Political Tech
A coalition of enterprise tech giants wants to translate AI regulation into machine-readable rules — and the implications for accountability are profound.
NewsOnScale Staff
August 10, 2026
There is a seductive logic to the idea of turning AI policy into code. Regulations are slow, inconsistent, and often written by people who have never deployed a machine learning model in production. Code, by contrast, is precise, repeatable, and scalable. So when Red Hat, NVIDIA, and IBM threw their collective weight behind a project promising to do exactly that — convert AI governance frameworks into executable, machine-readable rules — the enterprise technology world took notice.
The initiative, backed by some of the most influential names in enterprise infrastructure, represents a significant bet on what practitioners are calling "policy-as-code" for AI governance. The core premise is straightforward: instead of having compliance teams manually interpret regulatory guidance and apply it inconsistently across deployments, you encode the rules directly into the systems being governed. Compliance becomes automated. Audits become programmatic. Governance scales with the technology.
On paper, this sounds like exactly the kind of pragmatic solution a fragmented, overwhelmed regulatory landscape needs. In practice, it deserves far more scrutiny than it has received.
## Who Writes the Code That Writes the Rules?
The first and most important question is authorship. When you translate a legal or policy document into code, every ambiguity in the original text becomes a decision made by an engineer or a product team. That decision — often invisible to regulators, auditors, and the public — effectively becomes the operative regulation. The law says one thing; the implementation says something subtly different; and the gap between them is where accountability goes to die.
This is not hypothetical. Financial services firms learned this lesson painfully when automated compliance systems, built to satisfy the letter of post-2008 regulations, found creative ways to satisfy rule checks without capturing the underlying risk the rules were designed to prevent. The code was compliant. The behavior was not.
With AI governance, the stakes are higher and the underlying policies are more contested. The EU AI Act, California's emerging enterprise AI transparency rules, and the patchwork of federal guidance documents that Brookings and others are urging Congress to consolidate — none of these exist in a stable, finalized, mutually consistent form. Encoding a moving target into production infrastructure creates brittle systems that may be simultaneously over-compliant with yesterday's guidance and under-compliant with tomorrow's.
## Enterprise Capture by Another Name?
There is also a structural concern that the coverage of this initiative has largely glossed over: the companies building the policy-as-code infrastructure are the same companies selling the AI infrastructure being governed. Red Hat sells enterprise Linux and OpenShift. NVIDIA sells the GPUs that power most commercial AI workloads. IBM sells consulting, cloud, and AI services to the same enterprise customers who will use these compliance tools.
This is not an accusation of bad faith. These are legitimate technology companies with genuine compliance expertise. But the conflict of interest is real, and it deserves acknowledgment. When the entities most affected by AI regulation are also the entities defining how that regulation gets operationalized in code, the governance architecture needs robust independent oversight — third-party auditing, open-source transparency into the rule definitions, and meaningful public participation in how policy intent gets encoded.
So far, the public record on those safeguards is thin.
## The Accountability Infrastructure That Must Come With This
None of this means policy-as-code is a bad idea. Automated, consistent, auditable compliance checks are genuinely better than the alternative: ad-hoc, manually-applied, inconsistently-documented processes that vary by team and geography. If done transparently, this approach could actually increase accountability by making compliance decisions visible and testable.
The condition is transparency. The rule definitions must be public. The encoding decisions — the places where ambiguous policy language was resolved in a particular direction — must be documented and accessible to regulators and civil society. Independent auditors must be able to inspect not just whether the code runs correctly, but whether the code encodes the right things.
The enterprise coalition backing this project has the technical talent and the market reach to build something genuinely useful for AI governance. What remains to be seen is whether they have the appetite to build it in a way that serves the public interest as clearly as it serves their own.