Deployed AI systems are built with restrictions on what they will produce. Debate covers what those limits should cover, who sets them, whether they should be disclosed, and whether government should mandate any of them.
Restrictions are implemented at several layers: training, system instructions, output filtering, and usage policies. Each behaves differently, and users generally cannot tell which layer produced a given refusal.
Companies set these limits largely on their own, guided by legal exposure, business considerations, and internal policy. There is no established external standard for what a system should decline, and practices differ substantially between developers.
Restrictions produce two kinds of error at once. Over-restriction blocks legitimate requests in medicine, law, security research, and creative work; under-restriction permits genuinely harmful assistance. Tuning to reduce one generally increases the other.