Political Tech
A coalition of major tech players wants to encode regulatory language directly into machine-readable rules, raising urgent questions about who controls the translation.
NewsOnScale Staff
August 5, 2026
There is a version of this story that sounds like obvious progress. AI governance documents are notoriously difficult to operationalize. Regulators write in the language of principles and obligations; engineers build in the language of conditionals and constraints. The gap between those two worlds costs compliance teams enormous time and money, and frequently produces inconsistent results. If you could bridge that gap systematically — turning policy text into executable logic that systems could actually follow — you would solve a real problem.
That is the premise behind a project now drawing institutional weight from Red Hat, NVIDIA, and IBM, which are backing an effort to encode AI policy frameworks directly into machine-readable code. The initiative represents one of the more ambitious intersections of regulatory technology and AI governance yet attempted at scale.
But the version of this story that demands scrutiny is quieter and less comfortable.
## Who Decides What the Law Means?
Legislative and regulatory language is deliberately open to interpretation. That is not a bug — it is how democratic systems accommodate complexity, evolving norms, and contested values. When a policy document says an AI system must be "transparent" or must avoid "undue risk," the meaning of those terms is supposed to be worked out through enforcement actions, court decisions, agency guidance, and public deliberation.
When you encode that language into software, someone has to make the interpretive choices. Every conditional statement, every threshold, every exception is a translation decision. And right now, the entities best positioned to make those decisions at scale are the same large technology companies that have the most at stake in how the rules are interpreted.
This is not a hypothetical concern. It is the structural condition of the project being described. Red Hat, NVIDIA, and IBM are not neutral arbiters of regulatory intent. They are vendors whose products will be governed by the very policies being translated. The conflict of interest is not disqualifying — expertise and interest frequently overlap in technical domains — but it demands explicit acknowledgment and independent oversight, neither of which has been prominently featured in how this initiative is being presented.
## The Compliance Theater Risk
There is a second problem, related but distinct. Encoding policy into code creates an audit trail that looks like accountability without necessarily delivering it. A system that passes machine-readable compliance checks has not necessarily honored the spirit of the underlying regulation. It has satisfied the parameters set by whoever wrote the code.
This dynamic is already visible in other domains. Cookie consent frameworks are technically compliant with privacy regulations in ways that systematically undermine the privacy protections those regulations were designed to provide. The compliance layer became the product, and the legal obligation became a box to be checked rather than a value to be upheld.
AI governance is higher stakes. If executable policy code becomes the standard against which AI systems are measured, and if that code is authored primarily by industry incumbents, the result could be a compliance infrastructure that entrenches existing players, raises barriers for smaller competitors, and insulates powerful systems from meaningful public challenge.
## What Legitimate Policy-as-Code Could Look Like
None of this means the underlying technical ambition is wrong. Interoperable, machine-readable governance frameworks could genuinely improve regulatory consistency across jurisdictions — a real need given the fragmented global landscape evident from Europe's AI Act, proposed U.S. federal frameworks, and Australia's shifting posture all operating simultaneously.
But legitimacy here requires structural conditions that do not yet appear to be in place: independent governance of the translation process, public transparency about interpretive choices, formal input from civil society and affected communities, and regulatory bodies that retain authority to override coded implementations when they diverge from legislative intent.
The initiative is technically interesting. Whether it serves the public or primarily serves its sponsors depends entirely on questions of process and power that the current framing largely avoids. That avoidance is itself the story.