Field Dispatch

Corporate Self-Regulation: Does It Work?

PCI-DSS, aviation safety, UL. The pattern: every success requires external enforcement. Regulation creates the conditions for self-regulation to emerge.

2026-06-17 8 min read Dispatches
Contents

The frontier AI labs spent 2024 and 2025 telling Congress that the industry could regulate itself. The reference cases were aviation safety, Underwriters Laboratories, the Payment Card Industry Data Security Standard, and the nuclear industry’s Institute of Nuclear Power Operations. Each was cited as proof that voluntary, industry-led standards could produce safety at scale without state regulation strangling innovation.

Each of those cases is real. Each one works. And each of them required external enforcement to make the voluntary part work.

That is the part the AI labs leave out.


PCI-DSS

The Payment Card Industry Data Security Standard was created in 2004 by the major card brands (Visa, Mastercard, American Express, Discover, JCB) as a contractual framework binding merchants and processors that accept their cards. PCI-DSS is not law. It is a contract. The enforcement mechanism is loss of card-acceptance privileges, which for most merchants is loss of the ability to operate.

The results have been substantial. Card-present fraud, counterfeit cards swiped at physical terminals, fell roughly 76 percent in the United States after the EMV chip-card migration completed around 2015. The infrastructure that produced the drop was, in large part, PCI-DSS-enforced merchant upgrades. The card brands wrote the standard. The card brands enforced compliance through contractual penalties. The drop happened.

Card-not-present fraud rose during the same period to roughly $32.34 billion globally by 2021. The bad actors moved from physical cards to online transactions, where PCI-DSS controls are weaker and harder to enforce. The trend was foreseeable. The infrastructure that protected swipe transactions did not transfer to web checkouts.

The major breaches of the PCI-DSS era (Target in 2013, Home Depot in 2014, Heartland Payment Systems in 2008) all occurred at merchants who were certified PCI-DSS compliant at the time of the breach. Compliance is not security. The audit confirms that the controls existed on the day the auditor visited. The breach demonstrates that the controls were insufficient against the actual attack.

PCI-DSS works because the card brands have a monopoly on the payment rails, the contractual leverage to compel compliance, and the economic incentive to limit fraud that they otherwise have to absorb. None of those preconditions apply to AI safety. The AI labs do not have a monopoly on a payment network. They are not contractually downstream of a single fraud-absorbing entity. They have no equivalent of card brands writing rules that everyone who wants to operate must follow.

Aviation Safety

Commercial aviation is the safest mode of mass transport ever developed. IATA reported approximately 0.03 fatal accidents per million flights in 2023. The fatality rate per passenger-mile has fallen roughly 99.7 percent since the 1950s. The improvement is real. The systems that produced it are real.

The Aviation Safety Reporting System, run by NASA since 1976, has received more than 1.7 million voluntary reports from pilots, controllers, mechanics, and cabin crew. ASRS reports carry limited immunity from FAA enforcement action. The pilot who reports a near-miss is not punished for it. The system collects the data, identifies systemic patterns, and feeds the patterns back to the industry. The voluntary reporting works because the immunity is meaningful and the immunity is meaningful because the FAA’s enforcement authority is also meaningful.

The FAA writes type certificates, certifies pilots, audits airline operations, investigates accidents through the NTSB, and can ground an aircraft type globally. The 737 MAX was grounded for two years after the Lion Air and Ethiopian Airlines crashes. Boeing did not ground itself. The FAA grounded the aircraft after the second crash forced the issue. The voluntary self-improvement layer (ASRS, airline safety management systems, the Commercial Aviation Safety Team) runs on top of a regulatory floor that is among the most rigorous in any industry.

Aviation safety is the textbook case of self-regulation working. It works on top of a regulatory stick that is also the textbook case.

Underwriters Laboratories

UL Solutions, founded in 1894, certifies roughly 22 billion products per year for approximately 87,000 manufacturers. The UL mark is on light bulbs, extension cords, smoke detectors, lithium batteries, industrial equipment, and almost every consumer-electronics product sold in North America. The certification is voluntary. The market treats it as mandatory.

The market treats it as mandatory because building codes adopted UL standards by reference. Insurance underwriters require UL-certified equipment as a condition of coverage. Retailers refuse to stock uncertified products because their liability insurers refuse to cover the inventory. Local fire marshals enforce code provisions that incorporate UL standards. The voluntary mark works because every adjacent enforcement mechanism (code, insurance, retail, fire marshal) has made it effectively non-optional.

UL’s 130-year track record is real. The institutional architecture that makes it effective is also real, and it is not voluntary.

INPO

The Institute of Nuclear Power Operations was founded by the US nuclear-power industry in December 1979, eight months after the partial meltdown at Three Mile Island. The industry had concluded, correctly, that another major accident would end commercial nuclear power in the United States. INPO was the industry’s response: a peer-review and accreditation body funded by member utilities, with the authority to inspect plants, rank performance, and publish results inside the industry.

Since INPO’s founding, the US commercial nuclear-power industry has had zero radiation fatalities. Capacity factors have risen from roughly 56 percent in 1980 to above 92 percent in the 2020s. The industry’s safety performance is one of the cleanest in any heavy-industrial sector.

INPO works because the Nuclear Regulatory Commission also exists. The NRC writes the reactor licensing rules, conducts independent inspections, enforces operational limits, and can shut a plant down. INPO’s peer reviews are not redundant with NRC inspections. They are more frequent, more granular, and more focused on operational best practices. They also occur in a regulatory environment where a serious failure can end the industry. The industry self-organized because the alternative was extinction.

The AI safety advocates citing INPO want the self-organization. They do not want the regulatory environment that produced the self-organization.

The Pattern

Every successful example of industry self-regulation has one or both of two features.

It exists because external enforcement makes compliance mandatory. Building codes mandate UL-certified equipment. Card brands mandate PCI-DSS compliance through contract. The FAA mandates type certification, operational certification, and accident investigation. The NRC mandates reactor licensing and operational oversight. The self-regulation operates inside a regulatory shell.

Or it emerged after catastrophic failure that threatened the industry’s survival. INPO post-Three Mile Island. The FAA’s modern certification regime after the 1950s and 1960s accident rate that made the public refuse to fly. The card brands’ acceleration of EMV after the Target breach demonstrated that the existing infrastructure could not contain the loss exposure. The self-regulation emerged when the alternative was a market collapse the industry could not absorb.

Pure voluntary self-regulation, without external pressure, without the historical memory of catastrophic failure, is hard to find succeeding at scale. The examples that look like pure self-regulation generally turn out, on inspection, to be running inside an external enforcement shell that the industry stopped noticing.

The AI Safety Comparison

The NIST AI Risk Management Framework, the Frontier Model Forum, the various voluntary commitments at the 2023 Bletchley Park and 2024 Seoul summits, the Anthropic Responsible Scaling Policy, the OpenAI Preparedness Framework, the DeepMind Frontier Safety Framework. Every one of these initiatives cites aviation or nuclear safety as the model.

The aviation safety culture they cite came after decades of crashes and after the establishment of the FAA’s certification regime. The nuclear safety culture they cite came after Three Mile Island and operates inside the NRC’s licensing authority. The PCI-DSS regime they cite operates inside the card brands’ contractual chokehold.

The AI safety advocates want to skip to the self-regulation phase without building the regulatory foundation that made the self-regulation function. The Responsible Scaling Policy that Anthropic dropped in February 2026, the company’s hard commitment not to train more capable models without demonstrated safety measures, is the example case. The commitment was voluntary. Chief Science Officer Jared Kaplan’s stated reasoning was that the company “didn’t really feel, with the rapid advance of AI, that it made sense for us to make unilateral commitments … if competitors are blazing ahead.”

That is what voluntary self-regulation without external enforcement looks like. The most safety-committed lab in the industry, founded explicitly to be the safety lab, dropped its hard commitment because competitors had not made the same commitment. There was no regulatory floor. There was no enforcement mechanism. There was no equivalent of the FAA’s authority to ground an aircraft type, the NRC’s authority to suspend a license, the card brands’ authority to revoke acceptance privileges. There was a public commitment, an internal review process, and the commercial environment.

The commercial environment won. The commercial environment will always win against voluntary commitments. That is what voluntary means.


PCI-DSS works because the card brands enforce it. Aviation safety works because the FAA grounds aircraft. UL works because building codes require it. INPO works because the NRC can close a reactor. Each of these self-regulation success stories is a regulation success story with a voluntary layer painted on top.

The AI labs cite the voluntary layer. They do not cite the regulation underneath it. The regulation is the part that made the voluntary layer work. The voluntary layer without the regulation is a press release.

Click.


The receipts (free, on this site): the universal capture mechanism

This research appears in The Ratchet, Chapter 20 (“The Blueprint”).

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.