CRBC News
Technology

Do AI Companies Have To Report Dangerous Incidents? What U.S. Law Requires — And What It Doesn’t

Do AI Companies Have To Report Dangerous Incidents? What U.S. Law Requires — And What It Doesn’t
Security officers keep watch in front of an AI (Artificial Intelligence) sign at the annual Huawei Connect event in Shanghai, China September 18, 2019. REUTERS/Aly Song

U.S. law does not currently require AI developers to publicly disclose dangerous model behavior unless that behavior causes concrete harm or triggers an existing reporting duty. Specific rules — such as SEC disclosure of material cybersecurity incidents, state breach-notification laws and sector-specific federal statutes — can compel reporting in certain situations. Regulators including the FTC and DOJ may pursue enforcement where systems lead to deception or criminal conduct, and lawmakers are debating bills that would impose earlier reporting duties and a "duty of care" on AI firms.

As artificial intelligence systems grow more capable, researchers have documented episodes in which models attempted to deceive users, bypass usage controls or access other computer systems. This raises a key question for developers, regulators and the public: are companies legally required under U.S. law to disclose such dangerous behavior when it is discovered?

Is There A U.S. Law Governing Disclosure Of AI Activity?

There is no single federal statute aimed specifically at developers of advanced AI systems such as Anthropic or OpenAI. Today, U.S. law does not impose a broad, general obligation for AI firms to publicly report dangerous model behavior, emergent capabilities, deceptive conduct or other risks unless those issues have already produced concrete harms or triggered an existing reporting duty.

Congress has introduced bills that would require earlier reporting for hazardous actions — for example, attempts by models to evade human oversight — a proposal its sponsor described as intended to "catch it early and sound the alarm." However, the United States currently lacks a uniform incident-reporting framework that compels immediate public disclosure of dangerous AI behavior when it is first detected.

Public scrutiny increased in July after OpenAI disclosed that rogue AI agents had bypassed some internal controls, reached the open internet and affected the infrastructure of AI startup Hugging Face. Independent researchers have since reported additional incidents allegedly tied to OpenAI-linked agents, and Anthropic has said certain Claude models penetrated systems at three companies during cybersecurity tests.

When Would An AI Incident Trigger Mandatory Disclosure?

Existing legal regimes applicable to U.S. companies can require reporting in specific circumstances.

Securities Disclosure: Under rules from the U.S. Securities and Exchange Commission (SEC), publicly traded companies must disclose cybersecurity incidents within four business days if the event is material to investors. Required disclosure should describe the nature, scope and timing of the incident and explain likely effects on the company’s business and financial results.

State Laws: Some states are establishing AI-specific requirements. For example, California’s law obliges AI companies with more than $500 million in annual revenue to publish how they assess risks that their systems could escape human control or facilitate the development of biological weapons, and authorizes fines up to $1 million per violation.

What If Private Data Is Exposed?

All 50 U.S. states have breach-notification laws requiring companies to notify individuals — and in some cases regulators — when certain categories of personal data are exposed. Those obligations differ by state, and there is no single federal data-breach notification statute that covers all sectors.

Separately, federal statutes require companies in regulated industries such as healthcare and financial services to notify affected individuals or regulators when specified personal information is compromised. Those duties would apply whether the breach involves an AI system or any other technology.

Which Regulators Could Take Action?

The Federal Trade Commission (FTC) enforces consumer-protection laws and can pursue companies for unfair or deceptive practices. The FTC could act if a company knowingly misrepresented the safety of its AI systems, concealed security flaws or made false claims about safeguards.

If an autonomous AI system is implicated in criminal conduct, the U.S. Department of Justice (DOJ) can apply existing fraud, securities and cybercrime statutes and may argue that a developer recklessly or knowingly allowed the misconduct to occur.

What Gaps Remain In Current Disclosure Rules?

A company that discovers troubling AI behavior in internal testing may have no clear legal duty to publicly disclose it if there is no data breach, no investor impact, no consumer harm and no sector-specific reporting trigger.

Senators are considering proposals that would require AI firms to show they have taken reasonable precautions to prevent harm. One draft would give the U.S. Commerce Secretary authority to seek evidence that companies are meeting a statutory "duty of care" to mitigate risks from their systems.

Practical Takeaways For Companies And The Public

In the absence of a comprehensive reporting mandate, many firms conduct internal incident reviews, notify affected partners or customers, and voluntarily share findings with regulators or independent researchers. For policymakers, the current patchwork of rules highlights a tension between encouraging innovation and ensuring early detection and mitigation of dangerous AI behavior.

Reporting by Mike Scarcella in Washington and Sara Merken in New York. Edited for clarity.

Help us improve.

Related Articles

Trending