REVIEW 3 major objections 5 minor 63 references
Regulating Multifunctionality
T0 review · 3 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read The paper argues that regulating multifunctional AI calls for management-based regulation: mandated, audited internal risk-management plans rather than fixed rules.
desk verdict A coherent policy synthesis whose management-based recommendation inherits the very information problem it uses to reject alternatives; send to referees, but the auditability premise must be defended. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is management-based regulation, defined as a regulatory strategy that requires a regulated entity to develop and implement an internal plan for identifying and monitoring risks, establishing protective procedures, and documenting changes over time, with regulators auditing plans and their execution. It is carried by the paper's typology of AI heterogeneity—design heterogeneity, use heterogeneity, and problem heterogeneity—which is used to show why prescriptive rules, performance standards, and liability each fail at some step of specifying or verifying AI conduct, while an audited internal planning process does not need that specification.
What would settle it
A regulator would need to show a concrete counterexample: a general-purpose foundation model for which a measurable safety outcome (for example, a bounded rate of harmful outputs under adversarial prompting) was specified in advance and enforced, or a jurisdiction where audited management-based plans were demonstrably implemented without privileged access to model internals. Either observation would test the paper's central dichotomy.
Extended reading notes
Core claim
The paper's central claim is that management-based regulation is arguably the only regulatory strategy equipped to handle the heterogeneity challenges posed by foundational and generative AI. Because a foundation model is a Swiss-army-knife technology whose uses are limited only by users' imagination, regulation cannot specify means or measurable outcomes in advance. Management-based regulation adapts by obligating each developer to build an internal, documented process for identifying, monitoring, and mitigating risks, and by having regulators audit that process and its implementation over time. If correct, this means the central task of AI governance shifts from writing technology rules to building institutional capacity for ongoing oversight of firms' internal risk management.
Load-bearing premise
The argument depends on regulators being able to audit developers' internal risk-management plans and their implementation, even though the paper does not explain how regulators obtain the information and monitoring capacity that it says is missing when it rejects performance standards.
Editorial extensions
If this is right
- Regulators of AI should focus less on dictating model designs or banning outputs and more on requiring developers to maintain audited risk-management plans.
- Performance standards may remain workable for narrow, single-function deployments of AI, but not for general-purpose models with open-ended uses.
- Ex post liability can supplement, but not replace, proactive oversight, because it acts only after harm and faces causation and foreseeability problems.
- Information disclosure, such as model cards, can support management-based regulation but needs to be designed so ordinary users can act on it.
- AI governance will depend on regulatory resources, human talent, and organizational culture, not just on the choice of legal instruments.
Reading between the lines
- If management-based regulation is right, then the most consequential design question for AI law is auditability: what records, metrics, and access rights make an internal AI risk-management plan genuinely verifiable by outsiders.
- The same logic may extend to open-weight models, where the developer's internal plan cannot control downstream users; management-based obligations might need to move to deployers or hosting platforms, a step the paper only gestures at.
- The argument implies a testable prediction: jurisdictions that adopt audited management-based requirements should show fewer severe AI incidents per deployment than those relying on voluntary guidance or pure liability.
- The paper's analogy to the Swiss army knife suggests a research program: map which categories of AI uses have stable, measurable risk endpoints, because those are the islands where performance standards can survive.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This policy chapter argues that foundation models and generative AI exhibit an extreme form of heterogeneity—across designs, uses, and risks—that makes prescriptive ('micro-means') regulation infeasible. The authors review four more flexible regulatory options—performance standards, information disclosure, ex post liability, and management-based regulation—and conclude that management-based regulation, which would require AI developers to maintain and periodically update internal risk-management plans subject to auditing, is the most realistic primary approach. They add that regulatory vigilance, agility, resources, and human capital are necessary complements. The chapter is a conceptual and argumentative contribution, not an empirical study.
Significance. If accepted, the chapter would redirect AI governance discussions away from model-specific rules and toward organizational process regulation, a position with real policy consequences. The paper offers a useful typology of AI heterogeneity and a balanced account of the limits of prescriptive rules, performance standards, and liability. Its central positive claim, however, rests on an unexamined auditability premise and on effectiveness evidence drawn substantially from the authors' own prior work in other regulatory domains. The chapter is therefore a valuable framing contribution, but it does not yet establish that management-based regulation can succeed for multifunctional AI.
major comments (3)
- [Abstract and §5.4, first paragraph] The claim that management-based regulation 'has proven effective in other contexts of heterogeneity' and is 'arguably the only regulatory strategy equipped' to handle foundational AI is supported only by citations to [13], [20], [11], and forthcoming [16], all authored or co-authored by the first author. No empirical study of management-based regulation applied to AI is cited, and no mechanism is given that would explain why the industrial-safety, environmental, and food-safety record transfers to foundation models. This is a load-bearing premise for the chapter's central recommendation; the authors should either supply independent evidence or explicitly qualify the claim as an analogy rather than a demonstrated result.
- [§5.4, fourth paragraph, and §5.1, last paragraph] The chapter rejects performance standards partly because regulators cannot specify or measure the risks posed by multifunctional models, stating that such limitations may make performance standards 'as infeasible as reliance on prescriptive or micro-means regulations.' Management-based regulation, however, requires regulators or third-party auditors to judge whether an internal plan is adequate—which risks it should cover, what monitoring is sufficient, and whether implementation is genuine. The paper does not explain what an audit would inspect or how an auditor can distinguish substantive risk management from paper compliance without access to training data, deployment telemetry, or model internals. The same information and monitoring deficits therefore apply to the auditability of management-based plans; this should be addressed by specifying audit criteria, information rights, or a role for external model evaluations.
- [§6 (Regulatory Vigilance and Agility)] The recommendation assumes regulators will have the capacity to audit AI firms' internal processes, but the chapter's own Section 6 acknowledges only the need for 'resources, financial resources, technological tools, and human capital' without explaining how these can be obtained or whether existing agencies are capable of exercising them. Given the heterogeneity and pace the paper describes, this capacity assumption is not trivial. The authors should offer concrete institutional design suggestions—such as specialized agencies, certification schemes, mandatory data-access regimes, or sunset-and-review mechanisms—or acknowledge that the proposal is conditional on an as-yet-unmet regulatory capability.
minor comments (5)
- [§3, paragraph on the Zelenskyy video] The name 'President V olodymyr Zelenskyy' contains a stray space after the initial; it should read 'President Volodymyr Zelenskyy.'
- [§5.2, subsection on performance disclosure] The phrase 'model or system cards' should be 'model cards or system cards' for parallel phrasing and clarity.
- [§5.4, paragraph on the iterative process] The 'plan-do-check-act' cycle is invoked without citation or definition; since it is a specific management doctrine, provide a reference or a one-sentence explanation of what each step requires.
- [§6, opening paragraph] The term 'regulatory excellence' is used as if self-explanatory; tie it to the Best-in-Class Regulator Initiative cited at [41] or define its components explicitly.
- [§7, Conclusion] The closing sentence states that 'meaningful, multifaceted regulatory strategies do exist,' but the body of the chapter only argues that management-based regulation is promising while performance standards and liability have serious limitations. The conclusion should be softened to match the evidence presented.
Circularity Check
Policy recommendation leans on self-cited effectiveness claim; core heterogeneity analysis is otherwise independent.
-
self citation load bearing
[Section 5.4, Management-Based Regulation]
"Management-based regulation is arguably the only regulatory strategy equipped to handle the heterogeneity challenges posed by foundational and generative AI. This type of regulation is already used widely in other diverse and dynamic risk settings where neither prescriptive nor performance standards are feasible [13, 20, 11]."
The paper's central recommendation—that management-based regulation is the only strategy equipped for multifunctional AI—is supported by citations to the authors' own prior work: [13] Coglianese, [20] Coglianese and Lazer, and [11] Coglianese. The abstract's stronger claim that this approach 'has proven effective in other contexts of heterogeneity' rests on this same self-cited lineage. No independent empirical studies or external benchmark are offered for the effectiveness premise. The argument therefore partly reduces to the authors' own prior assertions, even though the surrounding analysis of AI heterogeneity and the critiques of prescriptive, performance, and liability approaches are independently developed.
full rationale
This is a policy-analysis paper, not a formal derivation, so there are no equations, fitted parameters, or construction-level reductions. The main circular element is the empirical grounding for the central recommendation: Section 5.4 asserts that management-based regulation is 'arguably the only regulatory strategy equipped' for multifunctional AI and supports this with three citations, all of which include the present first author. The abstract likewise states that the approach 'has proven effective in other contexts of heterogeneity' without independent support. That self-citation is load-bearing because the effectiveness of management-based regulation is the key premise for choosing it over the alternatives. However, much of the paper's content—the taxonomy of heterogeneity, the analysis of why prescriptive rules, performance standards, disclosure, and liability face challenges, and the emphasis on regulatory vigilance—is developed from general reasoning and external examples. The auditability premise in Section 5.4 is arguably an unsupported assumption and a possible inconsistency with Section 5.1, but that is a correctness or completeness concern rather than a circularity. Overall, the central claim retains independent analytical content, but its pivotal empirical premise is substantially self-referential, warranting a moderate score of 4.
Assumptions & free parameters
assumptions (4)
- domain assumption Regulators cannot foresee the full range of uses of foundation models, making prescriptive micro-means regulation infeasible.
- domain assumption Performance standards require a defined problem and a measurable compliance test, which is unavailable for multifunctional AI.
- ad hoc to paper Management-based regulation has proven effective in other heterogeneous contexts and will be effective for AI.
- domain assumption Regulators can audit the internal risk-management plans of AI developers.
Cite this review
Pith. "Pith review of Regulating Multifunctionality." pith.science (2026). https://pith.science/paper/VOVQONF6
@misc{pith2026250215715,
author = {Pith},
title = {Pith review of: Regulating Multifunctionality},
year = {2026},
howpublished = {\url{https://pith.science/paper/VOVQONF6}},
note = {Machine review of arXiv:2502.15715}
}
read the original abstract
Foundation models and generative artificial intelligence (AI) exacerbate a core regulatory challenge associated with AI: its heterogeneity. By their very nature, foundation models and generative AI can perform multiple functions for their users, thus presenting a vast array of different risks. This multifunctionality means that prescriptive, one-size-fits-all regulation will not be a viable option. Even performance standards and ex post liability - regulatory approaches that usually afford flexibility - are unlikely to be strong candidates for responding to multifunctional AI's risks, given challenges in monitoring and enforcement. Regulators will do well instead to promote proactive risk management on the part of developers and users by using management-based regulation, an approach that has proven effective in other contexts of heterogeneity. Regulators will also need to maintain ongoing vigilance and agility. More than in other contexts, regulators of multifunctional AI will need sufficient resources, top human talent and leadership, and organizational cultures committed to regulatory excellence.
Reference graph
Works this paper leans on
-
[13]
C. Coglianese. Regulating machine learning: The challenge of heterogeneity. Competition Policy International: TechReg Chronicle, February, pages 23–06, 2023
work page 2023
-
[20]
C. Coglianese and D. Lazer. Management-based regulation: Prescribing private management to achieve public goals. Law & Society Review, 37(4):691–730, 2003
work page 2003
-
[11]
C. Coglianese. Management-based regulation: implications for public policy. 2010
work page 2010
-
[16]
C. Coglianese and C. R. Crum. Leashes, not guardrails: A management-based approach to ai risk regulation. Risk Analysis: An International Journal, Forthcoming
-
[1]
Office of Public Affairs , 2024
Justice department sues realpage for algorithmic pricing scheme that harms millions of american renters. Office of Public Affairs , 2024. https://www.justice.gov/opa/ pr/justice-department-sues-realpage-algorithmic-pricing-scheme- harms-millions-american-renters
work page 2024
-
[2]
J. Abramson, J. Adler, J. Dunger, R. Evans, T. Green, A. Pritzel, O. Ronneberger, L. Willmore, A. J. Ballard, J. Bambrick, et al. Accurate structure prediction of biomolecular interactions with alphafold 3. Nature, pages 1–3, 2024
work page 2024
- [3]
-
[4]
Y . Bathaee. The artificial intelligence black box and the failure of intent and causation. Harv. JL & Tech., 31:889, 2017
work page 2017
Show all 63 references
-
[5]
Y . Bengio. Faq on catastrophic ai risks.https://yoshuabengio.org/2023/06/24/faq- on-catastrophic-ai-risks/, 5 2023
2023
-
[6]
J. Black. Forms and paradoxes of principles-based regulation. Capital Markets Law Journal , 3(4):425–457, 2008
2008
-
[7]
Bolukbasi, K.-W
T. Bolukbasi, K.-W. Chang, J. Y . Zou, V . Saligrama, and A. T. Kalai. Man is to computer program- mer as woman is to homemaker? debiasing word embeddings. Advances in neural information processing systems, 29, 2016
2016
-
[8]
Bommasani, D
R. Bommasani, D. A. Hudson, E. Adeli, R. Altman, S. Arora, S. von Arx, M. S. Bernstein, J. Bohg, A. Bosselut, E. Brunskill, et al. On the opportunities and risks of foundation models.arXiv preprint arXiv:2108.07258, 2021
2021 arXiv
-
[9]
Buolamwini and T
J. Buolamwini and T. Gebru. Gender shades: Intersectional accuracy disparities in commercial gender classification. In Conference on fairness, accountability and transparency , pages 77–91. PMLR, 2018
2018
-
[10]
R. Calo. Robotics and the lessons of cyberlaw. Calif. L. Rev., 103:513, 2015
2015
-
[12]
Coglianese
C. Coglianese. The limits of performance-based regulation. U. Mich. JL Reform, 50:525, 2016
2016
-
[14]
Coglianese
C. Coglianese. A people-and-processes approach to ai governance. The RegReview, 8, 2024
2024
-
[15]
Coglianese
C. Coglianese. Rule design: Defining the regulator–regulatee relationship. In The Regulator– Regulatee Relationship in High-Hazard Industry Sectors: New Actors and New Viewpoints in a Conservative Landscape, pages 89–97. Springer Nature Switzerland Cham, 2024
2024
-
[17]
Coglianese and L
C. Coglianese and L. M. B. Dor. Ai in adjudication and administration. Brook. L. Rev., 86:791, 2020
2020
-
[18]
Coglianese and X
C. Coglianese and X. Fu. Machine governing: The rise in artificial intelligence use by the u.s. government. Working Paper, 2025
2025
-
[19]
Coglianese and A
C. Coglianese and A. Lai. Algorithm vs. algorithm. Duke LJ, 71:1281, 2021. 14
2021
-
[21]
Coglianese and D
C. Coglianese and D. Lehr. Regulating by robot: Administrative decision making in the machine- learning era. Geo. LJ, 105:1147, 2016
2016
-
[22]
R. Crootof. War torts: Accountability for autonomous weapons. U. Pa. L. Rev., 164:1347, 2015
2015
-
[23]
R. Crootof. International cybertorts: Expanding state accountability in cyberspace. Cornell L. Rev., 103:565, 2017
2017
-
[24]
Dosovitskiy
A. Dosovitskiy. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929, 2020
2010 arXiv
-
[25]
D. F. Engstrom, D. E. Ho, C. M. Sharkey, and M.-F. Cu ´ellar. Government by algorithm: Artificial intelligence in federal administrative agencies. NYU School of Law, Public Law Research Paper , (20-54), 2020
2020
-
[26]
I. O. Gallegos, R. A. Rossi, J. Barrow, M. M. Tanjim, S. Kim, F. Dernoncourt, T. Yu, R. Zhang, and N. K. Ahmed. Bias and fairness in large language models: A survey. Computational Linguistics, pages 1–79, 2024
2024
-
[27]
Gebru, J
T. Gebru, J. Morgenstern, B. Vecchione, J. W. Vaughan, H. Wallach, H. D. Iii, and K. Crawford. Datasheets for datasets. Communications of the ACM, 64(12):86–92, 2021
2021
-
[28]
Hacker, A
P. Hacker, A. Engel, and M. Mauer. Regulating chatgpt and other large generative ai models. In Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency , pages 1112–1123, 2023
2023
-
[29]
K. He, X. Zhang, S. Ren, and J. Sun. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition, pages 770–778, 2016
2016
-
[30]
J. d. Heinzelin, J. D. Clark, T. White, W. Hart, P. Renne, G. WoldeGabriel, Y . Beyene, and E. Vrba. Environment and behavior of 2.5-million-year-old bouri hominids. Science, 284(5414):625–629, 1999
1999
-
[31]
Hullman, S
J. Hullman, S. Kapoor, P. Nanayakkara, A. Gelman, and A. Narayanan. The worst of both worlds: A comparative analysis of errors in learning from data in psychology and machine learning. In Proceedings of the 2022 AAAI/ACM Conference on AI, Ethics, and Society, pages 335–348, 2022
2022
-
[32]
Jarovsky
L. Jarovsky. Principle-based ai governance. Luiza’s Newsletter: AI Governance Professional Edi- tion (Substack), 2024. https://www.luizasnewsletter.com/p/principle-based- aigovernance?utm campaign=post&utm medium=web
2024
-
[33]
C. E. Karnow. The application of traditional tort theory to embodied machine intelligence. InRobot law, pages 51–77. Edward Elgar Publishing, 2016
2016
-
[34]
P. R. Kleindorfer and E. W. Orts. Informational regulation of environmental risks. Risk Analysis, 18(2):155–170, 1998
1998
-
[35]
Krizhevsky, I
A. Krizhevsky, I. Sutskever, and G. E. Hinton. Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems, 25, 2012
2012
-
[36]
LeCun, B
Y . LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, and L. D. Jackel. Backpropagation applied to handwritten zip code recognition. Neural computation, 1(4):541–551, 1989
1989
-
[37]
A. Lior. Insuring ai: The role of insurance in artificial intelligence regulation. Harv. JL & Tech., 35:467, 2021. 15
2021
-
[38]
A. Lior. Innovating liability: the virtuous cycle of torts, technology and liability insurance. Yale JL & Tech., 25:448, 2023
2023
-
[39]
G. E. Marchant and C. I. Gutierrez. Soft law 2.0: an agile and effective governance approach for artificial intelligence. Minn. JL Sci. & Tech., 24:375, 2022
2022
-
[40]
G. E. Marchant and R. A. Lindor. The coming collision between autonomous vehicles and the liability system. Santa Clara L. Rev., 52:1321, 2012
2012
-
[41]
S. H. Metzenbaum and G. Vasisht. What makes a regulator excellent? mission, funding, informa- tion, and judgment. Penn Program on Regulation’s Best-in-Class Regulator Initiative, 2015
2015
-
[42]
Mitchell, S
M. Mitchell, S. Wu, A. Zaldivar, P. Barnes, L. Vasserman, B. Hutchinson, E. Spitzer, I. D. Raji, and T. Gebru. Model cards for model reporting. In Proceedings of the conference on fairness, accountability, and transparency, pages 220–229, 2019
2019
-
[43]
N. A. of Sciences Engineering, Medicine, et al. Designing safety regulations for high-hazard in- dustries. The National Academies Press, 2018
2018
-
[44]
R. PACHECO. Projeto de lei n. 2338/2023. In Disp˜oe sobre o uso da Intelig ˆencia Artificial. Bras´ılia: Congresso Nacional do Brasil , volume 6, 2023. https://www25.senado.leg.br/ web/atividade/materias/-/materia/157233
2023
-
[45]
B. Perrigo. Bing’s ai is threatening users. that’s no laughing matter. Time, 2023. https:// time.com/6256529/bing-openai-chatgpt-danger-alignment/
2023
-
[46]
Quilty-Harper
C. Quilty-Harper. $ 335, 000 pay for ‘ai whisperer’ jobs appears in red-hot market. Bloomberg,
-
[47]
Richards, D
J. Richards, D. Piorkowski, M. Hind, S. Houde, and A. Mojsilovi ´c. A methodology for creating ai factsheets. arXiv preprint arXiv:2006.13796, 2020
2006 arXiv
-
[48]
Satariano
A. Satariano. Chatgpt is banned in italy over privacy concerns. New York Times, 2023. https: //www.nytimes.com/2023/03/31/technology/chatgpt-italy-ban.html
2023
-
[49]
Schuett, M
J. Schuett, M. Anderljung, A. Carlier, L. Koessler, and B. Garfinkel. From principles to rules: A regulatory approach for frontier ai. arXiv preprint arXiv:2407.07300, 2024
2024 arXiv
-
[50]
X. Shen, Z. Chen, M. Backes, Y . Shen, and Y . Zhang. ” do anything now”: Characterizing and evaluating in-the-wild jailbreak prompts on large language models. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pages 1671–1685, 2024
2024
-
[51]
Silver, J
D. Silver, J. Schrittwieser, K. Simonyan, I. Antonoglou, A. Huang, A. Guez, T. Hubert, L. Baker, M. Lai, A. Bolton, et al. Mastering the game of go without human knowledge. nature, 550(7676):354–359, 2017
2017
-
[52]
Simonite
T. Simonite. A zelensky deepfake was quickly defeated: The next one might not be. Wired, 2022. https://www.wired.com/story/zelensky-deepfake-facebook- twitter-playbook/
2022
-
[53]
G. Team, R. Anil, S. Borgeaud, J.-B. Alayrac, J. Yu, R. Soricut, J. Schalkwyk, A. M. Dai, A. Hauth, K. Millican, et al. Gemini: a family of highly capable multimodal models. arXiv preprint arXiv:2312.11805, 2023
2023 arXiv
-
[54]
Tinsley, A
P. Tinsley, A. Czajka, and P. Flynn. This face does not exist... but it might be yours! identity leakage in generative models. In Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision, pages 1320–1328, 2021. 16
2021
-
[55]
Touvron, T
H. Touvron, T. Lavril, G. Izacard, X. Martinet, M.-A. Lachaux, T. Lacroix, B. Rozi `ere, N. Goyal, E. Hambro, F. Azhar, et al. Llama: Open and efficient foundation language models. arXiv preprint arXiv:2302.13971, 2023
2023 arXiv
-
[56]
Triantafillou, F
E. Triantafillou, F. Pedregosa, J. Hayes, P. Kairouz, I. Guyon, M. Kurmanji, G. K. Dziugaite, P. Tri- antafillou, K. Zhao, L. S. Hosoya, J. C. S. J. Junior, V . Dumoulin, I. Mitliagkas, S. Escalera, J. Wan, S. Dane, M. Demkin, and W. Reade. Neurips 2023 - machine unlearning. h...
2023
-
[57]
S. Vallor. The danger of superhuman ai is not what you think. Noema Magazine , 23,
-
[58]
A. Vaswani. Attention is all you need. Advances in Neural Information Processing Systems, 2017
2017
-
[59]
Wallach, M
I. Wallach, M. Dzamba, and A. Heifets. Atomnet: a deep convolutional neural network for bioac- tivity prediction in structure-based drug discovery. arXiv preprint arXiv:1510.02855, 2015
2015 arXiv
-
[60]
R. A. F. Zanatta and M. Rielli. The artificial intelligence legislation in brazil: Techni- cal analysis of the text to be voted on in the federal senate plenary. Data Privacy Brasil Research, 2024. https://www.dataprivacybr.org/en/the-artificial- intelligence-legislation-in-br...
2024
-
[61]
Zao-Sanders
M. Zao-Sanders. How people are really using genai. Harvard Business Review, 2024. https: //hbr.org/2024/03/how-people-are-really-using-genai . 17
2024
-
[2023]
https://www.bloomberg.com/news/articles/2023-03-29/ai-chatgpt- related-prompt-engineer-jobs-pay-up-to-335-000
2023
-
[2024]
https://www.noemamag.com/the-danger-of-superhuman-ai-is-not- what-you-think/
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.