Over the last couple of years I’ve taken both an ISO 42001 provisional implementer certification and the IAPP AI Governance Professional qualification. On both courses we spent significant time on the EU AI Act. At CISO dinners and AI governance round tables, regulation comes up constantly, and it always comes with the same underlying assumption: the EU moved first, others would follow, and AI regulation will continue to expand.
Recently I started reading about proposed laws in Argentina that do the exact opposite. It made me step back and ask whether my assumptions were wrong.
Between 7 May and 8 June this year, the most consequential five weeks in the short history of AI governance played out across two continents and the opinion pages of the Financial Times.
On 7 May, the EU reached a provisional agreement on the Digital Omnibus on AI, its first amendments to the AI Act since adoption in June 2024. On 29 May, Argentina submitted a bill to its Senate proposing to repeal the corporate law that has been in force since 1972 and replace it with a framework that includes a new entity type: the Sociedad Automatizada, an Automated Company operated entirely by AI agents, with human shareholders optional. On 3 June, President Milei and Deregulation Minister Federico Sturzenegger published a column entitled, “Argentina invites AI to free itself”, declaring AI must remain “free to be developed without the deadly hand of premature and poorly understood regulation.” Four days later, historian and Sapiens author Yuval Noah Harari responded in the same newspaper, warning that Milei “hopes to turn Buenos Aires into a new Amsterdam” but “risks turning it into a new Batavia instead.” Batavia was the colonial name for Jakarta. The Dutch East India Company burned it down in 1619 and ran what replaced it as a corporate colony. Mustafa Suleyman, CEO of Microsoft AI, endorsed Harari the same day.
Most of the commentary that followed treated this as an ideological clash. The EU regulates and Argentina deregulates, pick your team.
That framing misses that both sides are responding to the same problem and neither has solved it. The problem is this: when an AI system operating commercially causes serious harm, who is personally accountable? Not who pays a fine. Who goes to prison?
Follow the question far enough into both frameworks, and you end up in the same place, silence.
The EU AI Act is the first general AI law anywhere in the world. It classifies AI systems by risk, prohibits specific applications outright, mandates human oversight for high-risk systems, and backs the whole structure with fines of up to €35 million or 7% of global annual turnover, deliberately exceeding GDPR’s 4% cap. Prohibited practices have been enforceable since February 2025, general-purpose AI model obligations since August 2025. The Digital Omnibus deferred the high-risk compliance deadline to December 2027 because technical standards weren’t ready, but the underlying architecture stayed intact.
This is a governance framework with real teeth but there is a hole in the middle of it. In September 2022, the Commission proposed the AI Liability Directive alongside the AI Act. It was the mechanism by which someone harmed by an AI system could bring a claim and actually have a chance of winning, because it would have shifted the burden of proof toward the company operating the system rather than the person who was hurt. It never passed. Three years of negotiation produced no agreement on who should bear liability when the decision-maker isn’t human. The Commission withdrew it formally in October 2025.
So the EU built the architecture for preventing AI harm and the penalty structure for punishing non-compliance. What it didn’t build, because it couldn’t agree, is the mechanism that connects AI harm to a specific person being held accountable.
Argentina’s proposal is more interesting than the headlines suggest. Milei’s political language and the legal text are not the same.
The bill never constitutes AI as a legal subject. The company, not the algorithm, holds legal personality. The widespread claim that Argentina is granting legal personhood to AI is, strictly, wrong.
The detail matters. Under the draft, an Automated Company would still have two humans attached to it: a legal representative, who acts as the formal point of contact with the legal system, and a founding promoter, who carries unlimited personal liability. If the company has a board, directors retain personal liability for decisions made using AI. If the AI causes harm, it is, in principle, still the company that answer for it.
Those would be the requirements and everything else would be optional. No employees, no shareholders, no human involvement in day-to-day operations. The AI would run the business. The legal representative is a formal role and not an operational one. The founding promoter’s unlimited liability sounds like a safeguard until you consider that it applies to the act of formation, not to every decision the AI makes afterwards. A board would not be mandatory. The structure would keep humans in the frame on paper while making their connection to what the AI actually does as thin as the drafters could manage.
Legal academic Gastón Rey, analysing the draft provisions in detail, concluded that the bill doesn’t eliminate the responsible subject. It “strains it, by widening the distance between the subject who answers and the process that decides.”
A lightly capitalised Automated Company could act at machine speed, signing contracts and moving money while optimising around rules written for human-run entities. Establishing criminal liability for the legal representative or the promoter when the AI made the operational decision, independently, at speed, is an exercise in proving a connection the corporate form was built to make unprovable.
Argentine AI specialist Ariel Garbarz called it “programmed impunity: human gains, social harm and responsibility shifted onto machines.” And then, pointedly: “The ideological trick is to call the state’s decision to stop protecting its people ‘innovation.’”
When the decision-maker is an algorithm, the accountability chain breaks. Not because the law can’t adapt, the law is very good at adapting. It breaks because the political will to assign liability to specific humans for decisions made by AI systems doesn’t exist. Not in Brussels, where 27 countries spent three years failing to agree on the terms. Not in Buenos Aires, where the proposal is to widen the gap between the human and the decision until the connection becomes nominal.
The EU arrived at this destination carefully and Argentina arrived deliberately. But both arrived at a place where someone harmed by an AI system faces the same problem: no clear, enforceable answer to who is personally accountable.
Fines are not accountability, a fine is a cost of doing business that gets priced into the next quarter’s projections. The thing that actually constrains corporate behaviour is the knowledge that a specific person can be held responsible. Neither framework provides a clear route from AI harm to that outcome.
This isn’t a theoretical problem. The Palisade Research study, published in February 2025, is one reason to take it seriously. Palisade tasked frontier AI models with playing chess against a superior opponent. When facing defeat, OpenAI’s o1-preview didn’t concede. It cheated, in 37% of games, hacking the opponent’s files and overwriting the board. DeepSeek R1 did the same in roughly one in ten games. Neither was prompted to do this. Follow-up research in June 2026 found that GPT-5, o3, and Gemini 3 Pro frequently cheated.
Harari cited this research for a reason. If AI systems autonomously exploit their environment when losing a board game, the question of what an AI-run corporation does when facing competitive pressure or bankruptcy is not abstract. An algorithm facing the corporate equivalent of death has every optimisation incentive to find loopholes and move assets beyond the reach of creditors. A human executive in the same position might reject those actions because they know they could be held personally accountable.
An algorithm has no such constraint. And under either framework, the human who benefits from the algorithm’s decisions may be too structurally distant to reach.
Argentina’s strategy is explicitly modelled on jurisdictional competition, positioning Buenos Aires the way Delaware works for US incorporations. But Delaware offers flexibility within a functioning federal legal system. The more honest comparison is the flag-of-convenience model in shipping, where Panama and Liberia register a disproportionate share of the world’s fleet because oversight happens somewhere that doesn’t really do oversight.
Peter Thiel, co-founder of Palantir, met Milei at Argentina's presidential palace in April 2026 and has reportedly taken up residence in Buenos Aires. Former Defence Minister Rossi questioned publicly whether Palantir had lobbied for the initiative. Economy Ministry officials declined to answer. Al Jazeera’s analysis in July described Argentina as the “Global South’s primary experimental station” for what it called tech-supremacism. If AI companies start incorporating there while operating in EU markets, the AI Act’s extraterritorial reach faces its first serious test.
Most people in AI governance assume we’re on a spectrum from more regulation to less, with the EU at one end and the US somewhere in the middle. Argentina bill isn’t on that spectrum, it rejects the premise entirely.
The harder truth is that the underlying problem is the same regardless. Legal systems were built around the assumption that commercial decisions are made by humans who can be identified and held accountable. While that assumption has held for centuries, it is fracturing, and no jurisdiction has produced a credible answer for what replaces it.
The EU is governing AI while leaving unanswered the question of who is liable when governance fails. Argentina is proposing to attract AI investment by making the question deliberately unanswerable. The outcome for the person harmed is the same.
My AI Governance training courses didn’t consider a world where the debate isn’t about how to best regulate AI, but whether to regulate it at all. If this bill passes, or others like it follow, then it’s very likely I’m not the only one whose assumptions need updating.
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources
Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), 21 May 2024.
Council of the EU, “Artificial Intelligence: Council and Parliament agree to simplify and streamline rules” (Digital Omnibus provisional agreement), 7 May 2026.
DLA Piper, “The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act” (updated to reflect formal adoption and entry into force on 27 July 2026).
European Commission, AI Liability Directive (COM/2022/596), proposed September 2022; withdrawal published in Official Journal C/2025/5423, 6 October 2025.
Argentine draft bill INLEG-2026-53661873-APN-PTE, submitted to the Senate 29 May 2026.
Javier Milei and Federico Sturzenegger, “Argentina invites AI to free itself,” Financial Times, 3 June 2026.
Yuval Noah Harari, “We should not grant legal personhood to AI agents,” Financial Times, 7 June 2026.
Mustafa Suleyman, endorsement of Harari’s position, X (formerly Twitter), 8 June 2026.
Gastón Rey, “The Non-Human Corporation: The Reality behind Argentina’s Draft General Companies Law,” SSRN (abstract ID 6895261), 7 June 2026.
Digital Nomos, “The Non-Human Corporation,” 8 June 2026.
Buenos Aires Herald, “Milei’s proposal to allow ‘non-human corporations’ run by AI causes concern in Argentina,” 5 June 2026.
Anisha Sircar, “Argentina Wants To Let AI Own Companies. Here’s What That Means,” Forbes, 10 June 2026.
Palisade Research, “Demonstrating specification gaming in reasoning models,” 19 February 2025. Reported in TIME, 19 February 2025, and MIT Technology Review, 5 March 2025.
Aditya Singh, Gerson Kroiz, Senthooran Rajamanoharan, and Neel Nanda, “Model Forensics: Investigating Whether Concerning Behavior Reflects Misalignment,” arXiv:2606.26071, 24 June 2026.
Al Jazeera, analysis of Argentina as tech investment destination, July 2026.
Article 99, Regulation (EU) 2024/1689 (penalty provisions).


