State Frontier Model Regulation: A Misguided Approach to AI Governance

State regulation of frontier models poses significant risks to AI innovation, national security, and public safety. California's Transparency in Frontier Artificial Intelligence Act (TFAIA), SB 53, is the first U.S. jurisdiction to regulate AI frontier model development. Introduced by Senator Scott Weiner, TFAIA raises concerns around the law's threshold for regulation and protection of trade secrets. While SIIA appreciates the approach's flexibility and alignment with emerging industry best practices, it falls short in addressing the public's top concerns around AI.

Key Takeaways:

  • State frontier model regulation creates a false sense of security, focusing on "catastrophic risk" defined as a foreseeable and material risk that a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars in damage to, or loss of, property arising from a single incident. This framing is a poor proxy for assessing the capabilities of frontier models.
  • California's TFAIA will incentivize developers to comply with the law but does not incentivize frontier model developers to make their models more safe and secure. This oversight approach fails to consider misuse, misalignment, and security risks that developers should prioritize to make their models useful and reliable.
  • State frontier model regulation is limited to conduct within the state, limiting its effectiveness and creating a situation of fragmented, inconsistent laws that apply to the same developers and conduct.
  • A decentralized, state-by-state approach to frontier model regulation is a recipe for increasing the surface area for cybersecurity attacks and generating inconsistencies with the federal government's approach to AI governance.
  • State regulators are likely to demand and store sensitive technical information, which has great value to malicious actors, including foreign adversaries.
  • Congress should pass legislation establishing a unified, national framework for frontier model oversight and risk management, which creates a baseline for developers and avoids regulatory fragmentation.

Statistics:

  • 87% of Americans are concerned about foreign governments using AI to attack the United States, according to a Gallup poll.
  • State frontier model regulation will require states to siphon limited public resources from other priorities, diverting attention from other AI-related areas, such as advancing cybersecurity operations and enforcing tech-neutral laws.
  • Over 50 people or more than one billion dollars in damage to, or loss of, property arising from a single incident is considered "catastrophic risk."
  • The California Office of Emergency Services and the California Attorney General will need to devote resources to implement TFAIA oversight, which under limited budget flexibility could lead to underinvestment in AI-related areas within state purview.
  • Implementing TFAIA charges the California Office of Emergency Services and the California Attorney General with different roles for reporting, oversight, and enforcement.

Sources:

  • Transparency in Frontier Artificial Intelligence Act (TFAIA), SB 53
  • Software and Information Industry Association (SIIA) statement on TFAIA
  • RAISE Act (New York)
  • TAKE IT DOWN Act (federal law)
  • Gallup poll on AI and national security concerns
  • Frontier Model Forum research on AI risks and mitigation strategies
  • National Institute of Standards and Technology (NIST) and Center for AI Standards and Innovation (CAISI) research and guidelines on AI development and regulation