One of my favourite things about the early days of motoring in Britain is that, for a while, the law required someone to walk in front of your car carrying a red flag.
Imagine you’ve splurged on the latest motorcar and a shiny new pair of goggles (windscreens came later), only to discover your first major upgrade was… another pedestrian. It sounds faintly ridiculous now, but it wasn’t ridiculous then: cars were new. At a top speed of around 20mph they were faster than almost anything people had encountered before. Roads weren’t designed for them, nobody had driving lessons, there was no Highway Code, no speed limits, no traffic lights, no seatbelts, no crash barriers, no MOTs and precious little understanding of what happened when a few tonnes of wood and metal met a stone wall.
The red flag wasn’t the finished solution; it was society buying itself time while it worked out a better one, because we hadn’t anticipated anyone would ever move this fast – so we couldn’t conceive of the safety measures we would need to invent to work around it.
I wonder if we’re in our own red flag era
Not just with AI, but with social media, online safety and a whole collection of technologies that have developed faster than our ability to decide how they fit into everyday life. The recent debate about new restrictions for young people using social media in the UK and elsewhere is a good example. People have very different views about where the balance should sit, but I suspect we’re asking exactly the sort of questions societies have always asked when a technology becomes both widely used and unexpectedly risky.
How much freedom? How much protection? Who’s responsible when things go wrong? What are the penalties, and how can we enforce them? Who should change their behaviour? How much education is enough, and when do we need rules?
None of those questions are new; only the tech is. Every major shift seems to follow a familiar pattern: something extraordinary arrives, some people delight in the possibilities, others fear the unintended consequences, and a small but significant number immediately work out how to exploit it for nefarious purposes. Someone announces civilisation is over; someone else insists there are no risks whatsoever. Then, gradually, we stop arguing about the technology itself and start building the infrastructure that lets the rest of us use it safely.
The inevitable lag between innovation and safety
Cars eventually brought us driving tests, insurance, road markings, learner plates, seatbelts, speed cameras and the Green Cross Code man. Electricity led to plugs that children can’t poke their fingers into, circuit breakers and building regulations. The printing press didn’t just give us Shakespeare; it also gave us propaganda, scams, libel and every flavour of dubious medical advice imaginable. Then it took centuries for journalism, editors and libel law to evolve alongside it.
More recently, the internet has given us spam filters, two-factor authentication and passwords that, according to every cyber security expert I’ve ever met, are still not nearly complicated enough. Tech arrives first, good advice arrives later.
Modern AI risk frameworks are our latest attempt to retrofit some structure onto systems that are already out in the world. They’re about deliberately understanding where AI is being used, what risks it creates and how those risks should be managed, rather than just hoping for the best.
That’s worth remembering because it’s tempting to imagine every new challenge as unprecedented, but the situation is another version of a problem humans have solved before. Although not perfectly, as a rule. We still crash cars, click suspicious links and publish libelous nonsense. But generally we’ve solved these problems well enough that the safety systems become almost invisible. And that’s actually the goal: successful safety is boring. Nobody wakes up in the morning marvelling at pedestrian crossings.
Which brings us – at last – to AI
The interesting question isn’t whether AI or social media need guard rails because of course they do. The interesting question is what those guard rails should look like. History suggests a few useful principles:
First, safety features tend to start out… a bit weird, before becoming more proportionate. The answer wasn’t permanently requiring someone to walk in front of every car carrying a flag; it was gradually designing a whole system that allowed millions of people to drive safely most of the time. Better roads. Better vehicles. Better rules. Better education. Shared expectations about what responsible behaviour looks like. But the red flag was valid because it was a signal that society had recognised there was a genuine problem to solve. It wasn’t the destination; it was a stop gap.
Second, we gradually get better at placing responsibility where it belongs. We don’t ban everyone from driving because some people speed: we expect people to pass a test, follow the rules and face consequences if they don’t. We’ve also extended responsibility to designers and manufacturers. It isn’t just your fault if the brakes fail.
Finally, education matters just as much as regulation. Maybe more. Driving safely isn’t just about laws, which is why it’s not enough to ask what the government is doing about it when things go wrong. It’s about learning hazard perception, decoding signs, having ‘don’t drink and drive’ etched permanently into your brain and developing judgement.
I suspect AI will be much the same: we’ll need sensible regulation, and we’ll need organisations to take responsibility for the systems they build. We will also need consequences for people who deliberately misuse powerful tools rather than endless restrictions on everyone who doesn’t.
And AI is increasing the urgency of all this by making social media’s rabbit holes deeper, quicker to fall into and more convincing. It’s like trying to design safety features for cars while they’re doubling in speed every month.
So what?
If you’re introducing AI into your organisation, I’d borrow a lesson from the red flag era.
- Treat your first controls as prototypes, not permanent fixtures.
- Put responsibility on designers and decision-makers, not just end users.
- Invest at least as much in education as compliance.
- Review and adapt quickly; the technology definitely will.
The goal isn’t perfect governance on day one. It’s to move, deliberately and proportionately, from red flags to a system.
Don’t panic
Perhaps most importantly, we’ll need people who understand enough to use AI thoughtfully rather than fearfully. The mistake would be to only see today’s debates as evidence that something has gone badly wrong and assume it’s the thin end of a hefty wedge, but it’s also evidence that something rather familiar is happening: society is catching up.
We’ve started moving from “anything goes online” towards duties of care and clearer expectations for platforms. We’re now beginning the same journey with AI. And good safety features eventually disappear into the background. We don’t consciously think about wearing a seatbelt, giving way at roundabouts or looking both ways before crossing the road. Those behaviours feel like common sense now, but they had to be invented, taught and, for a while, more firmly enforced.
AI is still in that awkward adolescent phase where very little feels like common sense yet. Most people simply don’t know enough about the technology to keep themselves safe all of the time, or to recognise when the systems around them are unsafe. That’s why governments, regulators and organisations are stepping in. Not because they’re the perfect long-term answer, but because society hasn’t yet developed the shared instincts that eventually make those guard rails feel almost invisible.
The car wasn’t really the big social transformation, and neither was the seatbelt. The innovation that changed civilisation permanently was the transport system. We’re only just beginning to build the AI equivalent.