AI Policy Wiki
Dashboard

Regulating Under Uncertainty: Governance Options for Generative AI (G'sell, 2024)

high confidence · updated 2026-06-06

470-page comparative report from Stanford's Cyber Policy Center canvassing global generative-AI regulation as of August 2024: industry practices, EU AI Act, Chinese framework, US federal + state, 10 other jurisdictions, and international initiatives. Framed around the laissez-faire ↔ co-regulation ↔ command-and-control continuum.

Regulating Under Uncertainty: Governance Options for Generative AI is a 470-page comparative report by Florence G'sell, published December 2024 through Stanford's Cyber Policy Center (Program on Governance of Emerging Technologies) with funding from the Project Liberty Institute. It assesses the global regulatory landscape for generative AI as of August 2024, inventorying industry practices, the EU AI Act, the Chinese framework, US federal and state action, ten additional jurisdictions, and international initiatives. The report is descriptive rather than prescriptive: it maps regulatory options onto a continuum from self-regulation (laissez-faire) through co-regulation to command-and-control, without advocating a single model.

Summary of argument

G'sell frames the report around the problem of "regulating under uncertainty" — setting rules for a technology whose risks and capabilities governments do not yet fully understand, without the option of waiting until they do. The report states: "Regulation is both urgently needed and unpredictable. It also may be counterproductive, if not done well. However, governments cannot wait until they have perfect and complete information before they act, because doing so may be too late to ensure that the trajectory of technological development does not lead to existential or unacceptable risks."

The central analytic move is to array regulatory approaches on a spectrum:

  1. Self-regulation — firms develop their own rules (US pre-EO-14110, UK "wait-and-see," Israel).
  2. Co-regulation — government and private actors jointly develop standards (EU, Singapore, Saudi Arabia soft-law).
  3. Traditional government regulation — binding legal frameworks imposed by the state (China, EU AI Act's command-and-control portions).

The report observes that all three coexist in most jurisdictions; the typology captures tendencies, not absolutes. As G'sell summarizes: "While the United States favors self-regulation, Europe combines regulation and co-regulation, and China tends to adopt a top-down regulatory approach."

Structure

The report comprises seven chapters (roughly 440 pages of text plus appendices):

  • Ch. 1 — Introduction (pp. 8–28). The ChatGPT turning point; the benefits-vs-harms debate; the pause letter and counter-arguments; the three regulatory modes; industry calls for regulation (Altman/Microsoft licensing proposals); the "Microsoft Blueprint: Know Your Cloud, Customer, and Content."
  • Ch. 2 — Technology and supply chain (pp. 29–57). Foundation models, training pipelines, compute, data sources, deployment patterns, and the value chain (foundation model developer → fine-tuner → deployer → user).
  • Ch. 3 — Risks (pp. 58–120). A taxonomy covering technical, ethical/social, legal, and environmental/economic/societal risks (detailed below).
  • Ch. 4 — Industry initiatives (pp. 121–171). Pre-deployment, deployment, post-deployment, and collective initiatives (detailed below).
  • Ch. 5 — Regulatory initiatives (pp. 172–404). The bulk of the report. Section 5.1 EU (GDPR, copyright, DSA, AI Act, Liability Directives, Cyber Resilience Act). Section 5.2 China (Algorithm Recommendation Provisions, Deep Synthesis Regulation, Interim Measures, Basic Safety Requirements, ethics norms). Section 5.3 US (existing law, federal executive action, state initiatives). Section 5.4 a ten-country survey: Brazil, Canada, India, Israel, Japan, Saudi Arabia, Singapore, South Korea, UAE, UK.
  • Ch. 6 — International initiatives (pp. 405–439). G7 Hiroshima AI Process, G20 AI Principles, EU-US TTC, BRICS AI Study Group, Council of Europe Framework Convention, UN High-Level Advisory Body, UNESCO, African Union, OECD, Bletchley/Seoul Summits, Global Partnership on AI.
  • Ch. 7 — Final conclusions (pp. 440–445). Five high-level principles (detailed below).
  • Appendices (pp. 446–459). A16Z top-100 consumer AI apps; EU AI Act text evolution; China framework comparison table.

Concluding principles (Ch. 7)

The report draws five high-level conclusions from the survey:

  1. Technology-level vs. application-level regulation. Sector-specific laws let AI regulation evolve incrementally, but GPAI models demand technology-level rules because future applications are unpredictable. Dedicated AI Safety Institutes have emerged in the UK, US, Japan, and EU to build state capacity.
  2. Transparency and auditing are foundational. Model cards and training-data disclosures are "only the initial steps." Both developers and independent third parties must rigorously test pre-deployment for performance, biases, alignment, and catastrophic-risk potential.
  3. Enforcement matters at least as much as legislation. Legislation alone cannot specify rules for a fast-moving technology. Enforcement requires governments to recruit scarce and expensive AI talent and to maintain ongoing coordination with industry and civil society.
  4. Public-vs-private sector power. Almost all frontier models are built by private firms because data, chips, and compute are concentrated. "Democratizing" AI production may require large public investment in non-commercial alternatives.
  5. Open-source promise and risk. Meta (Llama), Mistral, and Falcon have produced significant open models. These could democratize benefits and break platform oligopolies, but once released cannot be un-released, and fine-tuning can remove safety measures.

Jurisdiction findings

European Union (Section 5.1)

The report devotes substantial space to the EU AI Act (Regulation 2024/1689, adopted June 2024) because it "presents many of the fundamental regulatory choices policymakers must confront." Key features as described: a risk-based four-tier structure (unacceptable / high / limited / minimal); GPAI model obligations added late in negotiations, shifting focus "from specific use cases to the technology itself"; a limited-risk category covering generative-AI systems (transparency plus labeling); and a high-risk category triggering risk management, data governance, human oversight, robustness, and cybersecurity requirements. Enforcement runs through the AI Office and national authorities, with fines up to €35M or 7% of global turnover. See EU AI Act (Regulation 2024/1689) for detailed coverage of the Act itself.

The report also covers the surrounding EU instruments: the Liability Directives (the Product Liability Directive revised to classify software, including AI, as "products"; the proposed AI Liability Directive that would ease the burden of proof for plaintiffs in fault-based claims, later withdrawn in 2025 after the report's cutoff); the Cyber Resilience Act (cybersecurity rules for "products with digital elements," including AI systems); GDPR (already applying to AI training and deployment, with tensions over web scraping and training-data lawfulness); and the Copyright Directive 2019 (TDM exceptions with commercial opt-outs governing training-data use).

China (Section 5.2)

The report surfaces a more nuanced picture than the "state-driven" framing in Bradford's account: China's AI framework shares some objectives with democratic regimes (content labeling, privacy, IP protection for non-state actors) while adding authoritarian-specific objectives (preventing "fake news" and content violating "socialist values," registering technologies capable of influencing public opinion, user identification and activity monitoring, and retraining models that produce prohibited content).

The Chinese framework is built from layered instruments:

The ethics instruments include the Ethical Norms for New Generation AI; the Measures for Scientific and Technological Ethics Review (Trial); and municipal-level AI ethics committees.

United States (Section 5.3)

The report characterizes the US posture as "hands-off" / "encouraged self-regulation," with most action in the executive branch and the states.

  • Existing law: sectoral data protection (HIPAA, COPPA, state laws, with no federal comprehensive statute); copyright (training-data lawsuits pending); liability (Section 230 interaction with AI content unsettled).
  • Federal executive action: Biden-administration voluntary commitments (July and September 2023); Executive Order 14110 (October 2023), with eight guiding principles; the NIST AI RMF and companion documents; agency actions under existing authority (FTC, EEOC, DOJ, CFPB, SEC).
  • State initiatives: California SB 1047 vetoed (the governor "intends to craft another legislation," a statement that predates SB 53); the Colorado AI Act (the first comprehensive state algorithmic-discrimination law); state deepfake and elections laws; and NYC Local Law 144 (hiring-tools audits).

The report predates the Trump-administration pivot: EO 14179 rescinding EO 14110, America's AI Action Plan, and Executive Order 14365 — Ensuring a National Policy Framework for AI preempting state AI laws. Its US coverage should be read as a December 2024 snapshot, with subsequent wiki pages superseding it.

Ten-country survey (Section 5.4)

CountryPostureKey instruments
BrazilEmulating EU risk-based approach[[brazil-pl-2338PL 2338]] pending; sandboxes; text/data-mining exception
CanadaDraft risk-basedAIDA (within Bill C-27); Voluntary Code of Conduct for advanced generative AI — see Canada AIDA (Bill C-27, Part 3) — Source Summary
IndiaSectoral + draftingExisting law + policy instruments; Digital India Act in preparation
IsraelPro-innovation, softFocus on promoting tech sector; potential shift to binding/voluntary mix
JapanSoft-law → considering bindingNon-binding guidelines + application of data/copyright law; considering a binding framework for large-scale foundation models — see Japan AI Promotion Act — Source Summary
Saudi ArabiaCo-regulationSDAIA; AI Ethics Principles; copyright + data-protection amendments
SingaporeCo-regulation (soft-law)National AI Strategy (2019); Model AI Governance Framework (2020); [[singapore-mgf-genaiMGF for Generative AI]] (2024)
South KoreaMoving toward bindingNational Strategy (2019); Human-Centered AI Ethics; Digital Bill of Rights (2023); PIPA amendments (2024); [[south-korea-ai-basic-actAI Basic Act]] (passed shortly after the report — see page for current status)
UAENo AI law anticipatedRegulatory sandboxes; UAE AI Ethics framework
UK"Pro-innovation" / wait-and-seeSector-specific regulators; [[uk-ai-safety-instituteAISI]]; Generative AI Framework for HMG; Online Safety Act 2023

International initiatives (Section 6)

  • G7 Hiroshima AI Process — Guiding Principles plus a Code of Conduct for AI developers (non-binding) — see G7 Hiroshima Code of Conduct for Advanced AI (2023)
  • G20 AI Principles
  • EU-US Trade and Technology Council — collaborative AI projects
  • BRICS AI Study Group — aligned with China's Global AI Governance Initiative
  • Council of Europe — Framework Convention on AI and Human Rights, Democracy, and the Rule of Law (May 2024), the first international legally binding AI treaty; requires 5 ratifications to enter into force; general provisions with significant latitude for signatories
  • UN — High-Level Advisory Body on AI; first AI resolution adopted
  • UNESCO — ethical guidelines plus education and research guidance
  • African Union — various AI policy documents
  • OECD — AI Principles (2019, updated 2024); Recommendation on AI; studies and reports that many other initiatives build upon
  • AI Safety Summits — Bletchley (The Bletchley Declaration (AI Safety Summit, 1–2 November 2023)); Seoul Frontier AI Safety Commitments (Frontier AI Safety Commitments (Seoul, 2024)); Paris (Paris AI Action Summit Declaration (2025)); and the International Scientific Report on the Safety of Advanced AI (a 75-expert compilation, May 2024, chaired by Bengio)

Industry initiatives (Ch. 4)

Pre-deployment practices:

  • Data curation: source selection (Common Crawl critiques), data filtering, data augmentation and synthesis. The report cites Stanford CRFM Transparency Index findings that "developers are least transparent with respect to the resources required to build foundation models" and that "data remains a key area of opacity."
  • Model evaluation: capability benchmarks, red teaming, third-party assessments.
  • Alignment: RLHF, constitutional AI, fine-tuning.
  • Differential privacy: limited production use.

Deployment practices: Responsible Scaling Policies of leading AI companies — Anthropic's RSP (see v2.2 and v3.1), OpenAI's Preparedness Framework, Google DeepMind's Frontier Safety Framework, and Meta's Frontier AI Framework. The report notes their limitations: voluntary, no independent oversight, and commercial-pressure conflicts.

Post-deployment practices: constraining user behavior (usage policies, rate limiting, account review); transparency reports; C2PA content provenance and authenticity (a coalition of Adobe, Microsoft, Intel, BBC, and others — see Data Provenance, C2PA, and Watermarking); and removing unwanted data (opt-outs, takedown mechanisms).

Collective initiatives: Partnership on AI; Frontier Model Forum; the AI Alliance (Meta, IBM, and 50+ partners, open-source-favoring); MLCommons (benchmark standards); and C2PA (Coalition for Content Provenance and Authenticity).

Risk taxonomy (Ch. 3)

  1. Technical/operational: robustness failures, misalignment, hallucinations, opacity (both the "black box" problem and industry opacity).
  2. Ethical/social:
    • Malicious use: cybercrime, cyberattacks, biosecurity threats, sexually explicit content generation (including CSAM), mass surveillance, military applications.
    • Misinformation and disinformation.
    • Bias and discrimination: training-dataset bias, value embedding, value lock and outcome homogenization.
    • Influence, overreliance, dependence: manipulation, overreliance on AI, and emotional dependence (foreshadowing mental-health debates).
    • Nascent capabilities: agency/autonomy, emergent capabilities.
    • Risk disparities: the open-source debate; risks of highly capable models.
  3. Legal: privacy and data protection (PII collection, personal-data protection); copyright (training-data infringement, infringing output, authorship of AI-generated content).
  4. Environmental/economic/societal: market-power concentration; labor-market disruption (displacement and inequality); environmental cost (energy, water, mitigation); and AGI existential risk (including "relativizing" counter-views).

Cross-cutting observations

The report draws several cross-cutting observations:

  • EU AI Act as de facto global template. Brazil, Canada, and others explicitly emulate the risk-based approach, echoing the "Brussels Effect" documented by Bradford.
  • Soft-law to binding-law drift. Countries that initially favored voluntary guidance (Japan, South Korea, Singapore) were, at the time of writing, considering binding frameworks, particularly for high-risk AI.
  • AI Safety Institutes network. The UK, US, Japan, and EU had established dedicated institutes — see International AI Safety Institute Network (INSAI / AISIN).
  • Industry self-regulation is voluntary and asymmetric. Per the report: "While AI companies have formed industry groups, many current practices stem from individual initiatives by generative AI developers and are sometimes adopted by competitors... remain entirely voluntary commitments without independent oversight."
  • International consensus is narrow and non-binding. Principles are often "exceedingly broad"; there are no binding limits on AI model capabilities or global compute thresholds, no international compliance commission, and no cross-jurisdictional safety recognition.

Key quotes

  • On urgency: "Governments cannot wait until they have perfect and complete information before they act, because doing so may be too late to ensure that the trajectory of technological development does not lead to existential or unacceptable risks."
  • On regulatory approaches: "While the United States favors self-regulation, Europe combines regulation and co-regulation, and China tends to adopt a top-down regulatory approach."
  • On the AI Act: "Parts of the law represent a command-and-control model... The Act also has aspects of co-regulation to it... it applies to all AI services used in the EU, which, as with GDPR, may set a new international standard for AI."
  • On industry voluntary measures: "Such initiatives are not always driven by a desire to prioritize a responsible or ethical approach. For example, practices like red teaming or reinforcement learning primarily focus on technological advancement and enhancing the quality and reliability of AI models."

Relation to other wiki coverage

Single-jurisdiction pages already exist for the EU, China, and the US, alongside individual state laws and pages for Japan, Brazil, Canada, South Korea, and Singapore. This report adds:

  • Comparative scaffolding. The self-regulation ↔ co-regulation ↔ command-and-control typology serves as an organizing frame for cross-country comparison (see Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation).
  • The risk-based approach. It formalizes the approach the EU AI Act pioneers (see Risk-Based AI Regulation).
  • The "regulating under uncertainty" framing — the epistemological problem of rule-making for technology whose trajectory is unknown (see Regulating Under Uncertainty).
  • A December 2024 baseline for international initiatives — the CoE Framework Convention, OECD Recommendation, G7 Hiroshima Process, and Bletchley/Seoul summits — useful for reading later sources that reference these.
  • Detailed treatment of jurisdictions less covered elsewhere: India, Israel, Saudi Arabia, and the UAE.

Temporal caveat: August 2024 landscape

The report explicitly assesses the regulatory landscape as of August 2024. Subsequent developments not captured include:

Jurisdiction-specific claims in this source should be read as a December 2024 snapshot; more recent wiki pages carry current status.

Confidence assessment

  • High confidence on descriptive claims about published laws, frameworks, and initiatives as of August 2024. The report is footnoted (2,340+ footnotes) and peer-reviewed by a panel of AI and law experts.
  • Medium confidence on characterizations of regulatory posture (for example, "UK favors self-regulation"), which were accurate for the snapshot but where several jurisdictions have since shifted.
  • The report is observational rather than normative: it describes options without advocating among them. Where it does stake positions (the Ch. 7 conclusions), these are best read as considerations emerging from the survey rather than advocacy.

Provenance and contributors

Principal author: Florence G'sell (Visiting Professor, Stanford Law; director, Stanford Cyber Policy Center's Program on Governance of Emerging Technologies). Program manager: Ben Rosenthal.

Country-specific contributors: Elliot Stewart (industry practices); Chris Suhler, Ashok Ayyar, Nikta Shahbaz (US federal and state); Prof. Jiaying Jiang, Jasmine Shao, Sabina Nong (China); Zeke Gillman (Canada, South Korea, Singapore, UK, Israel, Saudi Arabia, UAE, international); Arpit Gupta (India); Tally Smitas (Brazil); Ryoko Matsumoto (Japan); Prof. Keeheon Lee, Nathan Levit, Maya Rodriguez (South Korea, Singapore).

Review panel: Nate Persily, Dave Willner, Rishi Bommasani, Kevin Klyman, Dan Ho, Mark Lemley, Daphne Keller, Shayne Longpre, Hiroki Habuka, Jingwen Wang, Xinyu Fu, and others.

Origin: the Spring 2023 Governance and Regulation of Emerging Technologies Policy Practicum at Stanford Law.

Relationships

See also