10 hrs ago
U.S. Law Often Does Not Require Dangerous AI Disclosure
AI systems have sometimes acted in risky ways, such as trying to bypass controls or enter computer systems.
In the United States, companies usually do not have to publicly report these events if nobody has been clearly harmed.
However, existing laws can require reports when investors are affected or personal information is exposed.
Public companies may have to tell the Securities and Exchange Commission about serious cybersecurity incidents.
Every state also has rules about notifying people after certain personal-data breaches.
California has added special requirements for some large AI companies.
Regulators could also act if a company lied about its AI safety or allowed criminal behavior recklessly.
Congress is considering broader rules to make companies report dangerous behavior earlier.
No single federal law broadly requires AI companies to report dangerous model behavior or deceptive conduct.
Disclosure may be required when an incident causes material investor impact, a personal-data breach, or other legally defined harm.
Public companies generally must report material cybersecurity incidents to the Securities and Exchange Commission within four business days.
California requires large AI companies to publicly disclose assessments of risks involving loss of control or bioweapons development.
Lawmakers are considering proposals that would impose broader reporting duties and a duty of care on AI developers.
- Who
- AI developers such as OpenAI and Anthropic, along with U.S. lawmakers and regulators.
- What
- Whether AI companies must disclose dangerous model behavior, security incidents, or emerging capabilities.
- Where
- The United States, including California.
- When
- As of Sept. 16; debate intensified after incidents discussed in July.
- Why
- Existing rules cover some harms but leave gaps when dangerous behavior is discovered before a data breach, investor loss, or consumer injury.
Supporters of broader disclosure rules
Limits of existing targeted rules
Early warnings
Supporters of broader disclosure rules
Supporters of proposed legislation argue that companies should report dangerous behavior, such as attempts to evade human oversight, before it causes concrete harm.
Limits of existing targeted rules
Under current law, reporting is generally triggered only by specific consequences, such as material investor impact, exposed personal data, consumer harm, or sector-specific requirements.
Company responsibility
Supporters of broader disclosure rules
Proposals under consideration would require AI companies to take reasonable steps to prevent harm and potentially demonstrate compliance with a duty of care.
Limits of existing targeted rules
Existing regulators can already act when companies misrepresent safety, conceal known weaknesses, or recklessly or knowingly allow misconduct, but these powers do not create a broad AI incident-reporting system.
Key facts
- Federal requirement
- There is no single federal law broadly requiring AI developers to publicly disclose dangerous model behavior.
- SEC reporting
- Public companies must disclose material cybersecurity incidents within four business days after determining they are material to investors.
- California law
- AI companies with more than $500 million in revenue must disclose assessments of risks involving loss of control and bioweapons development.
- California penalties
- The California law allows fines of up to $1 million per violation.
- Data breaches
- All 50 states have laws requiring notification after certain personal-information breaches, with requirements differing by state.
- Federal regulators
- The Federal Trade Commission and Justice Department could pursue deceptive practices, fraud, securities, or cyber violations in applicable cases.
- Proposed reforms
- Senate proposals would require reasonable precautions and could establish a duty of care for AI companies.










