The AI Industry Wants Out of the Law

Published on Sep 26, 2026

By Zephyr Teachout

AI companies have been falling all over themselves to announce that they are currently on track to build illegally dangerous products capable of mass destruction.

Along with sounding the alarm on the catastrophic risk that their products might cause, they have been demanding solutions that share a theme: they all untether AI regulation from the law. They asked for, among other things, immunity from laws against collusion, a bespoke regulator who regulates only AI, and preemption of state laws.

They have been pushing for a federal moratorium barring states from enforcing their own laws, a new federal agency to license large models, and immunity from federal antitrust law that prohibits competitors from colluding. This comes on top of the legal exceptionalism they have successfully demanded in states by way of tax exemptions and efforts to override local input.

Underneath all of these requests is a demand not to be subject to law itself as it normally operates, to be untethered from state regulators, to be untethered from existing federal law, and to be untethered from tort. In the logic of AI companies, because the risks are different in kind and scale, they should be treated as wholly new and freed from law as it operates in the world.

This is a bad idea, and as I’ll explain, there are many more reasons why we should radically strengthen existing legal regimes and institutions to address existing illegality and possible existential risks, and pass additional safety laws on top of this infrastructure, instead of trading old laws for new ones.

But before we get to why legal exceptionalism is a bad idea, it’s worth pausing and noting why they might be doing this.

I think there are three reasons that they are asking for a bespoke legal regime to deal with reports of catastrophic risk.

The first reason is that the AI companies were formed inside the same big tech culture, with the same investors and in many cases the same people, who built tools under the assumption that the internet has its own rules. Thirty years ago, we decided that the best way to develop technology was to give tech platforms broad immunity for the harm they caused, to treat “the internet” as wholly different, and to untether it from common law and to preempt state law. We removed it from the normal domain of law (in particular, liability for harms caused) built up over generations and put it in its own special category. For three decades, Section 230 blocked ordinary negligence or product-liability law, and tech investors and C-suites became accustomed to operating untethered from law. Some of the big AI companies are the same companies that were habituated, but all were formed inside an assumption that a new technology gets its own rules rather than the old ones.

The second is that expertise in probabilistic forecasting and threat modeling, practices that are embedded in AI culture, does not go hand in hand with expertise in law. In the last few weeks, we’ve seen remarkably thin understanding of law, and of how law, built up over generations, is designed to protect society from catastrophe.

Finally, of course, the investors and the CEOs have unlimited incentive to demand legal exceptionalism. Immunity from existing law is potentially worth trillions of dollars, and new regulatory regimes are far easier to control than old ones.

But whether opportunistic or ignorant or both, the urge to reach for solutions outside of existing legal frameworks and institutions actually exacerbates risk.

The message is: “If you don’t stop us from our compulsions we will build an illegally dangerous product of mass destruction.”

However, if we take the threats to human health and well-being seriously, the last thing we should do is remove them from the normal domain of law. Law protects each competitor from another competitor’s illegal action; it is designed to prevent extreme danger and to separate the profit motive from the destructive motive.

The demand for a wholly new regime assumes our existing order is helpless before catastrophic risk. It is not. In our current legal system, there are many, many ways we protect people from catastrophe.

The threat of liability for causing harm, or breaking the law, deters companies from building dangerous products every day. And while regulatory agencies with expertise and a precautionary mindset can help, they always need to be backed up with a decentralized enforcement regime of state attorneys general and private rights of action.

When I say “deter,” I don’t mean just a lone wolf deciding to pause. I mean that our capital markets won’t fund products that carry high liability. Tort law and products liability law operate in tandem with the SEC. The SEC can stop an IPO if an issuer fails to disclose material risks from the business (like a CEO saying our product is going to destroy human civilization), and if the issuer includes the risk, then investors won’t invest, and the company, knowing this, won’t build the product.

Liability regimes made cars safer, and failure-to-warn lawsuits forced drugmakers to disclose risks regulators had missed. And basic products liability lawsuits led to new disclosures, which in turn fueled even more sector-specific safety regulation, like seat belt and labeling rules.

That relates to one of many reasons collusion would be dangerous. It isn’t needed for companies to share safety information, and it would help destroy the power of liability rules. If the big AI companies can collude, they can form a cartel immune to the usual pressures of liability, and build a fortress of political and informational power.

The more AI is tethered to the principles of tort law, consumer protection law, and criminal law, the better. Inasmuch as our legal regime is unprepared, it is because we have weakened those arenas, and the catastrophic scenarios presented by AI companies should make us reconsider that weakening. For instance, having far stronger private rights of action and whistleblower lawsuit laws would go a long way both in uncovering some of the potential harms and dissuading companies from building in ways that cause them.

Big risks require decentralized enforcement structures, to protect against fragility in enforcement and capture. A serious response therefore requires decentralized modes of enforcement, so that capture at the federal level does not mean wholesale capture.

Because the risk of capture by companies and LLMs tasked with identifying political weakness is so great, we should build any new oversight tools within an existing agency, instead of creating a wholly new agency. The more embedded an oversight agency is within a non-AI history, the less risk of capture.

The risk models of AI firms themselves would tell us that those same firms will rationally use frontier models to map weaknesses and accelerate capture, and a new agency, where staff have not been acculturated to norms of law and precaution, would be far easier to weaken.

So when we think about existing capacity, we should always take a multipronged approach, always ensure decentralized enforcement, and strengthen existing regimes. The FTC already has oversight capacity legally, but lacks the resources: one natural response to the new risks would be to quadruple FTC funding or more, so it has the capacity to build more expertise for oversight.

Many have proposed a new federal regulatory regime like the Nuclear Regulatory Commission (NRC) and the National Nuclear Security Administration (NNSA), the federal atomic oversight bodies, but a more reasonable response would be to expand the authority and budgets of both of those bodies. They were built not to be captured and not to be corrupted, with a deep culture of respect for great risk, and that cultural and staffing history at the top of those agencies would go far in cabining the high-risk-appetite culture within a lot of AI communities — an appetite that is embedded in the probabilistic, instead of precautionary, mode of reasoning that is very popular among C-suites in AI. The NRC has generations of established institutional culture that treats catastrophic risk with a careful, professional, precautionary approach, and would be a far safer home, were it granted massive funding and authority. There are many other existing agencies that protect against defective products that should also be given funding to expand their oversight.

We’ve heard proposals for an industry-funded, FINRA-style body to police frontier AI, and OpenAI wants a new federal safety institute. The risk of regulatory capture is at its peak with a new agency, an industry-funded agency, an agency prone to revolving doors, and an agency whose regulated entities are highly capitalized. A new AI regulator would be at the peak of the risk of being captured by companies that have already shown disdain for copyright, antitrust, and privacy laws.

Any regulatory vision that untethers AI from tort, products liability, antitrust, or criminal law in exchange for immunity is a dangerous vision. A vision that depends on a wholly new entity as a single-point-of-failure regulator is a dangerous vision. A vision that requires preemption of state law is a dangerous vision. Catastrophic threats require decentralized enforcement of existing law, new laws that enhance safety, and much stronger oversight by existing regulators, not the creation of new ones.

Zephyr Teachout is a professor of law at Fordham Law School and the author of Corruption in America (2014), Break ‘Em Up (2020), and the forthcoming Anti-Monopoly: A Citizen’s Guide (2027).