Political Tech

Brad Smith's Warning About Invisible Rules Should Concern Everyone Building on AI

Microsoft's top lawyer is sounding an alarm about a regulatory environment where the rules exist — but nobody can fully see them.

NewsOnScale Staff

July 24, 2026

There's a particular kind of risk that doesn't show up on most AI governance scorecards: the risk of being subject to rules you cannot fully read. Microsoft President Brad Smith put that problem into unusually plain language recently, describing the current Washington AI policy environment as one defined by 'regulation without transparent or complete rules.' For a company of Microsoft's size and legal resources, that's a manageable inconvenience. For everyone else building in the AI agent economy, it can be existential.

Smith's comments, made in the context of ongoing U.S. federal AI policy discussions, deserve more scrutiny than they typically get when filtered through the lens of a major tech company complaining about regulatory burden. The specific framing matters here. He didn't say there's too much regulation. He said the regulation that exists lacks transparency and completeness. That's a different argument — and in some ways, a more credible one.

## What 'Incomplete Rules' Actually Means in Practice

When regulatory guidance is opaque or incomplete, the compliance burden falls unevenly. Large companies with dedicated government affairs teams and armies of lawyers can work the phones, attend the right briefings, and get informal clarity that never makes it into any public document. Smaller companies, independent developers, and civic technologists don't have that access. They're left reading tea leaves in agency guidance documents, trying to infer intent from enforcement actions, or simply gambling.

This isn't a hypothetical. The AI agent space — where autonomous systems are making consequential decisions about credit, hiring, content moderation, and public services — is operating right now under a patchwork of existing law, informal agency guidance, and anticipated rulemaking that hasn't materialized. The Federal Trade Commission has signaled interests in AI accountability. The Equal Employment Opportunity Commission has issued guidance on hiring tools. The Consumer Financial Protection Bureau has weighed in on algorithmic decision-making in lending. None of these agencies are coordinating their frameworks in a way that produces coherent, accessible rules for people actually trying to build compliant systems.

## Transparency Cuts Both Ways

It would be easy to read Smith's comments purely as corporate advocacy — a powerful company pushing for a regulatory environment it can better predict and shape. That reading isn't wrong. Microsoft benefits enormously from regulatory clarity, and the company has not been shy about participating in policy processes in ways that serve its competitive interests.

But accountability journalism requires holding two things at once. The fact that Microsoft's motivations are mixed doesn't make the underlying problem less real. Opaque governance structures are bad for democratic accountability regardless of who's complaining about them. When enforcement discretion is exercised without clear public criteria, when safe harbor provisions are implied but not codified, when compliance expectations are communicated through private meetings rather than public rulemakings — those conditions create a governance environment that's bad for everyone except the well-connected.

## The Sandbox Problem

This month's wave of global AI governance news — regulatory sandboxes in Georgia, framework-mapping exercises from Brookings, China's new ethics rules for AI agents — reflects a world trying to build governance infrastructure in real time. The United States, despite housing most of the largest AI developers, has been slower to produce durable, transparent frameworks than many of its peers.

Regulatory sandboxes can be legitimate tools for governance under genuine uncertainty. But they can also become mechanisms for indefinitely deferring clear rules while selected participants operate under informal arrangements the public can't see. The line between a thoughtful sandbox and a captured process is thin, and it requires active public scrutiny to maintain.

## What Should Actually Change

The ask shouldn't just be for more regulation or less regulation. It should be for regulation that is written down, publicly accessible, consistently applied, and subject to meaningful challenge when it's wrong. That's not a radical standard. It's the basic expectation of rule-of-law governance.

Smith is right that incomplete and non-transparent rules are a problem. The follow-up question — one that Microsoft's lobbying apparatus is not going to answer — is who benefits from keeping them that way, and for how long.

← Back to all news