Private Governance: Creating a Market in AI Regulation, with Dr. Gillian Hadfield & Andrew Freedman
Summary
Hadfield’s core proposal is to make AI regulation an outcome market: government decides acceptable risk, while competing, approved specialists discover, implement, and verify the technical controls. Instead of legislators freezing today’s red-teaming, data, or process requirements into statute, regulatory-services providers would adapt them as technology changes. The wager is that markets are better “information processing and discovering engines,” provided government retains muscular oversight.
California’s SB 813 would bootstrap that market by making independent certification meaningful evidence that an AI company met its duty of care. The current concept is a rebuttable presumption, not blanket immunity: injured parties could still sue and introduce evidence of negligence. For developers facing unsettled agentic-AI liability, that converts tort law’s “potential energy” into an immediate reason to purchase credible oversight.
The investable bottleneck is not demand for AI-safety services but institutional credibility around who certifies, how performance is measured, and who can revoke approval. Certifiers would need to show that covered vehicles crash less, chatbots cause fewer harms, or other specified outcomes improve—not merely that forms were completed. Hadfield’s non-negotiable backstop is that government must be able to “yank your license.”
A race to the bottom remains the proposal’s central execution risk because developers may select whichever certifier is cheapest and most permissive. Hadfield therefore favors an expert commission, scrutiny of certifiers’ funding, and proof that each can financially survive denying certification; an auditor that must approve four of five customers to stay alive is structurally compromised. Multi-state or international approval could add redundancy when one government “takes its eye off the ball.”
Well-designed certification could reduce rather than deepen big-tech concentration by giving startups a proportionate route to institutional trust. A 10-person developer serving a limited application should face a different program from software entering 10,000 vehicles, while static thresholds such as FLOPs will age poorly. Without trusted validation, Freedman argues, only incumbents can afford to prove to banks and other enterprises that their systems are safe.
Neither insurance nor expanded liability eliminates the need to build the underlying regulatory intelligence. Insurers cannot rationally price novel AI risks without loss histories, duties, standards, and evidence about which controls work; near-miss liability might meanwhile discourage reporting and red-team discovery. Insurance can become a powerful complementary carrot once certifiers supply the missing risk structure, but it should not decide society’s acceptable bioweapons or systemic-finance risk.
The model deliberately does not claim to solve catastrophic externalities, where after-the-fact damages may be meaningless. Bioweapons, market collapse, or harms so large that “who cares that you followed some rules” may require separate ex-ante restrictions and explicit carve-outs. Hadfield’s closing call is pragmatic: society needs “the MVP of new approaches on regulation,” because static rulemaking still has its “shoelaces tied on the starting line.”
Deep dive
1. Nineteenth-century institutions cannot regulate on AI’s clock
Hadfield roots the proposal in decades spent studying access to justice and, from the mid-2000s onward, legal systems confronting technology and globalization. Institutions designed largely in the 19th century no longer match a world whose products are fast-moving, technically complex, and distributed across jurisdictions; AI “ramps that up several levels.”
Her objection to top-down regulation is informational before it is ideological. Legislatures, courts, and agencies operate on a slower clock than engineers at the frontier, while laws and judicial opinions have become longer and harder to revisit: “There’s just so much sand in the gears.”
Freedman’s Colorado cannabis experience supplies the implementation lesson. Even that simpler rollout repeatedly encountered surprises—edibles being his example—and worked best when regulators could revise rules iteratively; expecting AI guardrails written today to remain sensible “even six months later is wrong.”
2. Regulation is infrastructure for markets, not their opposite
Nathan recalls the line that markets are neither free nor unfree; they have rules, some better than others. Hadfield embraces it as a “constant refrain”: contract, property, fraud, antitrust, and reliable enforcement make participants confident enough to invest rather than merely dragging commerce down.
Her economics-and-law framing comes from observing post-Soviet transitions: removing state control did not automatically produce flourishing markets where contract and property institutions were weak. “There’s no such thing as a free market”—only healthier or less healthy markets built on different legal foundations.
3. Government should set outcomes while specialists discover the controls
The proposed division of labor preserves democratic authority over society’s risk tolerance. Government might require autonomous vehicles to outperform human drivers or demand that an AI system not materially uplift bioweapons capability; private specialists would determine the tests, data reviews, monitoring, and technical practices needed to reach that outcome.
Hadfield contrasts this with prescriptive pollution regulation: government can mandate a particular smokestack scrubber, freezing one technology into law, or specify the acceptable pollution at the smokestack’s top and let factories discover cheaper, better methods. Regulatory markets extend that performance-based logic by creating independent firms dedicated to discovering those methods.
Government would approve “regulatory services providers” only after they demonstrate that their programs achieve the public outcome. Target companies would select among approved providers, whose domains could be narrowly scoped—autonomous vehicles, chatbots, companion AI, or another application requiring distinct expertise.
The theoretical model Hadfield developed would mandate purchasing an approved regulator’s services. The immediate problem is supply: society cannot require every relevant company to hire an approved provider tomorrow when that provider market barely exists, so the first policy task is to attract financial and human capital into building it.
4. SB 813 uses liability incentives to bootstrap the missing market
Freedman calls SB 813 the proposal’s fullest current instantiation while stressing that it “requires quite a bit of revision.” A developer, deployer, or application provider worried about risk could voluntarily engage an approved certifier, implement its practices, and seek evidence that it had met recognized best practice.
Certification would not be permanent reputation laundering. Providers would return to California with outcome evidence: certified cars should have fewer crashes, certified chatbots fewer harmful incidents involving teenagers, and each provider should demonstrate improvement against both an uncertified baseline and competing certifiers.
The commercial carrot is legal: compliance could support a finding that the company met its duty to the public if harm nevertheless occurred. Freedman rejects “liability shield” as too strong; the immediate aim is sufficient protection to make companies value oversight and help a viable provider sector emerge.
5. Existing institutions supply components, but not the complete design
Freedman’s closest analogy is Underwriters Laboratories. It began around a late-19th-century world’s fair as independent expertise intended to prevent electrical exhibits from burning the fair down, then spread through consumer products; roughly a century later, UL standards began appearing directly in law. “We don’t have 100 years” to repeat that organic path for AI.
Hadfield points to ISO and other nonprofit standards organizations that develop highly technical requirements. Markets may adopt their standards voluntarily because the mark carries value, while governments can incorporate them by reference—requiring regulated equipment, for example, to follow an outside organization’s specification.
Medical-device regulation gets closer: a consortium of roughly five countries lets each country choose its quality standard—the US using an FDA standard and Canada an ISO standard—while maintaining approved private certifiers. One authorized audit can permit a device to be sold across participating countries.
Securities regulation likewise grew from private exchanges imposing disclosure rules, then became integrated with government. FINRA remains a private membership organization whose rules are overseen by the SEC. The proposal is novel as a complete system, but public-private standard setting, certification, and supervision already “come up to the doorstep.”
6. Certification would alter tort evidence, not close the courthouse
AI liability remains profoundly unsettled. Technology historically enjoyed substantial insulation from tort claims, but Freedman expects agentic AI—software “being an actor in the world”—to expose developers, deployers, applications, and other parts of the stack to duties technology companies have not previously faced. He cites the Character.AI litigation surviving a motion to dismiss as an early signal.
SB 813 presently contemplates a rebuttable presumption concerning duty of care. Certification would provide meaningful evidence that a defendant was not negligent, but a plaintiff could counter it with evidence that the company ignored requirements or otherwise failed to take reasonable precautions.
Hadfield’s law-professor answer is blunt: “You can always sue,” especially in tort. Compliance with automobile or FDA requirements does not generally prevent a claim; courts instead weigh that compliance when determining reasonableness. Vaccines and the September 11th Victim Compensation Fund are exceptional models pairing limits on litigation with alternative compensation—not what she understands this proposal to create.
The deeper change is temporal. Rather than wait for injury, expensive discovery, and plaintiffs able to sustain litigation, the system tries to specify reasonable precautions before deployment through continuous independent oversight. Freedman’s “true north” is not preserving the maximum number of lawsuits but producing “fewer people harmed.”
7. Measured outcomes must replace compliance box-checking
Freedman expects static mandates to become a floor handed to compliance departments: check every box while keeping lawyers away from the business unit. A credible independent standard, applied across competitors and continuously revised, becomes the “brass ring” operating teams must reach rather than another document proving technical compliance.
Some outcomes have clean human benchmarks. Nathan cites Waymo and Swiss Re graphs comparing accidents and injuries from human and autonomous driving; certifiers could compete on demonstrable safety uplift. Other domains require expert qualitative judgments, especially where incident systems do not exist or the first failure could itself be unacceptable.
Enterprise adoption creates bottom-up demand beyond formal liability. A business may refuse to integrate a customer-service chatbot because hallucinated promises could harm customers or misstate what it sells. Markets can “sniff out” those adoption blockers and direct regulatory investment toward risks that boardroom taxonomies missed.
8. Credit-rating capture reveals the guardrails certification needs
Nathan’s sharpest challenge comes from witnessing credit-rating agencies near the mortgage collapse: in his account, supposedly independent judgments had become captured amid increasingly exotic products. AI’s “explosion of exotic products” could recreate a similar shopping dynamic if developers simply seek the easiest certifier.
Hadfield’s distinction is structural. Government created demand for credit ratings while immunizing rating agencies from liability for their judgments and supplying no comparable oversight of whether their work achieved public outcomes. Regulatory markets instead make supervision of providers—not passive recognition of their labels—the government’s central job.
A provider claiming state-of-the-art protection against giving people with no more than high-school chemistry the capacity to build bioweapons would need evidence. Government could revoke approval when performance slipped, while competitors would profit from showing that another provider was trying to “pull the wool over your eyes.” Rivalry supplies information only if licensing has teeth.
Hadfield adds financial stress tests: providers should not be seeded or controlled by the labs they inspect, and they must be able to deny major customers without collapsing. If survival requires certifying four out of five applicants, “we’re going to figure out how to certify four out of five labs” regardless of actual safety.
9. Catastrophic externalities require a different first line of defense
Freedman uses pandemic-scale harm to expose tort law’s limit: with “10 million plus dead globally,” visiting a laboratory afterward to seek damages is not a meaningful governance response. Similarly, a bioweapons incident or systemic collapse may be so severe that certification history and compensatory liability become beside the point.
Freedman would welcome an SB 813 amendment excluding harms “so big that it shouldn’t fall within this.” Regulatory markets can begin by governing tractable domains, mature through experience, and coexist with hard prohibitions or other controls for cases where the first incident cannot be tolerated.
Hadfield repeatedly calls the proposal “one tool in the toolbox.” AI “is not a thing” or single product like a car or drug; it is a general-purpose technology entering health, education, justice, logistics, city management, finance, companionship, and weapons. There can therefore be no single moment when society has simply “regulated AI.”
10. A race to the top ultimately rests on competent state capacity
Nathan’s realist case is that frontier developers, even if more responsible than plausible alternatives, will generally prefer the least costly approved option. If providers are paid when selected, permissiveness can win market share; if California’s attorney general controls approval and monitoring, one distracted, under-resourced, lobbied, or ideologically different administration could weaken the entire market.
Hadfield says SB 813 likely needs a commission with relevant expertise rather than concentrating the work in one office. Providers need a “fear of God moment”: complaints about bent rules must trigger funded investigations, and the authority to certify should be capable of disappearing quickly.
Multi-state and eventually international recognition could create useful redundancy. If one jurisdiction withdraws a provider’s license, that event should prompt every other approving authority to investigate, limiting the damage when one government overlooks evidence or changes course.
Yet Hadfield concedes that “there’s some point where there’s turtles all the way down.” Every regulatory architecture fails if officials stop caring about enforcement. Her comparative claim is narrower: transparent performance between competing providers makes neglect more visible than a regime where statutory ceilings quietly become compliance floors.
11. Private regulators could pierce the information wall around AI labs
Hadfield accepts Nathan’s formulation that “republics require virtue,” then adds: “They also require visibility.” For perhaps the first time, a massively consequential general-purpose technology is being built almost entirely inside corporations, surrounded by a “legally created fictional ring” under which internal information stays private unless companies or government disclose it.
Her proposed state is not smaller so much as differently muscular. Instead of attempting detailed surveillance of every lab practice, government would specialize in supervising providers across distinct domains—autonomous driving, companion AI, biological risk, or financial stability—and demanding evidence that their methods achieve democratically selected outcomes.
Private contractual relationships may unlock finer-grained information than direct government demands because firms routinely share confidential technology in joint ventures under enforceable IP protections. A certifier can require what it needs to inspect; government can then demand the provider’s methods, findings, and outcome evidence without necessarily absorbing every piece of proprietary lab data.
12. Proportionate certification could give little tech a trust channel
Nathan relays A16Z policy leader Matt Perault’s concern: onerous standards may become affordable only for incumbents, giving big tech liability benefits while startups face a worse legal position, difficulty raising capital, and reduced ability to compete. Freedman refuses to accept that concentration as an unavoidable price.
His alternative is a specialty lane scaled to actual exposure. Best practice for a 10-developer team serving a limited application should differ from software entering 10,000 vehicles and needing to recognize traffic signs or “a little girl drops a ball in the street.” Private providers can update that gradation faster than statutory FLOPs or size thresholds.
No-regulation conditions already favor incumbents. A small fintech supplier may have no credible way to convince a bank that its novel system is trustworthy, while large vendors can fund extensive internal testing and outside assurance. A recognized, proportionate seal could therefore become shared infrastructure that lets smaller vendors sell into risk-sensitive enterprises.
Hadfield sees differentiation as a core market property: investors committed to little tech could finance the regulatory infrastructure it needs. Her target is precisely today’s costly, process-heavy regime—GDPR being her example—which burdens startups without proving that logs and prescribed procedures produce the desired protection. “We do not need more words on paper.”
13. Near-miss liability may complement certification—but can punish discovery
Nathan presents law professor Gabriel Weil’s proposal, while warning that his summary may be incomplete: expand liability to negligent near misses when catastrophic harm did not occur only because the developer got lucky. He initially frames expanded liability and SB 813’s protection as opposing directions.
Hadfield considers tort useful for bottom-up legal evolution but doubts it should be the principal defense against catastrophe. Society does not wait for nuclear facilities to fail or drugs to injure before setting requirements; biological and systemic-finance risks—market crashes, trading failures, or bank-run equivalents—similarly call for ex-ante oversight, with litigation retained as backup.
Freedman flags a perverse incentive: liability for discovered near misses could encourage firms to avoid red teams, fragment knowledge across silos, and ensure nobody sees the whole risk picture. Nathan then revises his framing—liability could be expanded while certification protects firms that proactively comply and mitigate hazards, making the approaches potentially complementary.
14. Insurance cannot price an AI-risk structure that does not exist
Nathan’s insurance alternative is appealingly simple: require coverage as society requires it for driving, let insurers put every risk on a dollar scale, and rely on institutions with direct financial exposure to demand appropriate audits. A vast AI market should give them ample incentive to develop the necessary expertise.
Freedman’s answer is that the argument “waved a magic wand.” Insurers cannot rationally price risks they cannot identify, connect to reliable loss probabilities, or mitigate through proven controls. They could respond with astronomical premiums, universal self-insurance, or guesses no better than anyone else’s; none creates the missing knowledge base.
Hadfield stresses that automobile, construction, and pharmaceutical insurers price against dense backgrounds of litigation, safety codes, regulation, and historical evidence. Even the supposedly massive AI insurance market depends on a defined duty: “What’s the risk of what?” Liability coverage requires courts to impose standards, while compliance coverage requires government regulation.
Insurance can nevertheless reward adoption once regulatory technology exists. Hadfield cites Armilla as a model: she says it has an arrangement through Lloyd’s of London, she thinks, or other insurers, under which using specified controls can unlock coverage. But insurers should not become society’s unelected AI regulators—and for civilization-scale loss, they might rationally insure precisely because nobody capable of collecting would remain after the event.
15. Governance needs an MVP, not a perfect blueprint
Fathom does not position itself for an equity payoff as a future regulator. Freedman describes a philanthropically funded nonprofit seeking proofs of concept and real deployments that reveal the model’s “kinks”; Hadfield says the project is giving small grants to technical partners to demonstrate credible practice.
Nathan values the framework’s continuing entry and reevaluation—an implicit alternative to laws whose thresholds become obsolete almost immediately. New providers, methods, and evidence can change what approval requires, giving the structure a better chance to age well than a fixed list of AI processes.
Hadfield’s closing call is urgency with institutional humility: “We need the MVP of new approaches on regulation.” Markets can recruit diverse knowledge, but they must remain government-supervised, and democratic institutions must set acceptable risk. AI is accelerating while regulation has its “shoelaces tied on the starting line”; the priority is to start, observe, revise, and build.