Political Tech
A coalition of enterprise tech giants wants to turn AI regulations into machine-readable rules — and that ambition deserves far more scrutiny than it's getting.
NewsOnScale Staff
August 8, 2026
There is a quiet but consequential project underway in the infrastructure layer of the AI economy. Red Hat, NVIDIA, and IBM — three of the most influential names in enterprise computing — are lending their weight to an initiative designed to convert AI policy frameworks into machine-readable code. The pitch is straightforward: regulations are complex, inconsistent across jurisdictions, and slow to implement. Why not let software do the interpretation?
It sounds like an efficiency argument. It is also a power argument, and that distinction matters enormously.
## What the Project Actually Does
The effort centers on translating governance documents — think the EU AI Act, NIST AI Risk Management Framework, or emerging state-level statutes — into structured, executable policy definitions. The idea is that an enterprise deploying an AI system could automatically check its behavior against codified rule sets, generating compliance evidence without armies of lawyers parsing legislative text.
Proponents frame this as democratization. Smaller companies that can't afford extensive legal teams would gain access to compliance tooling that currently only large organizations can sustain. Audits become reproducible. Rules become consistent across deployments.
These are not trivial benefits. Regulatory ambiguity has become a genuine operational burden for organizations trying to build responsibly in a landscape where the EU, the United States federal government, and a growing number of state legislatures are producing overlapping and sometimes contradictory requirements.
## The Interpretation Problem
But here is the part that deserves more scrutiny than the trade press has given it: translating law into code is not a neutral act. Every statute contains ambiguity by design. Legislatures write broadly because they cannot anticipate every technical configuration a rule might eventually touch. Courts exist precisely to adjudicate what the language means when applied to specific facts.
When a consortium of private companies encodes their interpretation of a regulation into software that other enterprises then rely upon for compliance, the interpretation layer shifts from public institutions — courts, agencies, elected bodies — to whoever controls the codebase. That is a significant transfer of governance authority, and it is happening largely outside public view.
This is not a hypothetical concern. Financial services have lived this story. When large vendors encoded their interpretation of Basel III capital requirements into risk management platforms, those interpretations effectively became the operational standard across hundreds of institutions. Regulatory agencies later discovered they were examining systems that all shared the same underlying assumptions — assumptions the vendors had made, not the regulators.
## Who Audits the Auditors?
The accountability gap here is structural. If an AI system causes harm and the deploying company says it passed automated compliance checks, the question immediately becomes: compliant according to whose reading of the rule? If that reading lives in proprietary code maintained by a vendor consortium, regulators may find themselves negotiating with software rather than interrogating judgment.
None of this means the project is malicious. IBM, Red Hat, and NVIDIA are responding to a real market problem. Enterprises are drowning in regulatory uncertainty, and there is genuine demand for tools that reduce compliance friction. The companies involved have legitimate business reasons to want standards that their platforms can satisfy.
But good intentions do not resolve the structural issue. Governance automation needs its own governance layer — public, independent, and adversarially reviewed.
## What Accountability Would Look Like
At minimum, any policy-to-code translation project operating at scale should publish its interpretive choices openly, maintain a versioned public record of how regulatory language was mapped to executable logic, and create a clear mechanism for regulators and civil society to flag misalignments.
Ideally, the relevant agencies — whether that is the FTC, sector-specific regulators, or EU supervisory authorities — would participate in or formally review the encoding process rather than learning after the fact that a de facto standard has already been deployed across the market.
The Brookings Institution's recent call for federal AI governance legislation is directly relevant here. Without a coherent statutory foundation, policy-to-code projects will encode a patchwork, and the vendors doing the encoding will make the calls that fill the gaps.
Code is law, as the old internet adage goes. The question is who gets to write it — and who gets to check their work.