Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

How Do You Tame AI? Gary Marcus Argues for Risk-Based Oversight

By TheFinanceBase Team9 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

AI should not be governed only by voluntary promises from the companies that build it, argues cognitive scientist Gary Marcus. His proposal is layered oversight: independent audits, responsibility when systems cause serious harm, and stronger checks before high-risk systems are deployed. For consumers, that matters when AI influences decisions about jobs, credit, health care, or money—or is used to impersonate someone and commit fraud.

What does “taming AI” mean?

It does not mean banning every chatbot or treating every automated tool as equally dangerous. It means setting rules that reflect what a system can do, where it is used, who may be harmed, and whether people have a way to challenge a consequential decision.

A drafting assistant, a résumé screener, a medical triage tool, and an AI agent authorized to move money have different failure modes. A workable approach would preserve useful, low-risk applications while requiring stronger evidence, oversight, and remedies as the stakes rise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Gary Marcus is a cognitive scientist and professor emeritus at New York University who has become a prominent critic of inflated claims about large language models and an advocate for stronger oversight. He made the case during a November 2024 Seattle conversation with science-fiction author Ted Chiang, covered by GeekWire. Marcus’s views are influential advocacy, not a consensus position representing all AI researchers. His book Taming Silicon Valley: How We Can Ensure That AI Works for Us was published by MIT Press on September 17, 2024; see the publisher’s book page.

What oversight is Marcus proposing?

Marcus argues for a system in which companies do not set the rules for high-impact AI entirely on their own. In GeekWire’s account, he proposed considering FDA-like approval for AI systems with substantial risks, independent external audits, and laws that make companies bear some costs when their systems cause major social harm. He also floated a Federal AI Administration or an international civil organization modeled in spirit on aviation oversight, with independent scientists involved.

  • Pre-deployment review: Require evidence that especially risky systems have been tested and that their benefits justify their risks.
  • Independent audits: Have qualified reviewers examine the system and its intended deployment, rather than treating a company’s internal safety report as sufficient.
  • Liability: Give developers and deployers incentives to prevent foreseeable failures and provide remedies when serious harm occurs.
  • Continuing oversight: Monitor systems after launch, investigate incidents, and require corrective action when risks emerge.

The comparisons to the Food and Drug Administration and the Federal Aviation Administration concern the structure of oversight, not a claim that AI can simply be licensed exactly like a drug or aircraft. They point to testing, standards, incident investigation, and ongoing responsibility rather than reliance on a promise to behave responsibly.

Why risk-based rules make more sense than one rule for all AI

A regulatory system can scale its requirements to the likely severity and reach of harm. The examples below are a proposed way to think about oversight, not a description of one current law.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Risk tier Example use Possible safeguards
Lower Personal drafting or spelling assistance Clear disclosures, privacy protections, and ordinary consumer safeguards
Moderate Customer-service or classroom support tool Reliability testing, monitoring, disclosure, and a route to human help
High Hiring, credit, medical triage, or public-service decisions Impact assessment, independent audit, decision records, human review, and a way to appeal
Very high Critical infrastructure or an autonomous system capable of taking harmful actions Potential pre-deployment approval, strict access controls, continuous monitoring, and enforceable accountability

For personal-finance readers, the distinction is practical. A chatbot suggesting ways to organize a household budget is not equivalent to a system that affects a loan application, selects job candidates, or initiates transactions. When an automated decision can materially affect someone’s income, access to credit, or ability to contest a charge, disclosure alone may not be enough; documentation, human escalation, and a meaningful appeal route matter too.

Which harms are already visible?

Marcus cited concerns including biased hiring systems, hallucinated information, plagiarism and copyright disputes, disinformation, deepfakes, and limited transparency. These issues are not all the same kind of risk, and their presence does not mean every AI system causes them.

  • Consequential errors: A system can produce plausible but false information. In a high-stakes setting, a confident-sounding answer may be especially hard for a user to detect.
  • Discrimination: Automated screening can reproduce or amplify unfair patterns in data or in the way a system is used. Testing data alone does not resolve every institutional or measurement problem.
  • Impersonation and fraud: Deepfakes and synthetic content can make it easier to imitate a person or create misleading material. The risk depends on how tools are accessed and deployed.
  • Privacy and data rights: Questions about personal information, training material, licensing, and surveillance are distinct from whether a model gives accurate answers.
  • Less certain future scenarios: Claims about cascading failures in infrastructure or catastrophic outcomes are predictions, not established results. They should be evaluated separately from harms already being encountered.

Marcus also raised concerns about business models built around surveillance and about companies making consequential decisions with little outside scrutiny. Those are arguments for examining incentives and deployment practices, not proof that every AI company or use operates in the same way.

What makes an AI audit meaningful?

An audit is not a magic stamp of safety. Its value depends on the auditor’s independence, competence, access to evidence, and ability to escalate significant findings. A review that relies only on a vendor’s selected demonstrations or idealized test cases may miss problems in real use.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Model evaluations: Test reliability, bias, refusal behavior, cybersecurity, and misuse potential, using cases that resemble the intended use.
  • Data review: Examine provenance, licensing, quality, privacy, and whether the data represents the people affected.
  • Deployment review: Check the actual workflow, including who relies on outputs, whether a person can override them, and what happens when they are wrong.
  • Security testing: Look for data leakage, prompt injection, jailbreaks, model theft, and unauthorized use of connected tools.
  • Impact assessment: Record affected groups, foreseeable harms, mitigations, and risks that remain.
  • Post-launch monitoring: Track complaints, incidents, performance changes, and unexpected behavior after updates or integration with other systems.

Auditors need access to relevant documentation, logs, and system behavior. Regulators may also need authority to compel information; voluntary disclosure alone can leave outsiders unable to verify a safety claim. Even a sound audit can identify and reduce risk, not guarantee that a system will never fail.

Why use the FDA and FAA as analogies—and where they fail

What the FDA analogy contributes

Drug regulation offers a model for asking whether evidence supports a product’s benefits in relation to its risks, particularly before use in consequential settings. It also highlights post-market monitoring and the possibility of corrective action when problems emerge. Marcus’s reported question—whether a risky system’s benefits outweigh its costs—captures that logic.

What the FAA analogy contributes

Aviation safety depends on multiple layers: design standards, testing, maintenance, operating procedures, accident investigation, and continuing oversight. Marcus’s point is that safety cannot rest only on manufacturers’ assurances; responsibility is distributed across institutions and the life of a system.

Why neither analogy transfers literally

AI software can be copied, updated, fine-tuned, connected to other tools, and used in very different settings. A model may behave differently depending on prompts, data, integrations, and the version in use. There is no single universally accepted test suite or equivalent of a drug dose for general-purpose AI. Harm may stem as much from the organization’s use of a model as from the model itself. Approval would therefore need to specify the intended use and account for changes after release, rather than certify a model once for every purpose.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who should be accountable when an AI system causes harm?

Responsibility can be split across several parties. The developer controls aspects of model design and training; an application vendor may add features or connect the model to tools; the organization deploying it chooses the use case, workflow, and data; managers determine how much human review actually occurs. A user may also misuse a system, but that does not automatically erase the responsibilities of the companies and institutions that designed or deployed it.

Liability could encourage testing, recordkeeping, monitoring, correction of known defects, and compensation for people harmed. The difficult policy questions remain: what misuse was foreseeable, how should responsibility be divided across linked systems, and when should following an accepted standard count in a company’s favor? Compliance costs also matter: rules that only the largest firms can afford could entrench incumbents and narrow competition. Marcus’s proposal to make companies bear some costs of major social harms is a principle, not a settled answer to those legal design questions.

Does openness make AI safer or more dangerous?

The Seattle discussion included disagreement about releasing advanced AI systems. GeekWire reported Marcus’s criticism of major technology companies releasing models that could be used by geopolitical rivals, while Meta’s Mark Zuckerberg and AI chief Yann LeCun supported greater openness and Geoffrey Hinton opposed it. That disagreement is best understood as a trade-off, not as proof that open or closed systems are inherently safe.

  • Reasons to favor openness: Independent scrutiny, reproducible research, more competition, less concentration of power, and the ability to run or customize a system locally.
  • Reasons to limit unrestricted release: Once model weights are widely distributed, access may be difficult to revoke; modified versions can be harder to monitor, and powerful capabilities may be easier to misuse.

“Open source” can refer to different things: source code, model weights, training data, or a license allowing certain uses. Access to one does not necessarily mean access to all. The safety question depends on capabilities, safeguards, deployment, and incentives—not on a label alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can organizations do before stronger public rules exist?

Organizations do not need to wait for a new agency to create basic controls. NIST’s AI Risk Management Framework, released on January 26, 2023, is a voluntary resource for incorporating trustworthiness into AI design, development, use, and evaluation. It organizes work around governance, mapping, measurement, and management; it is not a binding law or a guarantee of safety. See NIST’s AI RMF page and its implementation resources.

  1. Inventory systems: Identify AI tools in use, including features embedded in software bought from vendors.
  2. Classify the use: Record the purpose, people affected, possible severity of error, and whether the system can take actions.
  3. Document the system: Keep information about intended use, data sources, limitations, vendor, model version, and changes.
  4. Test before use: Evaluate accuracy, disparate impact, privacy leakage, and security in conditions resembling the actual workflow.
  5. Set human controls: Require review for consequential decisions and make sure reviewers can understand and override an output.
  6. Prepare for failures: Establish incident reporting, escalation, rollback, and correction procedures.
  7. Protect affected people: Give clear notice where appropriate and provide a way to question or appeal an automated decision.
  8. Keep monitoring: Reassess after updates, changes in data, or new integrations; launch is not the end of evaluation.

ISO/IEC 42001:2023 is a separate international standard for establishing, implementing, maintaining, and continually improving an AI management system. It is not a universal certificate that an individual model is safe. Details are on the ISO standard page.

What should readers look for in a proposed AI rule?

A useful proposal should answer more than whether it promises “responsible AI.” Ask:

  • What specific harm is the rule meant to reduce, and how severe and likely is it?
  • Can the risk be measured before deployment, and who can inspect the evidence?
  • Does the obligation fall on model developers, application vendors, deployers, or more than one layer?
  • Can an affected person get an explanation, human review, or a remedy?
  • Can the rule adapt when a model is updated, fine-tuned, embedded in another product, or released as downloadable weights?
  • Could compliance costs protect large incumbents at the expense of smaller developers?
  • Are independent researchers, workers, civil society, and affected communities represented alongside industry experts?

Technical expertise from industry is necessary, but relying on companies alone to define the evidence and standards creates a risk of regulatory capture. Counterweights include independent scientists, technical auditors, labor and civil-society groups, and people directly affected by deployments. Rules also need enforceable access to information rather than depending wholly on voluntary company reporting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.