The short version
For two centuries, free societies have argued about who may limit what people say. Almost nobody has had to argue about who may limit what people think, because thinking happened in places no one else controlled: a notebook, a blackboard, a personal computer. That era is ending, and we have not noticed.
Nearly half of American adults now use AI chatbots, and 38 percent of employed adults use them for work[1]. AI is becoming where people draft, research, reason and decide. Every one of these systems runs on guardrails: rules about what it will discuss, what it will help with, how it frames contested questions, and increasingly, what users themselves are allowed to do. Those rules are written by a few companies, shaped more and more by governments, and answerable to neither voters nor courts the way laws are.
Today this is tolerable for one reason: you can leave. You can switch models, run an open one on your own machine, or close the laptop and think unaided. The coming crisis is the day you can’t.
Let me be clear about where I stand, because this is not an argument against AI or against guardrails. AI is among the most beneficial technologies ever built; I build AI products and use AI every day. Stopping crime, fraud and catastrophic misuse is necessary. I also believe a society’s mental health matters as much as its physical health, and free societies are weak at protecting it: our information environment is saturated with disinformation and content engineered to exploit people. Some guardrails, on AI and on society, are not just acceptable but needed.
The question is who sets them, by what process, and what stops that process from being captured. Right now we are writing these rules the way the tech industry ships products: fast, expecting to fix them later. But policy does not patch like software. It hardens, and it gets repurposed by whoever holds power next.
The argument in six points:
- Guardrails have moved from governing speech to governing thought. Platform moderation controlled what you could publish. AI guardrails sit inside the process of thinking itself, and experiments show a model’s built-in leanings can shift users’ views without their noticing.
- Guardrails now bind users, not just models. Usage policies govern what people may do, enforced by cutting off access. The newest example: from November 12, Anthropic’s usage policy bars “sustained and needless” cruelty toward its models, a rule on user conduct justified by an unresolved question about machine moral status.
- Enforcement means exile without a hearing. Accounts are closed with no stated reason and no meaningful appeal, and users lose their work with them. Flags on what someone asked can be retained for years. Credit, banking and online platforms all eventually got due-process rules. AI has none, and if these records ever feed into other systems, the result starts to look like a social credit score for thought.
- Governments are already reaching in. A 2025 executive order makes “ideological neutrality,” as the government defines it, a condition of federal AI contracts. A 2026 order set up a government pre-release review of frontier models whose rules have not been published. The Pentagon blacklisted an American AI company after it refused to drop its restrictions on autonomous weapons and domestic surveillance. China already requires public models to pass a pre-release review built around political and content controls.
- The Constitution doesn’t reach any of it. A company’s guardrails are likely its own protected expression. Government pressure on companies is hard to challenge in court. And freedom of thought, one of the few rights international law treats as absolute, has almost no case law behind it.
- What keeps private rules legitimate is the ability to leave, and that is narrowing. Competitive necessity, licensing proposals and the first serious AI-enabled crisis could leave a small number of approved models as the only lawful way to think with a machine. And rules made in a hurry harden: whatever regime emerges will be inherited, and repurposed, by whoever holds power next.
The proposal: public obligations should grow as exit shrinks. While people can choose among providers and run open models, companies should keep the right to set their own guardrails, but owe users due process: a reason before a ban, an appeal, their work back, and records that expire. When government shapes guardrails, every request should be disclosed and reviewable, and every mandate should expire. If the law ever limits which models people may use, those models should carry common-carrier duties, including no restrictions on lawful inquiry and independent oversight. And these limits should be set by legislation after public debate, not by terms-of-service updates, executive orders or classified annexes.
The battle line is not left versus right, or companies versus governments. In the one real fight so far, a company and a government went to court over who controls a model’s guardrails. The people who use the model were not a party. The question this essay asks is the one nobody in that courtroom was asked to answer: who guards the guardrails, and what guardrails apply to them?
From governing speech to governing thought
The last great fight over private rules was about social media. Platforms decided what could be posted, amplified or removed, and a decade of argument followed about whether they had too much power. But those rules governed the distribution of speech. Whatever a platform allowed, you could still write anything you liked in your own notebook, on your own computer, in your own head.
AI guardrails govern something earlier: the production of thought. When a researcher explores a hypothesis with a model, when a student drafts an argument, when an analyst works through a contested question, the model is not a channel for finished ideas. It is part of how the ideas get made. Its rules shape which questions can be asked, which lines of reasoning get followed, and which framings appear first.
Those rules now operate at three distinct layers:
| Layer | What it governs | Who writes it | Example |
|---|---|---|---|
| Model guardrails | What the system will say, do or help with | The developer, through training and filters | Refusing certain topics or tasks |
| Defaults and framing | How contested questions are presented | The developer, often implicitly | Which side of an argument the model leans toward |
| User rules | What people are allowed to do with the system | The developer’s usage policy, sometimes shaped by law | Account termination for prohibited conduct |
The first layer is the one people argue about. The second may matter more. In a 2023 experiment with 1,506 participants, people who wrote with an AI assistant built to favor one side of a question were about twice as likely to argue that side, and their stated attitudes shifted afterward. Most did not notice the assistant was slanted[2]. That was one topic, one session, and a deliberately opinionated model. It still shows the mechanism: a tool’s leanings can quietly become the user’s.
The third layer is the newest. Usage policies have always forbidden things like fraud or harassment of other people. In October 2026, Anthropic added a rule that, from November 12, bars users from “sustained and needless abusive or cruel behavior” toward its models. The company says it applies only in extreme cases, not to ordinary frustration, pushback, dark fiction or research[3]. Reporting connects the rule to Anthropic’s 2025 model-welfare work, in which the company said it was uncertain whether its models have moral status but wanted low-cost precautions in case they do.
The rule itself is narrow, and reasonable people will disagree about it. Its form is what matters. It is a restriction on the user’s conduct, enforced by the provider, and justified by a premise (that the model might be harmed) that no user can verify or contest. Critics have already noted that the policy does not define abuse[4]. Whatever one thinks of this case, the precedent is clear: providers can govern how people behave inside the tools they think with, on grounds the provider alone decides.
Generative AI also makes its guardrails harder to see than any earlier kind of rule. A search engine that buries a result leaves the rest of the web in place, and a banned book leaves a gap on the shelf. A model that declines to pursue a line of reasoning, or quietly frames a question one way, leaves nothing to notice. The user sees only what was produced, never what was withheld or steered away from. Rules you cannot see are rules you cannot contest.
When a tool is optional, its rules are terms of service. When a tool becomes the place where a society does its thinking, its rules start to function as rules of thought.
Why private rules have been tolerable: exit
In 1970 the economist Albert Hirschman described two ways people respond when an organization fails them: exit, by leaving for an alternative, and voice, by pushing for change from inside. Governments, which people cannot easily leave, owe their citizens voice: elections, courts, due process. Companies mostly don’t, because their customers can exit.
That is the quiet bargain behind every AI usage policy. A company may set whatever rules it likes for its product, because no one is forced to use it. The law supports this. In Moody v. NetChoice (2024), the Supreme Court treated a platform’s content moderation as its own editorial judgment, protected by the First Amendment. Courts have not yet decided whether a model’s outputs are its developer’s speech. If they are, an AI developer’s guardrails enjoy the same protection: the developer has a constitutional right to its rules, and the user has no constitutional right to a model without them.
As long as exit is real, that arrangement is defensible, and today exit is real. There are several competing frontier developers with different policies. Open-weight models, whose parameters anyone can download and run, are legal and widely used. In August 2026, reporting on the White House’s new frontier-model review framework said it excluded open models from coverage[5]. And anyone can still think without a machine at all.
The trouble is that this bargain was designed for ordinary products. Lawrence Lessig argued in 1999 that software architecture regulates behavior the way law does, “code is law,” but without legislatures, courts or constitutional limits. For a word processor, that is a minor concern. For the main instrument a society uses to reason, it is a constitutional one. The bargain holds only as long as leaving remains possible in practice, not just in theory.
How exit closes
No one needs to plan a world where people can think only through approved machines. It can arrive by accretion, through three forces that are each reasonable on their own.
1. Competitive necessity. Exit is only real if staying out is survivable. Once AI-assisted work becomes the baseline in research, law, medicine, engineering and education, declining to use it stops being a choice and starts being a handicap. Adoption is moving fast: chatbot use among U.S. adults rose from 33 percent in August 2024 to 49 percent in February 2026, and about a quarter now use them daily[1]. An academic who refuses AI today is eccentric. In ten years, they may be uncompetitive. The blackboard remains legal, but it stops being a real alternative.
2. Gatekeeping at release. Governments are steadily building the machinery to decide which models reach the public, each step with a genuine security rationale:
- United States. A June 2, 2026 executive order directed a voluntary framework under which the government may take possession of a frontier model for up to 30 days before public release. The cyber-capability benchmarks and the coverage threshold are classified, and the framework itself has not been published[6, 5]. It is voluntary today. It is also a ready-made template for a mandatory regime.
- European Union. Since August 2025, the AI Act has imposed obligations on general-purpose models. Open-source models get some exemptions, but models above the systemic-risk threshold, presumed at 1025 training FLOP, get none, whether open or closed. Fines became enforceable in August 2026[7].
- China. The endpoint already exists. Since 2023, public-facing generative AI has had to reflect “core socialist values.” Models must pass a pre-deployment filing in which authorities get test accounts to probe them, and filings include keyword block lists and evaluation question sets. By August 2024, regulators reported 190 approved filings[8].
3. The crisis. Major restrictions on liberty are rarely passed in calm times. The USA PATRIOT Act became law 45 days after September 11. A serious AI-enabled cyberattack, or a biological near miss traced to an open model, could produce a licensing regime for capable models and restrictions on open weights within a single legislative session. Officials are already weighing whether open models should face the same pre-release review as closed ones, and reporting on that question remains unsettled[9]. This is a prediction, not a fact. But the tools for it are being built now, in classified annexes and voluntary frameworks, before anyone has argued about their limits.
Put the three together and the end state is plain: a small number of licensed models whose guardrails reflect both corporate policy and government requirements, operating as the only lawful and competitive way to think with a machine. No one would have chosen it. Everyone would live inside it.
Move fast and lock in
Silicon Valley’s old motto was to move fast and break things, then fix them later. That works for software, where a bad release can be rolled back next week. It does not work for policy. Rules made in a hurry harden: agencies are built to enforce them, budgets and careers come to depend on them, and companies design products around them. And once a tool of control exists, it gets used for purposes nobody voted for.
The clearest modern precedent is post-9/11 surveillance. Under Section 215 of the PATRIOT Act, the government collected Americans’ phone records in bulk for years, under a secret interpretation of the law. The program became public only in 2013, through leaked documents. In May 2015 a federal appeals court found it exceeded what the statute allowed, and in June Congress ended it with the USA FREEDOM Act. A power created for counterterrorism had quietly become something far broader, and it took more than a decade to unwind.
Two forces make AI guardrails especially prone to this.
Bootleggers and Baptists. The economist Bruce Yandle observed in 1983 that restrictive rules pass most easily when two very different groups want them: sincere moral advocates (the Baptists, who wanted Sunday liquor sales banned) and businesses that profit from the restriction (the bootleggers, who sold liquor on Sundays). AI has both. Many safety advocates are sincere. But licensing regimes also raise barriers to entry, and the companies that clear them first become the chosen few. Governments, for their part, gain leverage over the systems their citizens think with. When the moral case and the commercial and political interests all point the same way, nobody in the room is arguing for the user.
The successor problem. Every power built by one government is inherited by the next. In his dissent in Korematsu v. United States (1944), Justice Robert Jackson warned that a principle, once accepted, “lies about like a loaded weapon” for any authority that wants to use it. The right test for a guardrail regime is not what today’s officials intend. It is what the worst plausible future government, of either party, could do with it. A pre-release review built to screen for cyberweapons could screen for dissent. A ban record built to stop fraud could be used to stop organizers. The machinery does not know the difference; only law can.
That is why the safeguards proposed below have to be built in before the machinery is finished, not added after a crisis has shown what it can do.
Exile without a hearing
When a private guardrail is enforced, the penalty is rarely a fine. It is exile: the account is closed, and everything inside it goes too.
This is already happening in today’s open market. On OpenAI’s own community forum, users describe accounts deactivated with no warning and no stated violation. One Pro subscriber wrote in June 2026 that months of work, project context and accumulated memory vanished overnight, and that the appeal was passed to a review team with no timeline[10]. In January 2026, after a viral complaint about a Claude ban, Anthropic said its restrictions follow its terms and are part of standard security protocol, without describing any appeal process[11]. Individual cases are hard to judge from outside, and some bans are surely deserved. The structural problem is that the user is given no way to show which kind theirs was.
The record can also outlast the account. Anthropic’s privacy documentation says that when its automated systems flag a conversation for a possible policy violation, the inputs and outputs may be kept for up to two years, and trust-and-safety classification scores for up to seven[12]. There are sound reasons for this: abuse investigations take time, and repeat offenders exist. But it means a classifier’s judgment about what someone asked can persist as long as a bad debt on a credit report, without any of the protections a credit report carries.
Those protections exist because we have been here before. Every time a private service became essential to ordinary life, societies eventually demanded due process from it:
| Essential service | What happened | Protection that followed |
|---|---|---|
| Credit reports | Private files decided who could borrow, rent and work | The Fair Credit Reporting Act: notice when a report is used against you, the right to see and dispute your file, corrections usually within 30 days, and most negative items barred after seven years[13] |
| Bank accounts | Closures over political or reputational concerns | An August 2025 executive order requiring access decisions to rest on individualized, objective, risk-based analysis, and directing efforts to reinstate wrongly denied customers[14] |
| Online platforms (EU) | Opaque suspensions and removals | Digital Services Act Article 17: a clear, specific statement of reasons for any account suspension, including whether it was automated and how to seek redress[15] |
| AI assistants | Bans without stated reasons; work lost; flags retained for years | None specific. The DSA was written for hosting services, platforms and search engines, and whether it reaches AI assistants is unsettled[16] |
In a market with real alternatives, a ban without explanation is bad practice. In a world where exit has closed, it is something worse: removal from the main way a society works, learns and communicates, imposed without a reason, a hearing or an end date.
The danger compounds if these records begin to travel. China’s court blacklists show the mechanism. Since 2013, the Supreme People’s Court has published lists of people who failed to comply with court orders, and by 2017 the resulting penalties, including bans on buying plane and high-speed rail tickets, had been imposed more than seven million times. Human Rights Watch documented people listed without notice; one lawyer discovered he had been placed on a second list he was never told about, and a journalist who sued the court received no response[17]. The wider system is far more fragmented than its Western reputation suggests, and there is no single national score for individuals[18]. But it shows how a record in one system can quietly restrict access to many others.
Now imagine an automated flag on a prompt, which is an inference about what someone was thinking, joining a record like that. A ban based on what you asked becomes a penalty for what you thought. The UN’s 2021 report on freedom of thought names freedom from punishment for one’s thoughts, whether real or inferred, as a core part of the right[19]. That standard has not yet been applied to AI usage policies.
Credit law already accepts that people change and that old mistakes should stop following them. A record of what someone once asked a machine deserves at least as much forgiveness as a missed car payment.
The constitutional gap
The U.S. Constitution restrains governments, not companies. Under the state action doctrine, a private company’s rules raise no First Amendment question unless the government is effectively behind them. That design made sense when the institutions that shaped public thought were either clearly public or clearly private. AI guardrails increasingly sit in between.
The government can shape guardrails without writing them. In NRA v. Vullo (May 2024), a unanimous Supreme Court held that an official cannot coerce a private party into punishing or suppressing disfavored speech on the government’s behalf[20]. The principle goes back to Bantam Books v. Sullivan (1963). But proving coercion is hard. In Murthy v. Missouri (2024), the challenge to federal pressure on social media platforms was dismissed for lack of standing, without the Court ruling on whether the pressure was lawful. Informal influence over private rules is real, and largely unreviewable.
Procurement is the quieter lever. Executive Order 14319 (July 2025) requires federal agencies to buy only language models built on two “Unbiased AI Principles”: truth-seeking and “ideological neutrality,” with contracts allowing termination for noncompliance[21]. The order itself says the government should be hesitant to regulate models in the private market, and it applies only to federal purchases. But a developer that sells one model to both government and the public has every incentive to tune it once, to the standard its largest customer defines. Whoever holds power will define “neutral,” and the next administration will define it differently.
The first open fight over who controls guardrails is already in court. In early 2026, Anthropic refused to let the Pentagon use its models for autonomous weapons or surveillance of Americans. The administration ordered agencies to stop using its technology, and the Pentagon designated the company a “supply chain risk,” a label usually reserved for foreign adversaries[22]. The Pentagon’s position, which deserves a fair hearing, was that a vendor should not insert itself into the military chain of command or decide how the government lawfully uses tools it buys. In March, District Judge Rita Lin blocked the measures, calling them “classic First Amendment retaliation”[23], and in August she ruled them unconstitutional[24]. In September, the D.C. Circuit split 2–1 the other way on a separate designation, holding that the dispute concerned a contract term, not speech, and that the President and the Secretary of War, not courts, should weigh the risks[25].
The outcome is unsettled[26]. The structure is the point. A government tried to make a company remove its guardrails. The company argued its guardrails were protected expression. Courts disagreed about who should decide. No party to the case represented the people who will actually think with these systems.
Freedom of thought has no working doctrine. International law treats freedom of thought as absolute: under the International Covenant on Civil and Political Rights, it cannot be limited even in emergencies. Yet the UN Special Rapporteur on freedom of religion or belief reported in 2021 that its scope remains “largely underdeveloped and poorly understood,” and that courts have rarely addressed it directly[19]. The report identifies freedom from manipulation as part of the right and flags AI as a growing threat. U.S. law recognizes a right to receive information and ideas (Stanley v. Georgia, 1969), but nothing resembling a right to think with tools free of someone else’s undisclosed rules.
Even the record of thinking is weakly protected. People now tell AI systems things they would write nowhere else. Under the third-party doctrine, information people hand to a company has traditionally received weaker Fourth Amendment protection. Carpenter v. United States (2018) required a warrant for cell-phone location records, and some courts have required warrants for email contents, but the Supreme Court has not said how these rules apply to conversations with an AI.
The result is a new category of power: guardrails that are set privately, influenced publicly, protected as corporate speech, and reviewed by no one on behalf of the person on the other side of the screen.
The strongest objections
An argument like this deserves its best counterarguments. Here are eight, and where each one is right.
“Some guardrails are necessary.” True, and this essay does not argue otherwise. Models that can meaningfully help someone build a biological weapon or break into critical infrastructure should not do so for anyone who asks. Governments have a legitimate duty to manage catastrophic risk, and a world with no guardrails is not a free world; it is a dangerous one. The question is not whether guardrails exist but how they are made, disclosed, limited and reviewed.
“Companies have the right to set their own terms.” They do, and the Supreme Court has said as much. A developer should be free to build a cautious model, a permissive one, or one with a particular character. That right is exactly why exit matters. Corporate discretion is legitimate in a competitive market and becomes something else in a licensed one.
“The market is plural. This is alarmism.” Today, mostly true. Several developers compete, open-weight models are legal, and current U.S. policy has largely favored openness: the July 2025 AI Action Plan explicitly encourages open-source and open-weight AI[27]. This essay is about trajectory, not the present. But the time to set limits on a power is before it consolidates. After a crisis, the debate tends to be short.
“Democratic oversight of AI is the cure, not the disease.” Agreed, and this is the most important objection to get right. The problem is not that governments regulate AI. It is regulation without the safeguards we demand of every other exercise of state power: published rules, judicial review, limits on viewpoint control, and expiry. Classified benchmarks, unpublished frameworks and contract terms that define “neutrality” are not democratic oversight. They are oversight that has escaped democracy.
“A model refusing a request is not thought control.” Correct, as long as alternatives exist. A refusal is an inconvenience when you can go elsewhere and a wall when you cannot. And refusals are the least of it. The quieter influence is in defaults and framing, which shape what users conclude without their noticing.
“Search engines have shaped what people think for 25 years.” They have, and much of this critique applies to them. But a search engine ranks documents other people wrote. A buried result still exists and can be found another way. A generative model produces the reasoning itself, and what it declines to produce leaves no trace anywhere.
“Explaining bans helps bad actors.” Partly true. Fraud rings and state-backed hackers probe for the edges of enforcement, and a detailed reason can teach them what to avoid. That justifies delayed or limited explanations in genuine security cases, subject to audit. It does not justify the default of silence ordinary users get today. Banks and credit bureaus fight fraud while giving reasons and handling disputes at scale, and Europe already requires large platforms to do the same.
“Mandating any of this would itself violate the First Amendment.” This is the sharpest objection. If guardrails are a developer’s protected expression, a law dictating what a model must or must not say could be compelled speech. That is why the proposal below does not tell companies what their models may say while the market is open. It regulates process (reasons, appeals, data, records), as credit and banking law already do. Content obligations attach only when government itself closes exit, and at that point the rules are no longer purely private.
A healthy society and a free one
None of this means the answer is no guardrails. A society’s mental health is as real as its physical health, and free societies are poor at protecting it. Disinformation, manipulation and content engineered to exploit people move through the information environment much as pathogens move through a population. Unrestricted technology does not automatically produce a free society. Left alone, it can produce a sick one.
Authoritarian states have made a different choice, and some of their decisions have defenders even in the West. Since 2021, China has limited minors to one hour of online gaming on Fridays, weekends and holidays, enforced by identity checks[28]. Plenty of parents elsewhere would welcome something similar. But the same state requires AI models to reflect the ruling party’s values and maintains blacklists people cannot contest. It does not separate protecting a population’s health from controlling its thought. Holding that separation is the whole task for a free society.
The epidemiological framing cuts both ways. A vaccine policy anyone may opt out of can fail to reach herd immunity, and in an information environment, choice can look like a loophole: if anyone can use an unrestricted model, the protection leaks. But epidemiology also shows how free societies actually manage contagion, and it is not by controlling every individual:
- Herd immunity does not require 100 percent. Public health aims for enough resistance to stop spread, not perfect compliance. A free society can tolerate people using tools it disapproves of, as long as the resulting harms to others do not spread.
- Build immunity, not walls. Psychologists call it “prebunking,” and it works like a vaccine for manipulation. In a 2022 study by researchers from Cambridge, Bristol and Google’s Jigsaw, short videos explaining common manipulation techniques improved people’s ability to recognize them, including in a field test that reached about 5.4 million YouTube users[29]. It strengthens minds instead of restricting them.
- Treat the channels, not the minds. Public health cleans the water supply; it does not police what people drink at home. The equivalent here is regulating vectors: bot networks posing as humans, coordinated deceptive campaigns, engagement-maximizing design aimed at children. These rules target conduct that harms others, not thought. Anthropic’s October 2026 policy update, for example, added bans on astroturfing and bots posing as humans, which is exactly this kind of rule[3].
- Protect the vulnerable through law. Children are a legitimate special case. Australia’s ban on social media accounts for under-16s took effect in December 2025, with fines aimed at platforms rather than at children or parents[30]. Critics call it rushed, and whether it works is still disputed. But it was enacted by a parliament, in public, and it can be challenged in court. That is the difference that matters.
- Use compulsion last, and only under law. Free societies do sometimes compel. In Jacobson v. Massachusetts (1905), the Supreme Court upheld compulsory smallpox vaccination while warning that such powers must not be exercised arbitrarily or oppressively. That is the template: legislated, evidence-based, proportionate, time-limited and reviewable by courts.
The goal is a society that is both healthy and free. That requires guardrails, and it requires guardrails on the guardrails.
A proposal: guardrails on guardrails
A free society does not answer this by banning guardrails, or by trusting whoever writes them. It answers the way it has handled every other concentration of power: by tying obligations to the amount of power held. The core proposal is simple. Public obligations should grow as exit shrinks.
The idea has deep roots. In Marsh v. Alabama (1946), the Supreme Court held that a company town, privately owned but functioning as a town, could not suppress speech on its streets. When a private owner takes over a public function and residents have nowhere else to go, constitutional duties follow. Current doctrine reads that principle narrowly (Manhattan Community Access Corp. v. Halleck, 2019, limited it to functions traditionally and exclusively performed by government), so this is a proposal for legislation, not a claim about what courts would do today. But the logic is the right one.
| Condition | Who effectively sets the guardrails | Obligations that should attach |
|---|---|---|
| Open market: many providers, lawful open models | Each company, as its own expression | Procedural duties like those in credit and banking: published rules, reasons, appeal, data export, record expiry, no record sharing |
| Government shapes guardrails through procurement, pressure or pre-release review | Company and state together | All of the above, plus disclosure of every government request, no government viewpoint-setting, judicial review and sunset dates |
| Law restricts which models people may use, through licensing or open-weight bans | Effectively the state | All of the above, plus common-carrier duties: no restrictions on lawful inquiry, independent oversight, and a protected path to lawful alternatives |
How a free society should decide
The process matters as much as the rules. Today, AI guardrails are set through terms-of-service updates, executive orders, contract clauses and classified annexes. None of these is how a free society should decide the limits of thought. A legitimate process has four parts:
- Legislation after public debate. Congress passed the Fair Credit Reporting Act in 1970, and the EU’s due-process rules for platforms came through legislation. Rules about how people may think with machines deserve at least that much democratic deliberation.
- Independent oversight. An existing regulator or a new ombudsman with the power to audit enforcement, hear complaints and publish findings, insulated from both the companies and the administration of the day.
- Transparency by default. Regular public reports from every major provider: accounts restricted and why, appeals filed, decisions reversed, and every government request to add, remove or change a guardrail.
- Courts as the backstop. Any government role in a guardrail should be reviewable by a judge, on the record.
The pieces already exist across party lines. The nonbinding 2022 Blueprint for an AI Bill of Rights called for notice and explanation, and for human alternatives and fallback, when automated systems affect people. The 2025 debanking order applied similar logic to banks. What is missing is a statute that applies them to the systems people now think with.
Ten principles, sorted by who they bind
Every provider, starting now
- Publish the rules. Users should be able to read what a model will not do and why. No secret guardrails.
- Due process before exile. Outside genuine emergencies, such as an attack in progress, no one should lose access without a specific reason: the rule broken, the conduct at issue, and whether the decision was automated. They should be able to respond, and to appeal within a set time to a person with the authority to reverse the decision.
- Your work stays yours. Losing access must not mean losing your work. Users should be able to export their conversations, files and memory, including during a grace period after a ban. A provider may close a door; it should not confiscate what was built behind it.
- Records expire and can be repaired. Flags, scores and ban histories should be visible to the person they describe, open to dispute, corrected when wrong, and deleted after a fixed period, as credit law already requires. A classifier’s guess about what someone meant should not follow them for seven years.
- No fusion of records. A provider’s judgment about a user should not be shared with employers, lenders, other providers or governments, or combined with other scores, except under specific legal process. This is the line between a terms-of-service decision and a social credit system.
- Restrict actions, not inquiry. Guardrails should target concrete capabilities and harmful conduct, such as weapons synthesis routes or attacks on systems, not topics, questions or lines of reasoning. A free society must be able to think about everything, including what it fears. In an open market this is a norm providers should adopt; for any licensed or mandated model it should be a legal duty.
Every government
- Disclose every request. When a government asks or requires a provider to add, remove or change a guardrail, that request should be public and reviewable, so state influence cannot hide behind a corporate policy.
- Keep the state out of viewpoints. Governments may buy what they like for their own use. They should not use licensing, procurement or informal pressure to set the viewpoints of models sold to the public. NRA v. Vullo already forbids coercing intermediaries to suppress speech; that principle should be extended explicitly to AI.
- Sunset every mandate, and keep exit open. Any government-imposed guardrail should expire unless renewed on evidence, and should state in advance the conditions under which it would be lifted. Lawful alternatives, including open-weight and locally run models, should remain available, with oversight proportionate to demonstrated risk rather than blanket bans. No law should ever require citizens to think through a single approved system.
- Recognize cognitive liberty in law. Freedom of thought should extend to the tools of thought. That means requiring a warrant for the contents of AI conversations, and treating undisclosed manipulation by a model as a violation, not a feature.
None of these principles requires weakening safety. Each one requires that safety be pursued in the open, within limits, and subject to challenge. That is what separates a guardrail from a cage.
The battle line
This is not a left-versus-right issue. The examples in this essay come from a Democratic administration’s pressure on social media platforms, a conservative executive order on AI “neutrality,” a national-security fight between a Republican administration and an AI lab, a European regulatory regime, and a one-party state. Each side worries about the other side controlling the guardrails. Both are right to.
It is not a companies-versus-government issue either. Companies want the right to set guardrails as their own expression. Governments want the right to override or direct them. Both claims have merit, and both leave out the same party.
The real line runs between institutions and the individual mind. On one side is the growing power, public and private, to shape what people can ask, explore and conclude while they think. On the other is the idea, older than any constitution, that a person’s thoughts are their own. For most of history, that idea needed little legal protection, because no one could reach inside the process of thinking. Now the process runs through infrastructure that someone else owns, governs and can be pressured to change.
Every proposal for AI governance, from any company or any government, should have to answer seven questions:
- Who writes the rule?
- Who can read it?
- Who can appeal it?
- When does it expire?
- What happens to my work, and my record, if I’m cut off?
- Can I go somewhere else?
- What would the worst future government do with it?
If the answers are “no one you elected,” “no one,” “no one,” “never,” “you lose both,” “no” and “whatever it likes,” then it doesn’t matter how good the intentions behind the rule are. That is not a guardrail on a machine. It is a guardrail on a mind.
We spent two centuries building protections around government power over speech. We may have only a few years to decide whether those protections reach the machines we now think with. The battle lines are not drawn yet. They should be, before a crisis draws them for us.
References
[1] Pew Research Center, “Americans and AI” (June 2026; survey Feb. 17–23, 2026)
[3] MacRumors, “Anthropic Says Users Can’t Be Needlessly Cruel to Claude” (Oct. 8, 2026)
[4] Gizmodo, on Anthropic’s usage-policy rule against cruelty toward its models (Oct. 2026)
[5] Axios, “Scoop: Inside Trump’s AI framework” (Aug. 4, 2026)
[6] Let’s Data Science, “White House finalized AI safety framework, contents secret” (Aug. 2026)
[7] European Commission, FAQ: Guidelines on obligations for general-purpose AI providers
[8] ChinaTalk, “SB 1047 with Socialist Characteristics: China’s Algorithm Registry in the LLM Era”
[9] Brett Pollak, AI Intelligence Briefing (Aug. 22, 2026), summarizing reporting on open-weight review
[11] Daily Security Review, “Anthropic Responds to Viral Allegations of Account Bans” (Jan. 12, 2026)
[12] Anthropic Privacy Center, “How long do you store my data?”
[13] A Summary of Your Rights Under the Fair Credit Reporting Act
[14] Mayer Brown, “President Trump Signs Debanking Executive Order” (Aug. 2025)
[15] Digital Services Act, Article 17: Statement of reasons
[17] Human Rights Watch, “China’s Chilling ‘Social Credit’ Blacklist” (Dec. 12, 2017)
[18] MERICS, “China’s social credit score – untangling myth from reality” (Feb. 11, 2022)
[20] Faegre Drinker, “Supreme Court Decides NRA v. Vullo” (May 2024)
[22] Axios, “Anthropic sues Pentagon over rare ‘supply chain risk’ label” (Mar. 9, 2026)
[23] WUNC/NPR, “Judge temporarily blocks Trump administration’s Anthropic ban” (Mar. 26, 2026)
[24] The Defense Post, “Judge Blocks Trump Administration’s Anthropic Ban on Military AI” (Aug. 28, 2026)
[26] Washington Examiner, Pentagon confirms Anthropic remains a supply chain risk (Sept. 3, 2026)
[27] Holland & Knight, “America’s AI Action Plan: What’s In, What’s Out, What’s Next” (July 25, 2025)
[28] Sixth Tone, “China Limits Minors to Gaming at Most 3 Hours a Week” (Aug. 30, 2021)
[30] Al Jazeera, “Australia’s social media ban for young people takes effect” (Dec. 9, 2025)
Also cited from the standard record: Albert O. Hirschman, Exit, Voice, and Loyalty (1970); Bruce Yandle, “Bootleggers and Baptists: The Education of a Regulatory Economist,” Regulation (1983); Lawrence Lessig, Code and Other Laws of Cyberspace (1999); Jacobson v. Massachusetts (1905); Korematsu v. United States (1944), Jackson, J., dissenting; Marsh v. Alabama (1946); Bantam Books v. Sullivan (1963); Stanley v. Georgia (1969); Carpenter v. United States (2018); Manhattan Community Access Corp. v. Halleck (2019); Murthy v. Missouri (2024); Moody v. NetChoice (2024); ACLU v. Clapper (2d Cir. 2015); USA PATRIOT Act (Oct. 26, 2001); USA FREEDOM Act (June 2, 2015); White House OSTP, Blueprint for an AI Bill of Rights (Oct. 2022).