Imagine a world where everyone can carry something like a GPT box: a cheap, powerful AI system that can write, code, persuade, research, design, and act on instructions. The usual policy response is easy to imagine: regulate the models, regulate the companies, regulate the dangerous uses.
But that response may miss the deeper problem.
The regulation trap
Traditional technology regulation assumes that control can be concentrated somewhere. A government can license an operator. A regulator can inspect a factory. A platform can remove an application. A company can be held responsible for the system it deploys.
General-purpose AI changes that structure. When capable intelligence becomes cheap, portable, replicable, and widely available, the object being regulated is no longer just a product or a company. It is a capability that can spread through millions of people and thousands of systems.
That creates a difficult policy paradox: the more widely AI capability is distributed, the harder it becomes to govern through centralized controls.
The GPT box problem
Consider a hypothetical GPT box. It does not need to be a frontier model. It might simply be an inexpensive device or local system with enough intelligence to perform useful cognitive work.
- It can draft documents.
- It can write and debug software.
- It can analyze information.
- It can tutor a student.
- It can automate routine decisions.
- It can coordinate other software.
- It can operate continuously without asking a company for permission.
Now imagine millions of these systems.
At that point, AI policy starts to resemble internet policy more than industrial regulation. The important question is not simply, “Who owns the machine?” It becomes, “How do we govern a capability that can be copied, adapted, combined, and redistributed?”
Why model regulation is necessary—but insufficient
There are good reasons to regulate powerful AI models. Evaluation, security requirements, transparency, liability, privacy protection, and restrictions on genuinely dangerous applications can all be justified.
The problem begins when we assume that regulating the model solves the social problem.
A capable model can become a component inside another system. Its capabilities can be distributed through APIs, open weights, specialized models, agents, applications, or locally running software. Even when one provider imposes restrictions, alternatives can emerge.
The policy target keeps moving.
The diffusion problem
Technology becomes difficult to regulate when three things happen at once: capability improves, cost falls, and distribution expands.
That combination changes the economics of control. A regulator may be able to supervise a few frontier laboratories. It is much harder to supervise millions of developers, businesses, hobbyists, and users building on increasingly capable systems.
This is not an argument against regulation. It is an argument for regulating the right layer.
From regulating models to regulating consequences
A more durable framework may focus less on trying to classify every model and more on the consequences of deploying AI in the real world.
- High-risk outcomes: stronger controls where AI can cause serious physical, financial, legal, or societal harm.
- Accountability: someone must remain responsible for consequential decisions, even when an AI system made the recommendation.
- Traceability: important AI-mediated actions should leave enough evidence to reconstruct what happened.
- Security: systems with meaningful capabilities need safeguards against theft, misuse, and uncontrolled replication.
- Human recourse: people affected by consequential automated decisions need a meaningful way to challenge them.
This approach does not require governments to predict every future AI architecture. It focuses on the social consequences that regulation is actually meant to manage.
The uncomfortable question
There is another issue that is easy to overlook.
If AI becomes extremely cheap and widely distributed, the state may no longer be the only institution capable of deploying intelligence at scale. Individuals, small organizations, communities, and informal networks may acquire capabilities that were previously available only to large institutions.
That can be economically liberating. It can also make old assumptions about power, expertise, enforcement, and information obsolete.
The central policy question therefore becomes larger than “How powerful should AI be?” It becomes: Who should be allowed to exercise that power, under what conditions, and who is accountable when things go wrong?

The real regulation challenge
The hardest AI regulation problem may not be stopping a few companies from building powerful systems. It may be governing the world after powerful cognitive tools become ordinary.
Once intelligence becomes something people can buy, download, copy, customize, and embed almost anywhere, regulation cannot depend entirely on controlling the source.
We will need institutions that can govern use without assuming that capability itself can be contained.
That is the regulation trap: we may spend enormous effort regulating the boxes while the real transformation is happening because everyone has one.

