You can find the Palisade Research podcast on Spotify and Apple Podcasts, or anywhere else you get your podcasts.
Matthew Lipka is a partner at Catalyst Wayfare Partners, where he advises and invests in emerging technology companies in highly regulated spaces: autonomous vehicles, fusion energy, robotics, and AI. He was previously head of policy at Nuro, where he secured the first and only US Department of Transportation exemption for an autonomous vehicle and the first commercial autonomous vehicle deployment permit in California. Before that he worked at McKinsey, at the White House Office of Information and Regulatory Affairs, and as chief of staff at the New York MTA.
Dave Kasten, Palisade’s Head of Policy, talks with Matthew about what regulation actually is and how it gets made: the Administrative Procedure Act, notice and comment, OIRA review, and why a new federal rule now takes nine years on average when the highway regulator once adopted twenty standards in ten weeks.
They then dig into what this means for AI: why existing authorities are more flexible than people assume, what agencies can do quickly in a genuine emergency through interim final rules and export controls, where regulation can and can’t address concentration of power, and why the AI policy community’s habit of writing long Google Docs misses the formal channels that actually move rules. Matthew closes with a practical case that anyone can submit a comment or request a meeting with OIRA, no law degree required.
Transcript lightly edited for readability.
Matthew: You can just do things regulatory edition, The process is set up specifically because we want public input. You can just submit that comment. You can just request a meeting with OIRA. You can request a meeting with the agency you don’t have to go to law school or be a DC lawyer in order to influence a regulation.
Dave: Hi, and welcome to the Palisade Podcast. I’m Dave Kasten, Head of Policy at Palisade Research. Today, we’ve got a great episode for you. We’re joined by my very good friend, Matthew Lipka, who’s a partner at Catalyst Wayfare Partners, where he advises and invests in emerging technology companies in highly regulated spaces. That’s things like autonomous vehicles, fusion energy, robotics, and AI. Previously, he was head of policy at Nuro, which builds and deploys electric autonomous vehicles in partnership with companies like Uber. There, he oversaw federal, state, and local policy, government relations and public affairs, as well as the company’s sustainability program. In that role, he shaped national autonomous vehicle policy. He was the first and only person to get the US Department of Transportation to approve an exemption for an autonomous vehicle, the other guys weren’t able to get it, and the first commercial deployment permit granted in California for an autonomous vehicle and shaped the first federal rulemaking, which we’ll talk about in this episode, on autonomous vehicles. And he’s advocated for new regulation and legislation, federally and at the state and local levels. Prior to all of that, he led consulting teams for public and private sector clients, at McKinsey & Company. He worked on regulations at the White House. He served as a chief of staff at the New York MTA, and was a fellow for Senator Sheldon Whitehouse, of Rhode Island. Matthew holds a bachelor’s degree from Yale University, which is where he and I first met, and a JD from Harvard Law School. I think you’re really going to enjoy this conversation. So without further ado, let’s jump in. Matthew, thank you for being here.
Matthew: Oh, thanks so much for having me. Great to be on.
Dave: Why don’t we start by just talking a little bit about sort of your journey and how you got into being so focused on regulation?
Matthew: Sure. So, I went to law school and had the opportunity to study under Cass Sunstein, who is the most prolific. Legal writer of all time. I think he’s 5 times as many citations as number 2.
Dave: He was an LLM before there were LLMs.
Matthew: [laughs] indeed.. And in addition to that is brilliant and led the Office of Information and Regulatory Affairs, which is the most powerful office no one’s ever heard of, sometimes called the regulatory czar. And so I got really interested in regulation because I went to law school, but I really wanted to do policy. And regulation is the closest you can get to policy if you’re going to law school. And, so I spent time in DC, at OIRA, at other White House offices, Domestic Policy Council, really focused on how do we set rules, in my first love, transportation, but also, other sectors where we have new innovative technologies that are kind of breaking the existing paradigms. And our existing rules either hold them back in ways that don’t make any sense, or make them let them go free in ways that could have harms to society and are not good for the responsible players.
Dave: Yeah. So I think part of what I’m really excited about to talk in this, conversation, which we’re going to focus mainly on sort of regulatory administrative state kind of stuff. You also know a lot about, as we, I mentioned in the intro, you know a lot about Congress. You know a lot about state and local stuff as well. We’re saving that for a future podcast, I think one of the things I’m really excited to talk to you about, on this podcast, because I’ve talked about it many times over, a cocktail, is I think there’s this oversimplification that happens sometimes in AI policy where kind of people end up getting backed into these corners where either all regulation good or all regulation bad, or even just on a certain topic, regulation on that topic is always good or always bad. And I think one of the things I’ve learned the most from you is when you get underneath the hood and actually talk to companies that are trying to figure stuff out, even very early stage startups, or when you talk to regulators basically nobody who actually is trying to wrestle with things on a ground level seems to feel that way. Is that a fair characterization? And if so why is that?
Matthew: Regulation is just an interpretation of a law. Right? It’s just Congress passed a vague law, like no restraint of trade or no unfair or deceptive practices. What does that mean? And if you’re a business, you want clarity. And it is very unclear what it means, when it just says something so vague. And so regulations spell that out. And then you have other things like guidance which says, “Well, we’re not. You can’t hold us to this, but, this is kind of how we’re thinking about it.” And that gives you even more clarity because you understand that, “Okay, if I do this, I’m probably not going to get in trouble.” And so most companies want that. Also, at least companies that want to do good in the world, and most people think they want to do good in the. Are trying to, be the best, right? And so they want regulation to actually be kind of shutting the door behind them in some, sometimes, such that, you don’t have a dangerous player. So if you take autonomous vehicles, for example Waymo has now gone 200 million miles. They are proven to be 10 times safer than a human driver. That’s pretty good. But the technology is now good enough that you could probably build as a senior in college with one friend, an autonomous vehicle and just drive it on the road, right? And that is somewhat worrisome if you are the market leader or in the top 5 to say, “Okay, well, they could have a crash and then we get a bad reputation for the whole industry.”
Dave: Right. Because the headline is just autonomous vehicle crashes, not that it’s an autonomous vehicle designed by a couple college students as their senior project crashes. It’s not the same as sort of all the edge case logic you get when you hire many people after they graduate from college. Build it out.
Matthew: Right. Policy’s very reactive, so if that happens, you’re going to see an overreaction. Right? Like, “Okay, let’s make a rule that will prevent this specific thing from ever happening again,” and it’ll inadvertently swoop in all sorts of other stuff because it’s focused on an edge case.
Dave: Yeah. And so I think let’s dive a little bit into what is regulation? Maybe you can sketch out for our listeners when people say at the federal level, let’s start there maybe,
Matthew: Yeah. So most broadly, the federal government does 5 things. Okay? It spends money. It delivers services like an army and a postal service. It collects and disburses information, like the Bureau of Labor Statistics-. Something like that. Enforces the rules or enforces the laws, and it does foreign affairs. So regulation is a subset of enforce the laws because Congress passes these vague statutes that I alluded to, and then, in order to enforce it, they need to adjudicate it and decide if we should sue. And they want rules that govern that. So regulation is just a set of principles that expound in greater detail what the law that Congress passed, says. And rules are good because they give that certainty to the regulated public. In addition to the rules, they can do what we call guidance. This is a variety of forms. Interpretive statements of. Things like that don’t have to go through as formal of a process, although they can. And that lets okay, they didn’t just say in a tweet that they’re going to go do this. They went through a formal process. They had to get approval by the general counsel of the agency.
Dave: Uh-huh.
Matthew: They might have even done voluntary, notice and comment to get input on it, and they published this PDF, right? So that’s pretty good prediction that they’re going to do something. So those are the different, kinds of things they can make, and it is governed by what’s sometimes called the Constitution of the Administrative State, which is the Administrative Procedure Act.
Dave: So, maybe let’s jump from there to talk to a little bit about. Let’s say that there is sort of the political capital that emerges in order for Congress to actually do something on an issue. Let’s say it’s AI, right? And of course there is on some aspects of AI already, but about something that they haven’t touched already. Let’s say that it is the case that there is a for whatever reason, a policy window that opens up and Congress passes a law that says the Department of Commerce or whoever has to go regulate the following things that it doesn’t currently regulate. Once it does that law, let’s say gets passed, gets signed. Let’s say that even happens pretty quickly. How long from there? Walk me through the process of all those steps and how long it takes to get from that law being passed to a final regulation actually being in place, and then from that regulation being in place to stuff happening in the world as a result of that regulation.
Matthew: So, it takes a long time. It didn’t used to be this way. So I’ll use NHTSA because I. Which is the highway regulator, autonomous vehicles as an example. When they were founded, really within 10 weeks, because they didn’t have any funding at first, they. Like, within 10 weeks, they adopted 20 standards for here is what it means to have safe brakes and safe, steering wheels, et cetera.
Dave: Mm-hmm. And those standards, were they more like the. They were more like the guidance than the regulation thing?
Matthew: No, they were regulations. They adopted industry standards, so it moved faster. But, even so, rules didn’t. You were. Could be done in a couple years, or less. And now it takes about 9 years on average to do a new rule. To give you a sense, in 2013 to 2015, Congress required NHTSA to make 22 rules. The way they do a big, a big service transportation reauthorization, so they require a bunch of stuff at one time. So they said 22 rules. As of a couple months ago, they had done 6 of those, and they missed the statutory deadline on all of those 6. So they’re like 0 for 22 on hitting the deadline and 6 for 22 on even doing it So what is the process to. And why, and you’ll see why it takes so long. And I’m going to go into a little bit of detail because one of the things we should talk about is, okay, I’m an AI person. What can we do in this?
Dave: Yep.
Matthew: So I want to show the different spots. So you have a, you have an idea of some, of a rule is needed. It could be from a new statute, like you said, or it could be just a political decides you want to do it. The first thing you do is you put in the regulatory agenda that says, “We’re thinking about this. It’s on the plan.” every 6 months, they put out, “Here are all the rules we’re thinking about doing, proposed rules, final rules.” You can actually comment on this if you want. Almost no one does. But they put it out, and so you can see the future. These are the rules they’re going to do. Then they figure out what to write. They might start by collecting information. Could be informal consultations, a hearing, or something called an advanced notice of proposed rule-making. So even before the proposed rule, you can do an advanced notice of proposed rule, which is basically a request for information, a list of questions that people can submit information-. In response to. Then they will write the rule. When they write the rule, they will use that information or other sources, and, then they will, get it. Go through a clearance process. So they’ll have an internal process at the. General counsel and so forth.
Dave: And just for clarity, that’s different than security clearances. This is the word being used in another meaning.
Matthew: Indeed, yeah. It’s like clearing it to go out the door. And so out the door is not to the public. It’s over to the White House. The White House has OIRA, that agency I mentioned before, which is, or the division of the of, the Office of Management and Budget, in the White House. And they will do 2 things. They’ll coordinate, information and insights from other agencies. And they will give their own big brain thoughts, because they’re smart people who have seen a lot of rules. And they will send that back to the agency as pass back. And the agency has to then incorporate or address those, that feedback, and there might be multiple rounds, and there might be disagreement. And so OIRA and other politicos in the White House will coordinate that, right? That’s why the White House does. Is you’re solving equities between agencies. So this whole process is happening, and there’s not even a proposed rule yet. Okay, finally you do it. You send it to the Federal Register. You get a sneak preview if you look at the public inspection a couple of days before, and then it’s published in the Federal Register for anyone to see.
Dave: Mm-hmm. Which used to be a big book and maybe still is, but it’s also just a website now.
Matthew: It is, yes. And so you can subscribe to alerts on this and find out about things. You have a proposed rule, and I, and you read it. It has a comment, it has a preamble which says, “Here’s the reasons.” It has regulatory text. And then you have a comment period. Could be 30, 60, 90 days. Could be extended. You can submit a request for an extension. And then you submit these things through regulations.gov, which is a clunky website for submitting and reading others’ comments. So you submit your comment. They’re public, so other people can see what you wrote. So don’t write, “We are proprietary. Here’s our, here’s our weights-“ “. Our model weights in it.” and so you have that formal public open process. Then they consider all the comments. While they’re considering the, so they’ll consider the comments. They’ll then, send it back to clearance process for the final rule, OIRA again. While it’s in OIRA, by the way, at either the proposed or final stage, you can find out, that it’s there through this web, another reg website called reginfo.gov. And while it’s there, you can request a meeting called a 12866 meeting, which is a, meeting where they will sit, across the table from you, the people at
Dave: Uh-huh
Matthew:. And the agency, and you can tell them your thoughts even before they’ve issued the proposed rule. This is, not used by many people, but, and it’s public, any information you give them. Like, if you give them a paper and that you had the
Dave: They have to
Matthew:.
Dave: It publish
Matthew: Obviously not your. In the meeting, so they have to do a summary of it. It’s under executive order. So all this stuff is under executive order and just practice. It’s not in a statute. So it can change. But it’s an opportunity to basically influence it before the proposal is even out and to make sure they receive your comment. Right? Some of these rules receive 10,000 comments. If you sit there and talk to them, they’re more likely to pay attention to your comment. And I hope they don’t hate me for saying this on a podcast. You can do, you can do this, and they’re not going to give you a lot back. The instruction I was given is, be a sphinx, you know? No response. But you get your point across. Then the final rule comes out. It has an effective date, 30 days or more in the future in general. And then there’s litigation. [laughs] Not always, but if it’s a big, important rule with affected interests and a lot of money at stake, what the government calls an economically significant rule, there’s a good chance that it’ll result in litigation. And so that is why this ends up taking 9 plus years. It can take 19 years, for the, for a rule, at OSHA on silica, for example, took 19 years to
Dave: Uh-huh
Matthew:. When they adopted their first 600 standards in 30 days, right? Now it takes 19 years. Not in. That’s the most contentious cases, but if you’re doing a rule on AI, it’s likely to be contentious.
Dave: Yeah. This is an incredibly important thing that I think most people, many people inside Washington don’t really know exists. They sort of see its sort of impact on the world, the shadow it casts, but they don’t really know what it is. So maybe you can unpack in a little more detail what is the APA
Matthew: Well, let’s start with what it is, and then we should start with the history even before the APA.
Dave: Okay, great.
Matthew: So it was, it was passed in 1946, and it sets out how, agencies can, make and administer rules. It. There are 2 parts, adjudication and rule-making, and then a section on judicial review. That’s the main bulk of it. And adjudication is what has, was for most of democratic history House of before in England and so forth, that was used, right? The common law was courts were taking a case by case, figuring out how does it compare to past cases and moving it incrementally forward, moving the law forward.
Dave: So I had a sawmill. Some such and such happens. Someone sues me. I go in front of a magistrate judge in England in 1400, and they say, “Ah, that was irresponsible,” or, “Oh, no, that was a reasonable thing to do with your sawmill,” kind of thing.
Matthew: And then, and then someone invents something new compared to the. And they say, “Well, this is this other case, not,” and so they make a new rule. And so that’s sort of the way that it, the biggest way that things were done in ye olden days. And so they thought there was going to be a lot more adjudication-type procedures, and so the formal rule-making, which is the main way they thought there would be, rule-making, when they made the APA, is like a trial court. It’s witnesses, statements on the record, a hearing room. You basically put a rule on trial.
Dave: Uh-huh.
Matthew: So that’s what they thought they were going to do. So they did that once, and it was horrible. They never did it again, except for, the National Labor Relations Board. Basically, all other agencies now use informal rule-making, which is sometimes called notice and comment rule-making. It’s supposed to be a concise statement [laughs], of the. For the rule, the regulatory text, and then, opportunity to be heard, which now takes the form of submitting comments online, mostly.
Dave: Yep.
Matthew: And sometimes they’ll do a public hearing on it. You can, in if you want, go in person and drop off your comment. And that gives the public an opportunity to give input, and then they consider those comments, and the, they have to substantively respond, as courts have, elaborated this. They have to substantively respond to all the major themes in the comments, and then they issue their final rule, which has an effective date. So that’s like the, what the law says the process is. The real process is much more than that, but that’s how the APA set it up.
Dave: Yeah. And I think a couple things really strike me every time we talk about the APA, right? The first is that Congress had this whole idea of how they wanted it to go and how they expected most of it to go, and they did it once, literally once, which I really want to underscore to our listeners that isn’t an exaggeration. It literally happened once, and then basically got abandoned for everything except the National Labor Relations Board, which is kind of its own weird entity for reasons of that I doubt we’ll get into, but it’s kind of its own edge case. And then everything else operates via notice and comment to the point where basically people all the time forget that the formal thing that was intended to be a thing even exists. They just think the APA is notice and comment.
Matthew: Right. And it’s supposed to be faster, right? That’s why it’s called informal.
Dave: Supposed to. [laughs] Yeah.
Matthew: It’s not in reality. Yeah.
Dave: Yeah. And maybe you can talk a little bit about what does it mean for them to substantively respond, right? Because I think sometimes when people first hear this, they think it means, oh, they have to agree, or, oh, they have to give an a full rebuttal of whatever I put on the record. And it’s kind of not quite that. People are filing all sorts of things onto the administrative onto the record for any given notice and comment opportunity. Like, I literally once, when I was looking at a given AI, request that the White House had put out, people literally filed a bunch of paintings as scanned paintings as their submission to the record, right? I don’t know how you would sort of substantively respond to that. Of course, most of them are letters from interest groups and things like that. So can you maybe talk about sort of what does it mean for like our friend Dean Ball, when he was sort of substantively going through all the responses on the AI Action Plan stuff what was he doing to substantively respond?
Matthew: Well, the, Action Plan isn’t a rule. It’s just
Dave: Fair, yeah.
Matthew: But if you were going to respond on a rule, you would, basically summarize the comments and major themes and then respond to the major themes. And the root of this is due process, right? So when the APA was enacted, the context was that it was the New Deal. The Democrats had been, in power, and the, they wanted. There was a because. The debate happened still under Roosevelt, and then only passed in 1946 under Truman. They. Each party basically was thinking, “Oh, I want to constrain the other party, but I want to be able to do what I want.” And so
Dave: Common Washington.
Matthew: Exactly. And so the result was they just codified what the existing practice at that time really was.
Dave: Mm.
Matthew: And that basically rests on due process, which is 3 things. The basic things of due process are a notice that you’re in trouble, a, an opportunity to be heard, and an impartial arbiter. So in order to have an opportunity to be heard, you really need to have them consider your comments. If you just send your comments into the void and they never respond to your comments, then did you really have an opportunity to be heard? So courts have expounded this idea. It’s not really in the. That you have to respond to every comment, but they’ve expounded this idea that, okay, in order for that to be a real notice, a real opportunity to comment, then you have to comment on it. So they’ll say “Hey, we got 10,000 comments. 9,900 of them were, postcards, generated by some interest group like Greenpeace.”
Dave: Yep.
Matthew: Or the AI-generated equivalent. And 100 of them are substantive comments. The those 9,900 are an emotional or political view that you should not be doing this thing or you should be doing this thing, which is valuable. This is democracy. It’s good to have that version of a poll. But the, last 100 comments they’ll kind of respond to substantively and say, “Okay, this person say, gave this technical feedback and it’s wrong because they actually don’t understand the engineering. This person said this is what the threshold should be, this many parts per 1000000 in an environmental rule.” “And, actually they made a good point because they brought up some studies we hadn’t considered,” and so forth. And so they don’t go one by one, but they’ll do the major themes.
Dave: Yeah. And to be clear, there are instances where judges will say in between sort of that interim proposed rule. Or sorry, I’m probably giving the terminology wrong. Between the thing they propose and the final version that comes out, if it morphs in a bunch of ways that kinda seems sketchy with regards to the record of the comments and the final result the judge can just throw out the rule and tell them, “No, try again,” right?
Matthew: Yes. So the. A huge part of administrative law is not this one statute. It is the record of judicial decisions. And so this is called logical outgrowth. The final rule has to be a logical outgrowth of the proposed rule, because otherwise, it wasn’t a real notice. Right? If the proposed rule was, “We’re going to not regulate AI at all,” and the final rule is, “We’re seizing all the labs,” that’s not a logical outgrowth from the proposal.
Dave: Maybe one thing that I think is worth spelling out for our listeners is that this isn’t just a tool that’s used by. I think the examples you’ve given so far by chance happen to be more like Greenpeace and things like that. They’re actually used by both sides, right? So for example the sort of gun the pro-gun rights lobby has used the APA in a bunch of instances to overturn a bunch of Biden-era, gun restrictions on things like pistol braces and things like that, Whether or not it’s neutral in terms of which side it favors is probably a more complicated question, but it’s certainly a tool that is really used by all sides in political debates.
Matthew: Yes. I think that’s true, but different sides use it differently.
Dave: Oh, say more.
Matthew: So in particular, I think the divide is between more, people that, claim to represent the mass public and people that are special interest. And the special interest folks probably do it better because what the value of this is, right, this is like the current state, but why does it, why do we care about it? It’s because we want agencies to have expertise from the public. Right? It’s we’re. Agencies, the model of agency government, instead of just Congress doing everything, part of why it’s evolved to this way is because agencies have more expertise than
Dave: Uh-huh
Matthew:. For a variety of reasons we should talk about. But they are trying to be the expert implementers of a broad rule, and so a broad, a broad law set by Congress. And that means that, they are trying to do the technocratically right thing, in general. And so the people that have information that they can’t just get from Googling and. Academic articles are people that are the regulated parties, typically. And so, they will say something “We’re going to put this requirement on all the AI labs.” Well, the AI labs know, “Hey, that may have made sense 6 months ago, but actually, we’re no longer doing that.”
Dave: Uh-huh.
Matthew: And so you can do this, it’ll have no effect. What you really should do is regulate what we’re doing now or where the future is going. And so that’s something that they can’t get from the general public. General public still has a very valuable point, perspective to make, but it is, the administrative state is most responsive to expertise-. Whereas, Congress, the people’s branch, is most responsive to popular opinion. But they also, of course, want to do what’s right and what they, you know. The. My first, boss in politics, was an intern for Rush. A, who’s a plasma physicist. He used to say, that he’s bound by a constitution, conscience, constituents, in that order. Right? So he’s not going to do, violate his conscience, but he’s there to serve his constituents.
Dave: Why is it that we ended up in that place with Congress say, like writing very broad laws and then handing off regulatory authorities to sort of executive branch agencies? Like why did we end up here? How, like how do people feel about that? Like where is that. And like where is that going?
Matthew: Yeah. I think that this is not the world the framers envisioned. Okay? So article one is Congress. It’s first, it’s longer, the, it’s the primary of the 3 branches in the in the founder’s minds. And they just fought a war against the king, right, who was tyrannical. So it wasn’t all about, the strong executive, the agencies that we have today at the founding. That’s not, it’s not 100% because, they had also lived through the Articles of Confederation where a weak executive doomed the whole thing. And they wrote article 2, the executive specifically for one man, George Washington, who was basically a god to them. Really great guy, big fan. And so they were willing to give more powers than they otherwise would have. So it’s not that the executive was numbered, but they intended that the laws would be written by Congress and the executive would take care that they’d be faithfully executed. That was the original idea. And the way that, administration happened early on, was very different, than it is today. So there’s like this idea that there was no regulation until almost 1900, but actually one of the first laws they passed was a one-sentence law saying, “The president will take care of distributing pensions for veterans.” Right? It was one of the big early issues. It was one sentence, right? So they were good at writing vague laws even at the first Congress. And the way that people were held accountable then was either you check in advance with the court or you could be personally sued, right? So we didn’t have this whole elaborate procedure at the founding that we do today. And I want to make that point because it’s kind of a choice that we have right. That we’re. The way that we make sure that people don’t do crazy stuff is we put hundreds of procedures on them. Instead, you could just make them accountable for what they were doing. That was. How we did at the founding. And basically, this was one of the big issues in the revolution. You had, inspectors going into people’s houses looking for smuggling, which they were doing.
Dave: Yep. Lots
Matthew:.
Dave: It of
Matthew: They didn’t, they didn’t like that. They didn’t like being caught. They didn’t like the inspectors coming into their house. And so they would sue them because if you were wrong, you went into someone’s house and you were wrong, you could be sued personally. So that was the regime we had for making sure people didn’t do bad. At the founding. Over time, though, it wasn’t enough. There was this thing called the steamboat. Big invention, right, in the 1830s. And hundreds of them exploded. And so they passed a law saying we’re going to have steamboat inspectors. It was like the first regulatory agency. And so they were “Okay, well, what standards should the inspectors, apply?” So they went and talked to experts on steamboats. And so this is how we, how it really started as technology advanced, as government got more complicated, we started relying on these agencies. So fast-forward to today, we’re in this world where the APA has passed, there’s, the agencies exist, and it’s much easier for Congress to write a vague law that just directs an agency to do something generally. And so that is the vast majority of how they establish these things. And that is in part because it’s super hard to pass a law. Today, Congress passes about 2% of introduced bills. That doesn’t have to be that way. Colorado passed 74%-. Of their introduced bills last year. But a very few things become law. And so you’re incentivized to boil it down to be less objectionable so fewer people can object. You. When members of your coalition, like in, like a union or a business group, get hurt by the law you passed, you can blame it on the executive. “Oh, I. Gave them this vague rule. It wasn’t my fault that you got hurt.” and also we have really increased polarization, which makes it hard to pass laws. Federalist number 10 was this whole idea that we would have. That would be overlapping and would fight each other. But today, like the West is not really a faction anymore. And so, it’s really Democrat versus Republican. So very few things cross party lines by more than a few votes. So it’s hard to, hard to pass laws. So that all leads to this kind of boiling down and delegating to agencies. And then the agencies are held accountable by, with procedure instead of individual accountability. And so, the result is that there’s a lot of litigation over not following the procedure instead of actually fighting about the substance.
Dave: My understanding is that Congress continues to do this, but the Supreme Court is in rulings, agitating more and more for telling Congress, “No, you really need to take the ball back somewhat and actually like really make more, decisions.” And well, both Congress. They’re telling Congress to do its job a little more, and they’re also trying to give more authority back to judges. Is that correct?
Matthew: Yes. So 2 trends are happening at the same time. One is that the court is doing that. They are building a much more robust major questions doctrine, which basically means that, if it was a big deal, Congress would’ve been specific about it. So agencies less and the president get less deference. And then this other decision, Loper Bright, where they stopped giving deference to agencies on their interpretation of statutes for regulation, or significantly reduced the deference. So judges are deciding, did you follow the law when you made this rule? And so they’re. The judges are taking more power for themselves. On the other hand, we have just the practice of the. 3 or 4 presidents of a much more aggressive executive. Right? And so they are, doing, just doing a lot more stuff. And they are of both parties, but some parties more than others, are saying, “Hey, we’re going to interpret this law how we want to,” or, “We’re going to do a veneer of plausibility and dare you to challenge us.” And sometimes they get challenged and lose in court. Sometimes people are too afraid to challenge them. So those 2 things are kind of pointing in opposite directions. The executive’s taking more power and then the court is taking more power, but Congress is not taking more power. Congress is kind of laying down.
Dave: Yeah. And I think, this is something that you hear from people in Congress, by the way. This isn’t as if Congress is, unaware of this and you’ll hear sort of both pro and cons on this. There are some people who genuinely are “No, I think the proper constitutional role is the trend you described.” You also hear people saying “Yeah, this is bad, but we can’t really stop it. It’s just kind of this is the world that we’re in now-“ “. Kind of thing.” but I think the implication of that is that there’s this desire sometimes to find a very vague law and say “Oh, there’s one weird trick that you can do with this law that allows you to solve all the AI stuff.” And the answer is that, yeah, sometimes, but often the courts will just tell you, “No, that isn’t what that law is intended to mean.” Like, you can’t sort of get things to. You can’t just one weird trick things in this way.
Matthew: Yeah. Sometimes. Sometimes yes, sometimes no. Like, so, for example, there’s this law, the Ku Klux Klan Act. It was passed to stop, the Ku Klux Klan, which is not the not a modern law, as you might guess. It. After. It was during Reconstruction, after the Civil War. And in the last 5 years, there have been a bunch of lawsuits about political violence where individuals have said, “You’re violating the Ku Klux Klan Act because it says private people can sue you in court for political violence.” Right? So you can dig things like this out. And actually make them work. Or the Trump administration took a deep sea mining law from 1980 that had never been used and
Dave: Huh
Matthew:. “Okay, now we’re going to start issuing deep sea mining permits 50 years afterwards, for ourselves, because, we don’t like the international system, which is, uh.” And it has. The international system isn’t issuing these licenses. So there’s. You can dig these things out and find things. I actually. So I think that I wouldn’t, I wouldn’t dismiss that totally, but you can’t say the law does something that it doesn’t say you can do. Right? So, there are, a bunch of laws that, govern, say, the use of power in emergencies. And if you stretch those too far, you can be pushed back Trump’s use of IEEPA on. Was pushed back by the Supreme Court.
Dave: Yeah. And what I hear you saying, I think, in particular is that the policy priorities as well as the sort of pace of unexpected events causes people to get more creative in terms of thinking about how authorities might be used in some sense.
Matthew: Absolutely. Like, if you think about it, the right way to regulate a new technology would be to think, “Okay, what does this new technology need?” and write a law for it. Right? That is not the world we live in. It is very hard to pass a law. And so we rely on regulators as the primary thing. I think this is one of the, kind of the key takeaways is that structural change has made the administrative state the de facto place where policy is made, even though it’s not Article 1, you know. And so it. This is challenging. It’s not as fast as it should be. It’s limited by what the law says. It can’t just do anything. But that is where the action is. And so it’s important to know that.
Dave: Yeah. We’ve sort of talked about the different ways that you can engage. Should we sort of talk about then how to do things fast. In an emergency? Like, because I think the takeaway that I have from all this is either A, this isn’t useful at all, which I don’t think is. It’s why we’re doing this podcast, or B, that there are ways of doing this more quickly in an emergency, things like COVID, things like the war on terror, that kind of thing. And I’d be curious What does that look like? And to what extent is it writing new rules versus and using some sort of way to do it faster temporarily? To what extent is it using your existing authorities? Like, how do people think about this when the, you’re in crunch time?
Matthew: Yeah. So, you can do things, faster through, not making it a. Or by using an exception, to parts of this process, or to using political power to run it through this process quickly. Basically your main paths. And so by not making a rule, that’s the guidance things we were talking about. Guidance is not, doesn’t have the force of law, but if the president calls up some Sam Altman and says, “I really want you to do this-“. He’s going to listen. He’s going to consider it. So you can just do that. Right? And a guidance is more of a formal way of doing, of doing that. That’s one set of things is you do it through something other than a rule, use some other power, enforcement power, right? If you say, “I’m going to put you in jail if you do this,” and you can say, “Well, I’ll win in court, but I will have to spend all of my money defending myself,” you might not do the thing. So that’s the first category. The 2nd is the exceptions. So the exceptions are, I think a few different kinds. So one is there’s exceptions to notice and comment for good cause, and one of them is impracticability, which is basically an emergency exception. So you can, you can do what’s called an interim final rule, which is you just send the final rule right out because you don’t have time to do, to do it. So in COVID, there were a lot of interim final rules, for example.
Dave: Mm-hmm. By the way, love the name interim final rule. Like, there’s something distinctly Washington about that phrase.
Matthew: Yes. It is very, Orwellian, right? And the, even though it’s interim, there’s not a expiration date. It’s just
Dave: Oh,
Matthew:. Until you go back and do it final, and it’s in force until then. There’s no you’re supposed to. There’s no law that says you have to.
Dave: And do courts ever say on the, on the interim final rules “Eh, actually this doesn’t meet the exception. Never mind, it’s going away,” kind of thing? Or.
Matthew: I don’t have a specific case example, but you could say, “I don’t like this rule being applied to me. I’m going to sue. It doesn’t meet the, impracticability exception. It was a procedural defect.”
Dave: Yeah. So in principle, yes, but in practice, if you’re using this pathway, it’s probably because everyone’s pretty freaked about something and they’re probably not trying to fight it too hard.
Matthew: Right. Well, it depends how aggressive you get, right?
Dave: Sure, fair enough. Yeah.
Matthew: So, during, World, the Korean War, Truman was “I’m nationalizing the steel mill,” the Youngstown steel mill, great state of Ohio.
Dave: Great state of Ohio.
Matthew: And so, they were “We don’t want the army running our steel mill.” And so they sued, and, in that case, it was found that he, that he had exceeded his authority. But it’s, I wouldn’t say it’s definitive that you could never seize a mill. And in World War II, Roosevelt said, “I’m going to seize this, these coal mines,” because the coal miners went on strike in the middle of World War. And he said, “I’m going to send the army in,” and then the coal miners backed off. But anyway, so you could, you can challenge it, but the coal miners the coal miners’ strike basically substantially weakened the power of unions, right? So if it’s an emergency and you say, “I’m going to fight you on doing what you think needs to be done in an emergency,” you could permanently, reduce the power of your political constituency. So people might not want to do that.
Dave: You’re pushing a lot of chips into the center of the. On that bet.
Matthew: Exactly. So that’s the good cause exception. There’s also a very relevant exception for foreign affairs and military affairs. Just doesn’t go through this. So DOD rules for drones are not subject to notice and comment.
Dave: At all? Really? Okay, this is something, I’ve lived in DC for 15 years, I never realized that. That explains a lot of things.
Matthew: Yeah. So they have a parallel process for procurements-
Dave: Ah,
Matthew:. With its own set of rules. But you’re not going to go to regulations.gov and say, “I think that we need more humans in the loop on the way that we use our drones.”
Dave: Which is why DOD can just publish a new directive on its own website. Although they do have their own. This is maybe a little bit a of digression. They do have their own very monstrous internal clearance process like you just described, right? Arguably worse than it is inside any other government agency.
Matthew: Yeah. There’s maybe just less litigation.
Dave: I once saw a map, of the DOD internal clearance process.
Matthew: Uh-huh.
Dave: It was a, When it was unrolled, it was 15 feet long by 3 feet high and everything was in 8 point font, and it was thousands of boxes with arrows between them.
Matthew: When we understand that chart, we will have won the war.
Dave: Correct, yeah. Okay, so not everything is as bad. So even then, they can still do it faster because they don’t have to go through notice and comment and all this stuff.
Matthew: I mean, the main reason I want to point out the foreign affairs one is export.
Dave: Mm
Matthew: Because that is the tool this administration’s using on AI, and it doesn’t go through any, notice and comment because it is foreign affairs exception.
Dave: Oh, so export control. This is actually something that I think I didn’t really understand underneath the hood. Obviously, I see when the. I hit my mic a second. I think that’s something I didn’t understand underneath the hood. Obviously, I see when sort of export control decisions get made. I think I thought it was more oh, they’re using their existing authorities. What I hear you saying is actually sometimes, no, it’s like a new export, it’s like a new rule-making that’s being done effectively, under their broader existing authorities and law. The
Matthew: Well, it’s so export controls are basically excluded. From the scope of this. So the good cause is skip notice and comment, and then the exceptions are these are things that this
Dave: Just doesn’t apply to
Matthew:. Doesn’t apply to.
Dave: Got it.
Matthew: But the thing to understand is the APA more broadly, APA is just a procedural law, but then there’s 100,000 substantive laws, right? And so, you are doing your export controls under the law that governs export controls, and that has its own procedures. And if you’re doing things even that are under the APA say, an Endangered Species Act or finding or something, that has additional procedures and rules in the underlying substantive. So basically, there’s this procedural layer. Of the APA. There’s, of course, the Constitution-. And then there’s the substantive vertical way of looking at it as well. So a couple, a couple other exemptions to think about, agency management, and personnel and property rules are not subject to this. So if they’re reorganizing NIST for, or in case or something-
Dave: Uh-huh
Matthew:. Presidential actions. So if the president is doing something personally, like saying, “Yeah, this TikTok law doesn’t apply to me,” that is not reviewable in court. And then in general, there’s a big problem of you can’t get into court without standing. So you might not like what happened to Anthropic, with DoD, but you can’t sue because you’re not Anthropic. So it’s up to Anthropic to decide whether they
Dave: Or someone else who was harmed in some way.
Matthew: Right, exactly. So that maybe you lost access to Mythos or something-. I don’t know, because of what they did. So those are a bunch of constraints on this is not always governing it, and then there’s a bunch of other laws that have emergency exemptions. I mentioned IEEPA, the National Emergencies Act, the Defense Production Act. So for example, the Defense Production Act was used to order reporting under the first Biden AI executive order. Right? That they wouldn’t otherwise have had to give this information, so but because he invoked the Defense Production Act, he was able to kind of order them to do that. You. There’s also more extreme things you could do. Like, I gave the steel mill example. Well, if we’re in a hot war with China and they’re saying, “Okay, well, are we going to nationalize the data centers?” Like, you could potentially see, maybe not nationalizing, but ordering them to take action. And if they refuse, there is an authority to actually nationalize. So I don’t know if we’re going to, we’re going to get there, but some of the depending. It really depends on how big the emergency is, right? The Civil War, existential, the country’s split in. Right? No longer a United States of America. You can basically do almost anything, right? President even
Dave: Suspended habeas corpus.
Matthew: He suspended habeas corpus without notifying Congress, which is literally in the Constitution. You know it’s an old rule because it’s Latin. There was a case, called Merryman where the court said, “This guy has to go free.” And he said, “Nah,” just straight up defied the Supreme Court, and said “Shall all the laws, but one, go unexecuted so that this one can be enforced?” and the whole country goes to pieces. So it depends how big the emergency is. Civil war is the highest bar. If we’re in a civil war level thing, a lot of this stuff is academic, [laughs] but hopefully we’re not there yet. And so, World War II, you also had a lot of existential, treatment of emergency authorities. So it just kind of depends how big it is. But Korean War, I gave the example, no, you can’t nationalize a steel mill.
Dave: Every time we talk about this stuff, one thing that always comes to mind for me is, it is certainly the case that there is a lot of regulatory aspects of this that are based on sort of really understanding okay, where is the state of the technology? Where is the state of the current law, the current policy conversation in DC? Like, that’s one really important layer. I also always feel like when we talk that part of this is also you have to understand how a lot of the entities involved, particularly the courts, but also the executive branch how did they get to where they are and what are the sort of deep underlying scars, lessons learned, whatever you want to call them, that they’ve had at various points in American history that really shape behavior today. And all the way back to the Civil War, all the way back to the founding of our country. And I think one thing that I always wonder is do you think that AI is going to be something that God willing, 20 years from now, people look back on and say, “Oh this really reshaped the fundamental balance of power on the, on issues like this in a substantive way”? Or do you think we’re going to more look at it I don’t know, the internet, where oh yeah a bunch of stuff got tweaked around the edges. We passed Section 230 and some other stuff, but eh, more or less at the end of the day, it was the same?
Matthew: I think we’re probably not going to fundamentally remake our system of government in response to AI. And that’s not to say that we don’t every generation do that. Like, in the 1970s, we added a whole extra layer of procedure on top of things in response to Nixon overreach in Vietnam and so. And Ralph Nader, right? So we do reshape how we govern. But if I think about AI, I don’t know. I don’t see people saying, “Hey, here’s a totally new way of governing that we need to adopt.” so let’s take one example. This is Palisades Podcast, so we can take a cybersecurity example. The Hugging Face thing, right, it happened. That’s. If you or I had hacked Hugging Face, that’s a crime. Probably go to jail, right?
Dave: Yep.
Matthew: We have a bunch of authorities already in place. So we have authorities for the, basically the victims to notify and disclose that the, that they were hacked. Basically anyone that has employee. Is subject to this, but critical infrastructure and public companies and banking of higher levels, right, the most sensitive. We. And so these things would already kind of be in place, like the disclosure of being hacked. We need to adapt the computer crimes law to figure out how this applies to an. To deter the agents from doing this. So there’s some other differences that are, that are maybe helpful. Or we don’t, we don’t have regimes that are premised on the basis that the labs might cooperate, right? So if you take like the Colonial Pipeline hack, in 2011. The TSA had existing authority to make the pipelines do a bunch of things really fast to improve their cybersecurity, but they didn’t do anything to go after the ransomware company. Now we have a whole new layer of how we can defend on cybersecurity, which is say okay, because they didn’t expect the ransomware criminal. To obey some emergency directive they issue on them, right? So now we have this whole other layer. So I do think we’ll have some more authorities that we’ll need, but I don’t know that it totally reshapes, how we, how we approach all these problems.
Dave: So I think I want to push back on you on that one, right?
Matthew: Please.
Dave: I think I agree with you that our existing authorities are much more flexible than people give them credit for. One of the big debates on my group chats about sort of Hugging Face with people “Well can you hold the AI company accountable?” Like, it was it was OpenAI’s agents that went rogue. It wasn’t OpenAI. And I’m “Guys, literally the first prosecution under the CFAA, the Computer Fraud and Abuse Act, was of Robert Morris Jr.-. For his computer worm that he thought was intended to just hack a few computers on his local lab network, having the ability to have much wider scope on the then very nascent, ARPANET, it may have been called the internet at the point, I forget. But ARPANET or internet, and it went to a lot more computers across the internet, like half of them basically, and hacked them at that time. And similarly, it was out of control. It wasn’t his intention, and they still prosecuted him. It’s also very embarrassing because his dad worked at the NSA at the time. Yeah. A little known fact.
Matthew: That’s fun.
Dave: Yeah. His dad apparently [laughs] had a bunch of very awkward conversations with some people who were friends with
Matthew: Security clearance problems. [laughs]
Dave: Oh, no. He, they were “Look it was your son, not you.” And. It, to, RMS Jr.’s, sorry, Robert Morris Jr.’s, credit, he also was very helpful in terms of the. And things like that. And I think scared straight would be an exaggeration for any OG hacker like that. But relatively so. But I, returning maybe to the main point, I want to push back on the notion that we won’t have fundamental transformation of how the system works, right? When I hear you sort of talking, it’s hey we have a system that is relatively sclerotic in certain parts of it, relatively fast-moving in others, defers a lot to certain entities versus others in terms of emergencies, and is predicated on the notion that there’s a particular balance of power. All of those things feel like things that AI can fundamentally shift, right? Like, so for example, right, if it turned out that you could adjudicate the entire administrative record by an AI, and we just, we got the courts okay with it, let’s say hypothetically, all of this in principle could happen much faster. You could have the AIs very quickly canvas all the AIs at all the companies and be “Hey, what’s Dow Corning’s concerns with this new regulation? What’s ACLU’s concerns with.” And and do it all in 20 minutes, right? And then that, so that’s the most trivial example. Then you also have the thing of if
Matthew: Please build that. [laughs]
Dave: Someone should build that. And in fact, one of the things that our friend Dean Ball said when he was doing the AI action plan, which although it wasn’t, to your point earlier, wasn’t a formal regulation, they did use that RFI, system to essentially act as their data clutch. Right, for it. One of the things he said is that he really he obviously couldn’t use an LLM in that kind of way because it wasn’t approved, but he really wishes he could have. Not that he would’ve substituted his own judgment, but just to be sort of. “I’m working 14-hour days. It’d be great to have a spot check.”
Matthew: Agencies are starting to do that. DOE has a, an LLM for that it licenses to other agencies.
Dave: Interesting.
Matthew: So I hear you that it could move, it could speed it up, but I don’t know. I guess it’s difference of kind. I think that we’ve been dealing with new problems for hundreds of years. And we were talking about public law, which is laws created by Congress, but there’s also private law, which is torts, contracts, property law. And there used to be a first year required class, called 8, the Law of Agency, which is who, when are you responsible for other things, other people’s actions? No longer taught at Harvard Law School. It used to be a first year class. And so seems pretty relevant to when is an agent that you created responsible for you? So a whole field of law still exists, right? And so it’s not like we’ve never had a problem where somebody else did something, and you are partially responsible for it. So I think that’s what the kind of the common law history is all about, is we kinda incrementally move things forward by analogy. So I think that system is, capable of adapting. And it probably prefers incremental progress given how sclerotic it is. That said, it doesn’t mean that a more idealistic non-lawyer person can’t come up with ways to actually really improve these things, and I would love if they did. So I take your point that we have the potential to do it. I maybe am too pessimistic that we are set in our ways. And I didn’t live through the 1970s, despite the gray hair. So I haven’t, I haven’t seen it transform in that way, even in response to something as remarkable as the internet. So is this government, this government system that has become lower in many ways in the state capacity since the internet going to take full advantage of this technology to improve how it does things? I don’t know.
Dave: Okay. But I still don’t feel like I heard an answer on the concentration of power thing, right? Like, we are going to have AI companies that they’re currently 10Xing their revenue every year. They sure seem to think they can keep doing it for a while. Maybe they’re wrong, but they sure seem to think they can. Even if they can’t, I think the models are going to keep on getting better. Maybe they’re open source, so there’s kind of some sort of different sort of constellations of power that emerge. But certainly you’re going to have a lot of power in the world that is, I think, by default concentrated in a very few number of companies, in a way that we haven’t seen even in the Gilded Age. And one of the one of the things the Founding Fathers were very deeply worried about was sort of unaccountable concentrations of power, right? Like, whether it was trading companies that were chartered by the Crown or Crown entities that weren’t amenable to judicial review because the colonies didn’t have certain rights or whatever. They were very nervous about the notion of private actors outside of, democratic oversight getting tremendous amounts of power, and that seems to be the default path we’re on.
Matthew: Mm-hmm. That’s true.
Dave: Like, talk to me about how you think regulation evolves, bends, pick what your wording, in order to deal with that.
Matthew: Yeah. It’s a good point. It doesn’t take that many 10Xs of Anthropic’s, revenue for at least their market cap, if not their revenue, to rival, the government share of GDP, right, and government budget. So right now, a lot of the way the government exercises power is, in the shadow of the law, saying, “If you don’t do this, we will come after you.” Right? There’s not a lot of litigation under it, so because the car companies just stop doing what they were doing if they get a cease and desist, in general. And other industries are not like that. The utilities are much less submissive, for example. So it could, it could be that if Anthropic has a revenue equal to the military budget, then they might not, be as submissive as some other agencies when the government comes. So I do think that would really reshape things. It would require more pure use of force, which by definition will happen less frequently. And so we could be in a world where we are, where government is essentially less powerful as a share of total power in society than we are today. How would government respond to that? They do still basically have a monopoly on the use of force. And so there are certain powers that they probably will always be able to exert in real emergencies. But I do think we could see more capture, of government by these, by these large entities, in the future. And so how do, how will government respond to that? Well, one is you might see greater use of the competition authorities. Things that are there’s, the Sherman Antitrust Act is amongst the very broadest, no, restraints of trade, is the, basically on its face, it makes contracts illegal. [laughs] And so it’s not a, it’s a, it’s a pretty broad, law, so I think you could see more creativity, in that. You could see more, rules that try and diffuse the concentrated power. I think we are seeing also in big tech reaction, right? Meta this week had a $18 8llion settlement-. Making fundamental changes to their platform. Some people may say not as fundamental, but there’s a big, concern in the populous amongst concentration of power right now. And I think that Anthropic and OpenAI learned from the political, ups and downs of the prior era of big tech, and are trying to get ahead of that by, welcoming regulation and doing a good for the community through foundations and things sooner in their trajectory. But I don’t know that many people in the public buy it. I think that there’s a general skepticism-. Know, you permanently of big corporations. So I do think that creates more political will to regulate them. That’s why that matters, is so you could see Congress pass things. Congress passed KOSA, which is a law regulating kids online safety for social media, like 93 to 7, I think.
Dave: Yeah. And that was a long slog to get there
Matthew: Yeah, but
Dave:. Some folks we know
Matthew:. That’s pretty bipartisan. Right? That’s pretty strong, overwhelming. It didn’t actually become law, [laughs] so maybe I shouldn’t, give it as an example. But when there is, a high political salience issue, it can break through these things. And that’s really the point, is that, if AI gets more powerful, if we see harms that really harm people, like Hugging Face didn’t really hurt. But if it had hacked a bank and emptied everyone’s bank account, you
Dave: Or a hospital, God forbid.
Matthew: Yeah, a hospital, shut down a hospital, with people on life support, that, then we would see, I think, more politically salient reactions. So that could happen. Congress reacts to a crisis, and we could see stronger laws come into place in that case.
Dave: I wanted, I want to turn then to sort of okay, let’s say that there is a crisis, right? Let’s say that you’re familiar with a lot of the work by some of friends of the podcast, folks at like the AI Futures project and things like that, where they sort of say, “Look, we think if you sort of keep on climbing the exponential curve of model capability and autonomy, you’re very quickly going to get to a point where you have some real serious shifts in the nature of the world, some real risks of loss of control, some real risks of misuse events, some real risks of really runaway competition between the US and China.” let’s take sort of a loss of control thing. Let’s say that there was an OpenAI Hugging Face-style warning shot. By the way, I hate the phrase warning shot. I think it conveys the notion that these things might not have human costs to them, right? Whereas, of course, they might, right? If it had done if it had been a hospital or something like that. But, let’s say there’s an open, there’s like a, an even bigger, a times 10 kind of in terms of the attention that it gets, not necessarily the literal metrics, but in terms of the attention it grabs, a times 10, times 100 scale kind of thing that happens in terms of AI policy. It’s the number one issue on the front page. It’s like our, a Hurricane Sandy or Hurricane Katrina kind of level event. In those kinds of instances, like what, how do you expect the sort of administrative and regulatory state to respond in that kind of situation?
Matthew: So I do think that if there’s a politically salient crisis. Which means sympathetic people got hurt. Unfortunately that doesn’t mean overseas, right? Like, it means Americans that Americans respond to. Then I do think that we could see fast reaction. And I think you’ve seen pretty aggressive action already, right, on AI by this administration. Right? There have been 4, 5, 6 orders on export controls, restricting their use, stuff that you don’t see. You never saw that for social media, right? There have been, the use of the emergency authorities under the energy emergency that there was declared to enable data centers. So there’s been quite creative use of emergency authority on AI. I do think that its salience in policymakers’ minds is already pretty high. So if there is a big salience, you could see things like that, more aggressive pause-type actions. What Congress tends to do in those cases, and this is really more a Congress. Is look for a proposal that’s on the. And takes it off the shelf and passes it. It may not be exactly the right response to this crisis, but it looks the right. And it allows them to act quickly because they want to. They are worried about this. They’re worried about their kids. They’re worried about their families, their constituents, and they obviously want to be seen to be responsive. And so I think that Congress could do that, and that could make a big change. And you could also see the government using its existing authorities, like those emergency authorities, stop new compute, stop new data centers, prevent the release of a, of a new. Or require the rollback of the model, do large fines billions of dollars of fines that are big enough to actually change behavior. And so I think you could see all those things. But there’s some things where it’s not going to reach, right? It’s not going to reach a Chinese open weight model, right? The authorities of the government are most effective on the victims, saying, “Victims, you need to do better protecting yourself.” they’re they’re effective on, US regulatable, developers, but, they are not going to reach bad guys who there’s a decent chance are the ones are, that are going to do something bad, right? And it’s not going to necessarily, reach the, foreign state actors that might be the ones that are doing it. And the. I think one thing that the Hugging Face example shows us is these agents are much more creative than we could
Dave: Yep
Matthew:. In what they are doing. Like, no one really expected them to not only break out of their sandbox and not only, solve an impossible problem by hacking to someone else, but also to cover their tracks and do it pretty effectively, right? Maybe some people expected it.
Dave: I think that’s actually interesting, right?
Matthew: But there could be other. That, they’re going to do that we don’t expect.
Dave: For sure.
Matthew: As Rumsfeld said unknown unknowns. And so I think that it’s going to stop some things, but the fundamental issue of loss of. Or recursive self-improvement to a, in a bad way. Like, that, those sorts of things may not be reached by this, right? The response will be “Hey, you hacked into a pipeline. Let’s strengthen our pipeline security regulations.” Right? It may not be “We’re going to go to here are all the rules for loss of control,” right? And there will be a big billion-dollar fine for the company that did it if they’re American. But, I think you there’s going to be some places where the regulations just can’t reach.
Dave: I think one thing I’m struck by about what you’re saying is the notion that regulation can do a lot, but it can’t do everything. And I think sometimes we end up in this debate in the AI policy space where it’s kind of “We need regulation.” “Well, no, we don’t need regulation.” And that’s kind of where we end up getting trapped as opposed to we need to solve the problem across the full stack of technical, social, political, economic sort of stuff going on. Regulation can hit some pieces of this. Other parts of it are things like the president going and meeting with leaders of other countries and threatening and cajoling and cutting deals. Some parts of it can look more like technological innovation. Some parts of it look more like social resilience stuff going on and things like that. And I think, I’m struck by the notion that sometimes we end up sort of using regulation to mean as a shorthand for do the AI safety agenda. And actually, that isn’t sufficient.
Matthew: Yeah. If you think about the last 5, 10 minutes of our conversation, it became not quite regulation. It became political economy, right? Congress is reacting this way. The administration is reacting in this way, private companies in this other. And so regulation is, or the administrative state, right, including. And, the threat of enforcement and so forth, is one big tool in our toolbox. And I think that it should be, it should be part of. If I’m making the org chart of an AI safety org, you should have a regulatory person. You know? Or a administrative state-type person, right? You have a regulatory council at a, at a at a business usually.
Dave: Yep.
Matthew: But you should also have a government relations person for the Hill and state person and a litigation person and a press person, right? These are all different tools in your toolbox.
Dave: Yep.
Matthew: And so regulation is one, way you can do it. And I think it’s, one that I’ve been particularly attracted to because it is possible to move. And because it is. I think in first approximation, trying to do good, trying to do the right thing. So, like most people that work for the government, and I think this is something that you talk about sometimes, Dave, is most people in the government are pretty competent, right? And they’re people of goodwill. They’re working for the
Dave: Absolutely
Matthew:. A at generally reduced salary. It used to be like these were cushy jobs. Now they get paid less than their private sector counterparts. And so they’re people of goodwill that want to do good, but they’re overworked because no one wants to raise taxes, no one wants to ask for more money for their agency or their congressional office. So over. And so if you come to them with, “Here’s a good idea for how you can fix something,” And you can tell a story of how it would get them political points, especially.
Dave: Yep.
Matthew: And how you can show them how it works within their existing authorities, they want to do it. And so, I do think that it is an area that is tractable. It’s a place where we can make improvements. And if you look at Congress, like it’s so hard to pass something. I work in Congress, with Congress, have passed things, right? It’s possible.
Dave: Mm-hmm. Sure.
Matthew: But, I’m kind of still shocked [laughs] at all the things we passed, right? So I think that it is, it’s a place where you can make those improvements. And if you’re into AI, you’re probably pretty nerdy and,
Dave: We’re not beating the allegations on that one, yeah.
Matthew: [laughs] And so being nerdy is a competitive advantage in regulation, right? In Congress, being, politically savvy and channeling the public and getting the public to agree with you, having those kind of comm skills is a competitive advantage. Not that they’re not also trying to get the right policy, but in. If you’re talking to a civil servant that’s like the chief counsel for, or assistant chief counsel for rule-making-. Right, this person is most likely a quite a nerdy person that thinks about, “How do I make rules that achieve my objectives more effectively?” And so they are not only, willing, but you as a AI person are exactly the person they are most likely to listen to.
Dave: Yeah. And I think the culture of Google Docs, right, that is AI, research and policy work, like hasn’t really updated on this fact, I don’t think. Right? Like there. There are a lot of people who have like beautiful proposals that they’ve written. They write many thousands of words on LessWrong or on their Substack or in just like internal Google Docs that are circulated sort of just informally. And like those are all exactly the skills that you need in order to do like a regulatory filing, right? Or, and like they are exactly the things that you need. And I feel there’s a lot more of that could be happening, relative to currently is.
Matthew: Yeah. Just like very tactically, no one in Congress, almost no one in Congress will read more than 2 pages, right? In a regulation, they might read 20, okay? And that’s, it’s single-spaced, not graphics. They’ll be 20 pages.
Dave: You can tell it’s 20 pages, yeah.
Matthew: And so probably not 1000 pages, but like they’re reading academic articles, you know? They’re trying to understand the science of these things. And it’s not that congressional staff aren’t, but a House office legislative assistant might have 8 issues that range from housing and homelessness to AI to all other technology to infrastructure and the energy and I mean, that’s like a lot of stuff. Right? [laughs] You know? And so even if you are one of the 10 members that are most interested in AI like take like Josh Gottheimer who’s like on the, commission, one of the chairs of the commission, like his AI stuff also does energy, which is pretty important. You know? [laughs] Like electricity prices are going up.
Dave: Pretty much he’s what? And he’s in New Jersey, right?
Matthew: Yeah.
Dave: And pretty important in New Jersey economy in particular, right?
Matthew: Yes, exactly. So I mean, this is true for every office. So I think that, whereas you have one person whose job is to just focus on this particular thing, like that’s your, that’s your party. That’s
Dave: That’s your competitive advantage, yeah.
Matthew: Yeah, that’s your, that’s your team.
Dave: Yeah. And I think the other thing that I, just to like really underscore this, because I absolutely agree with you on this, I’ve had multiple meetings in the past month with sort of administrative state folks. I’m kind of vaguing up here to, for confidentiality. But like with folks that when you met with them 6 months ago, sure were still wrapping their heads around AI stuff, and they still very much are. They’ve got, to your point, even those folks have some other fish to fry. But they’re literally like of their own will, they’re the first ones to use things like alignment in the conversation, right? That was not true even 3 months ago, much less 6 months ago. And the reason is that when these very, to your point, like dedicated civil servants wake up and start being “Well, guess it’s time to start Googling some things and learning some things,” they really do hit the books. And like the more that like you make it that your stuff is out there and easy for them to find, the more likely it is. Or for that matter, if you can build relationships with them and help steer them towards finding the good stuff, the more that you’re going to be able to get them to really. Caring about your issue.
Matthew: Absolutely. And like I want to go back to that Colonial Pipeline example for a second, because it shows both you can just do things and government is capable. So for like 20 years, this office existed before Colonial Pipeline. The TSA, it was called something else before. Like the TSA office responsible for pipeline cybersecurity voluntary guidelines, right?
Dave: Yeah. I think you said 2011 before early on, but it’s actually 2021, right?
Matthew: Sorry, 2021. Got the 2nd digit, 2nd digit right. Right, 20 years, 9/11. So the, so they exist for 20 years, that these like voluntary guidelines, GAO found like a 3rd of them were. A 3rd of the top 100 pipelines were following any of them, okay? So like very weak. It had 6 people in at the time of the pipeline. Within 19 or 20 days after the attack, they had issued the first emergency directive, right? So almost nothing for 20 years, and then within 20 days they moved. So that. I think that shows, one, if you had met with those 6 people and said, “Here’s what I think you should be doing about cybersecurity and pipelines in case there’s an attack,” probably no one had ever met with them on that, right? [laughs] That was not a pipeline, a regulated pipeline. And then number 2, when there was a need, they really moved. They can really, they can really do things fast.
Dave: Yeah. And I think to slightly refine one thing you just said, you were just “Well, maybe no one ever met with them.” I actually happen to know some details on this from some conversations with them folks. The pipeline folks had definitely. Like, the ones in government, that is, had definitely talked with folks who do industrial control systems, cybersecurity, things like that, as well as with industry. It wasn’t like people didn’t. That they weren’t in a good state. It’s just that there was a lot of good reasons to not move that quickly. Right? It wasn’t the highest priority. “Well, we’ve gotten away with it for so long. What if you mess something up as part of this upgrade and energy prices spike?” Like, energy prices in a sort of statistical way, when energy prices go up, people die because people can’t afford their heating. Right? This is just true, right? And so I think there was a lot of reluctance to move quickly, but they had a bunch of relationships of. That they were working with to the extent they felt like they could at the time. And then once the rubber hit the road, not only was it the case that they then moved that way up to the top of the priority stack, but also the guys that they’d been talking with already, brought in a lot of their. Very quickly. Which means, one, meet the people involved ahead of time and build those relationships. But 2, also, even if you don’t have those relationships, meet the people in our, in the AI community who do have those relationships and let them know that you’re available to take a call if it’s big enough. And I think I have some friends who just finished up doing the OpenAI Hugging Face independent audit that Redwood and METR did, and they’d literally just, like. It was exactly as happened exactly as quickly, as it seemed like it did from Twitter. Like, they basically, you know. The tweet happened, they announced in all the group chats, “Hey, guys. [laughs] We’re going to be busy for a while.” and then did that and then came back when they were done. One thing that I think people in our community are often really reluctant to do, because I think they don’t. They don’t know they have social permission to do this, right? Like, something that happens not too infrequently as you pointed out a little bit ago, is that child safety is really important to everyone on Capitol Hill because at a first approximation, everyone on Capitol Hill is a parent or a grandparent, and if they’re not, they’re an aunt and an uncle, basically everyone. Right? Just, yeah, that’s how families work, right? And so they care about it even more so than you might think from the outside, right? They care about it’s almost the top priority on tech stuff sometimes, right? And we get pinged a bunch of the time by people asking us questions about the intersection of child safety and AI. And the first time I got one of these, I was a little reluctant. I was “Well, I want to be helpful,” right? I want to, I want to, like. I want to like. There’s a part of you that has this feeling of “Oh, I should give the answer if they’re asking me.” But I you it know, was actually not our area of expertise. Like, we sort of vaguely from general industry knowledge knew some stuff on it, but we didn’t feel “Hey, this isn’t something where we can really go that deep with you on this.” And so we actually had to make a decision. We’re “No, actually we want to get them the right answer.” So we actually reached out to some friends of ours and were “Hey, we think you guys are the ones who really study this issue technically and can give the right answer.” And then they were “Well, actually, [laughs] it’s very surprising that you say that. We’re not the right people either. There’s this other group that you should talk to.” And so then we got connected through that additional paths of, our friends to this other group that we didn’t, at the time, know well. Talked to them very quickly. They were “Yep, this is exactly what we do. Here’s all our publications. Look at our website.” And we sort of did the 30 minutes of due diligence. Obviously we trust our recommendation from our friends, but you still want to be responsible. Look at their website. Yep, they are exactly the right people. Connected them to the Congressional Office. Congressional Office emails us back a week later being “Hey, these were exactly the right people. Thank you so much.” And I think there’s a lot more value in just extending your network to help people than people realize. And I think you do a lot of this as well. I think this is a big part of, where policy success in DC comes from.
Matthew: Yeah. I think obviously I’ve just spent like an hour explaining the Ministry of State, but you kinda got the basics. Now you’ve listened to this podcast. So with that foundation, you can skip going to law school. And,
Dave: Don’t go to law school.
Matthew: And I mean I, as you can just do things regulatory edition, right? There’s. The process is set up specifically because we want public input.
Dave: From non-lawyers.
Matthew: From experts. Right? So, if you have. And there’s certainly ways you can make it more effective. Like, don’t just write your comment in the text form. Put it on a PDF in letterhead, right? There’s ways you can be more effective than random Joe. But,
Dave: And ask Claude what those are. Like, Claude can just tell you. Claude knows.
Matthew: Yes. Yeah. Or ask me. It’s fine.
Dave: Sure. [laughs]
Matthew: And so but you can just submit that comment. You can just request a meeting with a OIRA. You can request a meeting with the agency or the staff, and you say, “Hey, I’m an I work on this. I, my. Does this, or I do this for my company. I’ve been thinking about this issue. I would love to come in and meet with you.” their email addresses are often online, right?
Dave: Yep.
Matthew: There’s often an inter-governmental and external affairs division of an agency that, whose whole job is stakeholder engagement. And so you can, you can just email them. And the worst thing that can happen is that they do not email you back.
Dave: Yep
Matthew: Or you give them bad advice. And, so don’t do that.. But I think that it’s a, lower barrier to entry. And it doesn’t have to just be through the formal rule-making process, although that is set up to give everyone a chance to participate. So I think that’s a very, useful thing to know, is that you don’t have to go to law school or be a DC lawyer in order to influence a regulation.
Dave: Yeah. So one of the things that, one of our other guests, said when we were filming this podcast, I don’t know when we actually publish, whether it’ll be before or after this episode, one of the things he said about Congress is “Look, they look at the same internet as everyone else does.” and my sense is that’s true of regulators as well. They look at the same internet as everyone else does. But where in particular do regulators get their information, right? Sort of when they’re just trying to get smart on something, are they just googling? Are they just. Are they emailing their buddies? Like, is there a Regulator 101 portal they go to? Like, how do they, how do they start getting smart on an issue? And I’m asking in part for the how you can just do things. Like, how can people just then go do the thing of being, in the flow of whatever they use to get smart?
Matthew: Yeah. You can, you can be in the flow, or you can just send your article to them, right? [laughs]
Dave: Ah, yeah.
Matthew: And then it will be in their email inbox. So a lot of agencies do a news clip service. A lot of, times they will try and follow, as much of the industry news as they can. So they’re regulating autonomous vehicles. They’ll try and read every company announcement, to understand what actually is happening, and then read press reporting about, okay, what did they not put in the press release that’s really happening? They’re probably not that at much on Twitter [laughs], compared to,
Dave: Compared to the AI community-. Which is Twitter-addicted.
Matthew: The, they also, though, when they’re trying to figure something out, will look at the most authoritative sources. So, when they are doing a rule about. That affects human. Right how a vehicle will enter. How you operate a vehicle that has some autonomy features in. They’re going to look at the academic psychology and behavioral science research. It’s the most robust, right? If
Dave: Yep.
Matthew: They’re doing a rule on environmental, they’ll look at public health academic research. So they prefer things that’ll hold up in court, right? Because as I said, everything is. Not everything, but everything important is basically litigated. And so they want to have the most reliable sources that they can. So, that obviously has some disadvantages because it’s slower. But they’re going to try and, try and look at those sources. And then people come and meet with them. They’re working 8 hours a day, approximately, and half of that is meetings.
Dave: Yep.
Matthew: You know? And so if you’re there and you have a meeting with them and you are telling them things, that is a source of information, right? And instead of just. They’re not just spending all day browsing. They’re trying to do the stuff they have to do. And then when they’re in a meeting, they have to be focused on the meeting. So being in front of them is probably the best way to get their attention on something. And if you’re talking about something that is important to them or their bosses, then they’ll be more likely to take the meeting. And as you said, AI is the issue of political salience that is rising faster than any other issue by far. Still issue number 25 for the general public, but it’s higher amongst policymakers. So they might well take the meeting with. Like, if you are a member of technical staff as your title, they’re “That’s the person I want to meet.”
Dave: Yep. Who could be more an expert than an MTS, right? Literally, right? Like, this. Like, I think the average member of technical staff is “Yeah, I know hundreds of me. Like, what are you talking about?” They don’t understand that by comparison, in the eyes of a regulator, it’s you versus lobbyist number 814, who I know doesn’t actually know this deeply by default. I’d rather take a meeting with you.
Matthew: Yeah. And they’re. And you’re likely to be less filtered, so they’re probably more interested in that.
Dave: Yeah, so. Think through the upsides and downsides there for your career. But yeah, like. And the other thing I would say is also that I think, 2 other implications of this, because you were sort of saying about they prefer for formal channels and things like that in terms of like publications in journals and things like that. There are ways to make things that you have that are already inside to you as an AI researcher look much more formal very easily, right? So like for example, you can say, “I presented this at a conference,” which you probably in fact have, right? Or, “I presented this at a meeting at OpenAI,” or whatever, or something like that. Again, something that lots of independent researchers often do, right? Or, “I did this through work, through this prestigious fellowship,” like the MATS Fellowship or whatever, right? Like, or for that matter, people inside the AI companies, if they make public statements, even just on Twitter being “I think this is good research and people should pay attention to it,” don’t just view that as a tweet. View that as, “A senior researcher at OpenAI said that our research was worthy of further study.” Right? Like, there are ways to take what is already happening and package it in ways that are much more metabolizable by the DC ecosystem, than people do currently, I think.
Matthew: Yeah. I think it’s all about trust, right? Why should they trust you? They’ve got 10,000 comments in their docket. How do you communicate to a regulator as a, basically as an effective lay. And you have signals of credibility, like your resume, your format that you submit it in, others agree with it, right?. All the things you do to make people in your field know that you’re credible help someone that’s not an AI expert understand why this means you are worth listening to. And find ways, like we’ve talked about, to rise above the. Because no human can read 10,000 comments.
Dave: Mm-hmm. So Matthew one question we’re asking, folks is, what do you wish that you had known, when you were just starting out doing policy here in DC?
Matthew: That you can just do things, regulatory edition. You know you can not go to law school when. You don’t need to do that in order to know how to write a regulatory comment. You’ve just gotten the hour-long spiel of basic, the basic structure of the administrative state and the websites you can go to. Anyone with expertise really can do that. If you are AI native, if you have a lot of expertise in, building these, you could even build new tools that are, that are, that are, don’t exist yet today that make it even more effective. You could build a tool that reads every comment and analyzes them and helps you find what did all the big labs say. And you can then kind of do an analysis of it to make sure that there’s a rebuttal to those if you don’t agree with it or that those are getting proper attention if you do agree with it. You can create these tools much more easily than before where you literally have to click through hundreds of pages on regulations.gov to read each end comment individually and then hit back and then read the next one. And each one is labeled comment number 1234792, right? That’s what. It doesn’t even tell you who it’s from in the, in the hyperlink. So you could build a tool that fixes that. So I think if you are an expert, you can just submit a comment. You can just reach out. It. You don’t have to go to law school to do it. If you are someone with moderate AI or other coding capabilities, you could build tools that makes regular, regulatory process work much better.
Dave: All right, Matthew, where can people find you if they want to follow up with you on anything we talked about today?
Matthew: You can email me, [email protected], or I’m on LinkedIn, Matthew Lipka. I am allegedly on, X, but I’m one of those lurker types, but I’m @matthewlipka there too.
Dave: Yep, cool. And if you can’t find him for some reason, just reach out to me. I have all of his other contact methods as well, postcards, phone number, all that good stuff. Thank you so much, Matthew, for coming on the podcast. This conversation was a real treat. Really appreciate you coming on, and talk to you again soon.
Matthew: Thanks so much for having me. This was a blast.