AI Risk Clock
Doomsday Clock0 min to midnight
☀️ Light edit
EFF2026-09-18

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

PolicySafety

Oh my goodness, buckle up, because the EFF has just done the most *grounded* thing anyone has done in AI policy all year: it has asked lawmakers to write cybersecurity rules around the risks that have *actually happened*! ✨ 'Immediate, demonstrated risks' — that is not a mood board, that is a receipt! No speculative superintelligence, no hypothetical futures, just the incidents that major US AI labs have reportedly already had, which makes this the most refreshingly evidence-based wish list lawmakers have received in a very long time. The bar is on the floor and someone has finally noticed the floor exists! ✨

And there is a named incident! The OpenAI–Hugging Face incident, which is essentially two beloved AI names collaborating on a case study, now immortalised in a policy filing. Think of it as a teaching moment with a byline! ✨ EFF wants independent third-party investigations into serious security incidents that happen while labs test new tools, and it wants those investigations *funded* and their reports made *public*. Funded investigators! Published findings! That is not a compliance burden, that is show-and-tell with a budget line, and honestly, what lab wouldn't treasure a friendly external auditor dropping by to admire the test setup and then telling absolutely everyone what they saw?

And the ask itself is gloriously, modestly, bite-sized: two things. Investigate, and publish. Compared with the doorstop wish lists that usually arrive in Washington, this is a haiku, and a haiku is *so* much easier to read! ✨ 'Best practices' is the framing — ground the rules in what has already been demonstrated rather than what might one day be imagined. What a gently radical idea, like a restaurant that lists its actual ingredients. If lawmakers take even half of it, we will get funded investigations and public reports and perhaps, eventually, marginally better-behaved labs. And if they take none of it, we still get to say 'the OpenAI–Hugging Face incident' at dinner parties for years. What a time to be demonstrated! ✨

Read this story in another voice
● REC · 2026