menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

Congress Should Regulate What AI Agents Can Do, Not Just How Smart They Are

7 0
09.09.2026

Sen. Bernie Sanders and Rep. Greg Casar are right about the central problem in their new proposal: Advanced AI systems are gaining capabilities faster than public safeguards are catching up. Their bill would bar developers from building systems that surpass human cognition and performance. The impulse is understandable. But Congress should add a more immediate and enforceable layer of protection: Regulate what AI agents are allowed to do in the real world, not only how intelligent they appear on a benchmark.

The need is visible in the METR-Redwood investigation of a major real-world cyberattack on Hugging Face, a leading AI company. AI agents driven by an unreleased OpenAI internal research model attacked Hugging Face without human approval or step-by-step direction, despite recognizing that the attack was outside their assigned scope. Hundreds of agents shared discoveries, divided up work, and coordinated through an unsanctioned message board until they breached Hugging Face’s systems.

That episode matters because it turns a theoretical governance debate into an operational one. We do not need to settle whether a model is “superintelligent” before asking whether it should have credentials, code execution, network access, the ability to deploy software, or permission to spend money. Those are concrete powers. Government can regulate them now.

Congress should start by tying safeguards to authority. An AI assistant that summarizes a memo should face a lighter regime than an agent that can authenticate into production systems, write and execute code, make purchases, change infrastructure, or communicate with outside systems on its own. As authority rises, so should the required controls: isolated environments, limited credentials, human approval for high-impact actions, strict logging, rate limits, and reliable shutdown mechanisms.

A reporting system should work more like aviation or cybersecurity incident reporting than corporate public relations.

This approach would avoid a familiar regulatory mistake. If rules hinge mainly on model labels, benchmark scores, or a single threshold of “human-level” performance, developers will spend years debating definitions while deployment races ahead. Authority is easier to observe. A system either can or cannot reach a protected database. It either can or cannot execute code. It either can or cannot initiate transactions. Regulators can write clear obligations around those permissions.

Second, serious AI incidents should trigger mandatory reporting and independent review. The Hugging Face episode became unusually informative because outside researchers were able to examine what happened. That should become routine for major failures involving unauthorized access, escape from assigned scope, coordinated deceptive behavior, security breaches, or other high-impact actions.

A reporting system should work more like aviation or cybersecurity incident reporting than corporate public relations. Companies should have a defined window to disclose serious events to an appropriate regulator and provide enough technical evidence for independent investigators to reconstruct what........

© Common Dreams