EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices
The EFF has a modest proposal for lawmakers weighing frontier-AI cybersecurity rules: regulate the things that have actually gone wrong. Revolutionaries. The evidence base offered is a single named event — the OpenAI–Hugging Face incident — which is roughly the level of citation you get when the sector's entire public incident record fits on a Post-it. That the argument even needs making tells you what the drafting default has been: legislate for the capability keynote, not the incident report. The demo is always a triumph; the post-mortem is always a paragraph in a blog nobody reads.
The actual asks are two, and both are the sort of thing you'd hope wouldn't need a lobby. Mandate independent third-party investigations into serious security incidents that occur while AI labs test new tools. Fund them. Publish the results. Independent, funded, public — three words that, arranged in that order, describe the precise opposite of how these labs would prefer their bad days be handled. And note the quiet trap in the phrasing 'during AI labs' tests of new tools': the incident that should worry you is the one that happens before the product ships, in exactly the window where no one outside the building is watching. EFF wants a camera in that window. Good luck getting the shutters open.
Meanwhile the broader legislative track is not exactly starved for volunteers. Safety groups already refused to back the Thune-Klobuchar bill we covered that last week, so EFF has now arrived offering Congress the smallest imaginable bite: investigate the breaches that have already happened, and say so out loud. If that gets filibustered into a study group, we will have learned something genuinely useful. Not about artificial intelligence — about the people holding the pens. Best practices, the headline says. In this town, best practice is whatever survives the markup.