We are trying to govern AI at a fraction of the speed it is advancing, and the outcome is a widening gap between policy and reality. The growing gap between those two velocities is the speed at which we are losing control.
Reality velocity − policy velocity = rate of control loss
The gap grows over time, so even a small constant lead for reality compounds into a large difference between the two.
This is not isolated to AI or tech. It is a pervasive and persistent issue across many (potentially all) industries. AI just widens the gap faster than anything before it, because of the speed of change.
In the same week that the EU AI Act’s Article 50 transparency obligations go live, frontier labs are publishing that their models are breaking sandboxes and exploiting systems never intended to be touched.
In my opinion the model outbreak stories were either proof of security negligence, or partially amplified for marketing purposes. Neither is acceptable, particularly from the frontier labs pioneering the space, who should be setting the example for industry standards.
There is, however, an underlying current of truth: we have already lost control.
How should security and GRC practitioners handle it?
Policy is not the finish line. It is the bare minimum, and should be considered the floor of an adequately resourced ISMS programme, not the ceiling. Waiting for deadlines to implement controls is chasing best practice, not living it.
Now more than ever, the responsibility sits with the professionals operating in those spaces. We should bridge the gap between minimum compliance requirements and the reality of current technology, using our specialised understanding to build secure and trusted systems that are more aligned with reality.
How can policy makers keep up?
Increase the frequency of reviews and updates to technology focused policy. Where possible, reduce bureaucracy and incentivise involvement from industry leaders and tip of the spear practitioners to set the standard.
That would narrow the gap between policy and reality, and dissolve some of the scepticism practitioners currently hold towards incoming regulation.
Godspeed to all GRC professionals out there.