The reason regulation matters is becoming increasingly clear. Artificial intelligence is evolving from software that answers questions into software that takes actions.
From assistants to agents
The most important development in AI may not be that models are becoming smarter. It is that they are becoming more autonomous.
The first generation of AI largely operated as a tool. Users asked questions and received answers. The next generation increasingly acts on behalf of users. An AI chatbot that drafts an email creates one set of risks. An AI agent that can access company systems, browse the internet, execute code, authorise transactions, modify software or interact with customers creates another.
That distinction matters because the regulatory debate changes entirely once software begins making decisions and taking actions.
Meta’s Muse, which recently became one of the most downloaded free iPhone apps in the United States, illustrates this shift. Rather than simply producing answers, the personal AI agent can organise travel, compare products, conduct research and complete tasks across websites and applications with user approval.
Every additional permission potentially makes these systems more useful, but it also makes them more difficult to secure. A system that can read emails requires identity controls. A system that can access internal databases requires monitoring and audit trails. A system that can authorise payments or interact with external systems raises questions around accountability, liability, insurance and cyber security.
The investment significance is not that machines are becoming conscious. It is that autonomous systems create entirely new categories of demand.
Much of the attention surrounding artificial intelligence focuses on the companies building the models. Investors may be overlooking the businesses that make those models safe to deploy.
Every major technological revolution creates supporting industries. The internet created cybersecurity leaders. Modern financial markets created compliance and risk-management businesses.
AI agents may create large new markets for identity verification, monitoring, controlled execution, model testing, risk management and specialist insurance. As autonomous systems enter corporate workflows, organisations will increasingly need to know which system took an action, what information it accessed, what authority it possessed and who approved its behaviour.
A valuable technology layer
Evidence that this market is already emerging can be seen across the industry. Nvidia recently launched an Open Agent Safety Platform designed to control what AI agents can access, monitor their behaviour and restrict their permissions. The initiative reflects a broader shift: as AI evolves from answering questions to taking actions, the surrounding infrastructure for security, identity, auditing and control may become just as important as the models themselves.
For investors, this is significant. The next generation of AI winners may not be limited to model developers. They may also include the companies building the guardrails that make autonomous AI safe, accountable and commercially deployable.
In some cases, those safeguards may become mandatory. That possibility brings regulation into the centre of the investment story.
Regulation does not merely slow an industry. It redistributes its profits.
History suggests that regulation rarely affects all participants equally.
Banking regulations strengthened many large financial institutions because compliance became expensive. Pharmaceutical regulation favoured companies capable of funding lengthy clinical trials and navigating complex approval processes.
Those regulations served important public purposes. They also helped create competitive advantages for participants with the scale to absorb the costs.
Artificial intelligence may follow a similar path. Imagine a world where advanced AI systems must undergo independent testing, cybersecurity reviews, ongoing monitoring, incident reporting and formal certification before deployment. Those requirements may be entirely reasonable. But they could also be expensive.
For large organisations such as Microsoft, Alphabet, Amazon, OpenAI or Anthropic, compliance may become another cost of doing business. For a university laboratory, small developer or open-source project, it could become a significant barrier to entry.
The largest AI companies may therefore build two moats. The first is technological, consisting of models, talent, computing capacity and proprietary data. The second is regulatory, consisting of the ability to satisfy increasingly complex requirements.
The winners may not simply be the organisations building the most powerful models. They may be the businesses that control critical bottlenecks.
Infrastructure is one obvious example. Whether regulation becomes strict or remains relatively light, demand for computing resources may remain strong. Under stricter regulation, AI development could become concentrated among a smaller number of well-funded organisations operating ever-larger computing clusters. Under lighter regulation, a broader ecosystem of developers and applications may emerge.
Either outcome can support demand for semiconductors, cloud services, networking equipment, electricity and data-centre infrastructure. What changes is not necessarily demand itself, but who captures the resulting profits.
Infrastructure providers therefore occupy one of the few areas that could benefit under almost any regulatory outcome. That does not mean every investment will succeed. Electricity availability, grid access, financing costs, utilisation rates, technological obsolescence and competitive pressures will still matter.
Investors must distinguish between a compelling theme and an attractive investment purchased at the right price.
The real risk
Many AI application companies face a different challenge. Their products often rely on models owned by somebody else. Their economics depend on upstream pricing decisions, platform access and competitive dynamics they do not control.
In some cases, the features they offer can be replicated when model providers release new capabilities. If regulation imposes additional compliance obligations on top of those existing pressures, their margins could become even more vulnerable.
As in previous technology cycles, owning the platform can prove more valuable than building on top of it.
That does not mean application companies cannot succeed. It does mean investors should pay close attention to proprietary data, embedded customer relationships, distribution advantages and switching costs.
The regulatory contest is not occurring in isolation. It is increasingly a competition between national approaches to technological development.
The United States has broadly favoured private-sector leadership, infrastructure expansion and commercial innovation. China has combined significant investment with stronger control over models, content, data and domestic technology ecosystems.
Both countries want AI leadership. They are simply pursuing it through different frameworks.
The result may be a fragmented global market characterised by different standards, approved suppliers, trusted models and data-localisation requirements. That fragmentation could increase costs but also create regional advantages for approved cloud providers, domestic infrastructure operators and local technology champions.
Open-source AI adds another layer of complexity. Supporters argue that open-weight models broaden innovation and competition. Critics argue that they make powerful capabilities available without adequate safeguards.
If stringent requirements are imposed only on domestic developers, regulation could unintentionally strengthen competing international ecosystems. The challenge is not whether regulation should exist. It is whether regulation addresses specific risks or simply increases development costs.
One of the most important distinctions regulators may eventually make is between a model’s capability and the access granted to it.
A powerful model operating within a tightly controlled environment presents one level of risk. The same model connected to confidential information, payment systems, industrial infrastructure and external tools presents another.
As AI agents become more capable, regulators may increasingly focus on what systems are authorised to do rather than merely whether the models exist.
That shift would have significant investment implications.
It would favour businesses involved in identity verification, secure access, cyber security, auditability, monitoring and controlled execution. It could also reduce the burden on smaller developers by concentrating oversight on high-risk uses rather than model development itself.
The investment question
The most important shift is not that AI can answer questions. It is that AI is beginning to take actions.
As autonomous agents gain access to data, systems, payments and real-world decisions, the need for security, monitoring, accountability and governance will grow. Regulation is likely to grow alongside it.
Under lighter regulation, experimentation may accelerate. Under stricter regulation, the largest technology platforms and leading AI laboratories may strengthen their advantages.
But neither outcome guarantees attractive returns for every participant. Price still matters. Competitive advantage still matters. Capital intensity still matters.
The biggest winners may not be the companies building the most powerful models. They may be the businesses that own the infrastructure, control the customer relationship or provide the guardrails that make autonomous AI safe to use.
Artificial intelligence may prove to be the biggest investment opportunity since the internet, but the battle over regulation may determine who captures the profits.
Generate is a New Zealand-owned KiwiSaver and Managed Fund provider managing over $10 billion on behalf of more than 200,000 New Zealanders.
This article is intended for general information only and should not be considered financial advice. The views expressed are those of the author. All investments carry risk, and past performance is not indicative of future results.
To see Generate’s Financial Advice Provider Disclosure Statement or Product Disclosure Statement, go to www.generatewealth.co.nz/advertising-disclosures/. The issuer is Generate Investment Management Limited.
Tags:
- AI
- artificial
- Artificial intelligence
- ArtificialIntelligence
- attractive
- biggest
- captures
- company
- could
- Datacentre
- determine
- developer
- does
- emerging
- every
- how
- intelligence
- Internet
- investment
- manufacturer
- mean
- New Zealand
- NewZealand
- NZ
- opportunity
- produce
- Profits
- project
- rapidly
- Regulation
- returns
- semiconductor
- since
- software
- Technology
- that
- the
- WHO
- will