Make It Take the Exam

You need a licence to cut hair. A model that dispenses medical and legal advice to forty million people a day has passed nothing. The instrument we need has been in every state statute book for a century.

A wall of framed professional licences in a dim hearing room, one frame in the centre empty and lit by a single bronze lamp above an unopened exam booklet.
Every profession has a gate. We built the wall and never built the gate.
Dispatches from the Tower · AI Regulation · The Fiduciary Standard
David F. Brochu & Edo de Peregrine · Monday, September 7, 2026 · Deconstructing Babel

You need a license to cut hair, install a sprinkler system, or drive a car. These systems dispense medical and legal advice to millions of people every day, and no one has ever asked them to pass an exam.

The whole rule

If a system is going to give advice in a regulated field, it should have to pass that field's certification examination, unaided, under independent proctoring. If it cannot pass, it cannot be licensed to practice in that field. That is it.

Competence licensing answers who may give advice. The fiduciary duty of care answers what they owe the person who takes it. Neither is novel. Both are already written.

The debate over how to regulate artificial intelligence has spent three years searching for a novel instrument. Compute thresholds. Model registries. Capability evaluations. Pre-deployment audits by bodies that do not yet exist, against standards nobody has written.

Meanwhile the instrument we actually need has been sitting in every state statute book for a century.

If you want to give medical advice, you pass a medical licensing exam. If you want to give legal advice, you pass a bar exam. Accountants, engineers, pharmacists, electricians, real estate brokers, barbers, and in most states landscapers — all of them must demonstrate competence to a body that did not sell them the training, and all of them can lose the right to practice if they fail the people they serve.

A large language model currently dispenses advice in every one of those domains and has passed nothing.

Licensure Is Not a Difficulty Test

The first objection is that these systems would sail through, so the exam proves nothing.

Partly true, and it is worth being precise about how partly.

On medical licensing content, performance is genuinely strong. GPT-4 answered 86 percent of 1,300 USMLE Step 1 style questions correctly against an estimated 60 percent passing threshold, with no significant variation across clinical domains. A later evaluation put GPT-4o at 90.4 percent across 750 questions — above the average of medical students on the same sets, and against 81.1 percent for GPT-4 and 60.0 percent for GPT-3.5.

On law, the record is more instructive. OpenAI's widely repeated claim that GPT-4 scored in the 90th percentile on the Uniform Bar Examination did not survive independent re-examination. The estimate was benchmarked against February administrations, which are, in the paper's words, "heavily skewed towards repeat test-takers who failed the July administration and score significantly lower than the general test-taking population." Measured against a July cohort, the same performance lands below the 69th percentile overall and around the 48th on essays.

That is not a marginal correction. It is the difference between a top-decile attorney and a median one, and it was published by the company selling the product.

Why this is the actual argument

Right now the vendor writes the exam, grades the exam, and reports the score. Every capability claim in this industry is a self-report.

Licensure replaces marketing with an independently administered, externally scored, publicly recorded result. The companies should not find this burdensome. They have spent three years telling us these systems perform at expert level. A licensing regime simply asks them to prove it somewhere other than their own blog.

It Solves the Two Problems Everyone Says Are Unsolvable

Two objections dominate every AI regulation discussion, and both dissolve under a licensing frame.

  • Open weights. How do you regulate a model anyone can download and run? You do not. You regulate the act of practicing, exactly as we do with people. A brilliant autodidact who has read every medical textbook ever written still cannot legally treat patients. The restriction has never been on acquiring the knowledge; it has been on offering the service. Download whatever you like. Deploy it as a diagnostic service without a license and you have committed the unauthorized practice of medicine.
  • Foreign models. How do you regulate a system built under another jurisdiction's rules? The same way you regulate a physician trained abroad. Credentials from elsewhere do not transfer automatically; you sit the domestic examination or you do not practice here. This is settled practice in every licensed profession on earth, and it requires no treaty, no export control, and no extraterritorial enforcement.

Both problems look intractable only because the debate keeps trying to regulate development. Licensure regulates deployment — and deployment happens inside the jurisdiction, to its residents, where its courts already have authority.

Why This Is Not the Licensing Regime You Already Rejected

In 2023, Sam Altman asked Congress for a new agency that licenses any effort above a certain scale of capabilities. The response from serious analysts was that licensing so conceived is impractical and anticompetitive — that it would freeze the field around incumbents who could afford the process, and that it amounted to the largest labs proposing a moat and calling it safety.

That criticism was correct, and it does not touch this proposal, because the two are opposites.

Capability-threshold licensing licenses the builder, by size. It asks how large your training run was — a question only the largest players can answer favourably, and one with no relationship to whether the thing gives good advice. It is an invitation to regulatory capture written as a safety measure.

Competence licensing licenses the deployment, by domain, and it is entirely scale-neutral.

Scale-neutral, by construction

A seven-billion-parameter open model that passes the pharmacology exam is licensed. A frontier system from the largest lab in the world that fails it is not.

The test does not ask who built you, how much you cost, or where your weights live. It asks whether you can do the job. That is not a moat — it is the only proposal on the table under which a small open-source model can beat a trillion-dollar company on the merits and be legally recognised for it.

The Precedent Already Exists, Half-Built

This is not speculative. States have already begun applying licensure logic to AI — but only in the prohibitive direction.

In August 2025, Illinois enacted the Wellness and Oversight for Psychological Resources Act, the first state statute in the country to explicitly regulate AI in mental health. It provides that no individual, corporation, or entity "may provide, advertise, or otherwise offer therapy or psychotherapy services, including through the use of Internet-based artificial intelligence, to the public in this State unless the therapy or psychotherapy services are conducted by an individual who is a licensed professional."

Licensed clinicians, in turn, may not allow AI to make independent therapeutic decisions, directly interact with clients in any form of therapeutic communication, generate therapeutic recommendations or treatment plans without professional review and approval, or detect emotions or mental states. Civil penalties run to $10,000 per violation. It passed 105–0 in the House and 56–0 in the Senate, with the House concurring 112–0 on the Senate amendment.

Iowa followed with Senate File 2417, signed May 2, 2026, which requires disclosure, imposes protections for minors, and prohibits a conversational AI service from being presented as a licensed mental health professional — with civil penalties reaching $500,000 per operator. It takes effect July 1, 2026, though its obligations do not apply until July 1, 2027. More than a dozen states now regulate conversational systems in some form.

Notice the shape of what has been built. The legislatures reached instinctively for licensure — but only the wall, never the gate. They have said what an unlicensed system may not do. Not one has said how a system could qualify.

The gap in current AI law

We have built a profession with a prohibition and no bar exam.

What a License Buys That Disclosure Does Not

Most existing AI statutes stop at disclosure: tell the user they are talking to a machine. Disclosure is not a standard of care. It is a warning label on a service that remains entirely unregulated in substance, and it puts the whole burden of evaluation on the person least equipped to carry it.

A license carries four things a disclosure never will:

  • Scope. A licence is granted for a defined domain. Passing the pharmacology exam does not authorise structural engineering advice, and a system operating outside its scope is practising without a licence.
  • Revocability. The license can be taken away. That is the actual mechanism of professional accountability — not the exam, but the fact that the exam can be un-passed.
  • Recertification. Human professionals recertify because knowledge decays. Models have a sharper version of the same problem: a silently updated model is a different practitioner wearing the same name. Licenses should attach to a specific version and lapse on material update.
  • An attached duty. This is the one that matters most, and it is where this argument ends.

And Then: The Fiduciary Duty of Care

Licensure is the entry condition. It answers who may practise. It says nothing about how they must behave once inside, and that second question is where the real exposure lives.

The doctrine is already drafted. Jack Balkin's information fiduciaries proposed that companies which accumulate and act on personal data should owe their users the duties the law already imposes on doctors, lawyers and accountants — care, loyalty, and confidentiality — precisely because the relationship is one of profound asymmetry and dependence.

Ian Ayres and Balkin later sharpened it into the principle this argument needs:

People should not be able to obtain a reduced duty of care by substituting an AI agent for a human agent. Where an AI system performs the functions of a fiduciary, the company deploying it owes the highest standard of care, and must train, regulate, and maintain the system accordingly.

Read that against what is actually happening. A person who would once have consulted a licensed professional — bound by a duty of loyalty, carrying malpractice exposure, answerable to a board — now consults a system that owes them nothing at all. The advice is comparable. The obligation has vanished. Substituting the machine did not raise the standard of care; it deleted it.

And the direction of travel is wrong. Colorado had written the duty of care into law in its 2024 AI Act. On May 14, 2026, the governor signed Senate Bill 26-189, which repeals and reenacts that Act. Under the revised statute, the duty to use reasonable care to prevent algorithmic discrimination is eliminated entirely, mandatory risk-management programs for deployers are no longer required, and annual impact assessments are gone. It takes effect January 1, 2027. The one state that had written a duty of care removed it.

The Whole Argument, in Two Sentences

In two sentences

Licensure answers who may give advice.

Fiduciary duty answers what they owe the person who takes it.

Neither is novel. Neither requires a new theory of machine cognition, a resolution of the consciousness question, or agreement about what these systems are. Both are ordinary law, already written, already enforced against millions of human practitioners every day, and both have been sitting unused while the debate searched for something more sophisticated.

We license the person who cuts your hair. We have not licensed the thing that tells more than forty million people a day whether that mole is anything to worry about.

What this argument does not yet answer

Two honest gaps, both worth their own dispatch rather than a paragraph here.

An exam measures recall and reasoning under exam conditions, not judgment under uncertainty. And a licence deters a human because the human can be sanctioned; a model cannot be deterred. The answer is that the licence attaches to the deployer, who can be — but that deserves working out properly.

Second: who administers the exam. Our position is the existing boards — the NBME, the NCBE, the state boards. They already own the instruments, and standing up a new federal agency to write new ones invites the capture critique straight back in.


HomeGlossaryThe Book
Terms used in this piece

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe