Topics

AI Governance and Law

How legal systems assign responsibility, rights and liability for systems that act without a human deciding each action.

10
Talks
19
Speakers
17
Organizations

Latest talks

Maximum Friction to Copy a Person, Zero Friction to Act as One
Maximum Friction to Copy a Person, Zero Friction to Act as One

Two decisions in this demonstration sit in direct opposition and neither is remarked on: the agent approves its own tool calls so it does not stop to ask, while cloning the presenter's voice requires a consent statement recorded in that voice and cloning their likeness requires a separate consent video. Maximum friction to copy a person, zero friction for the agent to act. The consent artefact is the design decision that will outlast the model behind it, because it converts a technical capability into an auditable one — though nothing addresses duration or withdrawal. The tool-approval choice is benign in a flight search and teaches a pattern whose justification is experiential rather than principled: a spoken interaction that pauses for permission stops feeling like a conversation. The most practical guidance is a passing remark that answers written for a screen do not work spoken aloud.

Microsoft Build

Pichai Calls Google a Buffer Between People and the Raw Internet
Pichai Calls Google a Buffer Between People and the Raw Internet

Pichai's framing of Google as the buffer between people and the raw internet is offered as continuity — search did it, browsers did it, agents do it more — and it is also the most contested claim in the industry, because a buffer decides what passes through. He reaches immediately for the counterweight, the connection people feel to creators they follow, which is precisely the tension the company is currently managing without resolving. Two answers are sharper than the format usually produces. On competition he describes participants running on different pre-training and release cadences rather than at different speeds in one race, which is a more honest account than the leaderboard framing and comes from someone with an interest in leaderboards. On security he acknowledges models improving at cyber work, which is the one domain where better capability does not obviously net out positive, since an attacker needs one vulnerability and a defender needs all of them.

Google I/O

From an Attention Economy to an Attachment One
From an Attention Economy to an Attachment One

The distinction in this session that deserves to travel is a two-word change: the model is moving from an attention economy to an attachment economy. That changes what is measured and what regulation would have to address, because attention competes for time while attachment competes for relationship, and the two produce different products from identical technology. Attention is finite in a way people notice; attachment produces reliance that feels like preference, which makes it harder to regulate for the same reason it is harder to notice. The supporting argument is about incentives rather than intent: earlier engagement produces more data and longer relationships. The regulatory proposal — measuring well-being outcomes rather than asking for safety by design — identifies the right target without solving the measurement problem that made regulators settle for a floor in the first place.

World Economic Forum Annual Meeting

Agents Will Not Swipe a Credit Card
Agents Will Not Swipe a Credit Card

The claim worth arguing about here is that the native currency for AI agents will be crypto, because agents will not carry cards and blockchain is the interface most native to them. It comes from someone with an obvious interest in it being true, which is a reason to examine it rather than dismiss it. The strong part is structural: card networks assume a cardholder who can be contacted and can attest to a transaction, and an autonomous process breaks each of those assumptions. What does not follow is the conclusion, because nothing prevents existing networks issuing delegated credentials with limits and revocation. The panel's most direct voice calls these areas highly speculative with hard use cases, and both positions can hold, since stablecoins and speculative assets are separable in a way the panel treats as one thing. The quieter claim about tokenised government instruments is the more consequential one.

World Economic Forum Annual Meeting

The Compounds Are Not Hidden. That Is the Problem
The Compounds Are Not Hidden. That Is the Problem

The fact that makes this session difficult is not that the scam compounds are hidden but that they are known. International law enforcement knows their street addresses, because hundreds of survivors have said so and digital traces corroborate it — four or five hundred facilities across three countries that stole between 50 and 85 billion dollars in a single year. This is not a detection problem. The strongest argument made is that the captive workforce is the operation's weakest link rather than merely its cruellest feature, because thousands escape and can describe who is doing this, where and how. The proposed lever is deliberately modest: international physical inspection of five or six facilities rather than all of them. The structural diagnosis is about tempo, and synthetic media widens the asymmetry further.

World Economic Forum Annual Meeting

Sovereignty Without the Servers: The Digital Embassy Idea at Davos
Sovereignty Without the Servers: The Digital Embassy Idea at Davos

The proposition is narrow and more consequential than it sounds: a country extends its critical digital infrastructure into another state's territory while retaining legal control over the data, compute and governance. The inversion starts from a physical fact — power and water cannot be relocated across borders, so move the facility to where they already exist rather than demanding they appear where the sovereignty is. The concept predates AI, having been arranged to protect continuity of essential government services, and the change is one of scale: a defensive instrument satisfied by modest infrastructure becomes a template for where the world's compute physically sits. The argument for standardising is practical rather than principled — bilateral agreements otherwise reinvent the same legal and technical answers, and investors want a tried framework in place before capital is committed. What it does not resolve is leverage, since the scenarios that make sovereignty matter are precisely the ones in which holding the buildings confers options.

World Economic Forum Annual Meeting

Not Being Forced to Choose Between Hegemons and Hyperscalers
Not Being Forced to Choose Between Hegemons and Hyperscalers

The phrase worth extracting from this address is short: cooperating with like-minded democracies so as not to be forced to choose between hegemons and hyperscalers. It states compactly a problem most governments have not named, because the conventional framing of technology sovereignty concerns states, and this one puts corporate platforms in the same sentence as state powers. A country dependent on a small number of compute providers faces a structurally similar vulnerability that is rarely described that way. The proposed response is coalition rather than domestic substitution, which is realistic, since no middle power builds an alternative alone. The organising idea is variable geometry — different coalitions for different issues — and the most substantive claim links economic exposure to foreign policy directly: spreading trade and investment abroad is presented as the physical basis on which a state can afford to say what it thinks, since lowering how much a partner can hurt you is what makes a principled stand affordable.

World Economic Forum Annual Meeting

Harari's Question for Davos: Should an AI Be a Legal Person?
Harari's Question for Davos: Should an AI Be a Legal Person?

Harari spends most of his address establishing terms before asking the question he came to ask. His preliminary work is to dismantle the word tool: a knife's use is decided by whoever holds it, whereas what is arriving decides for itself, and can also invent new kinds of knives. From there he argues that anything constituted by words — law, books, text-centred religion — is exposed, while drawing a firm line at feeling, where he says there is no evidence at all. The structural claim is that the ancient tension between letter and spirit has always run inside humanity and is about to be externalised between humans and the new masters of words. Only then does he arrive at personhood, and his handling is precise: corporations, New Zealand rivers and Indian deities hold legal personhood safely because the decisions are made by humans behind the container. An entity that decides for itself ends that arrangement. He does not answer the question; he tells the room it is coming.

World Economic Forum Annual Meeting

When Metadata Stops Describing the Access Path and Becomes It
When Metadata Stops Describing the Access Path and Becomes It

The line that explains this session comes from the customer in the last ten minutes: they are preparing for a world where metadata is how agent-based systems find the data they need and access it through the controls being built. That relocates a function — governance has spent two decades as compliance activity describing data that people locate by other means, and if agents navigate by the catalogue then the catalogue stops describing the access path and becomes it. An incomplete catalogue is a documentation problem when humans can ask a colleague; an agent has no such workaround. The most honest moment addresses the perennial failure that rules get written and ignored, with enforcement rather than publication as the argument. Generated descriptions and greyed-out classification suggestions divide the labour correctly, keeping a person accountable while removing the burden of finding candidates.

AWS re:Invent

Trust Becomes a Key Policy
Trust Becomes a Key Policy

The session opens by dismantling the reassuring version of its own subject: you put a box around the workload, secure it, call it confidential computing, and the problem is solved — which is why the presentation exists. The gap comes down to one question: how do you know the code you are talking to is the code that is running, rather than taking someone's word for it. A protected environment addresses operator access but not the customer's actual objection, which is that they cannot confirm any of it. Attestation converts the claim into a signed measurement, and the step that turns evidence into a control is a key policy permitting operations only when the environment matches. Trust becomes arithmetic rather than process, with no reviewer to convince and no exception to grant, which is what allows a model owner and a data owner to collaborate without trusting each other.

AWS re:Invent

How to cite this page

Copy a stable citation for this source-backed profile.