) help against superintelligence but worsen normal-technology risks by increasing market concentration, while others (such as fostering open-source AI for resilience) do the reverse. Cost-benefit analysis based on probability estimates is rejected on the grounds that AI-risk probabilities lack inductive reference classes or deductive models and so vary by orders of magnitude, that the consequences of policy choices are themselves deeply uncertain in magnitude and direction, and that some outcomes implicate moral values and liberal-democratic principles (the state should not restrict freedom based on controversial beliefs reasonable people can reject). They cite the California bill again as a case where weak justification drove opposition, including from scholars and advocates rather than only self-interested firms. They recommend value pluralism (policies acceptable across a range of values) and robustness (policies that remain helpful, or at least not harmful, if key assumptions are wrong).
Reducing uncertainty as a policy goal. The authors recommend five approaches: strategic funding of research on risks aligned with the normal-technology view (noting the AI Incident Database draws on news reports rather than systematic research); monitoring of AI use, risks, and failures through "evidence-seeking policies"; guidance on what kinds of evidence are useful (citing the "marginal risk" framework for comparing open-weight and proprietary models); treating evidence-gathering as a first-rate goal in evaluating any policy; and using research tools such as evidence synthesis and adversarial collaborations across worldviews.
The case for resilience. Drawing on Marchant and Stevens's four approaches to governing emerging technology — two ex ante (risk analysis, precaution) and two ex post (liability, resilience) — the authors argue ex ante approaches are poorly suited to AI given the difficulty of assessing risks before deployment, and that liability, though better, faces causation and chilling-effect problems. They define resilience, following Marchant and Stevens, as the capacity of a system to absorb shocks while retaining its core functions and identity, combining ex ante and ex post elements and helping with the "pacing problem." They group resilience strategies into four categories, the first three being "no regret" policies: broad societal resilience (protecting democratic foundations such as the free press and equitable labor markets); prerequisites for effective technical defenses and policymaking (research funding, transparency requirements for high-stakes developers, reducing community fragmentation, government technical expertise, international cooperation, AI literacy); interventions helpful regardless of AI's trajectory (early-warning systems, defenses against identified risks, incentives for defenders to adopt AI, legal protections for researchers, adverse-event reporting, whistleblower protections); and a fourth category that helps if AI is normal but could make a superintelligence harder to control (promoting competition including through open model releases, ensuring AI is available for defense, and polycentricity). They recommend pursuing the fourth category cautiously while improving readiness to change course.
Against nonproliferation. Nonproliferation policies — export controls, licensing to build or distribute powerful AI, and bans on open-weight models — are described as appealing under the superintelligence view but, in the authors' assessment, infeasible and counterproductive under the normal-technology view. They argue the requisite technical knowledge is already widespread, that costs are falling, and that enforcement would require unprecedented international coordination and increasingly draconian measures. Nonproliferation is said to reduce competition and increase concentration, creating single points of failure (analogized to Windows-targeting worms exploiting software monoculture) and brittleness against shocks such as leaked weights, and to restrict the deep access needed for safety research to a few firms. On bioweapons, the authors argue general-purpose models will find some use by bioterrorists but that this no more makes bioterror an "AI risk" than an "internet risk," and that existing defenses (restricting materials and equipment) apply. They describe nonproliferation as a mindset favoring centralized control across a hierarchy from governments down to end users, list example interventions (capability "forgetting," limiting fine-tuning, entrusting models with autonomous safety decisions, increasing model access to context and data, and developer-controlled "AI organizations"), and argue these paradoxically increase the very power-related risks they aim to prevent.
Realizing the benefits of AI. The authors stress that progress is not automatic, citing Jeffrey Ding's argument that the capacity to diffuse innovations varies across countries and strongly affects national power. They argue regulation that ignores the need for experimentation can freeze business models and miscategorize risk — for example treating whole domains such as insurance, benefits adjudication, or hiring as "high-risk" when within-domain variation may exceed cross-domain variation, or burdening foundation-model developers with deployment-context responsibilities they cannot discharge, or drawing a binary between automated and non-automated decisions that penalizes new oversight models. They frame "regulation versus diffusion" as a false tradeoff and note regulation can enable diffusion, citing the ESIGN Act of 2000 (legal validity of electronic signatures) and the FAA's 2016 small-drone rules (which spurred adoption). They recommend mandatory-negotiation models with regulatory oversight for journalism–AI deals, and investment in the "complements of automation" — AI literacy and workforce training, digitization and open government data, and energy-grid reliability. They argue governments should redistribute AI's benefits, strengthen social safety nets, consider funding the arts and journalism through taxes on AI companies, and strike a balance in public-sector adoption (citing the New York City chatbot that told businesses to break the law, and dubious uses by the U.S. Department of Government Efficiency, alongside the risk of moving too slowly), invoking Nicholas Bagley's critiques of "procedure fetish" and "runaway bureaucracy."
Relation to other positions
The essay sets out a contrary position to Dario Amodei's timeline and risk framing. Where Amodei predicts a Compressed 21st Century in 5–10 years, Narayanan and Kapoor predict transformation over decades, which they describe as consistent with prior general-purpose technologies. The contrast across several dimensions:
| Dimension | Narayanan & Kapoor | Amodei |
|---|---|---|
| Timeline | Decades | 1–2 years to powerful AI |
| Framing | Normal technology, tool | Country of geniuses in a datacenter |
| Risks | Accidents, inequality, misuse | Existential: autonomy, bioweapons, authoritarianism |
| Policy | Resilience, sectoral regulation | Transparency first, then targeted intervention |
| Superintelligence | Incoherent as usually conceptualized | Not inevitable but plausible enough to plan for |
| Control | Many existing flavors; tractable | Requires massive new science (interpretability, constitutional AI) |
The essay also bears on the Eight Worlds Framework, which treats "superintelligence vs. bounded AI" as a binary axis; Narayanan and Kapoor argue the superintelligence concept is itself incoherent, which on their account would make half of that matrix irrelevant. Its regulatory stance aligns with Ezrielev's argument in algorithmic pricing that regulation should wait for evidence, and with the techno-federalism observation that governance is emerging through decentralized, sector-specific processes. The authors situate their own work as putting "normalist" thinking on firmer footing, a project related to Farrell and Shalizi's "AI as Social Technology"; their call for early ethical intervention connects to Lazar's work on anticipatory AI ethics, and the broader argument develops themes from Narayanan and Kapoor's AI Snake Oil. The essay acknowledges detailed feedback from Gillian Hadfield, Seth Lazar, Henry Farrell, Atoosa Kasirzadeh, and others associated with the Knight Institute workshop on AI and democratic freedoms.
Relationships
- contradicts: Compressed 21st Century
- related: AI as Social Technology (Farrell + Shalizi, Knight Columbia, May 11 2026)
- related: Anticipatory AI Ethics (Lazar, Knight Columbia, May 1 2026)
- related: AI Snake Oil — Narayanan and Kapoor (2024)
- related: Eight Worlds Framework
- related: Premature Antitrust Standards in Algorithmic Pricing
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race
Provenance
This page summarizes the essay "AI as Normal Technology" by Arvind Narayanan and Sayash Kapoor, published April 15, 2025 by the Knight First Amendment Institute at Columbia University (Source: https://knightcolumbia.org/content/ai-as-normal-technology). The essay is classified foundational; its full text is held at Raw Sources/AI as Normal Technology.md.