Political Tech
When a platform defines what counts as dangerous, the rulebook belongs to the company, not the public.
NewsOnScale Staff
September 11, 2026
There is a particular kind of corporate document that arrives dressed as transparency but functions as a boundary-setting exercise. Google's newly released AI governance framework is that document. It deserves to be read carefully — not for what it promises, but for what it quietly claims the right to decide.
The framework, analyzed this week by Tech Policy Press, lays out how Google intends to define, categorize, and respond to harms caused by its AI systems. On the surface, that sounds like exactly the kind of internal accountability structure that critics of the AI industry have demanded. Look closer, and a more complicated picture emerges.
## Who Gets to Define 'Harm'?
The central problem with self-governance frameworks in high-stakes technology is definitional authority. When a company publishes a document explaining what it considers harmful, it is not submitting to external judgment — it is pre-empting it. The categories of harm Google acknowledges, the thresholds it sets for intervention, and the processes it reserves for internal review all reflect choices made by Google, for Google.
This is not a conspiracy. It is an institutional logic. Companies build governance frameworks to manage risk, satisfy regulators, and maintain public trust. All three of those goals are legitimate. None of them is the same as putting the public interest first.
For users of Google's AI products — which now number in the hundreds of millions — the distinction matters enormously. If a person is harmed by a model output in a way that Google's internal taxonomy does not recognize as harm, there is no external body with the authority or the access to override that classification. The framework is the ceiling, not the floor.
## The Accountability Gap at the Center of the AI Boom
This dynamic is not unique to Google. Across the AI industry, the largest platforms are racing to publish governance documentation precisely because federal legislation has not arrived. The absence of a binding federal framework — something Brookings, CSIS, and Brookings-adjacent scholars have been pressing Congress on for years — has left a vacuum. Platforms are filling it with their own paperwork.
To be clear: some of that paperwork is genuinely useful. Internal red-teaming, harm taxonomies, and model evaluation protocols have real value. The AI safety community has pushed for exactly these practices. The problem is not that Google has a governance framework. The problem is that a governance framework written by Google, reviewed by Google, and enforced by Google is not governance in any civic sense of the word. It is risk management with a public-facing label.
## What Accountability-Focused Coverage Has to Ask
For journalists and researchers covering the AI agent economy, the release of documents like this one creates a specific obligation: do not treat publication as equivalent to accountability. The questions that matter are not in the framework itself. They are in the gaps.
Which harms did Google's internal teams debate including but ultimately leave out? Who participated in drafting the taxonomy — engineers, ethicists, lawyers, affected communities? What happens when a harm is identified after the fact and does not fit existing categories? Is there any external audit mechanism with real access, or only the appearance of one?
These are not bad-faith questions. They are the basic infrastructure of accountability reporting, and they are precisely what glossy governance documents are not designed to answer.
## The Stakes Are Larger Than One Company
Google's framework will influence how other platforms write their own. It will be cited in regulatory proceedings. It will shape how policymakers in Washington and Brussels think about what voluntary compliance looks like. That is the nature of first-mover power in a standard-setting vacuum.
That is also why this moment — before a federal framework exists, while the definitional battles are still live — is the moment when public scrutiny matters most. Once industry-drafted categories of harm become the default reference point for legislators and regulators, changing them becomes exponentially harder.
The question for the public is not whether Google means well. It is whether meaning well is sufficient when no one outside the company can verify the answer.