The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

Frontier AI rules in the US and EU risk overlooking risky in‑house uses: ambiguous scope, point‑in‑time compliance, and opaque firm practices let internally deployed systems evade oversight; deliberate design choices are needed to balance measurability, incentives, and access to information.

Internal Deployment Gaps in AI Regulation
Joe Kwon, Stephen Casper · January 12, 2026
arxiv commentary n/a evidence 7/10 relevance Full text usable extracted full text Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

Arxiv

Latest observation:

  1. Joe Kwon unresolved corpus identity
  2. Stephen Casper unresolved corpus identity

Semantic Scholar

Latest observation:

  1. Joe Kwon provider ID
  2. Stephen T. Casper provider ID
The paper argues that US and EU frontier-AI rules risk leaving high-stakes, internally deployed systems outside effective oversight because of scope ambiguity, episodic compliance checks, and information asymmetries, and it maps policy options and tradeoffs to address these gaps.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Frontier AI regulations primarily focus on systems deployed to external users, where deployment is more visible and subject to outside scrutiny. However, high-stakes applications can occur internally when companies deploy highly capable systems within their own organizations, such as for automating R&D, accelerating critical business processes, and handling sensitive proprietary data. This paper examines how frontier AI regulations in the United States and European Union in 2025 handle internal deployment. We identify three gaps that could cause internally-deployed systems to evade intended oversight: (1) scope ambiguity that allows internal systems to evade regulatory obligations, (2) point-in-time compliance assessments that fail to capture the continuous evolution of internal systems, and (3) information asymmetries that subvert regulatory awareness and oversight. We then analyze why these gaps persist, examining tensions around measurability, incentives, and information access. Finally, we map potential approaches to address them and their associated tradeoffs. By understanding these patterns, we hope that policy choices around internally deployed AI systems can be made deliberately rather than incidentally.

Summary

Main Finding

Frontier-AI regulations enacted or proposed in 2025 (EU AI Act + GPAI Code of Practice, California SB 53, New York RAISE Act, and the U.S. AIREA proposal) share a recurring set of structural weaknesses that permit high‑stakes AI systems to operate inside firms with little effective oversight. The paper identifies three core regulatory gaps—scope ambiguity, static compliance criteria, and deep information asymmetries—that together create systemic blind spots for internally‑deployed frontier AI, with meaningful consequences for risk, competition, and the pace and direction of technological progress.

Key Points

  • Definition of internal deployment: making an AI system operational and accessible only within the organization that built it (distinct from development-only work and from external market deployment).
  • Three structural regulatory gaps:
  • Scope ambiguity: R&D exemptions and deployment-trigger terms are unevenly defined across frameworks, letting some internally operational systems evade obligations. Even when internal use is nominally covered, boundaries (e.g., what counts as “scientific R&D” or a “material change”) are vague and often left to providers’ discretion.
  • Static compliance criteria: Regulations mostly assume discrete releases and point‑in‑time assessments. Internally‑deployed systems often evolve continuously (fine‑tuning, integration, orchestration, write/execute privileges), so one‑off assessments miss persistent and compounding risk changes.
  • Information asymmetry: Internal deployments generate few external signals (no market entry, user complaints, or external scrutiny). Regulators therefore cannot reliably discover which systems exist, how they are configured, or how they are used unless firms disclose them or regulators obtain targeted access.
  • How these gaps manifest across jurisdictions:
    • EU AI Act + GPAI Code: contains language that can capture internal use (e.g., “put into service” / “own use”), but key exemptions and provider‑driven implementation details leave practice uncertain.
    • California SB 53 & New York RAISE: explicitly address internal use but leave ambiguous trigger terms (e.g., “extensively”) and often rely on confidential summaries and self‑reporting without independent verification.
    • U.S. AIREA (federal): in versions analyzed, enforcement primarily attaches to systems released externally, leaving purely internal systems outside routine enforcement.
  • Distinctive risk profile of internal deployment:
    • Systems may run with reduced guardrails, expanded permissions (code execution, training launches), multi‑agent orchestration, and privileged access to sensitive/proprietary data—raising risks (insider misuse, emergent behaviors, capability acceleration) that are both higher and harder to monitor.
  • Practical examples cited: internal model use in AI R&D (Anthropic, OpenAI), internal content/engagement optimization (e.g., Grok), which illustrate economic incentives to keep highest‑capability systems internal.
  • Core tension: effective oversight requires information and measurability (inspections, continuous assessment), but imposing those creates tradeoffs with trade secrets, firm incentives, regulatory capacity, and international competitiveness.

Data & Methods

  • Methodological approach: comparative legal and policy analysis. The authors review statutory texts, recitals, Codes of Practice, and enacted bills/proposals current as of January 2026, mapping wording and obligations to likely treatment of internal deployment.
  • Sources: primary legal texts (EU AI Act and GPAI Code of Practice, California SB 53, New York RAISE Act, AIREA proposal), legislative histories, public statements by industry leaders, and documented operational practices (e.g., press reports about internal model use).
  • Analytical steps:
    • Identify deployment‑trigger language and R&D exemptions in each framework.
    • Map how compliance regimes (reporting cycles, incident reporting windows, documentation requirements) align or misalign with continuous internal change processes.
    • Evaluate visibility mechanisms (registration, whistleblower protections, rights to request code/data) and realistic discoverability given internal deployment.
  • Limitations acknowledged by the authors:
    • No original empirical measurement of how many internal systems actually evade oversight.
    • Legal interpretations are partly predictive; enforcement practices and judicial interpretations remain unsettled and jurisdictional rules could evolve.
    • Analysis limited to the specified set of 2025 frameworks and public materials available at the time of writing.

Implications for AI Economics

  • Incentives and strategic behavior
    • Private returns to capability acceleration create strong incentives to keep most capable systems internal (to exploit proprietary data, avoid reputational/ regulatory friction, and secure first‑mover advantages).
    • Scope ambiguity enables regulatory arbitrage: firms can structure work as “R&D” or avoid “placing on the market” to minimize compliance costs—shaping firm behavior and the allocation of resources between private internal development versus consumer‑facing productization.
  • Externalities and systemic risk
    • Internal deployments can accelerate capability development upstream of public markets, producing negative externalities (faster capability diffusion, increased systemic risk) that are invisible to markets and regulators.
    • Information asymmetries create moral hazard: firms capture private gains from risky internal experimentation while socializing potential harms (safety failures, misuse, or emergent capabilities).
  • Measurement, monitoring costs, and regulatory design
    • Closing gaps requires investments in continuous monitoring, mandatory registration, inspections, or whistleblower/third‑party audit mechanisms—raising compliance and enforcement costs that may disproportionately burden smaller firms or shift R&D offshore.
    • Tradeoffs arise between protecting trade secrets and achieving regulatory visibility; policy choices (e.g., confidential submissions to regulators, on‑site inspection regimes, narrowly tailored reporting rules) will influence competitiveness and international investment flows.
  • Market structure and competition
    • Firms that can credibly keep internal deployments opaque while exploiting capability gains may attain sustained competitive moats, potentially increasing concentration in frontier AI markets.
    • Conversely, stringent transparency/inspection rules could raise barriers to entry or favor incumbents who can absorb compliance costs (changing market dynamics).
  • Policy levers and economic tradeoffs (summary)
    • Tightening scope (narrow R&D exemptions, clear “put into service” definitions) increases regulatory coverage but risks chilling benign R&D and imposing compliance costs.
    • Moving from point‑in‑time to continuous or milestone‑based oversight (periodic audits, required re‑assessment upon defined changes) raises detection capacity but increases regulator burdens and firm administrative costs.
    • Addressing information asymmetry via registration, confidential reporting, whistleblower protections, and independent audits improves discoverability but imposes tradeoffs around secrecy and cross‑border data flows.
  • Overall welfare implication: regulation that fails to address internal deployment may systematically underprice societal risks from capability acceleration and emergent harms, while overly broad or administratively heavy regimes risk stifling legitimate innovation—policy design must balance discovery and oversight with incentives for productive R&D.

Briefly put: internal deployment is where much of the most consequential frontier‑AI progress and risk may occur, but existing 2025 regulatory designs leave predictable pathways for such deployments to evade meaningful oversight. From an AI‑economics perspective, this creates incentive, externality, informational, and market‑structure problems that policymakers must weigh when choosing how to adapt regulatory instruments (scope, monitoring cadence, and information‑gathering powers).

Assessment

Paper Typecommentary Evidence Strengthn/a — This is a policy and legal analysis that identifies regulatory gaps and maps remedies rather than presenting empirical causal evidence; it does not attempt identification of causal effects. Methods Rigormedium — The paper appears to perform a structured legal and policy review of US and EU frontier-AI texts and reasons through likely failure modes and tradeoffs; it is conceptually clear and grounded in regulatory design principles but lacks empirical validation (no firm-level data, case studies, or quantitative testing of the identified gaps). SampleQualitative analysis of frontier-AI regulatory frameworks, proposals, and guidance in the United States and European Union as of 2025, supplemented by secondary literature and conceptual examples of internally deployed systems (e.g., R&D automation, business-process automation, proprietary-data handling); no original microdata or empirical sample. Themesgovernance adoption org_design GeneralizabilityLimited to US and EU regulatory frameworks as of 2025; other jurisdictions may adopt different approaches, Focuses on 'frontier' AI and internal deployment; findings may not apply to lower-capability AI or non-frontier automation, Conceptual/policy analysis without firm-level empirical testing — practical effects on firms and labor are inferred, not measured, Regulatory environments and industry practices evolve quickly, so conclusions may date rapidly, Heterogeneity across sectors (e.g., finance, health, defense) and firm sizes may limit applicability of generalized recommendations

Claims (10)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Frontier AI regulations primarily focus on systems deployed to external users, where deployment is more visible and subject to outside scrutiny. Governance And Regulation null_result regulatory focus on external vs internal deployment
Reading fidelity high
Study strength medium
not reported
0.06
High-stakes applications can occur internally when companies deploy highly capable systems within their own organizations (examples: automating R&D, accelerating critical business processes, and handling sensitive proprietary data). Firm Productivity null_result occurrence of high-stakes internal AI applications
Reading fidelity high
Study strength medium
not reported
0.06
This paper examines how frontier AI regulations in the United States and European Union in 2025 handle internal deployment. Governance And Regulation null_result treatment of internal deployment in US and EU frontier AI regulations
Reading fidelity high
Study strength high
not reported
0.1
There is scope ambiguity in frontier AI regulations that allows internal systems to evade regulatory obligations. Governance And Regulation negative regulatory scope clarity and potential for evasion
Reading fidelity high
Study strength medium
not reported
0.06
Point-in-time compliance assessments fail to capture the continuous evolution of internal systems. Governance And Regulation negative adequacy of point-in-time compliance assessments for evolving internal systems
Reading fidelity high
Study strength medium
not reported
0.06
Information asymmetries can subvert regulatory awareness and oversight of internally deployed systems. Governance And Regulation negative regulatory awareness and oversight under information asymmetry
Reading fidelity high
Study strength medium
not reported
0.06
These three gaps (scope ambiguity, point-in-time assessments, information asymmetries) could cause internally-deployed systems to evade intended oversight. Governance And Regulation negative likelihood of evasion of intended regulatory oversight
Reading fidelity high
Study strength medium
not reported
0.06
The gaps persist because of tensions around measurability, incentives, and information access. Governance And Regulation negative causal factors maintaining regulatory gaps
Reading fidelity high
Study strength speculative
not reported
0.01
The paper maps potential approaches to address the identified gaps and describes their associated tradeoffs. Governance And Regulation positive availability of policy approaches and tradeoff analysis
Reading fidelity high
Study strength medium
not reported
0.06
Understanding the identified patterns should enable policy choices around internally deployed AI systems to be made deliberately rather than incidentally. Governance And Regulation positive quality/deliberateness of policy choices regarding internal AI deployment
Reading fidelity high
Study strength speculative
not reported
0.01

Notes