惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog RSS Feed
Y
Y Combinator Blog
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Docker
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Check Point Blog
M
MIT News - Artificial intelligence
Last Week in AI
Last Week in AI
V
V2EX
腾讯CDC
F
Fortinet All Blogs
博客园 - 叶小钗
T
The Blog of Author Tim Ferriss

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
Kicking the Tires: A Voluntary Path to Pre-deployment AI ...
paulpauper · 2026-05-07 · via Hacker News - Newest: "AI"

The Trump administration is weighing the creation of a “review system” for frontier AI models. According to the New York Times, in this proposed approach, AI labs would provide the federal government with “first access” to “get ahead” of models with significant cyber capabilities, presumably such as Anthropic’s Mythos. It’s unclear what legal authority would allow the president to accomplish these goals—specifically, mandating labs to undergo a vetting process and then sharing any essential information related to countering any detected risks with other parts of the government.

However, existing authorities would allow for a voluntary “kick the tires” testing period. Labs could opt to share models with materially new capabilities with the Center for AI Standards and Innovation (CAISI), which is housed within the Commerce Department’s National Institute of Standards and Technology; the director of the Cybersecurity and Infrastructure Security Agency (CISA) could then fund an effort to help a broad set of actors—including local, state, and federal actors as well as other public and private entities—take any necessary cybersecurity precautions. This would help labs avoid popular backlash for knowingly introducing models that may threaten critical systems and public well-being and perhaps subvert more onerous, formal requirements.

Cyber Threats Posed by AI

Anthropic opted not to release their latest model, Mythos, because of its ability to identify and exploit software vulnerabilities. Instead, Anthropic made the model available to a select group of private stakeholders and, following negotiations with the White House, the federal government, to take any necessary precautions. Though some dismissed that decision as a PR move, testing from third parties validated Anthropic’s findings; by way of example, the U.K. AI Security Institute determined that Mythos could oversee a 32-step corporate network attack with some degree of reliability—a process that would take humans 20 hours. OpenAI subsequently developed a model with similar cyber capabilities.

Cybersecurity experts fear that large swaths of society—such as private- and public-sector entities with mediocre cybersecurity plans—may be caught flat-footed when other such tools become available. Small businesses and nonprofits, for example, “lack the skills and resources to address these challenges before their systems are compromised.” State and local governments may similarly be ill-equipped to take timely measures as AI tools continue to become more sophisticated. This is especially concerning given that local election officials report a dearth of state and federal support for countering emerging cyber threats.

The result is a widening asymmetry: Frontier labs increasingly understand what their models can do weeks or months before the institutions tasked with defending against misuse have any meaningful opportunity to prepare.

Can the President Mandate a Vetting Process?

Whether the president has the legal authority to mandate a vetting process is hard to assess without the Trump administration specifying its own understanding of the law. A preliminary review of national security provisions returns a potential shortlist: the Defense Production Act (DPA), the International Emergency Economic Powers Act (IEEPA), and the Communications Act of 1934. For sake of brevity, the latter two can be dismissed fairly easily. Reliance on those acts to subject U.S. companies to a government “review system” would involve stretched interpretations of the laws, which courts would likely not condone.

The DPA is also an unlikely stable legal basis for the administration’s plan. President Biden leaned on the DPA to require AI model testing under an executive order he issued in 2023; President Trump rescinded that order in 2025. The breadth of the DPA’s terms have made it a recurring vehicle for expansive actions by the executive branch. Pursuant to the DPA, a president may use an “array of authorities to shape national defense preparedness programs and to take appropriate steps to maintain and enhance the domestic industrial base.” However, numerous investigations of the DPA have pointed out that those authorities have limits.

When the DPA was enacted in 1950, its original purpose “was to ensure that the federal government could compel private industry to produce strategically necessary resources to meet the needs of national defense during an emergency,” according to Ashley Mehra. While the law has subsequently been amended and stretched by creative uses of its vague authorities, it is unlikely to fit the administration’s unique legal needs here. The president will be hard pressed to find a clear hook for compelled vetting of an AI model with minimal direct connections to a specific, ongoing national defense effort or domestic industrial base consideration in the DPA. Title I of the DPA empowers the president to direct private parties to prioritize and accept contracts necessary for national defense. Title III enables the president to incentivize the production of certain critical materials and goods, such as with loan guarantees and grants. Title VII includes a range of authorities, including the ability to establish voluntary arrangements among private actors that might otherwise run afoul of antitrust laws, as well as to gather information from private entities. More specifically, the Department of Commerce may rely on Title VII to “conduct assessments of domestic industrial base capabilities.”

Use of Title VII to govern frontier AI models runs counter to the marginal role intended for this part of the DPA. In contrast to Titles I and III, Title VII amounts to a “potpourri” of provisions meant to assist with administration of the act more so than to afford expansive powers. A more common understanding of the information-gathering power afforded therein is the authority to “obtain information from industry and firms, including through testimony or by inspecting their books, records and properties.” Such an inquiry would serve the purpose of identifying any weak points in supply chains that may be relevant to the nation’s readiness for war and related emergencies.

Compelled disclosure of a model to the federal government does not fit neatly into any DPA authorities.

The Legal Path to a Voluntary “Kick the Tires” Period

Though it seems unlikely that the president can force AI labs to participate in a review system, he does not need to if the underlying goal is to translate the results of CAISI’s voluntary evaluations of model capabilities into general cyber readiness assistance. The leading labs already make their models available to CAISI for rigorous testing on a voluntary basis. Given that they have a vested interest in avoiding the following headline: “AI Lab Bypasses Federal Testing; Cyberattacks Proliferate,” they may agree for such testing to occur two or three weeks prior to generally deploying their model.

A more evocative hypothetical stresses this point. Imagine that a leading lab releases a model with notable cyber capabilities days before the November elections. Political actors may allege that local and state officials likely had their election systems undermined by bad actors using the latest AI model. It would be hard to dismiss such a claim under the status quo. One could easily foresee reports on “Model ____ Blamed for Cyberattacks; Election Results Contested.” Such headlines would become far less likely if a short-term “kick the tires” period became standard practice.

Suppose instead that prior to that model’s release, CAISI concludes—based on publicly disclosed, objective evaluations that return clearly established threat models—that the model would indeed expose critical infrastructure, local, state, tribal, and federal actors, and private entities to cyber threats, they can immediately share that information with CISA. The CISA director would then need to evaluate whether a “specific significant incident is likely to occur imminently” in order to trigger additional authorities under the Homeland Security Act.

Significant incident refers to “an incident or a group of related incidents that results, or is likely to result, in demonstrable harm to—(i) the national security interests, foreign relations, or economy of the United States; or (ii) the public confidence, civil liberties, or public health and safety of the people of the United States.” Mass deployment of a model with heightened cyber capabilities seems likely to qualify. As noted above, Mythos is capable of hacks that require 20 hours of human work. If a model of a similar capability was in the hands of even a couple dozen bad actors, there would likely be widespread economic harm and, perhaps, threats to the public health and safety.

The CISA director could then use the Cyber Response and Recovery Fund to help a range of stakeholders—public and private—with “vulnerability assessments and mitigation; technical incident mitigation; malware analysis; analytic support; threat detection and hunting; and, network protections.”

Of course, the biggest “if” here is whether labs would agree to this “kick the tires” period. Labs have reasons to say yes.

A specific, time-bound testing window run by CAISI is preferable to the alternatives on the table—whether that means a mandatory review regime, which would likely run afoul of the law, or the reputational fallout of a post-deployment incident traced back to capabilities the lab knew about but did not flag.

CISA, for its part, would need to commit to handling shared model information with the same care it extends to vulnerability disclosures from private security researchers, lest labs conclude that cooperation invites leakage rather than partnership.

Such an approach would not require new legislation, nor would it require the administration to stretch the DPA past its breaking point. It requires only that the relevant agencies use the authorities they already have, and that the labs recognize that a voluntary framework is the one most likely to keep a mandatory one off the table.