Political Tech
The search giant's internal AI governance framework reveals how much power private companies now hold over defining what counts as dangerous technology.
NewsOnScale Staff
September 6, 2026
There is a specific kind of alarm that should accompany any news story where a company releases a document explaining its own ethical limits. Not because the company is necessarily acting in bad faith, but because the structure of the situation itself — a private entity setting the rules for its own conduct, then announcing those rules as governance — represents a fundamental category error about how accountability is supposed to work.
Google's recently released AI governance framework is that kind of document.
According to reporting from Tech Policy Press, the framework attempts to codify what Google considers harmful AI outputs, drawing explicit lines around what its systems will and will not do, and under what circumstances. The effort is framed as responsible self-regulation — a company taking the initiative to build guardrails before legislators can mandate them.
## The Preemption Play
This framing is not new, and it is not neutral. When technology companies publish governance frameworks, especially ahead of anticipated regulation, they are engaged in a form of regulatory preemption. The goal, whether stated or not, is to make the case that external oversight is redundant — that the company has already handled it.
This dynamic is playing out across the AI sector at precisely the moment when federal AI policy, as Brookings has noted, is struggling to move from governance frameworks to actual execution. The regulatory infrastructure for AI in the United States remains fragmented, under-resourced, and politically contested. Into that vacuum, companies like Google are inserting their own definitions, their own enforcement mechanisms, and their own appeals processes.
The problem is not that Google's definitions of harm are necessarily wrong. Some of them may be reasonable. The problem is that the public has no independent mechanism to evaluate them, challenge them, or hold the company accountable when they are applied inconsistently — or when the lines shift to accommodate business interests.
## Who Defines Harm?
The question of what constitutes harmful AI output is not a technical question. It is a political and ethical one, and it carries enormous consequences. Does a model that systematically underperforms for speakers of non-dominant languages cause harm? Does a recommendation algorithm that amplifies politically extreme content cause harm? Does an AI hiring tool that encodes historical discrimination cause harm?
These are contested questions. Societies typically resolve contested questions of this magnitude through democratic processes — legislation, agency rulemaking, public comment, litigation. What they do not typically do, in a healthy governance environment, is delegate those questions entirely to the entity with the largest financial stake in the outcome.
Google's framework may check boxes that impress policymakers and generate favorable press coverage. But a governance document authored, interpreted, and enforced by a single corporation is not governance in any meaningful civic sense. It is a policy position dressed in the language of accountability.
## What Meaningful Oversight Would Look Like
This is not an argument that Google should do nothing while waiting for Congress to act. Responsible internal practices matter. But they are not a substitute for external accountability structures — they are, at best, a floor.
Meaningful AI governance would involve independent auditing of AI systems against publicly defined harm standards. It would include mandatory disclosure when systems are updated in ways that affect those standards. It would create legal liability pathways for affected parties. And it would ensure that the people most likely to be harmed by AI systems — workers, marginalized communities, users with less market power — have standing to participate in defining what harm means.
None of that is present in a company's self-published governance framework, however thoughtfully written.
Google is a powerful company operating in a regulatory vacuum, and it is filling that vacuum with its own judgment. The appropriate response from journalists, policymakers, and the public is not gratitude. It is scrutiny — and a renewed urgency around building the external oversight infrastructure that actually belongs in its place.