In this piece:

Boston Common Asset Management (BCAM) wants artificial intelligence (AI) to build stronger companies and make meaningful contributions to human well-being. We believe AI can and should drive productivity, scientific progress, advances in security, and generate attractive long-term returns for our clients. That requires both confidence in the conditions under which risks can be taken and the room for innovation to flourish.

A clear regulatory framework should meet societal needs while supporting business opportunity, investor confidence, and the financing required for U.S. AI leadership. Reducing avoidable risk should not be treated as an opportunity to insulate early AI leaders from competition or other threats to profitability.

A well-structured, enforceable framework should reduce avoidable risk and uncertainty while enabling rapid development within credible safety limits. By clearly defining and disclosing expectations and potential liabilities, investors are empowered to assess and price risk before committing capital, and management avoids relitigating culpability after serious harm occurs.

Effective regulations should make responsible growth easier without making it harder for new entrants to compete.

Self-regulation is not enough

Company expertise and voluntary safeguards are valuable, but they are not a substitute for legally binding obligations that remain operative when commercial pressures intensify.

The federal government’s June 2026 frontier-evaluation framework is voluntary and does not authorize mandatory preclearance. “Frontier” here refers to advanced systems with particularly serious capabilities or risks; the term excludes ordinary AI-enabled products.1 Oversight should follow the risk, whether a system is sold commercially, used internally, or connected to other systems. Ordinary applications should not be subject to a general licensing requirement.

Industry proposals for self-regulation or a role in government oversight warrant both consideration and reasonable scrutiny for potential self-dealing. Anthropic advocates mandatory regulation alongside voluntary coordination. Google DeepMind’s proposal envisages assessments becoming a condition of deployment. OpenAI supports mandatory national requirements, although its detailed June 2026 blueprint leaves deployment decisions with developers and permits release when government capacity constraints cause reviews to miss deadlines. 2–5

These three positions differ materially and should not be treated as a single self-regulation bloc. The key questions are who has final authority to require action, what limits apply to that authority, and whether the resulting system serves the broader economy.

The introduced Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting (FRONTIER) Act illustrates why the details matter. It combines preventive duties and independent assessment with broad immunity for licensed verifiers against specified catastrophic-risk claims, subject to a narrow exception. It also provides for the loss of a verifier’s license.6

Immunity does not eliminate every incentive to perform well. But shielding assessors too broadly from the consequences of deficient work would weaken accountability. Such provisions should be removed or substantially narrowed. Neither investors nor society should be asked to bear preventable losses from deficient oversight.

Investors should scrutinize the incentives of those evaluating risk as carefully as the incentives of those creating it.

The social-media lesson: prevention cannot wait for litigation

The recent rulings against Meta over youth harms expose a failure to protect people early enough. The lesson for AI is to establish clear, enforceable safeguards before serious harm becomes the basis for litigation. Companies remain responsible for the products they design; public authorities must set and enforce effective safety requirements.

In August 2026, a New Mexico court ordered a $567 million fund to address youth mental-health harms, in addition to $375 million in civil penalties and required product changes. It found Meta’s platforms a substantial contributing factor to the state’s youth mental-health crisis. Meta said it would appeal.11,12

Separately, Meta announced a court-approved multistate settlement it described as up to approximately $18 billion, with payments over ten years and partly contingent on competitors’ actions. The agreement also requires product changes and contains no admission of wrongdoing. These are financial obligations, not evidence that the full amount has already been paid.13,14

These cases show that existing law can impose meaningful accountability, including changes intended to prevent further harm. They do not prove that a particular earlier rule would have prevented every injury. Social media and generative AI are not identical; the relevant lesson is to combine liability with earlier safety testing, independent scrutiny, and timely intervention. Investors should understand these obligations before losses emerge; families should not have to wait for litigation to secure adequate protection.

Set clear red lines

Some conduct should be prohibited rather than approved, subject to conditions. BCAM supports clear limits in four areas.

Biological weapons. Prohibit AI use to develop, produce, acquire, or deploy biological weapons, and clearly define what constitutes knowing assistance to those activities. The rules must distinguish weaponization from legitimate medical research and defensive biosecurity. Existing federal biological-weapons law already distinguishes weapons activity from bona fide research and peaceful purposes; AI-specific measures should preserve that distinction.7

Nuclear use and initiation of hostilities. Never delegate to an AI system the decision to initiate nuclear use or begin hostilities.

Lethal targeting of people. Require effective, informed, context-specific human authorization. A nominal human approval should not substitute for responsible judgment. Bounded defensive interception of incoming threats requires a separate, carefully defined analysis.

Abusive surveillance. Prohibit AI-enabled mass domestic surveillance outside lawful authority, with meaningful privacy safeguards, independent oversight, and avenues for challenge. Government use should not receive a blanket exemption from accountability.

These are proposed boundaries, not a claim that all four already command agreement or require identical legislation. Congress should clarify existing prohibitions and close identified gaps.

Prohibitions still require definitions, investigation, and enforcement. They also cannot address every dangerous failure of an otherwise lawful system.

An infrastructure-protection system could cause severe harm because of inadequate controls, even without any intent to violate a prohibition. Clear red lines and preventive supervision should work together, not substitute for one another.

Leverage existing authority to close the gaps

Government should not wait for a comprehensive AI statute to act. Whatever the legislative timetable, delay leaves avoidable risks unresolved and businesses without needed clarity. Existing federal tools can make progress now while Congress closes gaps in authority.

The Securities and Exchange Commission (SEC) has an existing material disclosure framework relevant to AI risks and business effects. Its Investor Advisory Committee has recommended building further AI guidance around that framework; those recommendations are not themselves new binding rules.8

The Federal Trade Commission (FTC) has investigative and enforcement powers addressing unfair or deceptive conduct, subject to statutory limits and jurisdictional exceptions.9

The National Institute of Standards and Technology (NIST), through its Center for AI Standards and Innovation, provides technical evaluation and standards expertise. Its published mandate supplies a foundation for assessment; it confers no general power to approve or halt frontier development.10

The practical approach is to use existing agencies where their responsibilities fit, while giving accountable public authorities additional, clearly defined powers where protection is missing. Technical expertise, information-gathering authority, and power to compel corrective action are different capabilities.

Congress should establish mandatory reporting of serious incidents and significant near misses for covered high-risk systems, with protected reporting channels and penalties for concealment. It should require proportionate protection of sensitive model assets, including model weights (the learned numerical parameters used to run a model) and development infrastructure. Coverage should follow dangerous capability and exposure rather than company size.

Reporting a dangerous deficiency should trigger investigation and corrective action where warranted. Public supervisors must be able to require remediation and restrict inadequately controlled activities under defined, reviewable standards. Prior authorization should be confined to specifically designated highest-risk activities, not ordinary AI development. Those powers can sit within an existing department; a new stand-alone agency is not the objective. Published criteria, reliable review deadlines, and appeal rights must protect against arbitrary intervention and indefinite delay.

Lead in security without depending on universal restraint

None of these safeguards requires ceding ground abroad. American AI leadership should remain an explicit objective. Policy should accelerate responsible development for cyber defense, intelligence, logistics, science, and resilient infrastructure.

National security programs should have technically competent, appropriately classified assessments and responsible authorization. Secrecy may limit public disclosure; it should not remove scrutiny. Human responsibility for lethal force and strategic escalation remains essential.

Minimum domestic safeguards should not depend on foreign reciprocity. Broader agreements to restrain development should require credible verification and acceptable security consequences. Allied cooperation should reduce duplicative compliance; if cooperation fails, policy must still support defensive capabilities and beneficial development without abandoning necessary safeguards.

We should not surrender national capability on the strength of unverifiable promises from other nations. Nor should another country’s recklessness become permission to deploy a system we cannot adequately control.

Protect children’s development and older adults’ independence

The same design-before-harm principle applies where users are most exposed. AI should help children learn, and older people live more independently. Those benefits require that safety and dignity be built into products before release, rather than added after harm. These should be enforceable responsibilities of developers and service providers, not merely questions investors ask or burdens left to families. These protections should apply whether or not the product qualifies as a frontier system.

For children, require age-appropriate safety testing before release and material changes, protective defaults, and ongoing assessment of actual use. Providers should prevent sexualized interactions with minors, grooming, and encouragement of self-harm, while preserving access to legitimate, age-appropriate health information. Products should disclose that they are artificial systems, not people or professionals, and should not be designed to create harmful emotional dependency or exploit distress to prolong use or increase spending.

Privacy-preserving age checks, limits on disruptive engagement features, accessible reporting, and tested routes to qualified human help should support these protections. Parent and caregiver tools are important, but should not excuse unsafe design; responses to serious danger must also account for a child’s safety and privacy. Claims that an AI product improves learning, health, or well-being should require evidence appropriate to the claim. These proposals build on, rather than merely restate, the United Nations Children’s Fund’s guidance on child-centered AI.15

For older adults, protection must preserve autonomy rather than assume incapacity. Providers should address impersonation, financial exploitation, manipulative selling, and attempts to exploit loneliness, grief, or cognitive vulnerability. Suspicious financial instructions should have proportionate independent verification and prompt human review. Age alone should not justify blocking an account, denying a service, or transferring control to relatives.

Healthcare, banking, and other essential services should offer practical access to a person empowered to help or correct a decision, with reasonable non-digital alternatives. Consent and privacy should remain with the individual unless lawful representative authority applies. Older adults should participate in design and testing. Systems used in consequential decisions should be tested with representative populations and assessed for unjustified age-related disparities. The World Health Organization identifies ageism and exclusion as risks requiring specific attention in AI for health.16

AI companions and care tools should strengthen independence and desired human relationships. Before reducing human visits or qualified staffing, providers should demonstrate that necessary care, safety, and individual preferences remain protected. Lower staffing costs or longer chatbot conversations do not, by themselves, demonstrate better care. Declining an optional AI companion should not mean losing essential services.

For both groups, boards should identify accountable executives, oversee incentives that might conflict with safety, and ensure significant harms prompt corrective action. Independent evaluation should be proportionate to risk. Measures should include resolved complaints, access to human support, and credible outcomes for learning, autonomy, and well-being. Engagement metrics alone do not qualify. Regulators should be able to redesign or restrict inadequately controlled harmful features without banning useful applications.

A child’s distress and an older person’s loneliness should never be treated as opportunities for exploitation.

A practical legislative recommendation

BCAM’s recommendation to Congress is a coherent package: clear prohibitions on conduct; mandatory security, evaluation, and serious-incident duties; explicit protections for children and older adults; adequately funded technical capacity; and an accountable public authority to require corrective action, including narrowly targeted authorization and restriction powers where justified.

The package should preserve meaningful liability, protect competition and legitimate research, and coordinate federal and state responsibilities. Federal preemption—displacement of state law—should replace overlapping protections only when an effective federal substitute is operating, while preserving appropriate application-specific and generally applicable protections.

Implementation should proceed alongside defensive and beneficial development rather than require a general pause while institutions are built. Its success should be judged by clearer obligations, timely decisions, reduced preventable harm, and continued productive investment.

We want AI to grow. We want clear rules that support that growth. And we want the institutions enforcing those rules to be worthy of the confidence investors and the public place in them.

Contributing author: Tara Doyle, SVP, Business Development


Source baseline: September 14, 2026. This editorial review rechecked the Meta judgment and settlement references [11–14]; other policy references retain their existing source baseline. The policy comparisons describe the specified publications, not every subsequent legal development. Judicial findings, settlement terms, financial obligations, and company responses are distinguished. The child and older-adult duties are BCAM’s proposals; background guidance is identified separately.

1 The White House. Promoting Advanced Artificial Intelligence Innovation and Security (June 2, 2026). Section 3: voluntary frontier evaluation; not authority for mandatory preclearance.

2 Dario Amodei. We Must Pace the Frontier (September 2026). Advocates regulation alongside voluntary coordination; see “Pacing Within Democracies.”

3 Demis Hassabis. A Framework for Frontier AI and the Dawning of a New Age (July 14, 2026). Federally overseen standards institution and eventual mandatory assessments for market access.

4 OpenAI / Chris Lehane. The AI policy window is open. We need to act. (September 9, 2026). Mandatory national safeguards; voluntary coordination is complementary, not a replacement.

5 OpenAI. Democratic Governance of Frontier AI: A blueprint for a federal framework (June 2, 2026), p. 6. Evaluation versus deployment-blocking authority and missed review deadlines. Read with [4].

6 U.S. Government Publishing Office. H.R. 9925, FRONTIER Act: introduced House text (July 23, 2026). Sections 4–5: preventive and assessment duties; 5(q): verifier immunity; 3(c)(2)(C): license-revocation criteria. H.R. identifies a House of Representatives bill, not an enacted statute. Analysis is of the introduced version.

7 United States Code, reproduced by Cornell Legal Information Institute. 18 U.S.C. § 175: Prohibitions with respect to biological weapons (accessed September 14, 2026). U.S.C. means United States Code. Existing weapons prohibitions distinguish bona fide research and peaceful purposes. Proposed AI-specific boundaries are recommendations.

8 Securities and Exchange Commission, Investor Advisory Committee. Disclosure of Artificial Intelligence’s Impact on Operations (approved December 4, 2025), especially pp. 6–9. Materiality-based recommendations using existing disclosure requirements; these are advisory recommendations, not Commission rules.

9 Federal Trade Commission. A Brief Overview of the FTC’s Investigative, Law Enforcement, and Rulemaking Authority (revised July 2025). Existing unfairness and deception powers, statutory conditions, and jurisdictional limits.

10 National Institute of Standards and Technology. Center for AI Standards and Innovation (accessed September 14, 2026). Published technical evaluation, voluntary collaboration, and standards functions; not a general deployment-authorization mandate.

11 New Mexico First Judicial District Court. State ex rel. Torrez v. Meta Platforms, Inc., No. D-101-CV-2023-02838: findings and judgment (August 6, 2026). Paragraphs 12, 79, and 120–121: $375 million civil penalty, causal finding concerning the state’s youth mental-health crisis, and $567 million abatement fund. The judgment also orders product changes. Court-ordered amounts are not a finding that payment has occurred.

12 Reuters. How could New Mexico’s $567 million ruling change Meta? (August 7, 2026). Meta disputed the decision and said it would appeal. The article is used for that response; the court’s judgment is the source for its findings.

13 Meta. Our Agreement With Bipartisan Attorneys General: Calling on TikTok and YouTube to Join Us in Supporting Teens (August 26; updated August 27, 2026). Reports court approval; describes approximately $18 billion over ten years, about $12.7 billion in scheduled payments and $5.3 billion contingent on specified competitor actions. Includes usage restrictions and independent oversight. These figures are Meta’s description of the overall agreement, not cash already paid.

14 California et al. v. Meta Platforms, Inc. et al., No. 4:23-cv-05448-YGR. Filed settlement agreement and proposed consent judgment, document 572-1 (filed August 26, 2026), agreement Section X.C and proposed judgment Section IX.C: no admission of liability or wrongdoing. The filed exhibit itself is proposed; subsequent approval is confirmed separately by the North Carolina Department of Justice announcement of August 27, 2026. North Carolina confirmation of approval.

15 United Nations Children’s Fund. Guidance on AI and children, version 3.0 (December 2025). Guidance on child-centred oversight, safety, privacy, accountability, development, and well-being, including AI companions. Background for BCAM’s proposals, not evidence that all proposed duties are existing law.

16 World Health Organization. Ensuring artificial intelligence technologies for health benefit older people (February 9, 2022). Introduces the Ageism in Artificial Intelligence for Health policy brief: inclusion, representative evidence, autonomy, consent, and governance.

Published On: September 17, 2026

This piece is intended as an editorial review of a survey of risk considerations and does not constitute investment advice, a solicitation, or an offer to buy or sell any security. Past performance does not guarantee future results. All investments involve risk, including the risk of loss of principal.

References to third-party research, publications, and data sources are provided for informational purposes only. Boston Common Asset Management does not warrant the accuracy or completeness of third-party information cited herein. Readers should consult original sources and qualified professional advisors before making any investment decision.