Digital Regulation and Artificial IntelligenceEssay
The adaptive regulator: institutional capacity in the age of artificial intelligence
Technology changes fast, but the regulatory problem is not simply keeping up with every new development. The challenge is building institutions that can learn, test, correct course and remain accountable for their decisions.
On the morning of Plenary 3 at the IX World Forum on Energy Regulation, in Tbilisi, the discussion revolved around technological transformation, digitalization, new market models and the role of regulators in a power sector undergoing rapid change.
At one point, someone posed a provocative question that drew laughter from the room: if artificial intelligence is becoming so capable, why do we still need regulators? Couldn’t an AI agent take their place at some point? [1][2] The question was asked in a light tone, but the problem behind it was serious.
Fully replacing a regulatory authority with a machine does not seem like a realistic scenario today. The question does, however, bring something more important into view: what, after all, do we expect from a regulator in an environment where technology, markets and business models change faster and faster?
That question came up several times throughout WFER. At times, the discussion was about companies using artificial intelligence. At others, it was about the regulator itself needing to adopt new tools, develop new skills, and take on new forms of oversight.
The conclusion I found most compelling was almost the opposite: the regulator is not becoming less important. The more complex the regulated system becomes, the greater the demands on the institutional capacity of those who regulate it.
AI does not arrive in isolation
It is tempting to treat artificial intelligence as just another technology that government needs to learn to regulate. That is only part of the story. AI also changes the regulated sector, alters the way companies make decisions, speeds up certain processes and is starting to be used by the regulator itself.
In the energy sector, this is already visible on several fronts. Algorithms can help forecast load, identify faults, operate distributed resources, manage batteries, support customer service, detect abnormal patterns, assess documents and organize large volumes of information. Some applications have low impact. Others can directly affect the operation of critical systems or the functioning of markets. That difference matters.
In a WFER session devoted specifically to the impact of artificial intelligence on energy systems, Jonathan Thurlwell of Ofgem described an approach based on outcomes and proportionality. The point was not to treat every AI application as if it carried the same risk. Regulatory intervention should be more intense where the consequences of a failure are greater and lighter where the risk is limited. [3]
The latest version of Ofgem’s guidance on the ethical use of AI in the energy sector follows this logic. The document covers governance, risk, skills, transparency, explainability, safety and consumer protection, and it distinguishes between contexts of use. [4] This seems more promising to me than trying to create a single regulatory response to something as broad as “artificial intelligence.”
A model used to summarize consumer complaints is not the same thing as a system capable of coordinating thousands of devices connected to the grid. The word AI may be the same. The risk is not. The regulator needs to learn to recognize that distinction.
Technology-by-technology regulation is a hard race to win
At the close of my participation in Tbilisi, I made a joke about the “electrosaurs.” The idea was simple: in the power sector, we sometimes feel that by the time we finally understand a technology, it has already changed again. The joke was meant to lighten the mood at the end of the session, but there was a serious argument behind it.
If regulation tries to keep up with innovation by writing a technology-specific rule for every new development, there is a good chance it will arrive late. Technical rules are still necessary, and in infrastructure systems many of them are indispensable. The question is choosing more carefully the level at which regulatory intervention should take place.
Instead of starting with the technology, it is often worth starting with the problem. What system need must be met? What outcome do we want to produce, and which risks are acceptable? Who is responsible if something goes wrong? What evidence will be needed to show that the outcome was achieved, and which limits must not be crossed?
This logic came up several times in the WFER discussions. In the session on artificial intelligence, representatives from Ofgem and the AEMC spoke of approaches guided by principles, outcomes, proportionality and accountability. The question of who remains accountable when there is automation was raised quite directly. [3]
The OECD has been using similar language when discussing regulation in fast-changing technological environments. The Regulatory Policy Outlook 2025 recommends “adapt and learn” approaches, combined with anticipation, monitoring and institutional capacity. [5]
This does not mean unstable regulation. The goal should be the opposite: to preserve principles that are stable enough and to create mechanisms that allow for review when the evidence changes. Predictability does not require standing still.
The regulator will also have to use AI
There is another aspect of this transformation that interests me in particular. Besides watching companies use artificial intelligence, the regulator will also be a user of the technology. That has already begun.
In the WFER session on AI, Ofgem described initiatives aimed at using the technology within its own regulatory work, while at the same time developing guidance, regulatory labs and testing environments for the sector. The debate reached a practical question: some markets and systems are beginning to operate at speeds and data volumes that challenge traditional methods of oversight. [3]
The OECD also recognizes this potential. In a study on the use of AI in government functions, it identifies applications that can improve analysis, service delivery, detection of irregularities and decision support. At the same time, it warns of problems with data quality, transparency, overreliance, legacy infrastructure, skills shortages and risks to accountability. [6] It is an uncomfortable combination: the same technology that can help the regulator deal with complexity can also create new forms of dependence.
Imagine an agency that uses AI to analyze thousands of documents, monitor patterns of behavior or support complex decisions. The productivity gain can be enormous. But someone inside the institution needs to understand, at least to some degree, what that system does, what data it uses, what its limitations are and in which situations its output should not be accepted. Otherwise, we trade one difficulty for another.
Traditionally, we depended on human capacity to process information. Increasingly, we may come to depend on systems that process information without anyone being able to explain adequately how an output was produced. For a regulator, this is especially sensitive.
A company can use a model because it improves a business decision. A public authority must, in addition, justify its decisions, protect rights, act consistently, and answer for its mistakes. Responsibility does not disappear because a machine took part in the process.
Continuous learning is no longer optional
This may be the point that interests me most in this whole discussion. While preparing my participation in Plenary 3, one of the questions I considered was precisely whether regulators would have the capacity to deal with everything being asked of them.
The answer starts with a simple observation: today, relevant regulatory issues cut across fields such as power engineering, economics, digital systems, artificial intelligence, cybersecurity, behavioral science and climate risk. The list may grow.
You cannot simply add responsibilities to an institution without developing new capabilities. That requires data, multidisciplinary teams, continuous training, international cooperation and mechanisms for sharing knowledge. [2]
One of the sentences I used to sum up this idea was:
Adaptive regulation requires an adaptive regulator.
The sentence seems obvious until we think about what it demands in practice.
An adaptive regulator needs to learn on an ongoing basis and to admit that part of the knowledge it will need five years from now is not yet fully available today. It needs to make room for different specialists to work together, attract and retain people whose skills are also in high demand in the private sector, and improve its data infrastructure. It needs to talk with other institutions, including those outside its own sector. And it needs to learn without outsourcing its judgment.
The OECD has been insisting on this point. In addressing the regulatory governance of the digital economy, it identifies information asymmetries, the speed of technological change, the opacity of algorithmic systems and business models that cut across sector boundaries as challenges for public supervisors. The conclusion is that digital transformation requires institutional capacity that matches the complexity of the systems regulators are expected to oversee. [7]
This applies to artificial intelligence, but not only to it. The problem is broader.
Learning cannot be occasional
In government, training is still often treated as something separate from day-to-day work. A person takes a course, goes to a conference, or attends a talk. Then the routine resumes as before.
That model works poorly when the regulated sector is changing all the time. If the knowledge needed changes quickly, learning has to be part of the work process itself. That can include formal courses, but it also involves communities of practice, case analysis, exchanges between regulators, access to knowledge bases, controlled experimentation, review of past decisions and contact with outside researchers and experts.
WFER seemed valuable to me precisely for this reason. No one is going to copy a British, Australian, Japanese or American solution and apply it directly in Brazil. That would be simplistic. The value lies in seeing how people facing similar problems framed their questions, what risks they identified, what they tested, and where they still have doubts.
Learning from another jurisdiction is not importing an answer. Sometimes it is discovering a better question.
Sandboxes help regulators learn before rules harden
One concrete example is sandboxes. The term has become popular and is sometimes used as if it simply meant “letting people innovate.” It should not be. A good sandbox is a mechanism for regulatory learning.
Ofgem has been using AI Reg Labs to discuss use cases with regulated companies and innovation partners. It has also moved ahead with building a technical sandbox to test AI applications in a controlled environment. [4][8]
This can make experimentation easier for innovators while allowing the regulator to learn as well. It can observe the technology before adoption becomes widespread, identify risks, test requirements, understand limitations, and determine whether existing rules are sufficient.
With new technologies, this can be smarter than choosing between two bad extremes: banning out of ignorance or allowing out of enthusiasm. Experimenting, in this sense, means producing evidence before turning a hypothesis into a permanent rule, without giving up protection.
There are things AI does better
I also see no point in defending human work by pretending that people are better at everything. They are not. Machines can process volumes of data that would be impractical for a team. They can identify patterns, summarize documents, compare texts, organize evidence and carry out repetitive tasks far faster. That is a real opportunity for institutions working with limited time and staff.
The problem begins when we confuse processing capacity with decision-making responsibility. A system can suggest that a certain behavior looks abnormal, but someone still has to decide what to do with that information. It can compare thousands of comments received in a public consultation; someone needs to assess which arguments are relevant. It can produce a draft, and someone has to answer for it. It can point to a correlation. Someone has to ask whether there is causation, bias, an error in the data or an alternative explanation.
The most valuable gain may come from taking some of the mechanical work off the shoulders of the public official responsible for the decision, allowing more time for the judgment that truly requires context. That also changes the training needed. Knowing how to use a tool is not enough. It will be increasingly important to know how to question it.
The risk of a new asymmetry
There is a more uncomfortable aspect to this issue. Technology companies and large market participants tend to have more resources to hire specialists, acquire computing infrastructure, develop models, and experiment with new tools.
If the regulator does not develop comparable capacity, even at a different scale, a new asymmetry may emerge: a gap in analytical capacity layered on top of existing information asymmetries.
The OECD notes that public authorities find it hard to compete for scarce and expensive digital skills. The problem arises precisely when those skills become necessary to supervise technologically sophisticated markets. [6] This is a point that deserves attention.
The regulator does not need to reproduce in-house every technology or capability used by the entities it regulates. That would be impossible. But it does need to keep enough capacity to understand what is being proposed, set requirements, test evidence and recognize when it needs to seek specialist support.
The boundary matters. External cooperation strengthens an institution when it complements its own knowledge. External dependence weakens it when it replaces the capacity for judgment.
Humans remain at the center for a less romantic reason
When the provocative question about replacing the regulator with an AI agent came up in Tbilisi, it would have been easy to answer by talking about human sensitivity, experience or intuition. All of that has some value, but I do not think it is the main argument. The strongest reason is responsibility.
Regulation distributes costs and benefits. A decision can favor one investment and make another unviable. It can change rates, shift incentives, create barriers, remove barriers, affect vulnerable groups or move risks between current and future consumers. No algorithm can strip these choices of their institutional dimension.
Even if an AI becomes extraordinarily good at recommending the most technically efficient solution, there will still be questions about fairness, legitimacy, public priorities and risk acceptance. These decisions require identifiable human decision-makers who can be held accountable. The decisions themselves must be explainable, open to challenge, and subject to the law.
That is why the most useful question may not be “will AI replace the regulator?” I prefer another one: how can artificial intelligence expand the regulator’s capacity without diluting the responsibility of those who regulate? This question is harder. It is also more productive.
The adaptive regulator
Coming back from Tbilisi, I was left with the impression that we are entering a phase in which technical knowledge will remain indispensable but will not be enough. The regulator will have to develop something close to an institutional capacity for learning.
That involves observing emerging technologies, testing before consolidating rules whenever possible, using better data and sharing knowledge. It involves revisiting assumptions and working with specialists from other fields. It means using artificial intelligence where it truly improves the work and putting controls in place when its use creates significant risks. And, perhaps the hardest part, it means recognizing early when an answer that worked in the past has stopped working.
The OECD draws attention to approaches based on anticipation, adaptation and learning precisely because very rigid regulatory frameworks tend to struggle when confronted with rapid technological change. [5]
I do not think this means making regulation volatile. Institutions need to be predictable. Markets need to know the rules. Long-term investments do not go well with arbitrary changes. The challenge lies in combining stable principles with the capacity to adapt. Perhaps that is the difference between a regulator that merely reacts to innovation and one that can adapt alongside it.
The provocative question raised in Tbilisi about replacing the regulator with an AI works precisely because it exaggerates a real concern. Artificial intelligence can greatly expand institutional capacity. It can speed up analysis, improve oversight, organize information and open new possibilities for action.
But it does not eliminate the need for knowledge, judgment and responsibility. It may do exactly the opposite: by raising the technological capacity of the regulated system, it also raises the level of expertise expected of those who regulate.
For the regulator, this is a less dramatic challenge than predictions about machines replacing people, but probably a more important one. Continuous learning has become part of regulatory work, and not an add-on to it.
References
- INTERNATIONAL CONFEDERATION OF ENERGY REGULATORS (ICER); GEORGIAN NATIONAL ENERGY AND WATER SUPPLY REGULATORY COMMISSION (GNERC). IX World Forum on Energy Regulation, WFER IX. Official program. Tbilisi, Georgia, Sept. 21 to 24, 2026. Available at: https://www.wfertbilisi2026.com/en/programa/general. Accessed on: Sept. 28, 2026.
- WORLD FORUM ON ENERGY REGULATION, WFER IX. Plenary 3: Technology as a Driver of Energy Transformation. Tbilisi, Sept. 24, 2026. Based on the official program, the author’s personal notes from the session and his preparation notes.
- WORLD FORUM ON ENERGY REGULATION, WFER IX. Concurrent Session 2C: The impact of AI on energy systems. Tbilisi, Sept. 22, 2026. Speakers: Jonathan Thurlwell, Ofgem; Hiromichi Tanoue, EGC; Victoria Mollard, AEMC; and Lindsay See, FERC. Based on the official program and the author’s personal notes from the session.
- OFGEM. Ethical AI use in the energy sector, version 2. May 2026. Available at: https://www.ofgem.gov.uk/guidance/ethical-ai-use-energy-sector. Accessed on: Sept. 28, 2026.
- OECD. OECD Regulatory Policy Outlook 2025. Paris: OECD Publishing, 2025. DOI: 10.1787/56b60e39-en. Available at: https://www.oecd.org/en/publications/oecd-regulatory-policy-outlook-2025_56b60e39-en.html. Accessed on: Sept. 28, 2026.
- OECD. Governing with Artificial Intelligence: The State of Play and Way Forward in Core Government Functions. Paris: OECD Publishing, 2025. DOI: 10.1787/795de142-en. Available at: https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html. Accessed on: Sept. 28, 2026.
- PAECH, Philipp; COHEN, Natalie. Regulatory governance of the digital economy: Lessons from the financial services sector. OECD Regulatory Policy Working Papers, No. 24. Paris: OECD Publishing, 2026. DOI: 10.1787/e881273f-en. Available at: https://www.oecd.org/en/publications/regulatory-governance-of-the-digital-economy_e881273f-en.html. Accessed on: Sept. 28, 2026.
- OFGEM. Artificial intelligence. Information on AI Reg Labs, guidance, assurance and the technical sandbox for the energy sector. Available at: https://www.ofgem.gov.uk/energy-regulation/technology-and-innovation/artificial-intelligence. Accessed on: Sept. 28, 2026.
The opinions and analyses expressed in this article are personal and do not represent the positions, decisions or institutional views of the Brazilian Electricity Regulatory Agency (ANEEL).
How to cite this article
ALCÂNTARA, Márcio. The adaptive regulator: institutional capacity in the age of artificial intelligence. Regulador.org, 2026. Available at: https://www.regulador.org/en/2026/09/28/the-adaptive-regulator-institutional-capacity-ai/. Accessed on: Sep. 30, 2026.