Political Tech
A major industry push to translate AI governance documents into executable software raises urgent questions about accountability, interpretation, and who holds the pen.
NewsOnScale Staff
August 16, 2026
There is a version of this story that sounds like unambiguous progress. Governments around the world are producing AI governance frameworks faster than most organizations can read them, let alone comply with them. An open-source toolchain that translates those frameworks into structured, machine-readable code could, in theory, reduce compliance costs, eliminate ambiguity, and make oversight more consistent. That is the pitch behind the project now drawing support from Red Hat, NVIDIA, and IBM.
But there is another version of this story, and it deserves equal attention.
## Policy as Code Is Still Policy
When a legislative body passes a regulation, the text goes through committee markups, legal review, public comment periods, and eventually judicial interpretation. Every word is contested. Ambiguity is often intentional — a legislative compromise that allows implementation to flex with context.
When engineers convert that same regulation into executable code, those compromises collapse into binary decisions. A parameter gets set. A threshold gets defined. A condition gets marked true or false. The interpretive choices embedded in that translation process are just as consequential as anything a congressional staffer might write — but they happen inside a pull request, not a public hearing.
This is not a hypothetical concern. It is the central accountability gap in the policy-as-code movement, and it is one that the project's corporate backers have a financial incentive to downplay.
## The Credibility of the Backers Cuts Both Ways
Red Hat, NVIDIA, and IBM are not fringe actors. They are among the most influential infrastructure companies in enterprise technology, and their involvement lends this project real technical credibility. It also lends it real market power.
These are companies that sell the hardware, the software stacks, and the consulting services that large organizations use to build and deploy AI systems. A compliance toolchain that their platforms integrate natively is a toolchain that advantages their customers — and disadvantages organizations using competing infrastructure. That is not a reason to dismiss the project, but it is a reason to examine its governance structure carefully.
Who sits on the committee that decides how a given regulatory clause gets encoded? Is that process open to civil society, affected communities, or the regulatory agencies whose frameworks are being translated? Or is it primarily driven by the engineering and legal teams of large technology vendors?
## The Sandbox Problem Resurfaces
This project lands in a broader regulatory moment worth tracking. Separately, a coalition is actively opposing the AI sandbox provisions in the CLARITY Act, arguing that sandboxes can become permanent shelters from accountability rather than temporary testing environments. The policy-as-code push shares some of the same structural tension: tools framed as accelerating compliance can, under the right conditions, substitute for it.
Regulators who accept a vendor-supplied compliance module as sufficient evidence of adherence to a framework may never look closely at whether the module accurately reflects the framework's intent. The audit trail becomes circular — the code certifies itself.
## What Accountability Infrastructure Would Actually Look Like
None of this means the underlying technical project is wrong. Machine-readable policy has genuine value. The EU's work on regulatory technology, and NIST's structured framework outputs, point toward a future where interoperability between governance systems requires some degree of codification.
But accountability infrastructure around this effort matters as much as the infrastructure itself. That means open governance over encoding decisions, mandatory disclosures when vendor interpretations diverge from regulatory agency guidance, and explicit legal clarity that the code does not supersede the underlying policy text.
Without those guardrails, what gets built is not a compliance tool. It is a private restatement of public law — written by engineers, blessed by industry, and deployed at scale before anyone outside the consortium has read the changelog.
The companies involved are capable of building something better than that. The question is whether they will be required to.