Existing law addresses AI’s harms—and learns from real cases, not hypothetical ones.
Legislators in Washington and dozens of state capitals are racing to legislate away AI’s risks, even as Brussels delays parts of its own sweeping AI Act. Yet, AI promises earlier disease detection, faster drug discovery, better fraud detection, and personalized learning. Five considerations argue for going slow on new rules—and for first asking which harms the laws we already have can’t reach.
First, new technologies follow predictable panic cycles. Printing, photography, motion pictures, automobiles and airplanes each set off alarms. The Information Technology and Innovation Foundation has charted the cycle: initial unconcern, rising panic, peak hysteria, then fading fears as risks are addressed and the unfamiliar becomes familiar. AI is now climbing the rising slope. True to form, an April op-ed in the Wall Street Journal by Sen. Bernie Sanders (I–Vt.) was headlined “AI Is a Threat to Everything the American People Hold Dear”; a popular AI book is titled If Anyone Builds It, Everyone Dies. Many feared harms never materialize, while real risks often turn out to be ones few foresaw—which is why anticipatory rules often miss the risks that matter.
Second, risks attract more attention and are more memorable than benefits. News outlets select for threats, and the mind recalls them more readily than gains. Deepfakes and displaced workers make headlines, yet tumors caught early by algorithms or new job categories that didn’t exist five years ago go unnoticed. A fair cost-benefit analysis of AI must correct for that asymmetry.
Third, regulators themselves face asymmetric incentives. An approved drug that causes a death produces hearings and headlines. A drug delayed or never approved produces no comparable scandal, because the patients it might have saved are invisible. Safety agencies and advocacy groups are funded and organized to prevent visible harms, while the vast but diffuse beneficiaries of faster innovation remain largely unfunded and unorganized. Political economist Mancur Olson explained why: small, concentrated interests routinely prevail over much larger, dispersed ones. Concentrated interests include industry giants, which can absorb compliance costs that sink or scare off startups, turning regulation into a barrier to entry.
Consider drones. Federal Aviation Administration rules keep them within their operators’ sight absent a waiver; a rule to ease that limit, proposed in 2025, has yet to take effect. Drones could be delivering medicine and inspecting pipelines far more widely, but the costs of seeking approval are more readily absorbed by giants such as Amazon and Alphabet than by startups. Alas, a few large operators are also easier for regulators to oversee than a messy ecosystem of challengers. If today’s regulatory apparatus had existed when the Wright brothers first flew, how long would commercial aviation have taken to get off the ground?
Fourth, regulations have unintended consequences. Economist Sam Peltzman famously argued in 1975 that drivers made safer by seat belts and other mandated equipment drove more aggressively, offsetting much of the gain. Overregulating nuclear power, among the safest energy sources per unit of electricity, keeps more-harmful fossil fuels burning.
Fifth, and most important, we don’t have to anticipate every AI harm. AI is already regulated. Generally applicable law regulates conduct and harm, not the technology used to produce them. There is no AI exemption. Fraud is fraud, with or without AI. Negligence law applies to both AI developers and deployers. In 2024, for example, a British Columbia tribunal held Air Canada negligent over a refund policy its chatbot invented, rejecting the airline’s argument that the chatbot was responsible for its own words. Courts are also weighing product-liability claims—design defect, failure to warn—against AI makers.
Warranties and terms of service assign responsibility when AI fails. The Federal Trade Commission polices deceptive AI claims; civil-rights, fair-housing, and fair-lending statutes govern algorithmic hiring and lending; antitrust law forbids price-fixing, whether by handshake or by algorithm; securities law reaches “AI-washing,” in which companies misrepresent their use of AI; and wire-fraud and identity-theft statutes reach deepfakes and voice cloning.
These bodies of law hold those responsible liable for harms, which gives developers strong reason to prevent them. And their application evolves case by case, drawing on thousands of judges confronting real disputes rather than hypothetical ones. As I argued in the Wall Street Journal in June about the end of Chevron deference, such distributed, on-the-ground discovery leads to better learning and decision-making than preemptive, centralized rulemaking. A comprehensive AI statute drafted amid today’s alarm could harden premature assumptions into law and constrain that learning.
If a specific danger seems to warrant a rule before anyone is hurt, lawmakers should name the danger, show why current law falls short, and tailor the remedy to fit. Otherwise, they should start with generally applicable law. When experience reveals a harm that existing law cannot reach, they will have found a real gap for legislation to fill.
Legislate in haste, and we will codify our fears rather than experience. AI’s harms will make headlines; the cures, products, and jobs that premature rules delay or preclude will not. The loss of those gains is no less real for being unseen.