Political Tech
When a platform writes its own rules about what counts as dangerous AI output, the lines between governance and self-interest blur fast.
NewsOnScale Staff
September 5, 2026
There is a version of corporate AI governance that is genuinely useful. Companies that deploy powerful systems at scale have operational knowledge that regulators lack, and thoughtful internal frameworks can translate into real protections for real people. That version exists.
Then there is the version where a company with dominant market share and billions of dollars riding on AI adoption writes a document that tells the public what counts as harm — and what doesn't — in a way that happens to be quite convenient for its existing product roadmap.
Google's recently published AI governance plan lands somewhere in that tension, and it deserves more scrutiny than it has received.
## What the Framework Actually Does
At its core, Google's governance document attempts to establish categorical definitions: what kinds of AI outputs and behaviors the company considers harmful, how those determinations are made, and who inside the organization has authority to act on them. This is not unusual — most major AI labs have published some version of this. What distinguishes Google's approach is its breadth and its implied universality.
The document doesn't just describe Google's internal policies. It frames the boundaries it draws as coherent, principled distinctions that could serve as a model for the broader industry. That framing matters. When a company of Google's scale presents its own risk taxonomy as a reasonable baseline, it exerts gravitational pull on every policy conversation that follows — in Brussels, in Washington, and in the boardrooms of smaller companies trying to figure out what compliance looks like.
## Who Decides What Harm Means?
This is the accountability question that tends to get buried under the technical language of AI governance documents. Harm is not a self-evident category. It is contested, contextual, and often politically loaded. Whether AI-generated content is harmful to, say, a labor organizer, a journalist working a sensitive investigation, or a person seeking health information in an underserved community depends heavily on who is asking and what assumptions are baked into the system making the call.
When that determination is made primarily by the company deploying the system — with limited external audit, no independent appeals mechanism, and no statutory obligation to publish meaningful transparency data — governance starts to look more like brand management.
Google is not unique in this. Every major AI company is navigating the same tension. But Google is uniquely positioned to shape how that tension resolves, and that's precisely why its framework demands close reading rather than polite applause.
## The Preemption Problem
There's a structural risk that gets underappreciated in these conversations: robust-looking voluntary governance frameworks can make it harder, not easier, to pass binding regulation. When companies demonstrate that they are "taking this seriously" with well-designed documents and blue-ribbon advisory boards, they create political cover for legislators who are already reluctant to move. The framework becomes a substitute for the law.
This dynamic is not hypothetical. It has played out in content moderation, in financial services, and in data privacy — sectors where voluntary commitments bought years of regulatory delay while harms compounded.
AI governance is on the same trajectory unless policymakers treat corporate frameworks as inputs to regulation rather than replacements for it.
## What Accountability Actually Requires
None of this means Google's governance work is worthless or made in bad faith. Detailed internal frameworks, when genuinely implemented, can raise the floor on system behavior. But the public and policymakers should insist on a few things that voluntary documents almost never include: mandatory third-party audits with real access, public disclosure of harm determination data disaggregated by affected population, and clear liability when systems cause documented harm that internal governance failed to prevent.
Until those elements exist, what we have is a powerful company defining the rules of a game it is also playing. That's not governance. It's positioning.