WisPaper
WisPaper
Search
QA
Pricing
TrueCite

Should large model companies be regulated as tech firms or as critical infrastructure?

Large model companies should be regulated as both tech firms and critical infrastructure, depending on the use case and societal risk.

Direct answer

The answer depends on the context. For general consumer use, regulating large model companies as tech firms (like software platforms) is appropriate, focusing on transparency and fairness. However, when these models underpin essential services like news media or healthcare, they function as critical infrastructure and require stricter oversight. Research shows that media organizations' reliance on AI infrastructure creates risks to media freedom that existing tech regulations don't fully address [1], while medical use raises unique privacy and liability concerns [3]. Across the studies here, the strongest evidence points to a hybrid approach: treat the underlying cloud and tool infrastructure as critical, but regulate specific applications based on their societal impact.

5sources cited

This article was generated with WisPaper-powered search and paper analysis.

When does regulating them as tech firms make sense?

For most consumer-facing applications—chatbots, writing assistants, image generators—regulating large model companies like traditional tech firms is a good starting point. The key issues here are transparency, fairness, and accountability, which are familiar from platform regulation. A 2024 analysis identifies four ethical touchpoints where safeguards can be applied to large language models (LLMs), and finds that the most effective approach is to apply safeguards before training begins, similar to how software engineering addresses bugs at the source [2]. This aligns with treating these companies as tech firms, where product-level rules apply. The paper also draws a historical parallel to the US auto industry, which initially resisted safety regulations but later embraced them as consumer attitudes shifted [2]—suggesting that tech-style regulation can evolve with public expectations.

However, even within this category, current laws fall short. The same analysis notes that two major ethical gaps persist in many LLM products: a lack of content or source attribution, and a lack of transparency about training data [2]. These are classic tech-regulation problems—like requiring a search engine to disclose how it ranks results—and they can be addressed by updating existing tech laws rather than creating entirely new frameworks.

When do they become critical infrastructure?

The line shifts when large models are embedded in systems that society depends on for essential functions. A 2025 study on media freedom shows that news organizations are increasingly reliant on AI companies for the infrastructure—cloud computing, APIs, and model access—needed to produce news [1]. This creates three specific risks: algorithmic opacity (journalists can't see how the AI shapes content), lock-in effects (switching providers is costly or impossible), and resource disparities (AI companies hold far more power than individual newsrooms) [1]. The study finds that existing EU media freedom law, which focuses on platforms' control over access to audiences, does not address these infrastructure-level dependencies [1]. The author argues that technology laws like the EU's Data Act and AI Act offer a better foundation, but they need to be adapted to treat AI infrastructure as a public-interest concern—essentially, as critical infrastructure [1].

Healthcare is another domain where the stakes are critical. A 2023 viewpoint in JAMA highlights that medical use of LLMs raises challenges around privacy, device regulation, competition, intellectual property, cybersecurity, and liability [3]. When a model helps diagnose a patient or recommend treatment, it is no longer just a tech product—it becomes part of the healthcare infrastructure. The authors call for regulators to address these issues specifically, which goes beyond standard tech-firm oversight [3].

What does a hybrid regulatory model look like?

The evidence points to a two-tier system: regulate the underlying infrastructure (cloud, APIs, foundational models) as critical infrastructure, while regulating specific applications as tech products. This mirrors how we treat electricity grids (critical infrastructure) differently from toasters (consumer products), even though both use electricity. A 2024 panel discussion of experts on LLM trust and regulation broadly supports this nuanced view, noting that the trustworthiness of these tools depends heavily on the context in which they are used [4].

The broader context of Big Tech regulation reinforces this approach. A 2022 analysis notes that companies like Google, Microsoft, and Amazon already underpin much of our social, political, and economic worlds by providing digital infrastructure [5]. The authors point out that this has triggered a 'techlash' and a surge in regulatory measures like the EU's Digital Markets Act, which specifically targets the market power of these infrastructure providers [5]. Applying this logic, large model companies that also control the cloud and data pipelines (e.g., Microsoft with Azure and OpenAI) should face infrastructure-level regulation for those layers, while their consumer chatbots face tech-firm rules. The key insight from the media freedom study is that alternative, publicly controlled infrastructures may ultimately be needed to fully resolve the dependency problem [1]—a step beyond regulation.

About These Sources

This answer is built on 5 peer-reviewed studies — published from 2022 to 2025, 3 from 2024 or later, 5 in Q1 journals, collectively cited 239 times — selected as the most relevant from 5 studies that passed quality screening, drawn from 71 papers retrieved from a database of over 500 million.

Sources used in this answer

1

Safeguarding media freedom from infrastructural reliance on AI companies: The role of EU law

Media organizations' reliance on AI company infrastructure (cloud, APIs, models) creates risks to media freedom—algorithmic opacity, lock-in, and resource disparities—that existing EU media law does not address; the study recommends adapting technology laws like the Data Act and AI Act, and notes that alternative public infrastructures may be needed.

2

How to Regulate Large Language Models for Responsible AI

Identifies four ethical touchpoints for LLMs and finds that applying safeguards before training is most effective but currently avoided; draws a parallel to the US auto industry's eventual embrace of safety regulations after initial resistance.

3

The Challenges for Regulating Medical Use of ChatGPT and Other Large Language Models

Highlights that medical use of LLMs raises distinct legal and ethical challenges—privacy, device regulation, competition, IP, cybersecurity, and liability—that require specific regulatory attention beyond general tech rules.

4

Large Language Models: Trust and Regulation

A panel of experts on LLM trust and regulation broadly supports the view that regulatory approaches should depend on the context of use, with trustworthiness varying by application.

5

Big Tech

Big Tech firms (including those developing large models) already function as digital infrastructure underpinning society, which has triggered a 'techlash' and new regulatory measures like the EU's Digital Markets Act targeting their market power.