Hard law, soft law, and self-governance: the three roads to AI rules
Different parts of the world are reaching for AI governance in very different ways. Understanding the three basic models clarifies the whole map.
- 01AI governance broadly takes three forms: binding law, voluntary frameworks, and industry self-governance.
- 02Each model trades enforceability against flexibility and speed.
- 03Most mature regimes end up combining all three rather than choosing one.

One technology, three philosophies
Governments and institutions confronting AI have, broadly, three tools available, and the choice between them reveals a lot about a jurisdiction's underlying philosophy.
Hard law is binding regulation with penalties — statutes, enforceable obligations, regulators with teeth. Soft law is voluntary or quasi-voluntary frameworks — codes of practice, standards, guidance, principles that organisations are encouraged but not strictly compelled to follow. Self-governance is industry doing it itself — company policies, internal review boards, sector commitments, and shared technical standards developed by the builders.
No serious actor relies on only one. But the emphasis a jurisdiction places on each tells you what it's optimising for.
Hard law: enforceable but slow
The strength of binding regulation is obvious: it has teeth. When an obligation carries real penalties, organisations take it seriously and invest in compliance. It creates a level playing field — everyone faces the same rules — and gives the public a clear accountability mechanism.
The weaknesses are equally real. Hard law is slow to write and slower to amend, which is a problem for a technology that moves fast; rules can be outdated before they take effect. It risks being either too specific (locking in assumptions that age badly) or too vague (leaving everyone guessing). And it can impose compliance costs that smaller players struggle to bear, unintentionally entrenching incumbents.
Soft law: flexible but optional
Voluntary frameworks and standards occupy the middle ground. They can be developed quickly, iterated as understanding improves, and tailored to context. They let good actors demonstrate responsibility before binding rules exist, and they often become the de-facto baseline that later hardens into law. Risk-management frameworks and voluntary principles have shaped how many organisations approach AI long before any statute required it.
The catch is in the name: they're voluntary. A framework only constrains those who choose to adopt it, and the actors most in need of constraint are often the least likely to opt in. Soft law is excellent at raising the ceiling for responsible organisations and poor at raising the floor for everyone.
Self-governance: fast but conflicted
Industry self-governance is the fastest-moving option because the people closest to the technology write the rules. Internal safety teams, model-release policies, evaluation commitments and shared technical standards can respond to new capabilities in weeks rather than years.
The obvious objection is the conflict of interest: asking companies to regulate themselves invites exactly the corner-cutting under competitive pressure that regulation exists to prevent. Self-governance works best as a complement — a fast first layer that handles detail and emerging issues — rather than as the whole structure. Its credibility depends heavily on transparency and on whether commitments survive contact with commercial incentives.
Why mature regimes blend all three
In practice, the most developed approaches layer the three together. Hard law sets the non-negotiable floor and the bright-line prohibitions. Soft law and standards fill in the operational detail and adapt as the technology shifts. Self-governance handles the fast-moving frontier where the law simply hasn't caught up.
This layering isn't a failure to choose — it's the sensible response to a technology that's powerful, fast-moving, and genuinely uncertain. A purely hard-law approach can't keep pace; a purely voluntary approach can't bind the actors that matter most.
How to read any new AI policy
When a new governance development crosses your desk, ask which of the three it is. Is it binding, and on whom? Is it voluntary, and who'll actually adopt it? Is it self-imposed, and what happens when it conflicts with the bottom line? That single question cuts through most of the noise and tells you how much the development actually changes — and for whom.
Ask Relay — he reads every question himself and replies personally by email.
