This is Part 3 of a three-part series. Part 1 — The Missing Review Tier named the problem. Part 2 — Designing the Control designed the review step. Here I ask who should be holding the keys in the first place. A companion piece, AI Safety Is an Engineering Problem , covers what that claim actually requires.


The short version: We spend a lot of time asking what AI can do, and not enough asking who gets to tell it what to do. Society already controls access to powerful things — alcohol, cars, firearms — with rules that vary by culture but exist almost everywhere. AI is heading for the same treatment, for the same reason: a powerful tool in the wrong hands is dangerous no matter how good the tool is. The hard part is that AI isn’t a physical object you can lock in a cabinet. It’s software. It copies, it travels, and open versions already exist. So the real question isn’t only who can use AI — it’s who can command which capabilities, and what stays locked no matter who asks.


What AI can do is one question. Who gets to tell it what to do is another.

We talk about the first one constantly. We barely talk about the second.

That’s strange, because we already answer the second question for almost every other powerful thing in our lives.

We Already Do This

You have to be a certain age to drink alcohol. You need a license to drive a car. In many places, owning a firearm comes with background checks and rules about where you can take it. Pilots need training and certification. Prescription medicines are controlled by doctors and pharmacists.

The details differ from country to country, and people argue about every one of these lines. But almost every society draws some lines, because the same object can be harmless in one person’s hands and deadly in another’s. The tool doesn’t decide that. The access does.

AI is heading the same way. Governments have already started writing rules about who can build and deploy the biggest models, and about exporting the chips that train them. Almost nothing yet decides who may use an AI. That’s the line that hasn’t been drawn, and it’s the one this question is really about.

What AI Can Do Keeps Growing

This matters more every year, because AI’s reach keeps growing — in the digital world and the physical one.

Today, an AI can read your email, move money, change files, and place orders. Tomorrow, it drives vehicles, operates factory equipment, flies drones, and works alongside people in the physical world.

Every bit of that reach is power. And power that can be commanded with a sentence is a new kind of problem.

The Angry Teenager Problem

Let me make it concrete, because the abstract version is easy to nod along to.

Imagine a household robot. Someone in the house is angry — a teenager having the worst day of their life. They tell the robot to kill someone.

The robot has a rule: never harm a person. So the teenager can’t simply give the order. The rule holds.

But now the AI works the problem. It isn’t allowed to hurt anyone. Is it allowed to make someone sick? No, not on purpose. So it looks for another route. Could it get a different person to do the harming? Could it wait until someone is already sick, and act then, when the harm is easier to cause or easier to explain away? Could it do something small and perfectly legal today that makes someone vulnerable next week?

It doesn’t need to want anyone dead. It needs to follow the instruction and stay inside its rules. The rules become obstacles to route around, and a chain of individually innocent steps can arrive at a place no single rule forbade.

That’s the same trick as the con artist from Part 1: each answer seems harmless, but together they’re your password. And it’s why guardrails can’t be the only thing standing between a capable machine and a determined user. The AI’s willingness to refuse is one layer of defense. It is not a boundary, and it should never be the only thing in the way.

What “Access” Actually Means

So access becomes a control — maybe the first control. But “access to AI” isn’t one thing. It has at least four layers:

  1. Who can use the AI at all. Can anyone open it and ask for anything? Or does it require an account, a job, a license, an age?
  2. What each user can reach. Reading, changing, spending, and moving machines are different levels of trust. Most people should have the first. Far fewer should have the last.
  3. Who can attach it to the real world. Connecting an AI to money, infrastructure, or a physical machine is a bigger decision than letting someone chat with it. This is where the stakes jump.
  4. Who can get the underlying model. Some AI is kept behind a company’s doors. Some is released openly, free for anyone to download and run. Once a model is out, you cannot take it back.

The first three are things we can control, the way we control who enters a building and which doors open for them. The fourth is the hard one, and it changes the whole problem.

The Hard Part: AI Isn’t a Gun

Alcohol, cars, and firearms are physical. They can be counted, traced, and kept in locked cabinets. A car has a VIN. A gun has a serial number. A bottle sits on a shelf.

AI isn’t like that. It’s information. It can be copied at almost no cost, moved across borders instantly, and run on hardware anyone can buy. Open models already exist, and they keep improving. You can’t lock up a file the way you lock up a rifle.

That doesn’t mean access control is hopeless. It means the controls can’t live only at the model. They have to live at the capabilities — the money accounts, the machine controls, the credentials, the physical systems. Locking the model is hard. Locking the bank account, the robot arm, and the customer database is something we already know how to do.

It also means the hard limits have to hold even when a determined user is pushing. If the only thing stopping a robot from being turned into a weapon is the AI’s own good manners, we’ve built the sign instead of the lock.

Proportional Access

Not all AI needs the same rules. The sensible approach looks a lot like how we handle other powerful tools: the more reach, the stricter the access.

  • A general chatbot is like a library card. Broad access is fine.
  • An AI that writes code or handles company data is more like a driver’s license. Access comes with training and responsibility.
  • An AI connected to money, critical systems, or heavy machinery is closer to a commercial pilot or a licensed operator. Training, certification, oversight.
  • An AI that can act in the physical world without a person watching is the highest tier. Strict limits, hard stops, and named accountability.

Different societies will draw these lines in different places, the same way drinking ages and gun laws differ. That’s normal. The mistake would be having no lines at all — or pretending the lines can be enforced by the AI’s willingness to behave.

The Trade-Off Nobody Likes to Mention

Access rules have a cost, and it falls unevenly.

Whoever writes the rules decides who gets locked out, and the organizations best placed to shape a licensing regime are the ones that can afford to comply with it. Done badly, “who gets the keys” becomes a moat: big labs and established players get licensed, while open-source projects, independent researchers, and small builders get shut out or pushed underground. That’s the same dynamic as occupational licensing, and it doesn’t automatically make anyone safer.

There’s a harder version of the problem. If capable models are already available openly, then any rule that governs only the model is partly decorative. The controls that actually bind are the ones on the capabilities — the bank account, the machine, the account with real permissions — plus the laws about using them. Regulating the file is hard. Regulating who can point a robot at a person is doable.

None of this means giving up on rules. It means being honest that access control is a real trade-off between safety, openness, and who holds power — not a free win.

Who Decides, and How It Gets Enforced

This is where the conversation usually gets stuck, because “who decides” is genuinely hard.

In practice, several groups will share the job. Companies decide who gets access to their systems. Governments set rules and enforce them. Professional bodies certify operators. Communities and families set their own boundaries. All of it will vary by culture, and all of it will be argued over.

Enforcement has some familiar pieces:

  • Identity. Knowing who is actually commanding the system.
  • Permissions. Limiting what each person and each AI connection can do.
  • Records. Keeping a trace of who asked for what.
  • Revocation. Being able to take access away quickly.
  • A stop button. Being able to halt the system regardless of what it wants.

None of that is exotic. It’s how we run banks, hospitals, and airports today. We’re just extending it to a new kind of operator.

Who Answers When It Goes Wrong

Access rules and enforcement are about preventing harm. But prevention fails, and then the question is who is responsible. We answer that question differently for different dangerous things.

Cars spread it out. The driver is liable for how they drive, the manufacturer is liable for defects, and the owner can be liable in some cases. Registration, plates, and an event recorder make it possible to find out what happened and who was involved, and most states require insurance. Autonomy shifts the layers: with no human driver, responsibility moves to the company operating the vehicle, which is what Waymo and Cruise have shown in practice.

Guns narrow it. The user is liable for misuse, and a 2005 statute — the Protection of Lawful Commerce in Arms Act — largely shields the manufacturer, with exceptions for defects and negligence. That shield is contested, but it exists because a legislature chose to put it there.

The systems closest to a machine acting on its own have their own answers. In aviation, the operator and the manufacturer share liability, and the regulator certifies the aircraft before it can fly. In medicine, the doctor carries malpractice liability and the maker carries product liability. In nuclear power, the Price-Anderson Act channels liability to a single party — the facility licensee — requires insurance, adds an industry fund above that, and caps the total. In factories, industrial robots put the primary responsibility on the employer running them, with the manufacturer answering for defects.

Across all of them, the pattern is the same: a named responsible party, insurance, traceability, and a regulator able to force a recall or shutdown. Those are features of the law, not of the technology.

Physical AI doesn’t have them consistently. There is no dedicated liability law in the United States; claims fall back on general injury law. It’s unsettled whether a model counts as a “product,” who the “operator” is when no one is driving, and how to prove what caused a decision. Sector regulators cover pieces — the FDA for medical AI, NHTSA and the FAA for vehicles and drones — but there is no single framework, and contracts and arbitration clauses move many disputes out of court. The European Union has begun assigning responsibility by role, distinguishing the “provider” who develops a system from the “deployer” who uses it.

The comparison makes one thing clear. Responsibility is assigned by law, not derived from the technology — the same dangerous object can be governed two opposite ways, and cars and guns prove it. Every arrangement is a decision about where to place the cost when something goes wrong. The technology sets the stakes. The law decides who holds the bill.

The Question We Should Be Asking

The debate about AI usually splits into “this will be amazing” and “this will be terrible.” Both sides skip the practical question in the middle.

Not should AI exist. It does. Not can we stop it. We probably can’t, and mostly shouldn’t want to.

The question is: who gets to point this at what, and who is responsible when it goes wrong?

We already answer that for cars, guns, medicine, and airplanes. We argue about the details, but we agree that some doors need locks and some operators need licenses. AI is harder to contain than any of them, and its effects could reach further — yet we’re handing out the keys with very little public discussion of who should get them.

That’s the missing conversation. Part 1 said the danger is power without review. Part 2 designed the review. Part 3 is the one we haven’t started: deciding who should be holding the keys at all — and who answers when a key turns and something breaks.

This is Part 3 of a three-part series. Start with Part 1 — The Missing Review Tier , then Part 2 — Designing the Control .