Nvidia founder and CEO Jensen Huang has argued that AI does not require a new regulatory framework because safety is fundamentally an engineering problem.
Speaking at Salesforce’s Dreamforce conference, Huang characterized AI as hardware and software made by people—and therefore controllable by people. His prescription is straightforward: companies should not ship systems whose functionality or safety they cannot support, and market incentives should reward those that get the balance right.
> “Safety is an engineering problem, not a legal one,” Huang said.
That view matters beyond a familiar policy debate. Nvidia sits at the center of AI infrastructure, while also expanding across models, agents, development tooling and sandboxing. Its chief executive is making a case for a governance model in which builders retain wide latitude—and carry the operational responsibility for deciding when a system is ready.
What changed
Huang’s comments are an unusually explicit rejection of new AI-specific rules. He argued that innovation, speed and safe products are not competing goals, and that companies can pause deployment when a product is not under control.
The position differs from calls for prescriptive AI regulation and shifts emphasis toward existing legal mechanisms, internal testing and commercial discipline. Huang did not outline a separate industry self-regulatory framework in these remarks, though TechCrunch notes that he has championed open-weight models as a competitive counterweight to proprietary AI labs.
Why operators should care
For enterprise leaders, “existing laws plus engineering” is not a lighter operating model if AI systems touch consequential workflows. It means the organization itself must define and document the controls that a future customer, regulator, insurer or court may expect to see.
The practical risks are familiar: models can behave unpredictably, agents can take inappropriate actions, and software failures can have wide downstream effects. The source points to the 2024 CrowdStrike outage as a reminder that even conventional software releases can disrupt operations at scale. AI adds issues around autonomy, data handling, misuse and the difficulty of reproducing model behavior.
Market pressure may punish obvious failures, but it is a delayed control. A company deploying AI into customer support, finance, security operations or code production needs safeguards before an incident—not merely a way to respond after one.
The operating implication: make safety measurable
Whether or not new rules arrive, teams should treat AI governance as a release-engineering function. That means setting boundaries for what a system may access or do; testing against misuse and failure scenarios; requiring human approval for high-impact actions; monitoring production behavior; and maintaining rollback paths and incident processes.
Executives should also distinguish between a model demonstration and a production system. The latter includes identity and access controls, audit logs, data-retention decisions, vendor accountability, evaluation thresholds and an owner who can stop deployment. Those controls are useful under either self-regulation or formal regulation.
Huang’s assertion that companies should hold back unsafe products is reasonable as a principle. The harder business question is how companies demonstrate that confidence when models, prompts, connected tools and user behavior can all change after launch.
What to watch next
The policy outcome is unsettled, but the commercial pressure is immediate. AI vendors will increasingly be judged on whether they provide customers with evidence of reliability and controllability, not only more capable models.
Watch for two signals: whether major AI suppliers publish more concrete safety and deployment commitments, and whether enterprise buyers turn assurance requirements into procurement gates. If that happens, self-governance will become less a philosophical alternative to regulation and more a baseline operating requirement.
Huang’s broader point—that safety must be engineered—will likely hold regardless of the legal framework. The open question is whether voluntary engineering discipline alone will be enough when incentives favor faster deployment.




