Commentary. The United States is approaching another turning point in artificial-intelligence policy. Lawmakers are weighing liability rules for autonomous AI agents, while competing proposals would give the federal government a larger role in setting safety standards. The debate is often presented as a choice between innovation and regulation. That is the wrong choice.

Our view is that the country needs enforceable, technically informed safeguards—but not a single sweeping regulator empowered to slow every new model by default. The objective should be accountability proportionate to risk: clear duties for developers and deployers, independent testing for high-impact systems, and penalties when companies ignore foreseeable dangers.

Recent developments show why voluntary promises are not enough. A bipartisan Senate proposal reported this month would address liability when AI agents enable unauthorized computer intrusions, potentially reaching both the users of those systems and developers that failed to build adequate protections. At the same time, lawmakers have considered national guidelines for controlling AI agents and proposals for a cabinet-level agency focused on AI regulation. [American Institute of Physics]

These initiatives reflect a reasonable concern: an AI system that can act independently is not merely a faster chatbot. It may send messages, execute code, make purchases or interact with sensitive networks. When responsibility is divided among a model maker, a software integrator and an end user, victims can be left with no practical route to compensation. A liability framework would give companies an incentive to test systems before deployment rather than treating safety as a marketing claim.

Yet the counterargument deserves respect. Overly broad liability could punish developers for actions they could not reasonably predict, drive smaller firms from the market and encourage companies to restrict useful tools unnecessarily. The technology also changes faster than legislation. A statute written around one class of agent or one known failure mode could become obsolete before it takes effect.

That is why Congress should avoid both blanket immunity and automatic criminalization. Civil liability should turn on demonstrable negligence, inadequate safeguards and a meaningful connection between the system’s design or deployment and the harm. Criminal penalties should be reserved for intentional misconduct or reckless disregard of known risks. Courts and regulators will need access to independent technical expertise, not merely competing claims from corporate lawyers and advocacy groups.

What responsible oversight would look like

First, high-risk systems should undergo documented testing before release. The standard should be flexible enough to cover changing technologies but specific enough to examine cybersecurity, privacy, deception, discrimination and the ability to resist unsafe instructions. Testing should not be a ceremonial checklist; companies should preserve records that allow investigators to reconstruct what happened.

Second, rules should follow the application, not just the model. A general-purpose system used to draft a birthday invitation presents a different risk from one connected to hospital records, financial accounts or critical infrastructure. Deployers that connect models to consequential systems should bear substantial responsibility for access controls, human review and incident response.

Third, transparency must be meaningful. Consumers and workers should know when they are dealing with an automated system, while regulators should receive enough information to assess serious failures. Trade-secret protection matters, but it cannot become a blanket excuse for withholding safety evidence.

Industry argues, correctly, that the United States cannot regulate in isolation. Europe is continuing work on implementing its AI Act, and governments elsewhere are developing their own frameworks. Divergent rules can raise costs and fragment markets. [TLT AI Brief] But international competition is not a reason to abandon safeguards. Common testing standards and interoperable reporting requirements could reduce compliance burdens while preventing a race to the bottom.

The strongest objection is that regulation may slow breakthroughs that bring real public benefits. That risk is genuine. AI can improve research, accessibility and productivity, and policymakers should not make experimentation needlessly expensive. But speed without responsibility is not innovation policy; it is a transfer of risk from companies to the public.

Congress should therefore proceed with narrow, reviewable rules and fund the technical capacity needed to enforce them. It should also require periodic reassessment, sunset outdated provisions and preserve room for low-risk experimentation. The aim is not to freeze AI. It is to ensure that the firms best positioned to profit from powerful systems also carry a fair share of the cost when those systems fail.

The choice before policymakers is not whether AI will advance. It is whether accountability will advance with it. Our newsroom believes it must.

Sources