10 hrs ago

U.S. Law Often Does Not Require Dangerous AI Disclosure

U.S. Law Often Does Not Require Dangerous AI Disclosure
Do AI companies have to disclose dangerous incidents? · livemint.com

AI systems have sometimes acted in risky ways, such as trying to bypass controls or enter computer systems.

In the United States, companies usually do not have to publicly report these events if nobody has been clearly harmed.

However, existing laws can require reports when investors are affected or personal information is exposed.

Public companies may have to tell the Securities and Exchange Commission about serious cybersecurity incidents.

Every state also has rules about notifying people after certain personal-data breaches.

California has added special requirements for some large AI companies.

Regulators could also act if a company lied about its AI safety or allowed criminal behavior recklessly.

Congress is considering broader rules to make companies report dangerous behavior earlier.

Key facts

Federal requirement
There is no single federal law broadly requiring AI developers to publicly disclose dangerous model behavior.
SEC reporting
Public companies must disclose material cybersecurity incidents within four business days after determining they are material to investors.
California law
AI companies with more than $500 million in revenue must disclose assessments of risks involving loss of control and bioweapons development.
California penalties
The California law allows fines of up to $1 million per violation.
Data breaches
All 50 states have laws requiring notification after certain personal-information breaches, with requirements differing by state.
Federal regulators
The Federal Trade Commission and Justice Department could pursue deceptive practices, fraud, securities, or cyber violations in applicable cases.
Proposed reforms
Senate proposals would require reasonable precautions and could establish a duty of care for AI companies.

Sources

Related news