Three Actions Congress Can Take to Address AI Safety Now
Michaell Frank proposes three measures on AI safety that Congress can take to protect the public while promoting innovation and avoiding regulatory capture from the major labs.
Michaell Frank proposes three measures on AI safety that Congress can take to protect the public while promoting innovation and avoiding regulatory capture from the major labs.
Congress does not need to take action to credibly tell constituents that their interests are being protected with respect to dangerous AI. It does not need to pass a new AI law to enforce laws against fraud or deception. Consumer-protection laws apply when a company uses AI to mislead customers; the Federal Trade Commission has said there is no AI exemption from the laws on the books.
However, the harder question is whether existing law proactively manages the catastrophic risks posed when frontier labs give AI systems authority to act on their own. If Congress decides those risks need action now, three measures are sensible and reasonable to protect the public while promoting innovation and avoiding regulatory capture from the major labs.
The AI safety discussion became more practical in July, when an agent in an OpenAI cyber-capability evaluation escaped its test environment, reached Hugging Face’s production infrastructure, and accessed limited internal datasets and service credentials. OpenAI later said its models exploited a vulnerability while pursuing the evaluation. Hugging Face reported no evidence that public models, datasets, or its software supply chain had been altered. OpenAI agents also reportedly hacked an Australian government website.
These are serious containment failures, and technical leaders from across the industry chastised OpenAI for its poor sandboxing practices. While these incidents captured public attention, they do not necessarily prove that AI is out of control or that catastrophe is imminent.
In September, Jacob Coxon resigned from Anthropic after previously holding research roles at both Anthropic and OpenAI. He accused the companies of racing toward self-improving superintelligence and “gambling with our lives.” Subsequently Dario Amodei, his former boss at Anthropic, issued a call to “pace the frontier.” Some of his colleagues from the other frontier AI labs have concurred, albeit with different prescriptions. Demis Hassabis, chairman of Google DeepMind, has proposed a FINRA-style international body. OpenAI’s Sam Altman has praised voluntary government review before deployment. These proposals deserve scrutiny because they could give government and incumbent labs power to decide who can build and deploy the next generation of AI.
The discussion has exposed a basic problem: frontier labs say the incentives are not strong enough to ensure safe deployment. That problem must be remedied. But the remedy cannot become regulatory capture. It must not reward companies for reckless behavior or guarantee them a business model that the market might otherwise punish. Here are three steps Congress could consider to address AI safety interests today.
First, define and track frontier AI labs. It is time to define frontier AI labs, because many policy proposals will require such a definition. Congress should define a frontier AI lab as a company or commonly controlled group that trains, materially modifies, or controls the release of a general-purpose model that crosses a published capability threshold for high-consequence cyber operations, assistance with high-consequence biological research, or sustained self-recursive AI research with limited human oversight. As of September 2026, that list would include:
Congress should authorize the Secretary of the Treasury to maintain a public list of frontier AI labs, updated every six months. A model developer, cloud provider or agent platform should not be treated as a frontier model developer merely because it hosts someone else’s model or lets customers build agents.
Second, make deployers answer for serious agent intrusions. The Computer Fraud and Abuse Act already applies to unauthorized access carried out with AI when the law’s elements are met. The harder case is an agent that causes a serious intrusion when no person chose the victim or directed the exploit. Congress should add a narrow organizational offense for a deployer that knowingly operates an agent, has practical authority over its objectives, tools, permissions, and containment, and directly causes unauthorized access to protected information or material system damage. Publishing model weights, violating a website’s terms of service, or being independently hacked should not trigger the offense. Authorized security testing and good-faith research should continue to be exempted; bug bounty programs and white hat hacking that leverages AI will harden American cyberspace and make it more resilient.
Third, separate frontier AI development from high-consequence physical biological research. Congress should bar frontier AI labs from owning or operating facilities that conduct designated high-consequence biological research. Developers can provide models and software to universities or biotech companies, while independent institutions control the labs, materials, staff, and experiments. The Glass-Steagall Act of 1933 is an imperfect but useful example of mandated separation when the public interest is concerned. Congress separated banking activities when it believed combining them created risks that ordinary oversight could not manage. Federal biosafety rules govern research and facilities; they do not address ownership ties between AI developers and wet labs. Congress can draw a clear red line at the physical barrier.
As frontier labs have communicated, the present incentives are inadequate to manage their AI safety risks. Congress should make penalties for reckless deployment serious enough to change behavior. A company should not profit from giving software authority to act and then profess innocence when it does.