The G20 Innovation Ministers meeting in North Carolina this week was supposed to be a routine diplomatic gathering. Instead, it became the stage for a quiet coup. The United States arrived with a document called the "Carolina Principles" — a non-binding framework designed to export its domestic "light-touch" AI policy to the world. Elon Musk and David Sacks spoke on day one. Sam Altman and Jensen Huang took the podium on day two. The message was unmistakable: this is not a policy discussion. It is a power play.
Let me be clear about what is happening here. The US is not trying to build consensus. It is trying to capture the definition of what constitutes reasonable AI governance before anyone else can. And the choice of venue is deliberate. The G20 covers the world's major AI economies, and its consensus-based decision-making means a small minority cannot easily block a proposal. This is a structural advantage the EU does not have.
For context, the EU spent years constructing the AI Act — a risk-based, legally binding framework that imposes strict obligations on high-risk systems. It is comprehensive, principled, and largely untested. The US approach is the opposite: avoid new regulators, rely on existing industry watchdogs, and let government and companies test new technologies together. The Carolina Principles are the international version of the White House's March decision not to create a federal AI regulator. This is the Trump administration's domestic policy, repackaged for export.
The strategic logic is sound. Soft law is easier to accept than hard law. A non-binding set of principles lowers the barrier to consensus, especially for countries that are wary of locking in regulations while the technology is still evolving. The US is betting that a flexible framework will attract more adherents than the EU's rigid one. It is a classic "soft power" move — and it is working.
But here is where my skepticism kicks in. Based on my years auditing smart contracts during the ICO boom, I learned that the absence of rules is not the same as the absence of risk. It just means the risk is deferred. The Carolina Principles prioritize innovation speed and industrial competitiveness over precaution. They assume that market forces and voluntary corporate responsibility can correct AI's failures. History doesn't support that assumption. We saw the same logic in crypto — "move fast and break things" — and it ended with billions in losses and a regulatory crackdown that made the original rules look mild.
The "government and industry co-testing" provision is particularly troubling. On the surface, it sounds pragmatic. In practice, it creates a conflict of interest. Companies should not be writing the rules for their own stress tests. Without independent third-party oversight, this becomes self-certification dressed up as collaboration. I have seen this movie before. In DeFi, protocols that audited themselves were the ones that got exploited. The audits that mattered were the ones conducted by independent firms with no stake in the outcome.
There is also a deeper structural problem. The framework's reliance on existing sectoral regulators — the FTC, the FDA, the SEC — ignores the cross-cutting nature of AI risk. A single foundation model can be used in healthcare, finance, and content generation simultaneously. Fragmented oversight cannot address systemic risks that span industries. The EU's risk-tiered approach, for all its flaws, at least acknowledges this complexity. The Carolina Principles, as described, do not.
Now, let me address the competitive dynamics, because that is what this is really about. The US is not just proposing a framework; it is building a coalition. By bringing in Japan, South Korea, India, and Australia — countries with AI-friendly tech sectors — the US can create a "coalition of the willing" that marginalizes the EU's stricter approach. The presence of Musk, Altman, and Huang is not ceremonial. It is a signal to the international community that America's AI industry stands behind this framework. The EU has no equivalent industrial backing for its regulatory narrative. That is a significant asymmetry.
There is also a hidden implication in the "co-testing" clause that deserves scrutiny. Government and industry collaboration on AI testing could become a channel for data access. In the name of national security, governments might gain technical details and datasets from private companies. That has legitimate uses, but it also opens the door to industrial espionage. The line between security and surveillance is thin, and this framework does not address it.
For investors, the implications are mixed. A light-touch framework reduces policy uncertainty, which is generally positive for AI valuations. It lowers compliance costs — the EU's AI Act could cost companies 1% to 3% of revenue for high-risk systems. If the Carolina Principles become the global standard, those costs disappear. That is a direct boost to the bottom line for companies like OpenAI, Anthropic, and xAI. It also signals to the capital markets that the US AI industry and policymakers are aligned, which strengthens confidence in the sector.
But there is a darker side. Reduced regulatory barriers mean more unproven AI systems enter the market faster. That increases the risk of a major safety incident — a catastrophic model failure, a massive data breach, or an autonomous system causing real-world harm. If that happens, the regulatory pendulum will swing back hard. The backlash will not be measured. It will be brutal. And it will hurt the very companies that benefit from the light-touch approach today.
There is also a risk that the framework becomes a hollow document. Non-binding principles without enforcement mechanisms often end up as aspirational statements. Countries may sign on, then do whatever they want domestically. That would fragment global AI governance further, not unify it. The "race to the bottom" scenario is real: if major AI powers adopt light-touch regulation, companies will migrate to the most permissive jurisdictions, creating a regulatory arbitrage that undermines safety standards everywhere.
What the report does not answer is how the EU will respond. Will it treat the Carolina Principles as a direct challenge to the AI Act? Will it propose an internationalized version of its own framework? And what about China? As a G20 member, China has its own AI governance model — algorithm filing, large model approval — which is stricter than the US approach. If the G20 adopts the US framework, Chinese AI companies face a "regulatory gap" when expanding overseas. They would need to adapt to a more permissive environment, which might trigger security reviews in host countries.
The December G20 Leaders' Summit is the real test. If the Carolina Principles are incorporated into the joint declaration, they gain the highest level of international political endorsement. That would be a decisive victory for the US approach. If not, the framework remains a statement of intent, not a rulebook.
Here is my contrarian take. The light-touch framework might actually be a trap for the US. By pushing for minimal regulation, the US is betting that its companies can self-regulate. But the evidence from the last decade suggests otherwise. OpenAI, Google, and Meta have all had high-profile AI failures — hallucinations, bias, data leaks. Market discipline has not corrected these issues. If the US succeeds in making light-touch the global standard, it will own the consequences when the next major AI incident occurs. The EU, by contrast, can point to its precautionary approach and say, "We told you so."
The "co-testing" provision could also backfire. If government and industry collaborate too closely, it blurs the line between regulator and regulated. That erodes public trust in the independence of oversight. In the long run, that trust is more valuable than any short-term competitive advantage.
What is missing from this framework is a commitment to AI safety research funding. The US has no equivalent to the EU's investment in safety infrastructure. The NIST AI Risk Management Framework is a good start, but it is voluntary. Without mandatory safety standards, the Carolina Principles are just a wish list.
So where does this leave us? The September meeting is the opening move. The December summit is the endgame. If the principles pass, we will see a global shift toward lighter AI regulation, faster deployment, and higher systemic risk. If they fail, we will see a fragmented governance landscape with the US and EU offering competing visions.
My advice to investors is to watch the December summit closely. The outcome will determine the regulatory environment for the next three to five years. And my advice to policymakers is to remember that the goal is not to make AI regulation easy. It is to make AI safe. Those are not the same thing. The Carolina Principles, as currently framed, confuse the two. That is a mistake we will pay for later.
The G20 is a stage. The real play is happening behind the scenes. And the script is not yet written.


