Executive Summary
A Small Shift With a Potentially Massive Impact
Technology has reshaped the economy, the political order, and the private formation of individual people, and the curve is steepening. The technology ethicist has never been more needed — or more poorly equipped, because well-argued principles keep losing to market incentives. If they could not constrain the platforms of 2015, they will not constrain the systems of 2030. This study argues for an ethics that can survive contact with the system. In brief:
- Understand what is before what ought. The indicative before the imperative — the incentives, mechanisms, and money before the prescriptions.
- Section 230 is the cautionary tale. A law meant to empower families became the internet's liability shield — the opposite of its stated purpose, and a catalog of how technology legislation fails.
- The real levers are unevenly used. Europe leads (GDPR, DMA, DSA, the AI Act); US federal action is sparse; states are active; and communities are resisting data centers from the ground up.
- Policymakers are flying blind. Congress dismantled its own technical advisory office — the OTA — in 1995, and the vacuum fills with lobbying or with nothing.
- Technology owes no duty of care. Every serious profession does — and the moral architects of a product are usually the product managers, not the engineers.
- What to do. Build a duty of care, rebuild information exchange, deepen technical expertise, and empower the states.
Section 1
A Short History of Technology Ethics
Technology ethics is not new. Norbert Wiener's The Human Use of Human Beings (1950) named the danger of systems that amplify human will without amplifying human wisdom — a generation before such systems existed at scale. The field took recognizable shape in the late 1980s and 1990s, as the personal computer and then the internet arrived. Computer ethics established the first working vocabulary of privacy, access, and intellectual property; bioethics lent its procedural models of institutional review and informed consent; the IEEE wrote codes for engineers; universities built centers and curricula. The field was serious and well-organized long before the systems that would truly test it were built.
There is a more useful way to divide this history than by decade. The line that matters falls around 2007, with the smartphone and the engagement feed. On one side lies the pre-attention era, when the object of concern was mostly data — who held it, who could see it, who could sell it. On the other lies the attention era, when the object of concern became the shape of a person's day.
The Pre-Attention Era
It is easy to forget how actively the United States once legislated technology. Across three decades, Congress returned to the subject again and again:
- the Fair Credit Reporting Act (1970), which gave people rights over the files that machines kept on them;
- the Privacy Act of 1974, which constrained what the federal government could do with its own records;
- the Cable Communications Policy Act (1984), which wrote privacy rules for a new distribution medium;
- the Electronic Communications Privacy Act (1986), which extended wiretap protections to digital messages;
- the Computer Fraud and Abuse Act (1986), the first serious federal computer-crime statute;
- the Video Privacy Protection Act (1988), passed after a Supreme Court nominee's video-rental history was published;
- and the Telecommunications Act of 1996, whose V-chip provision required televisions to read a content rating so that households could block programming for themselves.
The V-chip is worth pausing on, because it encodes a philosophy. Faced with programming it judged unsuitable for children, Congress did not ban the programming. It required that the tools of control be placed in the home — a rating system and a switch — and left the judgment to parents. Call it the tools-for-households model. Whatever its limits, it assumed that Congress could and should act, and that the point of acting was to arm families rather than to silence broadcasters.
The Attention Era
Then the platforms arrived. Between roughly 2007 and 2015, a small set of companies became the dominant channels of public discourse for first hundreds of millions and then billions of people — and the object of concern changed. The question was no longer only what a company knew about you. It was what a system, optimizing continuously for your attention, was doing to you.
Three dynamics made this era different in kind, not merely in degree. The first is the engagement trap: when attention is sold to advertisers, a platform has a direct financial incentive to maximize time on app, and time on app tracks the content that provokes fear, outrage, and social comparison. A system tuned for engagement drifts toward that content with no one intending harm. The second is the speed asymmetry: a feature can reach a billion users in weeks, while a regulation that addresses it takes years and the scholarship that frames the regulation takes longer still. The third is the authority migration: decisions about what a minor sees, what speech is carried, and what an AI system will refuse have moved — largely without public debate — from public institutions to private firms, which is to say to the precise place where the incentive to ignore ethical argument is strongest.
Here is the part that should surprise us. As the technology grew more powerful and more intimate, American law grew quieter. The field of technology ethics expanded enormously over the same window — the Partnership on AI formed in 2016; more than eighty AI-ethics principles documents appeared worldwide by 2020 — even as the instruments that once turned concern into law fell into disuse. The last major federal statute in the older spirit, the Children's Online Privacy Protection Act, passed in 1998, before the attention era had properly begun. Since then the federal record is nearly bare. Leadership passed to Europe, and at home to a handful of states — California above all, with the California Consumer Privacy Act (2018), its CPRA amendments, and an Age-Appropriate Design Code. Taken as a whole, the United States now regulates the intimate technology of the attention era less than it once regulated the comparatively modest technology of the pre-attention one.
Section 2
Getting Our Head Out of the Clouds: Considering What Is Before What Should Be
Grammar offers a useful distinction. The imperative mood commands: platforms should respect human dignity; AI must be transparent; companies ought not exploit a child's attention. The indicative mood describes: this is the metric the feed maximizes; this is the incentive that sustains it; this is the point at which a different input would produce a different output. Technology ethics has been fluent in the first mood and nearly silent in the second. The move this essay asks for is small and unglamorous — from imperative to indicative — and its consequences are large.
The problem sits in that gap. Imperatives are easy to write and legitimate to hold, and they address a system as though it were a person who might choose to comply. But a recommender system is not deciding whether to be good; it is executing an objective. To change what it does, you have to know what that objective is, what money stands behind it, and where the lever actually sits — and that knowledge is expensive. It means sitting with market structure, reading the product roadmap, learning what the machine is really optimizing for. This is the cost the field has mostly been unwilling to pay.
The argument is not to abandon the imperative but to reposition it. The imperative names where we want to go: systems that do not prey on children. The indicative names how to get there: here is the mechanism of the harm, here is the incentive that feeds it, here is the switch. Skip the indicative and the imperative floats free — a real aspiration with no mechanical connection to the thing it hopes to change. Statements get issued when an interface change was what the moment required; reports get published when a regulation was. The work is genuine and the leverage is absent. The rest of this essay tries to pay the indicative price — to look hard at how technology legislation has actually failed, and occasionally worked, before saying what we should do.
Section 3
An Example of Failed Technology Legislation: Section 230
Section 230 is known today as the internet's liability shield — the provision that lets platforms host others' speech without being treated as its publisher. What is largely forgotten is that it began as a family-empowerment bill. In 1995 Representatives Christopher Cox and Ron Wyden introduced the Internet Freedom and Family Empowerment Act, which was folded into the Telecommunications Act of 1996. Its purpose, written into the statute itself, was not immunity but control.
The stated policy of the United States, at 47 U.S.C. § 230(b), was to preserve a vibrant and competitive free market for the internet (b)(2); to maximize user control over the information received by individuals, families, and schools (b)(3); and to remove disincentives for the blocking and filtering tools that help parents restrict what their children can reach (b)(4). It was, in other words, the V-chip philosophy applied to the web: arm households, do not censor speakers.
Thirty years later, only one half of the bargain is real. The liability shield of § 230(c) became one of the most consequential and enforceable provisions in American law. The user-control policy of § 230(b) remained aspirational — a statement of hopes with no mechanism, no mandate, and no cause of action attached. A bill written to empower families became the legal foundation of the platforms that families now struggle to govern. It achieved, almost exactly, the opposite of its stated purpose.
What § 230(b) Promised
A competitive market, user control over what reaches individuals and families, and tools that let parents filter — the internet's V-chip. Written as the declared policy of the United States, and left as aspiration.
What § 230(c) Delivered
A broad, enforceable immunity for platforms hosting third-party content. The one operative provision — and the one that governed the next three decades. The shield outlived the purpose it was meant to serve.
Section 230 is not a freak accident. It fails in several of the ways technology legislation characteristically fails, and it is instructive precisely because it fails in more than one at once.
Common Failure Modes of Technology Legislation
- Loose or unenforceable language. Aspirational policy statements — like § 230(b) — that declare goals without attaching a mandate, a metric, or a cause of action.
- Limited technical understanding among legislators. Laws drafted for a technology the drafters do not fully grasp, and whose evolution they cannot anticipate.
- Corporate capture. The regulated industry shapes the rule, and the provision that survives is the one that serves it.
- Infeasible mandates. Requirements no one can actually implement, which are then ignored, waived, or struck down.
- Regulatory lag. By the time a statute is enacted it addresses the last technological cycle rather than the current one.
- Jurisdictional mismatch. National laws aimed at platforms that are global by design and can route around any single country.
- Compliance costs that entrench incumbents. Rules so expensive to satisfy that only the largest firms can afford them, raising the wall against competitors.
- Safe harbors that shield industry rather than users. Protections sold as consumer measures that operate, in practice, as immunity for the companies.
Section 230 exhibits at least three of these at once: loose language in the unenforceable § 230(b); a safe harbor that came to shield the industry rather than the households the bill named; and a statute whose one durable clause outlived — and inverted — the purpose of the whole. The lesson is not that Congress should not have acted. It is that intention without mechanism is not law. It is a wish with a statute number.
Section 4
What We Need to Control: Technology's Power Levers
If Section 230 shows what happens when intention arrives without mechanism, the next question is where the mechanisms are. A technology offers only a handful of points where law can actually grip it. What data may be collected and combined. What an objective function is permitted to optimize for, and whether it must be disclosed. How concentrated the market is allowed to become. What defaults a minor's account carries. These are the power levers — and the useful way to read the past decade of legislation is to ask who has actually pulled them.
The Active Legislature
The GDPR (2018) rewrote the law of data collection and consent; the Digital Markets Act and Digital Services Act reach market power and platform accountability; the EU AI Act (2024) is the first comprehensive attempt to regulate AI by risk tier. For a decade Europe has been the world's technology legislature.
Mostly Silent
COPPA (1998) remains the last major federal statute, and it predates the attention era. The Kids Online Safety Act has been debated for years but is not law. On the levers that matter most, Washington has largely declined to act.
Where It Actually Moves
California leads with the CCPA (2018), its CPRA amendments, and an Age-Appropriate Design Code modeled on Britain's. A widening wave of state privacy laws has followed. In the American system, the action has moved to the states.
Where a lever has actually been pulled, behavior has changed — and it changed for the reasons the indicative method predicts. The EU's General Data Protection Regulation altered the architecture of consent across the European internet within a single compliance cycle. Companies that had waved away a decade of ethical argument about data collection redesigned their consent flows in months — not because the argument finally persuaded them, but because a cost was finally attached to the old design. Britain's Age-Appropriate Design Code produced a set of audited changes to how the largest platforms treat children — default privacy settings switched on, geolocation off, profiling restricted — where years of exhortation had produced none. The Code did not ask platforms to respect children. It specified which switch had to be in which position, and attached a penalty. Mechanism, not sentiment, is what moved. It bears repeating that a default is not a suggestion: the setting most users never change is, in practice, the behavior of the system.
The newest lever is being pulled in an unexpected place — the county zoning meeting. As AI drives a building boom in data centers, the sharpest resistance is arising not in Brussels or Sacramento but in the towns asked to host them: communities contesting the water a facility will draw, the power it will pull off the grid, the land it will rezone. It is bottom-up governance, improvised and local, and it is worth watching. When the national instruments fall silent, the constraint that remains is the one closest to the ground.
Section 5
Information Mediation: Getting Truth to Policymakers
Behind every failure mode in Section 3 sits a quieter problem: legislators cannot regulate what they do not understand, and the technology has outrun the understanding. This was not always the gap it is now. From 1972 to 1995, Congress had its own in-house source of independent technical judgment — the Office of Technology Assessment, a nonpartisan body that produced careful, jargon-free analysis of emerging technologies for members who had to vote on them. It was defunded in 1995, at almost the precise moment the internet went mainstream. Congress dismantled its own eyesight just as the terrain grew difficult to read.
Nothing at that scale has replaced it. TechCongress places experienced technologists as fellows in congressional offices, and a handful of similar efforts supply real expertise, but none approaches the reach of a standing agency. The vacuum does not stay empty. Where independent analysis is absent, the space fills with the analysis that industry is only too willing to provide — which is to say, with lobbying, and with the capture that Section 3 named. The alternative to good information is rarely no information. It is interested information.
It is worth being specific about what was lost, because the design was unusually good. Over its life the OTA produced some 750 assessments — on subjects from acid rain to genetic testing — governed by a bipartisan, bicameral board and bound to a single discipline: lay out the options and their consequences, and let members decide. It ran on roughly $20–30 million a year, trivial against the federal budget, and its model was copied by legislatures around the world. What exists now does less. The Government Accountability Office runs a technology-assessment unit, but it is at heart an audit and oversight agency, without OTA's bipartisan board or dedicated line-item funding. The Congressional Research Service answers members' questions and writes short explanatory papers, not deep multi-year technical assessments. TechCongress places real technologists in congressional offices — on the order of sixteen fellows a year across some 550 offices and committees, funded by roughly $5 million from private foundations. Each is genuinely useful. None is a standing institution with the reach and neutrality the OTA had.
Meanwhile the interested information arrives at a very different scale. In the current cycle the largest pro-industry PAC, Leading the Future — backed by figures including OpenAI's Greg Brockman and Andreessen Horowitz's Marc Andreessen — raised on the order of $140 million to press a light-touch, accelerationist line, and pushed even for a federal ban on state AI legislation. The largest safety-oriented counterpart, Public First, raised around $20 million; a newer labor-populist entrant, the Guardrails Alliance, around $5 million. One need not take a side in that contest to see its shape: the money arguing for fewer constraints outweighs the money arguing for more by something like seven to one — and there is no neutral, publicly funded body of comparable weight in the room at all. This is what it means for the alternative to good information to be interested information. Not a metaphor — a set of budgets.
Section 6
Building a Duty of Care
A physician who harms a patient through carelessness can be sued for it. So can a lawyer, a structural engineer, a financial adviser bound by a fiduciary duty. Each of these professions carries a recognized duty of care: a legal and moral obligation to act with the caution that their power over others demands. Consumer software carries no such duty. A team can ship a feature that measurably worsens the sleep, attention, or mental health of millions of adolescents and incur nothing resembling the liability that governs medicine or civil engineering. Some of the most consequential design decisions of the age are made in one of the few remaining fields where a duty of care does not apply.
If such a duty were built, the interesting question is where it would bite — and the answer is not where most people look. The moral architecture of a product is rarely set by the engineers. Engineers implement an objective; they are handed a metric and asked to move it. The objective itself — maximize watch time, maximize daily active users, maximize retention — is chosen upstream, by product managers and business strategists who most likely never write a line of the code that carries it out. That is the room where the ethically decisive choice is made, and it is the room a duty of care would have to reach.
The Engineer
Implements the objective. Skilled, often conscientious, but handed the metric rather than choosing it. The place where ethics reviews usually land — and the wrong place to locate the decision.
The Product Strategist
Sets the objective the system optimizes for. The true moral architect of the product, and the role a duty of care would have to reach. Where the decisive choice is actually made.
This reframes where ethical effort belongs. Ethicists are typically hired as a signal and deployed late — reviewing outputs, writing principles, managing reputational risk after a feature has shipped. That is downstream of the moment that mattered. A duty of care would pull the obligation upstream, into the review where the objective function is chosen, and attach it to the person who chose it. It need not begin as legislation. A profession can bind itself before the law binds it: medicine and law were self-governing long before statutes codified their duties. A voluntary standard, honestly enforced by the people who set product objectives, could harden over time into something credentialed — a recognized qualification for those who decide what a system is built to maximize. The point is not another code of ethics to hang on a wall. It is to place a real obligation at the exact point where the decisive choice is made.
Section 7
What We Should Do
The case against imperative-mode ethics is not a case against ethics. It is a case against one deployment of it — the declarative, aspirational, audience-facing mode that has dominated the field for a decade — and an argument for an alternative grounded in mechanism, diagnosis, and the disciplined matching of problems to levers.
The stakes are not abstract. Pure economic optimization in the age of AI does not stabilize; it compounds. A handful of operators, by accidents of timing and capability, are accumulating leverage over the shape of the future that once required armies. The market will not self-regulate the moral dimension of that transition. The last ten years were the test of that proposition, on a curve gentler than the one ahead, and the test was failed. What follows is not a manifesto but four moves, each mirroring one part of the diagnosis above.
Build a duty of care. Place a real obligation — voluntary at first, credentialed over time — on the people who set product objectives, not merely the engineers who implement them. The decisive ethical choice is the choice of what to maximize, and it should carry a corresponding responsibility.
Empower information exchange. Rebuild the capacity that died with the Office of Technology Assessment. Legislators cannot regulate what they cannot understand, and the alternative to independent analysis is not neutrality but lobbying. Standing, nonpartisan technical judgment inside government is a precondition for every other reform.
Deepen technical expertise. Most of the failure modes in Section 3 trace back to a single deficit: laws written by people who do not understand the systems they govern. Close that gap — in legislators, in regulators, and in the ethicists who advise them — and write for the mechanism rather than the principle. A proposal that specifies which switch must be in which position is worth more than a framework that names the values the switch should honor.
Empower states. In the American system the action has moved to the states, and that is not a consolation prize. California has done more than Washington, and the states sit close enough to the ground to move faster than a stalled federal process — as the county fights over data centers already show. Support that work rather than waiting for a national statute that may never arrive.
Each of these moves trades the comfort of stating a position for the cost of learning a system. That cost is the indicative price the field has been avoiding, and paying it is the only way the imperative ever becomes operational.
Picture the next decade two ways. In one, technology ethics continues as it has — more principles documents, another generation of conferences, the same aspirational vocabulary applied to systems whose incentives it has not troubled to learn — while the metrics that matter, adolescent well-being, the share of public life mediated by recommendation, the concentration of decision-making in a handful of firms, continue along their present lines and the literature goes on describing them. In the other, a cohort of people who actually understand these systems sits in the rooms where objectives are chosen and statutes are drafted, writes specifications instead of statements, and measures success by whether a default moved. The first decade is the one we are on. The second is still available — but only to those willing to pay the indicative price first.
Read Next — The Companion Pieces
The three problem spaces below apply the indicative method to specific harms. Each starts from market structure and works toward the lever.
Social Media and Children
Why duration-based bans miss the variable that actually matters. Federated rating layers, recommender transparency, and content-tethering as parental authority.
The Morality of Language Models
Why "make AI moral" assumes a target the technology does not provide. Disclosed frameworks, anti-anthropomorphism rules, and tutor mode by default.
Workforce Displacement
Why entry-level hiring contraction is not a market failure waiting for the market to fix. National reskilling, new measurables, and philosopher builders.
Appendix A
References and Source Data
On the History of Technology Ethics
- Wiener, N. (1950). The Human Use of Human Beings: Cybernetics and Society. Houghton Mifflin.
- Moor, J. H. (1985). What is Computer Ethics? Metaphilosophy, 16(4), 266–275. The foundational framing of computer ethics as a field.
- Floridi, L., et al. (2018). AI4People — An Ethical Framework for a Good AI Society. Minds and Machines, 28, 689–707. A representative example of the principles-document era.
- Jobin, A., Ienca, M., & Vayena, E. (2019). The global landscape of AI ethics guidelines. Nature Machine Intelligence, 1, 389–399. Documents the proliferation of AI ethics guidelines and the convergence of their content.
On the Failure of Imperative-Mode Ethics
- Mittelstadt, B. (2019). Principles alone cannot guarantee ethical AI. Nature Machine Intelligence, 1, 501–507.
- Metcalf, J., Moss, E., & boyd, d. (2019). Owning Ethics: Corporate Logics, Silicon Valley, and the Institutionalization of Ethics. Social Research, 86(2).
- Hagendorff, T. (2020). The Ethics of AI Ethics: An Evaluation of Guidelines. Minds and Machines, 30, 99–120.
On Regulation as Mechanism
- Information Commissioner's Office (UK). (2021–2025). Age Appropriate Design: A code of practice for online services. Implementation and audit reports.
- Lessig, L. (2006). Code: Version 2.0. Basic Books. The canonical statement that architecture is regulation.
- Sunstein, C. R., & Thaler, R. H. (2008). Nudge: Improving Decisions About Health, Wealth, and Happiness. Yale University Press. On the determinative power of defaults.
On the Structural Dynamics of Platform Ethics
- Zuboff, S. (2019). The Age of Surveillance Capitalism. PublicAffairs. The authority migration and its structural logic.
- Haidt, J., & Rausch, Z. (2023). The Anxious Generation. Penguin Press. Empirical grounding for the harm-at-population-scale claim.
- ROOST (Robust Open Online Safety Tools). (2025). Founding announcement. Discord, OpenAI, Roblox, Bluesky founding partners. An example of lever i work — building the infrastructure that policy can then mandate.
On Section 230 and the Statutes of the Pre-Attention Era
- 47 U.S.C. § 230. Enacted as part of the Communications Decency Act, Title V of the Telecommunications Act of 1996 (Pub. L. 104–104). § 230(b) states the policy of user and family empowerment; § 230(c) provides the liability shield.
- Internet Freedom and Family Empowerment Act (1995), introduced by Representatives Christopher Cox and Ron Wyden — the legislative origin of Section 230.
- Telecommunications Act of 1996, V-chip and content-rating provisions (Title V). The tools-for-households model of parental content control.
- Fair Credit Reporting Act (1970); Privacy Act of 1974; Cable Communications Policy Act (1984); Electronic Communications Privacy Act (1986); Computer Fraud and Abuse Act (1986); Video Privacy Protection Act (1988). The recurring federal technology legislation of the pre-attention era.
On Positive Regulation by Jurisdiction
- Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), applicable from May 2018.
- EU Digital Markets Act and Digital Services Act (adopted 2022).
- EU Artificial Intelligence Act (2024).
- Children's Online Privacy Protection Act (COPPA), 1998, 15 U.S.C. §§ 6501–6506. The last major federal statute of the earlier spirit.
- Kids Online Safety Act (KOSA) — federal legislation debated across recent Congresses; not enacted into law as of this writing.
- California Consumer Privacy Act (2018); California Privacy Rights Act (2020); California Age-Appropriate Design Code Act (AB 2273, 2022).
On Information Mediation
- U.S. Congress, Office of Technology Assessment (1972–1995). Established by the Technology Assessment Act of 1972; funding eliminated in 1995.
- TechCongress — a nonpartisan fellowship placing experienced technologists in congressional offices.
Companion Pieces
- EconFaithAI: Social Media and Children — Problem space i.
- EconFaithAI: The Morality of Language Models — Problem space ii.
- EconFaithAI: Workforce Displacement — Problem space iii.
- EconFaithAI: For the Innovators — Moral Restraint Moves Us From Greed to Generosity