Every powerful technology eventually hits the same wall, and it’s rarely a technical one. The question is never can we build it. It’s who gets to say how it’s used. Gunpowder, nuclear energy, the internet, social media — each one was a battle over control that was fought after the invention, not before.
AI is arriving at that battle faster than any technology in history. A technology this general — one that writes, decides, predicts, and increasingly acts — isn’t being held by any single institution. Four players are pulling on it, and they all have legitimate claims, incompatible interests, and very different amounts of actual power. This piece is a map of that fight: what each side holds, what each side wants, what each side would lose, and where the public actually stands.
The four players in the arena
- The AI companies — a handful of firms that build the most capable systems.
- Governments — elected authorities trying to balance national competitiveness against public protection.
- Users — the billions of people whose data, attention, and trust the whole system runs on.
- Independent oversight — researchers, standards bodies, auditors, and civil society groups with expertise but no formal power.
The conventional way to talk about this is to argue for one of them. The more useful way is to look at what each side actually holds — because the answer to “who controls AI” is mostly revealed by the assets, not the arguments.
The companies: speed as a weapon
The AI companies sit on the one thing every other player needs: the systems themselves. They hold the compute, the trained models, the engineering talent, and — perhaps most importantly — the tempo. They can ship a capability in months that would take regulators years to even understand. That tempo is their strategic depth. When the world was still debating whether AI could do a thing, the companies had already done it, deployed it, and moved on.
Their public position is well known: safety is real, and they take it seriously, and the best regulator is a responsible developer. There’s some genuine truth in that — they have internal safety teams and published frameworks. But self-regulation has a structural ceiling. The company that ships first captures the market, and the incentives pull against caution at the exact moment caution matters most. Every firm insists it can be trusted to regulate itself, and every firm is a competitor in a race where the slowest careful player loses.
| What they hold | What they want | What they’d lose |
|---|---|---|
| The models, the compute, the data, the talent | Light-touch rules, freedom to ship, global scale | Competitive edge if rules bind them more than rivals |
| Deployment speed and default settings | To be the technical voice regulators consult | Mandatory transparency into how their systems work |
| Most of the actual AI in people’s lives | Public trust, without public constraints | The goodwill they still have with users |
The governments: authority without tempo
Governments hold the legal power — the only power in this whole fight that can actually stop something. They can tax, ban, mandate, investigate, and prosecute. They control access to markets and to compute infrastructure through export rules and energy policy. That is real authority.
Their problem is the opposite of the companies’: they have tempo too slowly. Lawmaking runs at the speed of committee hearings, while the technology runs at the speed of a training run. By the time a rule is drafted and passed, the capability it was written for has changed. There’s also the uncomfortable split personality inside every government: the same body that’s supposed to regulate AI is also desperate to win with it, because national competitiveness in AI is now a strategic objective. The regulator and the booster are the same institution, and they want different things.
On top of that, the public isn’t exactly cheering for them. The most recent survey data makes this striking: in the United States, only about three in ten people trust their own government to regulate AI responsibly — the lowest figure of any country in the survey, against a global average above half. A plurality of Americans say federal AI regulation won’t go far enough, rather than too far. And when people in 25 countries were asked which institution they’d trust to do it well, a majority median picked the EU — ahead of both the US and China.
| What they hold | What they want | What they’d lose |
|---|---|---|
| The legal power to stop things | National competitiveness and public safety | AI talent, investment, and companies to friendlier jurisdictions |
| Control of markets, exports, and infrastructure | A stable, rule-governed industry | The race itself, if rivals move faster |
| Procurement and public-sector adoption | To look capable in front of voters | Public trust, which polling shows is already thin |
The users: power they don’t know they hold
The users are the reason any of this exists, and they are the weakest player by every structural measure. Their power is real but diffuse: they supply the data, the adoption, the revenue, and the training signal. When they collectively move, markets move. In the abstract, they are the only actor whose withdrawal would be fatal to the entire enterprise.
In practice, they almost never move together. The paradox of the whole series applies here with full force: people are worried, and they keep using the tools, one prompt at a time. No individual user has the information to know what they’re consenting to, the leverage to negotiate terms, or the recourse when something goes wrong. The user’s “power” is a veto they could theoretically cast and almost never cast.
| What they hold | What they want | What they’d lose |
|---|---|---|
| Their data, attention, adoption, and money | Protection, transparency, and a way to appeal decisions | Their time, their privacy, their ability to contest outcomes |
| The legitimacy of the whole enterprise | To not be the product | The usefulness of the tools, if they left |
| Exit — in theory | Accountability when the system fails | Their leverage, permanently, once dependence deepens |
Independent oversight: knowledge without teeth
The fourth player has the least formal power and often the most credibility: researchers, standards bodies, auditors, and civil society. They are the only actor whose interest is structurally aligned with the public’s — nobody pays them to make AI faster or cheaper. The UK-coordinated International AI Safety Report, which pulls together evidence from researchers across countries, is a working example of what this looks like when it functions.
Their ceiling is enforcement. An oversight body can measure, warn, and shame, but it cannot fine, block, or stop. Its recommendations land as politely phrased PDFs unless a government picks them up and gives them legal force. And there’s a subtler failure mode: the people with the deepest expertise are the people most likely to get absorbed into the industry they’re meant to check, or to be dismissed as naive when they push for constraints. Knowledge without a mandate is expertise, but it isn’t control.
| What they hold | What they want | What they’d lose |
|---|---|---|
| Expertise, credibility, and independence | Verifiable access to systems and data | Relevance, if nobody gives their findings force |
| The trust of the public, in relative terms | Standards that are actually enforced | Their independence, through capture or co-option |
| The clearest picture of what’s really happening | A seat at the table where decisions are made | Their reputation, if warnings turn out to be noise |
Who actually controls what, today
Put the four maps side by side and the distribution of power stops being mysterious:
| The companies | Governments | Users | Oversight | |
|---|---|---|---|---|
| Today’s real control | High — they set what gets built and shipped | Medium — legal power, rarely used at pace | Low — diffuse, unorganized, barely exercised | Low — expertise with no mandate |
| What they’d need to win | Nothing; the default is theirs | Speed and political will | Organization and information | Enforcement and access |
| Biggest vulnerability | Public backlash and the loss of trust | Falling behind while deliberating | No recourse when harmed | Irrelevance |
The honest summary: right now, the default controller is the companies, not because they’ve won a legitimate contest, but because control defaults to whoever ships, and everyone else is still assembling their counter-move.
What the public actually wants
The data on public preferences is remarkably consistent, and it contradicts the story you often hear about “innovation vs. safety” being a genuine dilemma.
A nationally representative RAND survey of 2,000 American adults found very strong support for monitoring and oversight of the most powerful AI systems. When people were asked which structure they’d trust to manage it, the most preferred options were multinational partnerships and public-private partnerships — explicitly not sole corporate self-regulation, and not even sole national control. This is notable because the same respondents rated US dominance in AI as important. People want their country to win the race and want outside, multi-party oversight of the technology — the two aren’t in tension in their minds.
That pattern holds internationally. Support for regulation is broad, concern about too little regulation outweighs concern about too much in the United States, and the institution people trust most across 25 countries is a regional body (the EU) rather than any single national government. There’s a clear public verdict here, and it’s easy to state: most people want strong, multi-party, safety-first governance — and the actor they trust least to deliver it is the industry’s own self-regulation.
The three models on the table
Those preferences map onto three real governance models, and each has a known shape.
Self-regulation. Fastest, cheapest, most responsive to the technology — and it’s the model with the least public trust. Its fatal flaw isn’t the companies’ intentions; it’s their incentives. The external costs of AI failures don’t hit the balance sheet in time to change behavior.
State-led regulation. The EU AI Act is the most complete example — a comprehensive framework, in force since 2024, being phased in through the decade, with rules tied to risk levels. Its weakness is the one all national approaches share: AI is global, and the most capable systems are built by companies operating across borders. A law in Brussels or Washington can’t fully contain a technology trained and deployed worldwide.
International coordination. Agreements, standards bodies, and reports that try to build shared rules — the kind of structure the public keeps saying it prefers. Its weakness is enforcement: without a mechanism that costs non-cooperating states or firms something real, it stays a forum.
The evidence suggests the public’s instinct is the right shape — a hybrid, with multinational coordination as the frame, binding law as the floor, and real oversight institutions that can actually inspect the systems. The gap between that and today’s reality isn’t a gap of ideas. It’s a gap of mandate and speed.
The hinge: human oversight
One theme runs through every governance debate, and it’s the one the earlier articles in this series kept arriving at: whatever the structure, the actual protective mechanism is human oversight. Not the ceremonial kind — the meaningful kind: a person who can see what the system did, ask why, and reverse it.
That requires two things no model has fully delivered. Transparency — access to what models do and how they’re evaluated, at a level independent researchers can actually verify, not just marketing summaries. And accountability — a clear answer to “who is responsible when this fails,” which today is often answered with a shrug because the chain runs from a model to a team to a company to a set of terms you clicked. The governance question, at its core, is whether these two can be made real before the stakes grow further. The financial sector is the canary here — AI agents are already embedded in decisions that move money, and the rules for who’s responsible when an automated system causes harm are still being invented after the fact.
Six questions for judging any governance proposal
Since this piece is a map rather than a manifesto, it’s worth ending with a practical filter. Any serious AI governance proposal — from a company, a government, or an international body — should be able to answer these six things:
- Access. Can independent, qualified people actually inspect the system, or only receive the company’s own reports?
- Recourse. If a system harms someone, is there a real path to contest, appeal, or be compensated?
- Speed. Can the rule actually move faster than the technology it governs? If not, what trips the emergency brakes?
- Bite. What does the enforcement mechanism cost a violator, in terms they’ll actually feel?
- Coverage. Does it bind every player in the market, or just the ones willing to sign on?
- Legitimacy. Did the people affected have any voice in shaping it?
A proposal that fails these isn’t necessarily bad faith — it may just be premature. But the questions show the shape of the endgame. The technology is already making decisions that affect real people, with voice cloning and deepfakes rewriting what consent even means, and the institutions meant to govern all of it are still deciding who gets a seat at the table.
The four players aren’t going anywhere, and none of them can control AI alone — the companies can’t be trusted with unshared power, governments can’t keep pace alone, users can’t organize at the required scale, and oversight can’t enforce without a mandate. The battle isn’t about eliminating any of them. It’s about designing a system where their interests check each other, and where the people the technology affects are represented by something that can actually stop.
Independent technology writer focused on artificial intelligence, emerging technologies, and digital innovation. Covers AI applications in sports, productivity, and online business.









































