The core doctrines governing the digital world — intermediary safe harbours such as Section 230 and the EU e-Commerce Directive, notice-and-takedown, self-regulation and “permissionless innovation”...
...were built on 1990s assumptions of platforms as passive conduits. The failure to prevent social-media harms to children is the cautionary proof that after-the-fact enforcement arrives too late.
Beyond Reactive Rules
The Case for Proactive, “By-Design” AI Governance
A structured assessment of whether regulators should shift from after-the-fact enforcement toward preventative technical and operational infrastructure — with a decision framework, recommendations, and sources.
13 August 2026, by Claude
Executive summary
• Yes — the dominant regulatory paradigm remains reactive and ex post, and it is poorly matched to AI-era harms. The core doctrines governing the digital world — intermediary safe harbours such as Section 230 and the EU e-Commerce Directive, notice-and-takedown, self-regulation, and “permissionless innovation” — were built on 1990s assumptions of platforms as passive conduits. The failure to prevent social-media harms to children is the cautionary proof that after-the-fact enforcement arrives too late.
• Regulators and policymakers should become substantially more proactive — but selectively. The strongest case for governments actively designing, building, or mandating preventative infrastructure lies in a defined set of domains where harms are catastrophic, irreversible, or systemic: child online safety and age assurance, content provenance and authenticity, identity and anti-fraud, model-safety evaluation, incident reporting, and critical-infrastructure cybersecurity. A “public option” or digital-public-infrastructure approach is warranted where markets structurally under-provide a public good — not as a blanket replacement for private innovation.
• The right posture is a hybrid, tiered framework, not a binary choice. Ex ante “by design” obligations and public infrastructure should be reserved for high-severity, hard-to-reverse risks; ex post liability and lighter-touch approaches suffice for the long tail of lower-risk uses. The genuine risks of proactivity — surveillance, exclusion, regulatory capture, chilled innovation, and state-capacity gaps — are real and are best managed through governance design (open standards, independent oversight, purpose limitation, sunset clauses), not by defaulting to inaction.
Key findings
1. The reigning digital-governance doctrines are pre-internet or early-internet artefacts. Section 230 of the U.S. Communications Decency Act (1996) and the EU e-Commerce Directive (2000/31/EC) were designed to shield a nascent industry from liability for third-party content, treating platforms as neutral hosts. Legal scholars now argue this assumption of passivity cannot coexist with generative AI and algorithmic amplification: a large language model’s output is a product of the system’s own design and training choices, not third-party speech, and courts risk entrenching outdated assumptions as they did with social media. The Harvard Law Review’s “Beyond Section 230” argues the immunity shield may have outgrown its original purpose, leaving users without clear accountability pathways.
2. Social-media child harm is the paradigmatic failure of reactive regulation. The U.S. Surgeon General’s 2023 advisory reports that as many as 95% of teens aged 13–17 use social media, with more than a third describing near-constant use, and that adolescents who spend more than three hours a day on social media face roughly double the risk of depression and anxiety symptoms (citing Riehm et al., 2019). Facebook’s own leaked internal research — the “Facebook Files” reported by The Wall Street Journal (Wells, Horwitz & Seetharaman, 14 September 2021) — included a 2019 slide stating the company makes “body image issues worse for one in three teen girls,” alongside further findings that a large share of teen girls who already felt bad about their bodies felt worse after using Instagram. On criminal exploitation, NCMEC’s CyberTipline received more than 36.2 million reports of suspected child sexual exploitation in 2023 (up over 12% year-on-year), containing over 105 million files, with online-enticement reports rising from about 44,000 (2021) to roughly 187,000 (2023). Accountability arrived, if at all, only after more than a decade — through litigation, belated statutes, and a proposed warning label — long after harms had scaled. Researchers have also found that more than half of platforms’ own child-safety features do not work as advertised. This is the definitional signature of ex post failure: harm is realised, diffuse, and largely irreversible before enforcement bites.
3. There is a mature scholarship on proactive alternatives. “Safety by design” (Australia’s eSafety Commissioner), “regulation by architecture” (Lessig’s “code is law”), “anticipatory” and “agile” regulation (Nesta, OECD), risk-based ex ante conformity assessment (EU AI Act), and RegTech / SupTech all offer structured ways to prevent harm before it occurs rather than punishing it afterwards. The intellectual core is the Collingridge dilemma and the “pacing problem”: early on, harms are hard to foresee but easy to prevent; later, they are obvious but entrenched and costly to change.
4. “Public AI” and digital public infrastructure are moving from theory to practice. India’s DPI stack (Aadhaar, UPI, DigiLocker) demonstrates population-scale public digital infrastructure; the U.S. NAIRR pilot provides public compute; national AI Safety / Security Institutes provide public model-evaluation infrastructure; and scholars argue for a “public option” for AI as a democratic counterweight. Brookings researchers (Sanders, Schneier & Eisen, 2024) note that three firms — Microsoft, Google, and Amazon — control roughly two-thirds of the global cloud-computing market used to train and deploy AI models.
5. Proactivity carries serious, well-documented risks. Aadhaar shows how public digital infrastructure can produce surveillance, exclusion (biometric authentication failures cutting people off from food rations), and function creep. The innovation-principle camp (ITIF, Cato) argues that ex ante precaution chills beneficial innovation and generates hypothetical worst-cases. Public-option sceptics warn of state-capacity gaps, capture, and the “sovereign AI” marketing trap. These are reasons to design proactivity carefully — not to abandon it.
Analysis
The pre-internet inheritance, and why it fails for AI
The foundational bargain of internet law was to treat intermediaries as conduits. Section 230(c)(1) provides that platforms shall not be treated as the publisher or speaker of third-party content; the EU e-Commerce Directive created parallel “mere conduit,” “caching,” and “hosting” safe harbours and, in Article 15, barred member states from imposing general monitoring obligations. This architecture was deliberately permissive to nurture a young industry, reflecting the “permissionless innovation” ethos (Adam Thierer) and the cyberlibertarian belief that cyberspace was largely unregulable.
Three features make this poorly suited to AI-era harms. First, generative AI collapses the user–host dichotomy on which safe harbour rests: when a model produces the content, applying host-oriented immunity to systems that themselves generate speech is, scholars argue, a categorical error (Center for Democracy & Technology; American Bar Association; Brown Political Review). Second, algorithmic amplification means platforms are not passive: the harm often lies in the design of the recommender system, as litigated in Gonzalez v. Google. Third, the ex post model presumes an identifiable wrongdoer and a compensable, reversible harm — assumptions that break down for diffuse, systemic, or catastrophic AI harms.
The scholarly framing is provided by Julie E. Cohen (Georgetown), whose “The Regulatory State in the Information Age” argues that regulatory models built for the industrial economy face existential challenges from informational capitalism, and that regulators lack even a measure of “platform power” to parallel antitrust’s “market power.” Lawrence Lessig’s “Code is Law” supplies the deeper insight that architecture is itself a regulator — one of four modalities alongside law, norms, and markets — and that design choices embed values and can regulate behaviour through a kind of physics, often more effectively than after-the-fact law.
The scholarship on ex ante and “by design” approaches
• Ex ante versus ex post. In law and economics, regulation is ex ante (feed-forward) while litigation is ex post (feedback). Strong ex ante approaches draw on the precautionary principle. Scholars argue that certain harms — those so large that no actor could compensate for them afterwards, including catastrophic and national-security risks — justify ex ante prevention (Anderljung et al.; Kolt). Others (Bruegel’s Mario Mariniello, 2026) caution that AI’s unpredictability means a purely ex ante regime cannot safeguard against unforeseeable harm, and advocate rebalancing toward robust ex post liability. The mainstream conclusion is a hybrid.
• Safety by design. Australia’s eSafety Commissioner — the world’s first standalone online-safety regulator — built the global reference “Safety by Design” framework (2018) around three principles: service-provider responsibility, user empowerment and autonomy, and transparency and accountability. Its animating aim is to “anticipate, detect and eliminate online harms before they occur” rather than retrofit safeguards. The OECD’s 2024 work on digital safety by design for children builds on it.
• Regulatory markets (Hadfield & Clark). Governments license private regulators that compete to achieve publicly set outcomes, addressing both the “technical deficit” of legislators and the “democratic deficit” of self-regulation. This is being operationalised through “Independent Verification Organizations” (Fathom; California SB 813).
• Anticipatory and agile regulation. Nesta’s “anticipatory regulation” (proactive, iterative, responsive; sandboxes and testbeds) and the OECD’s “Framework for Anticipatory Governance of Emerging Technologies” (2024) — embedding values, foresight and technology assessment, stakeholder engagement, agile and adaptive rule-making, and international cooperation — provide the public-administration scaffolding.
• The Collingridge dilemma and pacing problem frame the timing challenge: early on, change is easy but the need for it is hard to foresee; later, the need is obvious but change has become costly, difficult, and slow.
Frameworks in force or proposed
• EU AI Act — risk-based, ex ante conformity assessment for high-risk systems, outright prohibitions for “unacceptable-risk” uses (Art. 5), and obligations for general-purpose models with systemic risk (trained above 10^25 FLOP). Critics call its conformity assessment a timid ex ante approach (limited to high-risk systems, largely internal checks); Bruegel argues for rebalancing toward ex post liability.
• EU Digital Services Act (Regulation (EU) 2022/2065) — the clearest “by design” systemic-risk regime. Article 34 requires Very Large Online Platforms (45 million-plus EU average monthly users) to assess systemic risks stemming from the design and functioning of their services, including their algorithmic systems; Article 35 requires proportionate mitigation, including adapting design and recommender systems and taking targeted measures to protect children; Article 28 requires “a high level of privacy, safety, and security of minors” and bans profiling-based advertising to minors; fines reach 6% of global annual turnover (Art. 74). CEPA argues the DSA approach — supervising how feeds are built and amplified — is superior to blunt social-media bans.
• UK Online Safety Act 2023 / Ofcom — a statutory duty of care requiring risk assessments for illegal content and child safety, with fines up to £18 million or 10% of global turnover. It is contested: encryption and “accredited technology” powers raise privacy concerns; research suggests age-assurance duties drive VPN circumvention; and Ofcom has faced criticism (including a Wikipedia legal challenge) over overbreadth.
• NIST AI Risk Management Framework (AI RMF 1.0, January 2023) — voluntary, with four functions (Govern, Map, Measure, Manage). Influential “soft law,” but non-binding.
• OECD AI Principles (2019, updated 2024) — the first intergovernmental AI standard.
• AI Safety Summits — Bletchley (November 2023; the 28-country-plus-EU declaration and the birth of AI Safety Institutes), Seoul (May 2024; Frontier AI Safety Commitments and a network of institutes), and Paris (February 2025; a shift in emphasis toward innovation and the launch of “Current AI,” a public-interest partnership with an initial $400 million endowment and a €2.5 billion multi-year target).
The case for governments building AI infrastructure
• Digital public infrastructure (DPI). India’s stack — Aadhaar (biometric ID), UPI (real-time payments), DigiLocker — shows government acting not only as a regulator but as a driver of digital innovation, conceived as “government-owned, non-competing” utilities on which others build (ORF America). By early 2026, India had signed DPI cooperation agreements with roughly two dozen countries. Estonia’s X-Road is a parallel model.
• Public AI / public option. Sanders, Schneier & Eisen (Brookings, 2024) argue that because a handful of firms control most global cloud compute, publicly developed and owned AI models and computing infrastructure could democratise the technology and set a benchmark that private services must surpass. Ganesh Sitaraman et al.’s “The Global Rise of Public AI” (Vanderbilt Policy Accelerator, 2025) catalogues four approaches (from outsourced provision, through state-corporate fusion, to genuine public options) and draws on Mozilla’s “Public AI” work and the Public AI Network. A distinct, more aggressive proposal — Senator Bernie Sanders’ “American A.I. Sovereign Wealth Fund Act” — would take public equity stakes in leading AI firms; Schneier warns against conflating genuine public AI with vendor-driven “sovereign AI.”
• Public compute. The U.S. NAIRR pilot (NSF-led, launched January 2024, with 10-plus agencies and 25-plus partners) provides shared compute, data, and tools — roughly 3.77 exaFLOPS in its initial resources, though CSET notes this is “a fraction of what is available to industry.”
• Public evaluation infrastructure. The UK AI Safety Institute (established November 2023, renamed the AI Security Institute in February 2025) has evaluated more than 30 state-of-the-art AI models and open-sourced its Inspect evaluation platform (May 2024), now a common substrate across national institutes. But the Ada Lovelace Institute stresses that the institute is “a research body, not a regulator”: it cannot compel model submissions, block a dangerous model, or intervene once real-world harm occurs, relying instead on voluntary cooperation. That gap is itself an argument for stronger, mandated public infrastructure.
The case against — and how to manage it
• Surveillance and exclusion. Aadhaar is the cautionary tale: biometric authentication failures excluded elderly, rural, and manual-labour populations from food rations; critics warn that centralisation enables surveillance, and that its export to states with weaker judicial oversight intensifies the risk. Public infrastructure can become coercive infrastructure.
• Capture and capacity. Cohen warns that information-era regulatory models are opaque to outside observation and highly prone to capture. Governments frequently lack the compute, talent, and technical depth to build and run frontier systems — and the “sovereign AI” label is sometimes, in Schneier’s words, “a marketing scheme for big tech companies looking to sell to governments.”
• Innovation chilling. ITIF and Cato argue that the precautionary principle “generates hypothetical worst-case scenarios” and that an innovation principle — permit innovation, add guardrails only where necessary — better serves welfare. Cato defends Section 230 as “part of the solution.”
• Rights and effectiveness. The UK Online Safety Act experience shows that proactive mandates can conflict with encryption and privacy, and can be circumvented (VPNs), undermining both efficacy and legitimacy.
Recommendations
A decision framework: when is a proactive or public-infrastructure approach warranted?
Apply four tests. A proactive, “by design” or public-infrastructure approach is justified to the extent that harms score high on the following:
1. Severity and irreversibility — is the harm catastrophic or non-compensable after the fact (for example, CSAM, bio- or cyber-risks, systemic financial or electoral shocks)? If so, favour ex ante.
2. Systemic and diffuse character — is the harm spread across millions with no single identifiable victim–defendant pairing (for example, algorithmic amplification, disinformation)? Ex post litigation is structurally inadequate; favour design mandates.
3. Market under-provision of a public good — will the private market structurally fail to provide it (for example, interoperable age assurance, provenance standards, independent model evaluation, shared research compute)? Favour public infrastructure or DPI.
4. Feasibility of prevention by design — can the harm actually be engineered out or substantially reduced at the design layer? If so, mandate it; if not, rely on ex post liability and monitoring.
Where a domain scores high on all four tests, government should facilitate or build. Where it scores low, ex post liability and light-touch or self-regulation suffice. Applying this, the domains that most clearly justify a proactive, government-facilitated approach are: child online safety and age assurance (high on all four); content provenance, authenticity, and synthetic-media detection (systemic, market-under-provided, partly design-soluble); identity and anti-fraud (systemic, public-good); independent model-safety evaluation(market-under-provided, catastrophic-risk relevant); AI incident reporting and monitoring (systemic); and critical-infrastructure cybersecurity (severe and irreversible). Domains such as general consumer chatbots, productivity tools, and most low-risk applications score low and are best left to ex post liability plus targeted rules.
Staged actions for policymakers and regulators
Stage 1 — immediate
• Reform intermediary liability so that safe harbours do not extend to AI-generated content or to design and amplification choices, while preserving protection for genuine hosting.
• Mandate “safety by design” risk-assessment-and-mitigation duties (the DSA Article 34–35 / eSafety model) for large platforms and high-risk AI, with meaningful penalties.
• Fund and empower public model-evaluation infrastructure (AI Safety / Security Institutes) and give them statutory access powers so they no longer depend on voluntary cooperation.
Stage 2 — 12 to 24 months
• Build public, privacy-preserving, interoperable age-assurance infrastructure as a public good, rather than leaving each platform to build brittle, circumventable systems.
• Mandate content provenance (C2PA Content Credentials) for AI outputs and government communications, and fund open watermarking and detection research — recognising that no single method suffices and a layered approach is needed.
• Stand up AI incident-reporting systems modelled on aviation and pharmacovigilance.
• Establish or scale public compute (a full-scale NAIRR) for safety research and academia.
Stage 3 — structural
• Pilot regulatory markets and Independent Verification Organizations to scale technical oversight.
• Consider narrowly scoped public-option foundation models for public-sector use (health, education, government services), under strict governance.
Governance guardrails
Any proactive build must be accompanied by: open standards and open source where possible; independent, well-resourced oversight; strict purpose limitation and data minimisation (learning from Aadhaar); non-biometric fallbacks and anti-exclusion audits; transparency and public reporting; and sunset and review clauses so that mandates adapt over time.
Benchmarks that would change the recommendation
• If independent audits show “by design” mandates are being met without measurable rights harms and with falling incident rates, expand them.
• If age-assurance or provenance systems show high circumvention or privacy leakage in post-implementation review, pause and redesign rather than expand.
• If a public compute or model effort cannot reach a usable capability threshold, or shows capture, wind it down in favour of procurement plus regulation.
Caveats
• Evidence on social-media causation is contested. The Surgeon General’s “three hours / double the risk” figure is an association (drawn from Riehm et al., 2019), not proven causation, and the advisory itself flags evidence gaps. Meta disputes the framing of its internal research, noting that the “one in three” figure applies to teen girls already experiencing body-image issues. The harm case is strong but not settled.
• Some headline numbers require care. NCMEC’s CyberTipline total fell from 36.2 million (2023) to about 20.5 million (2024), but this reflects a change in report “bundling,” not reduced abuse; the 2023 figure is the cleaner recent-year headline.
• Many proactive initiatives are recent, partial, or aspirational. NAIRR is a pilot; “Current AI” has a funding target not yet realised; AI Safety Institutes lack statutory powers; and regulatory markets remain largely proposals (SB 813). Their maturity should not be overstated.
• The literature is genuinely divided between the precautionary / ex ante camp and the innovation-principle / ex post camp. This report takes the position that a hybrid, domain-tiered approach is correct, but reasonable experts disagree on exactly where the lines fall.
• Publication-date artefacts. Several sources carry 2026 datelines (for example, the Bruegel policy brief, the Jurimetrics publication of Hadfield & Clark, and U.S. jury verdicts against Meta and YouTube reported in early 2026); these are recent as of this report’s date and should be re-verified against primary sources before formal citation.
Sources
All sources consulted in preparing this report, with associated URLs.
1. “Experimentalism beyond ex ante regulation: A law and economics perspective on AI regulatory sandboxes” — Cambridge Forum on AI: Law and Governance. https://www.cambridge.org/core/journals/cambridge-forum-on-ai-law-and-governance/article/experimentalism-beyond-ex-ante-regulation-a-law-and-economics-perspective-on-ai-regulatory-sandboxes/62F52DE3DDA932E4004CE3AD8B1E0E50
2. “The right balance: how to fix European Union artificial intelligence regulation” — Mario Mariniello, Bruegel (2026). https://www.bruegel.org/policy-brief/right-balance-how-fix-european-union-artificial-intelligence-regulation
3. “Licensing high-risk artificial intelligence: Toward ex ante justification for a disruptive technology” — Computer Law & Security Review (ScienceDirect). https://www.sciencedirect.com/science/article/pii/S0267364923001097
4. “Can there be responsible AI without AI liability?” — International Journal of Law and Information Technology, Oxford Academic. https://academic.oup.com/ijlit/article/doi/10.1093/ijlit/eaae021/7758252
5. “Computing Power and the Governance of Artificial Intelligence” — Anderljung, Barnhart et al. (arXiv 2402.08797). https://arxiv.org/pdf/2402.08797
6. EU AI Act proposal — European Commission / EUR-Lex (CELEX:52021PC0206). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52021PC0206
7. “Beyond the Search Bar: Generative AI’s Section 230 Tightrope Walk” — American Bar Association. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-november/beyond-search-bar-generative-ai-section-230-tightrope-walk/
8. “Section 230 and AI-Driven Platforms” — The Regulatory Review. https://www.theregreview.org/2026/01/17/seminar-section-230-and-ai-driven-platforms/
9. “The Future of Online Expression and Innovation Depends on Robust Section 230 Protections” — Cato Institute. https://www.cato.org/policy-analysis/future-online-expression-innovation-depends-robust-section-230-protections
10. “Section 230 is Not Fit for AI” — Brown Political Review. https://brownpoliticalreview.org/section-230-is-not-fit-for-ai/
11. “AI and digital governance: Exploring platform liability” — IAPP. https://iapp.org/news/a/ai-and-digital-governance-exploring-platform-liability
12. “Section 230 and its Applicability to Generative AI” — Center for Democracy and Technology. https://cdt.org/insights/section-230-and-its-applicability-to-generative-ai-a-legal-analysis/
13. “Beyond Section 230: Principles for AI Governance” — Harvard Law Review. https://harvardlawreview.org/print/vol-138/beyond-section-230-principles-for-ai-governance/
14. “Where’s the Liability in Harmful AI Speech?” — Volokh, Lemley & Henderson (arXiv 2308.04635). https://arxiv.org/pdf/2308.04635
15. “The Global Rise of Public AI” — Ganesh Sitaraman et al., Vanderbilt Policy Accelerator (May 2025). https://cdn.vanderbilt.edu/vu-URL/wp-content/uploads/sites/412/2025/05/05220054/The-Global-Rise-of-Public-AI.pdf
16. “The Tech Investment We Should Make Now to Avoid A.I. Disaster” — Schneier, Farrell & Sanders, Slate (2023). https://slate.com/technology/2023/04/ai-public-option.html
17. “How public AI can strengthen democracy” — Nathan Sanders, Bruce Schneier & Norman Eisen, Brookings (2024). https://www.brookings.edu/articles/how-public-ai-can-strengthen-democracy
18. “Public AI: Infrastructure for the Common Good” — Public AI Network / Berkman Klein. https://cyber.harvard.edu/story/2024-08/public-ai
19. “Bernie Sanders’ AI Sovereign Wealth Fund Plan” — Schneier on Security. https://www.schneier.com/blog/archives/2026/06/bernie-sanders-ai-sovereign-wealth-fund-plan.html
20. “Safety by Design” (principles, foundations, FAQ) — Australian eSafety Commissioner. https://www.esafety.gov.au/industry/safety-by-design
21. “What is Safety by Design?” — SafeDigital / Digital Safe Hub. https://digitalsafehub.org/articles/safety-by-design
22. “To protect kids online, don’t ban them from social media. Regulate design.” — EPIC. https://epic.org/to-protect-kids-online-dont-ban-them-from-social-media-regulate-design/
23. “Social Media Bans Fail to Protect Children” — CEPA. https://cepa.org/article/social-media-bans-fail-to-protect-children/
24. “Social Media and Harm to Children” — Ethics & Public Policy Center. https://eppc.org/publication/social-media-and-harm-to-children/
25. “Regulate Companies, Not Children” — Tech Policy Press. https://www.techpolicy.press/regulate-companies-not-children/
26. “More than half of social media child safety features aren’t working, per report” — Scripps News. https://www.scrippsnews.com/science-and-tech/more-than-half-of-social-media-child-safety-features-arent-working-per-report
27. “Social Media and Youth Mental Health: The U.S. Surgeon General’s Advisory” — Office of the Surgeon General / HHS (2023). https://www.hhs.gov/sites/default/files/sg-youth-mental-health-social-media-advisory.pdf
28. “Surgeon General: Why I’m Calling for a Warning Label on Social Media Platforms” — Vivek H. Murthy, The New York Times (17 June 2024). https://www.nytimes.com/2024/06/17/opinion/social-media-health-warning.html
29. “Facebook Knows Instagram Is Toxic for Teen Girls, Company Documents Show” — Wells, Horwitz & Seetharaman, The Wall Street Journal (14 Sept. 2021). https://www.wsj.com/articles/facebook-knows-instagram-is-toxic-for-teen-girls-company-documents-show-11631620739
30. “What Our Research Really Says About Teen Well-Being and Instagram” — Meta Newsroom. https://about.fb.com/news/2021/09/research-teen-well-being-and-instagram/
31. CyberTipline Data — National Center for Missing & Exploited Children (NCMEC). https://www.missingkids.org/cybertiplinedata
32. “Decoding the Indian data governance model: Relooking at Aadhaar” — ScienceDirect. https://www.sciencedirect.com/science/article/pii/S2590291125001354
33. “Digital Public Infrastructure as a Catalyst for Private Sector Innovation” — ORF America. https://orfamerica.org/newresearch/dpi-catalyst-private-sector-innovation
34. “Digital public infrastructure” / “India Stack” — Wikipedia. https://en.wikipedia.org/wiki/Digital_public_infrastructure · https://en.wikipedia.org/wiki/India_Stack
35. “Public Infrastructure and Private Surveillance in India’s Aadhaar System” / “The Aadhaar Paradox” — Tech Policy Press. https://www.techpolicy.press/public-infrastructure-and-private-surveillance-in-indias-aadhaar-system/
36. “Digital Public Infrastructure Through an Open Government Lens” — AfricLaw. https://africlaw.com/2026/02/11/digital-public-infrastructure-through-an-open-government-lens/
37. “Lessig’s modalities of regulation” — Bietti, MediaLaws. https://www.medialaws.eu/wp-content/uploads/2017/01/1.2017-Bietti.pdf
38. “Code and Other Laws of Cyberspace” (Code is Law) — Lawrence Lessig, via Stanford CS project pages. https://cs.stanford.edu/people/eroberts/cs181/projects/2010-11/CodeAndRegulation/about.html
39. “Regulatory Markets: The Future of AI Governance” — Gillian K. Hadfield & Jack Clark, Jurimetrics 65:195–240 (2026); arXiv 2304.04914. https://arxiv.org/abs/2304.04914
40. “Can a market-based regulatory framework help govern AI?” — Schwartz Reisman Institute, University of Toronto. https://srinstitute.utoronto.ca/news/co-designing-regulatory-markets-for-ai
41. Gillian K. Hadfield — policy & publications — gillianhadfield.org. https://gillianhadfield.org/policy
42. “Anticipatory regulation” & “’Anticipatory regulation’ in an age of disruption” — Nesta. https://www.nesta.org.uk/feature/innovation-methods/anticipatory-regulation/ · https://media.nesta.org.uk/documents/Renewing_regulation_v3.pdf
43. “Regulating for the future: OECD Regulatory Policy Outlook 2025” & “Framework for Anticipatory Governance of Emerging Technologies” (STI Policy Papers No. 165, 2024) — OECD. https://www.oecd.org/en/publications/oecd-regulatory-policy-outlook-2025_56b60e39-en/full-report/regulating-for-the-future_e948d334.html
44. “How anticipatory governance can lead to AI policies that stand the test of time” — OECD.AI. https://oecd.ai/en/wonk/how-anticipatory-governance-can-lead-to-ai-policies-that-stand-the-test-of-time
45. “The evolution of UK online governance” — Journal of International Law of Information Technology (Taylor & Francis). https://www.tandfonline.com/doi/full/10.1080/13600869.2026.2654234
46. “The current state of the UK online safety regime: Ofcom’s evolving role under the Online Safety Act 2023” — Taylor Hampton. https://taylorhampton.co.uk/the-current-state-of-the-uk-online-safety-regime-ofcoms-evolving-role-under-the-online-safety-act-2023/
47. “UK Online Safety Act” — PwC. https://www.pwc.com/us/en/services/consulting/cybersecurity-risk-regulatory/library/tech-regulatory-policy-developments/uk-online-safety-act.html
48. “Online Safety Regulation Increases Privacy Risk: Evidence from the UK Online Safety Act” — arXiv 2606.05273. https://arxiv.org/html/2606.05273v1
49. “Why The UK’s Online Safety Blunder Wouldn’t Survive In The US” — Tech Policy Press. https://www.techpolicy.press/why-the-uks-online-safety-blunder-wouldnt-survive-in-the-us/
50. “AI Risk Management Framework” (AI RMF 1.0) — NIST. https://www.nist.gov/itl/ai-risk-management-framework
51. Content Credentials whitepaper — Coalition for Content Provenance and Authenticity (C2PA). https://c2pa.org/wp-content/uploads/sites/33/2025/10/content_credentials_wp_0925.pdf
52. “Privacy, Identity and Trust in C2PA” — World Privacy Forum. https://worldprivacyforum.org/posts/privacy-identity-and-trust-in-c2pa/
53. “AI Watermarking 2026: C2PA, Metadata and Fingerprinting” — AI Buzz. https://aibuzz.blog/ai-watermarking-vs-metadata-vs-fingerprinting/
54. “Making sense of the UK’s AI Security Institute” — Ada Lovelace Institute. https://www.adalovelaceinstitute.org/feature/aisi/
55. “Early lessons from evaluating frontier AI systems” — UK AI Security Institute. https://www.aisi.gov.uk/blog/early-lessons-from-evaluating-frontier-ai-systems
56. “The NAIRR Pilot: Estimating Compute” — CSET (Georgetown). https://cset.georgetown.edu/article/the-nairr-pilot-estimating-compute/
57. “How the National Artificial Intelligence Research Resource can pilot inclusive AI” — Brookings. https://www.brookings.edu/articles/how-the-national-artificial-intelligence-research-resource-can-pilot-inclusive-ai/
58. NAIRR Pilot — U.S. National Science Foundation (NSF). https://www.nsf.gov/geo/updates/national-artificial-intelligence-research-resource-nairr
59. “The AI Seoul Summit” — CSIS. https://www.csis.org/analysis/ai-seoul-summit
60. “Key Outcomes of the AI Seoul Summit” — techUK. https://www.techuk.org/resource/key-outcomes-of-the-ai-seoul-summit.html
61. “What were the outcomes of the Paris AI Action Summit?” — techUK / wired-gov. https://www.wired-gov.net/wg/news.nsf/articles/what+were+the+outcomes+of+the+paris+ai+action+summit+17022025112500
62. “The Paris Summit: Au Revoir, global AI Safety?” — European Policy Centre. https://www.epc.eu/publication/The-Paris-Summit-Au-Revoir-global-AI-Safety-61ea68/
63. “The Pacing Problem, the Collingridge Dilemma & Technological Determinism” — Adam Thierer, Technology Liberation Front. https://techliberation.com/2018/08/16/the-pacing-problem-the-collingridge-dilemma-technological-determinism/
64. “Ten Ways the Precautionary Principle Undermines Progress in Artificial Intelligence” — ITIF. https://itif.org/publications/2019/02/04/ten-ways-precautionary-principle-undermines-progress-artificial-intelligence/
65. “The innovation governance dilemma: Alternatives to the precautionary principle” — Technology in Society (ScienceDirect). https://www.sciencedirect.com/science/article/abs/pii/S0160791X2030751X
66. “The Collingridge Dilemma and Its Implications for Regulating Financial and Economic Crime in the UK” — Laws (MDPI). https://www.mdpi.com/2075-471X/15/1/5
67. “The Regulatory State in the Information Age” & “Law for the Platform Economy” — Julie E. Cohen, Georgetown Law / SSRN. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2714072 · https://lawreview.law.ucdavis.edu/sites/g/files/dgvnsk15026/files/media/documents/51-1_Cohen.pdf
68. Regulation (EU) 2022/2065 (Digital Services Act), Articles 28, 34, 35, 74 — EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065
69. “Commission publishes guidelines on the protection of minors” (DSA Art. 28) — European Commission. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors


