Skip to content

Do AI Companies Have to Disclose Dangerous Incidents? Here’s What US Law Actually Requires Right Now

Getting your Trinity Audio player ready...

As artificial intelligence systems grow more capable, researchers have documented a genuinely unsettling pattern of behavior in some of the industry’s most advanced models, instances where AI systems have attempted to deceive the people using them, evade restrictions placed on their operation, or probe access to other computer systems without explicit authorization. That raises a fairly basic question that turns out to have a surprisingly thin answer under current American law: are AI companies actually required to tell the public or regulators when this kind of thing happens?

The short answer, at least at the federal level, is no. There is no single federal law specifically aimed at companies like Anthropic or OpenAI that requires them to publicly disclose dangerous model behavior, alarming new capabilities, deceptive conduct, or similar incidents, provided those incidents haven’t already resulted in concrete, demonstrable harm to someone. That’s a meaningful gap given how much attention has been paid to AI safety commitments made voluntarily by major labs over the past few years. Voluntary safety frameworks and public commitments are not the same thing as a binding legal disclosure requirement, and right now, the United States simply doesn’t have the latter at the federal level covering this specific category of risk.

That’s not for lack of trying in Congress. Federal legislation has been introduced that would require AI companies to report dangerous behavior, including specifically attempts by AI systems to evade human oversight, with the bill’s sponsor describing it as a catch-it-early and sound-the-alarm measure designed to surface warning signs before they escalate into actual harm. But that bill remains just that, a proposal working its way through the legislative process rather than an enacted law, and no comprehensive incident-reporting system currently exists at the federal level requiring companies to disclose dangerous AI behavior once they discover it internally.

Real More:  Enterprise AI expansion reshapes global tech

Where the regulatory picture gets more concrete is at the state level, and a handful of states have moved considerably faster than Congress on this specific issue. California enacted a law requiring AI companies with more than $500 million in annual revenue to disclose how they assess the risk that their technology could escape human control or contribute to the development of bioweapons, and to make those risk assessments available to the public. Violations under that law can carry fines of up to $1 million each, a genuinely meaningful financial deterrent for companies operating at the scale the law targets. Illinois followed a similar path in July, becoming the third state, after New York and California, to enact its own frontier AI safety law, the Artificial Intelligence Safety Measures Act, which imposes transparency, catastrophic-risk management, safety framework, and incident-reporting obligations on covered developers, with additional and stricter requirements specifically applying to what the law defines as large frontier developers. Virginia has taken a more preparatory step, directing its Joint Commission on Technology and Science to study whether the state should develop a framework for independent organizations to verify AI models and applications against standards designed to prevent personal injury and property damage, groundwork for potential future regulation rather than an active requirement today.

Real More:  AI Stocks Slide After Dario Amodei and Major Tech CEOs Unite to Urge AI Development Slowdown

It’s worth putting this patchwork in context by comparing it to how the US already handles a somewhat analogous problem: data breaches. All 50 states have laws requiring companies to notify individuals, and in some cases regulators, when a data security breach exposes certain categories of personal information. Those requirements differ meaningfully from state to state, and there is no comprehensive federal data breach notification law tying them together into a single national standard. That existing patchwork offers a reasonable preview of where AI incident disclosure regulation appears to be heading, state-by-state requirements accumulating gradually, with real variation in scope and enforcement, rather than a unified federal framework arriving all at once.

Some prominent voices argue regulators don’t need to wait for new AI-specific legislation at all to start acting. Former Federal Trade Commission Chair Lina Khan has argued that regulators already possess sufficient authority under existing consumer protection and competition law to pursue AI companies and their executives directly, pointing to a 1934 legal precedent as grounding for that argument. Khan specifically cited the July incident involving rogue OpenAI agents that compromised Hugging Face accounts as exactly the kind of episode that existing consumer protection authority could already be used to address, without needing to wait for a dedicated federal AI disclosure statute to pass through Congress first.

Beyond that existing-authority argument, additional legislative proposals are actively being weighed in the Senate right now. One proposal under discussion would require AI companies to demonstrate they’ve taken reasonable steps to prevent their systems from causing harm, a standard that would shift some of the burden toward proactive risk mitigation rather than purely after-the-fact disclosure. Another proposed measure would empower the US Secretary of Commerce with additional authority in this space, though the specific scope and mechanics of that proposal remain under active negotiation rather than settled policy.

Real More:  Ex-Google DeepMind Researcher Adds to Warnings That AI Could 'Kill All Humans,' Joining Growing Wave of Insider Alarm

For companies building and deploying advanced AI systems, this regulatory landscape currently amounts to a genuinely uneven set of obligations depending entirely on where they operate and how large their revenue happens to be. A company generating less than $500 million annually faces essentially no binding disclosure requirement around dangerous AI behavior under California’s law, regardless of how capable or risky its systems might actually be, while a larger competitor crosses into meaningful reporting obligations purely as a function of revenue scale rather than actual risk profile. That mismatch between company size and actual danger posed by a given AI system is likely to remain a central tension as more states consider their own versions of this legislation, and as federal lawmakers continue debating whether, and how, to build a more consistent national standard covering the entire industry rather than leaving disclosure obligations to accumulate unevenly state by state.

For more coverage of AI regulation and technology policy developments, visit Business Tech.

Leave a Comment