There's a particular kind of tech policy thinking that treats complexity as a problem to be solved with more complexity. We're seeing it play out right now in how governments are organizing themselves around artificial intelligence. A minister here, a task force there, inter-agency councils, advisory boards, oversight committees. It's governance theater, and the winners in this emerging landscape won't be the jurisdictions that build the most elaborate regulatory frameworks.
They'll be the ones that actually get things done.
Consider what we're watching globally. Governments are scrambling to position themselves as "AI-forward" while also appearing responsible and cautious. The result is exactly what you'd expect: organizational confusion masquerading as strategic planning. Multiple agencies claiming jurisdiction. Unclear decision-making authority. Endless consultation periods that delay action without improving outcomes.
Meanwhile, actual problems need solving. Websites hosting illegal content get taken down through straightforward enforcement of existing laws, not new AI-specific statutes. Network outages affect millions of users and require competent systems engineering to prevent recurrence, not philosophical debates about algorithmic fairness. Security vulnerabilities in high-stakes systems demand rapid patching and transparency, not months of regulatory impact assessments.
The fundamental mistake is treating "AI governance" as something that requires new institutional apparatus. It mostly doesn't. What we actually need is existing institutions working efficiently: competition regulators with teeth, cybersecurity teams with resources, labor departments understanding workplace impacts, and yes, criminal law enforcement that can keep pace with technology.
None of that requires a special AI ministry or a cabinet-level AI coordinator. Those positions signal seriousness to the public and create opportunities for ambitious bureaucrats, but they often create another layer of bureaucracy that slows decision-making rather than accelerating it. When an AI-related problem emerges, does it really help to have it routed through an AI-specific office before reaching the actual regulatory agency with statutory authority to act?
The contrarian view here is that simpler is better. A well-resourced competition authority that understands network effects can handle AI market concentration without needing to ask an AI minister's permission. A competent labor regulator can address workforce displacement without consulting an AI ethics board. A functional cybersecurity apparatus can secure AI systems the same way it secures any critical system: through basic, boring hygiene.
What this requires isn't organizational innovation. It requires political will to adequately fund existing institutions and let them do their jobs without creating competing fiefdoms. It requires accepting that not every emerging technology needs a custom-built governance structure.
The jurisdictions that will win are likely the boring ones. Singapore doesn't dazzle us with elaborate AI governance announcements, yet its regulatory environment has attracted serious investment and development. The EU's approach is famously bureaucratic and sometimes counterproductive, but at least it acts through established legal frameworks rather than creating new ones for each technology cycle. Meanwhile, countries that create splashy new AI positions often find those roles either powerless or duplicative of what existing agencies already do.
There's also a practical problem with the complexity-begets-complexity approach. Each new layer of governance creates constituencies that benefit from its existence. Once you establish an AI ministry, that ministry needs to demonstrate it matters. It will find things to regulate, studies to commission, consultations to conduct. The default output of bureaucracy is more bureaucracy.
The genuine issues with artificial intelligence are real and serious. But they're not new categories of problems. Market power concentration, worker displacement, security vulnerabilities, privacy invasion, systemic bias, misinformation: these are old problems with new accelerants. They need focused attention and adequate resources directed at them, not new organizational structures.
The winners in tech governance will be the operators who recognize this. Governments and regulators that cut through the noise, assign clear responsibility to existing institutions, give them resources, and hold them accountable for results. Not the ones that add another layer of hype, another coordinating body, another strategic committee.
Simplicity is unfashionable in policy circles. But it works.