Abstract
Policymakers confronting generative AI have often accepted a striking premise: that AI is too complex, too fast-moving, and too “unprecedented” to be governed by existing frameworks. We argue that this premise is itself part of the problem. Many harms associated with generative AI, including fraud, impersonation, deceptive advertising, and exploitative synthetic media, are not wholly new categories of threat. They are familiar harms, now produced and distributed more cheaply, more quickly, and at greater scale. To move beyond the current policy paralysis, we propose decomposing AI into three layers: the model layer, the deployment layer, and the distribution layer. Once disaggregated in this way, AI no longer appears as an ungovernable monolith, but instead as a supply chain of software products and infrastructures that already sit within consumer protection, product liability, sectoral, and platform-governance regimes. Governing actors should stop treating the absence of legal authority as the obstacle. The real challenge, we argue, is the persistence of AI exceptionalism and the resulting under-enforcement of ordinary law.

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Copyright (c) 2026 Sarah Barrington, Hannah Bailey
