The Problem With Regulating the Future
One of the best descriptions of innovation I’ve ever read has nothing to do with public policy. It’s Marc Andreessen and Michael McGuiness describing how SpaceX builds rockets.
As they explain, SpaceX’s approach was to replace the aerospace industry’s traditional effort to eliminate uncertainty through years of analysis with a rapid cycle of building, testing, failing, and correcting. Musk’s engineers produced relatively inexpensive prototypes, pushed them until they broke, and treated each explosion not as a scandal or failure but as sources of information about where their models had been wrong.
The first three Falcon 1 launches failed for three different reasons; each failure identified a specific problem that could be corrected. The fourth launch succeeded. This pattern became institutionalized in Musk’s operating “Algorithm”: question every requirement, eliminate unnecessary parts and processes, simplify what remains, accelerate the cycle, and automate only at the end. The objective isn’t failure for its own sake, but to make experimentation cheap and frequent enough that reality can expose errors faster than committees and computer models ever could.
They then explain what was so innovative about it and why it worked so well:
“The reason this works better than the alternative is because you cannot think your way to perfect solutions for problems you do not fully understand. Reality is the only adequate validator, and the trick is making it cheap enough to consult often.”
As I read, it occurred to me that this might also be the best argument for permissionless innovation. My friend Adam Thierer at R street defines permissionless innovation the following way: “[It] refers to the idea that experimentation with new technologies and innovations should generally be permitted by default and that prior restraints on creative activities should be avoided except in those cases where clear and immediate harm is evident.” In other words, permissionless innovation accepts that theoretical prediction is a poor substitute for actual discovery. When we don’t fully understand a technology – and we almost never do – the smartest approach is to let people experiment, learn from reality, and respond to actual harms rather than imagined ones.
By contrast, precautionary principle asks us to predict the future and remove all the risks a new technology or innovation presents, before allowing it to take place. In other words, new innovations should be curbed or even forbidden until they are proven safe, Thierer explains.
History is full of technologies that looked dangerous before they transformed the world for the better. Automobiles, airplanes, the internet, smartphones, even electricity all generated fear. Had regulators insisted on solving every conceivable problem before allowing widespread adoption, many of these innovations would have been delayed by years, perhaps decades. Instead, we discovered the real problems – as opposed to the many imagined ones – through experience and developed solutions along the way.
AI is the latest example. And as always, many people are worried and would like to limit future harm that could come from it. I take it to be the spirit of a recent public letter called We Must Act Now. The signers warn that AI could transform the economy over the next decade and, therefore, argues that “economists, policymakers and technology leaders must act now... to build the incentives, guardrails, and institutions needed to steer AI in a direction that complements humans and benefits society.”
This is precisely where the letter loses me. It’s not that I believe that AI poses no risks. I am sure it does. But the extremely vague statement opens the door to the precautionary principal approach to regulating AI. It doesn’t come out and say it but I think that left in the hands of politicians and bureaucrats what we will get is an approach to acting now that treats the whole exercise as if we already know enough about those risks to begin designing the institutions and regulations that will govern them.
Over At The Geek Way, Andrew McAfee explained why he didn’t sign the open letter and then proposed a subtle but profound revision. Instead of calling for policymakers to build new guardrails and institutions today, he suggests this instead:
3. So economists, policymakers and technology leaders must act now to understand the economics of transformative AI, and to build the capabilities needed to respond quickly and effectively to the challenges it will bring.
I would be tempted to sign that version (though I actually don’t sign joint letters).
Notice the difference. It doesn’t presume we know the right rules today. It prepares us to respond when experience teaches us what actual problems are. As McAffee writes:
I hope the below resonates with people who believe that even as powerful as AI is, it doesn’t yet require us to turn away from permissionless innovation and economic freedom and embrace higher levels of upstream governance and dirigisme.
This is also why recent reports showing frontier AI models exhibiting sophisticated hacking capabilities are not an argument for the precautionary-principle approach to regulating AI or for signing the We Must Act Now statement. If anything, they illustrate why the better approach is permissionless innovation.
Indeed, the debate here isn’t regulation versus no regulation. It’s about when regulation should occur. Before these capabilities (and harmful behavior) were observed, policymakers could only speculate about the risks. But with actual experience, we have concrete evidence of potential problems. That changes the conversation but also identifies a real risk to focus on and gives it priority.
The first line of defense should be the developers themselves, who have every incentive to make their models safer, and are already investing heavily in doing so. But if experience ultimately shows that existing laws and private incentives are insufficient, then you have a case for targeted rules addressing this specific, demonstrated risk.
It’s evidence-based governance. We learn first, and only then ask whether new rules are needed.

