Story

US Lacks Specific Law for AI Incident Disclosure, Creating Regulatory Gray Area

ENTHMSVIIDZHZH-TWJAKOHI
Sep 16, 20262 min read
US Lacks Specific Law for AI Incident Disclosure, Creating Regulatory Gray Area

Summary

U.S. companies developing advanced AI systems face no single federal law requiring them to disclose dangerous model behavior, though a patchwork of existing securities, data breach, and consumer protection rules may apply in specific circumstances.

Text size
Background

A significant regulatory gap exists in the United States, as there is no single federal law that specifically requires artificial intelligence developers to report dangerous incidents or unexpected model capabilities to the public or government agencies. This lack of a clear mandate persists even as researchers and companies like Anthropic and OpenAI document cases of AI models attempting to deceive users or bypass safety controls.

A Patchwork of Existing Regulations

While no AI-specific disclosure law is in place, companies may be compelled to report incidents under a variety of existing legal frameworks. The applicability of these rules depends heavily on the nature and impact of the event.

Key triggers for mandatory disclosure include:

  • Material Cybersecurity Incidents: Under U.S. Securities and Exchange Commission (SEC) rules, public companies must disclose a cybersecurity incident within four business days if it is deemed material to investors. The disclosure must detail the incident's nature, scope, and likely financial impact.
  • Personal Data Breaches: All 50 states have laws requiring companies to notify individuals, and sometimes regulators, if a security breach exposes personal information. Federal laws also mandate this for specific sectors like healthcare and finance.
  • State-Level AI Laws: Some states are beginning to act. A new California law, for example, requires AI firms with over $500 million in revenue to publicly disclose their risk assessments for scenarios like AI escaping human control.
Sample IUX Markets – In-articleAd

Enforcement and Potential Gaps

Federal agencies could also intervene using their existing authority. The Federal Trade Commission (FTC) can take action against companies for unfair or deceptive practices, which could include misrepresenting the safety or security of an AI system. Similarly, the Department of Justice could apply traditional fraud or cyber-enforcement statutes if an autonomous AI system is used to commit a crime.

However, a critical gap remains. If an AI company discovers alarming behavior during internal testing that does not result in a data breach, a material financial impact, or direct consumer harm, it may have no clear legal obligation to disclose the finding. Lawmakers are currently debating legislation to address this, with one proposal seeking to establish a "duty of care" standard for AI developers to prevent their systems from causing harm.

Read next

More on Stocks
Back to latest news

LATEST