← All news

Summit

Should AI Be Regulated? The Evidence on Both Sides

EX Future Summit · 21 August 2026

Only one in ten Americans want no AI rules. The real 2026 argument is not whether AI should be regulated but with which instrument, and at what cost.

Should AI Be Regulated? The Evidence on Both Sides

Asked plainly whether AI should be regulated, the public answers by roughly nine to one. The Ipsos Consumer Tracker found in March 2026 that just one in ten Americans think there should be no regulation at all, and that 63 percent want the federal government to ensure AI outputs do not cause harm, a figure that survives the partisan divide almost untouched at 67 percent of Democrats and 63 percent of Republicans.

That is not a close vote, and it means the interesting argument is somewhere else. The live disagreement in 2026 is about which instrument, applied at what threshold, by whom, and paid for by which firms. What has changed since this question was last fought over in public is that both sides now have measured evidence rather than predictions. The cost of regulating has been observed in company accounts. The demand for regulating has been polled repeatedly, by different houses, with results that barely move. Both sets of numbers are stronger than the rhetoric usually built on top of them, and read together they point at a problem neither camp campaigns on.

The case for regulating AI

The public is not divided on the principle

The Annenberg Public Policy Center at the University of Pennsylvania surveyed a nationally representative sample of 1,330 US adults between 17 February and 20 March 2026. Nearly two thirds, 65 percent, said government has done too little to regulate AI, against 8 percent who said too much. The bipartisan spread is the striking part: 77 percent of Democrats, 72 percent of independents and 53 percent of Republicans. Underneath sits a broader pessimism. Only 17 percent expect AI's effect on the country over the next decade to be positive, while 42 percent expect it to be negative.

Ask what people want protected and the answers get specific rather than vague. A Johns Hopkins University poll of more than 2,000 respondents in April and May 2026 found majorities for a right to reach a human instead of a machine in the settings where it matters most: 79 percent in medical care, 76 percent in legal proceedings, 74 percent in education. Three quarters want to be told when they are talking to an AI at all. These are not abstract anxieties about superintelligence. They are procedural demands, and most of them are cheap to build.

Not acting is also a decision

The strongest version of the pro-regulation argument is not about harm at all. It is about who is choosing. Viktor Mayer-Schonberger and Urs Gasser put it directly in The Regulatory Review in February 2026: waiting until the fog lifts is a bit like letting pollution run its course before starting to clean up, because not acting is not a pause but a decision that shapes the trajectory of society.

They also dispose of the objection that regulators only get one attempt. Rules are human acts that can be changed once the picture improves, and treating revision as an embarrassment rather than as the normal condition of governing anything that moves is the actual error. That reframing matters here, because most of the fear of regulating early is really a fear of regulating permanently.

Voluntary safety has no floor

On the question of who should set the standard, the polling is close to lopsided. In an AI Policy Institute survey of 1,007 likely voters conducted on 10 and 11 June 2026 and reported by NBC News, more than 60 percent of both Republican and Democratic respondents said the federal government rather than AI companies should set safety standards and then evaluate compliance with them. Most existing guardrails are currently designed and enforced by the companies themselves. The same survey found 84 percent of Democrats and 83 percent of Republicans agreeing that companies should not build systems smarter than humans until they can show they can control them.

The case against regulating AI the way it is being built

The costs stopped being predictions

The industry objection used to be a forecast. It is now an invoice. In its March 2026 statement on the AI omnibus, DIGITALEUROPE cites the European Commission's own impact assessment: an SME developing a high-risk AI system could face up to 319,000 euro in initial compliance costs plus up to 150,000 euro every year after that. A study by the German AI Association and the General Catalyst Institute puts the realistic initial figure nearer 600,000 euro once certification and dedicated staff are counted, which the statement translates into 30 to 40 percent profit erosion for a small firm.

Bruegel's June 2026 policy brief gives the proportional version, citing Haataja and Bryson: for an average AI system costing 170,000 euro to develop, compliance runs 14,623 to 29,277 euro, or 9 to 17 percent of the build. The decisive detail is not the size of that number but its shape. The requirements do not scale with the developer, so the same rule is an accounting line for one firm and an existential threat to another.

Field evidence points the same way. A Communications of the ACM analysis published on 17 August 2026 reports that in four years of autonomous driving commercialisation, compliance consumed 42 percent of the authors' budget against a cited software industry norm of 13 percent. The same piece names the mechanism worth borrowing: regulatory latency, the interval between a capability becoming technically possible and becoming deployable with acceptable legal certainty. In a fast market a twelve month delay does not postpone entry so much as cancel it. The authors also cite the French study by Aghion, Bergeaud and Van Reenen, in which firms approaching a 50-employee regulatory threshold became measurably less innovative, at an estimated cost of 5.4 percent of aggregate innovation. They are careful to say that study is not about the AI Act and does not prove anything about it, and that caution should be carried forward rather than dropped.

The human-scale version is short. Fortune reported in January 2026 that the autonomous driving startup PerceptIn budgeted 10,000 dollars for AI compliance, ended up paying more than 344,000 dollars per deployment project, more than double its entire research and development spend, and went out of business.

Fixed compliance cost is a concentration machine

This is the part of the anti-regulation case that ought to trouble regulators most, because it describes their policy failing in the direction of its own stated goal. Compliance spending is largely fixed. A global platform amortises a legal and documentation team across millions of customers; a new entrant cannot. Rules written to constrain dominant firms therefore raise the price of becoming their competitor, and the documented concentration effect of GDPR on smaller firms is the precedent nobody in Brussels disputes. A policy pursuing technological sovereignty by regulating foreign incumbents can end up removing the domestic challengers instead.

The patchwork is a separate harm from the rules

Two of the loudest numbers on this side come from interested parties, and should be read as advocacy that happens to be quantified. Shopify's policy position, published in June 2026, records more than 1,100 AI bills introduced in US state legislatures during 2025, and reports that 65 percent of American small businesses are worried about AI compliance costs, up 27 points in a year. The ACT App Association's survey of more than 1,000 technology MSMEs, conducted by TechnoMetrica across the EU, UK and US, found six in ten European and British firms reporting delayed access to frontier models and 58 percent of developers reporting regulation-driven launch delays, with more than a third stripping or downgrading features to comply.

Both organisations lobby for lighter rules. The underlying point still stands on its own logic: a firm meeting five incompatible documentation and registration regimes pays five times for one safety outcome, and no user is safer for the duplication.

Three things both sides already agree on

Conducted as a binary, this argument hides a consensus large enough to build on.

AI is not unregulated and never was. The Communications of the ACM counterpoint makes the point from the deregulatory side, and it is simply a description of the status quo: no central authority reviews each new US AI system because the FDA already oversees health applications, the SEC monitors automated trading and NHTSA handles autonomous vehicles, while product defect law, tort, contract and consumer protection powers sit underneath all of it. Anyone arguing from a blank slate is arguing about a country that does not exist. That is also the practical reason what is actually in force today rarely matches what either camp describes.

Regulate applications, not the technology. The ACM point essay proposed leaving AI research alone and regulating AI applications in transportation, medicine, politics and entertainment, with precepts that have aged unusually well: an AI is subject to the full range of law applying to its human operator, so "the AI did it" means you did it, and a system must disclose that it is not human. The same logic appears in the 2017 Issues in Science and Technology perspective quoting the Stanford One Hundred Year Study panel, whose consensus was that regulating AI in general is misguided because AI is not any one thing and the risks differ completely by domain.

Narrow procedural safeguards buy most of the safety. In Beyond the False Dichotomy, published in the Arizona State Law Journal in 2026, Maarten Herbosch argues that both extremes, comprehensive value-driven regulation and hands-off innovation policy, end up undermining their own aims, and proposes a Pareto principle instead: targeted procedural measures, robust documentation and clear accountability, anchored in legal regimes that already exist, capture most of the available safety at a small fraction of the cost.

The real disagreement is ex ante versus ex post

Strip away the tribal framing and one genuine technical question remains, which Bruegel states more clearly than anyone ranking for this phrase. Ex ante regulation requires conformance before deployment. Ex post regulation relies on liability and enforcement after an incident. Ex ante is preferable when harm is large or irreversible and the regulator can predict how it arises. Ex post costs less, distorts innovation less, and generates real-world information a regulator can learn from, but it fails when the harm is severe, and it fails badly when the victim never discovers they were harmed. The example is exact: a voter given false information by a chatbot may never find out it was wrong.

That is why the EU AI Act attracts the criticism it does. It was built as ex ante product safety regulation, a framework designed for objects whose failure modes can be enumerated in advance, and applied to systems whose defining property is that they act in ways nobody coded. The reform proposal that follows is not deregulation. It is tiering: a light checklist for small firms deploying at limited scale in areas where harm is reversible, the current obligations for the middle, mandatory third-party assessment for large firms and high-impact deployments, and a real liability regime paying for the reduction at the bottom. Whether that trade is right is an argument with an answer. Whether AI should be regulated is not, any more, which is also why governance and regulation are not the same job.

The gap nobody campaigns on

Here is the finding that should unsettle both sides. Angus Reid USA surveyed 2,007 American adults between 12 and 19 June 2026. Fifty-eight percent said government must heavily regulate AI and technology companies even if doing so slows development, against 21 percent who would leave it to self-regulation. In the same survey, 59 percent said no government, in the United States or anywhere, is truly equipped to regulate AI quickly enough to keep pace with it.

That is a mandate and a vote of no confidence from the same people. It says the public wants rules and does not believe the institutions can produce them at the speed the subject demands. Neither camp has an answer to that, because it is not a question about how much to regulate. It is a question about regulatory capacity, and it is the one that decides whether any of the rest matters.

The most credible partial answer is experimental. A law and economics analysis in the Cambridge Forum on AI published in January 2026 argues that regulatory sandboxes reduce the information asymmetry between regulator and developer and allow rules to be adjusted iteratively rather than guessed once, and notes that Article 62 of the AI Act gives SMEs priority sandbox access at no cost. It is equally clear about the failure modes: sandbox shopping across jurisdictions, risk-washing by firms that mimic assessment rather than doing it, distortion in favour of whoever gets admitted, and a resource burden that falls on regulators who are already short of people.

Where the argument is worth having

Most of this debate is conducted between people who will never operate the systems and people who had no seat when the rules were drafted. Closing that distance is a format problem before it is a policy one.

The EX Future Summit programme runs a Government track and an AI Ethics track on exactly this ground, alongside eight hosted sessions that put university research teams in front of private partners. It runs from 18 to 20 November 2026 as a single continuous thirty hour broadcast between Las Palmas in the Canary Islands and Bali, twelve hours apart, and online attendance is free for verified researchers, students and the EX community.

The capacity gap is also why the small experiments are worth watching. Bali Province's digital residency sandbox opens a cohort at the summit, granting a ninety day residency, a policy pilot lane and access to municipal data. That is one jurisdiction choosing to learn from a bounded deployment rather than from a consultation, which is the only mechanism anyone has proposed for closing the distance between what a rule intends and what it does. There are structural reasons islands make unusually good regulatory sandboxes, and the same reasoning sits behind what sovereign AI means for a state that will never train a frontier model but still has to govern one.

FAQ

Would banning AI be better than regulating it?

Voters do not treat prohibition as a first choice, but they treat it as better than nothing. Offered a choice between AI systems with mandatory safety requirements and banning them outright, roughly two thirds of AI Policy Institute respondents chose guardrails. Offered a choice between no regulation and a ban, the same population swung strongly toward banning. The revealed preference is not for prohibition. It is for a floor, and prohibition is what people reach for when no floor is on the menu.

Should the federal government or individual states regulate AI in the United States?

In the Annenberg survey, 52 percent favoured the federal government taking the lead. The practical argument behind that preference is volume rather than principle: more than 1,100 AI bills were introduced in state legislatures in 2025, and a company operating in a dozen states inherits a dozen regimes without any user gaining additional protection from the duplication. Federal preemption remains contested, and until a court or Congress settles it, state law binds regardless of what anyone expects to happen next.

Do people who actually use AI still want it regulated?

Yes, and the Johns Hopkins researchers named this as the surprise in their own data. Daily users and people who view the technology positively also supported more rules, and the specific measures cleared party lines. Support for regulation is not a proxy for unfamiliarity, which weakens the common assumption that opposition to AI rules will fade as adoption rises.

Is AI regulation the reason Europe has fewer large AI companies?

The mechanism is documented; the causation is not. Compliance costs that do not scale with firm size demonstrably fall harder on small firms, and the same distortion was recorded after GDPR. But American AI investment led European investment long before the AI Act existed, for reasons of capital depth and market size that no rulebook created. Bruegel argues the opposite effect also operates, that an unsupervised market carries its own cost in legal uncertainty and unstable demand, particularly for smaller and more risk-averse firms. Anyone offering you a single-variable explanation is selling something.

Should AI be regulated the same way in every country?

No serious proposal argues for identical rules, since jurisdictions differ in what they are willing to trade. But the cost of divergence is separable from the cost of the rules, and it is the cheaper problem to fix. One technical dossier, one set of evaluations and one reporting interface satisfying overlapping obligations wherever possible is the reform that industry submissions and the systems critique both converge on, and it lowers the burden without lowering the standard.

EX-AI-Summit 2026 · 18–20 November · Las Palmas (WET) · Bali (WITA) · Online
Presented by EX Venture Inc. · Seraph SL · Equation Labs SL

ProgramPartnersAboutContactLegalPrivacy

We use essential cookies to run this site and optional analytics cookies to understand how it is used. You can accept all or reject optional cookies. See our privacy notice and legal.