Several jurisdictions are starting to regulate frontier AI systems (i.e. general-purpose AI systems that match or exceed the capabilities present in the most advanced systems). Requirements could be formulated as high-level principles (e.g. ‘frontier AI systems should be safe and secure’) or specific rules (e.g. ‘frontier AI systems must be evaluated for dangerous capabilities following a specific protocol’). While rules provide more certainty and are easier to enforce, they can quickly become outdated and lead to a box-ticking attitude. Conversely, while principles provide less certainty and are more difficult to enforce, they are more adaptable and more appropriate when regulators are unsure what behavior would best advance their regulatory objectives. The chapter recommends that policymakers initially mandate adherence to principles, ensure that regulators and third parties closely oversee compliance with these principles, and build up regulatory capacity. Over time, the approach should likely become more rule-based.
