← All company positions
IBMagenda

Precision Regulation for Artificial Intelligence

Undated · The page prints no publication or last-updated date, carrying only the byline "Ryan Hagemann and Jean-Marc Leclerc, co-Directors, IBM Policy Lab". The only date in the text belongs to a January 2020 Morning Consult study it cites, which is not the document's own date and is not used as one.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

IBM argues that AI should not be regulated as a technology at all: regulation should attach to the specific use of an AI system and be proportionate to the risk of that use, an approach it names "precision regulation" and contrasts with blanket rules applied to algorithms as such. The document rests on three pillars — accountability, transparency, and fairness and security — and insists that accountability lands on the human entity that builds, owns or controls the system, which it calls the provider and/or owner, rather than on the model. It then converts that philosophy into five concrete obligations it says every such company should carry: designate a lead AI ethics official backed by an AI Ethics Board; run different rules for different risks, starting from a high-level harm assessment keyed to intended use, end-users, how much users rely on the output and how automated the decision is, with documented and auditable assessment for high-risk uses; don't hide your AI, disclosing its use in proportion to the potential harm; explain your AI through audit trails and accessible documentation including confidence measures and error analysis for high-impact determinations; and test your AI for bias both before deployment and continuously afterwards. Notably, it draws the transparency line deliberately short of source code and trade secrets — disclosure is achieved by documentation and audit trail, not by opening the model. It also holds that existing anti-discrimination law and sector-specific regulation already bind these systems and should be the reference point for conformance, rather than a new general-purpose AI statute. What it asks of governments is comparatively light-touch and infrastructural: recognise or designate co-regulatory mechanisms that can produce shared definitions, benchmarks, frameworks and standards across jurisdictions; finance AI testbeds with genuinely multi-disciplinary participation, explicitly prioritising minority-serving organisations and the communities an application would affect; and create incentives for voluntary adoption of globally recognised standards, including liability safe harbour for companies that certify against them. The through-line is that the sanctioning power should follow demonstrable harm in a defined use, while standards and certification do the day-to-day governing — a regime IBM positions itself as already meeting.

Stated positions (14)

  • Regulate the use of AI and the risk it carries in that use — not the technology or the algorithm itself; this is the document's core claim and its title.
  • Accountability rests with the entity that builds, owns or controls the AI system (the "provider and/or owner"), which is responsible for mitigating harmful outcomes.
  • Obligation should scale with risk: the same capability deployed in a low-stakes and a high-stakes use should not attract the same rules.
  • Every company handling AI should designate a lead AI ethics official, accountable for internal compliance mechanisms and risk assessment, supported by an AI Ethics Board.
  • Risk classification starts with a high-level harm assessment keyed to four factors — intended use, end-users, how far users rely on the output, and the degree of automation; high-risk uses then require a documented, auditable, detailed assessment.
  • "Don't hide your AI": disclose that AI is in use, proportionate to the potential risk and harm — but disclosure must not require revealing source code or trade secrets.
  • "Explain your AI": maintain audit trails and supply accessible documentation, including confidence measures and error analysis, for high-impact determinations.
  • "Test your AI for bias": bias testing before deployment and continuous re-testing and monitoring after release, particularly for automated and high-risk applications.
  • Conformance is measured against existing anti-discrimination law and relevant sector-specific law, not only against a new AI-specific rulebook.
  • Governments should designate or recognise co-regulatory mechanisms to produce shared definitions, benchmarks, frameworks and standards for AI globally, rather than legislating these unilaterally.
  • Governments should finance and create AI testbeds with diverse multi-disciplinary stakeholders, explicitly prioritising minority-serving organisations and affected communities.
  • Voluntary adoption of globally recognised standards should be incentivised by liability safe-harbour protection tied to certification compliance.
  • Trust is treated as a precondition for adoption — the three pillars of accountability, transparency, and fairness and security are framed as what makes AI deployable, not as a compliance cost.
  • The document is authored by the IBM Policy Lab (co-directors in Washington and Brussels), positioning it as IBM's institutional policy doctrine rather than a product or business statement.

About this document

A single web page in IBM's policy section, published under the IBM Policy Lab masthead rather than as a press release or a downloadable white paper: roughly 1,800-2,000 words of continuous prose, bylined to the Lab's two co-directors, Ryan Hagemann (Washington, DC) and Jean-Marc Leclerc (Brussels). No publication date appears anywhere on the page. The only date printed is "January 2020", attached to a Morning Consult poll the page cites in two pull-quote callouts (62% of Americans and 70% of Europeans preferring a precision-regulation approach; 74% and 85% wanting AI systems to be transparent). It opens on trust — "Among companies building and deploying artificial intelligence, and the consumers making use of this technology, trust is of paramount importance" — and closes on bias one day fading away. The body runs an untitled introduction, a three-pillar frame (accountability; transparency; fairness and security), then five imperative-mood subheadings, each a short explanatory paragraph: "Designate a lead AI ethics official", "Different rules for different risks", "Don't hide your AI", "Explain your AI", "Test your AI for bias". Those are addressed to companies generally, not logged as commitments IBM makes about its own products. A separate three-bullet list introduced "To achieve this, governments should" asks for co-regulatory mechanisms, financed AI testbeds, and liability safe harbours tied to certification. It ends with an "About IBM Policy Lab" block, a newsletter sign-up and social share links. Nothing on the page is versioned.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Regulate the use and its risk, not the technology itself

The document's core claim and its title: rules should attach to how an AI system is used and the risk that use carries, never to the algorithm or the technology as such. Obligation scales with the stakes of the deployment, so the same capability in a low-stakes and a high-stakes setting should not attract the same rules.

European UnionAligned

The Act's spine is exactly this: obligations follow the intended purpose, with prohibited practices, an Annex III list of high-risk uses, and light transparency duties elsewhere. The divergence is the general-purpose AI chapter, which attaches model-level duties to a system's training compute and capability regardless of any use — the one place the Act regulates the technology as such, which is what IBM argues against.

United StatesContradicts

SB 53 is built the opposite way round. Duties attach to the developer and to the model's scale, with no reference to what the model is deployed to do; a frontier developer owes the same framework, transparency report and incident duties whether the system is used for drug discovery or for a chat toy. This is the regulate-the-technology architecture IBM's document was written to head off.

Who classifies risk, and against what test

IBM proposes that the company performs a high-level harm assessment keyed to four factors — intended use, end-users, the degree to which users rely on the output, and the degree of automation — and that a high-risk result then triggers a documented, auditable, detailed assessment. Classification begins inside the firm.

European UnionAsks for more

The draft guidelines take classification out of the company's hands and turn Article 6 into an externally-specified legal test with worked examples, rather than a self-administered four-factor screen. A provider that concludes its Annex III system is not high-risk must document that reasoning and register it, so the self-assessment IBM describes survives only as a rebuttable step inside a regulator-defined frame.

RAI-EU-NA-CLASSIF-2026Draft — not binding law today.
United StatesAsks for less

M-25-21 does adopt IBM's shape — a use-based 'high-impact AI' category carrying minimum risk-management practices including pre-deployment testing and impact assessment — but binds only federal agencies' own use of AI. Nothing equivalent classifies private-sector deployments, so the framework IBM asks for exists in the US only where the government is the user.

Accountability rests with the entity that builds, owns or controls the system

The provider and/or owner of an AI system is responsible for mitigating harmful outcomes across the lifecycle. IBM assigns accountability to a single controlling entity rather than diffusing it across a supply chain, and treats it as something a responsible company assumes.

European UnionAsks for more

The enforcement layer converts assumed accountability into supervised, penalty-backed duty: designated national authorities, market surveillance powers, and turnover-based fines. It also splits the role IBM merges, allocating distinct obligations to provider, deployer, importer and distributor, so an owner who merely operates a bought-in system carries its own named duties rather than inheriting the provider's.

United StatesAligned

Colorado places a duty of reasonable care to protect against algorithmic discrimination on both the developer and the deployer of a high-risk system used in consequential decisions — the closest US statutory match to IBM's provider-and-owner allocation. It is state law reaching consequential-decision uses only, not an economy-wide principle.

RAI-US-CO-CSCPAXX-2024Repealed — not binding law today. Superseded by RAI-US-CO-SB26189-2026.

A named accountable officer and an ethics board inside every company

IBM asks that every company handling AI designate a lead AI ethics official, accountable for internal compliance mechanisms and risk assessment, supported by an AI Ethics Board — internal governance as a precondition, not a reporting artefact.

European UnionAligned

The function is required of high-risk providers through the quality management system, the standing risk management system, assigned human oversight and, for non-EU providers, an authorised representative — plus a general AI-literacy duty on all providers and deployers. No named ethics official or ethics board is mandated, and the duties reach high-risk providers rather than every company handling AI.

United StatesAsks for less

New York will require large frontier developers to write, publish and follow a safety protocol and to report safety incidents — documented internal governance, but only from the largest developers, with no accountable officer named and no ethics board. After the chapter amendment cut penalties to $1M/$3M and removed the deployment prohibition it is a disclosure-and-protocol regime rather than the company-wide governance office IBM describes. It takes effect 1 January 2027.

RAI-US-NY-A9449S8-2026Awaiting Entry — not binding law today.

Disclosure — don't hide your AI, but not at the cost of source code or trade secrets

Companies should disclose that AI is in use, proportionate to the potential risk and harm of the application; disclosure must never require exposing source code or proprietary trade secrets. Proportionality, not a flat rule, sets how much is said.

European UnionAsks for more

Transparency duties apply per se rather than in proportion to risk: people must be told they are interacting with an AI system, emotion-recognition and biometric categorisation must be notified, and synthetic content must be machine-readably marked and deepfakes labelled — obligations that bite even on low-risk uses. IBM's trade-secret carve-out is honoured, with confidentiality of source code and IP protected in the information authorities may demand.

United StatesNo equivalent law

EO 14179 revoked the prior executive order and directs agencies to remove policies acting as barriers to AI development; it creates no duty to disclose that AI is in use, to anyone. Federal law imposes no general AI-disclosure requirement at all — the only US disclosure duties of this kind sit in state statutes such as Colorado's.

Explain your AI — audit trails and accessible documentation for high-impact determinations

Companies should maintain audit trails and supply accessible documentation for high-impact determinations, including confidence measures and error analysis — enough for a person or an auditor to understand how a decision was reached.

European UnionAsks for more

Technical documentation, automatic event logging, and instructions for use covering accuracy and known limitations are mandatory for high-risk systems, and the Act adds what IBM does not: an individual right to an explanation of a decision taken with a high-risk system that produces legal or similarly significant effects. Explanation becomes a right owed to the affected person, not only a record the firm keeps.

United StatesAsks for more

Colorado required a deployer that made an adverse consequential decision to give the person a statement of the principal reasons, the data used and its source, plus rights to correct the data and appeal to human review — converting IBM's documentation-and-audit-trail proposal into an enforceable individual remedy, though only for consequential decisions. That remedy is no longer available: SB24-205 was repealed on 14 May 2026 and the successor act has not yet taken effect.

RAI-US-CO-CSCPAXX-2024Repealed — not binding law today. Superseded by RAI-US-CO-SB26189-2026.

Bias testing before and after deployment, measured against existing anti-discrimination law

Bias testing before deployment and continuous re-testing and monitoring afterwards, especially for automated and high-risk applications, with conformance assessed against existing anti-discrimination and sector-specific law rather than only a new AI rulebook.

European UnionAsks for more

Training, validation and test data must be examined for possible biases; a risk management system runs across the lifecycle and post-market monitoring continues after release; and certain public-body and financial deployers must run a fundamental rights impact assessment before use. The Act also does what IBM asks by leaving existing EU non-discrimination and sectoral law fully applicable alongside it.

United StatesContradicts

The Action Plan moves in the opposite direction, directing that references to misinformation, DEI and climate be stripped from the NIST AI Risk Management Framework and deprioritising algorithmic-discrimination work in federal AI policy. The bias testing IBM treats as a baseline duty is being removed from the federal government's own guidance rather than required of anyone.

Co-regulation, standards, testbeds and a liability safe harbour for certified adopters

Governments should recognise co-regulatory mechanisms to produce shared definitions, benchmarks and global standards rather than legislating them unilaterally; finance multi-disciplinary AI testbeds that prioritise minority-serving organisations and affected communities; and incentivise voluntary adoption of recognised standards with liability safe-harbour protection tied to certification.

European UnionAligned

This is close to the Act's own machinery: harmonised standards developed by the European standardisation bodies carry a presumption of conformity, and each member state must establish at least one AI regulatory sandbox with priority access for SMEs — IBM's co-regulation and testbeds, made statutory. What is absent is the liability safe harbour: conformity earns presumption of compliance with the Act, not protection from liability.

United StatesAligned

The plan backs federal standards and evaluation work through NIST and CAISI, national AI testbeds and regulatory sandboxes, which is the co-regulatory apparatus IBM asks for. It offers no liability safe harbour tied to certification either, and pairs the support with pressure on states not to legislate — a form of harmonisation IBM's document does not ask for.

IBM's doctrine reads as the EU AI Act's architecture argued in advance of it: risk tiered by use, accountability on the provider and owner, disclosure, documentation and bias testing — with the Act then making binding, regulator-classified and penalty-backed what IBM proposed as self-assessed and co-regulated, and adding an individual right to explanation the document never contemplates. Against current US federal policy the relationship inverts: EO 14179 and America's AI Action Plan dismantle rather than build a use-based framework and strip bias testing out of federal AI guidance, so IBM is asking Washington for considerably more regulation than exists. The sharpest break is with the US laws that do exist — California SB 53 and New York's Frontier Model Transparency and Safety Act regulate models by developer scale and training compute, precisely the regulate-the-technology approach the page was written to argue against.

Source

https://www.ibm.com/policy/blog/ai-precision-regulation
Date on the page:
None. Byline only; the sole date in the text belongs to a study it cites.
Source checked:
opened and confirmed on 2026-09-18