The textbook for AI Policy 101 does not exist. There is no AI Governance for Dummies. Recent incidents involving internally deployed AI models escaping the testing environments crafted by their developers sound like the stuff of science fiction. Yet cybersecurity, biological, surveillance, and loss-of-control risks from frontier AI models are very much real and very much something that existing government institutions are poorly equipped to evaluate.
Complexity, however, is not an excuse for inaction. Regulation of the securities sector through the Financial Industry Regulatory Authority, or FINRA, provides one example of Congress developing a regulatory framework that moves at the pace of the underlying industry, incorporates industry expertise, and retains federal oversight. It is therefore unsurprising that labs and lawmakers have rallied behind the idea of a FINRA for AI.
The analogy has real appeal as stakeholders look for the best framework to harness AI’s full potential while accounting for its risks. FINRA and its predecessors relied on industry participants to develop rules, inspect regulated firms, investigate potential violations, and discipline and even expel members. The Securities and Exchange Commission (SEC) supplied the public backstop by supervising the regulatory body, reviewing its rules, and retaining authority over consequential decisions.
Translated to AI, that model might rely on independent technical organizations to develop and regularly update model-evaluation standards. Such an approach would not need to apply to every model but could provide a balanced and adaptive way to address the concerns of both policymakers and the public surrounding specific issues such as cybersecurity. Accredited evaluators could test frontier models before deployment, continue monitoring them after release, and audit whether labs followed required risk-management practices. An AI self-regulatory organization might investigate deficiencies in a model’s safeguards, require remediation, or recommend that a model lose its certification as safe to deploy. A federal agency would oversee the system, approve or review its most consequential standards, and retain the final word when a decision could prevent a lab from deploying a model.
That framework strategically divides responsibility according to institutional competence. Technical experts would conduct the evaluations. The private organization could update its methods near the pace of model development. And the government would protect the public interest without attempting to reproduce the labs’ expertise inside a conventional federal agency.
The history of securities self-regulation shows why such an arrangement may not remain so neat.
The Securities Exchange Act of 1934 initially assigned exchanges substantial discretion and authority to govern themselves. The SEC held important reserve powers, but then–SEC Chairman William O. Douglas described the government’s intended role through a memorable image: “The exchanges take the leadership with the government playing a residual role. Government would keep the shotgun, so to speak, behind the door, loaded, well oiled, cleaned, ready for use but with the hope it would never have to be used.” The Maloney Act extended the same philosophy to the over-the-counter market, eventually producing the National Association of Securities Dealers, FINRA’s predecessor.
That allocation of responsibility did not last. Experience exposed gaps between self-regulatory performance and regulatory need. Congress responded in 1975 by expanding the SEC’s authority. A broader set of exchange rules and disciplinary actions became subject to federal approval or review. The commission acquired greater power to alter self-regulatory rules, promulgate its own requirements, and enforce federal law directly. It also used informal pressure to shape the conduct of self-regulatory organizations.
This gradual migration of authority from the private regulator to the federal agency is what commentators mean by the federalization of self-regulation. The private organization continues to exist. It may retain substantial technical expertise and conduct much of the day-to-day regulatory work, but the federal government increasingly determines the rules, reviews the organization’s decisions, and constrains how it exercises its authority. The SEC moved from holding the shotgun behind the door to standing in the room.
Some of that federalization was justified. Self-regulatory organizations do not merely publish voluntary best practices. They can investigate members, adjudicate violations, impose financial sanctions, and exclude firms from the regulated market. Because participation in FINRA is practically indispensable for most broker-dealers, expulsion may amount to exclusion from the securities industry itself.
An AI FINRA could possess comparable power. If federal law made certification or membership a prerequisite to deploying certain frontier models, a decision to expel a lab, revoke its certification, or block a model’s release could determine whether the company may bring a product to market. Billions of dollars, years of research, and the competitive position of a major American firm could turn on the decision of an ostensibly private body.
That possibility creates more than a policy concern. It also implicates constitutional limits on Congress’ ability to delegate governmental power. Congress generally cannot transfer coercive regulatory authority to private parties and then walk away. Courts have permitted private entities to assist in regulatory programs when they remain subordinate to public officials who retain ultimate authority. The more power a private regulator has to bind unwilling parties, the stronger the need for governmental supervision, fair procedures, and meaningful review.
Here lies the difficulty: The constitutional cure threatens the underlying justification for this regulatory approach. Loosen the governmental harness and the private regulator may exercise public power without sufficient public accountability. Tighten the harness and the organization begins to acquire the approval requirements, appeals, procedures, and delays that self-regulation was supposed to avoid.
FINRA now sits inside that tension. At the preliminary injunction stage in Alpine Securities Corp. v. FINRA, the DC Circuit concluded that FINRA likely could not expel a member through an expedited process before the SEC reviewed the merits. The significance of the decision follows from the significance of expulsion. FINRA was not merely reprimanding a voluntary member of a private club. Its decision could effectively prevent the firm from continuing in the securities business.
Litigation involving the Horseracing Integrity and Safety Authority shows that Congress’ more recent experiments with private rulemaking and enforcement face similar objections. Rulemaking, auditing, investigation, adjudication, and enforcement do not raise identical constitutional concerns. Yet proposals for an AI FINRA often collect those functions under the appealing but underspecified label of audited self-regulation. A more precise framework is necessary.
Congress cannot copy and paste FINRA into the AI context. The range of functions already associated with an AI FINRA is remarkably broad. The institution might develop evaluation standards, accredit third-party auditors, inspect labs, investigate testing failures, require access to models and internal records, adjudicate disputes over compliance, certify models as safe to deploy, order remediation, suspend releases, or impose financial penalties. Those functions require different forms of expertise, create different risks, and raise different constitutional concerns.
Housing all of them within one nominally private organization would be a mistake. The resulting institution would combine technical standard setting, investigation, adjudication, and enforcement under one roof. Its decisions could determine which firms may compete, which models may be released, and which forms of AI development remain lawful. An organization with that much authority would predictably attract demands for close federal supervision. The broader its mandate, the stronger the pressure toward the same federalization that transformed securities self-regulation.
A better approach would be to disaggregate the FINRA model. Congress should consider chartering a network of specialized, private evaluation bodies—each tethered to an existing federal agency rather than housed within one. A mini-FINRA for cybersecurity risks might answer to the Cybersecurity and Infrastructure Security Agency; a counterpart focused on biological risks might answer to the Department of Health and Human Services. Each body would remain private and technically self-governing, but each would operate under the supervision of the agency that already regulates the underlying domain. Competing technical bodies in discrete domains could develop and refine evaluation methods for relevant AI use cases. Institutions focused on biological, cybersecurity, or other specific risks could develop expertise that a general-purpose regulator would struggle to maintain. The applicable federal agency could establish minimum requirements, compare the performance of different evaluators, and intervene when an organization repeatedly fails to detect significant risks. And because sector agencies already hold relevant in-house expertise, they could better manage and hold to account their mini-FINRA than a single, newly created AI regulator could hold to account a single, all-purpose self-regulatory organization.
The Center for AI Standards and Innovation (CAISI) could serve as the connective tissue across this alternative regulatory paradigm—providing regular updates on AI advances and risks so that agencies supervising different mini-FINRAs would work from a common technical baseline. CAISI could also handle the small class of questions that resist domain-by-domain treatment: defining the capability thresholds that bring a model within the frontier regime and setting the minimum evaluation floor beneath which no mini-FINRA may fall. Those decisions require uniformity and should rest with a single technical body.
This modular structure would preserve several of the claimed benefits of self-regulation. Competition among evaluators could encourage the development of better testing methods and reduce dependence on a single organization’s assumptions. Specialization could allow standards to evolve alongside particular capabilities and risks. Cross audits and public performance measures could reveal which evaluators are overly permissive, overly restrictive, or simply ineffective. Congress would still need to guard against forum shopping—seeking to fall within the jurisdiction of one mini-FINRA and not another for perceived differences in regulatory pressure—and a race toward weaker standards, but a common federal floor need not require a single federalized regulator. This structure could allow for streamlined approval of models within discrete domains, fostering more competition and improving access. Models built for a single application could also be freed from standards that have nothing to do with them.
Disaggregation would also make the constitutional analysis more manageable. As briefly noted, a body that develops voluntary testing protocols, publishes technical guidance, or conducts nonbinding evaluations presents a different constitutional case from one that compels evidence, imposes fines, revokes licenses, or blocks deployment. The more coercive the function, the stronger the need for public control, appointment of key officials through politically accountable processes, fair procedures, and meaningful judicial review. Congress can leave room for experimentation with private experts without also allowing those experts to determine, without public supervision, who may participate in the AI market.
The allocation of responsibility should therefore track the nature and consequences of each decision. Private and competing institutions may be well-suited for research, standard setting, testing, and auditing. A hybrid body might issue provisional certifications or recommend remediation pursuant to publicly established criteria. Decisions that compel disclosure, impose sanctions, suspend deployment, or exclude a lab from the market should remain with a federal agency or become effective only after prompt and independent agency review. A regulator cannot be private when convenient, governmental when exercising coercive power, and insufficiently accountable in either capacity.
A modular system would also provide a more credible route to speed because knowledgeable agencies could more easily assess the risks posed by any new AI advances in their domains. Not every regulatory decision requires the same process. Technical standards can be updated continuously. Routine audits can proceed under predetermined protocols. Minor deficiencies can produce provisional certification and time-limited remediation rather than immediate exclusion. More elaborate procedures should attach when the government or its delegate seeks to block deployment or impose another sanction with substantial economic consequences.
Congress should specify those procedures in advance. The statute could establish fixed deadlines for agency review, determine whether a model may be deployed subject to interim safeguards during an appeal, and channel review of exclusion decisions to a designated federal court. The objective should not be to foreclose process where it is necessary but rather should be to reserve the most demanding process for the decisions that most resemble exercises of sovereign power.
AI developers and deployers need a regulatory system that moves at the speed of their release cycles and can take a flexible approach. The Constitution requires public accountability when regulatory institutions exercise public power. Ninety years of securities regulation show what happens when Congress tries to satisfy both demands through a single hybrid organization: Authority accumulates, oversight expands, and self-regulation gradually becomes federal administration by another name.
The better lesson from FINRA is therefore not that Congress should create one equivalent institution for AI. It is that Congress should separate the functions that benefit from competition and experimentation from those that require uniformity and public control. AI regulation should be plural where technical innovation matters, coordinated where common standards are necessary, and unmistakably governmental where coercion begins.