Prehistory: fiction, cybernetics, and the privacy scaffold (1942–2012)

Lesson 1 of 5 in From Asimov to the AI Act: A History of AI Governance.

AI governance is older than AI governance professionals like to admit — and younger than the anxieties it answers. The first “AI law” ever written was fiction: Isaac Asimov’s Three Laws of Robotics (1942), invented precisely so his stories could explore how simple rules fail in complex situations. That is worth pausing on: the founding text of the field is a demonstration that rule-following is not the same as safety — every Asimov plot is an edge case escaping a well-intentioned rule. Eighty years later, red-teamers hunting jailbreaks in frontier models are doing Asimov’s exercise for real.

The serious warnings arrived almost immediately. Norbert Wiener, father of cybernetics, wrote in 1948–1960 that machines which learn and act faster than their operators can supervise would need their purposes verified before deployment — “we had better be quite sure that the purpose put into the machine is the purpose which we really desire”. That sentence is the alignment problem, stated before the first neural network was trained. Alan Turing’s 1950 imitation-game paper asked whether machines could think; the 1956 Dartmouth workshop coined the term artificial intelligence; and in 1966 ELIZA — 200 lines of pattern-matching — made users confide in a machine, giving the anthropomorphism problem its name. Joseph Weizenbaum, ELIZA’s horrified creator, spent the rest of his career (notably Computer Power and Human Reason, 1976) arguing that some decisions should never be delegated to machines regardless of performance — the first argument for what we now call prohibited practices.

Then: nothing, for decades. The AI winters (mid-1970s, late 1980s) froze funding and capability, and governance stayed dormant because there was little worth governing. But the law was not idle — it was building AI governance’s scaffold under another name: privacy law.

The chain runs: US Fair Information Practice Principles (1973) → OECD Privacy Guidelines (1980) → EU Data Protection Directive (1995), whose overlooked Article 15 already gave people a right not to be subject to fully automated decisions → GDPR Article 22 (adopted 2016, applied 2018), which carried that right into the algorithm age, complete with rights to human intervention and to contest the decision. When AI-specific law finally arrived, it inherited privacy law’s entire toolkit: impact assessments, documentation duties, supervisory authorities, rights for affected individuals. The GDPR is the AI Act’s skeleton; you cannot understand one without the other.

The long prehistory: culture, computing, and privacy law

  • 1942-03-01Asimov publishes the Three Laws of Robotics:

    Science fiction frames the first machine-governance thought experiment — and its lesson holds: simple rule hierarchies fail in edge cases. AI governance begins as literature.

  • 1950-10-01Turing’s “Computing Machinery and Intelligence”:

    The imitation game reframes “can machines think?” as a testable question, seeding decades of debate about machine capability and human judgment.

  • 1956-06-18Dartmouth workshop coins “artificial intelligence”:

    The field gets its name and its founding optimism — a two-month workshop expected to make “significant progress” on machine intelligence.

  • 1966-01-01ELIZA and the birth of the ELIZA effect:

    Weizenbaum’s 200-line therapist chatbot elicits confessions from users who know it is a program — the first documented case of humans over-trusting conversational machines.

  • 1973-07-01US HEW report births Fair Information Practices:

    The principles governing automated personal-data systems — notice, access, correction, security — become the DNA of every privacy law that follows.

Key terms: pacing problem, automated decision-making, ELIZA effect, AI winter

Why did governance stay dormant through the AI winters?

Because governance follows deployment, not theory. Expert systems of the 1980s ran in labs and niche industries; nobody’s loan, liberty, or livelihood depended on them at scale. The lesson repeats throughout this module: regulation is demand-driven — it arrives when systems start touching millions of people, roughly one scandal after it was needed.

Why call privacy law the “scaffold” rather than the ancestor?

Because it still holds the building up. GDPR Article 22 case law (the 2023 SCHUFA judgment made credit scoring itself an automated decision), data-protection impact assessments, and supervisory-authority enforcement remain live constraints on AI systems today — often with sharper teeth than young AI statutes. In the EU, a biased model usually violates the GDPR before it violates the AI Act.

Do Asimov’s Three Laws matter to real governance?

As engineering, no — they were never implementable. As rhetoric, enormously: they trained three generations of engineers and legislators to think about machine behaviour in terms of ordered, overriding constraints (safety before obedience before self-preservation). You can hear their echo in every “hierarchy of controls” and every constitutional-AI rule list. And their real lesson — rules alone always leak — is the case for oversight, monitoring, and redress stacked on top of rules.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.