The internet’s founders governed a technology nobody agreed on, without kings, presidents, or voting. Congress still can’t figure out how.

The excuse for not regulating AI is that nobody can agree how. The people who built the internet would find that laughable.

One after another, the people building the most powerful AI in the world have asked to be regulated.

Dario Amodei, who runs Anthropic, published a 3,800-word essay calling for the industry to slow down and submit to outside oversight.

Sam Altman of OpenAI agreed within the day.

So did Elon Musk.

So did Demis Hassabis, who runs Google DeepMind.

Kevin Roose put it bluntly, “The platforms should be absolutely begging Congress to regulate them, because the alternative is they get sued into oblivion by a bunch of law firms.”

Congress, in response, said no.

Speaker Mike Johnson waved it off. His reasoning, that the government cannot really act because the industry itself cannot agree on what the rules should be, is a farce. No consensus, no legislation. The White House went the other way when AI czar David Sacks said the companies should simply “pace the frontier” themselves, and the President told everyone to stop trying to kill the Golden Goose.

The result is that the two positions on the table are “we can’t regulate it because they don’t agree” and “we don’t need to, they’ll regulate themselves.” Both are excuses.
While Washington argues about whether it can act, the people who actually build things are already shipping.

We know they are excuses, because the people who built the internet were handed the same problem thirty years ago, a crowd of brilliant people who profoundly disagreed and a technology moving faster than anyone could govern, and they solved it.

In 1992, at a meeting of the Internet Engineering Task Force, a computer scientist named David Clark stood up and gave the young internet its governing philosophy in a single sentence, “We reject kings, presidents, and voting. We believe in rough consensus and running code.”

He was not speaking in the abstract. He said it in the middle of a war most people have forgotten, one Andrew Russell has spent his career documenting. Through the 1980s and early 1990s, two visions competed for how computers should talk to each other.

One was the internet’s, TCP/IP, built from the bottom up by engineers who shipped working code and standardized whatever survived contact with reality. The other was called OSI, a complete and elegant framework designed top down by international committees, backed by European governments and mandated by the US Commerce Department for federal computer purchases. OSI had the institutions, the process, and the official consensus. The internet had rough consensus and running code.

At that very 1992 meeting, roughly 700 engineers revolted against their own leadership for suggesting they adopt a few OSI protocols, and the leaders, Vint Cerf among them, backed down. They wanted no part of the committee’s grand design. Clark titled his talk “A Cloudy Crystal Ball,” and gave it a second title too, “Apocalypse Now.”

The internet went on to win so completely that OSI collapsed under the weight of its own process. Russell, who wrote the definitive history of the whole fight, put the strangeness of it plainly, saying, “It’s almost alarming that something that recent can be so easily forgotten.”

You have probably never heard of the standard the government spent a decade backing.

Lawrence Lessig later called Clark’s line “a manifesto that will define our generation.” Lessig meant something larger though,how you govern something new and fast-moving that nobody fully understands yet.

That is basically the whole response to Mike Johnson’s reasoning. The consensus-first model already went to war with the ship-and-iterate model, in the actual history of the internet itself, and consensus-first lost. It lost because you cannot govern something new by waiting for everyone to agree on the finished specification first.

I have spent my career building digital products and what Johnson is actually doing, is something every product person will recognize immediately. He is refusing to ship until every stakeholder agrees and the requirements are complete.

That is the single most reliable way to kill a product, and everyone who has ever built one knows it. It is why we abandoned the waterfall process years ago.

You only arrive at certainty by building something, carefully, and learning in the open.

Regulating AI is a product problem, and right now Congress is a bad product owner.

Rough consensus and running code

They did not vote. They hummed, shipped what worked, and revised the rest. It built the internet.

What should embarrass Congress is that the method already exists. It has existed for more than fifty years, it is thoroughly documented, and it was invented by people solving a harder version of this exact problem.

When the engineers building the early internet needed to agree on how it would work, they did not convene a commission or wait for a finished rulebook. In 1969, a graduate student named Steve Crocker started writing up proposals and circulating them for reaction, and he was so worried about sounding presumptuous that he called them “Requests for Comments.” The name stuck.

The foundational documents of the internet, the specifications that still run the internet, are literally called requests for comments, because they were drafts, never meant to be handed down finished. You published one, people argued with it, you revised, and the parts that worked survived.

That process had rules, and the rules were the opposite of Mike Johnson’s. The IETF made decisions by “rough consensus,” which one of its own documents is careful to define as agreement reached “when all issues are addressed, but not necessarily accommodated.”

It was not unanimity, and it was not majority rule. It meant enough agreement, with the serious objections genuinely engaged, to move forward and ship.

Nobody had to be fully satisfied. Nobody got to stop the whole enterprise by withholding their blessing.

They even had a method for measuring it. Instead of voting, IETF engineers hum. The chair poses a question, the room hums, and the hums are judged by volume and intensity. A loud hum from a few people signals a real objection worth working through. A weak hum all around means you have not reached consensus yet.

It sounds ridiculous, and it is, but it also built the internet, on time, while running circles around a committee with government backing and a formal ballot process.

The genius of it, and the part that matters for AI, is that nothing was ever final. The internet’s standards process moved a proposal through stages, draft, then proposed standard, then full standard, and any of it could be revised as reality taught you something the spec had missed.

This is the thing every product person does for a living.

You ship a version, you watch what it does to real people, you fix what you got wrong, and you keep going. The rules improve because they are allowed to change.

Congress is still writing in waterfall, stuck in a world that is quickly passing them by. It wants one comprehensive, dare I say beautiful, AI bill, fully specified, passed once, ideally after everyone agrees, which is to say never.

The internet’s builders would have found that laughable. They governed a technology that was changing under their feet, and they did it by treating governance the way good teams treat a product, as a living thing you steer, not a monument you unveil.

None of this is foreign to government either, whatever Congress tells you. Prohibition took effect in 1920, written directly into the Constitution, and it failed on contact with reality so completely that thirteen years later a second amendment repealed the first, the only time in American history one amendment has undone another. The founding document itself got a patch.

The closest parallel to this exact moment takes place after the 1929 market crash, when Wall Street insisted the markets were too complex for outsiders to regulate and that the industry should police itself. Congress created the SEC anyway, a standing body with the authority to write and rewrite the rules as the market kept changing under it.

Bob Greifeld, who ran Nasdaq for over a decade, points to exactly that history as the model for AI, noting that “the SEC of 2026 is a faint echo of what was created in 1934.”

Governing by revision is how the country’s hardest rules have always actually been made.

The tools are sitting right there. We wrote them down. We have been using them for generations.

The interface is the loophole

The right was real. Getting to “no” was made deliberately impossible. That gap is where good intentions become dark patterns.

Say Congress surprises everyone and passes a law. It works out what it wants, it gets rough consensus, it ships. There is still one place the whole thing can quietly die, which may not seem completely obvious to most people, but it is arguably the most important.

The interface.

A good product team knows what Congress keeps forgetting, that you are not building for the company that has to comply. You are building for the person the rule is supposed to protect.

Right now the interface gets designed by the party with the least reason to make it honest, which is exactly backwards.

We have watched this happen already with GDPR. Europe’s data-protection law did something genuinely good in principle, giving people a right to control whether they are tracked, requiring that any consent be “freely given, specific, informed, and unambiguous.” Companies now had to ask before dropping cookies on you. A real right, handed to real people.

The trouble showed up immediately. On the very day GDPR took effect in 2018, privacy lawyer Max Schrems, the activist most responsible for putting the law on the books, filed complaints arguing that the consent companies were collecting was a sham. “Forced consent,” he called it, a choice engineered so the only easy answer was yes.

The companies, meanwhile, got to design how you’d exercise it, and you know exactly how that went, because you have clicked through it ten thousand times. “Accept All” is a big glowing button. “Reject” is greyed out, or buried behind “Manage Preferences,” or split across nineteen individual toggles, or simply absent.

The right technically exists. Exercising it was made deliberately miserable. Harry Brignull had already named this years earlier, in 2010, when he coined the term “dark patterns” for interfaces built to trick people into choices they would not otherwise make. His vocabulary was so obviously describing something real that it migrated out of the design world and into actual law, cited now in European regulation and American enforcement.

To be fair, GDPR was not useless. When you measure what it did to actual tracking rather than to your blood pressure, it moved the needle. Guy Aridor, Yeon-Koo Che, and Tobias Salz studied an online travel company and found that GDPR cut the number of tracking cookies by 12.5 percent.

Vincent Lefrere, Logan Warberg, Cristobal Cheyre, Veronica Marotta, and Alessandro Acquisti found the effect reached even US users before any American law required it.

John M. Yun summed up the early verdict plainly, saying, “the evidence in the aftermath of the GDPR is that it worked, in the sense that firms were using less data.”

The win was real but partial. Aridor’s own study found that among the users who stayed trackable, tracking actually intensified.

The law made companies ask before they tracked you, but it didn’t touch what they were allowed to do once you said yes.

Where it failed was the part it left unspecified. It said get consent. It did not say what asking for consent had to look like, and so the companies being regulated designed the asking, and they designed it to fail.

This is the most basic thing a product person knows and a legislator apparently does not.

An underspecified requirement does not get built well. It gets built in whatever way is cheapest and most self-serving for whoever is building it.

Ask the growing graveyard of apps that shipped fast and leaked everything: a sales tool whose founder bragged it was built with “zero hand-written code” and got hacked into oblivion within two days, a platform where anyone could walk into private apps with a single public ID, an AI app-builder that quietly shipped 170 sites exposing users’ personal data.

Iterate on the rule all you want, just don’t leave out what the person actually sees and clicks, because that is where good intentions become dark patterns.

The European Commission has admitted it, conceding in its own memo that the consent banners “might not achieve their aim” and that a fix for “the proliferation of cookie banners is long overdue.” Matt Burgess wrote in Wired that we need to fix GDPR’s biggest failure.

The regulator and the tech press agree that the law was right about the goal and naive about the execution.

The encouraging part is what regulators are doing now, because it looks a lot like running code. They are no longer only writing down outcomes and hoping. They are starting to regulate the design itself.

The EU’s proposed Digital Fairness Act targets deceptive interface design directly, by name. France’s data-protection regulator fined Google €150 million and Meta €60 million for exactly one thing: making it harder to reject cookies than to accept them.

In the US, the FTC’s “click-to-cancel” rule, which would have forced companies to make canceling a subscription as easy as signing up, was vacated by a federal appeals court in 2025 because the agency had skipped a required analysis of the rule’s costs. The FTC then went back and restarted the rulemaking to try again.

The lesson for AI could not be more direct. Nearly every AI rule anyone is proposing is a right exercised through an interface. The right to know you are talking to a machine and not a person. The right to see why an automated system denied your loan or flagged your kid. The right to opt your work out of a training set.

Grant those rights and leave the disclosure notice, the appeal process, the opt-out flow to be designed by the companies the rules are meant to constrain, and you already know what you will get. You will get a checkbox nobody can find and an appeals process that is a search for a phone number that does not exist.

The right will be real. The interface will make it worthless.

Patrick Neeman borrows the language of car crashes when writing about this. The first collision is the model being wrong. The second is what the interface does with that wrong answer on its way to a person, confident prose, no visible uncertainty, a fabricated number pre-filled into the field you were about to send.

Engineers spent decades unable to prevent the first collision, so they padded the interior for the second one.

AI has no padded interior. That is a design job, which means it is not going to get done by waiting for Congress.

If you are going to regulate AI, you cannot stop at what the companies must allow. You have to get specific about what it has to look like when a human being actually tries to use it. That is just knowing where the bodies are buried.

We already ran this experiment

We let one industry govern itself for fifteen years. It took a whistleblower with a hard drive to tell us how that went.

The other position from the opening, the one the White House is pushing, is that we do not need any of this because the companies will regulate themselves.

When the AI companies asked for oversight, JD Vance told them that if they were “building Frankenstein,” the answer was not regulation but to “build the defensive mechanism against Frankenstein.” The people who made the monster should build a bigger net, and leave the government out of it.

We tried that. Not as a thought experiment, as a fifteen-year live trial, and the technology was social media.

Social media grew up almost entirely unregulated, on the motto Facebook famously put on its office walls, “move fast and break things.” That was iteration, technically, but with none of the guardrails. Ship whatever keeps people scrolling, break whatever slows that down, and don’t think too hard about what you’re breaking.

The internet’s founders were iterating toward something real, a network that worked, that anyone could build on. Facebook was iterating toward one number that mattered to them, the time you spent in the app.

Its founding president, Sean Parker, admitted that the design question from the start was “how do we consume as much of your time and conscious attention as possible,” and the answer was to hand you “a little dopamine hit” every time someone liked your post, “a social-validation feedback loop” built by “exploiting a vulnerability in human psychology.”

We know exactly how the self-regulation went, because someone inside brought receipts. In 2021, Facebook product manager Frances Haugen copied tens of thousands of internal documents and handed them to the Wall Street Journal, the SEC, and Congress.

The reporting that followed, the Facebook Files, showed something worse than a company that did not know. It showed a company that knew, in detail, from its own research, and kept the findings quiet.

One internal slide from 2019 put it in the company’s own words, “We make body image issues worse for one in three teen girls.” Facebook’s studies also found that 13.5 percent of teenage girls said Instagram made thoughts of suicide worse.

Jeff Horwitz later wrote a book, Broken Code, on how the company’s own researchers kept finding the harm and executives kept declining to fix it.

It landed in the middle of what the U.S. Surgeon General would soon call a youth mental-health crisis, warning that social media use “is associated with harm to young people’s mental health.”

The company had the data. It ran a research program good enough to find the harm, and then it left the harm in place, because fixing it would have meant slowing down.

To be fair to other side, Zuckerberg pushed back hard, writing that the idea the company prioritized profit over safety was “just not true,” and asking why a company that wanted to ignore research would fund a research program to find it.

What is not in dispute is that the research existed, that it documented real harm, and that the fixes did not come from inside. They did not come at all until an employee smuggled the evidence out.

That is the actual track record of “let them regulate themselves.” The problem was a company that could not be the thing that stopped itself, because everything that would have slowed it down was in tension with the only number that mattered. Haugen’s own request to Congress is the part that should echo right now.

She wasn’t looking for them to punish Facebook, but just asking them to help, because the company, she said, could not fix itself on its own.

Aaron Sorkin made a film about it, The Social Reckoning, about Haugen and the Facebook Files. The AI industry is standing in front of Congress making the