Political Tech
A new industry-backed initiative wants to automate regulatory compliance, but who decides what the rules actually mean?
NewsOnScale Staff
August 22, 2026
There's a version of this story that writes itself as unambiguous good news. Three of the most influential enterprise technology companies in the world — Red Hat, NVIDIA, and IBM — are backing an effort to take the dense, ambiguous language of AI governance policy and render it into structured, executable code. Faster compliance, fewer interpretation gaps, auditable outputs. What's not to like?
Quite a bit, potentially. And the fact that the initiative is being received mostly as a logistics story, rather than a power story, is itself worth examining.
## What the Project Actually Does
The initiative, backed by these enterprise heavyweights, sits within a growing technical movement sometimes called "policy as code" — the idea that governance requirements shouldn't live only in PDF documents and legal memos, but should be translated into formal logic that software systems can evaluate automatically. Think of it as the difference between telling a driver the speed limit and installing a governor on the engine.
In the AI context, this means taking regulatory frameworks — the EU AI Act, NIST's AI Risk Management Framework, emerging state-level rules — and encoding their requirements into something a compliance pipeline can actually check. Does this model meet transparency requirements? Does this deployment context trigger high-risk classification? The code, in theory, gives you an answer.
For large enterprises managing dozens of AI deployments across multiple jurisdictions, the appeal is obvious. Manual compliance review is slow, expensive, and inconsistent. Automating the interpretation layer promises efficiency at scale.
## The Translation Problem
But here's what the efficiency framing obscures: translating natural language policy into formal logic is not a neutral technical act. It is an interpretive act, and interpretation is where power lives.
Every piece of legislation, every regulatory framework, contains ambiguity — sometimes intentional, sometimes not. When a human lawyer interprets whether a given AI system constitutes a "high-risk" application under the EU AI Act, that interpretation is visible, contestable, and subject to revision by courts or regulators. When a code library makes the same determination automatically, at scale, across thousands of deployments, the interpretation becomes infrastructure. It becomes very hard to see, and even harder to challenge.
Who wrote the encoding logic? What edge cases did they resolve, and how? What assumptions are baked into the classification schema? These are not hypothetical concerns. They are the exact questions that accountability journalism exists to ask.
## The Vendor Governance Gap
The deeper structural issue is that the companies building these compliance tools have a direct financial interest in how compliance is defined. A framework that encodes a narrow interpretation of "transparency" requirements is a framework that makes their own products easier to deploy. That's not a conspiracy — it's a normal market incentive. But it is an incentive that democratic oversight is supposed to check.
Regulators in the EU and the United States have been slow to engage with the policy-as-code movement on its own technical terms. That slowness is dangerous. If the governance encoding layer gets established before public agencies develop the capacity to audit or contest it, the de facto standard will be set by the vendors, not by the public.
## What Accountability Looks Like Here
None of this means the initiative is malicious or should be stopped. Structured, machine-readable policy frameworks could genuinely improve the consistency and speed of AI governance — outcomes that benefit everyone. But the accountability infrastructure needs to exist alongside the technical infrastructure, not as an afterthought.
That means open-sourcing the encoding logic and subjecting it to independent audit. It means civil society and regulatory bodies having a formal role in reviewing how ambiguous policy language gets resolved. It means treating the policy-as-code layer as public infrastructure, not proprietary tooling.
Right now, the project is being celebrated for solving a real problem. The harder question — who governs the governors — is getting considerably less attention. That's usually when it matters most.