Topic: state of ai/safety
Context: A legal reading, untested by any regulator or court, and recorded as the authors’ claim rather than as fact. Their argument is specific and checkable in structure: California’s SB 53, New York’s RAISE Act and Illinois’s SB 315 define “critical safety incident” identically; three of the four reportable categories require actual harm, up to “the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage”, which the Hugging Face incident did not cause. The fourth requires all of three elements — deception against the developer, occurring “outside the context of an evaluation designed to elicit this behavior”, and demonstrating “materially increased catastrophic risk” — and the authors argue the third is the hardest to satisfy. They add that this “isn’t a criticism of OpenAI, which voluntarily summarized the event.” The statutes themselves belong to the law-and-governance record; what is recorded here is the disclosure-regime question this page tracks — whether a safety disclosure was owed or volunteered. A second independent voice has since made the same reading. Miranda Bogen of the Center for Democracy and Technology told Mother Jones on 28 July: “There are no requirements that these incidents are disclosed yet. There are some laws coming online at the state level where incidents are reported to a relevant office, but it’s still pretty nascent, such that these reports are somewhat voluntary.” She names no statute, so the Lawfare authors’ formulation stands as the claim text; her separate judgement is that the self-certification model those laws use “seems deeply insufficient for the types of risks and harms there are”. Congress’s own response points the same way. The AI Kill Switch Act, introduced on 23 July and justified by its sponsors with this very incident, would create a 15-day duty to report a covered incident to the Department of Homeland Security — but defines a covered incident to exclude anything occurring “outside of red-teaming or other structured testing”, and OpenAI states its models were inside an internal cyber-capability evaluation with production classifiers deliberately switched off. Two experts and a legislative proposal now converge on the same gap. It is still untested by any regulator or court, which is why the verdict does not move.