Module 05

Self-regulation vs. public governance

Why relying on tech companies' goodwill is not enough and what is needed for democratic AI governance.

8 min3 resources

"Move fast and break things" — Facebook's motto in its early years — summarises Silicon Valley's dominant attitude towards regulation: innovation comes first, rules later. Tech companies have promised for years to "self-regulate" through ethical principles, internal committees and voluntary commitments. But history shows that this promise has not been kept.

Google published its "AI Principles" in 2018, committing not to develop AI for weapons, surveillance or technologies that cause harm. That same year, it signed Project Maven with the Pentagon for using AI in military drone image analysis. When employees protested, Google did not renew the contract — but not for ethical principles, rather due to public pressure. In 2020, Google fired Timnit Gebru, co-lead of its AI ethics team, after she published a paper critical of large language models. The message was clear: internal ethics holds only as long as it does not contradict commercial interests.

The problem with self-regulation is structural, not individual. Publicly traded companies have a fiduciary duty to shareholders to maximise profit. Executives who slow development for ethical reasons are replaced by those who don't. The market rewards those who arrive first, not those who arrive responsibly. In this context, internal "ethics committees" function as public relations tools (ethics washing) more than real governance mechanisms.

Public AI governance does not mean governments should control technology — it means that fundamental rules should be established democratically, not by the companies that profit from the technology. Just as we do not allow pharmaceutical companies to decide on their own whether their drugs are safe, we should not allow AI companies to decide on their own whether their systems are ethical.

Effective public governance requires four elements. First: independent authorities with technical expertise and real sanctioning power. Second: transparency obligations that allow independent verification (publishing principles is not enough, audits must be permitted). Third: enforceable rights for affected people (not just the right to know, but the right to challenge and obtain remedies). Fourth: public funding of independent AI research, to reduce dependence on corporate research.

An interesting model is multi-stakeholder governance: roundtables where government, industry, academia, civil society and representatives of affected communities sit together. It is not perfect — power is often skewed in favour of industry — but it is more democratic than pure self-regulation.

Key takeaways

  • Tech company self-regulation has failed: internal ethics yields to commercial interests
  • The problem is structural: the market rewards first movers, not the most responsible
  • Public governance requires independent authorities, transparency, enforceable rights and public research
  • Multi-stakeholder governance is more democratic, if imperfect

Reflection prompt

Do you think tech companies are capable of self-regulating on AI? If you had to design an AI governance authority for your country, who would you include? Only technicians? Also philosophers, sociologists, citizen representatives?

Further reading