Abstract
Frontier AI capabilities are advancing faster than comprehensive regulation can be developed, but the U.S. government need not wait for legislation. Targeted, low-cost actions in three areas — sharing national security expertise, promoting transparency into frontier AI development, and facilitating best practices for risk management — can complement existing voluntary corporate preparedness frameworks and meaningfully improve AI preparedness in the near term.
Framing
- Frontier AI capabilities show no sign of slowing to let governance catch up, while national security risks need addressing now.
- Comprehensive regulation or legislation may be years away; the pragmatic approach is to build on existing private-sector efforts.
- Private-sector frontier AI governance currently takes the form of voluntary preparedness frameworks:
- Anthropic’s Responsible Scaling Policy
- Google DeepMind’s Frontier Safety Framework
- OpenAI’s Preparedness Framework (scoped to cybersecurity, biological, chemical, and AI self-improvement risks)
- These frameworks draw on civil society research and are scoped to risks of severe harm.
- At the 2024 Seoul summit, leading AI companies signed the Frontier AI Safety Commitments, promising to manage risks effectively, hold themselves accountable, and be transparent to external actors including governments.
- Proposed government role: assist with national-security-relevant preparedness work the government is especially well suited for, across three areas.
1. Contributing national security expertise
Securing model weights
- The most advanced models, developed at great expense by American companies, are currently vulnerable to theft by the Chinese Communist Party, which could rapidly adapt stolen weights to its own ends.
- U.S. AI infrastructure also faces threats from other state actors, criminal groups, and terrorist groups.
- AI companies themselves are calling on the administration to confront misuse and industrial espionage risks and to streamline engagement with national security agencies.
- Securing weights against state-level cyber threats could take years, since protecting models in large-scale active use by untrusted users is technically difficult.
- A coordinated multi-agency effort may be needed; the intelligence community (especially NSA) and the Center for AI Standards and Innovation (CAISI) should explore options.
Cyber threat intelligence sharing
- Bidirectional information sharing between private companies and executive agencies is an established best practice.
- Some intelligence may be too sensitive to share where it would reveal classified sources or methods, but agencies can still share operational cybersecurity best practices.
- Sharing runs both ways — AI companies hold valuable threat intelligence (e.g., Microsoft partners with OpenAI to monitor attack activity).
- Existing vehicles that could be expanded:
- Joint Cyber Defense Collaborative (CISA, announced 2021) — already ran AI cyber tabletop exercises; could expand its intelligence-sharing role.
- Frontier Model Forum (six leading AI companies) — could reduce member overhead and act as a point of contact for national security agencies.
- A dedicated AI Information Sharing and Analysis Center (ISAC) — floated by the Bipartisan Senate AI Working Group under Sen. Schumer as a more comprehensive interface.
Classified evaluations and emergency preparedness
- Building on the 2024 Commerce–DOE Memorandum of Understanding, CAISI and national labs should continue evaluations using classified datasets to assess chemical and biological risks.
- Existing precedent: DOE’s National Nuclear Security Administration evaluates Anthropic’s models for nuclear and radiological risks.
- DHS is naturally positioned to lead preparations for emergencies caused by malicious use or loss of control, given its emergency preparedness expertise and coordination role with critical infrastructure Sector Risk Management Agencies.
- AI-triggered emergencies may cascade across sectors; DHS and partner agencies need to enhance internal AI expertise to fulfill this role.
2. Promoting transparency into frontier AI
- Unlike earlier emerging technologies where government funded and developed the technology directly, frontier AI development is relatively opaque to government, with critical capability information siloed in private companies.
- Transparency is a prerequisite for government and civil society to respond appropriately as capabilities advance.
- The Frontier AI Safety Commitments include only high-level transparency pledges; the abstract ideal needs operationalizing so the right information reaches the right policymakers.
- Policymakers need to understand intended model behavior, alignment with those goals, actual capabilities, and preparations for national security risks.
- Federal legislation could require public disclosure, empower a body to handle sensitive information, and protect whistleblowers and third-party researchers.
Information that should be public
- Behavioral specifications — every frontier company should release the specification used in training to define ideal system behavior. OpenAI’s Model Spec and Anthropic’s constitution demonstrate this is commercially workable. Disclosure lets external experts scrutinize intended behavior and lets citizens understand the principles behind influential technologies.
- Evidence of framework adherence — enough information on risk assessment, mitigation, and governance, with supporting evidence from evaluations, red teaming, and forecasting, for external experts to form independent opinions.
- Access information — who has access to frontier capabilities, especially hacking and military strategy capabilities that could assist power consolidation.
Information requiring sensitive handling
- Frontier capabilities and incidents of harm may need careful treatment: companies resist capability disclosure for competitive reasons and incident reporting for reputational reasons.
- The U.S. government may want temporary strategic ambiguity about frontier capabilities to buy time for policy responses.
- A body such as CAISI or the Bureau of Industry and Security could receive and distribute sensitive information — e.g., passing cyber-offense evaluation results to DHS, which can protect them, mitigate risks, and leverage capabilities defensively.
- Counterweight: transparency enables civil society response, and excessive secrecy risks international mistrust and misunderstanding.
Whistleblower protections
- The “A Right to Warn about Advanced Artificial Intelligence” open letter argued ordinary whistleblower protections are insufficient because they focus on illegal activity, while many AI risks are not yet regulated.
- Congress or the administration should establish a secure reporting line to a government body (CAISI or BIS) for cases where commitments diverge from actions or conduct threatens national security.
- Protections should shield employees from legal retaliation; monetary incentives may be appropriate to offset career and reputational costs.
Third-party researcher access
- Existing third-party evaluators (CAISI, METR, Apollo Research) already have company relationships and assess dual-use capabilities and propensities for deception.
- Government could empower more researchers to conduct a greater variety of evaluations for a more holistic picture.
- Recent advances in privacy-enhancing technologies make external scrutiny possible without compromising privacy, security, or IP.
- External researchers need legal safe harbor against account suspensions and legal reprisal.
3. Developing best practices for risk management
Why best practices help
- Companies can adopt them without devoting as many of their own resources to risk research.
- They clarify what policymakers expect.
- They shield U.S. companies from international regulatory burdens by demonstrating safety work.
- They help define “reasonable care” for liability purposes.
- The development process itself reveals what future regulation could feasibly require — e.g., whether intolerable risk thresholds are tractable, or whether jailbreak-robustness requirements are infeasible.
CAISI’s coordinating role
CAISI is well positioned to build stakeholder consensus and has had success already on a low budget. Preliminary industry and expert consensus identifies five components of preparedness frameworks:
- Risk identification — CAISI coordinates best practices; government expertise is especially useful for national-security-related risks.
- Intolerable risk thresholds — CAISI should be the authoritative home. Companies face pressure in a competitive environment to release models crossing thresholds since competitors (including in China) may release similar models anyway; guidance would help.
- Capability and risk evaluations — CAISI should be funded and staffed to keep leading here and to share what it learns from stakeholder interaction.
- Risk mitigation research — CAISI should closely track technical research and ideally conduct its own, to deeply understand company decisions.
- Risk governance — practices transfer well from other fields; CAISI should draw on existing stakeholder work.
Research funding
- NSF should continue funding foundational research into safe and reliable AI, with advancing the science of evaluations as a core priority — evaluations are central to preparedness frameworks, and work is needed on methodological rigor and accessibility of evaluation tools.
- DARPA and IARPA can fund applied national security research:
- Improving the feasibility of securing frontier models (e.g., secure model APIs yielding open-source protocols that bring higher security within reach).
- Under-discussed areas: how to disrupt the operation of rogue agents, and threat models for how U.S. AI development could be sabotaged.
Conclusion
- Targeted government actions can build on private-sector initiatives rather than reinventing them, making the most of company investments in safety and security while avoiding burdening companies with responsibilities government is better suited to handle.
- Many measures are light-touch and implementable with existing authorities and resources.
- There is no need to wait for comprehensive regulation or legislation to move the needle on AI preparedness.