The AI Cops Are Watching the Wrong Thing — And They Know It
The AI Cops Are Watching the Wrong Thing — And They Know It
Regulators built the entire AI governance stack around training compute. One paper just mapped out why that’s a crumbling foundation — and what comes next. If your product runs inference at scale, you’re about to become the new regulatory surface.
What happened
Samar Ansari argues that AI governance is structurally misaligned: every major regime in force today — compute thresholds, reporting requirements, frontier-model rules — attaches to the training run, not the inference call. As capability migrates to deployment via inference-time scaling, agentic workflows, and compression onto consumer hardware, the regulatory object is becoming obsolete before the ink is dry. To fill the gap, the paper builds a feasibility taxonomy of 20 inference-time mechanisms spanning monitoring, verification, and enforcement, rated on a four-point readiness scale against evidence from four vendors. The headline number: 15 of the 20 mechanisms have commercial technical substrates in production today — but governance-grade assurance and adversarial robustness vary “substantially.” The adversary stress-test is the cold water: readiness holds only against a cooperative deployer and a low-to-medium-capability user. No mechanism rates adequate against a high-capability state-level deployer, and fine-tuning strips out the model-internal enforcement components entirely. Inter-rater reliability on the readiness ratings — a rare methodological checkpoint in policy papers — returned a quadratic-weighted Cohen’s kappa of 0.74, which is respectable but not definitive.
Cold read
A kappa of 0.74 is solid for a qualitative taxonomy, but it still means roughly one in four ratings had meaningful disagreement between raters — on a four-point scale, that’s enough variance to shift a mechanism from “deployable” to “experimental.” The four-vendor evidence base is thin for a framework meant to generalize across an industry; four vendors in 2026 represent a narrow and likely US/EU-centric slice of the deployment landscape. The adversary model is the paper’s own admission of failure: the entire taxonomy collapses against state-level actors, which is precisely the threat scenario regulators actually lose sleep over. The “conditional substitution principle” connecting inference-stage controls to hardware-stage controls sounds elegant, but it’s conditional — the paper explicitly defers to a companion hardware paper for the conditions to actually hold, meaning this taxonomy is half an argument. Finally, prompt injection and fine-tuning as evasion vectors are flagged but not solved — acknowledging a hole is not the same as patching it.
What it means for you
- Signal maturity: 3/5 — serious framework, but governance adoption lags the taxonomy by years
- Who gets hurt: API-first AI companies and multi-agent orchestration platform builders — you are now the compliance surface, not just the product
- What breaks if this is true: If inference becomes the regulatory unit, every call-logging, rate-limiting, and output-filtering decision becomes a legal artifact; your infra costs and legal exposure grow in lockstep
- Why it might not land: State-level deployers and fine-tuned open-weight models are explicitly outside the taxonomy’s effective range — regulators may mandate mechanisms that sophisticated actors trivially bypass, leaving compliance burden only on the compliant
- Watch for: Any major jurisdiction (EU AI Office, US AISI, or a bilateral US-UK or US-EU instrument) explicitly referencing inference-compute thresholds or deployment-stage reporting requirements in proposed rulemaking — that’s the trigger that converts this academic taxonomy into your compliance checklist
Forecast as of 2026-09-10
By Q3 2027, at least one G7-jurisdiction regulatory proposal will include explicit inference-stage monitoring requirements (call logging, output auditing, or deployment-side compute thresholds) — but enforcement mechanisms against non-cooperative deployers will remain unresolved in the final text, validating the paper’s core pessimism rather than its optimism.
Source: Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance — Samar Ansari. https://arxiv.org/abs/2609.10105v1
