In September 2026, California Governor Newsom signed an AI safety bill into law. Why did the companies being regulated support the regulation? Goodwill and competitive strategy coexist without contradiction. For frontrunners, turning their existing safety practices into legal obligations is not a burden — it is a way to lock in their advantage by making those obligations apply to everyone, including latecomers who have not yet built the infrastructure.
01The bill that its targets backed
California's AI safety bill imposes certain safety standards on AI development and deployment. Governor Newsom, upon signing, called on the federal government to follow suit.
More notable than the bill's contents were its supporters. Anthropic and OpenAI both backed it. OpenAI issued a statement: "The policy window for AI is open — we need to act now." The companies that the law would regulate helped push it through.
The same week, Senator Bernie Sanders convened a classified briefing on the dangers of AI development. Geoffrey Hinton stated that a probability above ten percent of AI posing an existential threat within a decade is "not unreasonable." Pressure for regulation was building from inside and outside the industry simultaneously.
02Frontrunners welcoming regulation is a pattern pharma has seen before
It is rational for companies genuinely committed to safety to seek legal backing. If only they observe safety standards while competitors ignore them, the market penalizes the careful. Law applies to everyone. That is why law becomes desirable.
But another dynamic operates alongside. For companies that have already invested in safety infrastructure, codifying those practices into law adds no cost. For latecomers who have not made that investment, it becomes a barrier to entry. Goodwill and competitive advantage sit in the same statute.
In pharmaceutical material review, this pattern has recurred. A large firm builds a rigorous internal review system, then proposes that system as the industry standard. Smaller firms that never built such infrastructure now face compliance costs that the proposer absorbed years ago. The rule looks fair on paper. Its burden is not symmetric.
03The two-layer structure of self-regulation and statute is being woven now
In material review, self-regulation and statute have coexisted for years. The AI safety law is notable because these two layers are being woven in a new domain right now.
| Dimension | Self-regulation | Statute |
|---|---|---|
| Who decides | People inside the industry | Legislators and regulators |
| Non-compliance | Loss of industry trust | Legal penalties |
| Speed of revision | Consensus can move it | Amendment takes time |
| Effect on new entrants | May not know the code | Bound regardless |
Self-regulation is fast but has gaps. Statute is slow but reaches everyone. Rarely does one suffice alone. Just as JPMA's Promotion Code and pharmaceutical law complement each other, the two layers reinforce one another. The recognition that self-regulation alone is insufficient has now reached the developers themselves — that is the background to their support for this bill.
04The first real incident fell outside the law's scope
The ink was barely dry when a gap appeared. The first AI hacking incident in California fell outside the law's scope. The threats the law anticipated and the threats that actually materialized were different.
Law addresses threats known at drafting time. From the moment it is written, reality moves ahead. In fast-changing fields, law is always enforced one step behind. The question is not whether it lags — it will — but whether the law contains a mechanism for updating itself.
Limits of the drafting moment
A law responds to threats identified at the time of drafting. Unknown threats are structurally beyond its reach.
The first incident fell outside scope
That the first AI hacking case was not covered reveals what the drafters saw and what they missed.
Update mechanisms determine effectiveness
Whether a law remains frozen at the drafting moment or incorporates a revision cycle determines its real-world value.
05In material review, a rule's origin reshapes its application
In material review, a recurring scene: the person who helped draft a guideline later submits materials to be reviewed under it. The writer and the reader swap places.
Two things happen simultaneously. Because the person knows the rule's intent, the quality of submissions improves. Because the person also knows the rule's gaps, oversight must increase.
The same dynamic applies when Anthropic and OpenAI back the AI safety law. Having the makers inside the rules is not inherently wrong. But a state in which only the makers understand the rules is precarious.
A rule that works is one an outsider — someone with no access to the drafter's intent — can read and reach the same conclusion. The test California's AI safety law will face is whether regulators and courts outside the tech industry can apply it without needing a technical advisor in the room. That question is separate from whether the law is well-intentioned. It is about whether the law is well-constructed.
06Pressure from inside and outside starts from the same recognition
Regulatory pressure comes from two directions: inside the companies and outside them.
Inside pressure means developers themselves ask for safety standards to become law. The California bill is closer to this. The intent is to convert their own practices into obligations for everyone.
Outside pressure means researchers and legislators identify dangers and demand legislation. Senator Sanders's classified briefing and Hinton's statements are closer to this. The position is that developers' self-governance cannot be trusted.
Pressure from within
Developers seek to make their safety practices into legal obligations binding on the entire industry.
Pressure from without
Researchers and legislators identify risks and demand legislation, distrusting developers' ability to self-regulate.
The question is not which side is right. Both agree that the absence of regulation is untenable. They differ on who should write the rules. When inside pressure shapes the statute's text and outside pressure shapes its enforcement, the two can reinforce each other. The pharmaceutical industry has navigated this tension for decades. AI regulation is passing through it far faster, with far less institutional memory to draw on.
07Trace the origin of every rule you apply
Years in material review change your relationship with regulation. At first, rules look like constraints — walls around what you want to do. Then they start to function as authority. When a judgment is difficult, the rule lets you say "this does not pass" with the force coming from an external standard, not your personal opinion. That support is real.
The AI companies' embrace of regulation may reflect this same structure. The justification for continued safety investment cannot be sustained by market competition alone. If a law makes safety spending mandatory, it becomes an obligation. Obligations are easier to explain to shareholders.
What material review professionals can do is trace the origin of the rules they work with. Who drafted the rule? What interests were at stake for the drafter? Even when a rule is fair in substance, knowing the circumstances of its creation changes how you apply it.
| Verification | Without knowing the rule's origin | With knowing the rule's origin |
|---|---|---|
| Stringency | Follow uniformly | Can weigh the interests behind the stringency |
| Exceptions | Judge by the text alone | Can infer intent not written into the text |
| Participation in revision | Hard to enter the debate | Can propose amendments with informed context |
- Anthropic and OpenAI backed California's AI safety bill. For companies that have already invested in safety, codifying their practices into law costs nothing extra and raises the barrier for latecomers. Goodwill and strategy coexist in the same statute.
- Immediately after signing, the first AI hacking incident proved to be outside the law's scope. Law can only address threats known at drafting time. Whether it includes an update mechanism determines its real-world effectiveness.
- In material review, tracing a rule's origin — who wrote it and what interests were at stake — changes how you apply it. Even fair rules gain precision when you know the circumstances of their creation.
California's AI safety law is a first step — one that failed to cover even the first real incident. Yet the fact that the developers themselves sought regulation is worth recording. Regulation has shifted from something imposed to something invited. The next questions are how fast the law can be updated and whether people outside the drafting room can read it and reach the same conclusions. For those of us in material review, the takeaway is one: trace where your rules come from.
- AI Industry Analysis Report. September 10, 2026. (California governor signs AI safety bill backed by Anthropic and OpenAI; calls on federal government to follow)
- AI Industry Analysis Report. September 10, 2026. (First "rogue AI" hacking incident not covered by the newly signed law)
- CBS News. September 2026. (Geoffrey Hinton: "A probability above 10% of AI posing existential risk within a decade is not unreasonable")
- AI Industry Analysis Report. September 10, 2026. (Senator Bernie Sanders convenes classified AI briefing on "extraordinary dangers")
- Ian Kerr & Jason Millar. Expectations of Artificial Intelligence. (Analysis of the "pacing problem" — structural gap between technological change and legislative response)
- Lawrence Lessig. Code and Other Laws of Cyberspace. Basic Books, 1999. (Four modalities of regulation: law, norms, market, architecture)
- JPMA. Promotion Code for Prescription Drugs. (Two-layer structure of self-regulation and statute in pharmaceutical advertising)
- OpenAI. September 2026. ("The policy window for AI is open — we need to act now")