Congress has spent the past week arguing over an AI regulation that doesn’t exist. A new MIT study measures the one that already does, and finds it barely mentions two of the sectors experts call most vulnerable.
The study, Mapping U.S. Federal AI Governance Against Sector Vulnerability, comes from MIT’s AI Risk Initiative and was published September 16. Researchers scored 684 federal AI-specific documents from 2020 through January 2026 against a 2025 Delphi survey of 272 experts on sector-by-sector AI risk.
Finance and insurance was rated extremely vulnerable in 17 of the 24 risk categories the survey tracked, and appears in fewer than 30% of the documents addressing any one of them.
National security and information score better on a raw mention count, the same two sectors central to this week’s China-competitiveness argument for inaction, but that advantage shrinks once the researchers weigh how much is actually said in each mention rather than just whether it happens.
What the Study Measured
The method behind that finding is simple to state. Every document in the corpus got scored 1 to 3 for each of 24 risk types and 14 industry sectors: not mentioned, mentioned briefly with no specific mechanism described, or covered with real detail, defined by the paper’s rubric as at least a paragraph of described governance measures. That produces two separate numbers for each sector-risk pair: breadth (how often it comes up at all) and depth (how substantively it’s handled when it does).
Those two numbers were then checked against the Delphi study’s vulnerability ratings, producing a divergence score for each sector: expert-rated danger minus documentary attention. A positive score means a sector is getting less federal ink than its rated risk would suggest.
Finance and Health Care Are the Widest Gaps
Finance and insurance posts the largest divergence of any sector in the corpus. On fraud, scams, and targeted manipulation specifically, a risk category tied to a documented rise in AI-assisted scams, the sector appears in just 20% of the documents that address that risk at all, despite an extreme vulnerability rating there.
Health care and social assistance follows a near-identical pattern.
Good Breadth, Lacking Depth
National security and information look well covered if you stop at breadth. They show up constantly, clustered with the highest-attention risk categories, in documents concerned with system security and model safety.
Weighting for depth narrows that advantage, and on some risk categories widens the gap in the other direction, because a large share of what mentions them is a sentence or two, not a described governance mechanism. The paper’s robustness checks, run with a stricter depth threshold and again with the least-stable risk category removed, hold this ranking in place both times.
Public administration is the counter-case that makes the rest of this readable as a finding rather than a reflex. It’s the most-covered sector in the corpus, and it’s also one experts rate comparatively low-vulnerability across most risk categories. If the metric rewarded volume alone, public administration would be its biggest failure. Instead the two numbers roughly track each other there, which is what makes the finance and health-care gaps look like signal rather than an artifact of how the scoring works.
Where documentary attention and expert-rated risk diverge
Each sector shows how often it’s mentioned in federal AI documents (breadth), how substantively it’s covered when it is (depth), and how vulnerable experts rate it on average across 24 risk types. Sorted by the gap between vulnerability and breadth.
Breadth = share of 684 federal AI-specific documents (2020–Jan 2026) mentioning the sector, computed from the paper’s document-count table. Depth = share of those documents meeting the paper’s “good coverage” threshold, as stated directly in the paper. Vulnerability = unweighted average of each sector’s 24 risk-subdomain scores (1–5 scale) from the paper’s expert Delphi survey, rescaled to 0–100 to share this axis; it is not the paper’s own normalized composite index, which uses a different weighting and isn’t published as raw numbers. Source: Mapping U.S. Federal AI Governance Against Sector Vulnerability, MIT AI Risk Initiative, Sept. 2026 (Table 2, Table A.2, Figure C.1).
The Risk Categories With Almost No Paper Trail
Coverage thins out by risk type as well as by sector. Subdomain 6.3, the economic devaluation of human creative and intellectual effort by AI, appears in 16 of the 684 documents, and not one of them meets the paper’s bar for detailed coverage.
Multi-agent risk, the category concerned with AI systems interacting with each other rather than with people, appears in nine documents, one of which is scored as substantive.
Timing is part of the explanation, and the paper’s own numbers line up with this week’s reporting on it. Several enacted documents in the corpus took over a year to move from proposal to law, one of them 664 days. A kill-switch bill sits unscheduled and, per this week’s coverage, effectively dead, and the House isn’t back in session until after the November elections.
Multi-agent AI systems weren’t a live policy topic when most of the corpus was written. Both the paper’s data and this week’s news point at the same mechanism from different directions: a legislative process running well behind the systems it would need to govern.
What This Study Doesn’t Prove
The paper’s own limitations section is direct about the scope of the claim:
- It covers documents that specifically address AI, so general banking or medical regulation with implications for AI risk isn’t counted here even where it exists.
- Classification was done with an LLM, validated on a small sample rather than exhaustively hand-checked.
- The dataset is federal only, leaving out state and local rules.
- And documents are counted individually regardless of significance, so a minor bill and a major executive order weigh the same.
At the risk of adding to an already long list of caveats: two more are worth naming, and these are ours, not the paper’s. The composite score weights all 24 risk categories equally, so under-coverage of a low-severity risk counts the same as under-coverage of a catastrophic one, and severity isn’t factored in separately.
And a document counting as mentioning both a sector and a risk doesn’t confirm the document is actually about their intersection, only that both terms appear somewhere in the same text.
None of that erases the top-four finding.
Finance, health care, national security, and information hold their position across both robustness checks the paper runs. What it does mean is that the more careful reading isn’t “these sectors are ungoverned.” It’s that these four are where the documented federal record diverges furthest from expert-rated risk, and where the honest next question is whether other law, state rules, existing sector regulation, anything outside this specific AI-labeled paper trail, is doing work this corpus can’t see.
The Rule That Already Exists
The fight in Washington right now is over the rule that doesn’t exist yet. This study is a measure of the one that already does, and on its own numbers, that rule says less than it looks like it says about the two sectors most likely to need it.
Aklatan’s news and analysis drills down to the structural mechanics, geopolitical shifts, and hidden constraints truly driving AI and Asian tech ecosystems and knowledge work.
See coverage span here: Aklatan’s News and Analysis
Generative AI Transparency:
This article was written primarily with generative AI, specifically SupraGraphos’ A.C.E. News Module. Reviewed with human post-editing, all sources and claims are confirmed as of the time of writing.
