The unknown and hidden costs from AI legislation that nobody talks about
Alfredo González Briseño
8/12/202614 min read


An historic and landmark AI legislation. The most stringent in the nation. Those were some of the adjectives and words describing the approval of the "Artificial Intelligence Safety Measures Act" from Illinois. The Midwest state joins California and New York in a small group of subnational governments in the US that have created regulations to protect people from frontier AI models. The guardrails target potential catastrophic risks from these models. Despite its good intentions, this piece of legislation creates—as many others do—hidden and unknown costs on both AI firms and the government itself. Let's analyze and talk about how this happens and why it matters.
State governments creating balance to AI regulation in the US
It is interesting from many angles what Illinois did with its new AI safety law. For starters, it is a step in the opposite direction from what the federal government has been preaching in the past few years—removing as many regulatory barriers to innovation and AI as possible.
I will dive into the details of this piece of legislation soon, but at first instance it is worth acknowledging what is happening in Illinois and other states, because their contributions are balancing the AI regulatory equation in the US, by creating regulations that protect people from AI's development and use.
Then, in the medium- to long-term there are questions about how this opposite dynamics will play. They are natural in a federal system with different mandates, checks and balances. Yet, if you see the US as a single boat and not as 50 isolated boats, you can view that opposite and uncoordinated policy efforts can lead to greater problems that surpass the benefits each side pretends to create.
This second point is a separate topic that requires its own analysis, namely, how to create the conditions for coordinated AI governance and regulatory efforts, so policy results have higher probabilities of success. This analysis becomes more relevant in federal systems like the US, as opposed to other political systems where there is a larger central control and orchestration of policies, like in China, or even in federal systems that only exist on paper, like in Mexico.
Framework to analyze the AI safety law from Illinois
It is important to be clear that despite its good intentions, any piece of legislation creates costs. Costs created by regulations are not a problem per se. Some of them are justified to achieve important objectives, such as protecting people, consumers and the environment.
However, regulations often create costs that are not entirely necessary and that do not contribute to the policy objective they are trying to achieve. When you look at the case of Illinois's AI Safety Act—and many other AI laws and regulations in the world—, the difficult-to-achieve goal is balancing people's safety and still have a good business environment that creates jobs, economic growth and shared wealth.
The unexpected, unknown and hidden costs from regulations are more likely to appear when AI regulation or any type or government-made rule is created based on perceptions, quick reactions, fear, ideology or without a serious effort to ground decisions on a clearly identified policy problem.
In a previous article, I used the Better Regulation Test framework to analyze the export control directive that the federal government imposed on Anthropic and its latest models. That analysis looked at some of the available elements related to that regulatory decision. You can read about it here.
In this case, I am going to run a different type analysis, not entirely looking at "how" the regulatory decision was made. Instead, I will use the actual approved text of the "Artificial Intelligence Safety Measures Act" from Illinois as the main reference or unit of analysis.
When looking at the legal text of this AI regulation, I will be using what I call the "Regulatory Quality Review" framework. In this case, I will use these 5 pillars from a broader set of lenses to analyze regulatory texts:
Clear policy problem or objective.
Use of simple language.
Number of requirements.
Restrictiveness on the business environment.
Implementing institutions and obligations.
Regulatory Quality Review of the Artificial Intelligence Safety Measures Act from Illinois
The analysis started with me reading and taking a first look at the 50+ pages of the Act. After a set of first impressions, I asked Gemini Notebook for help to validate or refute them and to run specific analysis. In the text below, I will distinguish in color blue the answers I got from Gemini.
For starters, if you want to read the actual legal text approved, you can find it in this link. This is the document I used to make my analysis. Let's get started with the first pillar of the Regulatory Quality Review.
1. Clear policy problem or objective.
In my book, talks and analysis, I have said that every regulatory decision should start from a clearly identified policy problem or objective. This is not an academic idea. It is based on what happens in many countries, where regulations fail because they are created from reactions, ideology, poor judgement, lack of information, politics or even good intentions—and not real problems.
The policy problem or objective should be clearly outlined in the first articles of a law or regulation. Sometimes, the rationale is explained in the preamble, when there is one. This is not a rare practice.
In the case of the AI safety Act from Illinois, you can read and read and never find a clearly outlined purpose, objective or problem that this piece of legislation is aiming for. To doublecheck things, I asked Gemini to go over the document. This is part of the response I got (text in blue):
"The Act does not include an explicit statement of purpose, legislative findings, or a preamble that clearly outlines the specific problem it is trying to solve. After providing the short title, the text jumps directly into defining terms and outlining regulatory requirements.
However, the policy objective and the problem it aims to solve can be clearly inferred from its definitions and the strict frameworks it mandates. The implicit goal of the legislation is to prevent and mitigate "catastrophic risks" associated with the development and deployment of advanced artificial intelligence, which the Act refers to as "frontier models".
The specific problem the Act is trying to solve is the potential for these powerful AI models to cause mass casualties or massive financial devastation.
Gemini was able to infer and then state a clear objective or purpose of this AI legislation. This is something similar to what you can do, and was also part of the public declarations at the time the Act was announced.
However, as valid and important as these inferred purpose is, from a regulatory practice perspective there are two issues. First, the objective should be explicit in the text of the Act and not something to be inferred or guessed by the public and those affected—even with the help of AI. Then, the actual problem the AI Act from Illinois is trying to address is not clearly identified. On this Gemini's views are:
The specific problem the Act is trying to solve is the potential for these powerful AI models to cause mass casualties or massive financial devastation. The Act defines a "catastrophic risk" as a foreseeable incident involving a frontier model that materially contributes to:
The death of, or serious injury to, more than 50 people.
More than $1,000,000,000 in damage to, or loss of, property.
Furthermore, the Act anticipates specific dangerous scenarios that it wants to prevent, including frontier models doing any of the following:
Providing expert-level assistance in creating or releasing chemical, biological, radiological, or nuclear weapons.
Engaging in conduct without meaningful human oversight that results in a cyberattack or would constitute crimes like murder, assault, extortion, or theft if committed by a human.
Evading the control of its developer or user.
It is great that AI can tell us this. However, for the layperson or even firms affected, this is just a good interpretation by AI and not necessarily reflecting what rule-makers had in mind.
To be explicit and clear about the objective and problems behind the creation of an AI law or regulation is not a pure communications requirement, advice or suggestion. Rather, it is a reflection of the previous work done to understand "real" or likely potential problems, before or while drafting the regulation in question. This process involves evidence and dialogue. When this exercise is well done, it is reflected in the text of the rule.
I give the benefit of the doubt that there were adequate debates and policy analysis leading to the Artificial Intelligence Safety Measures Act from Illinois. In countries with better regulatory practices, it is more likely that this happens. Nonetheless, the text of the Act does not reflect explicitly this previous work that the public and firms affected by the Act should know. Why? Because laws need to be accessible for others to understand it—which takes me to the second pillar of analysis.
2. Use of simple language
Perhaps the reason is that I am an engineer, or maybe it is my experience when reading laws and regulations from Mexico, my home country—where writing is far from straightforward and clear.
Nonetheless, I have a firm believe that:
Government-made rules have to be accessible to everyone, no matter what their background and level of education is—laws and regulations are a public good; and
People should not have to break the bank to pay for legal experts when dealing with government rules, just because they are complex and not easy to understand.
Using these lenses, I asked Gemini whether the AI Safety Act from Illinois was written in simple language, so the public and those affected or needing to comply with this law were capable to sort out what the text says and what they need to do. This is part of Gemini's response:
The Act is not written in simple, everyday language. Instead, it relies heavily on dense legal jargon and highly advanced technical terminology.
For the average citizen, sorting out exactly what the text says would be quite difficult due to several factors:
Technical Complexity: To even determine what AI models are regulated by the Act, a reader must understand advanced computer science metrics. For example, the Act defines a regulated "frontier model" as one that was trained using "a quantity of computing power greater than 1026 integer or floating-point operations".
Dense Legal Structure: The text uses complex, nested clauses and convoluted definitions standard in legislative writing. For instance, an "Affiliate" is defined in a very roundabout way as "a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries".
Cross-References to Other Laws: Fully understanding the Act requires referencing outside statutes, as it heavily amends or cites laws like the Digital Voice and Likeness Protection Act, the Freedom of Information Act, and the Whistleblower Act.
Gemini also mentioned that big tech companies targeted by this laws should have the necessary resources to understand and comply with requirements. This may be true, but it defeats the idea of making laws and regulations accessible to everyone. In addition, it does not consider that paying for the salaries of a big legal teams or the fees of external advisors will not be the only costs created by the Act—which takes me to the third pillar of analysis.
3. Number of requirements
The first time I read the Act, I realized this piece of legislation had lots of "shall" and "shall not." From a legal writing perspective, this may not a problem. From a policy perspective, each article and paragraph with these words—or similar—is an obligation, prohibition or other type of requirement that demands compliance from affected firms or individuals. Compliance requires putting energy and resources into these requirements, which creates compliance costs.
As mentioned before, costs created by regulations are not an issue per se. Sometimes, those costs are required to achieve desirable goals, such as to "prevent and mitigate 'catastrophic risks' associated with the development and deployment of advanced artificial intelligence."
However, it is easy to write legal requirements, and it is not very easy to calculate the costs to comply with them. Although, this should not call for an academic exercise, rule-makers need to reflect and try get clarity on whether those compliance costs from their rules are justifiable compared to the benefits the Act or other AI regulations try to achieve.
To have a better idea about the requirements from the Artificial Intelligence Safety Measures Act from Illinois, I asked Gemini to count them by looking at words like "shall", "must" or "have to." His is the response I got:
Here is the exact breakdown of how many times these obligation-heavy words appear in the main regulatory text of the Artificial Intelligence Safety Measures Act:
"Shall": Appears 61 times. This is the primary vehicle the Act uses to force companies to take action.
"Required": Appears 17 times.
"Shall not": Appears 10 times. This is the specific phrase used to restrict business behavior and prohibit certain actions.
To give you a better sense of how these counts translate into actual business mandates, here are a few examples of how these words are applied to the targeted AI developers:
Examples of Obligations ("Shall" / "Required"):
Creating Frameworks: A large frontier developer "shall write, implement, comply with, and clearly and conspicuously publish on its website a frontier AI framework".
Reporting: A developer "shall report any critical safety incident... within 72 hours".
Transparency: Developers must publish a transparency report, and summaries of risk assessments are "required" to be provided in a machine-readable format.
Fees and Disclosures: Developers cannot operate in Illinois without filing a disclosure statement and paying the "required fee".
The high frequency of these words confirms that the Act is not merely a set of suggestions or guidelines; it is a highly mandatory, compliance-heavy framework packed with dozens of specific legal duties and restrictions.
Of course, some of these requirements will not require a huge effort. Others will. When we are talking about 70+ obligations or prohibitions in the AI Safety Act, things start to add up. If you look at the broader picture of a country's regulatory environment, this is a single piece of legislation creating more than 70 requirements. While in this case small or medium-size firms were not affected, when they are, the compliance costs on them are much higher in proportion to their revenue and available resource.
That is why a balance is needed when drafting rules, so to protect what needs to be protected, while preserving a good business environment—which takes me to the fourth pillar of analysis.
4. Restrictiveness on the business environment
During my work in Malaysia with the World Bank, I learned the phrase "no more regulation than necessary." This was from their task force PEMUDAH, a group with leaders from the public and private sector which aims to improve the country's business environment.
Analyzing whether a regulation is restrictive or not on the business environment requires a deeper analysis and more data. Even then, results and conclusions may be subjective. Because what some economies or international organizations perceive as a good environment for the private sector may not be the same for other countries.
Nonetheless, I asked Gemini for its views having the legal text of the Act as the only reference. This is part of the response I got:
You are absolutely right that determining whether the Act is "too restrictive" is a subjective question that requires looking beyond the statutory text to understand its real-world economic and industry impact.
However, based purely on the text of the Act, we can see that lawmakers did attempt to build in specific provisions to limit the regulatory burden on the broader business environment:
Targeting Only Tech Giants, Not Startups.
Preventing Duplicative Costs.
Protecting Intellectual Property.
On the other hand, for the massive companies that do meet the threshold, the restrictions are intensely strict. For example, forcing a corporation to investigate and report a critical safety incident within 24 to 72 hours is a highly aggressive timeline, and the financial penalties for failing to comply are severe—reaching up to $1,000,000 for a first violation and $3,000,000 for subsequent ones.
The quality of a country's business environment goes beyond an analysis focused only on the text of a specific AI regulation. From a regulatory perspective a good business environment relies on predictable rules, transparency in the rulemaking progress, and an honest effort to simplify implementation of rules and review them to understand their continued relevancy. These elements touch more on the "how" regulatory decisions are made and implemented—which was the focus of my previous analysis with the Better Regulation Test.
However, citizens and firms are not the only ones carrying the burdens of laws and regulations. Government agencies carry self-imposed burdens too—which takes us to the last pillar to the Regulatory Quality Review.
5. Implementing institutions and obligations
Regulators and government agencies are usually depicted as the "bad guys." They create the rules and obligations that burden citizens, firms and everyone—including themselves. This last words are precisely overlooked when rules are created, as there is often very little thinking on what are the implications on the government itself.
Again, it is easier to write things on paper. It is more difficult for government agencies to monitor and enforce compliance of regulations. They often operate under limited resources. Then, the new responsibilities without adequate resources perform them are a recipe for "institutional stress" and much likely to underachieve the policy objectives at stake.
In the case of the AI Safety Act from Illinois, the responsible institutions mentioned in the text include: the Illinois Emergency Management Agency and Office of Homeland Security (defined in the Act as the "Agency"), and the Attorney General.
To get a sense on their new "load," I asked Gemini about their responsibilities. This is part of the LLM's response:
These two entities share the workload, but they have distinct primary roles:
The Agency (Administration and Operations) The Illinois Emergency Management Agency acts as the primary administrative body. Its duties include:
Building the Infrastructure: It must establish the mechanisms and online portals that developers and the public will use to report critical safety incidents and confidentially submit risk assessments.
Registration and Fees: It is in charge of collecting the annual disclosure statements from large frontier developers, collecting the fees required to fund the administration of the Act, and maintaining a published list of these developers.
Guidance and Reporting: The Agency must designate which federal laws are "substantially equivalent" for the sake of interoperability, and it must produce an annual report for the General Assembly and the Governor detailing critical safety incidents and recommending updates to the Act.
The Attorney General (Consultation and Enforcement) While the Agency must consult with the Attorney General when setting up reporting mechanisms and drafting its annual reports, the Attorney General's most critical role is enforcement.
Exclusive Civil Actions: If a developer commits a major violation—such as failing to conduct a third-party audit, failing to report a critical safety incident, or making a false statement about their AI framework—the resulting massive civil penalties (up to $1,000,000 for a first violation and $3,000,000 for subsequent ones) can be recovered in a civil action brought exclusively by the Attorney General.
In total, there are 12 direct operational mandates (using "shall" or "shall not") specifically directed at the Agency and/or the Attorney General to implement and administer this law. Additionally, there is one exclusive enforcement mandate regarding how penalties are collected.
In summary, while the Act places a heavy burden on tech companies to write frameworks and conduct audits, it also imposes strict, legally binding obligations on the state government to build secure infrastructure, constantly monitor AI risks, and aggressively protect the sensitive corporate data they collect.
This is not very different to what I have seen in other countries. Laws, including AI rules, might sound and look great on paper. What happens in practice is that a few years after implementation, regulatory mandates are not implemented. Examples include electronic systems that are never developed, obligations that are not monitored, and many others failures.
This analysis did not intend to find whether the two involved agencies in Illinois will receive additional budget allocations to implement the Act. However, the common practices in many countries is that regulators and government bodies as asked to miraculously do more with the same or less resources.
Final words after the Regulatory Quality Review of the AI Safety Act from Illinois
Running the Regulatory Quality Review on the AI Safety Act gives us a few things to consider on this and future AI regulations at the state and federal or even in another country.
A. It is easier to write rules on paper than to regulate adequately following good regulatory practices. Among many other things, this implies understanding and expressing clearly the problem at stake, the pursued policy objectives and having a better idea of the compliance cost that affected citizens and firms will incur, as well as the tasks and burdens imposed on government agencies—often without extra budget.
B. It is possible to regulate in a better way by following a better process or "how" to make final decisions. This "how" to regulate is usually called good regulatory practices (GRP). When well done, the results of GRP are more likely to be reflected in the final text of the approved AI regulation. However, these better results do not stay on paper only. They are reflected in arriving to a better balance between the benefits rules intends to created and the costs they impose on everyone. Another positive consequence from this is the creation of a better business environment for economic growth, innovation and jobs.
C. Regulatory decisions rarely are pure technocratic decisions. Tensions and interests from politics, industry and other actors come at play to define rules that create winners and losers. Regulating means exercising power. Nonetheless, the final text of a regulation can give us an idea of two things. One is the quality of the rule—which comprises the quality of the process leading to the decision. The other is whether the politics were sorted out first and then a rule was made to serve those politics, or if rule-makers got the policy right first and then found the politics to make it happen—just like Tony Blair suggests in his latest book.

