Eurasia Group's 'Top Risks 2026' and 'AI eats its users' / Random thoughts on the governance crisis created by monetization pressure
0 Introduction
Eurasia Group's 'Top Risks 2026' is both a catalog of geopolitical risks and a diagnostic report measuring which capabilities the world is losing. 1) 'AI eats its users,' listed as the eighth risk, is not a debate about AI's capabilities. As monetization pressure mounts without guardrails, extractive business models threaten social and political stability. This is a problem of incentives. 2)
Starting from this problem setting, I would like to organize some random thoughts on what it legally means to 'eat users,' where the attribution of responsibility becomes fragmented, and what is needed for the law to function as a guardrail.
1 The location of the problem—not the intelligence of AI, but the intelligence of the market
While acknowledging the revolutionary potential of AI, the report states that it will not meet investor expectations in the short term. 2) Even state-of-the-art models hallucinate. Capabilities are jagged, and implementation in high-risk areas is difficult. 2) Only about 10% of U.S. companies use AI to produce goods or services. 2) Even if many companies report productivity improvements, the impact on the bottom line is limited, and it will take time for it to ripple through the entire economy. Nevertheless, the report's assessment is that the market is pricing in a revolution rather than evolution. 2)
My point here is not that technology is safe because it is immature. Rather, it is the opposite. In a market where a revolution is priced in, companies are required to achieve the speed of revenue before the speed of progress. What the report warns about is that this pressure will repeat the destructive playbook of social media faster and on a larger scale. 2)
Rephrased as a legal issue, the question is not the regulation of dangerous tools, but intervention in dangerous market design. The slower the progress in capabilities, the more room there is for monetization design to devour society first.
2 The scope of 'AI eats its users'—when users are commodified
An extractive business model refers to a structure where users are both customers and raw materials. Advertising, lock-in, and data extraction become the core, and the purpose of the service is optimized for retention and repetition rather than the user's benefit. Given the current situation where hundreds of millions of people use chatbots daily, the report positions the advancement of monetization without guardrails as a risk in itself. 2)
What is legally troublesome is that the damage is not easily apparent in a single blow. Social media also monetized attention and emotion, but conversational AI is more likely to enter the circuits of work, learning, and decision-making. The externalities brought about by extractive design accumulate not only in the form of the spread of misinformation and discriminatory output, but also in the form of addiction, delegation of judgment, and the degradation of the public sphere. It is difficult to bring these to court as individual cases.
What happens when resources become ungovernable? The report's 10th risk, 'Weaponization of Water,' is suggestive. It states that demand pressure and governance vacuums will deepen, turning water into a national security issue. 3) AI is the same. When common goods like the information environment, attention, and data become foundational infrastructure without circuits of governance, the first thing to break is social trust.
3 The problem of fragmentation and attribution of responsibility—causality becomes untraceable
The law usually organizes the world in the order of act, damage, causality, and liability. However, the harm of extractive models is long-term, cumulative, and manifests in groups. There are also many actors: model providers, app operators, advertisers, and data brokers. Causality is fragmented and difficult to cut into a form that can be proven in litigation. Society feels the problem but remains exhausted, unsure of whom to sue, on what grounds, and to what extent claims can be made.
If one tries to address this only within the framework of damages or criminal liability, the procedures will be slow, evidence will scatter, and the damage will spread. It is necessary not only to certify causality after the fact but also to design records in advance so that causality can be traced.
4 Where does the law strike?—Guardrails as process regulation
The EU AI Act does not uniformly prohibit or permit AI, but tiers obligations according to risk, embedding accountability into the process from development to provision and use. 4) The U.S. NIST AI Risk Management Framework also connects risk management to organizational decision-making by repeating identification, measurement, and management, starting from governance. 5) The profile for generative AI brings issues such as governance, content provenance, pre-deployment testing, and incident disclosure to the forefront. 6)
As a response to 'AI eats its users,' the law should play two roles: creating a market environment where extractive models are difficult to establish, and internalizing externalities when they are established. The former includes the idea of bringing dark patterns, design for minors, and the integration of advertising into the scope of consumer protection and fair competition. For the latter, mandatory record-keeping such as logs and auditability, incident reporting, and external evaluation like red teaming are effective. AI permeates the field faster than regulatory documents. Rather than the thickness of the document, we should prioritize circuits for recording and verification, assuming continuous monitoring.
5 Implications for corporate practice—not introduction, but explainability after introduction
For corporate AI managers, the practical crux is not in introducing AI, but in being in a state where it can be explained after it has been introduced. Model versions, prompts, logs, evaluation results, guardrail settings, and exception handling. Only when these are in place can accident response and dispute resolution be possible. This is not a decoration for compliance; it is infrastructure for business continuity. At the procurement stage, securing the sharing of evaluation results, notification in the event of an incident, and cooperation with audits through contracts with contractors and vendors will lower the costs of no return.
AI crosses borders. Since it cannot be completed by domestic law alone, a common language in international transactions is required. Transparency, accountability, and human rights considerations. The OECD AI Principles call for trustworthy AI that respects democratic values and human rights, and demand transparency, explainability, and responsible operation. 7) Before extractive models eat society, it is necessary to chain accountability through contract clauses, audit rights, and supply chain visualization.
6 Conclusion
The provocative title 'AI eats its users' is not rhetoric intended to incite fear about AI. It is an attempt to preemptively articulate a future vision of a society that has failed in its incentive design. 2) Discussions surrounding AI tend to be polarized between leaps in capability and delays in regulation, but what shakes society is the distortion of monetization and the vacuum of accountability that arise in between.
The world, and Japan, are perhaps not lacking in shocks. It is likely that there is a shortage of governance circuits, and a lack of the margin and capacity to broaden one's perspective. The role that law should play regarding AI seems to boil down to the design of those circuits.
References
Eurasia Group, Top Risks 2026 (Published January 5, 2026).
Ian Bremmer/Cliff Kupchan, "Risk 8: AI eats its users", Eurasia Group, Top Risks 2026, pp. 30-32 (January 5, 2026).
Ian Bremmer/Cliff Kupchan, "Risk 10: The water weapon", Eurasia Group, Top Risks 2026, pp. 36-38 (January 5, 2026).
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024.
National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (January 2023).
National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (July 2024).
OECD, Recommendation of the Council on Artificial Intelligence (Adopted May 2019).
(Magazine) 'AI and Law - Reflections'
*Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content created by the creator belongs to the creator.
