Rich Bowen
Working essay · October 2026

The Window We Cannot Miss

What social media should teach us about regulating artificial intelligence before scale becomes destiny

Rich Bowen · Technology, power & public responsibility

The argument

Society allowed social media platforms to reach enormous scale before imposing meaningful duties around transparency, safety, and systemic risk. Artificial intelligence could become far more consequential because it can generate, decide, persuade, and act. The answer is not to regulate every use of AI alike. It is to establish proportionate obligations before the most powerful systems become too embedded to govern.

The lesson arrived late

We did not entirely fail to regulate social media. Laws against fraud, harassment, discrimination, and illegal content still applied. Platforms developed moderation systems, and governments eventually imposed new transparency and risk-management duties. But much of that response came after the products, incentives, and market power were already established.

By then, engagement-driven systems had become infrastructure for friendship, news, commerce, political speech, and childhood. Changing them was no longer a matter of correcting a product. It meant intervening in institutions on which billions of people and businesses had come to depend.

The costs of delay are now easier to see. The U.S. Surgeon General has concluded that we cannot yet regard social media as sufficiently safe for children and adolescents, even while recognizing that it can provide connection and support. The European Union's Digital Services Act now requires the largest platforms to assess systemic risks, submit to independent audits, disclose aspects of advertising and recommendation systems, and provide researchers with certain forms of data access. [1] [2]

Those measures may be worthwhile. They also reveal how much harder governance becomes after scale, dependency, and business models have hardened.

AI is not social media again

The analogy has limits. Social media organizes communication among people. Artificial intelligence can generate content, interpret information, recommend decisions, and increasingly carry out tasks. Social platforms amplify human expression. AI systems can become participants in the process that produces the expression or decision itself.

This distinction matters because familiar platform rules do not cover every AI risk. Content moderation can address a prohibited post. It is less suited to a system that makes an unreliable medical recommendation, screens a job applicant, writes vulnerable software, impersonates a person, or takes an action through another service.

AI is also a general-purpose technology. The same underlying model can help a student understand algebra, assist a programmer, create a deceptive voice recording, or support a scientific investigation. Regulation aimed only at a list of forbidden outputs will miss how capability, access, and context combine.

We should learn from social media without pretending the technologies are identical.

Why the stakes may be larger

The phrase “orders of magnitude” should not be used as a measured fact. We do not yet know the full scale of AI's benefits or harms. It is better understood as a warning about reach.

Social media altered the distribution of information. Advanced AI may alter the production of information, the allocation of opportunity, and the execution of decisions. It can operate across education, employment, finance, health, security, government, and scientific research. A failure can be repeated at software speed, personalized to individual targets, and deployed across borders.

Some risks are familiar: bias, fraud, privacy loss, manipulation, and market concentration. Others become more serious as systems gain access to tools and infrastructure. A model that only produces text creates one risk profile. A system authorized to send money, modify code, contact people, or control equipment creates another.

The strongest argument for early regulation is therefore not that catastrophe is certain. It is that the technology may become deeply embedded before society has established who must test it, who must report failures, who can inspect the evidence, and who remains legally responsible when an automated action causes harm.

The false choice

Public debate often presents two options. Regulate AI and lose innovation, or allow innovation and accept the risk. This is a false choice.

Well-designed rules can make innovation more durable by establishing common expectations. Aviation, medicine, finance, and telecommunications did not stop developing because safety and accountability mattered. Their rules are imperfect, but the underlying principle is sound: the greater the potential consequence, the stronger the obligation to demonstrate care.

The opposite mistake is to regulate the word “AI” as though every use creates the same danger. A spam filter and an autonomous system controlling critical infrastructure should not face identical requirements. Neither should a small open model used locally and a frontier model deployed to millions of people with access to external tools.

The appropriate unit of regulation is often not the technology alone. It is the combination of capability, deployment context, scale, access, and consequence.

Regulate consequences

A useful regulatory structure begins with what a system can do and where it is used. Low-risk applications should remain lightly governed. High-impact uses should carry duties proportionate to the decisions they influence. The most capable general-purpose systems should face additional obligations because a single model can distribute risk across many downstream products.

This approach is already visible in policy. The European Union's AI Act assigns different obligations according to risk and establishes rules for general-purpose models, transparency, and high-risk uses. In the United States, the NIST AI Risk Management Framework offers a voluntary process to govern, map, measure, and manage AI risk across the system lifecycle. California's frontier AI law adds disclosure, critical-incident reporting, and whistleblower protections for large developers. [3] [4] [5]

These are not final answers. They demonstrate that governance can be more precise than either a ban or a promise to self-regulate.

What useful rules look like

First, developers of the most capable systems should evaluate dangerous capabilities before broad release. Testing should examine not only whether a model refuses a prohibited request, but whether safeguards remain effective when the model is connected to tools, fine-tuned, or placed under pressure.

Second, serious incidents should be reported through protected and clearly defined channels. Regulators cannot learn from failures they never see. Whistleblowers who disclose substantial public-safety risks should be protected.

Third, high-impact automated decisions should remain traceable to a responsible organization. A company should not be able to escape accountability by saying that the model produced an unexpected answer. Human review must be meaningful, not a ceremonial approval placed after an automated conclusion.

Fourth, independent researchers and qualified auditors need access to evidence. Public trust cannot depend entirely on safety claims produced by the company selling the system. Access must protect security, privacy, and trade secrets, but those concerns should shape oversight rather than eliminate it.

Finally, people should know when they are interacting with AI and when consequential content has been generated or altered by it. Disclosure will not solve deception, but it preserves a basic condition for informed judgment.

What regulation must avoid

Urgency can produce bad law. Rules written around today's model architecture may become obsolete. Compliance costs can protect established companies by making entry harder for smaller competitors. Broad restrictions on research or open development can concentrate power in the same firms regulators intend to constrain.

Regulation should therefore state durable outcomes where possible, support measurable standards, and include mechanisms for revision. It should distinguish research from mass deployment and experimentation from high-impact use. It should protect civil liberties and avoid turning safety into a justification for general surveillance or control of lawful speech.

Government also needs technical competence. An agency cannot oversee systems it cannot evaluate, and lawmakers cannot rely solely on the companies being regulated to explain what is possible. Public investment in measurement, standards, incident analysis, and independent expertise is part of regulation, not an optional supplement to it.

The window is still open

Social media's history does not prove that AI will produce the same harms. It shows what happens when governance begins only after a technology's incentives and dependencies become difficult to change.

AI regulation will always trail technical development to some degree. The goal is not to predict every capability or eliminate every risk. It is to create institutions that can observe, test, learn, and intervene before preventable harms become the price of participation.

There is still time to establish that power carries duties. Developers can be required to investigate foreseeable risks. Deployers can remain responsible for consequential uses. Regulators can demand evidence while allowing experimentation. Rules can become stronger as capability and impact increase.

The lesson of social media is not that technology should have been frozen before it changed society. It is that society should have asked for transparency, access, and accountability before a handful of platforms became too important to govern easily.

Artificial intelligence may become more powerful and more deeply embedded than social media ever was. If that possibility is credible, waiting for certainty is not restraint. It is a decision to let scale make the rules first.

The greater the potential consequence, the stronger the obligation to demonstrate care.

Sources & note

This is a policy argument informed by selected public sources. It does not claim that social media and AI create identical risks or that any existing regulatory framework is complete.

  1. U.S. Surgeon General (2023, reviewed 2025). Social Media and Youth Mental Health.
  2. European Commission. Digital Services Act obligations for very large online platforms and search engines.
  3. European Commission. AI Act regulatory framework and implementation timeline.
  4. National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework 1.0.
  5. State of California (2025). Transparency in Frontier Artificial Intelligence Act.

Read When Search Stops Being a List of Links →

← All essays