A July 2026 arXiv preprint proposes reframing AI's societal-scale harms as externalities and collective action problems [S1]. The authors argue that embedding general-purpose models across downstream systems creates cascading risks no single company can prevent alone, and they name the specific phenomena, from algorithmic monocultures to network effects, driving this. If the framework catches on, it could change how regulators and firms assess AI risk from the ground up. The question is whether a conceptual paper with no empirical data can do that.

The definition gap

The paper, posted to arXiv on 21 July 2026 under cs.AI and cs.LG, starts with a striking admission: the field lacks a universally accepted definition of systemic risk, whether in general or for AI specifically [S1]. Different researchers and regulators use the term in different ways. The EU AI Act's application of a systemic risk approach to human rights and fundamental rights is, according to the authors, relatively new [S1]. So is research into how AI contributes to systemic discrimination, privacy violations, erosion of democracy, and environmental degradation [S1].

This matters because the variety of concepts could prevent responsible actors from properly evaluating systemic AI risks, which would result in insufficient prevention, mitigation, and governance [S1]. If you cannot agree on what a systemic risk is, you cannot build rules around it.

From model failures to system failures

The core argument is that conventional AI risk thinking focuses too much on individual models and not enough on the systems they get built into. When general-purpose AI models, the large foundation models that power chatbots, coding assistants, and search tools, get integrated into downstream systems, they create new forms of risk that are systemic in nature [S1].

The authors argue that existing concepts have not sufficiently accounted for complexity and emergence [S1]. Emergence here means something specific: harms that appear only when many parts interact, harms that no single component produces on its own. Think of traffic jams. No single car causes a traffic jam. The jam emerges from the interaction of thousands of cars, each following its own logic. This paper applies the same logic to AI systems.

The three engines of systemic risk

The paper identifies several phenomena it says drive systemic AI risk:

  • Feedback dynamics, where outputs of AI systems become inputs for the next cycle, amplifying errors or biases over time [S1]
  • Market concentration through network effects and algorithmic monocultures, where many organisations rely on the same underlying model, so a single flaw propagates everywhere at once [S1]
  • Integration across AI supply chains and societal sectors, where dependencies between systems create cascading risks [S1]

These phenomena can produce structural dominance, interdependencies between actors, and cascading risks, according to the authors [S1]. The paper also names information asymmetries, informational emergence, and gaps in governance and institutional frameworks as further contributors [S1].

The framing is deliberate. By casting systemic AI risks as externalities (costs imposed on parties who did not choose to bear them) and collective action problems (situations where individual rational choices produce a bad outcome for everyone), the authors borrow from economics and political science. These are well-studied categories with known policy tools, from carbon pricing to financial regulation. The paper does not prescribe specific tools, but the framing implies that AI governance might need the same architecture.

What it means

The paper's central contribution is a shift in perspective. Most AI risk discussion asks whether a model is safe. This paper asks whether an ecosystem is safe. The difference matters because a model can pass every safety test in isolation and still contribute to systemic harm when thousands of organisations deploy it in ways that create interdependencies.

Algorithmic monoculture is the clearest example. If a hospital, a bank, an insurer, and a government agency all use the same foundation model for decision-making, a bias in that model becomes a bias across the entire economy. No single organisation caused it. No single organisation can fix it. That is a collective action problem in the textbook sense.

The paper also connects to a live regulatory question. The EU AI Act already uses systemic risk language for general-purpose AI models, and the authors note this application to fundamental rights is relatively new [S1]. If regulators adopt the externality and collective action framing, it could push governance toward systemic interventions: mandatory model diversity requirements, supply chain risk reporting, or sector-level stress tests rather than just model-level audits.

What it means for business

For a two-person firm building tools on top of a foundation model API, the paper's framing signals a direction regulators may move. If systemic risk thinking takes hold, the firms that distribute models could face obligations to report how their models are used downstream, or to maintain diversity in their model offerings. The small firm building on top would feel this through new compliance terms in their API contracts, not through direct regulation.

For a mid-sized company deploying AI across hiring, lending, or customer service, the concept of algorithmic monoculture is a practical risk. If every department uses the same model and that model has a blind spot, the blind spot shows up everywhere. The paper's framing suggests that diversifying models across functions, or at least auditing for shared failure modes, could become a governance expectation rather than a best practice.

For AI labs themselves, the externality framing is uncomfortable. It implies that the cost of a model's flaws may be borne by society at large, not by the lab that built it. That is the same logic that led to emissions standards for cars and safety standards for pharmaceuticals. Whether AI governance follows that path depends on whether regulators adopt this conceptual lens.

What we don't know yet

The paper is a preprint, version 1, and has not been peer-reviewed [S1]. It proposes a conceptual framework but provides no empirical data or case studies to validate it. The phenomena it names, from algorithmic monocultures to cascading risks, are identified as theoretical drivers, not verified instances of harm.

The authors' claims about the novelty of research areas and the lack of accepted definitions are their own assessments of the literature, not externally corroborated facts [S1]. Whether the research community and regulators will adopt this framing is unknown. The paper does not test its framework against any real-world AI deployment.

The next concrete signal to watch is whether peer review accepts or revises the framework, and whether regulators drafting AI governance rules cite the externality and collective action framing. The EU AI Act's implementing acts for general-purpose AI, still being developed, are one place this language could surface.

If this kind of analysis is useful, subscribe to keep reading. Each week we break down the research and regulation reshaping how AI is built, deployed, and governed.

Sources

More from Not A Tech Guy


Generated from an audited evidence pack with primary-source research. Social-media items are discussion signals, not verified facts. Nothing here is financial, legal or medical advice.