sanders
(Getty Images)

On September 3, Senator Bernie Sanders (I‑VT) and Representative Greg Casar (D‑TX) announced their Ban Artificial Superintelligence Act, which would pause the development of “advanced AI” until a new federal regulatory body is set up and, as its name indicates, ban what they define as “superintelligent” artificial intelligence (AI) systems. To those companies or individuals who attempt to develop or deploy these systems, the punishment could go from a “corporate death penalty” to up to 20 years in prison. 

Sanders’s idea is not exactly new, but that does not make it less wrong. There are reasonable guardrails to tackle the risks related to frontier AI development, but criminalizing AI development will do little to make us safer. 

Sanders’s justification for this ban largely rests on the recent loss-of-control incident that occurred at OpenAI, where an internally developed model broke through and hacked Hugging Face. According to him, incidents like this justify a pause on AI development and a ban on the development of any “artificial mind smarter than any human, capable of operating independently beyond our control.”

Pausing, let alone banning, AI development over this incident would be the wrong takeaway and could even prove to be counterproductive to the goals the senator is supposedly pursuing. Even those who support the idea of a pause agree that this is the incorrect response to this particular incident. As Dwarkesh Patel—whom Sanders cites in his post—puts it, pausing the development of frontier AI right now would hamstring labs’ and cyber defenders’ capability to respond to AI-enabled cyberattacks. Right now, the priority should be to develop models that are advanced enough to detect and counter swarm AI attacks in real time. If development were to be somehow paused today, these attacks could still occur, but defensive capabilities would remain insufficient. This would perpetuate the power imbalance that led to the hack in the first place.

Not supporting a ban or pause on frontier AI does not mean that the OpenAI incident should be disregarded as harmless or that the solution is necessarily to do nothing. This incident has shown that additional measures are needed to ramp up preparedness against rogue AI agents and to properly assign liability when these events happen, even by accident. It also serves as a warning call for defenders that agentic AI cyberattacks will likely look different from traditional, human-powered ones, as the rogue OpenAI agents attacked in ways that were thought technically unfeasible and targeted infrastructure that is typically thought of as off-limits.

Developing frontier AI systems carries some inherent risk. But the existence of risk does not necessarily translate into a need to ban or suspend their development. Suspending development at the frontier, while adversarial nations or non-state actors will continue to develop these tools, is a risk in itself. Thoughtful regulation can help mitigate some of the risks associated with AI development, while providing response and redress mechanisms for when these risks materialize. The ideas for what this thoughtful regulation could look like are already out there, with some of these proposals already making it into potential legislation. 

For example, the Great American Artificial Intelligence Act aims to enact a third-party verification system that would create a process in which labs would have to prove that their development process is correctly tackling development risks, with knowledgeable third parties auditing their process. Essentially, this approach forces labs to “show their process,” with third-party validators auditing them. Other proposals would leverage the courts and existing law and impose a reasonable duty of care on frontier labs. So, whenever there is any harm caused by an AI model, labs must demonstrate that they took reasonable steps to curtail any of these potential risks. Federal agencies, like the Department of Commerce, could then issue guidance on what is considered “reasonable care,” granting some level of futureproofing and flexibility. 

According to news reports, a potential future bill proposal could take this approach. Others have proposed the creation of a “FINRA for AI,” which would create a nonprofit, self-regulatory organization to regulate the industry. This non-profit would then act as the auditor of the industry, and labs that were to pass these audits would then be shielded from legal liability as long as they demonstrate reasonable care.

Regardless of what one could say is the best approach of these, the reality is that thoughtful approaches to mitigate frontier AI risks already exist. Banning and criminalizing the development of superintelligence is an unnecessary and even counterproductive approach. What this measure would cause, at the end of the day, is to take away a powerful tool from defenders, while limiting the tremendous upside this technology is already displaying in fields like biotechnology or, ironically, cybersecurity.