Key Takeaways
- Engage, don't fear. Denmark's fintech boom (about 280 firms by 2021) shows that industries treating regulation as a design brief shape it to their advantage instead of getting shaped by it.
- Watch the right door. Scrutinize how the AI itself was built, trained, and sold to you, not just whether your authors used it to write.
- The harm is already landing unevenly. Biased detection tools and models trained on biased data mean marginalized authors get flagged and dropped more often, while authors who openly use AI keep their deals. Governance aimed at the tech, not at authors, is how a house refuses to take part.
- The EU AI Act is a useful map even outside the EU. Its transparency and accountability requirements, phased in through 2025 and 2026, make excellent vendor-evaluation questions.
- Absence is a decision. If publishers stay out of the conversation, AI companies and regulators write the rules for them.
- Start with education, then policy. Understand what's already happening in your workflows before you try to govern it.
There's a claim you'll hear whenever AI regulation comes up: that rules are a brake, that they'll choke innovation and slow everyone down. It's worth understanding why that's wrong. But notice where the argument comes from. It's the AI industry making it, not publishing. Look at how publishing itself is reacting to AI, and the picture is pure chaos: no shared policy, scandals, detection tools, and cancelled book deals, and case-by-case improvisation.
Two real dangers are hiding here.
First, publishers aren't in the room where the rules are being written. Second, the ones paying attention are watching the wrong door: policing whether their authors used AI to write a book, while barely asking how the AI itself was built, what it trained on, or what the vendors do with the content once it's created or shared with the system.
There's a piece of recent history that shows what engaging with regulation actually gets you. When Denmark introduced rigorous financial regulation in the years after the 2008 crisis, the consensus prediction was a chill. New rules would smother invention and send talent looking for friendlier ground. What actually happened is that the country's fintech sector expanded dramatically. By 2021, Copenhagen had become a major fintech hub, and sector reports put the Danish fintech count at about 280, a cluster built almost entirely inside the regulatory framework rather than despite it. Those companies read the rules not as a ceiling but as a design brief; they built to the constraints and found their advantage in the clarity everyone else lacked.
This story has two lessons for publishers. First, you don't have to start from scratch. Thoughtful groups have already drafted guidelines and templates you can build from. Second, and more urgent: while the industry argues about whether authors should be allowed to write with AI, the bigger questions are going unasked. What did these models train on? What happens to the content once it's shared with the system? Who's accountable when the output is wrong?
If publishers don't press those questions, the AI companies and regulators will answer them for us, and their answers won't be built to protect authors or houses.
Why Governance and Innovation Are Not in Conflict
Governance reframes innovation rather than smothering it. Organizations that treat ethical AI guidelines as design criteria, rather than a compliance tax to minimize, build more durable, trustworthy, and defensible practices than the ones that resist until regulation drags them to the table. That's the point Alexandra Andhov, a legal scholar who studies technology regulation, made with the Danish fintech case at the NCAI Summit, and it lands squarely in our world.
It all sounds intimidating, with its talk of regulation and governance, but building an AI governance framework for publishing isn't as complicated as it seems. It's probably intuitive to anyone who works in books, because it starts with the same instinct you already have about protecting an author's work. No manuscript should train an AI model without consent, a correction of the AI industry's wanton theft of IP, paired with a compensation model that fairly recognizes past theft. (The Author's Guild in particular is fighting this fight.) Notice that none of that is about whether an author used a tool to draft a chapter. It's about what the tool does with what you give it.
These are contractual obligations we can fight for, even if AI companies are going to fight back hard. The clearest competitive edge in publishing right now belongs to the houses that decide what they stand for before the market decides for them.
Internally, setting up an ethical AI framework is even easier, because we have far more control. If you've set up an internal framework for your teams, you can require that any tool your teams adopt agrees not to feed anything into training data, that every piece of marketing content run through an AI model is signed off by a human (who's then responsible for that copy as if they'd written it themselves), and that AI-assisted edits are disclosed to the writers reviewing them.
What Does a 'Design Brief' Approach to AI Governance Look Like?
A design-brief approach means starting with your constraints (your commitments to authors, readers, and data standards) and building toward capability, instead of asking what you're allowed to do. You don't have to invent it from scratch: groups like BISG and the EU AI Act have already done framework work you can borrow. Given those commitments, what does responsible AI use look like inside your specific workflows?
The approach breaks into a few concrete moves:
- Define your non-negotiables before you evaluate tools, not after. Write down what must always be true about your AI use: consent, transparency, human review, and treat that document as the brief every tool must satisfy.
- Build your AI policy around your brand and author relationships, not around what platforms allow. Vendor terms describe the minimum they'll permit; your policy should describe the maximum you'll stand behind.
- Make governance decisions as a design team, not a compliance reaction. Bring editors, marketers, and rights managers into the room early, because the people closest to the work spot the risks a legal review misses.
- Document the reasoning, not only the rule. When you revisit a policy in a year, you'll want to know why you drew a line, not just where.
The publishers who do this now will hold a real head start over the organizations still waiting for external regulation to force the question for them. Governance written in calm is always cheaper than governance written in crisis.
What the EU AI Act Says, and Why It Reads More Like a Map Than a Threat
Most publishing houses are not subject to the EU AI Act as regulated entities, and very few produce the kind of high-risk AI systems the Act primarily targets. But Andhov argues its logic is worth studying regardless of where you sit. The core requirements include transparency about training data, technical documentation, and clear lines of accountability. These describe exactly what any responsible technology organization should already be building toward. The fact that European regulation now mandates them doesn't make them a burden but a shared baseline that industries get to borrow.
The enforcement timeline
The Act entered into force on 1 August 2024 and phases in over several years. The prohibitions on unacceptable-risk AI were applied from February 2, 2025. Obligations for general-purpose AI models, the category most relevant to the tools publishers actually touch, began taking affect on August 2, 2025, with the bulk of the remaining high-risk provisions arriving through August 2026.
Those dates matter even for non-EU publishers because partners and vendors are reshaping their products to comply, and the transparency they build for Europe becomes transparency you can ask for around the world.
Turning the Act into vendor questions
Read as a design document rather than a compliance requirement, the Act hands publishing leaders a concrete framework for interrogating their AI vendors, which is exactly where the industry's attention should be:
- Where does the training data come from, and can you document its provenance?
- Who is accountable when an output is wrong, biased, or harmful?
- What technical documentation exists to verify the claims in your sales deck?
- How do you handle a request to remove content from your systems?
These are reasonable questions, and a well-governed AI company should answer them without flinching.
Who Gets Hurt When Publishing Polices AI Instead of Governing It?
Easy, the people already least protected. In 2026, at least three debut and rising authors of color had major deals scrutinized or pulled over AI-use allegations, while established authors like James Frey, who openly champions writing with AI, keep it moving like normal. When publishing polices author behavior instead of governing the technology, the harm lands unevenly.
It gets worse when you look at the tools doing the policing. The detection software driving these accusations carries the same bias as the systems it claims to catch. A Stanford study found leading AI detectors flagged roughly 61% of essays by non-native English writers as AI-generated, while barely flagging native writers at all. And the models themselves inherit racial and cultural bias from their training data. So the industry are accepting results from biased machines to judge whether marginalized writers are "really" human, a purity test built on a flawed foundation.
This is exactly the wrong door we mentioned at the beginning of this article, now with real people behind it.
The cost is cultural as much as commercial. Every episode like this teaches authors, especially marginalized ones, that the traditional path is unsafe. The more they distrust it, the more they opt out, and the industry loses the very voices it says it wants. More houses with their own clear AI governance, aimed at the technology and its provenance rather than predominantely focusing the discussion on questioning authors, is how the industry takes a much needed step in the right directon.
Why Passive Adoption Is the Real Danger
Andhov opened her NCAI session with Hannah Arendt's concept of the banality of evil, the observation that catastrophic harm rarely requires villains. It requires ordinary people who stop asking questions. She maps that directly onto AI adoption: the danger doesn't live inside the tool. It lives in passive use, in reaching for a system without asking what it's doing, who benefits, and who ends up carrying the consequences.
The leaders most likely to regret their AI decisions are rarely the ones wrestling openly with governance. They're the ones who click accept on vendor terms without reading a word, because changing those terms feels impossible. They're the ones who assume that if everyone else is using a tool it must be fine, and who treat the absence of an internal AI policy as a neutral condition rather than a standing exposure. And they're the ones so busy deciding whether their authors are "allowed" to use AI that they never turn the same scrutiny on the companies supplying it.
An organization without an AI policy has not avoided making a decision. It has made one silently and left it undefended.
We want to be honest about the trade-off, because this work is not free. Writing a governance framework takes time. Vendors and AI companies do not want to have these conversations. We understand many publishers probably don't either; it's hard. It will occasionally slow a decision you'd rather move forward, and it will sometimes rule out a shiny tool everyone in the building wants to try.
But the thoughtfulness and friction is part of the journey to making a more-aligned decision that protects not only the company, but the employees using the tools and the creators dependant upon their support.
How Should a Publishing House Start Building Internal AI Governance?
Begin with education rather than regulation: understand what's happening before you design what should happen. That order matters more than it sounds, and here's a practical sequence I've used with editorial teams:
- Map what's already in use. AI has almost certainly entered your workflows without a memo. Ask your team, honestly and without blame, where they're already using it.
- Listen to expert content and talk to your own people. The person running manuscripts through a summarizer at their desk often understands the real risks better than the leadership drafting the policy.
- Identify your highest-exposure points. Rights, author consent, and reader-facing content are usually where the stakes concentrate.
- Borrow proven frameworks. Publicly available resources like BISG's best practices for the publishing supply chain and the OECD AI Principles give you a starting scaffold you don't have to invent.
- Write a simple policy you can refine. A one-page document you'll actually follow beats a fifty-page document that lives unread in a shared drive.
The temptation with any new technology is to sprint first and reckon later, but publishing has always been a craft built on judgment: knowing which sentence to keep, which author to champion, which risk is worth taking on a debut nobody's heard of yet. AI regulation asks us to bring that same judgment to the tools we adopt, and to point it at the tools, not just at the people using them.
At Next Chapter AI, we urge publishers to demand transparency in vendor contracts and in the industry's litigation with AI companies. That's how you stop being governed by rules written elsewhere and start helping write the ones that will shape the future of intellectual property. It's also how you protect the writers most exposed to flawed, biased enforcement, so the voices that get silenced aren't the ones publishing claims to champion.
A design brief has never been the enemy of a great story. It's the shape inside which the best work happens. The publishers who write their principles down today, while it's hard, are the ones who'll breathe easier later, when the AI companies have more precedent and change gets harder. They'll be trusted as leaders in a space where creators are looking for someone with their hands on the wheel. If you're ready to build that kind of clarity into your own house, there's no better day to start than this one.
FAQ
Does AI regulation harm publishing innovation?
The evidence suggests the opposite. Well-designed governance creates clarity that enables innovation rather than restricting it. Denmark's fintech sector, which grew to about 280 firms by 2021 after its post-2008 regulatory shift, is one documented case. Organizations that know what's permitted can build more confidently than those operating in ambiguity.
What should publishers focus on in AI regulation?
Less on whether their authors used AI to write, and more on how the AI itself was built and sold. The higher-stakes questions are about the technology and the vendors behind it: what the models trained on, what happens to content once it's created or shared with the system, and who's accountable when an output is wrong. Policing author use while ignoring the tech leaves the real exposure unaddressed.
What is a 'design brief' approach to AI governance?
It means treating governance constraints as creative inputs rather than restrictions. Instead of asking what you're allowed to do, you define what you want to be true about your AI use, given your author commitments, reader trust, brand values, and data responsibilities, then build practices that fulfill it. Governance becomes a framework for building.
What does the EU AI Act say that's relevant to publishers?
Publishing houses generally aren't classified as high-risk AI providers under the Act and aren't its primary target. But its logic is a useful framework for evaluating vendors: transparency about training-data provenance, technical documentation, and clear accountability. The Act entered into force on 1 August 2024, with prohibitions from 2 February 2025 and general-purpose AI obligations from 2 August 2025.
What is 'passive AI adoption' and why is it a risk?
Passive adoption means using AI tools without examining their terms, data practices, or governance: clicking "accept" without reading. Andhov frames it through Hannah Arendt's "banality of evil." The danger lives in the failure to ask who benefits and who carries the consequences, not in the tool itself. An organization with no AI policy hasn't avoided a decision. It's made one silently and left it undefended.






