Legal Authority: Who Governs AI Development?
Discover the pressing issues of AI regulation and its impact on infrastructure projects. Are you prepared for the future?
Nobody knows who's in charge of AI. That's not a provocative framing β it's the operational reality facing every developer, investor, and infrastructure operator trying to build something that touches this technology.
When Anthropic's internal documents reference capabilities that blur the line between research tool and cyber weapon, and when OpenAI subsequently develops models with comparable capabilities, the obvious question isn't technical. It's legal. Who has the authority to say yes or no? Who steps in when something goes wrong? Right now, the honest answer is: it depends on which country you're in, which agency is paying attention that week, and whether anyone has bothered to write a rule that applies.
For the infrastructure sector, that ambiguity isn't abstract. It's a project risk.
The Current State of AI Regulation
The existing regulatory framework for AI is best described as a patchwork β and not a carefully stitched one. The United States has sector-specific guidance from agencies like the FTC, NIST's AI Risk Management Framework (voluntary, not enforceable), and a 2023 Executive Order on AI safety that directed agencies to develop standards without giving anyone clear enforcement teeth. The EU's AI Act, which passed in 2024, is the most comprehensive binding legislation anywhere in the world β but it's still being phased in, with full compliance requirements not hitting until 2026 and beyond.
The gap between where AI capability is today and where regulation will be in two years is exactly where the risk lives.
That gap is particularly acute for high-risk applications β and under the EU AI Act's own classification system, AI systems used in critical infrastructure management fall into the "high-risk" category. That means data centers, grid management systems, energy distribution networks, and any AI-assisted permitting or land-use platform could face mandatory conformity assessments, registration requirements, and human oversight obligations. The compliance machinery is being built while the technology is already deployed.
What's missing in virtually every jurisdiction is a clear chain of legal authority. NIST can publish frameworks. The FTC can pursue deceptive practices. FERC can regulate energy markets. But none of them have explicit, comprehensive authority over AI development itself β the models, the training data, the capability thresholds that determine when a system becomes a national security concern. That vacuum is where the Anthropic and OpenAI situation becomes instructive: capable systems with cyber implications exist, and there is no clear statutory mechanism to evaluate, restrict, or approve them before deployment.
Legal Authority Surrounding AI Development
The question of *who governs* AI is genuinely contested, and the answer differs depending on whether you're asking about safety, competition, intellectual property, or national security.
In the U.S., the most aggressive regulatory posture has come from the national security apparatus β CISA, NSA, and the Commerce Department's Bureau of Industry and Security, which has moved to restrict semiconductor exports to limit adversaries' AI development capacity. That's a telling signal: the government's most concrete AI interventions have been about controlling hardware supply chains, not the models themselves.
International governance is even messier. There's no WTO equivalent for AI β no binding multilateral treaty, no enforcement mechanism, and no shared definition of what constitutes a dangerous capability.
The G7's Hiroshima AI Process produced voluntary principles. The UN Secretary-General's Advisory Body on AI published recommendations. The OECD has AI principles that 46 countries have signed. None of these are enforceable. They're diplomatic consensus documents dressed up as governance.
For infrastructure developers with international footprints β think cross-border transmission projects, multinational data center operators, or offshore energy platforms integrating AI-based monitoring β this creates a genuine compliance puzzle. A system that's permissible under U.S. guidance may trigger scrutiny under EU rules. A data governance practice that satisfies GDPR may not satisfy India's Digital Personal Data Protection Act. Layering AI regulation on top of existing infrastructure compliance requirements multiplies the complexity without adding clarity.
Local governance is often where the rubber meets the road, and local governments are almost universally underprepared. Municipal permitting offices, state utility commissions, and regional grid operators weren't built to evaluate AI systems. They're being asked to govern technology they don't have the staff or statutory authority to assess.
Impacts on Infrastructure and Development Projects
Here's what this means in practice for anyone financing, developing, or operating infrastructure assets.
AI regulation in infrastructure is no longer a future compliance concern β it's a present-day due diligence issue.
Consider a utility-scale solar project deploying AI-based grid integration software to manage dispatch and curtailment decisions. That system is almost certainly going to fall within the EU AI Act's high-risk category if the project has any European financing or offtake exposure. Conformity assessments, technical documentation, and human oversight requirements add cost and timeline to what was already a capital-intensive, schedule-sensitive development process.
For data center developers, the stakes are even higher. AI governance frameworks are increasingly intertwined with data sovereignty rules, energy consumption mandates, and cybersecurity requirements. The state of Virginia β home to the world's largest data center concentration β has seen utilities and regulators scrambling to assess the grid impact of AI-driven demand growth. That's a load forecasting and infrastructure planning problem, but it's also a governance problem: nobody anticipated that AI model training would require gigawatt-scale power procurement within a decade, and the regulatory frameworks weren't designed for it.
Risk management for infrastructure projects touching AI needs to evolve. Right now, most project developers treat AI-related regulatory exposure the way they treated NEPA uncertainty in the 1990s β something lawyers handle at the margins. The smarter posture is to treat AI governance risk the way you'd treat commodity price risk or interest rate exposure: model it, price it, and structure around it. That means:
- Identifying which AI components of a project trigger high-risk classification under applicable frameworks
- Building compliance cost contingencies into pro formas
- Structuring offtake and financing agreements with AI regulatory change provisions
- Engaging with regulators early, before final investment decisions, in the same way developers do with environmental agencies
The developers who do this work now will have a structural advantage when AI-specific permitting requirements become standard β and they will become standard.
The Future of AI Governance
The direction of travel is clear even if the destination isn't. More regulation is coming. The EU AI Act is the template other jurisdictions will adapt, not a one-off experiment. China has already implemented algorithmic recommendation regulations and generative AI rules. Brazil, Canada, and the UK all have AI-specific legislation in active development. The U.S. will eventually move from executive action to statute β the only question is whether it happens before or after a significant incident forces Congress's hand.
The infrastructure sector should be shaping these frameworks, not waiting to react to them.
Historically, industries that engage early in regulatory design β through comment processes, industry consortia, and direct legislative engagement β end up with frameworks they can work within. Utilities did this with FERC's Order 2222 on distributed energy resources. Offshore wind developers are doing it now with BOEM's leasing rules. AI governance in infrastructure is at the same inflection point: early enough that industry input still matters, late enough that the window is closing.
The most non-obvious risk here isn't over-regulation β it's the liability gap that exists in the absence of clear rules. When an AI-assisted grid management system makes a dispatch decision that contributes to a cascading outage, who is legally responsible? The model developer? The utility that deployed it? The software integrator? Without a defined legal authority and clear regulatory framework, that question gets answered by litigation, not policy. Litigation is slower, more expensive, and produces less coherent outcomes than regulation.
Infrastructure capital is long-duration capital. The projects breaking ground today will be operating in 2045. Whatever AI governance framework emerges in the next five years will define the operating environment for the assets being financed right now. The developers and investors who treat that as a background variable β something to address later β are underpricing a material risk. The ones who treat it as a structuring consideration from day one are building something more durable.
Get ahead of this. The legal authority governing AI development is being written right now, and the people in the room during that process will have the advantage. [INTERNAL LINK: AI regulation], [INTERNAL LINK: infrastructure compliance], [INTERNAL LINK: risk management strategies]
EDITOR NOTES
- Consider cutting the paragraph discussing the G7's Hiroshima AI Process for brevity.
- Ensure the internal link topics are relevant and lead to useful resources on the blog.