Slogans are not mechanisms
“We need precaution.” “Get informed consent.” “Someone should be liable.” Every debate about emerging technology reaches for these phrases within the first few sentences, and every one of them names a real, documented legal and institutional mechanism—not a mood. This article, the first in a series on ethics and governance of emerging technology, does the unglamorous work of tracing each mechanism from its origin document to its operating procedure, so that later pieces in the series can build on mechanics rather than slogans.
Three mechanisms anchor this piece: the precautionary principle as it actually functions in regulatory drafting, informed consent as it actually applies when biotechnology and AI stretch a framework built for clinical trials, and liability law as it actually allocates responsibility when an autonomous system causes harm. Around them sit five themes this series will keep returning to—rights, democratic authority, access, and intergenerational effects—which this opening piece introduces but does not resolve, because the honest answer at this stage is that no settled mechanism yet exists for several of them.
Throughout, a discipline: fact means something documented in a statute, regulation, judicial opinion, or standards text; vendor claim means an assertion made by a company about its own product; analysis means an inference this article draws from documented material; scenario means one coherent possible future among several, not a prediction; and prediction means a claim about what will happen, which this article makes only with an explicit horizon, assumptions, and a stated condition that would prove it wrong.
How the precautionary principle actually functions
The precautionary principle is often summarized as “better safe than sorry,” which is not wrong so much as useless—it gives a regulator no instruction about where to stop. The actual documented version is more specific. The 1998 Wingspread Statement, drafted by a convened group of scientists, lawyers, and policymakers, put it this way: “When an activity raises threats of harm to human health or the environment, precautionary measures should be taken even if some cause and effect relationships are not fully established scientifically” [1]. The statement adds two operational details that get lost when the principle is paraphrased: the process of applying it must be open, informed, and democratic, and it explicitly shifts the burden of proof—from those who might be harmed, who would otherwise have to prove danger before acting, onto those who propose the activity, who must instead show that it is reasonably safe.
That burden shift is the actual mechanism. It does not forbid an activity. It changes who has to produce evidence before the activity proceeds, and under what standard. In regulatory drafting, this shows up as a specific clause structure: instead of “X is permitted unless shown harmful,” a precautionary regime writes “X is permitted only once shown safe to a stated standard,” with the standard, the evidentiary threshold, and the reviewing body all specified. Genuine debates about precaution are almost always debates about where that threshold sits, not about whether caution in the abstract is good.
The most influential critique of the principle, from legal scholar Cass Sunstein, does not dispute that burden-shifting occurs; it disputes that shifting the burden onto every uncertain activity is coherent, because virtually every choice—including regulation itself—carries its own uncertain risks. Sunstein’s analysis, drawing on cases from arsenic regulation to genetically modified food, argues that a precautionary principle taken to its strongest form “leads in no direction at all,” since blocking one uncertain technology to avoid its risks can introduce different uncertain risks from the alternatives left in its place [2]. His proposed refinement—reserve heightened precaution for harms that are irreversible or catastrophic, and treat the regulatory choice as purchasing an “option” to prevent that harm later—is analysis built on documented case law, not a settled doctrine; different jurisdictions still draw this line in different places, and this article does not pick a winner between them.
What is fact, and load-bearing for everything downstream: the precautionary principle is a procedural device (who must prove what, to whom, by when) more than a substantive verdict on any specific technology. Readers who expect “precaution” to function as a stop sign are expecting something the documented mechanism does not provide.
How informed consent actually applies to emerging biotech and AI
Informed consent has a founding document, and it is worth reading past its summary. The Belmont Report, issued in 1979 by the U.S. National Commission for the Protection of Human Subjects of Biomedical and Behavioral Research, organizes research ethics around three principles: respect for persons, beneficence, and justice [3]. Respect for persons is the principle that generates informed consent specifically—it holds that individuals capable of deliberation about their own choices must be treated as autonomous agents, and that persons with diminished autonomy are entitled to additional protection. Beneficence requires that risks and anticipated benefits actually be disclosed as part of the consent process, not merely that a form exists. Justice concerns who bears research risk relative to who stands to benefit from it—a question that recurs, largely unchanged, in debates about whose data trains a model and who benefits from its deployment.
The Common Rule, the U.S. federal regulation implementing Belmont for federally funded research, turns these principles into an enumerated checklist. Under 45 CFR 46.116, informed consent must include, among other elements, a description of the research and its purposes, reasonably foreseeable risks, expected benefits, alternative procedures, confidentiality provisions, and—critically for anything ongoing—an explicit statement that participation is voluntary and can be withdrawn at any time without penalty [4]. Consent, on this framework, is not a signature; it is a sequence of disclosures that must each be met, with withdrawal treated as a standing right rather than a one-time event closed off once the form is signed.
That framework was built for a clinical trial with a defined start, a defined intervention, and a researcher who can be identified and held to account. Two features of emerging technology strain it. First, germline genome editing produces effects in a person—the future child—who cannot possibly consent to the intervention that shapes them, a problem the Nuffield Council on Bioethics addressed directly in its 2018 report on genome editing and human reproduction. The Council’s answer was not to abandon consent-based reasoning but to substitute two different anchoring principles for heritable interventions: consistency with the welfare of the future person, and a requirement that the technology not increase disadvantage, discrimination, or division in society, with the additional condition that clinical use wait until risks of adverse effects have been properly assessed and monitoring and moratorium powers are in place [5]. This is documented institutional analysis, not settled global law: the report’s own conclusions were more conditional than the “green light for designer babies” headlines that followed it, and no jurisdiction has fully operationalized the Council’s welfare-of-the-future-person standard into enforceable statute.
Second, AI systems trained on data and deployed in automated decisions do not fit the research-subject model at all—the “subject” is often someone whose data was used to train a system they never interacted with, or someone subject to an automated decision they did not request. The regulatory response has been to graft a different right onto the consent tradition: not consent to be studied, but a right to contest an automated outcome after the fact. The EU’s General Data Protection Regulation, Article 22, restricts decisions “based solely on automated processing” that produce legal or similarly significant effects, and Article 22(3) gives the data subject the right to obtain human intervention, to express their point of view, and to contest the decision [7]. This is not informed consent in the Belmont sense—it does not require disclosure before the fact so much as recourse after it—and treating it as equivalent to clinical-trial consent overstates what the regulation actually provides. It is a documented, narrower substitute built for a situation Belmont’s drafters were not addressing.
How liability law actually allocates responsibility for autonomous-system harms
When an autonomous vehicle or an automated decision system causes harm, the intuitive question—“was it the human’s fault or the machine’s?”—is not the question tort law actually asks. Comparative legal scholarship on autonomous-vehicle liability documents courts and legislatures instead asking how to divide fault among several parties who each contributed a different kind of failure: the manufacturer who designed and validated the system, the operator or fleet owner who deployed and maintained it, and in some frameworks the owner who accepted its use [9]. A 2025 comparative review of tort liability frameworks for autonomous-vehicle accidents documents this concretely: Ontario’s Negligence Act, for instance, allows courts to apportion fault by percentage across multiple parties based on their respective control capabilities, duty of care, and causal contribution to the harm, rather than assigning full liability to a single party [10].
This apportionment approach follows directly from a problem product-liability and negligence law have handled for decades: a car crash caused partly by a manufacturing defect and partly by driver error was never a binary question either, and doctrines like comparative negligence and enterprise liability already exist to split damages across contributing causes. What changes with autonomous systems is not the existence of apportionment but its inputs—instead of asking whether a driver was speeding, courts now have to evaluate whether a training dataset, a sensor specification, an override design, or a maintenance schedule caused the failure, each requiring different expert evidence and each pointing at a different defendant. Scholarship on this question also documents live disagreement rather than a converged answer: proposed alternatives include a manufacturer enterprise-responsibility model, similar in structure to workers’ compensation, that would shift most liability onto manufacturers regardless of fault in exchange for capped and faster-paid claims, an approach several comparative reviews discuss without treating it as settled law in any major jurisdiction [9].
The regulatory layer above tort law increasingly tries to shape which of these failures are foreseeable, and therefore litigable, before harm occurs. The EU’s Artificial Intelligence Act, Regulation 2024/1689, does this by classification rather than by liability rule directly: it bans certain AI practices outright, subjects “high-risk” systems—broadly, those that are safety components of regulated products or that operate in domains affecting fundamental rights or safety—to mandatory conformity requirements before deployment, imposes lighter transparency duties on other systems, and leaves the remainder largely unregulated [6]. A system’s risk tier under this regulation does not itself assign liability for a specific harm, but it does establish, as documented regulatory text, what obligations a deployer was required to meet beforehand—evidence that becomes directly relevant once a court is apportioning fault after the fact.
Two things follow, and this is analysis rather than settled doctrine: first, liability regimes for autonomous systems are converging on apportionment-by-contribution rather than either pure strict liability on manufacturers or a return to pure fault-based analysis of the human operator; second, the risk-classification regimes emerging alongside them (the EU’s tiers, sector-specific rules elsewhere) function less as liability rules themselves and more as pre-built evidentiary records that make apportionment tractable once a harm actually occurs.
Governance principles that name the values without settling the mechanism
Alongside precaution, consent, and liability sit broader statements of value that function differently—they name what should matter without specifying a procedure for adjudicating conflicts among the things named. The OECD’s 2019 Recommendation on Artificial Intelligence, the first intergovernmental AI standard, sets out five principles: inclusive growth and well-being, respect for human rights and democratic values including fairness and privacy, transparency and explainability, robustness and safety, and accountability [8]. These are documented commitments with real institutional weight—OECD recommendations shape national policy even where non-binding—but they are not, on their own, mechanisms in the sense the precautionary principle or informed consent are. Knowing that “accountability” matters does not tell a regulator who is accountable when a foundation model’s output is repackaged by a third party and causes harm three transactions downstream. That gap between naming a value and operationalizing it is precisely where the next three governance domains sit.
Democratic authority: the parts of the mechanism that already exist
Democratic authority over emerging technology is not usually exercised through a single dramatic vote. In documented regulatory practice it runs through slower, more procedural channels: public comment periods before a regulation is finalized, published dockets that make submitted objections part of the reviewable record, standing advisory bodies—like the Nuffield Council itself—that can be petitioned and whose recommendations become reference points in later legislative debate, and legislative committee hearings that create a public record independent of the eventual vote [5, 6].
What these channels can documentably do: create a public record that a regulator must acknowledge and that courts can later examine if a rule is challenged; slow down rulemaking enough that affected parties can organize; and put career civil servants and elected officials on record in a way that raises the political cost of ignoring stated objections. What they cannot do, and this is analysis rather than an established finding: guarantee that public input changes outcomes proportionate to its volume, or substitute for direct democratic control over decisions that operate at a pace public consultation was not built to match. A comment period measured in months does not obviously suit a technology whose deployed capability changes measurably within that same window—a genuine mismatch that no jurisdiction in the sources above has fully resolved.
Access and intergenerational effects: where mechanisms mostly do not yet exist
Rights, consent, and liability all have documented mechanisms with real teeth. Access and intergenerational effects mostly do not, and it would misrepresent the state of governance to imply otherwise.
On access: none of the frameworks surveyed above—Belmont, the Common Rule, GDPR, the EU AI Act, the OECD principles—contains an enforceable requirement that a beneficial technology actually reach the populations who cannot pay for it or whose language and infrastructure it was not built around. Justice, in the Belmont sense, asks whether those who bear a technology’s risks also share its benefits; it is a normative standard invoked in institutional reports and ethics reviews, but the sources here document no general statutory mechanism that operationalizes it for AI or biotechnology deployment the way informed-consent elements are operationalized for research. This is a genuine gap, not a solved problem this article can point to a citation for.
On intergenerational effects: the same is true, more starkly. Germline genome editing is the one domain among those surveyed where a documented institutional body—the Nuffield Council—has directly grappled with obligations to a person who does not yet exist and cannot be consulted, and even there the answer was a conditional welfare standard rather than an enforceable global rule [5]. For AI systems whose training data, deployed defaults, or infrastructure footprint will shape institutions decades past their release, no comparably developed doctrine exists in the sources reviewed for this article.
Scenario, not prediction: one plausible path is that intergenerational obligations get handled the way environmental law eventually handled long-horizon harms—not through a single sweeping rule but through accumulated sector-specific requirements (monitoring mandates, sunset clauses forcing periodic re-justification, dedicated review bodies with standing to revisit past approvals) that add up to a functional regime without ever being written as one statute. A competing scenario is that intergenerational effects remain unaddressed until a specific harm becomes undeniable, and regulation arrives reactively rather than in advance, as it has for several documented environmental and pharmaceutical cases discussed in the precaution literature above [2]. This article takes no position on which scenario is more likely; a genuine prediction would need a stated horizon and a disconfirmation condition, and the evidence surveyed here does not support one yet.
What this series inherits from here
The mechanics traced above are not exhaustive of ethics and governance, but they are the load-bearing ones: precaution reallocates the burden of proof rather than banning anything outright; informed consent is an enumerated sequence of disclosures and standing rights that biotechnology and AI are straining rather than simply satisfying; and liability law is converging toward apportioned responsibility across manufacturer, operator, and owner, with risk-classification regimes increasingly supplying the evidentiary record that apportionment depends on. Democratic authority operates through slow procedural channels whose fit with fast-moving technology is genuinely uncertain. Access and intergenerational effects remain the two areas where this article can document the absence of a settled mechanism more confidently than it can document one.
Later pieces in this series can now build forward from named mechanisms rather than slogans—asking, for a specific emerging technology, which burden the precautionary principle actually shifts, which disclosures a consent framework would actually require, and which parties a court would actually ask to share fault. That specificity is the discipline this opening piece exists to establish.