[Responses given after each direct quote passage]
Member Meeting
In meetings with policymakers, we have been met with frustration when explaining that a particular proposal does not work for startups. The response is often some version of: ‘The rest of the industry has accepted this framework, so you should too.’ (emphasis added)
This policymaker response is implausible as described. Then again the qualifier “often some version of” is impressive as both a) heroically load-bearing, and b) unfalsifiable. I’ve been in meetings with policymakers too. No one would so nakedly betray their own cynical resignation.
Unless they were close friends, letting you in on the real scoop (after “frustration” subsides of course). [Ed. Then why didn’t you push back? Explain how it is?]
Anyway their preceding paragraph works directionally against such a generous reading:
The result is that even policy interventions designed to check the power of large firms can end up disadvantaging smaller ones. To date, many of the laws enacted to govern AI suffer from this precise defect, such as broad compliance mandates or design requirements.
So this totally real policymaker:
wants “interventions designed to check the power of large firms,” BUT
is also apparently unconcerned about the effect on startups, AND
has a robust proxy for “rest of the industry” which is a sufficient condition for their viewpoint?
Ah, it must be Rep. Epic Strawman. His constituency in East Fakeington is famous for supporting any policy at any moment.1
Okay, cognitive dissonance is real. Could just be a very unique, sui generis case…applying to “many of the laws” which are in fact real being that they are “enacted.”
No the only time that framing would be used by a policymaker is not when developing or trying to win support for the policy. It's when the dish is already cooked, sitting at the pass, and ready hit the table (floor vote or equivalent).
I mean I suppose the authors could be saying this “conversation” happened at that stage in the process (yikes!). If that’s so…what’s the saying? “You’re tellin’ on yourself.”
Overwhelming
Consider the challenge of simply knowing what is coming. A startup building an AI-powered medical imaging tool needs to understand not only the technology it is developing but also the policy environment in which it will operate. That requires monitoring legislation, tracking regulatory proposals, interpreting agency guidance, and anticipating political shifts.
…External resources that could fill this gap, including law firms, policy consultants, and trade association memberships, are expensive, and the budget to retain them is difficult to justify when the same capital could extend the company’s runway or accelerate product development.
Directionally this is correct and taken with the below is really talking about the state level—there’s not a ton happening at the federal level legislatively, which incidentally is what facilitates ad hoc highly restrictive actions showing up for the frontier models.2
Further the list of tasks is disunified:
“monitoring legislation” and “tracking regulatory proposals” are distinct but I’ll grant the most salient, though the means of following them are largely the same.
“interpreting agency guidance” is a distinct task - important though not radically variable over a legislative cycle. Strictly speaking interpretation is something else. Taken with the following paragraph it’s made explicit the real concern is (proposed) state legislation anyway.
“anticipating political shifts” is something almost no one (big or small company) does well, neither is it a necessary condition to understanding the operative policy environment. It is altogether a distinct input, much broader and differing time-horizon, but has the passing resemblance to “policy” tasks.
Does this hypothetical startup need to understand “the policy environment?” Probably. In the same way this startup needs to understand HR systems, and office leasing, and candidate recruiting, and equity market conditions, and… Every startup presumably sets out to fix a narrow problem while along the way contending with a bunch of things they have zero interest in, but that’s running a business. It’s why there are various permutations of law firms, consultants, and associations for every one of those needs. In fact tons of the Silicon Valley startups are SaaS versions of those things, they’d argue are better and cheaper.
The non-zero cost of policy monitoring is not ipso facto a meaningful barrier insofar as it’s universal for anything outside the startup’s core mission. Tradeoffs are everywhere.
The burden of regulatory intelligence is only increasing. In 2025, more than 1,000 state-level AI bills were introduced across all 50 states. In 2026, the pace has accelerated: as of May, lawmakers in 46 states had already introduced over 1,779 AI-related bills,3 surpassing the total for all of 2024. Tracking and assessing these proposals requires a level of institutional capacity that is difficult for most startups to build.
Here one presumes “burden” means cost (money and time). And generously I read it inferring an increasing burden results from increasing legislative activity. That seems obvious but it assumes the marginal unit-price of “regulatory intelligence” is fixed or increasing. Does that seem right?
Well they concede the point later on that AI and new technologies are a solution. It’s actually easier than ever to track large dynamic categories like this. So I gave it a shot.
CASE STUDY: Legislation Tracker
Problem: A hypothetical medical imaging AI startup needs to stay abreast of potential policy changes across 50 states. But the skeleton staff doesn’t have the capacity (funding or labor) to dedicate to the task in traditional ways: outside lobbying/advisory services; high cost bespoke subscription services; real-time ‘manual’ searches.
Need: A low-effort, low-cost way to track the current state of affairs and changes as they occur, allowing product development, GTM, and executive teams to efficiently determine when and where a policy risk exists. As automated as possible.
Solution: Build an auto-updating dashboard
Execution:
secure LegisScan API passkey (free w/ registration)
use base consumer version of Claude Sonnet 5 (“medium effort”) to write an html code for a basic dashboard.
create a naive “risk weighting” to score items for likelihood of passing (also Claude).
The display separates out policy most likely to directly affect the AI/medical imaging space, as well as the full universe of AI-related bills.
[Note: I did not build an auto-updating data call script for this illustration, but Claude produced a code addendum to do so]
Total labor/time: One person, < 30 mins.
Direct Cost: monthly Claude subscription; computer; internet service
Plenty of opportunities for refinement/improvement/customization which I did not pursue since I don’t actually have VC funding for this hypothetical company.
Further there’s no plausible reason to have to actively track the entire corpus of AI-related state legislation.4 Even if you wanted to it’s fairly straightforward. And some startups and publishers offer off-the-shelf AI/ML tools for doing so: some limited but free all the way to expensive (almost as if it’s a whole market serving lots of different needs).
Being Heard
Both federal and state policymaking are relevant here, but require different scopes and at various times they emphasize one over the other so it’s hard to pin down. Federal is actually much easier (read: low cost) to monitor with a more extensive set of available tools to do so, but expensive to directly engage (read: lobby, influence); states are the reverse.
Note: this is separate from “monitoring the policy environment.” Reading the paper everyday doesn’t mean getting your op-ed published.
Impact
Regulation imposes fixed costs: legal teams, audit processes, reporting systems, compliance infrastructure. For a large company, these represent a modest share of revenue. For a small company, the same absolute cost consumes a much larger share of its resources. The result is that regulation can function as a barrier to entry, even when that is not the intent. (emphasis added)
Again directionally true,5 but not exclusively nor universally so. Regulation sometimes imposes fixed costs, but let’s stipulate it’s always the case. What is not true is that regulation is limited to fixed costs—some costs are quite variable. Import duties, copyright and data licensing, indeed audit costs for things like KYC and AML rules all scale according to scope and users. To be sure these stack on top of fixed costs (but incidentally the unit-cost economics drives increasing marginal production as much as possible, especially for smaller firms).
But there’s a couple examples given: GDPR and NY’s RAISE Act.
GDPR:
I don’t know from GDPR so concede the point—notwithstanding the implication thus far is that large firms lobbied for it at the expense of smaller ones? And we’ve so far only considered monitoring and lobbying for state and federal legislation—now global policy is the scope. Heard chef!
RAISE Act:
New York’s original RAISE Act, as passed by the legislature last June, would have imposed penalties of up to $10 million for a first violation and $30 million for subsequent violations, with coverage triggered by compute-cost thresholds that could have reached companies with significant venture investment but little or no revenue.
It continues that a key major flaw with the law is now corrected ($500M revenue threshold). It’s not irrelevant: the argument is an actual law, for a time, exhibited a policy framework they reasonably argue was acutely burdensome on startups. But the premise of this entire article is that startups are systematically biased against. Then how did this get corrected? If large incumbents overwhelm potential competitors with resources, relationships, and capacity, where was the impulse to make the eventual change? This advisory from a fancy law firm asserts the change also aligns with California law, which may itself be an awful law for startups, but it works against the heterogeneous state laws critique.
Applicability
The ecosystem is extraordinarily heterogeneous. A startup building AI for autonomous vehicles and a startup using AI to streamline medical billing face very different regulatory concerns, yet both are swept into the same “AI company” category in the policy debate. When a bill proposes new obligations for “AI systems,” these companies need different things from the legislative process, making it difficult to form unified positions or build the kind of durable coalitions that are effective in Washington. (emphasis added)
Absolutely. And without specific reference it’s impossible to go deeper. But note: imprecise terminology and definitions are a symmetric policy risk for older laws as well, themselves just as likely to overly burden startups (according to the obtuse version of public choice/Mancur Olsen gospel sang so far).
Previously codified definitions for “revenge porn” and “CSAM” are not necessarily forward-compatible to AI-generated examples, so at least some of the thousands of proposed laws address this.6 I assume the medical imaging co. is fine there.
Similarly extant laws may unintentionally preclude AI systems from competing on equal footing with older technologies so at least some of the thousands of laws of concern are favorable to their interests.
Since Washington is specifically recognized in this claim, let’s not forget the single widely-applicable federal legislation to get close to passing was a 10-year moratorium on AI state legislation. I suppose one could argue that favors large incumbents over startups, though odd then authors’ colleagues lobbied in favor.7 It’s one or the other guys.
Etc.
There’s additional descriptions of large incumbent advantages in the article that I’ll broadly concede as accurate, if overstated.
Broad market participation means larger firms have more opportunities for coalitions. I’d politely suggest brushing up on your Bertrand competition model before next class.
Longstanding participation means larger firms have more familiarity with the infrastructure of policy-adjacent institutions (think tanks, etc.8)
There’s also an extensive passage going through much of the theoretical cases for an incumbent-favoring policymaking production function. On the terms in which it’s presented I don’t dispute any of it. But it’s also tautological. The “invisible costs” of regulation smothering or aborting startups don’t get considered in policy impacts. Well, yes, but it doesn’t tell us anything instructive.
For instance it’s empirically possible particular regulatory schemes slow the rate of new firm formation, which over time eliminates fewer large incumbents. But as far as I can tell all the mechanisms of regulatory production and incidence are not specific to recent history—an arrangement of incentives and institutions true decades ago as they are now. What’s the evidence it’s worse now? Still worth countering but a fuller exploration would acknowledge how new entrants have ever been able to compete given this overwhelming disadvantage. Citing a friend of mine in a paper published by a place I used to work, they do not distinguish between a snapshot in time and a historical explanatory variable.
Proposed Improvements
A few of their suggestions to more favorably account for the startup perspective below:
CBO doesn’t do any of these kinds of assessments, so this is not an extension of an existing capacity, it’s a categorical reorientation (0 to 1?). For bills subject to committee reporting or some leadership-requested legislation, CBO focuses on fiscal budget impacts, costs to the government. This may include private sector considerations to the degree tax revenue impacts are significant and tractable. But to the degree regulatory impacts are considered it’s to explicitly acknowledge that the bill imposes a new regulatory requirement or not. Certainly not quantifying benefits and costs.
Still a good idea? Sure. But in the extensive discussion prior to this, the consistent theme is the difficulty of the startup view to be heard. Further that structural incentives are such that large incumbents systematically drive policy anyway. Changes to CBO rules would be commendable and an oddly misappropriated use of the startup’s limited resources.
OIRA’s reviews are just that, reviews. They help consider regulatory impact assessments (RIAs) written by agencies on rules they are promulgating and don’t produce analyses, BCA or otherwise. But I’m being precious.
RIAs do include small firms impacts, much of which is done pursuant to statutory requirements. The Small Business Administration also weighs in to improve this assessment and “lobby” that this impact receives maximum consideration in developing the final policy. Could these be done for a wider scope of rules? Sure. Could they be better? Absolutely. I’m not sure what operable policy change, certainly as lobbied by a startup coalition, would meaningfully accomplish this. Also, somewhat inconsistently applied, but consideration on innovation and firm entry by startups is an explicit criteria for the biggest rulemakings, especially when evaluating alternative regulatory approaches.
If they wanted to find a place to push in this direction where it may actually have an impact, they could consider any of the several regulatory/APA reform bills I was quarterbacking years ago.
No argument, but if they are in fact referring to the “notice” stage of rulemaking and that which follows, agencies don’t solicit or suppress perspectives. The notices are publicly published on the same central website, available simultaneously to anyone (and API yadda yadda). Yes individuals within an agency might call their allies to remind them of the posting—possibly extraneous effort since the large firms already have the infrastructure and resources to continually monitor I suppose—but doing so institutionally is not typically consistent with good form, not only because it’s a legal risk in later litigation. Though they could be thinking of formal rulemaking, which are rare but incredibly fulsome, and do require inviting parties to directly participate in the process.
Like much of what comes before it, these suggestions are not offensive and likely productive as far as they go. Unfortunately they are facile or betray a misunderstanding of the processes they seek to improve.
All that said, as they helpfully point out (and I was able to verify) low and no cost AI tools give startups a credible way to keep track of the policy arena without having to sacrifice time on their core mission.
So monitor on startups!
QED
The expected benefit/cost of capricious and unpredictable WH “voluntary” restrictions on frontier model release is partly downstream from absence of a statutory framework. State laws have no nexus here.
As I’ve written elsewhere:
Observing a surge of interest in a novel topic is not unusual (e.g., recent examples: AVs, crypto). Moreover many of those and the current AI ones are not substantive in nature, certainly not regulatory by any measure. Some are even favorable: e.g., DOT will study infrastructure needs for widespread AV adoption; parks department will purchase and pilot an AV for future fleet; the state agencies will develop a plan to accept crypto payments for certain official uses. Beyond the non-passage rate in each case exceeding 95%, how many were (1) never going past intro in earnest, (2) had no substantive regulatory impact (in making a patchwork, the fabric can’t be entirely threadbare); or (3) actually encouraging (either money, avenues for deployment, updating existing laws to put new tech equal footing with old)?
Id. It’s like, no one tracks all patent activity.
Unfortunately it's been scrubbed from the web but we even did a committee report to this end: Majority Staff Report, Direct From the Source: Understanding
Regulation From the Inside Out, S. Comm. on Homeland Sec. &
Governmental Affairs, 114th Cong. (Jan. 15, 2016).
See, e.g., TAKE IT DOWN Act.
It certainly would’ve simplified things.
The policy conversation around technology typically features two well-resourced sides: incumbent firms advocating for frameworks that work for them, and tech-skeptical organizations pushing for stricter oversight.
This is demonstrably untrue and plenty of wonk/think tank discourse pushes in the other direction. If this were structurally true, Silicon Valley wouldn’t exist because incumbent firms would’ve exercised this policy leverage to smother challengers. Yes, they do this sometimes, but this is a clear overstatement.






