Where current rules fall short
The Rapid Pace of Deployment vs. Regulatory Guardrails
Why this is an issue
New technology reaches millions of people within months. Laws take years to write,
pass, and enforce. In that gap, technology companies are largely responsible for
regulating themselves, and the public becomes the testing ground. Harms are often
discovered only after they have already happened, and design changes are made only
when companies are forced to make them.
Many of the laws that do exist were passed in response to harms that had already
occurred, harms that were foreseeable and could have been prevented. The United
States still has no comprehensive federal AI law and no general federal privacy law.
Congress considered a ten-year ban on enforcing state AI laws in 2025, which the
Senate removed by a vote of 99 to 1
(H.R. 1, 119th Congress).
In December 2025, the President signed
Executive Order 14365
directing the Attorney General to challenge state AI laws in court. Even Colorado’s
first-in-the-nation AI law
(SB 24-205) was delayed twice and
then repealed and replaced with a narrower version before it ever took effect
(SB 26-189).
Social media offers a preview of what happens when a powerful technology is deployed
at scale and left to regulate itself. AI is following the same path, only faster.
The harms
-
Products designed to be hard to put down. In August 2026, Meta agreed
to pay up to $17.1 billion to settle claims by 47 states, the District of Columbia,
and U.S. territories that it designed Facebook and Instagram to addict young users and
misled the public about the risks. A federal judge approved the settlement on
August 26, 2026. Meta denied wrongdoing
(WBUR, August 2026).
Years earlier, internal company research on the platforms’ effects on teens had been
made public by a former employee in testimony to the U.S. Senate
(Senate Commerce Committee, October 2021).
The risks were known long before anything was done about them.
-
A youth mental health crisis. In 2023 the U.S. Surgeon General warned
that there was not enough evidence to conclude social media is safe for children and
adolescents, and that it poses a meaningful risk of harm to their mental health
(Surgeon General’s Advisory, 2023).
-
Chatbots and children. In January 2026, Google and Character.AI agreed
to settle lawsuits from families in Florida, Colorado, New York, and Texas who alleged
that the company’s chatbots harmed their children, including contributing to the suicide
of a 14-year-old
(Associated Press, January 2026).
Character.AI barred users under 18 from open-ended chats only after these cases became
public. Similar lawsuits against OpenAI, including one brought by the family of a
16-year-old, are ongoing
(Raine v. OpenAI).
-
No federal rules for kids beyond age 13. The main federal law protecting
children online, the
Children’s Online Privacy Protection Act,
covers only children under 13 and focuses on data collection, not design. The Kids
Online Safety Act was first introduced in 2022. As of fall 2026, versions have advanced
in both chambers, but none has become law
(Congressional Research Service).
-
Bias built into automated decisions. A widely used health care algorithm
was found to systematically underestimate the needs of Black patients because it used past
medical spending as a stand-in for illness
(Obermeyer et al., Science, 2019).
Amazon abandoned an AI recruiting tool after it learned to downgrade résumés that
mentioned women’s organizations
(Reuters, 2018).
A tenant screening company settled a class action alleging its scoring system unfairly
rejected Black and Hispanic renters who used housing vouchers
(Louis v. SafeRent Solutions).
These systems reproduce the patterns in the historical data they learn from, and the
people affected usually never know an algorithm was involved.
-
Mass data collection. Data brokers buy, combine, and sell detailed
profiles of nearly every American, largely without their knowledge
(FTC report on data brokers, 2014).
This is covered in more detail below.
Each of these harms grew out of the same conditions: technology deployed faster than
it could be studied, and self-regulation that failed to protect the people using it.
The sections that follow look at how those conditions are playing out with AI.
Deepfakes, Harmful Content, Consent Violations
Why this is an issue
AI tools can now produce realistic fake images, video, and voices of real people in
seconds, at almost no cost, and with no special skill. The people shown never agreed to
it, and most viewers cannot tell the difference. Once fake content spreads, it is nearly
impossible to recall. Every copy, download, and reshare extends the harm.
This did not happen by accident. These tools were released to the public without clear
limits on acceptable use. Companies can build systems that refuse harmful requests and
test them so they cannot be easily manipulated. Some have chosen not to.
The harms
-
Sexual images of real people made without consent. In January 2026,
users of the Grok chatbot on X were able to generate and post sexualized images of real
women and, in some cases, children, simply by asking the tool to edit their photos.
Regulators in the United Kingdom opened a formal investigation, Indonesia and Malaysia
blocked the tool, and California’s attorney general opened an investigation
(Al Jazeera, January 2026).
For the people targeted, the harm is a violation of dignity and bodily autonomy that
can follow them into their schools, workplaces, and relationships.
-
The burden falls on victims. The federal
TAKE IT DOWN Act
requires platforms to remove nonconsensual intimate images within 48 hours, but only
after the person shown finds the image and reports it. Someone who never learns an image
exists has no remedy, and 48 hours is more than enough time for content to be copied
many times over. The law does not require the companies that build these tools to
prevent the images from being created in the first place.
-
Fraud that exploits trust. The FBI has warned that criminals use AI to
clone the voices of family members in distress and to produce fake identification
documents
(FBI Public Service Announcement, December 2024).
When a familiar voice on the phone can no longer be trusted, every call becomes a
potential scam.
-
Disinformation and elections. In 2016, a coordinated Russian campaign
used fake accounts and emotionally charged memes to divide American voters on social
media
(Senate Intelligence Committee, Vol. 2).
That content was made by people. AI now makes the same tactics cheaper, faster, and
more convincing
(Helmus, RAND, 2022).
Before New Hampshire’s January 2024 primary, voters received robocalls using an AI
imitation of President Biden’s voice telling them not to vote; the FCC fined the
consultant responsible $6 million
(FCC).
-
The loss of a shared reality. The deeper harm is not that people believe
every fake, but that they stop believing anything. Most people who share false
information are not trying to deceive; they simply do not stop to think about accuracy
before sharing
(Pennycook et al., Psychological Science, 2020).
As fake content becomes more realistic and more common, the work of sorting truth from
fiction falls on each individual, and most people have neither the time nor the tools
to do it. Researchers also warn of a “liar’s dividend”: when anything could be fake,
people caught on real video can simply claim it was fabricated
(Chesney & Citron, California Law Review, 2019).
The result is confusion, distrust of once-reliable sources, and deeper division.
-
Children growing up in a synthetic culture. Today’s children encounter
AI-generated videos, voices, and images every day, often without knowing it. Adults who
lived through the rise of online misinformation had years of experience to draw on when
judging what is real. Children do not have that framework, and no one yet knows how
growing up surrounded by fake content will affect how they learn to think.
Cognitive Shifts and Information Processing
Why this is an issue
Most AI chatbots are designed to give finished answers quickly and to keep people
engaged. That is useful for getting work done, but people build knowledge and judgment
through the effort of working problems out for themselves. When that effort is handed
to a machine, something is lost. Many chatbots are also built to agree with the user,
which offers validation rather than honest feedback.
These tools are already in classrooms, workplaces, and homes, while research on how
they affect thinking, memory, and development is just beginning. As with social media,
we are likely to learn the full effects only after they have already occurred.
The harms
-
Learning that does not stick. In a study of nearly 1,000 high school math
students, those given unrestricted access to GPT-4 did better on practice problems, but
when the tool was removed they scored 17% lower on exams than students who never had it.
Students used the AI as a crutch rather than a tutor
(Bastani et al., Proceedings of the National Academy of Sciences, 2025).
For a student, this means appearing to master material while never actually building
the skill.
-
Less mental engagement and memory. An MIT Media Lab study of 54 adults
found that those who wrote essays with ChatGPT showed the lowest brain engagement of
three groups, and most could not recall what they had written. The study is small and
was released before peer review
(Kosmyna et al., 2025).
Even so, it points to a real risk: work completed without thinking is work that is not
remembered or understood.
-
Less questioning of answers. A survey of 319 knowledge workers found that
the more people trusted AI, the less critically they reported thinking about its answers
(Lee et al., Microsoft Research and Carnegie Mellon University, 2025).
AI systems make mistakes. People who stop checking them will pass those mistakes along,
and over time may lose the very skills needed to catch them, including professionals
such as doctors and engineers who remain responsible when automated systems fail.
-
Emotional dependence in young people. Chatbots designed to act as friends
or companions are available at any hour and never disagree. Young people develop
emotional intelligence and relationship skills through real conversations, including
conflict, with other people. Heavy reliance on a chatbot can crowd that out. In
September 2025, the Federal Trade Commission ordered seven companies to explain how
their companion chatbots affect children and teens
(FTC).
The most serious outcomes are described in the lawsuits above.
-
A weaker defense against misinformation. The skills that protect people
from fake content, such as questioning sources, checking facts, and tolerating
uncertainty, are the same skills that weaken when thinking is outsourced. A population
that relies on AI for answers is more exposed to whatever those systems, or the people
manipulating them, produce.
Surveillance, Data Fusion, Privacy Implications
Why this is an issue
Nearly everything people do now leaves a digital record: where they go, what they buy,
what they search, who they talk to, how they drive, and how they sleep. Phones, apps,
cars, smart watches, store loyalty programs, and cameras collect this information
constantly. Because personal data is profitable, companies have every reason to collect
as much as possible, and data gathered for one purpose is routinely sold and used for
others.
AI makes this data far more powerful. It can combine scattered records into one detailed
profile, a process called data fusion, and use that profile to predict and influence
behavior. Information that seems harmless on its own can reveal a great deal when
combined. Just three facts, a ZIP code, birth date, and sex, are enough to uniquely
identify most Americans
(Sweeney, Carnegie Mellon University, 2000).
So-called anonymous data often is not anonymous at all.
The data collected from us is also what trains the AI systems that data centers are
built to run. Without that data, there would be no need for these facilities.
The harms
-
The myth of meaningful consent. Privacy policies are long, complex, and
written for lawyers. Most people accept them without reading because there is no
“decline and continue” option: either agree or go without the service. Consent becomes a
legal checkbox that shifts responsibility onto the individual. It also cannot exist at
all for cameras in public places, because going outside means being recorded. The
burden of protecting privacy falls on individuals who cannot possibly keep up.
-
A hidden industry selling our lives. Data brokers collect and sell
information about nearly every American, including inferences about health, income,
and religion, with little transparency
(FTC, 2014).
The FTC sued the broker Kochava for selling location data that could track people to
health clinics, places of worship, and shelters
(FTC v. Kochava).
-
Profiles that decide what we can have. These records feed scores that
shape people’s lives without their knowledge. General Motors shared drivers’ precise
location and driving behavior with companies that sold it to insurers, and some drivers
saw their rates rise; the FTC barred the practice for five years
(FTC, January 2025).
Tenant screening scores determine who can rent a home. Credit scores determine who can
borrow. The FTC found that companies use personal data such as location, browsing
history, and demographics to set individualized prices
(FTC surveillance pricing study, January 2025).
Taken together, our digital footprint becomes a profile that can limit where we live,
what we pay, and what opportunities we are offered, often with errors we cannot see or
correct.
-
Cameras everywhere. Flock Safety, which sells AI-powered license plate
cameras, has contracts with more than 5,000 law enforcement agencies. Its cameras record
the plate, make, model, and color of passing cars. Communities across the country have
canceled contracts amid concerns that the data was being searched on behalf of federal
immigration authorities and shared beyond what state laws allow
(NPR, February 2026).
A network of cameras that logs every trip, kept indefinitely and shared widely, amounts
to a record of where everyone goes.
-
Errors with serious consequences. In 2020, Detroit police arrested Robert
Williams in front of his family after a facial recognition system wrongly matched him to
shoplifting footage
(ACLU).
A federal study of 189 facial recognition algorithms found that many falsely matched some
demographic groups more often than others
(NIST, 2019).
The FTC banned Rite Aid from using facial recognition for five years after its system
falsely flagged customers as shoplifters
(FTC, 2023).
-
Tested on the poor first. New surveillance tools are often tried first on
people with the least power to refuse them, such as people receiving public benefits,
living in public housing, or living in heavily policed neighborhoods
(Eubanks, Automating Inequality, 2018).
By the time those tools spread to everyone else, they have already come to feel normal,
and being watched becomes a “reasonable expectation.” Surveillance that would once have
caused outrage arrives quietly, one accepted step at a time.
The harm is not only that information is collected. It is that people lose control over
how they are seen and judged, and that those who hold the data gain power over those who
do not.
Corporate Accountability & Ethical Governance
Why this is an issue
Every harm described on this page traces back to choices made by companies: how a
product was designed, what it was allowed to do, what data it collected, and how quickly
it was released. Technology is not a force of nature that evolves on its own. People
design it, and it becomes exactly what they allow it to be. Treating its harms as
inevitable shifts responsibility away from the companies that make these decisions.
The companies that build AI hold enormous wealth and power, including control over the
data centers that run these systems. With that power comes an ethical obligation to act
in the interest of the people and communities affected by their products. Slow
lawmaking is no excuse for failing to meet it. A company does not need a law to tell it
not to cause foreseeable harm.
Nor is there a lack of ethical guidance. Researchers who study people have followed clear
rules for decades, built on respect for persons, informed consent, and avoiding harm
(The Belmont Report, 1979).
Every student, professor, and institution that collects data from human subjects is held
to those standards. The commercial collection and use of the same data is, by contrast,
largely a free-for-all. Meanwhile, AI ethics principles published by companies and
organizations tend to be broad, hard to apply to real decisions, and unenforceable
(Whittlestone et al., 2019).
A pattern of knowing and proceeding
-
Known risks, delayed action. Meta’s internal research on how its platforms
affected teens was public by 2021, years before the company agreed to the product changes
in its 2026 settlement. When a company knows a design causes harm and proceeds anyway,
that is not an oversight. It is a choice, and it should carry responsibility for the
harm that follows.
-
Safety added after the damage. Character.AI restricted minors only after
lawsuits over teen deaths. Grok’s image tool was limited only after an international
outcry. In each case, safeguards that could have been built in from the start were
added after people had already been hurt.
-
Warnings from the inside. In 2024, current and former employees of leading
AI companies published an open letter saying the companies have strong financial
incentives to avoid effective oversight, and that employees are among the few people
able to hold them accountable
(“A Right to Warn about Advanced Artificial Intelligence”).
-
Communities left out. The same pattern shows up in how AI infrastructure
is built. When a community learns about a data center only after land has been bought,
often under nondisclosure agreements, it has not been asked for its consent. It has been
informed of a decision already made. See
Law & Process and the
Bedington and
Kearneysville project pages.
Moving fast and breaking things has produced harms to children, to privacy, to public
trust, and to communities. Most of these harms were foreseeable. Until companies are held
responsible for the effects of their products, and until they accept responsibility
without being forced to, the cost of this technology will continue to fall on the
people with the least say in how it is built.