Political Tech
A coalition of enterprise tech heavyweights is betting that machine-readable regulation could outpace the legislators writing it.
NewsOnScale Staff
August 6, 2026
There is a well-worn gap in every regulatory regime: the distance between what a law says and what an organization actually does. For decades, that gap has been filled by lawyers, compliance officers, and the occasional expensive consultant. A new project backed by Red Hat, NVIDIA, and IBM wants to fill it with code instead.
The initiative, which aims to convert AI governance policies into machine-readable, executable formats, is framed publicly as a practical tool for enterprises struggling to keep pace with a rapidly expanding patchwork of AI regulations. The pitch is sensible on its face — regulators produce documents, companies produce software, and the translation between the two is slow, inconsistent, and error-prone. Automating that translation layer sounds like an obvious efficiency gain.
But efficiency for whom, and defined by whom, are the questions worth sitting with.
## The Interpretation Problem
Laws are written in natural language for a reason. Ambiguity is not always a bug — it is frequently a feature, one that allows courts, regulators, and civil society to apply evolving judgment to situations legislators could not anticipate. When you encode a policy into software, someone has to make the interpretive choices that transform legislative intent into logical conditionals. That someone, in this case, is not a regulator or a judge. It is an engineering team at a company with direct financial interests in how compliance burdens are structured.
This is not a hypothetical concern. The history of financial technology is littered with examples of compliance automation that technically satisfied the letter of a rule while systematically undermining its purpose. Automated systems have a way of optimizing for what is measurable — checkbox completion — rather than what is meaningful, which is actual harm reduction.
The AI governance context makes this especially fraught. We are still in the early stages of figuring out what AI accountability even means. The EU AI Act, the emerging U.S. federal framework, state-level regulations like those being debated in California — these are living documents in contested territory. Freezing any particular reading of them into code risks locking in one stakeholder's interpretation before the broader policy debate has resolved.
## Who Audits the Auditors?
The project is described as open-source, which matters. Open-source governance tooling at least permits external scrutiny in a way that proprietary compliance software does not. Researchers, regulators, and civil society organizations can theoretically inspect the logic, flag errors, and propose corrections. That is a genuine architectural advantage over black-box alternatives.
But open-source is not the same as democratically governed. The organizations steering this project — large enterprise vendors with significant cloud and AI infrastructure revenue — have structural interests in how AI regulation develops. Lighter compliance burdens, or compliance burdens they are well-positioned to operationalize, are commercially favorable to them. An open codebase with a concentrated steering committee is still a concentrated steering committee.
The accountability question, then, is not just whether the code is visible but whether the roadmap, the interpretive decisions, and the governance of the project itself are subject to meaningful outside input — particularly from the civil society organizations and affected communities that AI regulation is ostensibly designed to protect.
## What Regulators Should Be Watching
Regulatory agencies engaging with this space should resist the temptation to outsource their interpretive authority to automated systems built by regulated parties. The convenience is real. The risk is that agencies gradually lose the institutional capacity to exercise independent judgment, becoming dependent on compliance infrastructure they did not design and cannot fully audit.
That does not mean policy-as-code is inherently dangerous. Done transparently, with robust multistakeholder input and clear lines of accountability, machine-readable governance could genuinely improve consistency and lower barriers for smaller organizations that cannot afford armies of compliance lawyers.
The technology is not the problem. The governance of the technology is always the problem.
The coalition behind this project has the resources to do this right. Whether they have the institutional incentives to do so is a different, and more important, question — one that journalists, regulators, and the public should keep pressing as this infrastructure quietly moves from concept to deployment.