There's a comfortable consensus settling over the cybersecurity industry right now. AI needs rules. The E.U. is building them. The U.S. will follow, eventually. Companies should prepare compliance roadmaps. Boards should ask their CISOs tough questions. We nod along, file it away, and assume the next five years will look like the last five: regulation arrives, industry adapts, the world continues.
This consensus is almost certainly wrong about what matters most.
The obvious framework assumes that AI regulation will work like previous technology regulation. We'll draw lines around training data, algorithmic transparency, bias testing, and liability. Some companies will grumble about compliance costs. Startups will find loopholes. The market will adjust. This is how it has always worked, so this is how it will work again.
But what if the real break point isn't about how rules get written? What if it's about the speed at which the ground shifts beneath those rules?
Consider what happened when E.U. regulators ordered Google to open Android's microphone, camera, and screen access to rival AI assistants. On the surface, this looks like standard interoperability enforcement. Fair competition. Level playing field. The consensus narrative writes itself: smart regulation, necessary guardrails, everyone adapts.
But step back. That order assumes the competitive landscape will remain relatively stable. It assumes Google's dominance in voice assistants will persist long enough for the remedy to matter. It assumes rival assistants will exist in meaningful form by the time compliance deadlines arrive. What happens if the entire category of "voice assistant" becomes obsolete in 18 months? What happens if AI capability advances so quickly that today's regulatory definitions of "assistant" or "algorithm" or even "training data" become functionally meaningless?
The consensus says: regulation creates stability, which allows business planning, which lets the market function. This is true in stable industries. But we are not in a stable industry.
The real risk isn't that AI regulation will be too strict or too loose. The risk is that regulation will calcify assumptions about what AI is and what it should do, right at the moment when those assumptions stop matching reality. Regulators will spend three years building frameworks around large language models, training data provenance, and bias audits. Then the architecture of useful AI will change fundamentally, and those frameworks will become either irrelevant or worse: they'll become barriers to the new thing everyone actually needs.
This has happened before. We still have regulations written for desktop computing. We have telecom rules built around voice calls. These aren't quaint relics; they actively slow down how quickly companies can move and how flexibly they can respond to new threats.
Here's the better question: What will AI regulation break that we're not currently thinking about?
Will it break the relationship between security teams and product teams, by making compliance a veto power rather than a collaborative constraint? Will it break the ability of smaller companies to innovate, by making regulatory expertise a fixed cost only giants can afford? Will it break the feedback loops between researchers and deployed systems, by making experimentation riskier? Will it break the open-source communities that have historically driven security innovation, by making liability chains too complex for volunteers?
The consensus thinks regulation solves problems. Maybe. But it definitely creates new ones, and the industry should be wargaming those harder right now.
The comfortable answer is: regulation is coming, prepare for it. The harder answer is: regulation is coming, and you should understand exactly what it breaks before you optimize for compliance with it.