The Garage Bomb Paradox: Why AI Risk Gets a Pass at Scale—And What That Means For Your Business
- Andrei Raileanu

- Jun 16
- 8 min read
By Andrei Raileanu — The AI Whisperer
If you build a bomb in your garage, you go to prison—even if it never explodes. Even if you never intended to use it. The attempt itself is the crime. If a company builds an AI system that its own researchers estimate carries a measurable, non-trivial chance of catastrophic failure, they get a Series C round and a seat at Davos.
This isn't a paradox. It's a preview of how AI regulation actually works—and it should concern small companies far more than it concerns the giants the headlines are about.
The Question Nobody Asks Out Loud
Here's the uncomfortable comparison: a person assembling explosives in a garage faces immediate legal consequences regardless of outcome, because the law treats intent and capability as sufficient grounds for action. Meanwhile, AI labs have published, in public, internal estimates of catastrophic risk that would be unthinkable in any other industry—and the response from markets, governments, and media has been investment, not indictment.
Why does scale flip the moral calculus?
The answer isn't comforting, and it isn't really about ethics. It's about power, utility, and who writes the rules.
Why the Comparison Isn't Quite Fair (And Why That Matters)
Before going further, it's worth being honest about where the garage bomb analogy breaks down—because the place it breaks down is exactly where the real risk to your business lives.
A bomb has one function: destruction. There's no version of a pipe bomb that also cures cancer. AI is structurally different. The same architecture that could, in a worst-case scenario, cause catastrophic harm is also the architecture diagnosing tumors earlier, optimizes energy grids, and accelerates drug discovery. This is what researchers call dual-use technology, and it's not a clever excuse—it's a genuine technical reality.
This is why the law can't simply ban AI research the way it bans bomb-making. The benefit and the risk aren't separable components that you can strip out. They're the same system.
But here's what that technical reality gets used for, and this is where things turn from philosophy to business strategy: the inseparability of risk and benefit becomes the justification for a regulatory structure that protects whoever already has scale—and crushes whoever doesn't.
The Mechanism: How "Dangerous" Becomes a Moat
Max Weber's century-old observation about the state still explains a lot here: governments don't actually punish risk itself. They punish risk that comes without systemic benefit and without centralized control. A small, unauthorized actor producing pure destructive potential gets neutralized. A large, visible actor producing a "universal engine"—something that could fuel economic growth, scientific breakthroughs, and geopolitical advantage—gets accommodated, even when the stated risk is severe.
This isn't a uniquely American or uniquely tech phenomenon. It's how power has always negotiated with catastrophic-but-useful technology, from nuclear energy to genetic engineering.
What's different about AI is the speed at which this dynamic is being formalized into law—and the specific shape that formalization is taking.
Look at how AI regulation has actually been drafted over the past two years. The EU AI Act's risk tiers, the various compute-threshold proposals discussed in 2023 and 2024 US policy circles, the licensing frameworks floated by major labs themselves—nearly all of them define "high risk" or "frontier risk" using thresholds that only apply to organizations operating at massive scale. Training runs above a certain compute threshold. Models above a certain parameter count. Deployment at a certain user volume.
These thresholds were, in many cases, proposed by the very companies the rules would supposedly constrain.
That's not an accident, and it's not hypocrisy in the conventional sense. It's a rational strategic move with a name: regulatory capture. When an industry helps write the rules that govern it, the rules tend to formalize the existing leaders' position while raising the cost of entry for everyone below them.
Three Reasons This Happens (And Why It's Not Going Away)
1. Transparency gets mistaken for responsibility
When a major AI lab publishes a safety framework acknowledging catastrophic risk, the implicit message is: "We told you. We're the responsible ones." This functions as a liability shield and a credibility signal simultaneously. But disclosing a risk is not the same as reducing it, and it is most certainly not the same as being subject to the same legal standard a smaller actor would face for equivalent risk.
2. The geopolitical excuse is structurally unfalsifiable
"If we slow down, someone with worse safety standards will build it first" is the most common justification for continuing high-risk AI development despite acknowledged danger. This argument can never be definitively proven or disproven, which makes it permanently available as a rationale—and it conveniently applies only to organizations already racing at the frontier. A 12-person startup building a vertical AI tool has no geopolitical stakes to invoke.
3. Compliance cost is a fixed cost, and fixed costs favor the large
A €150,000 governance framework (the kind I've written about as a baseline for serious AI deployment) is a rounding error for a company with venture funding in the hundreds of millions. For a 15-person company doing €2M in annual revenue, it can be existential. When regulation mandates audit trails, compliance officers, model documentation, and formal sign-off processes, it doesn't reduce risk proportionally to company size—it reduces competition proportionally to company size.
This is the part that should actually concern you, regardless of how you feel about AI safety philosophy.
What This Means If You Run a Small or Mid-Sized AI Business
If you're building AI products as a smaller company—whether that's a vertical SaaS tool, an agency offering AI-powered services, or a startup integrating AI into an existing product—the regulatory environment being constructed right now was not designed with you in the room.
The compliance frameworks emerging from AI Act implementation, from state-level AI legislation in the US, and from industry self-regulation initiatives are being shaped primarily by organizations that can afford to shape them. That doesn't make the resulting rules wrong. Many of the underlying concerns are legitimate. But it does mean the rules will tend to be structured in ways that are survivable for large incumbents and burdensome for everyone else.
Here's the strategic response, and it's not "lobby against regulation" or "ignore compliance and hope for the best."
Get ahead of governance before it's mandated, not after.
The framework I've outlined in previous pieces—structural integrity checks, security auditing, compliance verification, human review—isn't just risk mitigation against lawsuits or fines. It's positioning. A small company that can credibly demonstrate governance maturity is harder to regulate out of existence, because "we already do this" is a much stronger position than "we'll figure it out once it's mandatory."
Three concrete moves:
Document your AI decision-making now, before you're required to. When compliance requirements eventually formalize—and they will, on a timeline you don't control—companies with existing documentation trails adapt in weeks. Companies starting from zero face months of retroactive reconstruction, often under regulatory deadline pressure.
Treat compliance cost as a competitive signal, not just an expense. If you can demonstrate ISO-aligned quality processes, security auditing, and human review at a fraction of what a large incumbent spends, that's a sales argument—particularly with enterprise clients who increasingly ask about AI governance during procurement.
Watch which thresholds get proposed, and ask who benefits. When you see a new AI regulation proposal, look specifically at the size, compute, or revenue thresholds it uses to trigger obligations. If those thresholds conveniently exempt the companies that helped draft the proposal while capturing companies at your scale, that's worth factoring into how you engage with industry associations and policy conversations—even as a small player with limited lobbying power.
The Honest Conclusion
The garage bomb comparison isn't really about whether AI labs are acting unethically by continuing development despite acknowledged risk. Reasonable people disagree on that, and the dual-use nature of the technology makes it a genuinely harder question than the simple "they should be in prison" framing suggests.
The more useful question—the one that actually affects your business—is who gets to define acceptable risk, at what scale, and through what enforcement mechanism. Right now, that definition is being written largely by the organizations with the most resources to influence it, and the resulting frameworks have a strong tendency to formalize existing power rather than meaningfully reduce catastrophic risk.
You don't control that dynamic. But you can control whether you're caught flat-footed by it.
The companies that survive the next wave of AI regulation won't be the ones who argued loudest against it. They'll be the ones who built governance into their operations early enough that the new rules feel like documentation, not disruption.
❓ Frequently Asked Questions (FAQ)
1. Isn't this just an argument against AI regulation entirely?
No. The argument isn't that regulation is bad—it's that the current trajectory of regulation tends to favor incumbents by using scale-based thresholds that exempt the largest players from the practical burden they helped design. Good regulation is possible; the question is whether smaller companies have a voice in shaping it, and whether they prepare for it proactively, regardless.
2. As a small company, can I actually influence these regulatory thresholds?
Individually, rarely. Collectively, sometimes, through industry associations, public comment periods on proposed legislation (the EU AI Act and various US state proposals have had formal comment windows), and trade groups representing SMEs rather than enterprise vendors. The more realistic strategy is preparing for the rules as proposed rather than betting on changing them.
3. How do I know if a proposed regulation will hurt or help my business?
Look at the trigger thresholds: compute used in training, number of users, revenue, or model parameter count. If the threshold sits comfortably above where you operate, you're likely exempt from the heaviest requirements—but watch for "voluntary" industry standards that become de facto requirements for enterprise sales even without legal mandate.
4. Does building governance now actually help if the rules aren't finalized yet?
Yes, for two reasons. First, enterprise clients increasingly ask about AI governance during procurement regardless of legal requirements—it's becoming a sales differentiator. Second, retrofitting documentation and audit trails after a regulation takes effect is significantly more expensive and disruptive than building them incrementally from the start.
5. Is the "geopolitical race" justification for continued high-risk AI development legitimate?
It contains a real strategic logic—unilateral restraint by one actor doesn't guarantee restraint by competitors or rival nations. But it's also a justification that, by its nature, can never be disproven and conveniently applies almost exclusively to frontier labs racing at massive scale. For a smaller company, this argument has essentially no relevance, which is itself a sign of how unevenly the risk conversation applies across company size.
📚 Context & Further Reading
This piece draws on concepts from political philosophy, regulatory economics, and AI policy:
Political Philosophy & Power
Max Weber: "Politics as a Vocation" — the state's monopoly on legitimate violence and the conditions under which risk is tolerated versus punished.
Regulatory Capture
George Stigler (1971): "The Theory of Economic Regulation" — foundational economic analysis of how industries shape regulation to favor incumbents.
EU AI Act compute thresholds and risk-tier definitions: Regulation (EU) 2024/1689, particularly provisions distinguishing "systemic risk" models by training compute.
Dual-Use Technology & AI Risk
Existing AI governance framework (Parts 1-4 of this site's AI Governance series): Structural integrity, security auditing, compliance verification, and human review as a practical baseline—relevant here as the compliance cost referenced in the regulatory capture discussion.
About the Author
Andrei Raileanu — The AI Whisperer
Helping entrepreneurs build AI businesses that survive scale and survive scrutiny. Founder of HumanAILabs.org, where governance isn't an afterthought—it's the foundation.
Connect: LinkedIn | andreiraileanu.eu
Related Reading:
Published on andreiraileanu.eu | June 2026

Comments