Study finds developer AI regulation safer than deployer rules
A Study That Flips the Assumption
Everyone assumes that regulating the companies that use artificial intelligence is the safest path. If a chatbot gives bad medical advice or a hiring tool discriminates, the logic goes, hold the company that deployed it accountable. But A new study published in the journal PNAS suggests this instinct is precisely wrong. Researchers from Cornell University and Carnegie Mellon University used economic modeling and game theory to simulate how companies respond to different regulatory frameworks Their conclusion: when rules place most of the responsibility on the businesses integrating AI into products — chatbots, healthcare tools, shopping platforms — the companies that build the underlying models quietly stop investing in safety. The result is not a safer system, but a gap where critical precautions vanish.
The International Comparison That Reveals the Pattern
Consider how different governments are approaching this problem. In Europe, the AI Act focuses heavily on “high-risk” applications, meaning the companies that deploy AI in sensitive areas like hiring, credit scoring, or law enforcement bear most of the compliance burden. Developers of foundation models — the large, general-purpose AI systems that power many applications — face lighter obligations. In the United States, the Biden administration’s executive order on AI similarly targets deployers, requiring them to test and document how their systems perform. The PNAS study argues that both approaches inadvertently create a “free-riding” problem. When foundation model developers know that app builders will be held responsible for safety, they have little incentive to conduct independent safety testing or submit to third-party audits. Why spend resources on something someone else is expected to handle later? The economic modeling shows that under such rules, investment in safety by developers drops measurably, while deployers, who often lack visibility into the model’s inner workings, cannot compensate for that loss.

The Detail That Shows How Far Practice Is From the Promise
The most telling detail in the study is the researchers’ use of game theory to model the interaction between developers and deployers as a strategic game. Each side chooses how much to invest in safety based on what they expect the other to do. Under a developer-focused regulatory regime, where the builder is primarily responsible, both sides invest more because the builder cannot offload risk. Under a deployer-focused regime, the builder reduces investment, the deployer tries to pick up the slack but lacks the technical access to do so effectively, and overall safety declines. This is not a hypothetical scenario. The study cites real-world examples where foundation model companies have already reduced transparency about training data, model architecture, and internal safety testing — precisely the kind of information deployers would need to assess risk. The gap between the promise of shared responsibility and the reality of strategic cost-cutting is wide, and poorly designed regulation widens it further. The researchers conclude that the most effective rules are those that make both developers and deployers legally accountable, forcing them to invest in safety together rather than betting that the other side will carry the burden. Until that happens, the safest path is the one no one is taking, and the gap between regulatory intent and real-world safety will continue to widen.
