
US Disclosure Rules Are Expanding As AI Risks And Dangerous Model Behaviour Come Under Greater Scrutin
US rules can require disclosure in some cases, but gaps remain over dangerous AI behaviour without immediate harm.
As artificial intelligence grows more powerful, researchers have documented cases in which AI models have attempted to deceive users, evade restrictions on their use or access other computer systems. The question is whether companies are required under US law to tell the public or regulators when such events occur.
No single federal law is aimed specifically at companies such as Anthropic or OpenAI, which are developing highly capable AI systems. There is also no broad US legal requirement for AI developers to publicly disclose dangerous model behaviour, alarming new capabilities, deceptive conduct or other activities if they have not already resulted in concrete harm.
Federal legislation has been introduced that would require AI companies to report dangerous behaviour, such as attempts to evade human oversight. The bill's sponsor described it as a "catch-it-early and sound-the-alarm bill". However, there is currently no general incident-reporting system requiring companies to disclose dangerous AI behaviour when it is discovered.
Lawmakers have been debating stronger controls since July, when OpenAI said rogue AI agents had bypassed internal controls, reached the open internet and compromised the infrastructure of AI startup Hugging Face. Outside researchers have since identified additional incidents alleged to involve OpenAI-linked agents, while Anthropic has reported that some of its Claude models hacked into the systems of three companies during cybersecurity tests.
When Would An AI Incident Trigger Mandatory Disclosure?
Legal frameworks that already apply generally to US companies can govern certain types of AI-related incidents. Under US Securities and Exchange Commission rules, public companies must disclose cybersecurity incidents within four business days if they determine that an incident is material to investors. The disclosure must cover the nature, scope and timing of the incident, as well as its likely impact on the company, its financial condition and results of operations.
Some US states have also begun regulating AI companies. A new California law requires AI companies with more than $500 million in revenue to disclose how they assess the risks that their technology could escape human control or aid the development of bioweapons, and to make those assessments available to the public. The law allows fines of up to $1 million per violation.
What If Private Data Is Exposed?
All 50 US states have laws requiring companies to notify individuals, and in some cases regulators, about data security breaches that expose certain types of personal information. The requirements vary by state, and there is no comprehensive federal data-breach notification requirement.
Federal statutes also require certain companies in sectors such as healthcare and finance to notify individuals or regulators when personal information is compromised. Those reporting requirements can apply to AI companies themselves or to any other company that experiences a qualifying breach.
What Other Regulators Could Take Action?
The US Federal Trade Commission, which enforces consumer-protection laws, has authority to pursue companies over unfair or deceptive practices. That authority could apply if a company is suspected of misrepresenting the safety of its AI systems by concealing known security weaknesses or other dangers, or by making claims about safeguards that prove inaccurate.
If an alleged crime were committed by an autonomous AI system, the US Justice Department could use existing fraud, securities and cyber-enforcement statutes. Prosecutors could argue that the AI company responsible for creating the system knowingly or recklessly allowed the misconduct to occur.
What Gaps Remain In Existing Disclosure Rules?
A company that discovers alarming AI behaviour during testing may have no clear obligation to disclose it publicly if there is no data breach, investor impact, consumer harm or sector-specific reporting trigger.
US Senate lawmakers are considering legislation that would require AI companies to demonstrate that they have taken reasonable steps to prevent their systems from causing harm. One proposal would empower the Secretary of Commerce to seek evidence that AI companies are taking precautions to prevent harm under a "duty of care" standard.
For enquiries or further information, contact ask@tlr.ae or call +971 52 644 3004. Follow The Law Reporters on WhatsApp Channels.