By Allison Stanger | Analysis | September 7, 2026
A small number of private firms are writing the rules for a new constitution driven by artificial intelligence without input from citizens. Photo illustration by Thomas Gaulkin; images via depositphotos.com
Nearly 240 years after the framers designed an architecture for American political life, a new constitution is currently being written, driven by artificial intelligence and set to govern American life in the 21st century and beyond. AI is becoming the lens through which citizens read, deliberate, remember, and decide.
A small number of private firms are effectively writing the rules for this new system without input from citizens. The people who live inside these ecosystems have no exit and no voice. But it doesn’t have to be this way. A constitutional alternative exists—tiered where capabilities are dangerous, federated among local stewards, portable so that people can leave, and provable in its operation: every answer shows its sources, every contribution routes home, every reading leaves a deposit, and every error can be reversed. Those practices are not hypothetical; they already run at state scale in Taiwan. And civil society, not the AI industry or the universities the industry is increasingly funding, should build the alternative, because only an independent founder can write rules that bind the powerful.
The default constitution. Frontier laboratories are building architecture that is centralized three times over: The same firm trains the model, owns the infrastructure it runs on, and revises unilaterally the rules for who may speak with it and on what terms. A user’s accumulated context—the history, the adaptations, the accreted understanding that makes a system useful to a particular person—cannot be moved to a rival provider. In other words, the months of conversations and corrections a person builds up with one firm’s system cannot follow that person to a competitor.
Private firms are making decisions of genuine constitutional consequence behind closed doors, on schedules the public does not set and cannot see. A frontier model dominated world is authoritarian in structure regardless of the intentions of the people running it. Benevolent dictatorship is still dictatorship, and architecture long outlives intentions. What these firms build in the next few years is the system their users’ grandchildren will live inside.
Control over access is only half the ledger. The other half is what the firms extract. The Wikimedia Foundation has documented that human pageviews on Wikipedia fell even as the bandwidth consumed by AI crawlers scraping its archive rose 50 percent. Value now leaves through the same door that knowledge used to enter by, and nothing is deposited on the way out.
In July, at the Bibliothèque nationale de France, the institutions that steward what humanity knows—Wikimedia, the Internet Archive, Creative Commons, Europeana, UNESCO—convened to decide how that inheritance should be shared with, and shielded from, AI systems. Keynoting the gathering, Audrey Tang, Taiwan’s first digital minister, named a shared anxiety, a future she calls the dark commons: answers that no longer show their sources, and sources that never see their readers.
It is a pattern I described in the Bulletin last year. In the 18th century, the East India Company, a private firm, collected taxes, raised armies, and administered justice for millions before the Crown stepped in. Today’s private power—the AI Raj—is assuming public functions on the same model, and what it is colonizing is the accumulated knowledge of the entire human species.
Silicon Valley has split over where AI systems will live and run. One vision keeps them in the cloud, metered and gated by whoever operates it. The other places it on hardware the user owns. At Computex in May, NVIDIA and Microsoft announced RTX Spark: a one-petaflop chip purpose-built for AI agents that live on the device itself, shipping this fall in laptops from major manufacturers. That is enough to run a 120-billion-parameter model—an AI approaching frontier capability—on a home computer.
An AI agent that runs on a personal machine, but under permissions its vendor wrote and can revise, changes where the computation happens without changing who holds the power: the agent still answers to its maker before it answers to its owner. Wikipedia’s co-founder Jimmy Wales has described what that default future looks like: a reader whose machine visits three thousand pages while its human sees none, the reading done for you by software whose loyalties you cannot inspect.
A system this powerful cannot be open to everyone, anonymous to everyone, and safe for everyone at once. Capabilities that can materially assist in the synthesis of a pathogen cannot responsibly be handed to an unverified stranger. The critical question is which tradeoffs a free people would choose in daylight, and which are being chosen for them in the dark.
The standard objection to openness is that America is racing China and cannot afford to share. But the arms race logic cuts the other way. The United States can beat China at the frontier; what it cannot do is beat China at centralization. An authoritarian system is already optimized for concentration of power and pays no domestic price for it. A democracy that centralizes the infrastructure of cognition has conceded the terms of the competition before running it. The architecture that plays to free-world strengths is pluralist, because plurality is the thing an authoritarian competitor structurally cannot replicate without losing control.
The republican alternative. A constitutionally defensible architecture makes four promises.
First is tiering. The most powerful and potentially dangerous capabilities of an AI system should require users to prove who and where they are. Think of this like a driver’s license: It establishes your identity and physical presence, but it does not require you to swear allegiance. Less dangerous capabilities should remain open to everyone. Call this “tiering.”
Second is privacy. Operators should be able to prove what their machines are running without being able to read what the users are doing on those machines. Apple’s Private Cloud Compute already demonstrates this kind of verification at consumer scale.
Third is federation. No single company should control the entire system. Its units must be local stewards (accountable to the communities that deploy them) and connected through open protocols—a federation rather than a platform.
Fourth is portability. Users should be able to leave, taking their accumulated context across providers, just as they would a phone number from one carrier to another.
Portability is the promise that turns the other three promises from principles of good governance into rights. A person who can leave is a citizen; a person who cannot is a subject.
The computational unit is small, bounded, and tended locally. The concept comes from Audrey Tang and Director of Research and Head of Public Engagement at the Institute for Ethics in AI at University of Oxford’s Caroline Emmer de Albuquerque Green’s work. A Kami (short for Knowledge Artefact Management Intelligence) is AI capability placed in the service of a defined community and held accountable to it. The name borrows the Japanese folk idea of a small spirit that belongs to one particular place. A Kami holds no warrant beyond its constituted ends. It runs under deliberate caps on compute and reach. And it carries a sunset, so that its continuation is a decision its community must actively renew.
Picture one concretely. A county historical society keeps a Kami fluent in a century of local records—deeds, land surveys, the weekly newspaper, oral histories on decaying cassette. A resident tracing her grandmother’s farm asks it questions at the library terminal, and every answer arrives with citations pointing back to the box and folder where the source sits. When she spots an error, like a misdated photograph, her correction flows back into the archive rather than vanishing into some distant corporation’s training run. The Kami’s charter runs three years; its compute is capped; and unless the society’s board votes to renew it, it retires on schedule. The archive itself is permanent—the deeds and the newspapers remain.
None of this is hypothetical. Taiwan has put this idea into practice at a national level: using technology to help people work together despite their differences. The approach, put forth by Tang, borrowed from Wikipedia: Publish information openly, allow people to verify it together, and keep a record of every change so errors can be corrected quickly. By Tang’s account, public trust in government rose from about 9 percent in 2014 to more than 70 percent by 2020.
One example shows how this worked in practice.When deepfake investment scams flooded Taiwan in 2024, the Ministry of Digital Affairs convened 447 demographically representative citizens, recruited by text-message lottery, to deliberate online about how platforms should respond. Many initially favored mandated algorithmic transparency but support fell by 27.5 points after they weighed the tradeoffs. Nearly nine in 10 backed requiring platforms to detect and label AI-generated content. Within months, the Taiwanese government incorporated these concerns into anti-fraud legislation, having platforms take responsibility for fraudulant ads and establishing disclosure requirements for deepfakes.
Keeping it. Washington has already shown what executive-branch AI governance looks like in practice. On June 2, President Trump signed an executive order establishing a voluntary framework under which frontier laboratories grant the government up to 30 days of early access to models the National Security Agency designates as “covered frontier models”—through a benchmarking process that is classified. The implementing framework was circulated privately in early August with a handful of companies (OpenAI, Anthropic, and Google among them) and will not be published.
The Cyberspace Administration of China likewise reviews models before they reach the public, and negotiates the real terms privately with a handful of national champions. A nation cannot beat China at centralization, and a classified rulebook administered by a security agency is centralization in near-pure form: concentrated authority, no exit, no franchise, no appeal—now with the added feature that the rules themselves are secret.
On July 14, Google DeepMind co-founder Demis Hassabis published a framework calling for a US-led Frontier AI Standards Body modeled explicitly on the Financial Industry Regulatory Authority (FINRA), Wall Street’s industry-funded self-regulator. Laboratories would submit models before release for testing on cyber, biological, and deception capabilities, with passage eventually a condition of US deployment. Days later, the White House was reported to be reviewing a proposal built on the same template.
The proposal is concrete and light years better than the improvised, case-by-case interventions of 2026. But it cannot deliver what it promises, for two reasons of design rather than character.
The first is precedent. In 2020, Facebook established its Oversight Board: a “Supreme Court” for content decisions, ultimately funded with more than $200 million. The most serious self-regulatory experiment any platform has attempted, it worked exactly as far as its architecture permitted and not one step further. In January 2025, Mark Zuckerberg abandoned fact-checking and rewrote the platform’s speech rules in a single stroke, without consulting or forewarning the board.
As I elaborate in Who Elected Big Tech?, the lesson is architectural: The company that creates its own overseer also decides what the overseer may review, and for how long. Accountability that the accountable party administers is oversight cosplay. That is not a flaw the Financial Industry Regulatory Authority model corrects; it is its design.
The second is more fundamental. The proposal tests models while conceding the architecture. A system could pass every deception and bioweapons evaluation and still be deployed into a stack that leaves the public with no exit, no portability, no attestation, and no voice.
Who creates and governs the system is more important than who operates it. The obvious choice might be universities. I once thought so too. But leading universities increasingly depend on frontier laboratories for computing power, research credits, and other resources. This creates a problem. If universities depend on companies to perform their duties, it could hinder their ability to make rules that might constrain the companies. That is not a conflict of interest but a conflict of position. In other words, universities cannot be independent governors of those companies.
The architecture should instead be founded and governed by civil society, with universities providing technical expertise. Public libraries are a natural choice, because they are already trusted locally governed institutions.
Each library could host its own AI steward (or Kami). The AI would be trained on the library’s collections and community’s records. Its role would be clearly defined and it would operate under rules set by a board, who would retire it when needed.
This builds on what libraries already do. The United States has roughly 9,000 public libraries and 17,000 outlets: Each one is locally governed but all of them already share catalogs and lend materials across systems without a company controlling the network. Libraries are also still considered trusted institutions, despite a fractured public. A similar model could extend to community foundations, union locals, tribal nations, congregations—institutions that already manage resources on behalf of communities..
A founding federation of 100 to 150 civil-society anchor institutions would cost nearly $1 to $1.5 billion over three years—an amount philanthropy could fund. Building the full federal architecture would cost $50 to $75 billion over five years.
To put those numbers in context, a single frontier laboratory has committed $250 billion dollars in future purchases from a single cloud provider. And hyperscalers are expected to spend an estimated $700 billion on new infrastructure this year.
The public investment, by comparison, would be very little. Spreading the full federal build over five years would amount to about 2 percent of what the industry now spends on infrastructure annually—two cents of public investment on every private dollar.
But what does it cost the public if these investments aren’t made? Should those systems be permanently governed by entities bearing no constitutional obligation to the people who depend on them, the cost won’t be measured in dollars but in liberty. [1]
The precedent is the one this publication was founded on. The architecture of restraint for weapons of mass consequence was built in the windows between catastrophes—Geneva in 1925, Pugwash from 1957, the Non-Proliferation Treaty—and, as the political scientist Jeffrey Legro demonstrated, the chemical-weapons taboo held because military organizations had internalized the prohibition. Declarations constrain behavior at the margins. Cultures determine it at the center.
Here the AI case diverges from the nuclear one. Nuclear restraint could form within a small priesthood of experts. Frontier AI capability touches very nearly everyone, so the habits that make restraint prevail—knowing what these systems are, what they should not do, and how to catch them when they fail—must be habits the public itself practices, or restraint becomes something done to people rather than something citizens share in defending. That is what an industry-convened standards body cannot supply and what a civic federation rooted in libraries, congregations, and town deliberations can.
A republic, if we can build it. In April, Anthropic declined to release its most capable model, offering it instead to some 50 vetted partners as an invitation-only preview. That may well have been the responsible course. The constitutional point lies elsewhere: a decision of that consequence was made by a single private firm, unilaterally, with no treaty mechanism, no public deliberation, and no accountability structure. The Trump administration’s eventual response was a review process as opaque as the decisions it reviews.
Americans can do better.
The existence proofs are running in Taipei and, closer to home, in one Bowling Green, Kentucky county. Warren County is a community of nearly 150,000 facing a projected doubling of its population. To decide what to do, leaders ran a month-long online project called “What Could BG Be?,” on the same open-source platform Taiwan uses. It asked residents a single open question: What should this place become over the next 25 years? Nearly 8,000 of them responded, proposing 4,000 ideas. Residents then reviewed and voted on these ideas. The project was yet another example of how a community can come together to evaluate ideas about their future.
People know how to begin. The political theory is in hand. What is missing is the constitutional awareness that a free people must specify the architecture it wants before corporations specify it for them.
[1] Author’s analysis; see Allison Stanger, “The Constitutional Cost of Frontier AI” (companion essay, 2026), for the full derivation and methodology. Available on request.
The Bulletin elevates expert voices above the noise. But as an independent nonprofit organization, our operations depend on the support of readers like you. Help us continue to deliver quality journalism that holds leaders accountable. Your support of our work at any level is important. In return, we promise our coverage will be understandable, influential, vigilant, solution-oriented, and fair-minded. Together we can make a difference.
Keywords: AI, AI arms race, Anthropic, China, Microsoft, NVIDIA, Taiwan, United States, artificial intelligence, constitution, frontier
Topics: Artificial Intelligence, Disruptive Technologies